Avast

Bonjour,
J'ai désinstallé avast avec revo unistaller, mais il s'avère qu'il est toujours présent. Il n'est plus détecté sur ma liste d'ajout et suppression de programme, mais il est toujours en fonction, car j'ai encore ses alertes.

--
Il n'ya rien de tel que de comprendre qu'on est tous prisonniers des machines...
Configuration: Windows XP SP2
Mozilla Firefox 3.0.9

16 réponses

  1. AI-je besoin de passer en mode sans echec pour ça?
    Parce que actu, lorsque je l'ouvre y'a un message qui après traduction me dit que la protection résistante d'avast est activée, il est donc impossible de compléter l'opération.
    0
    1. regardes dans msconfig et onglet services pour voir s'il y a des services encore activés
      0
  2. Oué, ya des services d'avast en cours, mais il m'est impossible de les désactiver. On me dit que une erreur a été renvoyé, et qu'il est pas possible de désactivé les services sélectionnés
    0
    1. As tu essayé d'aller dans le gestionnaire de tache (Ctrl, Alt, Suppr) et de terminer les processus d'avast ?
      0
      1. Il refuse de terminer (l'opération n'a pas pu être terminer. Accès refusé)
        0
        1. vas dans poste de travail et programmes et regardes s'il reste un dossier sur avast
          essayes en mode sans échec
          0
      2. Bon alors telecharge Hijackthis

        Installe le sur ton bureau

        Une fois installé lance le en cliquant sur l'icone qui est apparu après l'installation

        Une fois hijackthis lancé clic sur "Do a system scan and save the logfile"

        Post le rapport ainsi généré dans ta prochaine réponse
        0
        1. Oui ou alors fait comme nathandre le dit , en mode sans échec
          0
          1. peut-etre qu'un RSIT aurai été mieux pour voir où il rest des éléments et peut-etre faire OTMovelt
            0
        2. J'avais oublié de signifier, le dossier Avast est toujours là dans program files. Et il a la plupart de ses composantes qui y sont. Je fait le hijack voir ce que c va donner
          0
          1. je les telecharge en meme temp au cas ou je devrais les utilisé
            0
            1. Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

              -> http://images.malwareremoval.com/random/RSIT.exe

              ! Déconnecte toi et ferme toutes tes applications en cours !

              Double-clique sur " RSIT.exe " pour le lancer .

              -> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

              * Devant l'option "List files/folders created ..." , tu choisis : 2 months

              * clique ensuite sur " Continue " pour lancer l'analyse ...

              -> laisse faire le scan et ne touche pas au PC ...

              Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

              Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

              Important : poste un rapport, puis l'autre dans la réponse suivante
              Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum

              ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )-
              --------------------------------------------------------------------------------------------------------------------------
              0
          2. Le rapport log

            Logfile of random's system information tool 1.06 (written by random/random)
            Run by alpha service at 2009-05-21 16:59:20
            Microsoft Windows XP Professionnel Service Pack 2
            System drive C: has 7 GB (34%) free of 20 GB
            Total RAM: 254 MB (17% free)

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 17:01:32, on 21/05/2009
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\csrss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\SuperCopier2\SuperCopier2.exe
            C:\Program Files\Messenger\msmsgs.exe
            C:\Documents and Settings\alpha service\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
            C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            C:\WINDOWS\system32\wscntfy.exe
            C:\WINDOWS\System32\alg.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\Program Files\4U Computing\Download YouTube Video\DownloadYouTubeVideo.exe
            C:\Documents and Settings\alpha service\Bureau\RSIT.exe
            C:\WINDOWS\system32\wbem\wmiprvse.exe
            C:\Program Files\trend micro\alpha service.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.imesh.com/sidebar.html?src=ssb
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.imesh.com/fr/
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
            O2 - BHO: UrlHelper Class - {474597C5-AB09-49d6-A4D5-2E8D7341384E} - C:\Program Files\iMesh Applications\iMesh MediaBar\iMeshIEHelper.dll
            O3 - Toolbar: iMesh MediaBar - {B7D3E479-CC68-42B5-A338-938ECE35F419} - C:\Program Files\iMesh Applications\iMesh MediaBar\iMeshMediaBar.dll
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [PowerDirector] C:\WINDOWS\Temp\TPDIR\setup.exe
            O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
            O4 - HKCU\..\Run: [Software Informer] "C:\Program Files\Software Informer\softinfo.exe" -autorun
            O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
            O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\alpha service\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
            O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
            O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
            O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O17 - HKLM\System\CCS\Services\Tcpip\..\{89C6CEAB-170D-41F9-A6BF-90FC336C94E8}: NameServer = 213.136.96.2 213.136.96.37
            O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
            O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            0
            1. regardes ce qu'il reste
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              "avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-02-05 81000]
              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
              "avast! Web Scanner"=3
              "avast! Mail Scanner"=3
              "avast! Antivirus"=2
              "aswUpdSv"=2
              R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2009-02-05 114768]
              R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2009-02-05 51376]
              R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2009-02-05 94032]
              S2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-02-05 138680]
              S3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-02-05 254040]
              S3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-02-05 352920]

              en plus j'ai vu une infection dans RSIT

              Télécharge et installe UsbFix de C_XX, Chimay8 & Chiquitine29
              http://sd-1.archive-host.com/membres/up/127028005715545653/UsbFix.exe

              Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d avoir été infectés sans les ouvrir

              # Double clic sur le raccourci UsbFix présent sur ton bureau .

              # Choisi l option 1 ( Recherche )

              # Laisse travailler l outil.

              # Ensuite post le rapport UsbFix.txt qui apparaitra.

              # Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

              ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

              # Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
              Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
              Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
              0
          3. Et l'info

            info.txt logfile of random's system information tool 1.06 2009-05-21 17:01:38

            ======Uninstall list======

            -->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
            -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
            4U Download YouTube Video (version 2.3.2)-->"C:\Program Files\4U Computing\Download YouTube Video\unins000.exe"
            7-Zip 4.65-->"C:\Program Files\7-Zip\Uninstall.exe"
            Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
            Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
            Adobe Photoshop 7.0.1-->C:\WINDOWS\ISUN040C.EXE -f"C:\Program Files\Adobe\Photoshop 7.0\Uninst.isu" -c"C:\Program Files\Adobe\Photoshop 7.0\Uninst.dll"
            Apple Mobile Device Support-->MsiExec.exe /I{A43B2A2F-1DB5-47F9-A608-F11A4835D7CB}
            Apple Software Update-->MsiExec.exe /I{74EC78BC-B379-4E29-9006-8F161DCAABA6}
            Applian FLV Player-->"C:\WINDOWS\Applian FLV Player\uninstall.exe" "/U:C:\Program Files\FLV Player\Uninstall\uninstall.xml"
            Bluesoleil2.6.0.8 Release 070517-->MsiExec.exe /X{438BB9B4-65FE-4626-91D9-A8F57B18001D}
            Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
            HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
            Hotfix for Windows XP (KB926239)-->"C:\WINDOWS\$NtUninstallKB926239$\spuninst\spuninst.exe"
            iMesh-->C:\Program Files\iMesh Applications\iMesh\UninstallSurvey.exe C:\Program Files\iMesh Applications\iMesh\UnwiseLauncher.exe /A C:\PROGRA~1\IMESHA~1\iMesh\INSTALL.LOG
            Internet Download Manager-->C:\Program Files\Internet Download Manager\Uninstall.exe
            Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
            MediaBar 2.0-->C:\Program Files\iMesh Applications\iMesh MediaBar\Uninstall.exe
            Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
            Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
            Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
            Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
            Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
            Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB944338-v2)-->"C:\WINDOWS\$NtUninstallKB944338-v2$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB958215)-->"C:\WINDOWS\$NtUninstallKB958215$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB960714)-->"C:\WINDOWS\$NtUninstallKB960714$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
            Mozilla Firefox (3.0.10)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
            MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
            Nero 6 Ultra Edition-->C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
            PowerDirector-->"C:\Program Files\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\setup.exe" -l0x000409 /z-uninstall
            QuickTime-->MsiExec.exe /I{95A890AA-B3B1-44B6-9C18-A8F7AB3EE7FC}
            RealPlayer-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
            Revo Uninstaller 1.83-->C:\Program Files\VS Revo Group\Revo Uninstaller\uninst.exe
            SAGEM F@st 800-840-->C:\Program Files\InstallShield Installation Information\{4AE3A0CB-87B0-4F51-BECD-3D1F8DFDD62F}\setup.exe -runfromtemp -l0x040c -removeonly
            SuperCopier2-->"C:\Program Files\SuperCopier2\SC2Uninst.exe"
            Total Video Converter 3.02-->"C:\Program Files\Total Video Converter\unins000.exe"
            VideoLAN VLC media player 0.8.6e-->C:\Program Files\VideoLAN\VLC\uninstall.exe
            Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
            Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
            Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"

            ======Security center information======

            AV: avast! antivirus 4.8.1335 [VPS 000000-0] (disabled) (outdated)

            ======System event log======

            Computer Name: APHA-17ED6DD260
            Event Code: 7036
            Message: Le service Service de la passerelle de la couche Application est entré dans l'état : en cours d'exécution.

            Record Number: 4404
            Source Name: Service Control Manager
            Time Written: 20090411125647.000000+120
            Event Type: Informations
            User:

            Computer Name: APHA-17ED6DD260
            Event Code: 7035
            Message: Un contrôle Démarrer a correctement été envoyé au service Service de la passerelle de la couche Application.

            Record Number: 4403
            Source Name: Service Control Manager
            Time Written: 20090411125647.000000+120
            Event Type: Informations
            User: AUTORITE NT\SYSTEM

            Computer Name: APHA-17ED6DD260
            Event Code: 7036
            Message: Le service Service de découvertes SSDP est entré dans l'état : en cours d'exécution.

            Record Number: 4402
            Source Name: Service Control Manager
            Time Written: 20090411125642.000000+120
            Event Type: Informations
            User:

            Computer Name: APHA-17ED6DD260
            Event Code: 7035
            Message: Un contrôle Démarrer a correctement été envoyé au service Service de découvertes SSDP.

            Record Number: 4401
            Source Name: Service Control Manager
            Time Written: 20090411125638.000000+120
            Event Type: Informations
            User: AUTORITE NT\SYSTEM

            Computer Name: APHA-17ED6DD260
            Event Code: 7036
            Message: Le service NLA (Network Location Awareness) est entré dans l'état : en cours d'exécution.

            Record Number: 4400
            Source Name: Service Control Manager
            Time Written: 20090411125636.000000+120
            Event Type: Informations
            User:

            =====Application event log=====

            Computer Name: APHA-17ED6DD260
            Event Code: 11
            Message: Échec de l'extraction de la liste racine tierce partie depuis le fichier CAB de mise à jour automatique à : <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> avec l'erreur : Un certificat requis n'est pas dans sa période de validité selon la vérification par rapport à l'horloge système en cours ou le tampon daté dans le fichier signé.

            Record Number: 586
            Source Name: crypt32
            Time Written: 20010227001716.000000+060
            Event Type: erreur
            User:

            Computer Name: APHA-17ED6DD260
            Event Code: 11
            Message: Échec de l'extraction de la liste racine tierce partie depuis le fichier CAB de mise à jour automatique à : <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> avec l'erreur : Un certificat requis n'est pas dans sa période de validité selon la vérification par rapport à l'horloge système en cours ou le tampon daté dans le fichier signé.

            Record Number: 585
            Source Name: crypt32
            Time Written: 20010227001716.000000+060
            Event Type: erreur
            User:

            Computer Name: APHA-17ED6DD260
            Event Code: 2
            Message: Récupération de la mise à jour automatique du fichier CAB de la liste racine tierce partie réussie à partir de : <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>

            Record Number: 584
            Source Name: crypt32
            Time Written: 20010227001716.000000+060
            Event Type: Informations
            User:

            Computer Name: APHA-17ED6DD260
            Event Code: 7
            Message: Récupération de la mise à jour automatique du numéro de séquence de la liste racine tierce partie réussie à partir de : <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>

            Record Number: 583
            Source Name: crypt32
            Time Written: 20010227001715.000000+060
            Event Type: Informations
            User:

            Computer Name: APHA-17ED6DD260
            Event Code: 11
            Message: Échec de l'extraction de la liste racine tierce partie depuis le fichier CAB de mise à jour automatique à : <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> avec l'erreur : Un certificat requis n'est pas dans sa période de validité selon la vérification par rapport à l'horloge système en cours ou le tampon daté dans le fichier signé.

            Record Number: 582
            Source Name: crypt32
            Time Written: 20010227001715.000000+060
            Event Type: erreur
            User:

            ======Environment variables======

            "ComSpec"=%SystemRoot%\system32\cmd.exe
            "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
            "windir"=%SystemRoot%
            "FP_NO_HOST_CHECK"=NO
            "OS"=Windows_NT
            "PROCESSOR_ARCHITECTURE"=x86
            "PROCESSOR_LEVEL"=6
            "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 8 Stepping 3, GenuineIntel
            "PROCESSOR_REVISION"=0803
            "NUMBER_OF_PROCESSORS"=1
            "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
            "TEMP"=%SystemRoot%\TEMP
            "TMP"=%SystemRoot%\TEMP
            "CLASSPATH"=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
            "QTJAVA"=C:\Program Files\QuickTime\QTSystem\QTJava.zip

            -----------------EOF-----------------
            0
            1. Et le hijack

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 17:05:29, on 21/05/2009
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\csrss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\WINDOWS\Explorer.EXE
              C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\SuperCopier2\SuperCopier2.exe
              C:\Program Files\Messenger\msmsgs.exe
              C:\Documents and Settings\alpha service\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
              C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              C:\WINDOWS\system32\wscntfy.exe
              C:\WINDOWS\System32\alg.exe
              C:\Program Files\Mozilla Firefox\firefox.exe
              C:\Program Files\4U Computing\Download YouTube Video\DownloadYouTubeVideo.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
              C:\WINDOWS\system32\wbem\wmiprvse.exe

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.imesh.com/sidebar.html?src=ssb
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.imesh.com/fr/
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
              O2 - BHO: UrlHelper Class - {474597C5-AB09-49d6-A4D5-2E8D7341384E} - C:\Program Files\iMesh Applications\iMesh MediaBar\iMeshIEHelper.dll
              O3 - Toolbar: iMesh MediaBar - {B7D3E479-CC68-42B5-A338-938ECE35F419} - C:\Program Files\iMesh Applications\iMesh MediaBar\iMeshMediaBar.dll
              O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
              O4 - HKLM\..\Run: [PowerDirector] C:\WINDOWS\Temp\TPDIR\setup.exe
              O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
              O4 - HKCU\..\Run: [Software Informer] "C:\Program Files\Software Informer\softinfo.exe" -autorun
              O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
              O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\alpha service\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
              O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
              O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
              O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O17 - HKLM\System\CCS\Services\Tcpip\..\{89C6CEAB-170D-41F9-A6BF-90FC336C94E8}: NameServer = 213.136.96.2 213.136.96.37
              O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              0
              1. Relance hijackthis mais cette fois clic sur "Do a system scan only"

                ensuite coches les cases sur la gauche des ces lignes :

                O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

                O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

                O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

                O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

                Puis clic sur "Fix checked" ensuite redémarre ton pc et réessai de supprimer le dossier avast en te servant de l'utilitaire que l'on t'as donné au début
                0
                1. et encore ceci

                  ======Security center information======

                  AV: avast! antivirus 4.8.1335 [VPS 000000-0] (disabled) (outdated)

                  avant de fixer les lignes, je pense qu'il faut désinfecter le pc
                  il faut désactiver les services d'avast avant de fixer les lignes
                  0
              2. Bon nathandre je te laisse lui dire quoi faire sinon on va l'embrouiller LoL
                0
                1. Merci de vous soucier de mon ptit cerveau (mdr)
                  0
                  1. fait d'abord le post 19 USBFix
                    0