Probleme ordinateur qui rame

Bonjour,
Je viens chercher de l'aide depuis quelque temps mon ordinateur rame.Je viens d'utiliser le logiciel HijackThis .J'ai fait un scan et voila se que ça donne :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:35:07, on 18/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\GammaSutra.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\WINDOWS\system32\RunDLL32.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Tioseb\Bureau\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/toolbar/ie8/sidebar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/?gws_rd=ssl
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://actus.sfr.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/toolbar/ie8/sidebar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchasst.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/toolbar/ie8/sidebar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/toolbar/ie8/sidebar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/toolbar/ie8/sidebar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/search?q=%s
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = iexplore
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer avec Club-Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [GammaSutra] C:\Program Files\GammaSutra.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [EPSON Stylus C46 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE /P23 "EPSON Stylus C46 Series" /O6 "USB001" /M "Stylus C46"
O4 - HKLM\..\Run: [Printer] C:\WINDOWS\system32\vmmon32.exe
O4 - HKLM\..\RunServices: [Virtual CD V6] grplscd.exe
O4 - HKLM\..\RunServices: [Printer] C:\WINDOWS\system32\vmmon32.exe
O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Printer] C:\WINDOWS\system32\vmmon32.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?90e82ce96afc4460b09ad3d8a86d7750
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?90e82ce96afc4460b09ad3d8a86d7750
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O17 - HKLM\System\CS2\Services\Tcpip\..\{622508CC-364F-4376-9BB2-10ED0E281DB7}: NameServer = 194.117.200.10,194.117.200.15
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

--
End of file - 9421 bytes
Je doit avouer que je ne suis pas une experte niveau ordinateur .
Alors si quelqu'un peut m'aider merci.
Configuration: Windows XP
Firefox 3.0.3

25 réponses

Résumé de la discussion

Un PC sous Windows XP rame après un scan HijackThis, avec une longue liste de processus, modules et barres d’outil potentiellement indésirables. Plusieurs éléments de réponse recommandent de maintenir AVG et Spybot S&D, puis d’envisager un pare-feu alternatif et des outils de nettoyage tels que CCleaner et ToolsCleaner. Des propositions détaillent des actions pratiques: remplacer le pare-feu XP, désactiver puis réactiver la restauration système pour créer un point sain, puis redémarrer pour stabiliser l’ordinateur. En complément, des conseils évoquent l’utilisation d’outils anti-malware supplémentaires et l’analyse du système pour confirmer l’absence d’infection persistante après le nettoyage.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    bonsoir ;

    Tu est bien infecté !

    Tu vas faire ceci :

    Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
    http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
    Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
    • Redémarre ton ordinateur
    • Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
    • A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
    • Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
    • Choisis ton compte.
    Déroule la liste des instructions ci-dessous :
    • Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le scrïpt.
    • Appuie sur Y pour commencer le processus de nettoyage.
    • Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
    • Appuie sur une touche pour redémarrer le PC.
    • Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
    • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
    • Appuie sur une touche pour finir l'exécution du scrïpt et charger les icônes de ton Bureau.
    • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
    • Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum, avec un nouveau log Hijackthis !
    1. Tout d'abord merci!!! Je me sens moi seul...
      J'ai suivi tes recommandation et voila le résulta
      SDFix:

      [b]SDFix: Version 1.236 [/b]
      Run by Tioseb on 18/10/2008 at 21:24

      Microsoft Windows XP [version 5.1.2600]
      Running From: C:\SDFix

      [b]Checking Services [/b]:

      Restoring Default Security Values
      Restoring Default Hosts File

      Rebooting

      [b]Checking Files [/b]:

      Trojan Files Found:

      C:\Documents and Settings\Tioseb\Application Data\GDIPFONTCACHEV1.DAT - Deleted
      C:\WINDOWS\system32\TFTP1208 - Deleted

      Removing Temp Files

      [b]ADS Check [/b]:

      [b]Final Check [/b]:

      catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2008-10-18 21:35:37
      Windows 5.1.2600 Service Pack 2 NTFS

      scanning hidden processes ...

      scanning hidden services & system hive ...

      scanning hidden registry entries ...

      scanning hidden files ...

      scan completed successfully
      hidden processes: 0
      hidden services: 0
      hidden files: 0

      [b]Remaining Services [/b]:

      Authorized Application Key Export:

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
      "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
      "C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe:*:Enabled:avginet.exe"
      "C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
      "C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe:*:Enabled:avgcc.exe"
      "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
      "C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
      "C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Disabled:eMule MorphXT"
      "C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
      "C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:*:Enabled:ActiveSync Connection Manager"
      "C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:*:Enabled:ActiveSync Application"
      "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
      "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
      "C:\\Program Files\\AVG\\AVG8\\avgupd.exe"="C:\\Program Files\\AVG\\AVG8\\avgupd.exe:*:Enabled:avgupd.exe"
      "C:\\Program Files\\AVG\\AVG8\\avgemc.exe"="C:\\Program Files\\AVG\\AVG8\\avgemc.exe:*:Enabled:avgemc.exe"
      "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe:*:Enabled:hpqpse.exe"
      "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe:*:Enabled:hpqsudi.exe"
      "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe:*:Enabled:hpqpsapp.exe"

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
      "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
      "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
      "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
      "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe:*:Enabled:hpqpse.exe"
      "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe:*:Enabled:hpqsudi.exe"
      "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe:*:Enabled:hpqpsapp.exe"

      [b]Remaining Files [/b]:

      File Backups: - C:\SDFix\backups\backups.zip

      [b]Files with Hidden Attributes [/b]:

      Thu 19 Aug 2004 60,416 A.SH. --- "C:\Program Files\Outlook Express\msimn.exe"
      Mon 15 Sep 2008 1,562,960 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDHelper.dll"
      Thu 14 Aug 2008 1,429,840 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
      Wed 30 Jul 2008 4,891,984 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
      Tue 16 Sep 2008 1,833,296 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
      Sun 12 Nov 2006 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
      Mon 2 Jul 2007 0 A..H. --- "C:\Documents and Settings\Tioseb\Bureau\ParisHilton.exe"
      Fri 16 Nov 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"

      [b]Finished![/b]

      hijdackthis :
      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 21:44:59, on 18/10/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
      C:\WINDOWS\System32\svchost.exe
      C:\PROGRA~1\AVG\AVG8\avgrsx.exe
      C:\PROGRA~1\AVG\AVG8\avgemc.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\notepad.exe
      C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
      C:\Program Files\GammaSutra.exe
      C:\PROGRA~1\AVG\AVG8\avgtray.exe
      C:\WINDOWS\system32\LVCOMSX.EXE
      C:\WINDOWS\system32\RunDLL32.exe
      C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Documents and Settings\Tioseb\Bureau\HiJackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/toolbar/ie8/sidebar.html
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/?gws_rd=ssl
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://actus.sfr.fr
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/toolbar/ie8/sidebar.html
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchasst.htm
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
      R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/toolbar/ie8/sidebar.html
      R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/toolbar/ie8/sidebar.html
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/toolbar/ie8/sidebar.html
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/search?q=%s
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = iexplore
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer avec Club-Internet
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
      O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
      O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [GammaSutra] C:\Program Files\GammaSutra.exe
      O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
      O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
      O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
      O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
      O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
      O4 - HKLM\..\Run: [EPSON Stylus C46 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE /P23 "EPSON Stylus C46 Series" /O6 "USB001" /M "Stylus C46"
      O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
      O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?90e82ce96afc4460b09ad3d8a86d7750
      O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?90e82ce96afc4460b09ad3d8a86d7750
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
      O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
      O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
      O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
      O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
      O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
      O17 - HKLM\System\CS2\Services\Tcpip\..\{622508CC-364F-4376-9BB2-10ED0E281DB7}: NameServer = 194.117.200.10,194.117.200.15
      O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
      O20 - AppInit_DLLs: avgrsstx.dll
      O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
      O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
      1. Contributeur sécurité
        Alors qu'en pense tu??

        Je pense que si tu as cinq minutes ,tu pourrais lire ceci : danger des cracks et P2P

        ensuite ,on continu le nettoyage :

        Télécharges ComboFix à partir d'un de ces liens :

        http://download.bleepingcomputer.com/sUBs/ComboFix.exe
        https://forospyware.com
        http://www.geekstogo.com/forum/files/file/197-combofix-by-subs/

        Et important, enregistre le sur le bureau.

        Avant d'utiliser ComboFix :

        ? Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.

        ? Désactive provisoirement et seulement le temps de l'utilisation de ComboFix,
        la protection en temps réel de ton Antivirus et de tes Antispywares,
        qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.

        Une fois fait, sur ton bureau double-clic sur Combofix.exe.

        - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

        /!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.

        - En fin de scan il est possible que ComboFix ait besoin de redémarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

        - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt,.
        est automatiquement sauvegardé et rangé à C:\Combofix.txt)

        ? Réactive la protection en temps réel de ton Antivirus et de tes Antispywares,
        avant de te reconnecter à internet.

        ? Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.
        1. Voici le résulta :
          ComboFix 08-10-18.01 - Tioseb 2008-10-18 22:33:28.1 - NTFSx86
          Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.649 [GMT 2:00]
          Lancé depuis: C:\Documents and Settings\Tioseb\Bureau\ComboFix.exe

          [COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B][/COLOR]
          .

          (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
          .

          C:\Documents and Settings\Tioseb\Local Settings\Temporary Internet Files\pse_350_fra.exe
          C:\WINDOWS\pack.epk
          C:\WINDOWS\system32\AutoRun.inf
          C:\WINDOWS\system32\msssc.dll
          C:\WINDOWS\system32\vkqqanya.dat
          C:\WINDOWS\system32\vkqqanya.exe
          C:\WINDOWS\system32\vkqqanya_nav.dat
          C:\WINDOWS\system32\vkqqanya_navps.dat

          .
          ((((((((((((((((((((((((((((( Fichiers créés du 2008-09-18 au 2008-10-18 ))))))))))))))))))))))))))))))))))))
          .

          2008-10-18 21:21 . 2008-10-18 21:21 <REP> d-------- C:\WINDOWS\ERUNT
          2008-10-18 21:02 . 2008-10-18 21:38 <REP> d-------- C:\SDFix
          2008-10-18 19:42 . 2008-10-18 19:42 <REP> d-------- C:\Program Files\RegCleaner
          2008-09-28 11:11 . 2007-12-07 14:13 111,292 --------- C:\WINDOWS\hpqins13.dat.temp

          .
          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          2008-10-18 20:27 12 -c--a-w C:\Program Files\GammaSutra.sav
          2008-10-05 11:01 --------- d-----w C:\Documents and Settings\Tioseb\Application Data\HLSW
          2008-10-04 10:07 --------- d-----w C:\Program Files\Java
          2008-10-02 10:44 --------- d-----w C:\Program Files\Spybot - Search & Destroy
          2008-09-11 16:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
          2008-09-10 20:58 --------- d--h--w C:\Program Files\InstallShield Installation Information
          2008-09-10 19:33 --------- d-----w C:\Program Files\Logitech
          2008-09-10 19:33 --------- d-----w C:\Program Files\Fichiers communs\FotoWire
          2008-09-10 19:33 --------- d-----w C:\Documents and Settings\Tioseb\Application Data\FotoWire
          2008-09-09 20:40 --------- d-----w C:\Documents and Settings\Tioseb\Application Data\vlc
          2008-09-09 20:39 --------- d-----w C:\Program Files\VideoLAN
          2008-09-05 14:17 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
          2008-09-02 09:24 97,928 ----a-w C:\WINDOWS\system32\drivers\avgldx86.sys
          2007-05-19 15:18 632 -c--a-w C:\Program Files\servers.ini
          2007-05-19 15:18 5,994 -c--a-w C:\Program Files\mirc.ini
          2007-01-03 10:38 58 -c--a-w C:\Program Files\perform.ini
          2003-06-08 16:15 9,216 ----a-w C:\Program Files\GammaSutra.exe
          .

          ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          .
          *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
          REGEDIT4

          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
          "NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2006-10-22 7700480]
          "GammaSutra"="C:\Program Files\GammaSutra.exe" [2003-06-08 9216]
          "AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-09-29 1234712]
          "LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2004-10-08 221184]
          "Smapp"="C:\Program Files\Analog Devices\SoundMAX\SMTray.exe" [2003-05-05 143360]
          "hpqSRMon"="C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016]
          "nwiz"="nwiz.exe" [2006-10-22 C:\WINDOWS\system32\nwiz.exe]
          "NvMediaCenter"="NvMCTray.dll" [2006-10-22 C:\WINDOWS\system32\nvmctray.dll]

          [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
          "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 15360]

          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
          "AppInit_DLLs"=avgrsstx.dll

          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
          "msacm.divxa32"= DivXa32.acm
          "msacm.avis"= ff_acm.acm
          "MSACM.CEGSM"= mobilev.acm

          [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^LE COMPAGNON CLUB.lnk]
          path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\LE COMPAGNON CLUB.lnk
          backup=C:\WINDOWS\pss\LE COMPAGNON CLUB.lnkCommon Startup

          [HKLM\~\startupfolder\C:^Documents and Settings^Tioseb^Menu Démarrer^Programmes^Démarrage^Club Internet.lnk]
          path=C:\Documents and Settings\Tioseb\Menu Démarrer\Programmes\Démarrage\Club Internet.lnk
          backup=C:\WINDOWS\pss\Club Internet.lnkStartup

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BJCFD]
          --a------ 2003-01-27 17:16 376912 C:\Program Files\BroadJump\Client Foundation\CFD.exe

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
          --a------ 2005-01-19 16:18 405583 C:\Program Files\Microsoft ActiveSync\wcescomm.exe

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
          --a--c--- 2007-03-11 22:34 49152 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
          --a------ 2008-08-20 10:54 150016 C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ITunesHelper]
          --a--c--- 2007-03-14 19:05 257088 C:\Program Files\iTunes\iTunesHelper.exe

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
          --a------ 2004-10-08 12:06 196608 C:\Program Files\Logitech\Video\ManifestEngine.exe

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
          --a------ 2004-10-08 12:31 458752 C:\Program Files\Logitech\Video\ISStart.exe

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
          --a------ 2004-10-08 12:24 217088 C:\Program Files\Logitech\Video\LogiTray.exe

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
          --a------ 2004-10-08 11:52 221184 C:\WINDOWS\system32\LVCOMSX.EXE

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
          --a------ 2006-04-21 15:41 438359 C:\PROGRA~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Msnmsgr]
          --a--c--- 2007-01-19 12:55 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
          --a--c--- 2007-02-16 10:54 282624 C:\Program Files\QuickTime\qttask.exe

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
          --a------ 2008-10-08 18:15 1410296 c:\Valve\Steam\Steam.exe

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SteamRS]
          --a------ 2008-10-08 18:15 1410296 C:\Valve\Steam\Steam.exe

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SuperCopier.exe]
          --a--c--- 2003-04-25 00:03 683520 C:\Program Files\SuperCopier\SuperCopier.exe

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
          --a------ 2007-12-02 16:18 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
          "RDSessMgr"=3 (0x3)
          "RasMan"=3 (0x3)
          "RasAuto"=3 (0x3)
          "iPod Service"=3 (0x3)
          "ImapiService"=3 (0x3)
          "wuauserv"=2 (0x2)
          "usnjsvc"=3 (0x3)
          "TapiSrv"=3 (0x3)

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
          "EnableFirewall"= 0 (0x0)

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
          "%windir%\\system32\\sessmgr.exe"=
          "C:\\Program Files\\iTunes\\iTunes.exe"=
          "C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"=
          "C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"=
          "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
          "C:\\Program Files\\MSN Messenger\\livecall.exe"=
          "C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
          "C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
          "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"=
          "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"=
          "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"=

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
          "4661:TCP"= 4661:TCP:*:Disabled:Emule
          "4672:UDP"= 4672:UDP:*:Disabled:Emule2

          R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-09-02 97928]
          R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-09-02 875288]
          R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-09-02 231704]
          R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-04 76040]
          R3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2006-12-20 45568]
          R3 whfltr2k;WheelMouse USB Lower Filter Driver;C:\WINDOWS\system32\DRIVERS\whfltr2k.sys [2005-11-03 6784]
          S2 PSTRIP;PSTRIP;C:\WINDOWS\system32\DRIVERS\PSTRIP.SYS [ ]
          S3 whmice2k;4D Mouse Upper Filter Driver;C:\WINDOWS\system32\DRIVERS\whmice2k.sys [2004-04-26 6885]

          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
          HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
          hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

          *Newly Created Service* - PROCEXP90
          .
          Contenu du dossier 'Tâches planifiées'

          2007-05-01 C:\WINDOWS\Tasks\defrag_cd.job
          - C:\defrag_cd.cmd [2006-04-19 17:48]
          .
          - - - - ORPHELINS SUPPRIMES - - - -

          HKCU-Run-WhenUSave - C:\Program Files\Save\Save.exe
          HKLM-Run-EPSON Stylus C46 Series - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE
          HKLM-Run-StandardInstall - (no file)
          MSConfigStartUp-Msmsgs - C:\Program Files\Messenger\msmsgs.exe
          MSConfigStartUp-RealTray - C:\Program Files\Real\RealPlayer\RealPlay.exe
          MSConfigStartUp-TkBellExe - C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
          MSConfigStartUp-Wookit - C:\Program Files\Wanadoo\Shell.exe
          MSConfigStartUp-Virtual CD V6 - grplscd.exe

          .
          ------- Examen supplémentaire -------
          .
          FireFox -: Profile - C:\Documents and Settings\Tioseb\Application Data\Mozilla\Firefox\Profiles\60tj47wk.default\
          FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.fr
          FF -: plugin - C:\Program Files\Adobe\Acrobat 5.0\Reader\browser\nppdf32.dll
          FF -: plugin - C:\WINDOWS\system32\Cult3D\NPMCult3DP.dll
          .

          **************************************************************************

          catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2008-10-18 22:35:36
          Windows 5.1.2600 Service Pack 2 NTFS

          Recherche de processus cachés ...

          Recherche d'éléments en démarrage automatique cachés ...

          Recherche de fichiers cachés ...

          C:\DOCUME~1\Tioseb\LOCALS~1\Temp\RGI1C.tmp

          Scan terminé avec succès
          Fichiers cachés: 1

          **************************************************************************
          .
          Heure de fin: 2008-10-18 22:37:25
          ComboFix-quarantined-files.txt 2008-10-18 20:37:19

          Avant-CF: 7,646,720,000 octets libres
          Après-CF: 7,666,196,480 octets libres

          182 --- E O F --- 2007-09-13 07:34:37
          1. Contributeur sécurité
            GoOd !

            On continu :

            Clique sur ce lien :
            http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
            pour télécharger navilog1.exe.

            Choisis Enregistrer

            et enregistre-le sur ton bureau.

            Ensuite double clique sur navilog1.exe pour lancer l'installation.

            double-clique sur le raccourci Navilog1 présent sur le bureau .

            Laisse-toi guider. Au menu principal, choisis 1 et valides.
            (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

            Patiente jusqu'au message :
            *** Analyse Termine le ..... ***
            Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
            Copie-colle l'intégralité du rapport dans ta réponse. Referme le blocnote.
            Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)
            1. Voici le nouveaux résulta :
              Search Navipromo version 3.6.6 commencé le 18/10/2008 à 22:55:38,37

              !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
              !!! Postez ce rapport sur le forum pour le faire analyser !!!
              !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

              Outil exécuté depuis C:\Program Files\navilog1
              Session actuelle : "Tioseb"

              Mise à jour le 29.09.2008 à 17h30 par IL-MAFIOSO

              Microsoft Windows XP [version 5.1.2600]
              Internet Explorer : 6.0.2900.2180
              Système de fichiers : NTFS

              Recherche executé en mode normal

              *** Recherche Programmes installés ***

              *** Recherche dossiers dans "C:\WINDOWS" ***

              *** Recherche dossiers dans "C:\Program Files" ***

              *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

              *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***

              *** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***

              *** Recherche dossiers dans "C:\Documents and Settings\Tioseb\applic~1" ***

              *** Recherche dossiers dans "C:\Documents and Settings\Tioseb\locals~1\applic~1" ***

              *** Recherche dossiers dans "C:\Documents and Settings\Tioseb\menudm~1\progra~1" ***

              *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
              pour + d'infos : http://www.gmer.net

              *** Recherche avec GenericNaviSearch ***
              !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
              !!! A vérifier impérativement avant toute suppression manuelle !!!

              * Recherche dans "C:\WINDOWS\system32" *

              * Recherche dans "C:\Documents and Settings\Tioseb\locals~1\applic~1" *

              *** Recherche fichiers ***

              *** Recherche clés spécifiques dans le Registre ***

              *** Module de Recherche complémentaire ***
              (Recherche fichiers spécifiques)

              1)Recherche nouveaux fichiers Instant Access :

              2)Recherche Heuristique :

              * Dans "C:\WINDOWS\system32" :

              * Dans "C:\Documents and Settings\Tioseb\locals~1\applic~1" :

              3)Recherche Certificats :

              Certificat Egroup absent !
              Certificat Electronic-Group trouvé !
              Certificat Montorgueil absent !
              Certificat OOO-Favorit trouvé !
              Certificat Sunny-Day-Design-Ltd absent !

              4)Recherche fichiers connus :

              *** Analyse terminée le 18/10/2008 à 23:00:57,48 ***
              1. Contributeur sécurité
                hello ,bien dormi ?

                On est reparti :

                Double clique sur le raccourci Navilog1 présent sur le bureau et laisse-toi guider.
                Au menu principal, choisis 2 et valide.

                Le fix va t'informer qu'il va alors redémarrer ton PC
                Ferme toutes les fenêtres ouvertes et enregistre tes documents personnels ouverts
                Appuie sur une touche comme demandé.
                (si ton Pc ne redémarre pas automatiquement, fais le toi même)
                Au redémarrage de ton PC, choisis ta session habituelle.

                Patiente jusqu'au message :
                *** Nettoyage Termine le ..... ***
                Le blocnote va s'ouvrir.
                Sauvegarde le rapport de manière à le retrouver
                Referme le blocnote. Ton bureau va réapparaitre

                PS:Si ton bureau ne réapparait pas, fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.
                Puis rends-toi à l'onglet "processus". Clique en haut à gauche sur fichiers et choisis "exécuter"
                Tape explorer et valide. Celà te fera apparaitre ton bureau.

                Postes le rapport içi.

                Cet adware est installé, entre autre, par les programmes :go-astro - Instant Access - InternetGameBox - GoRecord -
                HotTVPlayer - MailSkinner - Messenger Skinner - sudoplanet - Webmediaplayer


                Ensuite tu me recolles un nouveau hijack histoire de voir ou on en est .
                1. Bonjour,merci plutôt bien dormi et toi la nuit fut agréable ??i.Alors j'ai suivi ce que tu ma dit.
                  rapport navilog :

                  * Dans "C:\Documents and Settings\Tioseb\locals~1\applic~1" *

                  *** Sauvegarde du Registre vers dossier Safebackup ***

                  sauvegarde du Registre réalisée avec succès !

                  *** Nettoyage Registre ***

                  Nettoyage Registre Ok

                  *** Certificats ***

                  Certificat Egroup absent !
                  Certificat Electronic-Group supprimé !
                  Certificat Montorgueil absent !
                  Certificat OOO-Favorit supprimé !
                  Certificat Sunny-Day-Design-Ltdt absent !

                  *** Nettoyage terminé le 19/10/2008 à 10:22:51,65 ***

                  Rapport hijackthis :
                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 10:27:25, on 19/10/2008
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\nvsvc32.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                  C:\PROGRA~1\AVG\AVG8\avgemc.exe
                  C:\WINDOWS\system32\wscntfy.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\notepad.exe
                  C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                  C:\Program Files\GammaSutra.exe
                  C:\PROGRA~1\AVG\AVG8\avgtray.exe
                  C:\WINDOWS\system32\LVCOMSX.EXE
                  C:\WINDOWS\system32\RunDLL32.exe
                  C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
                  C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\Documents and Settings\Tioseb\Bureau\HiJackThis.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://actus.sfr.fr
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchasst.htm
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/toolbar/ie8/sidebar.html
                  R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/search?q=%s
                  R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = iexplore
                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
                  O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
                  O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                  O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                  O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
                  O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                  O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                  O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                  O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                  O4 - HKLM\..\Run: [GammaSutra] C:\Program Files\GammaSutra.exe
                  O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                  O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
                  O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
                  O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
                  O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
                  O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                  O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                  O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                  O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
                  O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?90e82ce96afc4460b09ad3d8a86d7750
                  O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?90e82ce96afc4460b09ad3d8a86d7750
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                  O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
                  O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
                  O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
                  O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                  O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                  O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
                  O17 - HKLM\System\CS2\Services\Tcpip\..\{622508CC-364F-4376-9BB2-10ED0E281DB7}: NameServer = 194.117.200.10,194.117.200.15
                  O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                  O20 - AppInit_DLLs: avgrsstx.dll
                  O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
                  O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                  O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                  1. Contributeur sécurité
                    re;

                    Il va falloir analyser un ou des fichier(s) suspect(s) !

                    Il se peut qu'il se trouvent dans les " dossiers cachés " du systeme.
                    Il faut donc les rendre visibles pour le scan.

                    Pour afficher les dossiers et fichiers cachés:

                    Panneau de configuration > Options des dossiers > onglet Affichage.

                    Coche Afficher les fichiers et dossiers cachés,
                    Décoche Masquer les extensions de fichiers connus
                    Décoche Masquer les fichiers protégés du Système.
                    Un message de mise en garde va apparaitre. Clique sur OK pour confirmer ton choix.
                    Les fichiers et dossiers cachés du système apparaitront alors dans l'explorateur Windows en transparence.

                    Rends toi sur ce site :

                    https://www.virustotal.com/gui/

                    Clique sur parcourir et cherche ces fichiers : C:\Program Files\GammaSutra.exe

                    Clique sur Send File.

                    Un rapport va s'élaborer ligne à ligne.

                    Attends la fin. Il doit comprendre la taille du fichier envoyé.

                    Sauvegarde le rapport avec le bloc-note.

                    Copie le dans ta réponse.

                    Ensuite :

                    ==> Télécharge OAD http://sosvirus.changelog.fr/OAD.exe
                    - Enregistre le sur ton bureau

                    Double clique sur le OAD pour le lancer

                    - nom de fichier à rechercher tape ou fais un copier coller de : nwiz.exe
                    - Type de recherche : sélectionne l'option 6 puis valide [entree]

                    OAD va maintenant rechercher le fichier. Laisse le travailler jusqu'à ce qu'il en ai terminé.
                    Le rapport de recherche s'affichera automatiquement à dès qu'il en aura terminé.

                    - Fais un copier / coller de ce rapport dans ton prochain post.

                    Note importante : Suivant la taille des disques dur cette recherche peut prendre plusieurs minutes. Sois patient
                    1. Alors résulta virustotal :

                      Fichier GammaSutra.exe reçu le 2008.10.02 15:04:02 (CET)
                      Situation actuelle: terminé
                      Résultat: 5/36 (13.89%)
                      Formaté Formaté
                      Impression des résultats Impression des résultats
                      Antivirus Version Dernière mise à jour Résultat
                      AhnLab-V3 2008.10.2.0 2008.10.02 -
                      AntiVir 7.8.1.34 2008.10.02 -
                      Authentium 5.1.0.4 2008.10.02 W32/Downloader.AJLL
                      Avast 4.8.1248.0 2008.10.01 -
                      AVG 8.0.0.161 2008.10.02 -
                      BitDefender 7.2 2008.10.02 -
                      CAT-QuickHeal 9.50 2008.10.01 -
                      ClamAV 0.93.1 2008.10.02 -
                      DrWeb 4.44.0.09170 2008.10.02 -
                      eSafe 7.0.17.0 2008.10.01 -
                      eTrust-Vet 31.6.6121 2008.10.02 -
                      Ewido 4.0 2008.10.02 -
                      F-Prot 4.4.4.56 2008.10.02 W32/Downloader.AJLL
                      F-Secure 8.0.14332.0 2008.10.02 -
                      Fortinet 3.113.0.0 2008.10.02 -
                      GData 19 2008.10.02 -
                      Ikarus T3.1.1.34.0 2008.10.02 Virus.Win32.Trojan
                      K7AntiVirus 7.10.481 2008.10.02 Trojan.Win32.Malware.1
                      Kaspersky 7.0.0.125 2008.10.02 -
                      McAfee 5396 2008.10.02 -
                      Microsoft 1.4005 2008.10.02 -
                      NOD32 3489 2008.10.02 -
                      Norman 5.80.02 2008.10.02 -
                      Panda 9.0.0.4 2008.10.02 -
                      PCTools 4.4.2.0 2008.10.02 -
                      Prevx1 V2 2008.10.02 Worm
                      Rising 20.63.62.00 2008.09.28 -
                      SecureWeb-Gateway 6.7.6 2008.10.02 -
                      Sophos 4.34.0 2008.10.02 -
                      Sunbelt 3.1.1675.1 2008.09.27 -
                      Symantec 10 2008.10.02 -
                      TheHacker 6.3.0.9.098 2008.10.01 -
                      TrendMicro 8.700.0.1004 2008.10.02 -
                      VBA32 3.12.8.6 2008.10.02 -
                      ViRobot 2008.10.2.1403 2008.10.02 -
                      VirusBuster 4.5.11.0 2008.10.01 -
                      Information additionnelle
                      File size: 9216 bytes
                      MD5...: 5d882f7f6616c4fa51e935cba5823557
                      SHA1..: 5574932535ddaecc7e3d3735608d904689b1e895
                      SHA256: f8c8abe58bf76ac032c23e73ca01c841f80fcaf06a4667c92d3edd503529d31a
                      SHA512: 2ffd840fa72cef559a56748f4320c8bc88642cb747acdf78de8d172638a624dc
                      3e247826047175ed3f85b757aec66e64f4c708eb0b1955a38c1808e6ae01817f
                      PEiD..: -
                      TrID..: File type identification
                      Win32 Executable Generic (68.0%)
                      Generic Win/DOS Executable (15.9%)
                      DOS Executable Generic (15.9%)
                      Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
                      PEInfo: PE Structure information

                      ( base data )
                      entrypointaddress.: 0x401030
                      timedatestamp.....: 0x3ee35322 (Sun Jun 08 15:15:46 2003)
                      machinetype.......: 0x14c (I386)

                      ( 5 sections )
                      name viradd virsiz rawdsiz ntrpy md5
                      .text 0x1000 0xfca 0x1000 5.50 516bb0d653de7c4e03f7d61763ecb738
                      .rdata 0x2000 0x4e6 0x600 4.21 27739d9b2e4f6347bd4016276450fabe
                      .data 0x3000 0xd7c 0x200 2.60 10b60f87936afe86757b4527294c7320
                      share 0x4000 0x4 0x200 0.00 bf619eac0cdf3f68d496ea9344137e8b
                      .rsrc 0x5000 0x500 0x600 2.49 9c3a0d50892710e2876f0111ea43f8bd

                      ( 6 imports )
                      > kernel32.dll: ReadFile, lstrcatA, GetModuleFileNameA, ExitProcess, CreateFileA, lstrlenA, WriteFile, GetModuleHandleA, lstrcpyA, CloseHandle
                      > user32.dll: ReleaseDC, SendDlgItemMessageA, SendMessageA, SetForegroundWindow, SetWindowPos, MessageBoxA, TrackPopupMenu, UnregisterHotKey, LoadIconA, GetWindowRect, ShowWindow, PostMessageA, GetSystemMetrics, GetDC, GetCursorPos, EndDialog, DialogBoxParamA, DestroyIcon, CreatePopupMenu, AppendMenuA, RegisterHotKey
                      > comctl32.dll: InitCommonControls
                      > shell32.dll: Shell_NotifyIconA
                      > gdi32.dll: SetDeviceGammaRamp
                      > advapi32.dll: RegSetValueExA, RegCloseKey, RegDeleteValueA, RegOpenKeyExA, RegCreateKeyExA, RegOpenKeyA, RegQueryValueExA

                      ( 0 exports )
                      Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=B9834D6E0052478624510069568FE5004D516EB2
                      ThreatExpert info: https://www.symantec.com?md5=5d882f7f6616c4fa51e935cba5823557

                      ATENTION ATTENTION: VirusTotal est un service gratuit offert par Hispasec Sistemas. Il n'y a aucune garantie quant à la disponibilité et la continuité de ce service. Bien que le taux de détection permis par l'utilisation de multiples moteurs antivirus soit bien supérieur à celui offert par seulement un produit, ces résultats NE garantissent PAS qu'un fichier est sans danger. Il n'y a actuellement aucune solution qui offre un taux d'efficacité de 100% pour la détection des virus et malwares.

                      OAD :
                      19/10/2008 ---- 11:23:13,04

                      ----------------------------------
                      §§§§§§ [ nwiz.exe ] §§§§§§
                      ----------------------------------
                      [X] Registre

                      -------------- [ ] rapide
                      -- Fichier --- [ ] disque systeme
                      ------------- [X] complete

                      ********************
                      [Registre]
                      ********************

                      Aucune entrée détectée

                      *******************
                      [Fichier]
                      *******************

                      *********************
                      [Même date]
                      *********************

                      Aucun fichier créé à la même date détecté

                      Outil Aide Diagnostic By !aur3n7 Version 1.1
                      ----------------------------------
                      §§§§§ Fin Rapport §§§§§
                      ----------------------------------
                      1. Contributeur sécurité
                        pour nwizz.exe il appartient apparement au cartes graphiques Nvidia donc pas de soucis mais en ce qui concerne GammaSutra.exe lui est bien infecté par un troyen .

                        Télécharge OTMoveIt3 de OldTimer sur ton Bureau en cliquant sur ce lien :

                        http://oldtimer.geekstogo.com/OTMoveIt3.exe

                        Double-clique sur OTMoveIt3.exe pour le lancer.

                        Vérifie que la case devant "Unregister Dll's and Ocx's est bien cochée.

                        Copie la liste qui se trouve en gras ci-dessous,

                        et colle-la dans le cadre de gauche de OTMoveIt : "Paste instructions for item to be moved".

                        C:\Program Files\GammaSutra.exe

                        Clique sur "MoveIt!" pour lancer la suppression.

                        Le résultat apparaitra dans le cadre "Results".

                        Clique sur "Exit" pour fermer.

                        Poste le rapport situé dans C:\_OTMoveIt\MovedFiles sous le nom xxxxxx_xxxxxxxxxx.log .

                        Il te sera peut-être demander de redémarrer le pc pour achever la suppression. Si c'est le cas accepte par Yes.

                        Ensuite pour vérifier :

                        1) Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

                        2) Télécharge Malwarebytes' Anti-Malware (MBAM) et enregistre le sur ton Bureau à partir de ce lien :

                        https://www.malwarebytes.com/

                        3) A la fin du téléchargement, ferme toutes les fenêtres et programmes, y compris celui-ci.

                        4) Double-clique sur l'icône Download_mbam-setup.exe sur ton bureau pour démarrer le programme d'installation.

                        5) Pendant l'installation, suis les indications (en particulier le choix de la langue et l'autorisation d'accession à Internet). N'apporte aucune modification aux réglages par défaut et, en fin d'installation, vérifie que les options Update Malwarebytes' Anti-Malware et Launch Malwarebytes' Anti-Malware sont cochées.

                        6) MBAM démarrera automatiquement et enverra un message demandant à mettre à jour le programme avant de lancer une analyse. Comme MBAM se met automatiquement à jour en fin d'installation, clique sur OK pour fermer la boîte de dialogue. La fenêtre principale de MBAM s'affiche :

                        7) Dans l'onglet analyse, vérifie que "Exécuter un examen complet" est coché et clique sur le bouton Rechercher pour démarrer l'analyse.

                        8) MBAM analyse ton ordinateur. L'analyse peut prendre un certain temps. Il suffit de vérifier de temps en temps son avancement.

                        9) A la fin de l'analyse, un message s'affiche indiquant la fin de l'analyse. Clique sur OK pour poursuivre.

                        10) Si des malwares ont été détectés, leur liste s'affiche.
                        En cliquant sur Suppression (?) , MBAM va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.

                        11) MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Ferme le Bloc-notes. (Le rapport peut être retrouvé sous l'onglet Rapports/logs)

                        12) Ferme MBAM en cliquant sur Quitter.

                        13) Poste le rapport dans ta réponse

                        Apres ça dis moi si tu as encore des soucis ?

                        1. rapport OTMoveIt3 :

                          Error: Unable to interpret <C:\Program Files\GammaSutra.exe > in the current context!

                          OTMoveIt3 by OldTimer - Version 1.0.5.0 log created on 10192008_114920

                          rapport Malwarebytes :

                          Malwarebytes' Anti-Malware 1.29
                          Version de la base de données: 1288
                          Windows 5.1.2600 Service Pack 2

                          19/10/2008 13:17:19
                          mbam-log-2008-10-19 (13-17-19).txt

                          Type de recherche: Examen complet (C:\|D:\|F:\|)
                          Eléments examinés: 107983
                          Temps écoulé: 1 hour(s), 4 minute(s), 45 second(s)

                          Processus mémoire infecté(s): 0
                          Module(s) mémoire infecté(s): 0
                          Clé(s) du Registre infectée(s): 1
                          Valeur(s) du Registre infectée(s): 0
                          Elément(s) de données du Registre infecté(s): 0
                          Dossier(s) infecté(s): 0
                          Fichier(s) infecté(s): 0

                          Processus mémoire infecté(s):
                          (Aucun élément nuisible détecté)

                          Module(s) mémoire infecté(s):
                          (Aucun élément nuisible détecté)

                          Clé(s) du Registre infectée(s):
                          HKEY_LOCAL_MACHINE\SOFTWARE\WhenUSave (Adware.WhenUSave) -> Quarantined and deleted successfully.

                          Valeur(s) du Registre infectée(s):
                          (Aucun élément nuisible détecté)

                          Elément(s) de données du Registre infecté(s):
                          (Aucun élément nuisible détecté)

                          Dossier(s) infecté(s):
                          (Aucun élément nuisible détecté)

                          Fichier(s) infecté(s):
                          (Aucun élément nuisible détecté)

                          Sinon il y a du mieux le pc subit moins de ralentissement
                          1. Contributeur sécurité
                            il y a eu comme une erreur avec Otmoveit ...

                            On va vérifier si le fichier est encore présent :

                            ==> Télécharge OAD http://sosvirus.changelog.fr/OAD.exe
                            - Enregistre le sur ton bureau

                            Double clique sur le OAD pour le lancer

                            - nom de fichier à rechercher tape ou fais un copier coller de : GammaSutra
                            - Type de recherche : sélectionne l'option 6 puis valide [entree]

                            OAD va maintenant rechercher le fichier. Laisse le travailler jusqu'à ce qu'il en ai terminé.
                            Le rapport de recherche s'affichera automatiquement à dès qu'il en aura terminé.

                            - Fais un copier / coller de ce rapport dans ton prochain post.

                            Note importante : Suivant la taille des disques dur cette recherche peut prendre plusieurs minutes. Sois patient

                            1. Voici le rapport avec oad :

                              19/10/2008 ---- 13:41:28,85

                              ----------------------------------
                              §§§§§§ [GammaSutra ] §§§§§§
                              ----------------------------------
                              [X] Registre

                              -------------- [ ] rapide
                              -- Fichier --- [ ] disque systeme
                              ------------- [X] complete

                              ********************
                              [Registre]
                              ********************

                              Aucune entrée détectée

                              *******************
                              [Fichier]
                              *******************
                              1. Contributeur sécurité

                                Double-clique sur OTMoveIt3.exe pour le lancer.

                                Vérifie que la case devant "Unregister Dll's and Ocx's est bien cochée.

                                Copie la liste qui se trouve en gras ci-dessous,

                                et colle-la dans le cadre de gauche de OTMoveIt : "Paste instructions for item to be moved".

                                :file
                                C:\Program Files\GammaSutra.exe


                                Clique sur "MoveIt!" pour lancer la suppression.

                                Le résultat apparaitra dans le cadre "Results".

                                Clique sur "Exit" pour fermer.

                                Poste le rapport situé dans C:\_OTMoveIt\MovedFiles sous le nom xxxxxx_xxxxxxxxxx.log .

                                Il te sera peut-être demander de redémarrer le pc pour achever la suppression. Si c'est le cas accepte par Yes.
                                1. Contributeur sécurité
                                  re; faute de frappes ;)

                                  Double-clique sur OTMoveIt3.exe pour le lancer.

                                  Vérifie que la case devant "Unregister Dll's and Ocx's est bien cochée.

                                  Copie la liste qui se trouve en gras ci-dessous,

                                  et colle-la dans le cadre de gauche de OTMoveIt : "Paste instructions for item to be moved".

                                  :files
                                  C:\Program Files\GammaSutra.exe


                                  Clique sur "MoveIt!" pour lancer la suppression.

                                  Le résultat apparaitra dans le cadre "Results".

                                  Clique sur "Exit" pour fermer.

                                  Poste le rapport situé dans C:\_OTMoveIt\MovedFiles sous le nom xxxxxx_xxxxxxxxxx.log .

                                  Il te sera peut-être demander de redémarrer le pc pour achever la suppression. Si c'est le cas accepte par Yes.

                                  j'avais oublié le S...
                                  1. Bonjour
                                    Alors je ne comprends pas il doit y avoir un problème avec OTMoveIt3.exe .Je suis tes instruction donc je lance la suppression tout se passe bien et il me fait redémarrer le pc .Une fois le pc redémarrer plus de trace de OTMoveIt3.exe .J'ai effectuer une rechercher et le seul fichier qu'il me trouve c'est OTMOVEIT3.EXE-067A6143.pf qui se trouve dans le dossier C:\WINDOWS\prefetch.
                                    As tu une idée ???
                                2. Contributeur sécurité
                                  salut chloé ;

                                  Retélécharge Otmoveit et relance le comme indiqué post#16 .
                                  1. Ah apparemment mea-culpa surement mauvaise manipe de ma part!!! Ça fonctionne mais il na pas redémarre le pc .
                                    Voici le rapport :
                                    ========== FILES ==========
                                    C:\Program Files\GammaSutra.exe moved successfully.

                                    OTMoveIt3 by OldTimer - Version 1.0.5.0 log created on 10202008_202613
                                    1. Contributeur sécurité
                                      t'as bien bossé !

                                      reposte un hijack pour finir .
                                      1. le voici :

                                        Logfile of Trend Micro HijackThis v2.0.2
                                        Scan saved at 23:22:04, on 20/10/2008
                                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                                        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                                        Boot mode: Normal

                                        Running processes:
                                        C:\WINDOWS\System32\smss.exe
                                        C:\WINDOWS\system32\winlogon.exe
                                        C:\WINDOWS\system32\services.exe
                                        C:\WINDOWS\system32\lsass.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\WINDOWS\System32\svchost.exe
                                        C:\WINDOWS\system32\spoolsv.exe
                                        C:\WINDOWS\Explorer.EXE
                                        C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\WINDOWS\System32\svchost.exe
                                        C:\WINDOWS\system32\nvsvc32.exe
                                        C:\WINDOWS\System32\svchost.exe
                                        C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                                        C:\WINDOWS\System32\svchost.exe
                                        C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                                        C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                                        C:\PROGRA~1\AVG\AVG8\avgemc.exe
                                        C:\PROGRA~1\AVG\AVG8\avgtray.exe
                                        C:\WINDOWS\system32\LVCOMSX.EXE
                                        C:\WINDOWS\system32\RunDLL32.exe
                                        C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
                                        C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
                                        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                        C:\WINDOWS\system32\wscntfy.exe
                                        C:\Valve\Steam\Steam.exe
                                        C:\Program Files\Club-Internet\Lanceur\lanceur.exe
                                        C:\Program Files\Logitech\Video\Editor2.exe
                                        C:\Program Files\Mozilla Firefox\firefox.exe
                                        C:\Documents and Settings\Tioseb\Bureau\HiJackThis.exe

                                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://actus.sfr.fr
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchasst.htm
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/toolbar/ie8/sidebar.html
                                        R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/search?q=%s
                                        R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = iexplore
                                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                        O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
                                        O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
                                        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                                        O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                                        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                                        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                        O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                                        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
                                        O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                        O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                                        O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                                        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                                        O4 - HKLM\..\Run: [GammaSutra] C:\Program Files\GammaSutra.exe
                                        O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                                        O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
                                        O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
                                        O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
                                        O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
                                        O4 - HKLM\..\Run: [EPSON Stylus C46 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE /P23 "EPSON Stylus C46 Series" /O6 "USB001" /M "Stylus C46"
                                        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                                        O4 - HKLM\..\Run: [Printer] C:\WINDOWS\system32\vmmon32.exe
                                        O4 - HKLM\..\Run: [WheelMouse] C:\4DMOUS~1\wh_exec.exe
                                        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                        O4 - HKCU\..\Run: [Printer] C:\WINDOWS\system32\vmmon32.exe
                                        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                                        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                                        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                                        O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                                        O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                                        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
                                        O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?90e82ce96afc4460b09ad3d8a86d7750
                                        O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?90e82ce96afc4460b09ad3d8a86d7750
                                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                                        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                                        O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
                                        O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
                                        O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
                                        O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                                        O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                                        O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
                                        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                        O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
                                        O17 - HKLM\System\CS2\Services\Tcpip\..\{622508CC-364F-4376-9BB2-10ED0E281DB7}: NameServer = 194.117.200.10,194.117.200.15
                                        O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                                        O20 - AppInit_DLLs: avgrsstx.dll
                                        O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
                                        O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                        O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                                        • 1
                                        • 2