Se connecter / S'enregistrer
Votre question

Probleme de fenetre de publicité intempestives

Tags :
  • Internet Explorer
  • Sécurité
Dernière réponse : dans Sécurité et virus
21 Mai 2008 16:47:49

Bonjour, je viens vers vous car j'ai un probleme de publicité en tout genre qui s'ouvrent lorsque je veux utiliser internet explorer et se sont parfois des pages un peu osées. pourriez vous m'aider à les supprimer?
merci d'avance.

je vous poste le rapport hijackthis que j'ai pu editer.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:42:20, on 21/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINXP\System32\smss.exe
C:\WINXP\system32\winlogon.exe
C:\WINXP\system32\services.exe
C:\WINXP\system32\lsass.exe
C:\WINXP\system32\svchost.exe
C:\WINXP\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINXP\system32\spoolsv.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINXP\system32\svchost.exe
C:\Program Files\UltraVNC\WinVNC.exe
C:\WINXP\system32\SearchIndexer.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINXP\system32\WgaTray.exe
C:\WINXP\Explorer.EXE
C:\WINXP\system32\VTTimer.exe
C:\WINXP\system32\S3trayp.exe
C:\WINXP\RTHDCPL.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
C:\WINXP\system32\ctfmon.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINXP\System32\spool\DRIVERS\W32X86\3\E_FATIBPE.EXE
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINXP\system32\SearchProtocolHost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ixquick.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\UltraVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Amok Eggs Four Web] C:\Documents and Settings\All Users.WINXP\Application Data\part dead amok eggs\drive joy.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINXP\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [EPSON Stylus Photo RX560 Series (Copie 1)] C:\WINXP\System32\spool\DRIVERS\W32X86\3\E_FATIBPE.EXE /FU "C:\WINXP\TEMP\E_S24.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [inter funk] C:\DOCUME~1\ADMINI~1\APPLIC~1\DATAOK~1\trustmemo.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINXP\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINXP\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-21-1844237615-73586283-1801674531-1005\..\Run: [CTFMON.EXE] C:\WINXP\system32\CTFMON.EXE (User 'LogMeInRemoteUser')
O4 - HKUS\S-1-5-21-1844237615-73586283-1801674531-1005\..\RunOnce: [NeroHomeFirstStart] C:\Program Files\Fichiers communs\Ahead\Lib\NMFirstStart.exe (User 'LogMeInRemoteUser')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINXP\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINXP\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Raccourci vers winvnc.exe.lnk = C:\Program Files\UltraVNC\winvnc.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINXP\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINXP\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: VNC Server (winvnc) - www.ultravnc.fr - C:\Program Files\UltraVNC\WinVNC.exe

--
End of file - 10521 bytes

Autres pages sur : probleme fenetre publicite intempestives

a b 8 Sécurité
21 Mai 2008 19:17:26

Bonjour,

Télécharge Lop S&D.exe ([#ff0000]Eric_71[/#f]) sur ton Bureau.
  • Lance l'installation du programme en exécutant le fichier téléchargé.
  • Double-clique maintenant sur le raccourci de LopS&D.
  • Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
  • Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
  • Poste le rapport généré (C:\lopR.txt*)

    (Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet Fichier , Nouvelle tâche , tape explorer.exe et valide)
    * le nom de la partition peut changer
    26 Mai 2008 16:31:23

    bonjour , désolé pour le retard ^^
    mais voici le rapport lopS&D :


    -----------------------[ Lop S&D 4.2.0-9 XP/Vista ]---------------------

    [ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
    [ USER : Administrateur ] [ "C:\Lop SD" ] [ Selection : 1 ]
    [ 26/05/2008 | 16:28:50,05 ] [ PC : X-16A39D73C36A4 ]
    [ MAJ : 16-05-2008 | 23:35 ]

    -------------[ Listing des dossiers dans Application Data ]------------

    [04/04/2008|00:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\Adobe
    [31/01/2008|13:11] C:\DOCUME~1\ADMINI~1\APPLIC~1\AdobeUM
    [26/10/2007|10:23] C:\DOCUME~1\ADMINI~1\APPLIC~1\Ahead
    [15/05/2008|20:03] C:\DOCUME~1\ADMINI~1\APPLIC~1\Dataokaytype
    [23/10/2007|19:19] C:\DOCUME~1\ADMINI~1\APPLIC~1\desktop.ini
    [26/12/2007|10:14] C:\DOCUME~1\ADMINI~1\APPLIC~1\Google
    [27/11/2007|11:42] C:\DOCUME~1\ADMINI~1\APPLIC~1\Help
    [23/10/2007|17:45] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
    [18/03/2008|10:40] C:\DOCUME~1\ADMINI~1\APPLIC~1\InstallShield
    [24/10/2007|23:53] C:\DOCUME~1\ADMINI~1\APPLIC~1\InterTrust
    [24/10/2007|21:49] C:\DOCUME~1\ADMINI~1\APPLIC~1\Macromedia
    [01/11/2007|11:18] C:\DOCUME~1\ADMINI~1\APPLIC~1\Media Player Classic
    [27/11/2007|11:05] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
    [29/10/2007|15:22] C:\DOCUME~1\ADMINI~1\APPLIC~1\MSNInstaller
    [18/05/2008|10:56] C:\DOCUME~1\ADMINI~1\APPLIC~1\SPAMfighter
    [26/05/2008|16:21] C:\DOCUME~1\ADMINI~1\APPLIC~1\U3
    [05/11/2007|19:29] C:\DOCUME~1\ADMINI~1\APPLIC~1\Windows Desktop Search

    [19/05/2007|15:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
    [19/05/2007|17:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
    [24/06/2007|15:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\EPSON
    [24/06/2007|23:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
    [28/09/2007|09:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
    [25/05/2007|21:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
    [22/05/2007|07:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo!
    [22/05/2007|07:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion

    [15/03/2008|11:27] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Adobe
    [23/10/2007|19:19] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\desktop.ini
    [18/03/2008|10:40] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\EPSON
    [19/02/2008|22:30] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\FLEXnet
    [21/12/2007|14:58] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Google
    [05/11/2007|19:02] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Microsoft
    [23/10/2007|18:30] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Nero
    [15/05/2008|20:03] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\part dead amok eggs
    [18/03/2008|10:37] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\UDL
    [26/12/2007|11:06] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Windows Genuine Advantage
    [30/03/2008|06:05] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\WLInstaller

    [19/05/2007|17:07] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
    [19/05/2007|15:18] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

    [23/10/2007|19:19] C:\DOCUME~1\DEFAUL~1.WIN\APPLIC~1\desktop.ini
    [23/10/2007|17:34] C:\DOCUME~1\DEFAUL~1.WIN\APPLIC~1\Microsoft

    [19/05/2007|16:28] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

    [05/11/2007|19:32] C:\DOCUME~1\LOCALS~1.AUT\APPLIC~1\Microsoft

    [19/05/2007|17:07] C:\DOCUME~1\LOGMEI~1\APPLIC~1\desktop.ini
    [19/05/2007|15:18] C:\DOCUME~1\LOGMEI~1\APPLIC~1\Microsoft

    [23/10/2007|19:19] C:\DOCUME~1\LOGMEI~1.X-1\APPLIC~1\desktop.ini
    [25/10/2007|14:37] C:\DOCUME~1\LOGMEI~1.X-1\APPLIC~1\Microsoft

    [23/10/2007|19:19] C:\DOCUME~1\LOGMEI~1.000\APPLIC~1\desktop.ini
    [08/11/2007|15:16] C:\DOCUME~1\LOGMEI~1.000\APPLIC~1\Microsoft

    [19/05/2007|16:25] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

    [05/11/2007|19:03] C:\DOCUME~1\NETWOR~1.AUT\APPLIC~1\Identities
    [05/11/2007|19:03] C:\DOCUME~1\NETWOR~1.AUT\APPLIC~1\Microsoft

    [22/05/2007|23:54] C:\DOCUME~1\NIGHTS~1\APPLIC~1\Adobe
    [19/05/2007|17:07] C:\DOCUME~1\NIGHTS~1\APPLIC~1\desktop.ini
    [04/09/2007|01:29] C:\DOCUME~1\NIGHTS~1\APPLIC~1\DivX
    [02/10/2007|21:30] C:\DOCUME~1\NIGHTS~1\APPLIC~1\ICQ
    [08/07/2007|22:59] C:\DOCUME~1\NIGHTS~1\APPLIC~1\ICQ Toolbar
    [22/05/2007|00:20] C:\DOCUME~1\NIGHTS~1\APPLIC~1\Identities
    [01/06/2007|02:36] C:\DOCUME~1\NIGHTS~1\APPLIC~1\InstallShield Installation Information
    [08/07/2007|00:51] C:\DOCUME~1\NIGHTS~1\APPLIC~1\Jpeg Resampler
    [23/05/2007|23:36] C:\DOCUME~1\NIGHTS~1\APPLIC~1\Macromedia
    [04/09/2007|01:29] C:\DOCUME~1\NIGHTS~1\APPLIC~1\Media Player Classic
    [09/10/2007|21:12] C:\DOCUME~1\NIGHTS~1\APPLIC~1\Microsoft
    [27/05/2007|04:35] C:\DOCUME~1\NIGHTS~1\APPLIC~1\MSNInstaller
    [13/09/2007|02:22] C:\DOCUME~1\NIGHTS~1\APPLIC~1\U3
    [27/06/2007|22:42] C:\DOCUME~1\NIGHTS~1\APPLIC~1\uTorrent
    [04/06/2007|22:04] C:\DOCUME~1\NIGHTS~1\APPLIC~1\Yahoo!


    ----------------[ Tâches planifiées dans C:\WINXP\tasks ]---------------

    [26/05/2008 16:00][--ah-----] C:\WINXP\tasks\33ECD197141B4ABF.job
    [26/05/2008 15:53][--a------] C:\WINXP\tasks\V‚rifier les mises … jour de Windows Live Toolbar.job
    [23/05/2008 03:09][--ah-----] C:\WINXP\tasks\SA.DAT
    [28/08/2001 14:00][-r-h-----] C:\WINXP\tasks\desktop.ini

    ---------------[ Listing des dossiers dans C:\Program Files ]--------------

    [15/03/2008|11:26] C:\Program Files\Adobe
    [26/10/2007|10:31] C:\Program Files\Alwil Software
    [23/10/2007|17:48] C:\Program Files\AMD
    [19/05/2007|15:47] C:\Program Files\ASUS
    [19/05/2007|15:54] C:\Program Files\AvRack
    [16/05/2008|17:25] C:\Program Files\BitDownload
    [15/05/2008|20:03] C:\Program Files\BitTorrent Fastest Tool
    [19/05/2007|13:31] C:\Program Files\ComPlus Applications
    [15/05/2008|20:03] C:\Program Files\Dataokaytype
    [22/10/2007|00:01] C:\Program Files\DynDNS Updater
    [21/05/2008|07:35] C:\Program Files\eMule
    [18/03/2008|10:36] C:\Program Files\epson
    [24/06/2007|15:39] C:\Program Files\epson31610eu.exe
    [24/06/2007|15:11] C:\Program Files\epson31782eu.exe
    [29/08/2007|17:56] C:\Program Files\ESET
    [20/10/2007|16:43] C:\Program Files\Everest Poker
    [20/05/2008|09:20] C:\Program Files\Fichiers communs
    [21/12/2007|14:58] C:\Program Files\Google
    [23/08/2007|23:33] C:\Program Files\ICQ6
    [02/08/2007|12:31] C:\Program Files\ICQToolbar
    [24/06/2007|13:15] C:\Program Files\Install_Messenger.exe
    [18/03/2008|10:36] C:\Program Files\InstallShield Installation Information
    [23/05/2008|03:01] C:\Program Files\Internet Explorer
    [01/11/2007|11:16] C:\Program Files\K-Lite Codec Pack
    [26/05/2008|10:33] C:\Program Files\LogMeIn
    [03/11/2007|04:05] C:\Program Files\Messenger
    [24/06/2007|13:12] C:\Program Files\MessengerPlus! 3
    [19/05/2007|13:35] C:\Program Files\microsoft frontpage
    [19/05/2007|19:29] C:\Program Files\Microsoft Office
    [05/11/2007|19:03] C:\Program Files\Microsoft SQL Server Compact Edition
    [19/05/2007|19:29] C:\Program Files\Microsoft Visual Studio
    [19/05/2007|19:29] C:\Program Files\Microsoft Works
    [19/05/2007|16:21] C:\Program Files\Microsoft WSE
    [19/05/2007|19:27] C:\Program Files\Microsoft.NET
    [19/05/2007|13:32] C:\Program Files\Movie Maker
    [02/11/2007|17:33] C:\Program Files\MSN
    [19/05/2007|13:31] C:\Program Files\MSN Gaming Zone
    [23/09/2007|21:58] C:\Program Files\MSN Messenger
    [19/05/2008|03:01] C:\Program Files\MSXML 4.0
    [09/05/2008|21:14] C:\Program Files\Multi_Media_France
    [23/10/2007|18:30] C:\Program Files\Nero
    [19/05/2007|13:37] C:\Program Files\NetMeeting
    [19/05/2007|13:31] C:\Program Files\Online Services
    [03/11/2007|04:04] C:\Program Files\Outlook Express
    [23/10/2007|18:13] C:\Program Files\Realtek
    [19/05/2007|15:54] C:\Program Files\Realtek Sound Manager
    [23/10/2007|18:01] C:\Program Files\S3
    [19/05/2007|13:33] C:\Program Files\Services en ligne
    [21/05/2008|16:41] C:\Program Files\Trend Micro
    [04/03/2008|12:46] C:\Program Files\UltraVNC
    [19/05/2007|15:25] C:\Program Files\Uninstall Information
    [23/10/2007|17:50] C:\Program Files\VIA
    [24/06/2007|14:46] C:\Program Files\Wanadoo_espace_partag‚
    [05/11/2007|19:02] C:\Program Files\Windows Desktop Search
    [27/02/2008|04:01] C:\Program Files\Windows Live
    [21/05/2008|16:39] C:\Program Files\Windows Live Safety Center
    [07/11/2007|04:07] C:\Program Files\Windows Live Toolbar
    [26/12/2007|10:42] C:\Program Files\Windows Media Connect 2
    [26/12/2007|10:42] C:\Program Files\Windows Media Player
    [19/05/2007|13:31] C:\Program Files\Windows NT
    [19/05/2007|13:33] C:\Program Files\WindowsUpdate
    [26/10/2007|10:24] C:\Program Files\WinRAR
    [19/05/2007|13:35] C:\Program Files\xerox
    [22/05/2007|07:42] C:\Program Files\Yahoo!

    ------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]------

    [20/11/2007|18:00] C:\Program Files\Fichiers communs\Adobe
    [23/10/2007|18:33] C:\Program Files\Fichiers communs\Ahead
    [19/05/2007|19:29] C:\Program Files\Fichiers communs\DESIGNER
    [26/06/2007|22:54] C:\Program Files\Fichiers communs\InstallShield
    [26/10/2007|10:23] C:\Program Files\Fichiers communs\LightScribe
    [20/11/2007|18:00] C:\Program Files\Fichiers communs\Macrovision Shared
    [30/11/2007|18:18] C:\Program Files\Fichiers communs\Microsoft Shared
    [19/05/2007|13:33] C:\Program Files\Fichiers communs\MSSoap
    [19/05/2007|15:22] C:\Program Files\Fichiers communs\ODBC
    [19/05/2007|13:33] C:\Program Files\Fichiers communs\Services
    [19/05/2007|15:22] C:\Program Files\Fichiers communs\SpeechEngines
    [03/11/2007|04:04] C:\Program Files\Fichiers communs\System
    [30/11/2007|18:17] C:\Program Files\Fichiers communs\WindowsLiveInstaller

    ---------------------------[ Process ]--------------------------

    ... 57

    iexplore.exe ~ [2896]
    iexplore.exe ~ [2980]
    iexplore.exe ~ [3084]

    ----------------------[ Recherche avec S_Lop ]---------------------

    C:\DOCUME~1\ADMINI~1\APPLIC~1\DATAOK~1
    C:\DOCUME~1\ADMINI~1\APPLIC~1\DATAOK~1\Bike Chin Stop.exe
    C:\DOCUME~1\ADMINI~1\APPLIC~1\DATAOK~1\oyhgyhxp.exe
    C:\DOCUME~1\ADMINI~1\APPLIC~1\DATAOK~1\trustmemo.exe

    -----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------

    C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\part dead amok eggs
    C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\part dead amok eggs\drive joy.exe
    C:\Program Files\Bitdownload
    C:\Program Files\Bitdownload\session.store
    C:\Program Files\BitTorrent Fastest Tool
    C:\Program Files\BitTorrent Fastest Tool\BitDownload-4.5-setup.exe
    C:\Program Files\BitTorrent Fastest Tool\BitP.exe
    C:\Program Files\BitTorrent Fastest Tool\INSTALL.LOG
    C:\Program Files\Multi_Media_France
    C:\Program Files\Multi_Media_France\INSTALL.LOG

    ----------------------[ Verification du Registre ]----------------------

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Poke hide anti]
    "DisplayName"="CiD Help"
    "UninstallString"="C:\\DOCUME~1\\ADMINI~1\\APPLIC~1\\DATAOK~1\\trustmemo.exe -uninstall"

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "inter funk"="C:\\DOCUME~1\\ADMINI~1\\APPLIC~1\\DATAOK~1\\trustmemo.exe"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Amok Eggs Four Web"="C:\\Documents and Settings\\All Users.WINXP\\Application Data\\part dead amok eggs\\drive joy.exe"

    --------------------[ Verification du fichier Hosts ]---------------------

    Fichier Hosts PROPRE


    ----------------[ Recherche de fichiers avec Catchme ]-----------------

    catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-05-26 16:29:46
    Windows 5.1.2600 Service Pack 2 NTFS
    scanning hidden processes ...
    scanning hidden files ...
    scan completed successfully
    hidden processes: 0
    hidden files: 0

    --------------------[ Recherche d'autres infections ]---------------------


    Aucune autre infection trouvée !

    [F:58][D:6]-> C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
    [F:74][D:0]-> C:\DOCUME~1\ADMINI~1\Cookies
    [F:426][D:7]-> C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMPOR~1\content.IE5

    --------------------[ Fin du rapport a 16:30:16,18 ]----------------------
    Contenus similaires
    a b 8 Sécurité
    26 Mai 2008 18:03:50

    Re,

    Ouvre le dossier Lop S&D puis double-clique sur Scan.bat. Tape sur "S" puis valide en appuyant sur "Entrée".
    [#ff0000]! Ne ferme pas la fenêtre lors de la suppression ! [/#f]
    Un rapport sera généré, poste son contenu ici.

    NOTE : Si ton Bureau ne réapparait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
    Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."
    Tape explorer puis valide.
    28 Mai 2008 15:05:14

    je n'ai aucun fichier scan.bat dans le dossier lop S&D :/ 
    a b 8 Sécurité
    28 Mai 2008 19:11:41

    Il y avait une erreur dans le programme qui contient mes procédures. C'est corrigé, désolé.

    Relance Lop S&D en double-cliquant sur le raccourci. Tape sur "2" puis valide en appuyant sur "Entrée".
    [#ff0000]! Ne ferme pas la fenêtre lors de la suppression ! [/#f]
    Un rapport sera généré, poste son contenu ici.

    NOTE : Si ton Bureau ne réapparait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
    Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."
    Tape explorer puis valide.
    29 Mai 2008 15:01:17

    rebonjour,

    voici le rapport :

    -----------------------[ Lop S&D 4.2.0-9 XP/Vista ]---------------------

    [ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
    [ USER : Administrateur ] [ "C:\Lop SD" ] [ Selection : 2 ]
    [ 29/05/2008 | 14:55:24,08 ] [ PC : X-16A39D73C36A4 ]
    [ MAJ : 16-05-2008 | 23:35 ]


    \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION /////////////////////////////

    Supprimé! - C:\Program Files\Bitdownload\session.store
    Supprimé! - C:\Program Files\BitTorrent Fastest Tool\BitDownload-4.5-setup.exe
    Supprimé! - C:\Program Files\BitTorrent Fastest Tool\BitP.exe
    Supprimé! - C:\Program Files\BitTorrent Fastest Tool\INSTALL.LOG
    Supprimé! - C:\Program Files\Multi_Media_France\INSTALL.LOG
    Supprimé! - C:\DOCUME~1\ADMINI~1\APPLIC~1\DATAOK~1\Bike Chin Stop.exe
    Supprimé! - C:\DOCUME~1\ADMINI~1\APPLIC~1\DATAOK~1\oyhgyhxp.exe
    Supprimé! - C:\DOCUME~1\ADMINI~1\APPLIC~1\DATAOK~1\trustmemo.exe
    Supprimé! - C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\part dead amok eggs
    Supprimé! - C:\Program Files\Bitdownload
    Supprimé! - C:\Program Files\BitTorrent Fastest Tool
    Supprimé! - C:\Program Files\Multi_Media_France
    Supprimé! - C:\DOCUME~1\ADMINI~1\APPLIC~1\DATAOK~1
    Supprimé! - C:\Program Files\DATAOK~1

    //////////////////////////////////////-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


    -------------[ Listing des dossiers dans Application Data ]------------

    [04/04/2008|00:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\Adobe
    [31/01/2008|13:11] C:\DOCUME~1\ADMINI~1\APPLIC~1\AdobeUM
    [26/10/2007|10:23] C:\DOCUME~1\ADMINI~1\APPLIC~1\Ahead
    [23/10/2007|19:19] C:\DOCUME~1\ADMINI~1\APPLIC~1\desktop.ini
    [26/12/2007|10:14] C:\DOCUME~1\ADMINI~1\APPLIC~1\Google
    [27/11/2007|11:42] C:\DOCUME~1\ADMINI~1\APPLIC~1\Help
    [23/10/2007|17:45] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
    [18/03/2008|10:40] C:\DOCUME~1\ADMINI~1\APPLIC~1\InstallShield
    [24/10/2007|23:53] C:\DOCUME~1\ADMINI~1\APPLIC~1\InterTrust
    [24/10/2007|21:49] C:\DOCUME~1\ADMINI~1\APPLIC~1\Macromedia
    [01/11/2007|11:18] C:\DOCUME~1\ADMINI~1\APPLIC~1\Media Player Classic
    [27/11/2007|11:05] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
    [29/10/2007|15:22] C:\DOCUME~1\ADMINI~1\APPLIC~1\MSNInstaller
    [18/05/2008|10:56] C:\DOCUME~1\ADMINI~1\APPLIC~1\SPAMfighter
    [26/05/2008|16:33] C:\DOCUME~1\ADMINI~1\APPLIC~1\U3
    [05/11/2007|19:29] C:\DOCUME~1\ADMINI~1\APPLIC~1\Windows Desktop Search

    [19/05/2007|15:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
    [19/05/2007|17:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
    [24/06/2007|15:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\EPSON
    [24/06/2007|23:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
    [28/09/2007|09:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
    [25/05/2007|21:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
    [22/05/2007|07:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo!
    [22/05/2007|07:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion

    [15/03/2008|11:27] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Adobe
    [23/10/2007|19:19] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\desktop.ini
    [18/03/2008|10:40] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\EPSON
    [19/02/2008|22:30] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\FLEXnet
    [21/12/2007|14:58] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Google
    [05/11/2007|19:02] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Microsoft
    [23/10/2007|18:30] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Nero
    [18/03/2008|10:37] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\UDL
    [26/12/2007|11:06] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Windows Genuine Advantage
    [30/03/2008|06:05] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\WLInstaller

    [19/05/2007|17:07] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
    [19/05/2007|15:18] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

    [23/10/2007|19:19] C:\DOCUME~1\DEFAUL~1.WIN\APPLIC~1\desktop.ini
    [23/10/2007|17:34] C:\DOCUME~1\DEFAUL~1.WIN\APPLIC~1\Microsoft

    [19/05/2007|16:28] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

    [05/11/2007|19:32] C:\DOCUME~1\LOCALS~1.AUT\APPLIC~1\Microsoft

    [19/05/2007|17:07] C:\DOCUME~1\LOGMEI~1\APPLIC~1\desktop.ini
    [19/05/2007|15:18] C:\DOCUME~1\LOGMEI~1\APPLIC~1\Microsoft

    [23/10/2007|19:19] C:\DOCUME~1\LOGMEI~1.X-1\APPLIC~1\desktop.ini
    [25/10/2007|14:37] C:\DOCUME~1\LOGMEI~1.X-1\APPLIC~1\Microsoft

    [23/10/2007|19:19] C:\DOCUME~1\LOGMEI~1.000\APPLIC~1\desktop.ini
    [08/11/2007|15:16] C:\DOCUME~1\LOGMEI~1.000\APPLIC~1\Microsoft

    [19/05/2007|16:25] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

    [05/11/2007|19:03] C:\DOCUME~1\NETWOR~1.AUT\APPLIC~1\Identities
    [05/11/2007|19:03] C:\DOCUME~1\NETWOR~1.AUT\APPLIC~1\Microsoft

    [22/05/2007|23:54] C:\DOCUME~1\NIGHTS~1\APPLIC~1\Adobe
    [19/05/2007|17:07] C:\DOCUME~1\NIGHTS~1\APPLIC~1\desktop.ini
    [04/09/2007|01:29] C:\DOCUME~1\NIGHTS~1\APPLIC~1\DivX
    [02/10/2007|21:30] C:\DOCUME~1\NIGHTS~1\APPLIC~1\ICQ
    [08/07/2007|22:59] C:\DOCUME~1\NIGHTS~1\APPLIC~1\ICQ Toolbar
    [22/05/2007|00:20] C:\DOCUME~1\NIGHTS~1\APPLIC~1\Identities
    [01/06/2007|02:36] C:\DOCUME~1\NIGHTS~1\APPLIC~1\InstallShield Installation Information
    [08/07/2007|00:51] C:\DOCUME~1\NIGHTS~1\APPLIC~1\Jpeg Resampler
    [23/05/2007|23:36] C:\DOCUME~1\NIGHTS~1\APPLIC~1\Macromedia
    [04/09/2007|01:29] C:\DOCUME~1\NIGHTS~1\APPLIC~1\Media Player Classic
    [09/10/2007|21:12] C:\DOCUME~1\NIGHTS~1\APPLIC~1\Microsoft
    [27/05/2007|04:35] C:\DOCUME~1\NIGHTS~1\APPLIC~1\MSNInstaller
    [13/09/2007|02:22] C:\DOCUME~1\NIGHTS~1\APPLIC~1\U3
    [27/06/2007|22:42] C:\DOCUME~1\NIGHTS~1\APPLIC~1\uTorrent
    [04/06/2007|22:04] C:\DOCUME~1\NIGHTS~1\APPLIC~1\Yahoo!


    ----------------[ Tâches planifiées dans C:\WINXP\tasks ]---------------

    [29/05/2008 14:00][--ah-----] C:\WINXP\tasks\B2445A82924BD26A.job
    [29/05/2008 14:53][--a------] C:\WINXP\tasks\V‚rifier les mises … jour de Windows Live Toolbar.job
    [26/05/2008 17:48][--ah-----] C:\WINXP\tasks\SA.DAT
    [28/08/2001 14:00][-r-h-----] C:\WINXP\tasks\desktop.ini

    B2445A82924BD26A.job <--> c:\docume~1\admini~1\applic~1\dataok~1\BikeChinStop.exe

    ---------------[ Listing des dossiers dans C:\Program Files ]--------------

    [15/03/2008|11:26] C:\Program Files\Adobe
    [26/10/2007|10:31] C:\Program Files\Alwil Software
    [23/10/2007|17:48] C:\Program Files\AMD
    [19/05/2007|15:47] C:\Program Files\ASUS
    [19/05/2007|15:54] C:\Program Files\AvRack
    [19/05/2007|13:31] C:\Program Files\ComPlus Applications
    [22/10/2007|00:01] C:\Program Files\DynDNS Updater
    [28/05/2008|00:47] C:\Program Files\eMule
    [18/03/2008|10:36] C:\Program Files\epson
    [24/06/2007|15:39] C:\Program Files\epson31610eu.exe
    [24/06/2007|15:11] C:\Program Files\epson31782eu.exe
    [29/08/2007|17:56] C:\Program Files\ESET
    [20/10/2007|16:43] C:\Program Files\Everest Poker
    [20/05/2008|09:20] C:\Program Files\Fichiers communs
    [21/12/2007|14:58] C:\Program Files\Google
    [23/08/2007|23:33] C:\Program Files\ICQ6
    [02/08/2007|12:31] C:\Program Files\ICQToolbar
    [24/06/2007|13:15] C:\Program Files\Install_Messenger.exe
    [18/03/2008|10:36] C:\Program Files\InstallShield Installation Information
    [23/05/2008|03:01] C:\Program Files\Internet Explorer
    [01/11/2007|11:16] C:\Program Files\K-Lite Codec Pack
    [29/05/2008|05:58] C:\Program Files\LogMeIn
    [03/11/2007|04:05] C:\Program Files\Messenger
    [24/06/2007|13:12] C:\Program Files\MessengerPlus! 3
    [19/05/2007|13:35] C:\Program Files\microsoft frontpage
    [19/05/2007|19:29] C:\Program Files\Microsoft Office
    [05/11/2007|19:03] C:\Program Files\Microsoft SQL Server Compact Edition
    [19/05/2007|19:29] C:\Program Files\Microsoft Visual Studio
    [19/05/2007|19:29] C:\Program Files\Microsoft Works
    [19/05/2007|16:21] C:\Program Files\Microsoft WSE
    [19/05/2007|19:27] C:\Program Files\Microsoft.NET
    [19/05/2007|13:32] C:\Program Files\Movie Maker
    [02/11/2007|17:33] C:\Program Files\MSN
    [19/05/2007|13:31] C:\Program Files\MSN Gaming Zone
    [23/09/2007|21:58] C:\Program Files\MSN Messenger
    [19/05/2008|03:01] C:\Program Files\MSXML 4.0
    [23/10/2007|18:30] C:\Program Files\Nero
    [19/05/2007|13:37] C:\Program Files\NetMeeting
    [19/05/2007|13:31] C:\Program Files\Online Services
    [03/11/2007|04:04] C:\Program Files\Outlook Express
    [23/10/2007|18:13] C:\Program Files\Realtek
    [19/05/2007|15:54] C:\Program Files\Realtek Sound Manager
    [23/10/2007|18:01] C:\Program Files\S3
    [19/05/2007|13:33] C:\Program Files\Services en ligne
    [21/05/2008|16:41] C:\Program Files\Trend Micro
    [04/03/2008|12:46] C:\Program Files\UltraVNC
    [19/05/2007|15:25] C:\Program Files\Uninstall Information
    [23/10/2007|17:50] C:\Program Files\VIA
    [24/06/2007|14:46] C:\Program Files\Wanadoo_espace_partag‚
    [05/11/2007|19:02] C:\Program Files\Windows Desktop Search
    [27/02/2008|04:01] C:\Program Files\Windows Live
    [21/05/2008|16:39] C:\Program Files\Windows Live Safety Center
    [07/11/2007|04:07] C:\Program Files\Windows Live Toolbar
    [26/12/2007|10:42] C:\Program Files\Windows Media Connect 2
    [26/12/2007|10:42] C:\Program Files\Windows Media Player
    [19/05/2007|13:31] C:\Program Files\Windows NT
    [19/05/2007|13:33] C:\Program Files\WindowsUpdate
    [26/10/2007|10:24] C:\Program Files\WinRAR
    [19/05/2007|13:35] C:\Program Files\xerox
    [22/05/2007|07:42] C:\Program Files\Yahoo!

    ------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]------

    [20/11/2007|18:00] C:\Program Files\Fichiers communs\Adobe
    [23/10/2007|18:33] C:\Program Files\Fichiers communs\Ahead
    [19/05/2007|19:29] C:\Program Files\Fichiers communs\DESIGNER
    [26/06/2007|22:54] C:\Program Files\Fichiers communs\InstallShield
    [26/10/2007|10:23] C:\Program Files\Fichiers communs\LightScribe
    [20/11/2007|18:00] C:\Program Files\Fichiers communs\Macrovision Shared
    [30/11/2007|18:18] C:\Program Files\Fichiers communs\Microsoft Shared
    [19/05/2007|13:33] C:\Program Files\Fichiers communs\MSSoap
    [19/05/2007|15:22] C:\Program Files\Fichiers communs\ODBC
    [19/05/2007|13:33] C:\Program Files\Fichiers communs\Services
    [19/05/2007|15:22] C:\Program Files\Fichiers communs\SpeechEngines
    [03/11/2007|04:04] C:\Program Files\Fichiers communs\System
    [30/11/2007|18:17] C:\Program Files\Fichiers communs\WindowsLiveInstaller

    ---------------------------[ Process ]--------------------------

    ... 48

    ... OK !

    ----------------------[ Recherche avec S_Lop ]---------------------

    Aucun fichier / dossier Lop trouvé !

    -----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------

    C:\WINXP\Tasks\B2445A82924BD26A.job

    ----------------------[ Verification du Registre ]----------------------

    ..... OK !

    --------------------[ Verification du fichier Hosts ]---------------------

    Fichier Hosts PROPRE


    ----------------[ Recherche de fichiers avec Catchme ]-----------------

    catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-05-29 14:56:20
    Windows 5.1.2600 Service Pack 2 NTFS
    scanning hidden processes ...
    scanning hidden files ...
    scan completed successfully
    hidden processes: 0
    hidden files: 0

    --------------------[ Recherche d'autres infections ]---------------------


    Aucune autre infection trouvée !

    [F:61][D:12]-> C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
    [F:206][D:0]-> C:\DOCUME~1\ADMINI~1\Cookies
    [F:52][D:7]-> C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMPOR~1\content.IE5

    --------------------[ Fin du rapport a 14:56:48,08 ]----------------------
    a b 8 Sécurité
    30 Mai 2008 21:23:19

    Reposte un rapport Hijackthis.
    2 Juin 2008 15:57:45

    rebonjour, voici le rapport hijackthis :

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 15:55:53, on 02/06/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINXP\System32\smss.exe
    C:\WINXP\system32\winlogon.exe
    C:\WINXP\system32\services.exe
    C:\WINXP\system32\lsass.exe
    C:\WINXP\system32\svchost.exe
    C:\WINXP\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINXP\system32\spoolsv.exe
    C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINXP\system32\svchost.exe
    C:\Program Files\UltraVNC\WinVNC.exe
    C:\WINXP\system32\VTTimer.exe
    C:\WINXP\system32\S3trayp.exe
    C:\WINXP\RTHDCPL.EXE
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
    C:\WINXP\system32\SearchIndexer.exe
    C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
    C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
    C:\WINXP\system32\ctfmon.exe
    C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\WINXP\system32\WgaTray.exe
    C:\WINXP\System32\spool\DRIVERS\W32X86\3\E_FATIBPE.EXE
    C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
    C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
    C:\WINXP\system32\wuauclt.exe
    C:\Program Files\LogMeIn\x86\LogMeIn.exe
    C:\Program Files\LogMeIn\x86\RaMaint.exe
    C:\WINXP\explorer.exe
    C:\Hotelwd8\binaires\HOTELWD8.exe
    C:\WINXP\system32\wuauclt.exe
    C:\WINXP\system32\SearchProtocolHost.exe
    C:\Program Files\LogMeIn\x86\LogMeIn.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ixquick.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
    O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe
    O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
    O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\UltraVNC\WinVNC.exe" -servicehelper
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINXP\system32\ctfmon.exe
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [EPSON Stylus Photo RX560 Series (Copie 1)] C:\WINXP\System32\spool\DRIVERS\W32X86\3\E_FATIBPE.EXE /FU "C:\WINXP\TEMP\E_S24.tmp" /EF "HKCU"
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINXP\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINXP\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-21-1844237615-73586283-1801674531-1004\..\Run: [CTFMON.EXE] C:\WINXP\system32\CTFMON.EXE (User '?')
    O4 - HKUS\S-1-5-21-1844237615-73586283-1801674531-1004\..\RunOnce: [NeroHomeFirstStart] C:\Program Files\Fichiers communs\Ahead\Lib\NMFirstStart.exe (User '?')
    O4 - HKUS\S-1-5-21-1844237615-73586283-1801674531-1005\..\Run: [CTFMON.EXE] C:\WINXP\system32\CTFMON.EXE (User 'LogMeInRemoteUser')
    O4 - HKUS\S-1-5-21-1844237615-73586283-1801674531-1005\..\RunOnce: [NeroHomeFirstStart] C:\Program Files\Fichiers communs\Ahead\Lib\NMFirstStart.exe (User 'LogMeInRemoteUser')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINXP\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINXP\system32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Raccourci vers winvnc.exe.lnk = C:\Program Files\UltraVNC\winvnc.exe
    O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINXP\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINXP\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
    O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
    O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
    O23 - Service: VNC Server (winvnc) - www.ultravnc.fr - C:\Program Files\UltraVNC\WinVNC.exe

    --
    End of file - 10344 bytes
    5 Juin 2008 18:19:59

    ce que j'ai supprimé dans le dossier tasks correspondait à une tache récurente.

    j'ai désinstallé avast et mis antivir dont voici le rapport:


    Avira AntiVir Personal
    Report file date: jeudi 5 juin 2008 15:13

    Scanning for 1311396 virus strains and unwanted programs.

    Licensed to: Avira AntiVir PersonalEdition Classic
    Serial number: 0000149996-ADJIE-0001
    Platform: Windows XP
    Windows version: (Service Pack 2) [5.1.2600]
    Boot mode: Normally booted
    Username: SYSTEM
    Computer name: X-16A39D73C36A4

    Version information:
    BUILD.DAT : 8.1.00.295 16479 Bytes 09/04/2008 16:24:00
    AVSCAN.EXE : 8.1.2.12 311553 Bytes 18/03/2008 09:02:56
    AVSCAN.DLL : 8.1.1.0 53505 Bytes 07/02/2008 08:43:37
    LUKE.DLL : 8.1.2.9 151809 Bytes 28/02/2008 08:41:23
    LUKERES.DLL : 8.1.2.1 12033 Bytes 21/02/2008 08:28:40
    ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 10:33:34
    ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 13:08:58
    ANTIVIR2.VDF : 7.0.4.120 2206720 Bytes 01/06/2008 13:02:26
    ANTIVIR3.VDF : 7.0.4.149 109568 Bytes 05/06/2008 13:02:27
    Engineversion : 8.1.0.51
    AEVDF.DLL : 8.1.0.5 102772 Bytes 25/02/2008 09:58:21
    AESCRIPT.DLL : 8.1.0.37 270715 Bytes 05/06/2008 13:02:35
    AESCN.DLL : 8.1.0.20 119157 Bytes 05/06/2008 13:02:34
    AERDL.DLL : 8.1.0.20 418165 Bytes 05/06/2008 13:02:34
    AEPACK.DLL : 8.1.1.5 364918 Bytes 05/06/2008 13:02:33
    AEOFFICE.DLL : 8.1.0.18 192890 Bytes 05/06/2008 13:02:32
    AEHEUR.DLL : 8.1.0.29 1253750 Bytes 05/06/2008 13:02:31
    AEHELP.DLL : 8.1.0.15 115063 Bytes 05/06/2008 13:02:29
    AEGEN.DLL : 8.1.0.25 307573 Bytes 05/06/2008 13:02:29
    AEEMU.DLL : 8.1.0.6 430451 Bytes 05/06/2008 13:02:28
    AECORE.DLL : 8.1.0.30 168311 Bytes 05/06/2008 13:02:27
    AVWINLL.DLL : 1.0.0.7 14593 Bytes 23/01/2008 17:07:53
    AVPREF.DLL : 8.0.0.1 25857 Bytes 18/02/2008 10:37:50
    AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:26:47
    AVREG.DLL : 8.0.0.0 30977 Bytes 23/01/2008 17:07:49
    AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
    AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 28/02/2008 08:31:31
    SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
    SMTPLIB.DLL : 1.2.0.19 28929 Bytes 23/01/2008 17:08:39
    NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
    RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 10/03/2008 14:37:25
    RCTEXT.DLL : 8.0.32.0 86273 Bytes 06/03/2008 12:02:11

    Configuration settings for the scan:
    Jobname..........................: Complete system scan
    Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
    Logging..........................: low
    Primary action...................: interactive
    Secondary action.................: ignore
    Scan master boot sector..........: on
    Scan boot sector.................: on
    Boot sectors.....................: C:, D:,
    Scan memory......................: on
    Process scan.....................: on
    Scan registry....................: on
    Search for rootkits..............: off
    Scan all files...................: Intelligent file selection
    Scan archives....................: on
    Recursion depth..................: 20
    Smart extensions.................: on
    Macro heuristic..................: on
    File heuristic...................: medium

    Start of the scan: jeudi 5 juin 2008 15:13

    The scan of running processes will be started
    Scan process 'avscan.exe' - '1' Module(s) have been scanned
    Scan process 'avcenter.exe' - '1' Module(s) have been scanned
    Scan process 'HOTELWD8.exe' - '1' Module(s) have been scanned
    Scan process 'sched.exe' - '1' Module(s) have been scanned
    Scan process 'avgnt.exe' - '1' Module(s) have been scanned
    Scan process 'avguard.exe' - '1' Module(s) have been scanned
    Scan process 'NMIndexingService.exe' - '1' Module(s) have been scanned
    Scan process 'FNPLicensingService.exe' - '1' Module(s) have been scanned
    Scan process 'NMIndexStoreSvr.exe' - '1' Module(s) have been scanned
    Scan process 'WindowsSearch.exe' - '1' Module(s) have been scanned
    Scan process 'E_FATIBPE.EXE' - '1' Module(s) have been scanned
    Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
    Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned
    Scan process 'NMBgMonitor.exe' - '1' Module(s) have been scanned
    Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
    Scan process 'apdproxy.exe' - '1' Module(s) have been scanned
    Scan process 'Acrotray.exe' - '1' Module(s) have been scanned
    Scan process 'LogMeInSystray.exe' - '1' Module(s) have been scanned
    Scan process 'RTHDCPL.exe' - '1' Module(s) have been scanned
    Scan process 'S3Trayp.exe' - '1' Module(s) have been scanned
    Scan process 'VTTimer.exe' - '1' Module(s) have been scanned
    Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
    Scan process 'explorer.exe' - '1' Module(s) have been scanned
    Scan process 'WgaTray.exe' - '1' Module(s) have been scanned
    Scan process 'LogMeIn.exe' - '1' Module(s) have been scanned
    Scan process 'alg.exe' - '1' Module(s) have been scanned
    Scan process 'searchindexer.exe' - '1' Module(s) have been scanned
    Scan process 'winvnc.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'MDM.EXE' - '1' Module(s) have been scanned
    Scan process 'LogMeIn.exe' - '1' Module(s) have been scanned
    Scan process 'ramaint.exe' - '1' Module(s) have been scanned
    Scan process 'LSSrvc.exe' - '1' Module(s) have been scanned
    Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'lsass.exe' - '1' Module(s) have been scanned
    Scan process 'services.exe' - '1' Module(s) have been scanned
    Scan process 'winlogon.exe' - '1' Module(s) have been scanned
    Scan process 'csrss.exe' - '1' Module(s) have been scanned
    Scan process 'smss.exe' - '1' Module(s) have been scanned
    44 processes with 44 modules were scanned

    Starting master boot sector scan:
    Master boot sector HD0
    [INFO] No virus was found!
    Master boot sector HD1
    [INFO] No virus was found!

    Start scanning boot sectors:
    Boot sector 'C:\'
    [INFO] No virus was found!
    Boot sector 'D:\'
    [INFO] No virus was found!

    Starting to scan the registry.
    The registry was scanned ( '35' files ).


    Starting the file scan:

    Begin scan in 'C:\'
    C:\pagefile.sys
    [WARNING] The file could not be opened!
    C:\Program Files\ESET\infected\C2HMRXCA.NQF
    [0] Archive type: HIDDEN
    --> FIL\\\?\C:\Program Files\ESET\infected\C2HMRXCA.NQF
    [DETECTION] Contains detection pattern of the worm WORM/Brontok.E.1
    [NOTE] The file was moved to '488ffe8a.qua'!
    C:\Program Files\ESET\infected\W12BISCA.NQF
    [0] Archive type: HIDDEN
    --> FIL\\\?\C:\Program Files\ESET\infected\W12BISCA.NQF
    [DETECTION] Contains detection pattern of the worm WORM/Rontok.D
    [NOTE] The file was moved to '4879fe8d.qua'!
    C:\System Volume Information\_restore{BC27474E-0E50-4F62-894B-0163167ABE77}\RP215\A0074395.exe
    [DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
    [NOTE] The file was moved to '48780598.qua'!
    C:\System Volume Information\_restore{BC27474E-0E50-4F62-894B-0163167ABE77}\RP222\A0077059.exe
    [DETECTION] Contains detection pattern of a probably damaged sample CC/UKMalw.LB
    [NOTE] The file was moved to '487805db.qua'!
    Begin scan in 'D:\'
    D:\holzer\Lost Folder(s)\[DIR00045717]\common200612051941[4].js
    [DETECTION] Contains suspicious code HEUR/HTML.Malware
    [NOTE] The fund was classified as suspicious.
    [NOTE] The file was moved to '48b50ba2.qua'!
    D:\holzer\Lost Folder(s)\[DIR00135885]\hp[2].js
    [DETECTION] Contains suspicious code HEUR/HTML.Malware
    [NOTE] The fund was classified as suspicious.
    [NOTE] The file was moved to '48a30bbd.qua'!


    End of the scan: jeudi 5 juin 2008 18:17
    Used time: 3:03:55 min

    The scan has been done completely.

    9808 Scanning directories
    628792 Files were scanned
    4 viruses and/or unwanted programs were found
    2 Files were classified as suspicious:
    0 files were deleted
    0 files were repaired
    6 files were moved to quarantine
    0 files were renamed
    1 Files cannot be scanned
    628788 Files not concerned
    4507 Archives were scanned
    1 Warnings
    6 Notes

    a b 8 Sécurité
    5 Juin 2008 18:35:39

    Reposte un rapport Hijackthis.
    11 Juin 2008 16:39:18

    voilà :) 

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 16:38:24, on 11/06/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINXP\System32\smss.exe
    C:\WINXP\system32\winlogon.exe
    C:\WINXP\system32\services.exe
    C:\WINXP\system32\lsass.exe
    C:\WINXP\system32\svchost.exe
    C:\WINXP\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINXP\system32\spoolsv.exe
    C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    C:\Program Files\LogMeIn\x86\RaMaint.exe
    C:\Program Files\LogMeIn\x86\LogMeIn.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINXP\system32\svchost.exe
    C:\Program Files\UltraVNC\WinVNC.exe
    C:\WINXP\system32\SearchIndexer.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINXP\system32\WgaTray.exe
    C:\WINXP\Explorer.EXE
    C:\WINXP\system32\VTTimer.exe
    C:\WINXP\system32\S3trayp.exe
    C:\WINXP\RTHDCPL.EXE
    C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
    C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINXP\system32\ctfmon.exe
    C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\WINXP\System32\spool\DRIVERS\W32X86\3\E_FATIBPE.EXE
    C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
    C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
    C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    C:\Hotelwd8\binaires\HOTELWD8.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
    C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
    C:\Program Files\LogMeIn\x86\LogMeIn.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ixquick.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
    O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe
    O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
    O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
    O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\UltraVNC\WinVNC.exe" -servicehelper
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINXP\system32\ctfmon.exe
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [EPSON Stylus Photo RX560 Series (Copie 1)] C:\WINXP\System32\spool\DRIVERS\W32X86\3\E_FATIBPE.EXE /FU "C:\WINXP\TEMP\E_S24.tmp" /EF "HKCU"
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINXP\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINXP\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-21-1844237615-73586283-1801674531-1005\..\Run: [CTFMON.EXE] C:\WINXP\system32\CTFMON.EXE (User 'LogMeInRemoteUser')
    O4 - HKUS\S-1-5-21-1844237615-73586283-1801674531-1005\..\RunOnce: [NeroHomeFirstStart] C:\Program Files\Fichiers communs\Ahead\Lib\NMFirstStart.exe (User 'LogMeInRemoteUser')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINXP\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINXP\system32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Raccourci vers winvnc.exe.lnk = C:\Program Files\UltraVNC\winvnc.exe
    O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINXP\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINXP\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
    O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
    O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
    O23 - Service: VNC Server (winvnc) - www.ultravnc.fr - C:\Program Files\UltraVNC\WinVNC.exe

    --
    End of file - 8999 bytes
    a b 8 Sécurité
    11 Juin 2008 16:47:13

    Euh pourquoi tu as Avast: là ?
    12 Juin 2008 10:18:21

    mon patron a dû le reinstaller :/  je vais lui réexpliquer que antivir est mieux et je reposte un rapport hijackthis
    a b 8 Sécurité
    12 Juin 2008 13:34:10

    Ok ;) 
    13 Juin 2008 17:39:22

    voilà j'ai reinstaler anivir :)  et refais un rapport hijackthis que voici :

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 17:37:21, on 13/06/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINXP\System32\smss.exe
    C:\WINXP\system32\winlogon.exe
    C:\WINXP\system32\services.exe
    C:\WINXP\system32\lsass.exe
    C:\WINXP\system32\svchost.exe
    C:\WINXP\System32\svchost.exe
    C:\WINXP\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    C:\Program Files\LogMeIn\x86\RaMaint.exe
    C:\Program Files\LogMeIn\x86\LogMeIn.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINXP\system32\svchost.exe
    C:\Program Files\UltraVNC\WinVNC.exe
    C:\WINXP\system32\SearchIndexer.exe
    C:\WINXP\system32\WgaTray.exe
    C:\WINXP\Explorer.EXE
    C:\WINXP\system32\VTTimer.exe
    C:\WINXP\system32\S3trayp.exe
    C:\WINXP\RTHDCPL.EXE
    C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
    C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\WINXP\system32\ctfmon.exe
    C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\WINXP\System32\spool\DRIVERS\W32X86\3\E_FATIBPE.EXE
    C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
    C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    C:\Hotelwd8\binaires\HOTELWD8.exe
    C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
    C:\WINXP\system32\SearchProtocolHost.exe
    C:\Program Files\LogMeIn\x86\LogMeIn.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ixquick.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
    O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe
    O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
    O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
    O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\UltraVNC\WinVNC.exe" -servicehelper
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINXP\system32\ctfmon.exe
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [EPSON Stylus Photo RX560 Series (Copie 1)] C:\WINXP\System32\spool\DRIVERS\W32X86\3\E_FATIBPE.EXE /FU "C:\WINXP\TEMP\E_S24.tmp" /EF "HKCU"
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINXP\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINXP\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-21-1844237615-73586283-1801674531-1005\..\Run: [CTFMON.EXE] C:\WINXP\system32\CTFMON.EXE (User 'LogMeInRemoteUser')
    O4 - HKUS\S-1-5-21-1844237615-73586283-1801674531-1005\..\RunOnce: [NeroHomeFirstStart] C:\Program Files\Fichiers communs\Ahead\Lib\NMFirstStart.exe (User 'LogMeInRemoteUser')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINXP\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINXP\system32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Raccourci vers winvnc.exe.lnk = C:\Program Files\UltraVNC\winvnc.exe
    O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINXP\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINXP\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
    O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
    O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
    O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
    O23 - Service: VNC Server (winvnc) - www.ultravnc.fr - C:\Program Files\UltraVNC\WinVNC.exe

    --
    End of file - 8660 bytes
    a b 8 Sécurité
    14 Juin 2008 11:13:34

    Tu as encore des soucis ?
    16 Juin 2008 17:33:30

    non plus rien, tout fonctionne bien :) 

    merci beaucoup pour ton aide et ta patience :) 
    a b 8 Sécurité
    16 Juin 2008 18:53:40

    Bon surf ;) 
    Tom's guide dans le monde
    • Allemagne
    • Italie
    • Irlande
    • Royaume Uni
    • Etats Unis
    Suivre Tom's Guide
    Inscrivez-vous à la Newsletter
    • ajouter à twitter
    • ajouter à facebook
    • ajouter un flux RSS