Comment désinstaller lelogiciel Spywaresecure

Bonjour,
je voudrais désisntaller sur mon PC portable (WindowsXP) le logiciel "Spyware secure", mais il n'y a pas de programme de désintallation, et il n'apparait pas dans la liste des logiciels du panneau de configuration. Pourriez-vous m'aider ? Merci d'avance.
Je copie-colle au cas où un highjack this report file :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:05:20, on 24/08/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\PROGRA~1\ANTIVI~1\backweb\6588780\Program\SERVIC~1.EXE
C:\Program Files\AntivirusFirewall\Anti-Virus\fsgk32st.exe
C:\Program Files\AntivirusFirewall\backweb\6588780\program\fsbwsys.exe
C:\Program Files\AntivirusFirewall\Anti-Virus\FSGK32.EXE
C:\Program Files\AntivirusFirewall\Common\FSMA32.EXE
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\AntivirusFirewall\Anti-Virus\fssm32.exe
C:\Program Files\AntivirusFirewall\Common\FSMB32.EXE
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AntivirusFirewall\Common\FCH32.EXE
C:\Program Files\AntivirusFirewall\Common\FAMEH32.EXE
C:\Program Files\AntivirusFirewall\Anti-Virus\fsqh.exe
C:\Program Files\AntivirusFirewall\Anti-Virus\fsrw.exe
C:\Program Files\AntivirusFirewall\FWES\Program\fsdfwd.exe
C:\Program Files\AntivirusFirewall\Anti-Virus\fsav32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\System32\hphmon05.exe
C:\PROGRA~1\MESSAG~1\StartMessager.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\AntivirusFirewall\Common\FSM32.EXE
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\PROGRA~1\ANTIVI~1\ANTI-S~1\fsaw.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AntivirusFirewall\FSGUI\fsguidll.exe
C:\Program Files\TRENDnet\TEW-441PC_443PI\TRENDnet.exe
C:\Program Files\AntivirusFirewall\backweb\6588780\Program\fspex.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\PROGRA~1\Wanadoo\Watch.exe
C:\Program Files\Trend Micro\HijackThis\monjack.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www8.hp.com/fr/fr/home.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://french.icrfast.com/index.php?rvs=hompag
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://side.search.ke.voila.fr
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {AEEC3B59-CA98-4EBA-A140-57B94E283583} - C:\PROGRA~1\ORANGE~1\TOOLBA~2.DLL
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: barre d'outils Orange - {D3028143-6145-4318-99D3-3EDCE54A95A9} - C:\Program Files\Orange Toolbar FR\ToolbarContainer234.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [MessagerStarter Wanadoo] C:\PROGRA~1\MESSAG~1\StartMessager.exe Messager Wanadoo
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\AntivirusFirewall\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\AntivirusFirewall\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\AntivirusFirewall\FSGUI\FSSW.EXE" /reboot
O4 - HKLM\..\Run: [News Service] "C:\Program Files\AntivirusFirewall\FSGUI\ispnews.exe"
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Spyware-Secure] C:\Program Files\Spyware-Secure\Spyware-Secure_trial.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Instant Access] C:\WINDOWS\system32\lnaccess.exe /res
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-21-1737973551-2847468568-730773158-1009\..\Run: [RecordNow!]  (User 'Sarah Calas')
O4 - HKUS\S-1-5-21-1737973551-2847468568-730773158-1009\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'Sarah Calas')
O4 - HKUS\S-1-5-21-1737973551-2847468568-730773158-1009\..\Run: [WOOKIT] C:\Program Files\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx (User 'Sarah Calas')
O4 - HKUS\S-1-5-21-1737973551-2847468568-730773158-1009\..\Run: [CarryLaunch] C:\Documents and Settings\Sarah Calas\Application Data\CoSoSys\CarryItEasy\CarryLaunch.exe (User 'Sarah Calas')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: 108Mbps Wireless LAN Adapte.lnk = C:\Program Files\TRENDnet\TEW-441PC_443PI\TRENDnet.exe
O4 - Global Startup: Antivirus Firewall.lnk = C:\Program Files\AntivirusFirewall\backweb\6588780\Program\fspex.exe
O4 - Global Startup: Image Transfer.lnk = ?
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: &Bloquer cette fenêtre publicitaire - C:\Program Files\AntivirusFirewall\Anti-Spyware\blockpopups.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: traduire la page - C:\DOCUME~1\ANDREC~1\LOCALS~1\Temp\cce11D.html
O8 - Extra context menu item: traduire le texte sélectionné - C:\DOCUME~1\ANDREC~1\LOCALS~1\Temp\cce11E.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Protection Internet Explorer - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\AntivirusFirewall\Anti-Spyware\ieshield.dll
O9 - Extra 'Tools' menuitem: Protection Internet Explorer... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\AntivirusFirewall\Anti-Spyware\ieshield.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSAG~1\Messager Wanadoo.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSAG~1\Messager Wanadoo.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.encyclo.wanadoo.fr/JS/tdserver.cab
O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://hermes.ac-versailles.fr/qp2.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1095370272640
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - https://www.3ds.com/products-services/3dvia/
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Antivirus Firewall (BackWeb Plug-in - 6588780) - Securitoo Portal - C:\PROGRA~1\ANTIVI~1\backweb\6588780\Program\SERVIC~1.EXE
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\AntivirusFirewall\Anti-Virus\fsgk32st.exe
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\AntivirusFirewall\backweb\6588780\program\fsbwsys.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\AntivirusFirewall\FWES\Program\fsdfwd.exe
O23 - Service: FSMA - F-Secure Corporation - C:\Program Files\AntivirusFirewall\Common\FSMA32.EXE
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Service de sécurité matérielle (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

--
End of file - 13467 bytes
Configuration: Windows XP
Internet Explorer 7.0

11 réponses

  1. Contributeur sécurité
    Salut,

    commences par ce-ci :

    Télécharges Navilog1 sur ton bureau :

    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

    !! Déconnectes toi,désactives tes défences( anti-virus,anti-spyware ) et fermes bien toutes tes applications le temps de la manipe !!

    Ensuite double clique sur navilog1.exe pour lancer l'installation.
    Une fois l'installation terminée, le fix s'exécutera automatiquement.
    (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

    Laisses-toi guider. Au menu principal, choisis 1 et valides.
    (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

    Patiente jusqu'au message :
    *** Analyse Termine le ..... ***

    Appuies sur une touche comme demandé, le bloc-note va s'ouvrir.
    Copie-colle l'intégralité de son contenu dans ta prochaine réponse et attends la suite .

    (Le rapport est en outre sauvegardé à la racine du disque "C\:fixnavi.txt" )

    TUTO (aide) : http://www.malekal.com/Adware.Magic_Control.php#mozTocId595901
    1. Bonjour Ske69
      merci de ta réponse claire et rapide.
      Voici le rapport de scan que tu m'as demandé :

      Search Navipromo version 3.6.5 commencé le 24/08/2008 à 23:27:41.82
      
      !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
      !!! Postez ce rapport sur le forum pour le faire analyser !!!
      !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!
      
      Outil exécuté depuis C:\Program Files\navilog1
      Session actuelle : "andrecalas" 
      
      Mise à jour le 22.08.2008 à 17h30 par IL-MAFIOSO
      
      
      Microsoft Windows XP [version 5.1.2600]
      Internet Explorer : 7.0.5730.11 
      Système de fichiers : NTFS
      
      Recherche executé en mode normal
      
      *** Recherche Programmes installés ***
      
      Instant Access
      
      *** Recherche dossiers dans "C:\WINDOWS" ***
      
      
      *** Recherche dossiers dans "C:\Program Files" ***
      
      ...\Instant Access trouvé !
      
      *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***
      
      
      *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***
      
      
      *** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***
      
      
      *** Recherche dossiers dans "C:\Documents and Settings\andrecalas\applic~1" *** 
      
      
      *** Recherche dossiers dans "C:\DOCUME~1\SARAHC~1\applic~1" *** 
      
      
      *** Recherche dossiers dans "C:\Documents and Settings\andrecalas\locals~1\applic~1" *** 
      
      
      *** Recherche dossiers dans "C:\DOCUME~1\SARAHC~1\locals~1\applic~1" *** 
      
      
      *** Recherche dossiers dans "C:\Documents and Settings\andrecalas\menudm~1\progra~1" *** 
      
      
      *** Recherche dossiers dans "C:\DOCUME~1\SARAHC~1\menudm~1\progra~1" *** 
      
      
      *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
      pour + d'infos : http://www.gmer.net
      
      Fichier(s) caché(s) :
      
      C:\WINDOWS\system32\imcsk.dat
      C:\WINDOWS\system32\imcsk.exe
      C:\WINDOWS\system32\imcsk_nav.dat
      C:\WINDOWS\system32\imcsk_navps.dat
      C:\WINDOWS\system32\imcsk_navup.dat
      
      
      *** Recherche avec GenericNaviSearch ***
      !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
      !!! A vérifier impérativement avant toute suppression manuelle !!!
      
      * Recherche dans "C:\WINDOWS\system32" *
      
      Fichiers trouvés :
      
      olztry.exe trouvé ! 
      
      Fichiers suspects :
      
      cvvocclwsz.exe trouvé ! 
      
      * Recherche dans "C:\Documents and Settings\andrecalas\locals~1\applic~1" * 
      
      * Recherche dans "C:\DOCUME~1\SARAHC~1\locals~1\applic~1" * 
      
      
      
      *** Recherche fichiers *** 
      
      
      c:\docume~1\alluse~1\bureau\NoCreditCard.lnk trouvé ! 
      C:\WINDOWS\dialerexe.ini trouvé !
      C:\WINDOWS\system32\nvs2.inf trouvé !
      
      *** Recherche clés spécifiques dans le Registre ***
      
      HKEY_CURRENT_USER\Software\Lanconfig trouvé ! 
      
      *** Module de Recherche complémentaire ***
      (Recherche fichiers spécifiques)
      
      1)Recherche nouveaux fichiers Instant Access :
      
      C:\WINDOWS\system32\lnaccess.exe trouvé !
      
      2)Recherche Heuristique :
      
      * Dans "C:\WINDOWS\system32" :
      
      lnaccess.exe trouvé !
      
      * Dans "C:\Documents and Settings\andrecalas\locals~1\applic~1" : 
      
      
      * Dans "C:\DOCUME~1\SARAHC~1\locals~1\applic~1" : 
      
      
      3)Recherche Certificats :
      
      Certificat Egroup trouvé !
      Certificat Electronic-Group trouvé !
      Certificat Montorgueil absent !
      Certificat OOO-Favorit trouvé !
      Certificat Sunny-Day-Design-Ltd absent !
      
      4)Recherche fichiers connus :
      
      
      
      *** Analyse terminée le 24/08/2008 à 23:38:15.46 ***

      Aux spécialistes de me dire maintenant ce que je dois faire pour la suite (merci encore)
      1. Contributeur sécurité
        Salut,

        On continue :

        !! Déconnectes toi, désactives tes défenses ( anti-virus,anti-spyware ) et fermes bien toutes tes applications le temps de la manipe !!

        --->Double-cliques sur le raccourci Navilog1

        Arriver au menu principal, choisir l'option 2 et valider (nettoyage "automatique" ).

        Le fix demandera ensuite de "redémarrer le PC", fermer toutes les fenêtres ouvertes
        et appuyer sur une touche comme demandé.( important : si le PC ne redémarre pas automatiquement, le faire manuellement )
        Au redémarrage du PC, choisir la session habituelle si nécessaire.

        Patienter jusqu'au message : "Nettoyage Terminé le ..."

        Le bureau revient, puis le bloc-note s'ouvre .
        Sauvegarder ce rapport de manière à le retrouver, puis fermer le bloc-note ...
        (Le rapport sera en outre sauvegardé à la racine du disque "C\:cleannavi.txt")

        Postes ce rapport dans ta nouvelle réponse accompagné d'un nouveau rapport hijacthis pour analyse et attends la suite ...

        (PS : Si le bureau ne réapparaît pas, faire CTRL+ALT+SUPPR pour ouvrir le gestionnaire de tâches.
        Choisir l'onglet processus. Cliquer en haut à gauche sur fichiers et choisir exécuter,
        Taper explorer et valider.)
        1. Bonjour
          j'ai fait ce que tu m'as indiqué.

          En lançant navilogue option 2, j'ai eu ce message :
          "Impossible d'exporter C:\Programme Files\navilog1\Safebackup\backup_registry.dat
          erreur d'écriture sur le fichier peut etre due a une erreur de disque ou de systeme de fichiers"
          aprés j'ai continué normalement, le PC a redemarré tout seul.
          Voici le rapport de navilog:
          Clean Navipromo version 3.6.5 commencé le 25/08/2008 à 10:08:03.78
          
          Outil exécuté depuis C:\Program Files\navilog1
          Session actuelle : "andrecalas" 
          
          Mise à jour le 22.08.2008 à 17h30 par IL-MAFIOSO
          
          
          Microsoft Windows XP [version 5.1.2600]
          Internet Explorer : 7.0.5730.11
          Système de fichiers : NTFS
          
          Mode suppression automatique 
          avec prise en charge résultats Catchme et GNS
          
          
          Nettoyage exécuté au redémarrage de l'ordinateur
          
          *** Creation backups fichiers trouvés par Catchme *** 
          
          Copie vers "C:\Program Files\navilog1\Backupnavi"
          
          Copie C:\WINDOWS\system32\imcsk.dat réalisée avec succès ! 
          Copie C:\WINDOWS\system32\imcsk.exe réalisée avec succès ! 
          Copie C:\WINDOWS\system32\imcsk_nav.dat réalisée avec succès ! 
          Copie C:\WINDOWS\system32\imcsk_navps.dat réalisée avec succès ! 
          Copie C:\WINDOWS\system32\imcsk_navup.dat réalisée avec succès ! 
          
          *** Suppression des fichiers trouvés avec Catchme ***
          
          C:\WINDOWS\system32\imcsk.dat supprimé ! 
          C:\WINDOWS\system32\imcsk.exe supprimé ! 
          C:\WINDOWS\system32\imcsk_nav.dat supprimé ! 
          C:\WINDOWS\system32\imcsk_navps.dat supprimé ! 
          C:\WINDOWS\system32\imcsk_navup.dat supprimé ! 
           
          ** 2ème passage avec résultats Catchme ** 
          
          * Dans "C:\WINDOWS\system32" *
          
          
          C:\WINDOWS\prefetch\imcsk*.pf trouvé ! 
          Copie C:\WINDOWS\prefetch\imcsk*.pf réalisée avec succès !
          C:\WINDOWS\prefetch\imcsk*.pf supprimé !
          
          
          * Dans "C:\Documents and Settings\andrecalas\locals~1\applic~1" * 
          
          
          
          *** Suppression avec sauvegardes résultats GenericNaviSearch ***
          
          * Suppression dans "C:\WINDOWS\System32" *
          
          
          olztry.exe trouvé ! 
          Copie olztry.exe réalisée avec succès !
          olztry.exe supprimé !
          
          
          * Suppression dans "C:\Documents and Settings\andrecalas\locals~1\applic~1" * 
          
          
          
          * Suppression dans "C:\DOCUME~1\SARAHC~1\locals~1\applic~1" * 
          
          
          
          *** Suppression dossiers dans "C:\WINDOWS" ***
          
          
          *** Suppression dossiers dans "C:\Program Files" ***
          
          ...\Instant Access ...suppression... 
          ...\Instant Access supprimé ! 
          
          
          *** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***
          
          
          *** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***
          
          
          *** Suppression dossiers dans "c:\docume~1\alluse~1\applic~1" ***
          
          
          *** Suppression dossiers dans "C:\Documents and Settings\andrecalas\applic~1" *** 
          
          
          *** Suppression dossiers dans "C:\DOCUME~1\SARAHC~1\applic~1" *** 
          
          
          *** Suppression dossiers dans "C:\Documents and Settings\andrecalas\locals~1\applic~1" *** 
          
          
          *** Suppression dossiers dans "C:\DOCUME~1\SARAHC~1\locals~1\applic~1" *** 
          
          
          *** Suppression dossiers dans "C:\Documents and Settings\andrecalas\menudm~1\progra~1" *** 
          
          
          *** Suppression dossiers dans "C:\DOCUME~1\SARAHC~1\menudm~1\progra~1" *** 
          
          
          
          *** Suppression fichiers ***
          
          c:\docume~1\alluse~1\bureau\NoCreditCard.lnk supprimé !
          C:\WINDOWS\dialerexe.ini supprimé !
          C:\WINDOWS\system32\nvs2.inf supprimé !
          
          *** Suppression fichiers temporaires ***
          
          Nettoyage contenu C:\WINDOWS\Temp effectué !
          Nettoyage contenu C:\Documents and Settings\andrecalas\locals~1\Temp effectué !
          
          *** Traitement Recherche complémentaire ***
          (Recherche fichiers spécifiques)
          
          1)Suppression avec sauvegardes nouveaux fichiers Instant Access :
          
          C:\WINDOWS\system32\lnaccess.exe trouvé !
          Copie C:\WINDOWS\system32\lnaccess.exe réalisée avec succès !
          C:\WINDOWS\system32\lnaccess.exe supprimé !
          
          2)Recherche, création sauvegardes et suppression Heuristique :
          
          
          * Dans "C:\WINDOWS\system32" *
          
          
          * Dans "C:\Documents and Settings\andrecalas\locals~1\applic~1" * 
          
          
          * Dans "C:\DOCUME~1\SARAHC~1\locals~1\applic~1" * 
          
          
          *** Sauvegarde du Registre vers dossier Safebackup ***
          
          sauvegarde du Registre réalisée avec succès !
          
          *** Nettoyage Registre ***
          
          Nettoyage Registre Ok
          
          
          *** Certificats ***
          
          Certificat Egroup supprimé !
          Certificat Electronic-Group supprimé !
          Certificat Montorgueil absent !
          Certificat OOO-Favorit supprimé !
          Certificat Sunny-Day-Design-Ltdt absent !
          
          *** Fichiers suspects non supprimés par Navilog1 ***
          !! Fichiers légitimes possibles, à contrôler avant suppression !!
          
          Fichiers suspects dans "C:\WINDOWS\system32" :
          
          cvvocclwsz.exe trouvé !
          
          *** Nettoyage terminé le 25/08/2008 à 10:15:11.89 ***


          Quand le PC a redemarré, cette satanée fenêtre de Spyware secure s'est relancée automatiquement malheureusement et comme d'habitude n'a pas pu se connecter a internet, je l'ai fermé manuellement, j'ail'impression que le logiciel a été mis en quarantaine par l'anti-virus anti-spyware.

          Sinon voici le rapport de Hijack, avec l'antivirus coupé :

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 10:19:54, on 25/08/2008
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16608)
          Boot mode: Normal
          
          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\system32\acs.exe
          C:\Program Files\AntivirusFirewall\Anti-Virus\fsgk32st.exe
          C:\Program Files\AntivirusFirewall\Anti-Virus\FSGK32.EXE
          C:\Program Files\AntivirusFirewall\Common\FSMA32.EXE
          C:\Program Files\AntivirusFirewall\Anti-Virus\fssm32.exe
          C:\WINDOWS\System32\FTRTSVC.exe
          C:\WINDOWS\System32\gearsec.exe
          C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          C:\WINDOWS\System32\nvsvc32.exe
          C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\wuauclt.exe
          C:\Program Files\Apoint2K\Apoint.exe
          C:\WINDOWS\AGRSMMSG.exe
          C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
          C:\Program Files\Apoint2K\Apntex.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
          C:\Program Files\iPod\bin\iPodService.exe
          C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe
          C:\WINDOWS\System32\hphmon05.exe
          C:\PROGRA~1\MESSAG~1\StartMessager.exe
          C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
          C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
          C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
          C:\PROGRA~1\Wanadoo\ComComp.exe
          C:\PROGRA~1\Wanadoo\Toaster.exe
          C:\PROGRA~1\Wanadoo\Inactivity.exe
          C:\PROGRA~1\Wanadoo\PollingModule.exe
          C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
          C:\PROGRA~1\Wanadoo\Watch.exe
          C:\Program Files\AntivirusFirewall\Common\FSLAUNCHER0.EXE
          C:\WINDOWS\system32\wuauclt.exe
          C:\Program Files\Trend Micro\HijackThis\monjack.exe
          
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www8.hp.com/fr/fr/home.html
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://french.icrfast.com/index.php?rvs=hompag
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://side.search.ke.voila.fr
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: (no name) - {AEEC3B59-CA98-4EBA-A140-57B94E283583} - C:\PROGRA~1\ORANGE~1\TOOLBA~2.DLL
          R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
          R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
          O3 - Toolbar: barre d'outils Orange - {D3028143-6145-4318-99D3-3EDCE54A95A9} - C:\Program Files\Orange Toolbar FR\ToolbarContainer234.dll
          O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
          O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
          O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
          O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
          O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
          O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
          O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
          O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
          O4 - HKLM\..\Run: [MessagerStarter Wanadoo] C:\PROGRA~1\MESSAG~1\StartMessager.exe Messager Wanadoo
          O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
          O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
          O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe"  -osboot
          O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\AntivirusFirewall\Common\FSM32.EXE" /splash
          O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\AntivirusFirewall\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
          O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\AntivirusFirewall\FSGUI\FSSW.EXE" /reboot
          O4 - HKLM\..\Run: [News Service] "C:\Program Files\AntivirusFirewall\FSGUI\ispnews.exe"
          O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
          O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [Spyware-Secure] C:\Program Files\Spyware-Secure\Spyware-Secure_trial.exe
          O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
          O4 - Global Startup: 108Mbps Wireless LAN Adapte.lnk = C:\Program Files\TRENDnet\TEW-441PC_443PI\TRENDnet.exe
          O4 - Global Startup: Image Transfer.lnk = ?
          O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
          O8 - Extra context menu item: &Bloquer cette fenêtre publicitaire - C:\Program Files\AntivirusFirewall\Anti-Spyware\blockpopups.htm
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
          O8 - Extra context menu item: traduire la page - C:\DOCUME~1\ANDREC~1\LOCALS~1\Temp\cce169.html
          O8 - Extra context menu item: traduire le texte sélectionné - C:\DOCUME~1\ANDREC~1\LOCALS~1\Temp\cce16A.html
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O9 - Extra button: Protection Internet Explorer - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\AntivirusFirewall\Anti-Spyware\ieshield.dll
          O9 - Extra 'Tools' menuitem: Protection Internet Explorer... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\AntivirusFirewall\Anti-Spyware\ieshield.dll
          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSAG~1\Messager Wanadoo.exe
          O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSAG~1\Messager Wanadoo.exe
          O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
          O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
          O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.encyclo.wanadoo.fr/JS/tdserver.cab
          O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://hermes.ac-versailles.fr/qp2.cab
          O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1095370272640
          O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - https://www.3ds.com/products-services/3dvia/
          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
          O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL
          O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
          O23 - Service: Antivirus Firewall (BackWeb Plug-in - 6588780) - Securitoo Portal - C:\PROGRA~1\ANTIVI~1\backweb\6588780\Program\SERVIC~1.EXE
          O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\AntivirusFirewall\Anti-Virus\fsgk32st.exe
          O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\AntivirusFirewall\backweb\6588780\program\fsbwsys.exe
          O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\AntivirusFirewall\FWES\Program\fsdfwd.exe
          O23 - Service: FSMA - F-Secure Corporation - C:\Program Files\AntivirusFirewall\Common\FSMA32.EXE
          O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
          O23 - Service: Service de sécurité matérielle (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
          O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
          O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
          O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
          
          --
          End of file - 11754 bytes


          Merci
          1. Contributeur sécurité
            Très bien ...

            pour Spyware secure , c'est normal ... on c'est occuper d'une autre bestiolle avant ... ^^

            Fais ce qui suit :

            1- Télécharges : - CCleaner
            https://www.pcastuces.com/logitheque/ccleaner.htm
            Ce logiciel va permettre de supprimer tous les fichiers temporaires et de corrigé ton registre .Lors de l'installation, avant de cliquer sur le bouton "installer", décoche toutes les "options supplémentaires" sauf les 2 première.
            Une fois le prg instalé et lancé, Clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures"( Par la suite, laisse-le avec ses réglages par défaut. C'est tout ).

            Un tuto ( aide ):
            http://perso.orange.fr/jesses/Docs/Logiciels/CCleaner.htm

            ---> Utilisation:
            ! déconnectes toi et fermes toutes applications en cours !
            * vas dans "nettoyeur" : fait analyse puis nettoyage
            * vas dans "registre" : fait chercher les erreurs et réparer ( plusieurs fois jusqu'à ce qu'il n'y est plus d'erreur ) .

            ( CCleaner : soft à garder sur son PC , super utile pour de bons nettoyages ... )

            2- Télécharges SmitfraudFix (de S!Ri, balltrap34 et moe31 ) :
            http://siri.urz.free.fr/Fix/SmitfraudFix.exe

            !! Déconnectes toi, fermes toute tes applications et désactives tes défenses ( anti-virus ,anti-spyware,...) le temps de la manipe !!

            Installes le soft à la racine de C\ ( et pas ailleurs! --->"C\:SmitfraudFix.exe" ) .

            Tuto ( aide ) : http://siri.urz.free.fr/Fix/SmitfraudFix.php

            Utilisation ---> option 1 / Recherche :
            Double clique sur l'icône "Smitfraudfix.exe" et sélectionnes 1 (et pas sur autre chose sans notre accord !) pour créer un rapport des fichiers responsables de l'infection.

            Postes le rapport ( "rapport.txt" qui se trouve sous C\: ) et attends la suite .

            (Attention : "process.exe", un composant de l'outil, est détecté par certains antivirus comme étant un "RiskTool". Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité.)
            1. Re bonjour
              voici le rapport.txt de Smitfraudfix:

              SmitFraudFix v2.339
              
              Rapport fait à 17:51:19.56, 25/08/2008
              Executé à partir de C:\Documents and Settings\andrecalas\Bureau\SmitfraudFix
              OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
              Le type du système de fichiers est NTFS
              Fix executé en mode normal
              
              »»»»»»»»»»»»»»»»»»»»»»»» Process
              
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\WINDOWS\system32\acs.exe
              C:\Program Files\AntivirusFirewall\Anti-Virus\fsgk32st.exe
              C:\Program Files\AntivirusFirewall\Anti-Virus\FSGK32.EXE
              C:\Program Files\AntivirusFirewall\Common\FSMA32.EXE
              C:\WINDOWS\System32\FTRTSVC.exe
              C:\WINDOWS\System32\gearsec.exe
              C:\Program Files\AntivirusFirewall\Anti-Virus\fssm32.exe
              C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              C:\WINDOWS\System32\nvsvc32.exe
              C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\Explorer.EXE
              C:\Program Files\Apoint2K\Apoint.exe
              C:\WINDOWS\AGRSMMSG.exe
              C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
              C:\Program Files\Apoint2K\Apntex.exe
              C:\Program Files\iTunes\iTunesHelper.exe
              C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
              C:\Program Files\iPod\bin\iPodService.exe
              C:\WINDOWS\System32\hphmon05.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\PROGRA~1\MESSAG~1\StartMessager.exe
              C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
              C:\Program Files\QuickTime\qttask.exe
              C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
              C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\TRENDnet\TEW-441PC_443PI\TRENDnet.exe
              C:\Program Files\AntivirusFirewall\Common\FSLAUNCHER0.EXE
              C:\Documents and Settings\andrecalas\Bureau\SmitfraudFix\Policies.exe
              C:\WINDOWS\system32\cmd.exe
              
              »»»»»»»»»»»»»»»»»»»»»»»» hosts
              
              
              »»»»»»»»»»»»»»»»»»»»»»»» C:\
              
              
              »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
              
              
              »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
              
              
              »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
              
              
              »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
              
              
              »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles
              
              
              »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\andrecalas
              
              
              »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\andrecalas\Application Data
              
              
              »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer
              
              
              »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ANDREC~1\Favoris
              
              
              »»»»»»»»»»»»»»»»»»»»»»»» Bureau
              
              
              »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files 
              
              
              »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues
              
              
              »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau
               
              [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
              "Source"="About:Home"
              "SubscribedURL"="About:Home"
              "FriendlyName"="Ma page d'accueil"
               
              
              »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
              !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
              
              IEDFix
              Credits: Malware Analysis & Diagnostic
              Code: S!Ri
              
              
              
              »»»»»»»»»»»»»»»»»»»»»»»» VACFix
              !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
              
              VACFix
              Credits: Malware Analysis & Diagnostic
              Code: S!Ri
              
              
              »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
              !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
              
              404Fix
              Credits: Malware Analysis & Diagnostic
              Code: S!Ri
              
              
              »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
              !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
              
              SrchSTS.exe by S!Ri
              Search SharedTaskScheduler's .dll
              
              
              »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
              !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
              
              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
              "AppInit_DLLs"="C:\\PROGRA~1\\Google\\GOOGLE~4\\GOEC62~1.DLL"
              "LoadAppInit_DLLs"=dword:00000001
              
              
              »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
              !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
              
              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
              "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
              "System"=""
              
              
              »»»»»»»»»»»»»»»»»»»»»»»» RK
              
              
              
              »»»»»»»»»»»»»»»»»»»»»»»» DNS
              
              
              
              »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll
              
              
              »»»»»»»»»»»»»»»»»»»»»»»» Fin

              J'attendsl les instructions ;-)
          2. Contributeur sécurité
            Bizard ... :-/

            Changeons le fusil d'épaule :

            -Télécharges SDFix sur ton bureau :
            http://downloads.andymanchesta.com/RemovalTools/SDFix.exe.

            --->Double-cliques sur SDFix.exe et choisis "Install" .

            ( tuto ici : https://www.malekal.com/slenfbot-still-an-other-irc-bot/ )

            Puis une fois l'installe faite ,
            Impératif : redémarres en mode sans échec .
            Comment aller en Mode sans échec :
            1) Redémarres ton ordi
            2) Tapotes la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
            3) Tu verras un écran avec options de démarrage apparaître
            4) Choisis la première option : Sans Échec, et valide avec "Entrée"
            5) Choisis ton compte habituel, et non Administrateur (si besoin ... )

            ( ps : n'oublies pas , en mode sans échec , pas de connexion ! Donc copies ou imprimes bien les info ci-dessous ...)

            Ouvres le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double cliques sur RunThis.bat pour lancer le script.
            --->Tapes Y pour lancer le script ...
            Le Fix supprime les services du virus et nettoie le registre, de ce fait un redémarrage est nécessaire , donc :
            presses une touche pour redémarrer quand il te le sera demandé .

            Le PC va mettre du temps avant de démarrer ( c'est normale ), après le chargement du Bureau presses une touche lorsque "Finished" s'affiche .

            Le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier C:\SDFix sous le nom "Report.txt".
            Postes ce dernier dans ta prochaine réponse accompagné d'un nouveau rapport Hijakcthis pour analyse ...
            1. Hello
              j'ai essayé de suivre tes instructions au plus prés mais j'ai l'impression que tout n'a pas bien fonctionné :
              je suis rentrée en mode sans echec dans mon PC. J'ai lancé Runthis, et une fenetre s'est ouverte, au bout d'un moment(assez long) j'ai appuyé sur la touche "tiret" de la fenetre pour la réduire, mais en fait elle a disparu, j'ai fait un crtl+alt+supp, j'ai vu que l'appli tournait, j'ai attendu trés longtemps et un moment mais on m'a rien demandé j'ai appuyé sur une touche, l'ordi s'est arrété et est reparti, j'ai choisi un des deux compte autre que Admin, là une fenetre s'est ouverte avec un message comme quoi le check des malware était en cour, j'ai attendu et finalement j'ai obtenu ce rapport :
              [b]SDFix: Version 1.219 [/b]
              Run by andrecalas on 25/08/2008 at 21:55
              
              Microsoft Windows XP [version 5.1.2600]
              Running From: C:\SDFix
              
              [b]Checking Services [/b]:
              
              
              Restoring Default Security Values
              Restoring Default Hosts File
              
              Rebooting
              
              
              [b]Checking Files [/b]: 
              
              Trojan Files Found:
              
              C:\WINDOWS\TMLPWIN.EXE - Deleted
              
              
              
              
              
              Removing Temp Files
              
              [b]ADS Check [/b]:
               
              
              
                                               [b]Final Check [/b]:
              
              catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
              Rootkit scan 2008-08-25 22:07:17
              Windows 5.1.2600 Service Pack 2 NTFS
              
              scanning hidden processes ...
              
              scanning hidden services & system hive ...
              
              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CriticalDeviceDatabase\pci#ven_8086&dev_7010]
              "Service"="intelide"
              
              scanning hidden registry entries ...
              
              scanning hidden files ...
              
              scan completed successfully
              hidden processes: 0
              hidden services: 0
              hidden files: 0
              
              
              [b]Remaining Services [/b]:
              
              
              
              
              Authorized Application Key Export:
              
              [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
              "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
              "C:\\WINDOWS\\system32\\ntvdm.exe"="C:\\WINDOWS\\system32\\ntvdm.exe:*:Enabled:NTVDM.EXE"
              "D:\\mysql\\bin\\mysqld.exe"="D:\\mysql\\bin\\mysqld.exe:*:Enabled:mysqld"
              "D:\\catalogue.exe"="D:\\catalogue.exe:*:Enabled:catalogue"
              "C:\\WINDOWS\\system32\\mmc.exe"="C:\\WINDOWS\\system32\\mmc.exe:*:Disabled:Microsoft Management Console"
              "C:\\Program Files\\AntivirusFirewall\\backweb\\6588780\\Program\\fspex.exe"="C:\\Program Files\\AntivirusFirewall\\backweb\\6588780\\Program\\fspex.exe:*:Enabled:Antivirus Firewall"
              "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
              "C:\\Program Files\\Wanadoo\\WOOBrowser\\WOOBrowser.exe"="C:\\Program Files\\Wanadoo\\WOOBrowser\\WOOBrowser.exe:*:Enabled:Navigateur Internet"
              "C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
              
              [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
              "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
              "C:\\Program Files\\AntivirusFirewall\\backweb\\6588780\\Program\\fspex.exe"="C:\\Program Files\\AntivirusFirewall\\backweb\\6588780\\Program\\fspex.exe:*:Enabled:Antivirus Firewall"
              "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
              
              [b]Remaining Files [/b]:
              
              
              File Backups: - C:\SDFix\backups\backups.zip
              
              [b]Files with Hidden Attributes [/b]:
              
              Sat 20 Jan 2007             0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
              Sat  7 Jun 2008             0 A..H. --- "C:\Documents and Settings\All Users\Application Data\Google Updater\cache\BIT75.tmp"
              Sun 21 Jan 2007       265,728 ...H. --- "C:\Documents and Settings\andrecalas\Application Data\Microsoft\Word\~WRL0435.tmp"
              Sun 21 Jan 2007       463,872 ...H. --- "C:\Documents and Settings\andrecalas\Application Data\Microsoft\Word\~WRL1236.tmp"
              Sun 21 Jan 2007       343,040 ...H. --- "C:\Documents and Settings\andrecalas\Application Data\Microsoft\Word\~WRL1539.tmp"
              Sun 21 Jan 2007       351,232 ...H. --- "C:\Documents and Settings\andrecalas\Application Data\Microsoft\Word\~WRL1662.tmp"
              Sun 21 Jan 2007       466,944 ...H. --- "C:\Documents and Settings\andrecalas\Application Data\Microsoft\Word\~WRL3230.tmp"
              Tue 21 Aug 2007        58,368 ...H. --- "C:\Documents and Settings\andrecalas\Mes documents\andrecalas\00SCIdocuments\~WRL1313.tmp"
              Sun  9 Sep 2007        24,064 ...H. --- "C:\Documents and Settings\andrecalas\Mes documents\andrecalas\00Scienceint‚gr‚ecours\~WRL3313.tmp"
              Thu 29 May 2003       109,056 A..H. --- "C:\Documents and Settings\andrecalas\Mes documents\andrecalas\ancien document04\Jeulin\Kitlu\~WRL0524.tmp"
              Sun  7 Mar 2004        79,360 ...H. --- "C:\Documents and Settings\andrecalas\Mes documents\andrecalas\001phychim345\05Abel4\04-abelchim\04-4exchim\~WRL0416.tmp"
              Thu  6 Jun 2002        87,552 A..H. --- "C:\Documents and Settings\andrecalas\Mes documents\andrecalas\ancien document04\Abel4\Abelchim\A4exchim\~WRL0002.tmp"
              Thu  6 Jun 2002       138,752 ...H. --- "C:\Documents and Settings\andrecalas\Mes documents\andrecalas\ancien document04\Abel4\Abelchim\A4exchim\~WRL0025.tmp"
              Thu  6 Jun 2002        34,304 ...H. --- "C:\Documents and Settings\andrecalas\Mes documents\andrecalas\ancien document04\Abel4\Abelchim\A4intdocchim\~WRL2839.tmp"
              Mon 17 Mar 2003        55,808 A..H. --- "C:\Documents and Settings\andrecalas\Mes documents\andrecalas\ancien document04\Alex3\Alexchim\A3exchi\~WRL2526.tmp"
              Mon 22 Mar 2004        23,552 A..H. --- "C:\Documents and Settings\andrecalas\Mes documents\andrecalas\ancien document04\Alex3\Alexel\A3exel\~WRL0005.tmp"
              Sun  9 May 2004        37,888 A..H. --- "C:\Documents and Settings\andrecalas\Mes documents\andrecalas\ancien document04\Alex3\Alexlu\A3intdoclu\~WRL1833.tmp"
              Sat  8 May 2004        21,504 A..H. --- "C:\Documents and Settings\andrecalas\Mes documents\andrecalas\ancien document04\Alex3\Alexlu\A3intdoclu\~WRL2673.tmp"
              Sat 29 Nov 2003        66,048 A..H. --- "C:\Documents and Settings\andrecalas\Mes documents\andrecalas\ancien document04\Alex3\Alexm‚ca\A3exm‚ca\~WRL1867.tmp"
              Tue  9 Dec 2003       707,584 A..H. --- "C:\Documents and Settings\andrecalas\Mes documents\andrecalas\ancien document04\Alex3\Alexm‚ca\A3exm‚ca\~WRL1905.tmp"
              Sat 12 Oct 2002        60,416 A..H. --- "C:\Documents and Settings\andrecalas\Mes documents\andrecalas\ancien document04\Alex3\Alexm‚ca\A3intdocm‚ca\~WRL0216.tmp"
              Thu 19 Sep 2002        21,504 A..H. --- "C:\Documents and Settings\andrecalas\Mes documents\andrecalas\ancien document04\Arthur5\Arthelec\A5corelec\~WRL0100.tmp"
              Sat  4 Oct 2003        19,456 A..H. --- "C:\Documents and Settings\andrecalas\Mes documents\andrecalas\ancien document04\Arthur5\Arthelec\A5intdocel\~WRL0076.tmp"
              Sun 30 May 2004        47,104 A..H. --- "C:\Documents and Settings\andrecalas\Mes documents\andrecalas\ancien document04\Arthur5\Arthmat\A5exmat\~WRL0213.tmp"
              Thu  5 Dec 2002       109,568 A..H. --- "C:\Documents and Settings\andrecalas\Mes documents\andrecalas\ancien document04\Arthur5\Arthmat\A5exmat\~WRL3246.tmp"
              Mon  3 Jun 2002        70,144 A..H. --- "C:\Documents and Settings\andrecalas\Mes documents\andrecalas\ancien document04\Arthur5\Arthmat\A5exmat\~WRL3679.tmp"
              Mon  3 Jun 2002       279,040 A..H. --- "C:\Documents and Settings\andrecalas\Mes documents\andrecalas\ancien document04\Arthur5\Arthmat\A5intdocmat\~WRL2413.tmp"
              Thu 29 May 2003       109,056 A..H. --- "C:\Documents and Settings\andrecalas\Mes documents\andrecalas\ancien document04\Jeulin\Jeulin\Kitlu\~WRL0524.tmp"
              
              [b]Finished![/b]


              Voici le hijackthis fait dans la foulée :
              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 22:14:26, on 25/08/2008
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16608)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\WINDOWS\system32\acs.exe
              C:\PROGRA~1\ANTIVI~1\backweb\6588780\Program\SERVIC~1.EXE
              C:\Program Files\AntivirusFirewall\Anti-Virus\fsgk32st.exe
              C:\Program Files\AntivirusFirewall\Anti-Virus\FSGK32.EXE
              C:\Program Files\AntivirusFirewall\backweb\6588780\program\fsbwsys.exe
              C:\Program Files\AntivirusFirewall\Common\FSMA32.EXE
              C:\Program Files\AntivirusFirewall\Anti-Virus\fssm32.exe
              C:\WINDOWS\System32\FTRTSVC.exe
              C:\Program Files\AntivirusFirewall\Common\FSMB32.EXE
              C:\WINDOWS\System32\gearsec.exe
              C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              C:\WINDOWS\System32\nvsvc32.exe
              C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\AntivirusFirewall\Common\FCH32.EXE
              C:\Program Files\AntivirusFirewall\Common\FAMEH32.EXE
              C:\Program Files\AntivirusFirewall\Anti-Virus\fsqh.exe
              C:\Program Files\AntivirusFirewall\Anti-Virus\fsrw.exe
              C:\Program Files\AntivirusFirewall\FWES\Program\fsdfwd.exe
              C:\Program Files\AntivirusFirewall\Anti-Virus\fsav32.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\system32\notepad.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Program Files\Apoint2K\Apoint.exe
              C:\WINDOWS\AGRSMMSG.exe
              C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
              C:\Program Files\iTunes\iTunesHelper.exe
              C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
              C:\Program Files\iPod\bin\iPodService.exe
              C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe
              C:\Program Files\Apoint2K\Apntex.exe
              C:\WINDOWS\System32\hphmon05.exe
              C:\PROGRA~1\MESSAG~1\StartMessager.exe
              C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
              C:\Program Files\QuickTime\qttask.exe
              C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
              C:\Program Files\AntivirusFirewall\Common\FSM32.EXE
              C:\Program Files\AntivirusFirewall\FSGUI\ispnews.exe
              C:\PROGRA~1\ANTIVI~1\ANTI-S~1\fsaw.exe
              C:\Program Files\AntivirusFirewall\FSGUI\fsguidll.exe
              C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
              C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Messenger\msmsgs.exe
              C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
              C:\Program Files\TRENDnet\TEW-441PC_443PI\TRENDnet.exe
              C:\Program Files\AntivirusFirewall\backweb\6588780\Program\fspex.exe
              C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
              C:\Program Files\Google\Google Updater\GoogleUpdater.exe
              C:\PROGRA~1\Wanadoo\ComComp.exe
              C:\PROGRA~1\Wanadoo\Toaster.exe
              C:\PROGRA~1\Wanadoo\Inactivity.exe
              C:\PROGRA~1\Wanadoo\PollingModule.exe
              C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
              C:\Program Files\Trend Micro\HijackThis\monjack.exe
              C:\PROGRA~1\Wanadoo\Watch.exe

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q304&bd=presario&pf=laptop
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://french.icrfast.com/index.php?rvs=hompag
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://side.search.ke.voila.fr
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              R3 - URLSearchHook: (no name) - {AEEC3B59-CA98-4EBA-A140-57B94E283583} - C:\PROGRA~1\ORANGE~1\TOOLBA~2.DLL
              R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
              R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
              O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
              O3 - Toolbar: barre d'outils Orange - {D3028143-6145-4318-99D3-3EDCE54A95A9} - C:\Program Files\Orange Toolbar FR\ToolbarContainer234.dll
              O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
              O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
              O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
              O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
              O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
              O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
              O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
              O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
              O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
              O4 - HKLM\..\Run: [MessagerStarter Wanadoo] C:\PROGRA~1\MESSAG~1\StartMessager.exe Messager Wanadoo
              O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
              O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
              O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
              O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
              O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\AntivirusFirewall\Common\FSM32.EXE" /splash
              O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\AntivirusFirewall\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
              O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\AntivirusFirewall\FSGUI\FSSW.EXE" /reboot
              O4 - HKLM\..\Run: [News Service] "C:\Program Files\AntivirusFirewall\FSGUI\ispnews.exe"
              O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
              O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
              O4 - HKLM\..\Run: [Spyware-Secure] C:\Program Files\Spyware-Secure\Spyware-Secure_trial.exe
              O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
              O4 - Global Startup: 108Mbps Wireless LAN Adapte.lnk = C:\Program Files\TRENDnet\TEW-441PC_443PI\TRENDnet.exe
              O4 - Global Startup: Antivirus Firewall.lnk = C:\Program Files\AntivirusFirewall\backweb\6588780\Program\fspex.exe
              O4 - Global Startup: Image Transfer.lnk = ?
              O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
              O8 - Extra context menu item: &Bloquer cette fenêtre publicitaire - C:\Program Files\AntivirusFirewall\Anti-Spyware\blockpopups.htm
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
              O8 - Extra context menu item: traduire la page - C:\DOCUME~1\ANDREC~1\LOCALS~1\Temp\cce4A4.html
              O8 - Extra context menu item: traduire le texte sélectionné - C:\DOCUME~1\ANDREC~1\LOCALS~1\Temp\cce4A5.html
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
              O9 - Extra button: Protection Internet Explorer - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\AntivirusFirewall\Anti-Spyware\ieshield.dll
              O9 - Extra 'Tools' menuitem: Protection Internet Explorer... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\AntivirusFirewall\Anti-Spyware\ieshield.dll
              O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSAG~1\Messager Wanadoo.exe
              O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSAG~1\Messager Wanadoo.exe
              O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
              O14 - IERESET.INF: START_PAGE_URL=https://www.msn.com/fr-fr?cobrand=compaq-notebook.msn.com&ocid=HPDHP&pc=CPNTDF
              O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.encyclo.wanadoo.fr/JS/tdserver.cab
              O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://hermes.ac-versailles.fr/qp2.cab
              O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1095370272640
              O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - https://www.3ds.com/products-services/3dvia/
              O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
              O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL
              O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
              O23 - Service: Antivirus Firewall (BackWeb Plug-in - 6588780) - Securitoo Portal - C:\PROGRA~1\ANTIVI~1\backweb\6588780\Program\SERVIC~1.EXE
              O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\AntivirusFirewall\Anti-Virus\fsgk32st.exe
              O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\AntivirusFirewall\backweb\6588780\program\fsbwsys.exe
              O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\AntivirusFirewall\FWES\Program\fsdfwd.exe
              O23 - Service: FSMA - F-Secure Corporation - C:\Program Files\AntivirusFirewall\Common\FSMA32.EXE
              O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
              O23 - Service: Service de sécurité matérielle (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
              O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
              O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
              O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
              O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
              1. Contributeur sécurité
                Bien ...

                Faut il que je refasse une session de SDFix en mode sans échéc ?
                --> non pas pour l'instant ....

                On continue :

                Télécharges MalwareByte's :
                ici ftp://ftp.commentcamarche.com/download/mbam-setup.exe
                ou ici : http://www.malwarebytes.org/mbam.php

                Installes le ( choisis bien "francais" ; ne modifies pas les paramètres d'installe ) et mets le à jour .

                (NB : S'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharges le ici : https://www.malekal.com/tutorial-aboutbuster/ )

                Potasses le tuto pour te familiariser avec le prg : https://forum.pcastuces.com/sujet.asp?f=31&s=3
                ( cela dis, il est très simple d'utilisation ).

                Impératif : redémarres en mode sans échec :
                Comment aller en Mode sans échec
                1) Redémarres ton ordi
                2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
                3) Tu verras un écran avec options de démarrage apparaître
                4) Choisis la première option : Sans Échec, et valide avec "Entrée"
                5) Choisis ton compte habituel, et non Administrateur (si besoin ... )
                (attention : pas de connexion possible en mode sans échec , donc copies ou imprimes bien la manipe pour éviter les erreurs ...)

                Lances Malwarebyte's .

                Fais un scan dit "complet" ( sélectionnes bien tous tes disks avant le scan ! ) et supprimes tout ce qu'il peut trouver, c'est à dire :
                -->Laisses le scan se terminer,puis à la fin tu cliques sur "résultat" .
                -->Vérifies que tous les objets infectés soient validés, puis cliques sur " suppression " .

                Redémarres ton PC ( mode normal ).

                Postes le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date) accompagné d'un nouvel hijackthis ( fait en mode normal ) ...
                1. Re bonjour
                  (dans les deux cas, j'ai branché un disque dur externe, utilisé par un autre membre de la famille parfois)

                  voici le rapport de MalwareBytes :

                  Malwarebytes' Anti-Malware 1.25
                  Version de la base de données: 1087
                  Windows 5.1.2600 Service Pack 2
                  
                  11:16:51 26/08/2008
                  mbam-log-08-26-2008 (11-16-51).txt
                  
                  Type de recherche: Examen complet (C:\|D:\|)
                  Eléments examinés: 158303
                  Temps écoulé: 1 hour(s), 24 minute(s), 9 second(s)
                  
                  Processus mémoire infecté(s): 0
                  Module(s) mémoire infecté(s): 0
                  Clé(s) du Registre infectée(s): 2
                  Valeur(s) du Registre infectée(s): 1
                  Elément(s) de données du Registre infecté(s): 1
                  Dossier(s) infecté(s): 2
                  Fichier(s) infecté(s): 9
                  
                  Processus mémoire infecté(s):
                  (Aucun élément nuisible détecté)
                  
                  Module(s) mémoire infecté(s):
                  (Aucun élément nuisible détecté)
                  
                  Clé(s) du Registre infectée(s):
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Spyware-Secure (Rogue.Spyware-Secure) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Spyware-Secure (Rogue.Spyware-Secure) -> Quarantined and deleted successfully.
                  
                  Valeur(s) du Registre infectée(s):
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\spyware-secure (Rogue.Spyware-Secure) -> Quarantined and deleted successfully.
                  
                  Elément(s) de données du Registre infecté(s):
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\StartMenuLogOff (Hijack.StartMenu) -> Bad: (1) Good: (0) -> Not selected for removal.
                  
                  Dossier(s) infecté(s):
                  C:\Program Files\Spyware-Secure (Rogue.Spyware-Secure) -> Quarantined and deleted successfully.
                  C:\Program Files\Spyware-Secure\resources (Rogue.Spyware-Secure) -> Quarantined and deleted successfully.
                  
                  Fichier(s) infecté(s):
                  C:\Program Files\Spyware-Secure\Spyware-Secure_trial.exe (Rogue.Spyware-Secure) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{688B846D-54D8-4A0B-BDB5-70B8E736C8E2}\RP776\A0176812.exe (Rogue.Spyware-Secure) -> Quarantined and deleted successfully.
                  C:\Program Files\Spyware-Secure\config.s3db (Rogue.Spyware-Secure) -> Quarantined and deleted successfully.
                  C:\Program Files\Spyware-Secure\language (Rogue.Spyware-Secure) -> Quarantined and deleted successfully.
                  C:\Program Files\Spyware-Secure\quarantine.s3db (Rogue.Spyware-Secure) -> Quarantined and deleted successfully.
                  C:\Program Files\Spyware-Secure\sqlite3.dll (Rogue.Spyware-Secure) -> Quarantined and deleted successfully.
                  C:\Program Files\Spyware-Secure\unrar.dll (Rogue.Spyware-Secure) -> Quarantined and deleted successfully.
                  C:\Program Files\Spyware-Secure\resources\filesDesc_1-12.dat (Rogue.Spyware-Secure) -> Quarantined and deleted successfully.
                  C:\Documents and Settings\andrecalas\Menu Démarrer\NoCreditCard.lnk (Dialer) -> Quarantined and deleted successfully.


                  et voici le rapport Hijackthis :

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 11:51:18, on 26/08/2008
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16608)
                  Boot mode: Normal
                  
                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\WINDOWS\system32\acs.exe
                  C:\PROGRA~1\ANTIVI~1\backweb\6588780\Program\SERVIC~1.EXE
                  C:\Program Files\AntivirusFirewall\Anti-Virus\fsgk32st.exe
                  C:\Program Files\AntivirusFirewall\backweb\6588780\program\fsbwsys.exe
                  C:\Program Files\AntivirusFirewall\Anti-Virus\FSGK32.EXE
                  C:\Program Files\AntivirusFirewall\Common\FSMA32.EXE
                  C:\Program Files\AntivirusFirewall\Anti-Virus\fssm32.exe
                  C:\WINDOWS\System32\FTRTSVC.exe
                  C:\WINDOWS\System32\gearsec.exe
                  C:\Program Files\AntivirusFirewall\Common\FSMB32.EXE
                  C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  C:\WINDOWS\System32\nvsvc32.exe
                  C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\AntivirusFirewall\Common\FCH32.EXE
                  C:\Program Files\AntivirusFirewall\Common\FAMEH32.EXE
                  C:\Program Files\AntivirusFirewall\Anti-Virus\fsqh.exe
                  C:\Program Files\AntivirusFirewall\Anti-Virus\fsrw.exe
                  C:\Program Files\AntivirusFirewall\FWES\Program\fsdfwd.exe
                  C:\Program Files\AntivirusFirewall\Anti-Virus\fsav32.exe
                  C:\WINDOWS\system32\wuauclt.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\system32\wuauclt.exe
                  C:\Program Files\Apoint2K\Apoint.exe
                  C:\WINDOWS\AGRSMMSG.exe
                  C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                  C:\Program Files\iTunes\iTunesHelper.exe
                  C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
                  C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe
                  C:\Program Files\Apoint2K\Apntex.exe
                  C:\WINDOWS\System32\hphmon05.exe
                  C:\Program Files\iPod\bin\iPodService.exe
                  C:\PROGRA~1\MESSAG~1\StartMessager.exe
                  C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
                  C:\Program Files\QuickTime\qttask.exe
                  C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                  C:\Program Files\AntivirusFirewall\Common\FSM32.EXE
                  C:\Program Files\AntivirusFirewall\FSGUI\ispnews.exe
                  C:\PROGRA~1\ANTIVI~1\ANTI-S~1\fsaw.exe
                  C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
                  C:\Program Files\AntivirusFirewall\FSGUI\fsguidll.exe
                  C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\Messenger\msmsgs.exe
                  C:\Program Files\TRENDnet\TEW-441PC_443PI\TRENDnet.exe
                  C:\Program Files\AntivirusFirewall\backweb\6588780\Program\fspex.exe
                  C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
                  C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
                  C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                  C:\PROGRA~1\Wanadoo\ComComp.exe
                  C:\PROGRA~1\Wanadoo\Toaster.exe
                  C:\PROGRA~1\Wanadoo\Inactivity.exe
                  C:\PROGRA~1\Wanadoo\PollingModule.exe
                  C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                  C:\PROGRA~1\Wanadoo\Watch.exe
                  C:\Program Files\Trend Micro\HijackThis\monjack.exe
                  
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www8.hp.com/fr/fr/home.html
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://french.icrfast.com/index.php?rvs=hompag
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://side.search.ke.voila.fr
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  R3 - URLSearchHook: (no name) - {AEEC3B59-CA98-4EBA-A140-57B94E283583} - C:\PROGRA~1\ORANGE~1\TOOLBA~2.DLL
                  R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
                  R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                  O3 - Toolbar: barre d'outils Orange - {D3028143-6145-4318-99D3-3EDCE54A95A9} - C:\Program Files\Orange Toolbar FR\ToolbarContainer234.dll
                  O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
                  O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                  O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                  O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
                  O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
                  O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
                  O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
                  O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
                  O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
                  O4 - HKLM\..\Run: [MessagerStarter Wanadoo] C:\PROGRA~1\MESSAG~1\StartMessager.exe Messager Wanadoo
                  O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                  O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                  O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
                  O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe"  -osboot
                  O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\AntivirusFirewall\Common\FSM32.EXE" /splash
                  O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\AntivirusFirewall\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
                  O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\AntivirusFirewall\FSGUI\FSSW.EXE" /reboot
                  O4 - HKLM\..\Run: [News Service] "C:\Program Files\AntivirusFirewall\FSGUI\ispnews.exe"
                  O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                  O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                  O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                  O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                  O4 - Global Startup: 108Mbps Wireless LAN Adapte.lnk = C:\Program Files\TRENDnet\TEW-441PC_443PI\TRENDnet.exe
                  O4 - Global Startup: Antivirus Firewall.lnk = C:\Program Files\AntivirusFirewall\backweb\6588780\Program\fspex.exe
                  O4 - Global Startup: Image Transfer.lnk = ?
                  O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                  O8 - Extra context menu item: &Bloquer cette fenêtre publicitaire - C:\Program Files\AntivirusFirewall\Anti-Spyware\blockpopups.htm
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
                  O8 - Extra context menu item: traduire la page - C:\DOCUME~1\ANDREC~1\LOCALS~1\Temp\cceF5.html
                  O8 - Extra context menu item: traduire le texte sélectionné - C:\DOCUME~1\ANDREC~1\LOCALS~1\Temp\cceF6.html
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                  O9 - Extra button: Protection Internet Explorer - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\AntivirusFirewall\Anti-Spyware\ieshield.dll
                  O9 - Extra 'Tools' menuitem: Protection Internet Explorer... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\AntivirusFirewall\Anti-Spyware\ieshield.dll
                  O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSAG~1\Messager Wanadoo.exe
                  O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSAG~1\Messager Wanadoo.exe
                  O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                  O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
                  O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.encyclo.wanadoo.fr/JS/tdserver.cab
                  O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://hermes.ac-versailles.fr/qp2.cab
                  O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1095370272640
                  O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - https://www.3ds.com/products-services/3dvia/
                  O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                  O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL
                  O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
                  O23 - Service: Antivirus Firewall (BackWeb Plug-in - 6588780) - Securitoo Portal - C:\PROGRA~1\ANTIVI~1\backweb\6588780\Program\SERVIC~1.EXE
                  O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\AntivirusFirewall\Anti-Virus\fsgk32st.exe
                  O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\AntivirusFirewall\backweb\6588780\program\fsbwsys.exe
                  O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\AntivirusFirewall\FWES\Program\fsdfwd.exe
                  O23 - Service: FSMA - F-Secure Corporation - C:\Program Files\AntivirusFirewall\Common\FSMA32.EXE
                  O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                  O23 - Service: Service de sécurité matérielle (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
                  O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                  O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                  O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                  O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                  
                  --
                  End of file - 12766 bytes
                  1. Contributeur sécurité
                    Salut,

                    dans les deux cas, j'ai branché un disque dur externe, utilisé par un autre membre de la famille parfois

                    --> les as tu scanner avec Malwarebytes ?

                    1- Supprimes tout ce qu'il peut avoir dans la quarantaine de Malwarebytes ( via celle-ci bien sûr ).

                    2- refais un coup de CCleaner ( registre compris ) .

                    3- Mets à jours ce qui suit, c'est important ( des version pas à jours = failles de sécurité ) :
                    * pour la console Java :
                    aller sur : Démarrer > Panneau de configuration > Icône Java > onglet Mise à jour > "Mettre à jour maintenant" > cocher la case "Automatiser la détection des mises à jour".
                    ( puis désinstalles les versions antérieurs via "paneau de configuration" et "ajout/suppression de prg" ...)

                    * Adobe Reader :
                    télécharges et installes la dernière version ici (désinstalles avant l'ancienne version via son propre prg de désinstallation):
                    http://www.commentcamarche.net/telecharger/telecharger 27 acrobat reader

                    --> un fois cela fait , postes moi un nouveau rapport hijackthis pour contrôler et attends la suite ...

                    Ps : dis moi aussi comment va le PC ... du mieux ?
                    1. J'ai éliminé ce qui était en quarantaine avec MalwareBytes

                      Pour les mises à jours je vais les faire, mais là je suis sur une connexion 56 k et que c'est trop long, je vais attendre le 29 aout que je retrouve une connexion ADSL.

                      J'ai passé un coup de cleaner quand même.
                      ..

                      Merci pour l'aide
                      1. Contributeur sécurité
                        Au 29 pour finir alors ^^

                        Le PC va mieux ? ...