Au-secours!!! mon pc est envahi

Bonjour à tous,

j'ai avast comme antivirus là c'est sûr je vais en changer,
déjà quel antivirus me conseillez-vous pour être bien protéger contre toutes sortes de logiciels malveillants, virus ou d'autres choses qui se trouveraient sur mon pc .
bon j'ai un pc que depuis 2 ans et j'ai pris avast dès le début.
à chaque fois que je me réinscrit chez avast (tous les ans) et que je fais un scan par la suite il me trouve pleins de choses pour lesquels il ne m'a jamais prévenu je ne comprend pas.
c'est vrai que j'avais remarqué quelques petites choses bizard, mon pc rame souvent ou dès que je fais 2 ou 3 choses en même temps il fait un bruit énorme, ou quand j'essaie de faire pivoter une photo et de l'enregistrer il me trouve un virus pourquoi allez savoir.
si quelqu'un pouvait m'aider pour me dire quoi faire pour éradiquer définitivement toutes ses m....;
HELP AIDEZ MOI je vous en serait très reconnaissante je suis à bout et ne sais vraiment pas comment faire toute seule

merci à vous tous et toutes.
Configuration: vista premium familiale
mozilla firefox

37 réponses

Résumé de la discussion

Une utilisatrice cherche quel antivirus choisir pour se protéger contre les malwares sur un PC Vista, et décrit Avast comme insuffisant après des détections répétées et des ralentissements persistants. Des réponses recommandent d’utiliser un seul antivirus et de désinstaller Avast, avec des conseils comme désactiver le contrôle des comptes utilisateurs lors d’infections et d’employer HijackThis ou Navilog pour diagnostiquer. D’autres échanges détaillent des procédures avec des outils comme ToolBar-S&D, NAVI/navifix, et Malwarebytes, demandant d’établir des rapports à coller puis relancer des nettoyages en mode sans échec et redémarrages. En cas de persistance, la discussion signale aussi des restes potentiels de programmes comme Norton ou Comodo et encourage le partage des rapports d’analyse pour obtenir une aide ciblée.

Bobot (l’IA à votre service)
  1. http://www.commentcamarche.net/telecharger/telecharger 55 antivir personal
    essaie avec celui ci, a ce jour avast est de moins en moins performant mais on espere toujours qu'il redevienne un des meilleur!!
    1. bonjour

      un seul antivirus sur un pc donc si tu installes antivir desinstalle avast.le scan ce n est pas seulement une fois par an .

      on va regarder de plus pres sur ton probleme.
      1)pour vista si infection.

      Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection: IMPORTANT A NE SURTOUT PAS OUBLIER):

      - Va dans démarrer puis panneau de configuration
      - Double Clique sur l'icône "Comptes d'utilisateurs"
      - Clique ensuite sur désactiver et valide.

      http://www.laboratoire-microsoft.org/tips-23933-desactiver-uac-vista.html

      2)telecharge cela:util pour voir ce que peut etre l infection et agir ensuite.

      http://www.commentcamarche.net/telecharger/telecharger 159 hijackthis

      installe le normallement comme tout autre programme dans c/programme/...............
      clique sur do a scan and save a logfile, tu obtiens un rapport que tu colles.

      1. Salut,

        merci à toi de me répondre, pour le moment avast est toujours en train de scanner mon pc depuis hier soir je finis le scan et après j'installe aviva à la place c'est ça? pourra t-il me débarasser de tous les logiciels malveillants et autres choses que j'ai sur mon pc ?

        merci à toi.
        1. Salut

          escuse moi totobetourne je n'avais pas vu que tu m'avais répondu aussi, j'arète carrément le scan et je fai ce que tu ma dis dès maintenant ou vaut mieux que je continu la scan en cours.
          1. resalut,

            j'ai désactive le contrôle utilisateur et voici le rapport hijackthis

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 10:18:59, on 02/04/2009
            Platform: Windows Vista SP1 (WinNT 6.00.1905)
            MSIE: Internet Explorer v7.00 (7.00.6001.18000)
            Boot mode: Normal

            Running processes:
            C:\Windows\system32\Dwm.exe
            C:\Windows\system32\taskeng.exe
            C:\Windows\Explorer.EXE
            C:\Program Files\iTunes\iTunesHelper.exe
            C:\Program Files\Alwil Software\Avast4\ashDisp.exe
            C:\Windows\ehome\ehtray.exe
            C:\Program Files\Windows Live\Messenger\msnmsgr.exe
            C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
            C:\Program Files\Windows Media Player\wmpnscfg.exe
            C:\Users\jessie\AppData\Local\aswyg.exe
            C:\Windows\System32\mobsync.exe
            C:\Windows\ehome\ehmsas.exe
            C:\Windows\system32\SearchFilterHost.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://lo.st
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
            R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
            O1 - Hosts: ::1 localhost
            O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
            O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
            O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
            O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
            O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
            O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
            O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
            O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
            O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
            O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
            O4 - HKCU\..\Run: [aswyg] "c:\users\jessie\appdata\local\aswyg.exe" aswyg
            O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
            O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
            O13 - Gopher Prefix:
            O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
            O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
            O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
            O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
            O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
            O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
            O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
            O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
            O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
            O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
            O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
            O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe
            O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
            O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
            O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
            O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
            O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
            O23 - Service: stllssvr - Unknown owner - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)
            1. ok

              quelques infections.on va enlev er une prenmiere avec cet outil mais ce n est pas fini.

              1)tu télécharges navilog1
              http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

              Laisse-toi guider. Au menu principal, choisis 1 et valides.
              (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)
              Patiente jusqu'au message :
              *** Analyse Termine le ..... ***
              Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
              Copie-colle l'intégralité dans une réponse. Referme le blocnote.
              Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)

              2)Arriver au menu principal, choisir l'option 2 et valider (nettoyage "automatique" ).

              Le fix demandera ensuite de "redémarrer le PC", fermer toutes les fenêtres ouvertes
              et appuyer sur une touche comme demandé.(si le PC ne redémarre pas automatiquement, le faire manuellement)
              Au redémarrage du PC, choisir la session habituelle si nécessaire.

              Patienter jusqu'au message : "Nettoyage Terminé le ..."

              Le bureau revient, puis le bloc-note s'ouvre .
              Sauvegarder ce rapport de manière à le retrouver, puis fermer le bloc-note ...
              (Le rapport sera en outre sauvegardé à la racine du disque "C\:cleannavi.txt")

              Postes ce rapport dans ta nouvelle réponse pour analyse et attends la suite ...

              (PS : Si le bureau ne réapparaît pas, faire CTRL+ALT+SUPPR pour ouvrir le gestionnaire de tâches.
              Choisir l'onglet processus. Cliquer en haut à gauche sur fichiers et choisir exécuter,
              Taper explorer et valider.)
              1. je m'escuse je ne savais pas si tu allais me répondre, c'est la première fois que je demande de l'aide alors mille escuse je ne le referait pas.

                voici le rapport : (si tu veut bien continuer à t'occuper de mon pb biensur)

                Search Navipromo version 3.7.6 commencé le 02/04/2009 à 11:21:44,00

                !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                !!! Postez ce rapport sur le forum pour le faire analyser !!!
                !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

                Outil exécuté depuis C:\Program Files\navilog1

                Mise à jour le 14.03.2009 à 18h00 par IL-MAFIOSO

                Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
                X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) D CPU 2.80GHz )
                BIOS : Phoenix - AwardBIOS v6.00PG
                USER : jessie ( Administrator )
                BOOT : Normal boot

                C:\ (Local Disk) - NTFS - Total:227 Go (Free:87 Go)
                D:\ (Local Disk) - NTFS - Total:5 Go (Free:0 Go)
                E:\ (CD or DVD)
                F:\ (USB)
                H:\ (USB)
                I:\ (USB)
                J:\ (USB)

                Recherche executé en mode normal

                *** Recherche dossiers dans "C:\Windows" ***

                *** Recherche dossiers dans "C:\Program Files" ***

                *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

                *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1" ***

                *** Recherche dossiers dans "C:\ProgramData" ***

                *** Recherche dossiers dans "c:\users\jessie\appdata\roaming\micros~1\windows\startm~1\programs" ***

                *** Recherche dossiers dans "C:\Users\jessie\AppData\Local\virtualstore\Program Files" ***

                *** Recherche dossiers dans "C:\Users\jessie\AppData\Local" ***

                *** Recherche dossiers dans "C:\Users\IUSR_N~1\AppData\Local" ***

                *** Recherche dossiers dans "C:\Users\jessie\AppData\Roaming" ***

                *** Recherche dossiers dans "C:\Users\IUSR_N~1\appdata\roaming" ***

                *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
                pour + d'infos : http://www.gmer.net

                *** Recherche avec GenericNaviSearch ***
                !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
                !!! A vérifier impérativement avant toute suppression manuelle !!!

                * Recherche dans "C:\Windows\system32" *

                * Recherche dans "C:\Users\jessie\AppData\Local\Microsoft" *

                * Recherche dans "C:\Users\jessie\AppData\Local\virtualstore\windows\system32" *

                * Recherche dans "C:\Users\jessie\AppData\Local" *

                * Recherche dans "C:\Users\IUSR_N~1\AppData\Local" *

                *** Recherche fichiers ***

                *** Recherche clés spécifiques dans le Registre ***
                !! Les clés trouvées ne sont pas forcément infectées !!

                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "aswyg"="\"c:\\users\\jessie\\appdata\\local\\aswyg.exe\" aswyg"

                *** Module de Recherche complémentaire ***
                (Recherche fichiers spécifiques)

                1)Recherche nouveaux fichiers Instant Access :

                2)Recherche Heuristique :

                * Dans "C:\Windows\system32" :

                * Dans "C:\Users\jessie\AppData\Local\Microsoft" :

                * Dans "C:\Users\jessie\AppData\Local\virtualstore\windows\system32" :

                * Dans "C:\Users\jessie\AppData\Local" :

                aswyg.exe trouvé !
                aswyg.dat trouvé !
                aswyg_nav.dat trouvé !
                aswyg_navps.dat trouvé !

                * Dans "C:\Users\IUSR_N~1\AppData\Local" :

                3)Recherche Certificats :

                Certificat Egroup absent !
                Certificat Electronic-Group absent !
                Certificat Montorgueil absent !
                Certificat OOO-Favorit absent !
                Certificat Sunny-Day-Design-Ltd absent !

                4)Recherche autres dossiers et fichiers connus :

                *** Analyse terminée le 02/04/2009 à 12:23:30,81 ***
                1. lance navilog en option 2 et colle le rapport obtenu.

                  ensuite fait cela.
                  1)Télécharge ToolBar-S&D ( Merci à Eric_71, Angeldark, Sham_Rock et XmichouX )
                  https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

                  lors du scan coupe ta connection internet.

                  * Double-clique sur ToolBar-SD afin de lancer l'installation, un raccourci sera ajouté sur le Bureau.
                  * Double-clique dessus pour démarrer l'outil; choisis la langue.
                  * Sous Vista, faire un clic droit et "Exécuter en tant qu'administrateur" (Elévation des privilèges), puis -> Continuer.
                  * Tape 1 puis sur la touche [Entrée] afin de lancer la suppression.
                  * Patiente jusqu'à la fin de la recherche.
                  * À la fin du scan, le rapport s'ouvrira dans le Bloc-notes.
                  * Poste ce rapport, par copier/coller, dans ta prochaine réponse.
                  * Le rapport se trouve également sous : C:\TB.txt

                  2)relance toolbar mais la appuie sur l option 2. tu obtiens un rapport que tu colles.
                  1. déjà je te remercie de me répondre à nouveau

                    j'ai fait le nettoyage auto avec navilog. le rapport :

                    lean Navipromo version 3.7.6 commencé le 02/04/2009 à 16:48:09,37

                    Outil exécuté depuis C:\Program Files\navilog1

                    Mise à jour le 14.03.2009 à 18h00 par IL-MAFIOSO

                    Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
                    X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) D CPU 2.80GHz )
                    BIOS : Phoenix - AwardBIOS v6.00PG
                    USER : jessie ( Administrator )
                    BOOT : Normal boot

                    C:\ (Local Disk) - NTFS - Total:227 Go (Free:87 Go)
                    D:\ (Local Disk) - NTFS - Total:5 Go (Free:0 Go)
                    E:\ (CD or DVD)
                    F:\ (USB)
                    H:\ (USB)
                    I:\ (USB)
                    J:\ (USB)

                    Mode suppression automatique
                    avec prise en charge résultats Catchme et GNS

                    Nettoyage exécuté au redémarrage de l'ordinateur

                    *** fsbl1.txt non trouvé ***
                    (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)

                    *** Suppression avec sauvegardes résultats GenericNaviSearch ***

                    * Suppression dans "C:\Windows\System32" *

                    * Suppression dans "C:\Users\jessie\AppData\Local\Microsoft" *

                    * Suppression dans "C:\Users\jessie\AppData\Local\virtualstore\windows\system32" *

                    * Suppression dans "C:\Users\jessie\AppData\Local" *

                    * Suppression dans "C:\Users\IUSR_N~1\AppData\Local" *

                    *** Suppression dossiers dans "C:\Windows" ***

                    *** Suppression dossiers dans "C:\Program Files" ***

                    *** Suppression dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

                    *** Suppression dossiers dans "c:\progra~2\micros~1\windows\startm~1" ***

                    *** Suppression dossiers dans "C:\ProgramData" ***

                    *** Suppression dossiers dans c:\users\jessie\appdata\roaming\micros~1\windows\startm~1\programs ***

                    *** Suppression dossiers dans "C:\Users\IUSR_N~1\appdata\roaming\micros~1\windows\startm~1\programs" ***

                    *** Suppression dossiers dans "C:\Users\jessie\AppData\Local\virtualstore\Program Files" ***

                    *** Suppression dossiers dans "C:\Users\jessie\AppData\Local" ***

                    *** Suppression dossiers dans "C:\Users\IUSR_N~1\AppData\Local" ***

                    *** Suppression dossiers dans "C:\Users\jessie\AppData\Roaming" ***

                    *** Suppression dossiers dans "C:\Users\IUSR_N~1\appdata\roaming" ***

                    *** Suppression fichiers ***

                    *** Suppression fichiers temporaires ***

                    Nettoyage contenu C:\Windows\Temp effectué !
                    Nettoyage contenu C:\Users\jessie\AppData\Local\Temp effectué !

                    *** Traitement Recherche complémentaire ***
                    (Recherche fichiers spécifiques)

                    1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

                    2)Recherche, création sauvegardes et suppression Heuristique :

                    * Dans "C:\Windows\system32" *

                    * Dans "C:\Users\jessie\AppData\Local\Microsoft" *

                    * Dans "C:\Users\jessie\AppData\Local\virtualstore\windows\system32" *

                    * Dans "C:\Users\jessie\AppData\Local" *

                    aswyg.exe trouvé !
                    Copie aswyg.exe réalisée avec succès !
                    aswyg.exe !!ERREUR SUPPRESSION!!

                    aswyg.dat trouvé !
                    Copie aswyg.dat réalisée avec succès !
                    aswyg.dat supprimé !

                    aswyg_nav.dat trouvé !
                    Copie aswyg_nav.dat réalisée avec succès !
                    aswyg_nav.dat supprimé !

                    aswyg_navps.dat trouvé !
                    Copie aswyg_navps.dat réalisée avec succès !
                    aswyg_navps.dat supprimé !

                    * Dans "C:\Users\IUSR_N~1\AppData\Local" *

                    *** Sauvegarde du Registre vers dossier Safebackup ***

                    sauvegarde du Registre réalisée avec succès !

                    *** Nettoyage Registre ***

                    Nettoyage Registre Ok

                    *** Certificats ***

                    Certificat Egroup absent !
                    Certificat Electronic-Group absent !
                    Certificat Montorgueil absent !
                    Certificat OOO-Favorit absent !
                    Certificat Sunny-Day-Design-Ltdt absent !

                    *** Recherche autres dossiers et fichiers connus ***

                    *** Nettoyage terminé le 02/04/2009 à 16:55:30,25 ***
                    1. coucou,

                      j'ai téléchargé toolbar mais j'ai pas réussi à le mettre sur le bureau, en faite je ne sais pas ou il est sur le pc.

                      le rapport avec l'option 1 :

                      -----------\\ ToolBar S&D 1.2.8 XP/Vista

                      Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
                      X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) D CPU 2.80GHz )
                      BIOS : Phoenix - AwardBIOS v6.00PG
                      USER : jessie ( Administrator )
                      BOOT : Normal boot
                      C:\ (Local Disk) - NTFS - Total:227 Go (Free:87 Go)
                      D:\ (Local Disk) - NTFS - Total:5 Go (Free:0 Go)
                      E:\ (CD or DVD)
                      F:\ (USB)
                      H:\ (USB)
                      I:\ (USB)
                      J:\ (USB)

                      "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
                      Option : [1] ( 02/04/2009|17:18 )

                      [ UAC => 0 ]

                      -----------\\ Recherche de Fichiers / Dossiers ...

                      -----------\\ [..\Internet Explorer\Main]

                      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                      "Local Page"="C:\\Windows\\system32\\blank.htm"
                      "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                      "Start page"="https://www.google.fr/?gws_rd=ssl"
                      "Url"="http://www.microsoft.com/athome/community/rss.xml"
                      "Url"="http://rss.msn.com/en-us/?feedoutput=rss&ocid=iehrs&unsub=true"
                      "Url"="http://www.microsoft.com/atwork/community/rss.xml"

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                      "Start Page"="http://lo.st"
                      "Default_Page_URL"="https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF"
                      "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                      "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"

                      --------------------\\ Recherche d'autres infections

                      C:\Users\jessie\AppData\Local\aswyg.dat
                      C:\Users\jessie\AppData\Local\aswyg.exe
                      C:\Users\jessie\AppData\Local\aswyg_navps.dat
                      [b]==> EGDACCESS <==/b

                      [ UAC => 1 ]

                      1 - "C:\ToolBar SD\TB_1.txt" - 02/04/2009|17:19 - Option : [1]

                      -----------\\ Fin du rapport a 17:19:19,66

                      le rapport avec l'option 2 :

                      -----------\\ ToolBar S&D 1.2.8 XP/Vista

                      Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
                      X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) D CPU 2.80GHz )
                      BIOS : Phoenix - AwardBIOS v6.00PG
                      USER : jessie ( Administrator )
                      BOOT : Normal boot
                      C:\ (Local Disk) - NTFS - Total:227 Go (Free:87 Go)
                      D:\ (Local Disk) - NTFS - Total:5 Go (Free:0 Go)
                      E:\ (CD or DVD)
                      F:\ (USB)
                      H:\ (USB)
                      I:\ (USB)
                      J:\ (USB)

                      "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
                      Option : [2] ( 02/04/2009|17:23 )

                      [ UAC => 1 ]

                      -----------\\ Recherche de Fichiers / Dossiers ...

                      -----------\\ [..\Internet Explorer\Main]

                      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                      "Local Page"="C:\\Windows\\system32\\blank.htm"
                      "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                      "Start page"="https://www.google.fr/?gws_rd=ssl"
                      "Url"="http://www.microsoft.com/athome/community/rss.xml"
                      "Url"="http://rss.msn.com/en-us/?feedoutput=rss&ocid=iehrs&unsub=true"
                      "Url"="http://www.microsoft.com/atwork/community/rss.xml"

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                      "Start Page"="https://www.msn.com/fr-fr/"
                      "Default_Page_URL"="https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF"
                      "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                      "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"

                      --------------------\\ Recherche d'autres infections

                      C:\Users\jessie\AppData\Local\aswyg.dat
                      C:\Users\jessie\AppData\Local\aswyg.exe
                      C:\Users\jessie\AppData\Local\aswyg_navps.dat
                      [b]==> EGDACCESS <==/b

                      [ UAC => 1 ]

                      1 - "C:\ToolBar SD\TB_1.txt" - 02/04/2009|17:19 - Option : [1]
                      2 - "C:\ToolBar SD\TB_2.txt" - 02/04/2009|17:23 - Option : [2]

                      -----------\\ Fin du rapport a 17:23:32,81
                      1. A)pour navilog infection pas enleve.
                        fait cela:
                        Démarre en mode sans échec :
                        Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
                        Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                        Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                        (Si F8 ne marche pas utilise la touche F5).

                        1)Double clique sur navilog1.bat
                        Au menu principal, choisis 4 et valide.
                        A la question posée, choisis "mode manuel" en tapant M ou m puis valide.
                        Il va te demander de saisir le nom de fichier, saisis ce qui est en gras ci-dessous et rien d'autre puis valide:

                        aswyg

                        le fix va te demander de le resaisir, fais-le et valide
                        Ton bureau va disparaitre, c'est normal.
                        Laisse-toi guider
                        Patiente jusqu'au message :
                        *** Nettoyage Terminé le ..... ***
                        Appuies sur une touche comme demandé, le blocnote va s'ouvrir.
                        Sauvegarde le rapport de manière à le retrouver
                        Referme le blocnote. Ton bureau va réapparaitre.
                        Le rapport est en outre sauvegardé à la racine du disque (cleannavi.txt)
                        Poste le rapport

                        2)refais une recherche de toolbar sd , tu dois l avoir sur le bureau normallement.

                        refais le en option 1 et ensuite en option 2 . colle les 2 rapports . merci . fait attention tu as maintenant 4 rapports avec toolbar sd , colle bien les 2 derniers que je te demande.
                        1. Bonjour TOTOBETOURNE

                          j'ai fait comme tu m'as dit, merci pour toutes tes précisions ça m'aide beaucoup.

                          le rapport avec navilog :

                          Clean Navipromo version 3.7.6 commencé le 03/04/2009 à 9:13:32,80

                          Outil exécuté depuis C:\Program Files\navilog1
                          Session actuelle : "jessie"

                          Mise à jour le 14.03.2009 à 18h00 par IL-MAFIOSO

                          Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
                          X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) D CPU 2.80GHz )
                          BIOS : Phoenix - AwardBIOS v6.00PG
                          USER : jessie ( Administrator )
                          BOOT : Fail-safe boot

                          C:\ (Local Disk) - NTFS - Total:227 Go (Free:87 Go)
                          D:\ (Local Disk) - NTFS - Total:5 Go (Free:0 Go)
                          E:\ (CD or DVD)
                          F:\ (USB)
                          H:\ (USB)
                          I:\ (USB)
                          J:\ (USB)

                          Mode suppression par méthode manuelle

                          Nom du fichier saisi : ASWYG

                          Nettoyage executé en mode sans échec

                          *** Recherche, création sauvegardes et suppression ***

                          * Suppression dans "C:\Windows\system32" *

                          * Suppression dans "C:\Users\jessie\AppData\Local\Microsoft" *

                          * Suppression dans "C:\Users\jessie\AppData\Local\virtualstore\windows\system32" *

                          * Suppression dans "C:\Users\jessie\AppData\Local" *

                          aswyg.exe trouvé !
                          Copie aswyg.exe réalisée avec succès !
                          aswyg.exe supprimé !

                          aswyg.dat trouvé !
                          Copie aswyg.dat réalisée avec succès !
                          aswyg.dat supprimé !

                          aswyg_navps.dat trouvé !
                          Copie aswyg_navps.dat réalisée avec succès !
                          aswyg_navps.dat supprimé !

                          * Suppression dans "C:\Users\IUSR_N~1\AppData\Local" *

                          *** Suppression dossiers dans "C:\Windows" ***

                          *** Suppression dossiers dans "C:\Program Files" ***

                          *** Suppression dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

                          *** Suppression dossiers dans "c:\progra~2\micros~1\windows\startm~1" ***

                          *** Suppression dossiers dans "C:\ProgramData" ***

                          *** Suppression dossiers dans c:\users\jessie\appdata\roaming\micros~1\windows\startm~1\programs ***

                          *** Suppression dossiers dans "C:\Users\IUSR_N~1\appdata\roaming\micros~1\windows\startm~1\programs" ***

                          *** Suppression dossiers dans "C:\Users\jessie\AppData\Local\virtualstore\Program Files" ***

                          *** Suppression dossiers dans "C:\Users\jessie\AppData\Local" ***

                          *** Suppression dossiers dans "C:\Users\IUSR_N~1\AppData\Local" ***

                          *** Suppression dossiers dans "C:\Users\jessie\AppData\Roaming" ***

                          *** Suppression dossiers dans "C:\Users\IUSR_N~1\appdata\roaming" ***

                          *** Suppression fichiers ***

                          *** Suppression fichiers temporaires ***

                          Nettoyage contenu C:\Windows\Temp effectué !
                          Nettoyage contenu C:\Users\jessie\AppData\Local\Temp effectué !

                          *** Traitement Recherche complémentaire ***
                          (Recherche fichiers spécifiques)

                          1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

                          2)Recherche, création sauvegardes et suppression Heuristique :

                          * Dans "C:\Windows\system32" *

                          * Dans "C:\Users\jessie\AppData\Local\Microsoft" *

                          * Dans "C:\Users\jessie\AppData\Local\virtualstore\windows\system32" *

                          * Dans "C:\Users\jessie\AppData\Local" *

                          * Dans "C:\Users\IUSR_N~1\AppData\Local" *

                          *** Sauvegarde du Registre vers dossier Safebackup ***

                          sauvegarde du Registre réalisée avec succès !

                          *** Nettoyage Registre ***

                          Nettoyage Registre Ok

                          *** Certificats ***

                          Certificat Egroup absent !
                          Certificat Electronic-Group absent !
                          Certificat Montorgueil absent !
                          Certificat OOO-Favorit absent !
                          Certificat Sunny-Day-Design-Ltdt absent !

                          *** Recherche autres dossiers et fichiers connus ***

                          *** Nettoyage terminé le 03/04/2009 à 9:16:45,83 ***

                          LE RAPPORT AVEC TOOLBAR EN OPTION 1 :

                          -----------\\ ToolBar S&D 1.2.8 XP/Vista

                          Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
                          X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) D CPU 2.80GHz )
                          BIOS : Phoenix - AwardBIOS v6.00PG
                          USER : jessie ( Administrator )
                          BOOT : Normal boot
                          C:\ (Local Disk) - NTFS - Total:227 Go (Free:86 Go)
                          D:\ (Local Disk) - NTFS - Total:5 Go (Free:0 Go)
                          E:\ (CD or DVD)
                          F:\ (USB)
                          H:\ (USB)
                          I:\ (USB)
                          J:\ (USB)

                          "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
                          Option : [1] ( 03/04/2009|10:28 )

                          [ UAC => 1 ]

                          -----------\\ Recherche de Fichiers / Dossiers ...

                          -----------\\ [..\Internet Explorer\Main]

                          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                          "Local Page"="C:\\Windows\\system32\\blank.htm"
                          "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                          "Start page"="https://www.google.fr/?gws_rd=ssl"
                          "Url"="http://www.microsoft.com/athome/community/rss.xml"
                          "Url"="http://rss.msn.com/en-us/?feedoutput=rss&ocid=iehrs&unsub=true"
                          "Url"="http://www.microsoft.com/atwork/community/rss.xml"

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                          "Start Page"="https://www.msn.com/fr-fr/"
                          "Default_Page_URL"="https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF"
                          "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                          "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                          "Local Page"="C:\\Windows\\System32\\blank.htm"

                          --------------------\\ Recherche d'autres infections

                          Aucune autre infection trouvée !

                          [ UAC => 1 ]

                          1 - "C:\ToolBar SD\TB_1.txt" - 02/04/2009|17:19 - Option : [1]
                          2 - "C:\ToolBar SD\TB_2.txt" - 02/04/2009|17:23 - Option : [2]
                          3 - "C:\ToolBar SD\TB_3.txt" - 03/04/2009|10:28 - Option : [1]

                          -----------\\ Fin du rapport a 10:28:54,42

                          le rapport avec toolbar en option 2 :

                          -----------\\ ToolBar S&D 1.2.8 XP/Vista

                          Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
                          X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) D CPU 2.80GHz )
                          BIOS : Phoenix - AwardBIOS v6.00PG
                          USER : jessie ( Administrator )
                          BOOT : Normal boot
                          C:\ (Local Disk) - NTFS - Total:227 Go (Free:86 Go)
                          D:\ (Local Disk) - NTFS - Total:5 Go (Free:0 Go)
                          E:\ (CD or DVD)
                          F:\ (USB)
                          H:\ (USB)
                          I:\ (USB)
                          J:\ (USB)

                          "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
                          Option : [2] ( 03/04/2009|10:30 )

                          [ UAC => 1 ]

                          -----------\\ Recherche de Fichiers / Dossiers ...

                          -----------\\ [..\Internet Explorer\Main]

                          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                          "Local Page"="C:\\Windows\\system32\\blank.htm"
                          "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                          "Start page"="https://www.google.fr/?gws_rd=ssl"
                          "Url"="http://www.microsoft.com/athome/community/rss.xml"
                          "Url"="http://rss.msn.com/en-us/?feedoutput=rss&ocid=iehrs&unsub=true"
                          "Url"="http://www.microsoft.com/atwork/community/rss.xml"

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                          "Start Page"="https://www.msn.com/fr-fr/"
                          "Default_Page_URL"="https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF"
                          "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                          "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                          "Local Page"="C:\\Windows\\System32\\blank.htm"

                          --------------------\\ Recherche d'autres infections

                          Aucune autre infection trouvée !

                          [ UAC => 1 ]

                          1 - "C:\ToolBar SD\TB_1.txt" - 02/04/2009|17:19 - Option : [1]
                          2 - "C:\ToolBar SD\TB_2.txt" - 02/04/2009|17:23 - Option : [2]
                          3 - "C:\ToolBar SD\TB_3.txt" - 03/04/2009|10:28 - Option : [1]
                          4 - "C:\ToolBar SD\TB_4.txt" - 03/04/2009|10:30 - Option : [2]

                          -----------\\ Fin du rapport a 10:30:48,60
                          1. refais un rapport hijack , c est etrange que toolbar n ait rien repere.
                            1. coucou,

                              j'ai refait un rapport hijackthis :

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 11:52:55, on 02/04/2009
                              Platform: Windows Vista SP1 (WinNT 6.00.1905)
                              MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                              Boot mode: Normal

                              Running processes:
                              C:\Windows\system32\Dwm.exe
                              C:\Windows\system32\taskeng.exe
                              C:\Program Files\iTunes\iTunesHelper.exe
                              C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                              C:\Windows\ehome\ehtray.exe
                              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                              C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
                              C:\Program Files\Windows Media Player\wmpnscfg.exe
                              C:\Users\jessie\AppData\Local\aswyg.exe
                              C:\Windows\System32\mobsync.exe
                              C:\Windows\ehome\ehmsas.exe
                              C:\Windows\system32\conime.exe
                              C:\Windows\system32\Taskmgr.exe
                              C:\Windows\explorer.exe
                              C:\Program Files\Mozilla Firefox\firefox.exe
                              C:\Windows\system32\cmd.exe
                              C:\Program Files\Navilog1\catchme.exe
                              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://lo.st
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                              R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
                              O1 - Hosts: ::1 localhost
                              O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
                              O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                              O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
                              O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
                              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                              O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
                              O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
                              O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
                              O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
                              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                              O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
                              O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                              O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
                              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                              O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
                              O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                              O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                              O4 - HKCU\..\Run: [aswyg] "c:\users\jessie\appdata\local\aswyg.exe" aswyg
                              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                              O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
                              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
                              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                              O13 - Gopher Prefix:
                              O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
                              O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                              O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                              O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
                              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                              O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
                              O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
                              O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                              O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                              O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                              O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
                              O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                              O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
                              O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe
                              O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                              O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
                              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                              O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
                              O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
                              O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
                              O23 - Service: stllssvr - Unknown owner - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)
                              1. elles sont mise a jour lorsque tu telecharges la version de toolbar , a priori il ne la reconnait pas ton infection.

                                passe cela :
                                passe cet antimalware, fait comme indique
                                Telecharges malwaresbytes antimalwares(MBAM) : egalement tres util sur pb de pub mais pas tous malheureusement

                                Malwarebytes Anti-Malware: http://www.malwarebytes.org/mbam/program/mbam-setup.exe

                                Tutoriel Malwarebytes Anti-Malware: https://forum.pcastuces.com/malwarebytes_antimalwares___tutoriel-f31s3.htm
                                fais comme indique,mise a jour , scan complet en mode sans echec et les rapports.
                                COLLE LE RAPPORT APRES SUPPRESSION MERCI.

                                garde le et lance un scan tout les mois comme indique.

                                si tu as ad aware tu peux desinstalle car il ne reconnait plus grand chose.

                                ensuite refais un rapport hijack . merci .
                                1. Salut,

                                  je remercie pour tous et aussi le site car sans vous on aurait pas d'autre choix que d'emmener le l'U.C. et on perderez énormément de choses qui nous sont précieuses alors un grand merci.

                                  je t'envoie le rapport de MALWAREBYTES :

                                  Malwarebytes' Anti-Malware 1.35
                                  Version de la base de données: 1939
                                  Windows 6.0.6001 Service Pack 1

                                  04/04/2009 16:07:05
                                  mbam-log-2009-04-04 (16-07-05).txt

                                  Type de recherche: Examen complet (C:\|D:\|)
                                  Eléments examinés: 184041
                                  Temps écoulé: 36 minute(s), 29 second(s)

                                  Processus mémoire infecté(s): 0
                                  Module(s) mémoire infecté(s): 0
                                  Clé(s) du Registre infectée(s): 1
                                  Valeur(s) du Registre infectée(s): 0
                                  Elément(s) de données du Registre infecté(s): 0
                                  Dossier(s) infecté(s): 0
                                  Fichier(s) infecté(s): 0

                                  Processus mémoire infecté(s):
                                  (Aucun élément nuisible détecté)

                                  Module(s) mémoire infecté(s):
                                  (Aucun élément nuisible détecté)

                                  Clé(s) du Registre infectée(s):
                                  HKEY_LOCAL_MACHINE\SOFTWARE\EoRezo (Rogue.Eorezo) -> Quarantined and deleted successfully.

                                  Valeur(s) du Registre infectée(s):
                                  (Aucun élément nuisible détecté)

                                  Elément(s) de données du Registre infecté(s):
                                  (Aucun élément nuisible détecté)

                                  Dossier(s) infecté(s):
                                  (Aucun élément nuisible détecté)

                                  Fichier(s) infecté(s):
                                  (Aucun élément nuisible détecté)

                                  le rapport hijackthis :

                                  Logfile of Trend Micro HijackThis v2.0.2
                                  Scan saved at 11:52:55, on 02/04/2009
                                  Platform: Windows Vista SP1 (WinNT 6.00.1905)
                                  MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                                  Boot mode: Normal

                                  Running processes:
                                  C:\Windows\system32\Dwm.exe
                                  C:\Windows\system32\taskeng.exe
                                  C:\Program Files\iTunes\iTunesHelper.exe
                                  C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                                  C:\Windows\ehome\ehtray.exe
                                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                  C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
                                  C:\Program Files\Windows Media Player\wmpnscfg.exe
                                  C:\Users\jessie\AppData\Local\aswyg.exe
                                  C:\Windows\System32\mobsync.exe
                                  C:\Windows\ehome\ehmsas.exe
                                  C:\Windows\system32\conime.exe
                                  C:\Windows\system32\Taskmgr.exe
                                  C:\Windows\explorer.exe
                                  C:\Program Files\Mozilla Firefox\firefox.exe
                                  C:\Windows\system32\cmd.exe
                                  C:\Program Files\Navilog1\catchme.exe
                                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://lo.st
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                  R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
                                  O1 - Hosts: ::1 localhost
                                  O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
                                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                  O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
                                  O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
                                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                  O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
                                  O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
                                  O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
                                  O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
                                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                  O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
                                  O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                  O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
                                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                                  O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
                                  O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                                  O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                  O4 - HKCU\..\Run: [aswyg] "c:\users\jessie\appdata\local\aswyg.exe" aswyg
                                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                  O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
                                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
                                  O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                                  O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                                  O13 - Gopher Prefix:
                                  O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
                                  O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                                  O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                                  O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
                                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                                  O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
                                  O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
                                  O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                  O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                  O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                                  O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
                                  O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                                  O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
                                  O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe
                                  O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                  O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
                                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                  O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
                                  O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
                                  O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
                                  O23 - Service: stllssvr - Unknown owner - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)
                                  1. pas reconnu(fait attention tu m as colle ton rapport hijack du 2 avril )

                                    on va passer alors a autre chose mais la je ne sais si il est prevu pour le reconnaitre.
                                    pour voir télécharge combofix (par sUBs) ici :

                                    http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                                    et enregistre le sur le bureau.

                                    déconnecte toi d'internet et ferme toutes tes applications.

                                    désactive tes protections (antivirus, parefeu, garde en temps réel de l'antispyware)

                                    double-clique sur combofix.exe et suis les instructions

                                    à la fin, il va produire un rapport C:\ComboFix.txt

                                    réactive ton parefeu, ton antivirus, la garde de ton antispyware

                                    copie/colle le rapport C:\ComboFix.txt dans ta prochaine réponse.

                                    Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi.

                                    Tu as un tutoriel complet ici :

                                    https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

                                    1. salut

                                      j'ai refait un rapport hijackthis le premier que j'ai fait ce soir m'a remit la date du 2 après je l'ai éxécuté en tant qu'administrateur et là il m'a mis la bonne date. je te tiens au courant pour le reste.

                                      Logfile of Trend Micro HijackThis v2.0.2
                                      Scan saved at 21:31:19, on 05/04/2009
                                      Platform: Windows Vista SP1 (WinNT 6.00.1905)
                                      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                                      Boot mode: Normal

                                      Running processes:
                                      C:\Windows\system32\taskeng.exe
                                      C:\Windows\system32\Dwm.exe
                                      C:\Windows\Explorer.EXE
                                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                                      C:\Windows\ehome\ehtray.exe
                                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                      C:\Program Files\TomTom HOME 2\HOMERunner.exe
                                      C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
                                      C:\Program Files\Windows Media Player\wmpnscfg.exe
                                      C:\Windows\ehome\ehmsas.exe
                                      C:\Windows\System32\mobsync.exe
                                      C:\Windows\system32\conime.exe
                                      C:\Program Files\Mozilla Firefox\firefox.exe
                                      C:\Program Files\Internet Explorer\IELowutil.exe
                                      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/...
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                      R3 - Default URLSearchHook is missing
                                      O1 - Hosts: ::1 localhost
                                      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                      O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
                                      O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
                                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                                      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                      O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
                                      O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
                                      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                                      O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
                                      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                      O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
                                      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                                      O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
                                      O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                                      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                                      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
                                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
                                      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                                      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                                      O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
                                      O13 - Gopher Prefix:
                                      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                                      O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                                      O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
                                      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                                      O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
                                      O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
                                      O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                      O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                      O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                                      O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
                                      O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                                      O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
                                      O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe
                                      O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
                                      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                      O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
                                      O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
                                      O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
                                      O23 - Service: stllssvr - Unknown owner - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)
                                      1. coucou

                                        c'est bon j'ai terminé avec Combofix, par contre je n'ai pas réussi à désactiver l'antispyware pour le pare feu et l'antivirus ok.

                                        voici le rapport :

                                        ComboFix 09-04-04.01 - jessie 2009-04-05 21:43:41.1 - NTFSx86
                                        Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.1022.361 [GMT 2:00]
                                        Lancé depuis: c:\users\jessie\Downloads\ComboFix.exe
                                        * Un nouveau point de restauration a été créé
                                        .

                                        (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                                        .

                                        c:\windows\patch.exe
                                        c:\windows\system32\winspool.dll

                                        .
                                        ((((((((((((((((((((((((((((( Fichiers créés du 2009-03-05 au 2009-04-05 ))))))))))))))))))))))))))))))))))))
                                        .

                                        2009-04-05 21:36 . 2006-03-03 00:42 73,728 --a------ C:\pv.exe
                                        2009-04-04 13:12 . 2009-04-04 13:12 <REP> d-------- c:\users\jessie\AppData\Roaming\Malwarebytes
                                        2009-04-04 13:12 . 2009-04-04 13:12 <REP> d-------- c:\users\All Users\Malwarebytes
                                        2009-04-04 13:12 . 2009-04-04 13:12 <REP> d-------- c:\programdata\Malwarebytes
                                        2009-04-04 13:12 . 2009-04-04 13:12 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
                                        2009-04-04 13:12 . 2009-03-26 16:49 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
                                        2009-04-04 13:12 . 2009-03-26 16:49 15,504 --a------ c:\windows\System32\drivers\mbam.sys
                                        2009-04-03 11:17 . 2009-04-03 14:51 <REP> d-------- c:\users\jessie\Contacts
                                        2009-04-02 16:53 . 2009-04-02 16:53 <REP> d-------- c:\users\All Users\Avira
                                        2009-04-02 16:53 . 2009-04-02 16:53 <REP> d-------- c:\programdata\Avira
                                        2009-04-02 16:53 . 2009-04-02 16:53 <REP> d-------- c:\program files\Avira
                                        2009-04-02 12:01 . 2009-04-03 10:30 <REP> d-------- C:\ToolBar SD
                                        2009-04-02 10:25 . 2009-04-03 10:17 <REP> d-------- c:\program files\Navilog1
                                        2009-04-02 10:18 . 2009-04-02 10:18 <REP> d-------- c:\program files\Trend Micro
                                        2009-03-17 14:57 . 2009-03-17 14:58 <REP> d-------- c:\users\All Users\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
                                        2009-03-17 14:57 . 2009-03-17 14:58 <REP> d-------- c:\programdata\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
                                        2009-03-12 10:22 . 2008-12-16 05:29 8,147,456 --a------ c:\windows\System32\wmploc.DLL
                                        2009-03-12 10:22 . 2008-12-16 07:31 7,680 --a------ c:\windows\System32\spwmp.dll
                                        2009-03-12 10:22 . 2008-12-16 07:31 4,096 --a------ c:\windows\System32\msdxm.ocx
                                        2009-03-12 10:22 . 2008-12-16 07:31 4,096 --a------ c:\windows\System32\dxmasf.dll
                                        2009-03-12 10:21 . 2009-02-09 05:10 2,033,152 --a------ c:\windows\System32\win32k.sys
                                        2009-03-12 10:21 . 2008-11-27 06:43 268,288 --a------ c:\windows\System32\schannel.dll

                                        .
                                        (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                                        .
                                        2009-04-02 17:36 --------- d-----w c:\program files\Common Files\Apple
                                        2009-03-29 18:34 --------- d-----w c:\users\jessie\AppData\Roaming\Canon
                                        2009-03-17 12:01 --------- d-----w c:\program files\Safari
                                        2009-03-12 19:31 --------- d-----w c:\program files\Windows Mail
                                        2009-03-08 11:34 914,944 ----a-w c:\windows\System32\wininet.dll
                                        2009-03-08 11:34 43,008 ----a-w c:\windows\System32\licmgr10.dll
                                        2009-03-08 11:33 420,352 ----a-w c:\windows\System32\vbscript.dll
                                        2009-03-08 11:33 18,944 ----a-w c:\windows\System32\corpol.dll
                                        2009-03-08 11:33 132,608 ----a-w c:\windows\System32\ieUnatt.exe
                                        2009-03-08 11:33 109,568 ----a-w c:\windows\System32\PDMSetup.exe
                                        2009-03-08 11:33 109,056 ----a-w c:\windows\System32\iesysprep.dll
                                        2009-03-08 11:33 107,520 ----a-w c:\windows\System32\RegisterIEPKEYs.exe
                                        2009-03-08 11:33 107,008 ----a-w c:\windows\System32\SetIEInstalledDate.exe
                                        2009-03-08 11:33 103,936 ----a-w c:\windows\System32\SetDepNx.exe
                                        2009-03-08 11:32 72,704 ----a-w c:\windows\System32\admparse.dll
                                        2009-03-08 11:32 71,680 ----a-w c:\windows\System32\iesetup.dll
                                        2009-03-08 11:32 66,560 ----a-w c:\windows\System32\wextract.exe
                                        2009-03-08 11:32 169,472 ----a-w c:\windows\System32\iexpress.exe
                                        2009-03-08 11:31 48,128 ----a-w c:\windows\System32\mshtmler.dll
                                        2009-03-08 11:31 45,568 ----a-w c:\windows\System32\mshta.exe
                                        2009-03-08 11:31 34,816 ----a-w c:\windows\System32\imgutil.dll
                                        2009-03-08 11:22 156,160 ----a-w c:\windows\System32\msls31.dll
                                        2009-02-18 22:40 --------- d-----w c:\program files\Messenger Plus! Live
                                        2008-07-21 17:35 174 --sha-w c:\program files\desktop.ini
                                        2007-04-16 21:40 0 ----a-w c:\users\jessie\AppData\Roaming\wklnhst.dat
                                        2008-11-01 20:10 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
                                        2008-11-01 20:10 32,768 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
                                        2008-11-01 20:10 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
                                        2007-04-16 19:34 22 --sha-w c:\windows\SMINST\HPCD.sys
                                        .

                                        ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                                        .
                                        .
                                        *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                                        REGEDIT4

                                        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                        "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
                                        "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2005-02-16 221184]
                                        "MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
                                        "TomTomHOME.exe"="c:\program files\TomTom HOME 2\HOMERunner.exe" [2008-12-09 234856]
                                        "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-01-07 1830128]
                                        "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

                                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                        "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-03-06 177472]
                                        "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
                                        "avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]

                                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
                                        "Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-24 44136]

                                        c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
                                        Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-01-21 65588]

                                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                                        "FilterAdministratorToken"= 1 (0x1)
                                        "EnableUIADesktopToggle"= 0 (0x0)

                                        [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
                                        "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

                                        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
                                        2009-01-07 19:45 356352 c:\program files\SUPERAntiSpyware\SASWINLO.DLL

                                        [HKEY_LOCAL_MACHINE\software\microsoft\security center]
                                        "UacDisableNotify"=dword:00000001
                                        "InternetSettingsDisableNotify"=dword:00000001
                                        "AutoUpdateDisableNotify"=dword:00000001

                                        [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
                                        "DisableMonitoring"=dword:00000001

                                        [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
                                        "DisableMonitoring"=dword:00000001

                                        [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
                                        "DisableMonitoring"=dword:00000001

                                        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
                                        "DefaultOutboundAction"= 0 (0x0)
                                        "DefaultInboundAction"= 1 (0x1)

                                        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
                                        "{62E80F4D-DF00-4043-856E-CB77E58D1927}"= UDP:c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
                                        "{500D6D5D-6DD3-4C70-A430-E82D159C03A9}"= TCP:c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
                                        "{953F1148-80F9-4907-8F7B-4AC5218CA93E}"= UDP:c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel(R) Viiv(TM) Media Server
                                        "{836E7D86-3D00-4F23-90F4-6D0031C2D9B1}"= TCP:c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel(R) Viiv(TM) Media Server
                                        "{4225A4FF-5D71-459B-8479-CFA42F2CBBF9}"= UDP:c:\program files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel(R) Remoting Service
                                        "{91690AAA-DDBB-48E8-A7D2-0128B9F8915E}"= TCP:c:\program files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel(R) Remoting Service
                                        "{BF756CE4-8E31-45E6-8937-C8D46089894F}"= TCP:9442:127.0.0.1:Intel(R) Viiv(TM) Media Server Discovery
                                        "{15566C52-DB77-46DD-884F-5387CDFC74FA}"= TCP:1900:LocalSubnet:LocalSubnet:Intel(R) Viiv(TM) Media Server UPnP Discovery
                                        "{2BB38C4C-F9DF-4F3B-8C0C-21DF2EDD39C1}"= Disabled:UDP:c:\program files\Skype\Phone\Skype.exe:Skype
                                        "{C0AB2429-613C-4BFD-BACC-E664426EA563}"= Disabled:TCP:c:\program files\Skype\Phone\Skype.exe:Skype
                                        "{90B4C1EE-11EA-41FE-BFAC-BF3C00F9C896}"= UDP:25766:BitComet 25766 TCP
                                        "{9331586F-067B-4767-91D9-F5A1ED3113BF}"= TCP:25766:BitComet 25766 UDP
                                        "{C75C3F64-0771-459D-A505-79E78750F06F}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
                                        "{0A9E6518-1110-4BED-97D9-9B2F6F8AD8B2}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
                                        "{FDDACF81-728B-44BF-83F0-85855919999D}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
                                        "{EF72784B-8CE7-47CA-B1B1-328D0DE21BE9}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
                                        "{DA9365B4-B5DB-4652-95B2-908C66BECD5A}"= UDP:c:\program files\Skype\Phone\Skype.exe:Skype
                                        "{2FEEC2F9-7B7B-4C35-93FE-E33C2AAA4E84}"= TCP:c:\program files\Skype\Phone\Skype.exe:Skype
                                        "TCP Query User{FF54DA29-C078-44D9-BF04-884B4193906B}c:\\program files\\azureus\\azureus.exe"= UDP:c:\program files\azureus\azureus.exe:Azureus
                                        "UDP Query User{C5BE296A-6FC5-4411-A740-20B88BEC2F83}c:\\program files\\azureus\\azureus.exe"= TCP:c:\program files\azureus\azureus.exe:Azureus

                                        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
                                        "DefaultOutboundAction"= 0 (0x0)
                                        "DefaultInboundAction"= 1 (0x1)

                                        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
                                        "EnableFirewall"= 0 (0x0)

                                        R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2008-05-28 8944]
                                        R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2008-05-28 55024]
                                        R2 DQLWinService;DQLWinService;c:\program files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [2006-09-03 208896]
                                        R3 3xHybrid;ASUSTek SAA713x PCI Card;c:\windows\System32\drivers\3xHybrid.sys [2007-01-12 2807936]
                                        R3 APL531;Hercules Blog Webcam;c:\windows\System32\drivers\BLvid.sys [2007-11-07 275072]
                                        R3 camfilt;camfilt;c:\windows\System32\drivers\camfilt.sys [2008-02-10 24192]
                                        R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-05-28 7408]
                                        S2 IntelDHSvcConf;Intel DH Service;c:\program files\Intel\IntelDH\Intel Media Server\tools\IntelDHSvcConf.exe [2006-05-10 29696]
                                        S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\System32\drivers\ASPI32.SYS [2008-06-14 84832]
                                        S3 DCamUSBPremier;USB Video Camera;c:\windows\System32\drivers\MPIXVID.SYS [2007-04-17 81921]
                                        S3 fbxusb;Carte réseau virtuelle FreeBox USB;c:\windows\System32\drivers\fbxusb32.sys [2007-05-29 21344]

                                        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                                        WindowsMobile REG_MULTI_SZ wcescomm rapimgr
                                        LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr

                                        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{973d5366-c349-11dc-80cb-001a92413c58}]
                                        \shell\AutoRun\command - G:\InstallTomTomHOME.exe

                                        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b8218725-69c1-11dc-b7a4-001a92413c58}]
                                        \shell\AutoRun\command - RavMon.exe
                                        \shell\explore\Command - RavMon.exe -e
                                        \shell\open\Command - RavMon.exe

                                        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d3b9ca01-4c31-11dc-9022-001a92413c58}]
                                        \shell\AutoRun\command - RavMon.exe
                                        \shell\explore\Command - RavMon.exe -e
                                        \shell\open\Command - RavMon.exe

                                        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d8e4e8f1-e1be-11dc-a3f3-001a92413c58}]
                                        \shell\AutoRun\command - G:\InstallTomTomHOME.exe

                                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
                                        "c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
                                        .
                                        Contenu du dossier 'Tâches planifiées'

                                        2009-04-05 c:\windows\Tasks\User_Feed_Synchronization-{52A80A35-9530-4AC4-84F9-2C230C46085C}.job
                                        - c:\windows\system32\msfeedssync.exe [2009-03-08 13:31]
                                        .
                                        .
                                        ------- Examen supplémentaire -------
                                        .
                                        uStart page = hxxp://www.google.fr/
                                        mWindow Title =
                                        DPF: Microsoft XML Parser for Java - file:///C:/Windows/Java/classes/xmldso.cab
                                        DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                                        FF - ProfilePath - c:\users\jessie\AppData\Roaming\Mozilla\Firefox\Profiles\h9yc8vfs.default\
                                        FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
                                        FF - prefs.js: browser.search.selectedEngine - Live Search
                                        FF - prefs.js: browser.startup.homepage - hxxp://fr.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:fr:official
                                        FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?mkt=fr-fr&FORM=MIMWA1&q=
                                        .

                                        **************************************************************************

                                        catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                        Rootkit scan 2009-04-05 21:49:13
                                        Windows 6.0.6001 Service Pack 1 NTFS

                                        Recherche de processus cachés ...

                                        Recherche d'éléments en démarrage automatique cachés ...

                                        Recherche de fichiers cachés ...

                                        Scan terminé avec succès
                                        Fichiers cachés: 0

                                        **************************************************************************
                                        .
                                        Heure de fin: 2009-04-05 21:52:48
                                        ComboFix-quarantined-files.txt 2009-04-05 19:52:45

                                        Avant-CF: 94 775 873 536 octets libres
                                        Après-CF: 94,781,333,504 octets libres

                                        194 --- E O F --- 2009-04-03 18:54:20
                                        1. coucou totobetourne,

                                          mon pc est il débarassé des infections? ou en a t-il encore?

                                          merci
                                          • 1
                                          • 2