Virus qui redirige les recherches

Bonjour,

Comme je le dis dans le titre, j'ai attrapé un virus qui redirige mes recherches dans google pour m'afficher toujours les mêmes pages (une page pornographique, une page pour les cartes de crédit et une page qui fait semblant de faire un scan de mon pc).
J'ai trouvé plusieurs posts sur ce forum de personnes qui ont le même probleme que moi. Pour résoudre ce problème, ils utilisent hijackThis, fixwareout. Le probleme, c'est que je n'arrive pas à télécharger ces programmes. Pour HijackThis, je l'ai téléchargé sur un autre pc mais je ne sais pas le lancer...
J'ai aussi testé des programmes de désinfection mais il ne se lancent pas. Est-ce que quelqu'un a une idée ?
Merci beaucoup d'avance !
Configuration: Windows XP
Firefox 3.0.5

31 réponses

Résumé de la discussion

Une infection du navigateur redirige systématiquement les recherches Google vers des pages indésirables (pornographiques, cartes de crédit et faux scan), avec Windows XP et Firefox 3.0.5 comme configuration. Plusieurs publications recommandent des outils comme HijackThis, FixWareout et FindyKill pour identifier et nettoyer les infections, mais les utilisateurs rencontrent des difficultés de téléchargement, d'exécution et de compatibilité sur Windows XP. Des recommandations concrètes incluent l'exécution de FindyKill sur les disques amovibles après installation, puis un rapport à poster; d'autres promeuvent Dr.Web CureIt, SmitfraudFix et ComboFix selon les cas. Des précautions telles que le démarrage en mode sans échec et la sauvegarde des rapports sont mentionnées pour éviter la disparition des fichiers nettoyés lors du redémarrage.

Bobot (l’IA à votre service)
  1. Salut,

    Fait ton rapport hijackthis sur le pc infecter si tu peut.
    0
    1. Hello,

      Voila, j'ai réussi à télécharger HijackThis après plusieurs essais. Voici le résultat :

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 11:30:42, on 5/01/2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.20935)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\Program Files\LANDesk\Shared Files\residentagent.exe
      C:\WINDOWS\system32\CTsvcCDA.exe
      C:\Program Files\LANDesk\LDClient\LocalSch.EXE
      C:\WINDOWS\system32\CBA\pds.exe
      C:\Program Files\LANDesk\LDClient\tmcsvc.exe
      C:\PROGRA~1\LANDesk\LDClient\issuser.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\McAfee\Common Framework\FrameworkService.exe
      C:\PROGRA~1\LANDesk\LDClient\collector.exe
      C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
      C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
      C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\cygwin\bin\cygrunsrv.exe
      C:\Program Files\LANDesk\LDClient\softmon.exe
      C:\cygwin\bin\rsync.exe
      C:\cygwin\bin\cygrunsrv.exe
      C:\Program Files\UPHClean\uphclean.exe
      C:\cygwin\usr\sbin\sshd.exe
      C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
      C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
      C:\Program Files\Common Files\Real\Update_OB\realsched.exe
      C:\Program Files\LANDesk\LDClient\webportal\sdclientmonitor.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Program Files\Analog Devices\Core\smax4pnp.exe
      C:\WINDOWS\system32\igfxtray.exe
      C:\WINDOWS\system32\hkcmd.exe
      C:\WINDOWS\system32\igfxpers.exe
      C:\WINDOWS\system32\igfxsrvc.exe
      C:\Program Files\McAfee\Common Framework\UdaterUI.exe
      C:\Program Files\McAfee\Common Framework\McTray.exe
      C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
      C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
      C:\Program Files\DAEMON Tools Lite\daemon.exe
      C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
      C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
      C:\PROGRA~1\LANDesk\LDClient\rcgui.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      D:\Documents and Settings\Administrator\Desktop\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.veosearch.com/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

      https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

      https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

      https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

      https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://uclouvain.be/fr/index.html
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride =

      *.local
      R3 - URLSearchHook: (no name) - {BE89472C-B803-4D1D-9A9A-0A63660E0FE3} - C:\PROGRA~1

      \COPERN~1\COPERN~1.DLL
      F2 - REG:system.ini: UserInit=userinit.exe,
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -

      C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1

      \SPYBOT~1\SDHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program

      Files\Java\jre1.6.0_07\bin\ssv.dll
      O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program

      Files\McAfee\VirusScan Enterprise\scriptcl.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program

      files\google\googletoolbar2.dll
      O3 - Toolbar: Copernic Agent - {F2E259E8-0FC8-438C-A6E0-342DD80FA53E} - C:\Program

      Files\Copernic Agent\CopernicAgentExt.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program

      files\google\googletoolbar2.dll
      O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef

      /Migration32
      O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
      O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
      O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Roxio\Easy CD Creator 5

      \DirectCD\DirectCD.exe
      O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update

      Manager\sgtray.exe" /r
      O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
      O4 - HKLM\..\Run: [Zetes Card kit Certificate Installer] "C:\Program

      Files\ZetesCardkit\tools\CheckCardkitTray.exe"
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"

      -osboot
      O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE"

      /STANDALONE
      O4 - HKLM\..\Run: [IntelAPMClient] "C:\Program Files\LANDesk\LDClient\amclient.exe" /apm /s

      /ro /Retry=2 /Tspan=60 /Rstart
      O4 - HKLM\..\Run: [SDClientMonitor] "C:\Program

      Files\LANDesk\LDClient\webportal\sdclientmonitor.exe"
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
      O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
      O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
      O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe"

      /StartedFromRunKey
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0

      \Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [CTCheck] C:\Program Files\Creative\Creative ZEN\ZEN Media

      Explorer\CTCheck.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
      O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -

      autorun
      O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%

      \Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SYSTEM')
      O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientAXDisabler] cmd.exe /C "%systemroot%

      \Installer\TSClientMsiTrans\tscdsbl.bat" (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%

      \Installer\TSClientMsiTrans\tscuinst.vbs" (User 'Default user')
      O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4

      \program\quickstart.exe
      O8 - Extra context menu item: Chercher avec Copernic Agent - res://C:\Program Files\Copernic

      Agent\CopernicAgentExt.rdl/INTEGRATION_MENU_SEARCHEXT
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2

      \OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

      Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

      C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra button: (no name) - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRA~1

      \COPERN~1\COPERN~1.EXE
      O9 - Extra 'Tools' menuitem: Démarrer Copernic Agent - {193B17B0-7C9F-4D5B-AEAB-

      8D3605EFC084} - C:\PROGRA~1\COPERN~1\COPERN~1.EXE
      O9 - Extra button: Copernic Agent - {688DC797-DC11-46A7-9F1B-445F4F58CE6E} - C:\PROGRA~1

      \COPERN~1\COPERN~1.EXE
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} -

      C:\WINDOWS\bdoscandel.exe
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-

      9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2

      \OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1

      \SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-

      A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network

      Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} -

      C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

      Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

      C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation

      Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -

      http://download.bitdefender.com/resources/scan8/oscan8.cab
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -

      http://update.microsoft.com/...

      1164877854609
      O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support

      Package) - http://www.creative.com/softwareupdate/su2/ocx/15035/CTPID.cab
      O17 - HKLM\System\CCS\Services\Tcpip\..\{9BFBD6F0-4C03-498B-A0DB-A713017188E4}: NameServer =

      130.104.1.1,130.104.1.2
      O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program

      Files\Lavasoft\Ad-Aware\aawservice.exe
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common

      Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple

      Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: LANDesk(R) Management Agent (CBA8) - LANDesk Software, Ltd. - C:\Program

      Files\LANDesk\Shared Files\residentagent.exe
      O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd -

      C:\WINDOWS\system32\CTsvcCDA.exe
      O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common

      Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program

      Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Intel Local Scheduler Service - LANDesk Software, Ltd. - C:\Program

      Files\LANDesk\LDClient\LocalSch.EXE
      O23 - Service: Intel PDS - LANDesk Software Ltd. - C:\WINDOWS\system32\CBA\pds.exe
      O23 - Service: Multicast LANDesk ciblé (Intel Targeted Multicast) - LANDesk Software, Ltd. -

      C:\Program Files\LANDesk\LDClient\tmcsvc.exe
      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program

      Files\iPod\bin\iPodService.exe
      O23 - Service: Service de contrôle à distance LANDesk (ISSUSER) - LANDesk Software, Ltd. -

      C:\PROGRA~1\LANDesk\LDClient\issuser.exe
      O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\MATLAB701

      \webserver\bin\win32\matlabserver.exe
      O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program

      Files\McAfee\Common Framework\FrameworkService.exe
      O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan

      Enterprise\Mcshield.exe
      O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program

      Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
      O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common

      Files\Ahead\Lib\NMIndexingService.exe (file missing)
      O23 - Service: OracleOraHome92ClientCache - Unknown owner - C:\oracle\ora92\BIN\ONRSD.EXE
      O23 - Service: Rsync daemon (Rsyncd) - Unknown owner - C:\cygwin\bin\cygrunsrv.exe
      O23 - Service: LANDesk(R) Software Monitoring Service (Softmon) - LANDesk Software, Ltd. -

      C:\Program Files\LANDesk\LDClient\softmon.exe
      O23 - Service: CYGWIN sshd (sshd) - Unknown owner - C:\cygwin\bin\cygrunsrv.exe
      0
      1. Re,

        ▶ Installe - Télécharge SmitfraudFix (de de S!Ri, balltrap34 et moe31)

        ▶ Option:1 => Recherche:

        ▶ Double cliquer sur SmitfraudFix.exe

        ▶ Sélectionner 1 et pressez =>Entrée dans le menu pour créer

        ▶ un rapport des fichiers responsables de l'infection. Le rapport se trouve à la racine du disque

        système

        ▶ C:\rapport.txt et colle le rapport génèrer sur le forum.

        ▶ Ne pas faire l'option 2 sans un avis d'une personne compétente*<=

        Tutoriel Smitfraudix

        Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.
        0
        1. Voici ce que donne le rapport de SmitfraudFix :

          SmitFraudFix v2.388

          Scan done at 11:39:11.25, lun. 05/01/2009
          Run from D:\Documents and Settings\Administrator\Desktop\SmitfraudFix
          OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
          The filesystem type is
          Fix run in normal mode

          »»»»»»»»»»»»»»»»»»»»»»»» Process

          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\Program Files\LANDesk\Shared Files\residentagent.exe
          C:\WINDOWS\system32\CTsvcCDA.exe
          C:\Program Files\LANDesk\LDClient\LocalSch.EXE
          C:\WINDOWS\system32\CBA\pds.exe
          C:\Program Files\LANDesk\LDClient\tmcsvc.exe
          C:\PROGRA~1\LANDesk\LDClient\issuser.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\McAfee\Common Framework\FrameworkService.exe
          C:\PROGRA~1\LANDesk\LDClient\collector.exe
          C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
          C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
          C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
          C:\cygwin\bin\cygrunsrv.exe
          C:\Program Files\LANDesk\LDClient\softmon.exe
          C:\cygwin\bin\rsync.exe
          C:\cygwin\bin\cygrunsrv.exe
          C:\Program Files\UPHClean\uphclean.exe
          C:\cygwin\usr\sbin\sshd.exe
          C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
          C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
          C:\Program Files\Common Files\Real\Update_OB\realsched.exe
          C:\Program Files\LANDesk\LDClient\webportal\sdclientmonitor.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\Program Files\Analog Devices\Core\smax4pnp.exe
          C:\WINDOWS\system32\igfxtray.exe
          C:\WINDOWS\system32\hkcmd.exe
          C:\WINDOWS\system32\igfxpers.exe
          C:\WINDOWS\system32\igfxsrvc.exe
          C:\Program Files\McAfee\Common Framework\UdaterUI.exe
          C:\Program Files\McAfee\Common Framework\McTray.exe
          C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
          C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
          C:\Program Files\DAEMON Tools Lite\daemon.exe
          C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
          C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
          C:\PROGRA~1\LANDesk\LDClient\rcgui.exe
          C:\Program Files\iPod\bin\iPodService.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\WINDOWS\system32\cmd.exe

          »»»»»»»»»»»»»»»»»»»»»»»» hosts

          hosts file corrupted !

          127.0.0.1 www.legal-at-spybot.info
          127.0.0.1 legal-at-spybot.info

          »»»»»»»»»»»»»»»»»»»»»»»» D:\

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

          »»»»»»»»»»»»»»»»»»»»»»»» D:\Documents and Settings\Administrator

          »»»»»»»»»»»»»»»»»»»»»»»» D:\DOCUME~1\ADMINI~1\LOCALS~1\Temp

          »»»»»»»»»»»»»»»»»»»»»»»» D:\Documents and Settings\Administrator\Application Data

          »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

          »»»»»»»»»»»»»»»»»»»»»»»» D:\DOCUME~1\ADMINI~1\FAVORI~1

          »»»»»»»»»»»»»»»»»»»»»»»» Desktop

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

          »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

          »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
          "Source"="About:Home"
          "SubscribedURL"="About:Home"
          "FriendlyName"="My Current Home Page"

          »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
          !!!Attention, following keys are not inevitably infected!!!

          o4Patch
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
          !!!Attention, following keys are not inevitably infected!!!

          IEDFix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
          !!!Attention, following keys are not inevitably infected!!!

          Agent.OMZ.Fix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» VACFix
          !!!Attention, following keys are not inevitably infected!!!

          VACFix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
          !!!Attention, following keys are not inevitably infected!!!

          404Fix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
          !!!Attention, following keys are not inevitably infected!!!

          SrchSTS.exe by S!Ri
          Search SharedTaskScheduler's .dll

          »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
          !!!Attention, following keys are not inevitably infected!!!

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
          "AppInit_DLLs"=""

          »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
          !!!Attention, following keys are not inevitably infected!!!

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
          "Userinit"="userinit.exe,"
          "System"=""

          »»»»»»»»»»»»»»»»»»»»»»»» RK

          »»»»»»»»»»»»»»»»»»»»»»»» DNS

          Description: Intel(R) 82566DM Gigabit Network Connection - Packet Scheduler Miniport
          DNS Server Search Order: 130.104.1.1
          DNS Server Search Order: 130.104.1.2

          HKLM\SYSTEM\CCS\Services\Tcpip\..\{9BFBD6F0-4C03-498B-A0DB-A713017188E4}: NameServer=130.104.1.1,130.104.1.2
          HKLM\SYSTEM\CS1\Services\Tcpip\..\{9BFBD6F0-4C03-498B-A0DB-A713017188E4}: NameServer=130.104.1.1,130.104.1.2
          HKLM\SYSTEM\CS2\Services\Tcpip\..\{9BFBD6F0-4C03-498B-A0DB-A713017188E4}: NameServer=130.104.1.1,130.104.1.2

          »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

          »»»»»»»»»»»»»»»»»»»»»»»» End
          0
          1. Re,

            ▶ Télécharge cet outil de SiRi:

            RHosts

            𥭭ouble cliquer dessus pour l'exécuter

            ▶ Cliquer sur " Restore original Hosts "

            NB : c est normal que rien ne se passe .

            ========================================================================
            Smithfraudix option 2:

            ▶ Démarre en mode sans échec :

            ▶ Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter

            ▶ Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.

            ▶ Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
            (Si F8 ne marche pas utilise la touche F5).
            ----------------------------------------------------------------------------
            ▶ Relance le programme Smitfraud :

            ▶ Cette fois choisit l’option 2, répond oui à tous ;

            ▶ Sauvegarde le rapport, Redémarre en mode normal, copie/colle le rapport sauvegardé sur le forum
            0
            1. Voici ce que donne le rapport après l'option 2 de Smitfraud :

              SmitFraudFix v2.388

              Scan done at 11:53:46.67, lun. 05/01/2009
              Run from D:\Documents and Settings\Administrator\Desktop\SmitfraudFix
              OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
              The filesystem type is
              Fix run in safe mode

              »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
              !!!Attention, following keys are not inevitably infected!!!

              SrchSTS.exe by S!Ri
              Search SharedTaskScheduler's .dll

              »»»»»»»»»»»»»»»»»»»»»»»» Killing process

              »»»»»»»»»»»»»»»»»»»»»»»» hosts

              127.0.0.1 localhost

              »»»»»»»»»»»»»»»»»»»»»»»» VACFix

              VACFix
              Credits: Malware Analysis & Diagnostic
              Code: S!Ri

              »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

              S!Ri's WS2Fix: LSP not Found.
              »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

              GenericRenosFix by S!Ri

              »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

              »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

              IEDFix
              Credits: Malware Analysis & Diagnostic
              Code: S!Ri

              »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix

              Agent.OMZ.Fix
              Credits: Malware Analysis & Diagnostic
              Code: S!Ri

              »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

              404Fix
              Credits: Malware Analysis & Diagnostic
              Code: S!Ri

              »»»»»»»»»»»»»»»»»»»»»»»» RK

              »»»»»»»»»»»»»»»»»»»»»»»» DNS

              HKLM\SYSTEM\CCS\Services\Tcpip\..\{9BFBD6F0-4C03-498B-A0DB-A713017188E4}: NameServer=130.104.1.1,130.104.1.2
              HKLM\SYSTEM\CS1\Services\Tcpip\..\{9BFBD6F0-4C03-498B-A0DB-A713017188E4}: NameServer=130.104.1.1,130.104.1.2
              HKLM\SYSTEM\CS2\Services\Tcpip\..\{9BFBD6F0-4C03-498B-A0DB-A713017188E4}: NameServer=130.104.1.1,130.104.1.2

              »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files

              »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
              !!!Attention, following keys are not inevitably infected!!!

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
              "System"=""

              »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

              Registry Cleaning done.

              »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
              !!!Attention, following keys are not inevitably infected!!!

              SrchSTS.exe by S!Ri
              Search SharedTaskScheduler's .dll

              »»»»»»»»»»»»»»»»»»»»»»»» End
              0
              1. Re,

                ▶ Télécharge random's system information tool (RSIT) et enregistre le sur ton bureau.

                ▶ Double clique sur RSIT.exe pour lancer l'outil.

                ▶ Clique sur ' continue ' à l'écran Disclaimer.

                ▶ Si l'outil HIjackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.

                ▶ Une fois le scan fini , 2 rapports vont apparaitre. Poste le contenu des 2 rapports
                ( log.txt & info.txt )

                (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.
                0
                1. Voici le contenu du fichier info.txt :

                  info.txt logfile of random's system information tool 1.05 2009-01-05 12:08:13

                  ======Uninstall list======

                  -->"C:\Program Files\Creative Installation Information\CD_RIPPER_UNICODE_2\Setup.exe" /remove /nolog/l0x040c
                  -->"C:\Program Files\Creative Installation Information\CREATIVE_SYNC_MANAGER_U\Setup.exe" /remove /nolog/l0x040c
                  -->"C:\Program Files\Creative Installation Information\CREATIVE_VIDEO_CONVERTER\Setup.exe" /remove /nolog/l0x040c
                  -->C:\WINDOWS\system32\\MSIEXEC.EXE /I {09DA4F91-2A09-4232-AB8C-6BC740096DE3} REMOVE=UpdateMgrFeature
                  -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
                  -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x40c
                  -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88B1984E-36F0-47B8-B8DC-728966807A9C}\SETUP.EXE" -l0x40c
                  -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
                  7-Zip 4.42-->"C:\Program Files\7-Zip\Uninstall.exe"
                  Ad-Aware-->MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
                  Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)-->MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7}
                  Adobe Anchor Service CS3-->MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
                  Adobe Asset Services CS3-->MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
                  Adobe Bridge CS3-->MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}
                  Adobe Bridge Start Meeting-->MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}
                  Adobe Camera Raw 4.0-->MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
                  Adobe CMaps-->MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
                  Adobe Color Common Settings-->MsiExec.exe /I{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}
                  Adobe Color EU Extra Settings-->MsiExec.exe /I{51846830-E7B2-4218-8968-B77F0FF475B8}
                  Adobe Color JA Extra Settings-->MsiExec.exe /I{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}
                  Adobe Color NA Recommended Settings-->MsiExec.exe /I{95655ED4-7CA5-46DF-907F-7144877A32E5}
                  Adobe Device Central CS3-->MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
                  Adobe ExtendScript Toolkit 2-->MsiExec.exe /I{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}
                  Adobe Flash CS3 Professional-->C:\Program Files\Common Files\Adobe\Installers\c3c7fe8b09d497ab2b3fd91c9353390\Setup.exe
                  Adobe Flash CS3-->MsiExec.exe /I{6B52140A-F189-4945-BFFC-DB3F00B8C589}
                  Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
                  Adobe Flash Player 9 ActiveX-->MsiExec.exe /X{BC4F8E84-5E29-49EC-B4E7-E6F9CB50986C}
                  Adobe Flash Player Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
                  Adobe Flash Video Encoder-->MsiExec.exe /I{2EFFFC71-1E66-454E-A6E6-CEEC800B96D2}
                  Adobe Help Viewer CS3-->MsiExec.exe /I{04AF207D-9A77-465A-8B76-991F6AB66245}
                  Adobe Linguistics CS3-->MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}
                  Adobe PDF Library Files-->MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
                  Adobe Reader 8.1.2 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81200000003}
                  Adobe Setup-->MsiExec.exe /I{FFC1ADE3-944B-4231-894E-3903C37271D2}
                  Adobe Shockwave Player-->C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
                  Adobe SVG Viewer 3.0-->C:\Program Files\Common Files\Adobe\SVG Viewer 3.0\Uninstall\Winstall.exe -u -fC:\Program Files\Common Files\Adobe\SVG Viewer 3.0\Uninstall\Install.log
                  Adobe Type Support-->MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}
                  Adobe Update Manager CS3-->MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}
                  Adobe Version Cue CS3 Client-->MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}
                  Adobe WinSoft Linguistics Plugin-->MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
                  Agent avancé LANDesk-->MsiExec.exe /I{7E8833A1-AF24-4CAE-82DF-CFE14C14B94D}
                  Apple Mobile Device Support-->MsiExec.exe /I{3EBD3749-304E-4A4C-9575-C00E5F015217}
                  Apple Software Update-->MsiExec.exe /I{02DFF6B1-1654-411C-8D7B-FD6052EF016F}
                  Blender (remove only)-->"C:\Program Files\Blender Foundation\Blender\uninstall.exe"
                  BlueJ 2.2.1-->"C:\Program files\BlueJ\uninst\unins000.exe"
                  CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
                  Client Citrix Presentation Server-->MsiExec.exe /I{E89956F9-5B89-470E-818D-BD46102D0A01}
                  Compatibility Pack for the 2007 Office system-->MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
                  ConTEXT-->"C:\Program Files\ConTEXT\unins000.exe"
                  Copernic Agent Basic-->"C:\WINDOWS\CopernicAgentUninstall.exe" /ARGSFILE="C:\Program Files\Copernic Agent\unwise.dat"
                  Creative Software AutoUpdate-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88B1984E-36F0-47B8-B8DC-728966807A9C}\SETUP.EXE" -l0x40c /remove
                  Creative System Information-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x40c /remove
                  Creative ZEN-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1B2DBF55-05D4-4072-87D8-689141E262BD}\SETUP.EXE" -l0x40c /remove
                  dBpoweramp m4a Codec-->"C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpoweramp m4a Codec.dat
                  dBpoweramp m4b Audio book Encoder-->"C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpoweramp m4b Audio book Encoder.dat
                  Easy CD Creator 5 Basic-->MsiExec.exe /I{609F7AC8-C510-11D4-A788-009027ABA5D0}
                  EasyCleaner-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F5346614-B7C4-4E94-826A-E2363155233D}\setup.exe" -l0x9 -removeonly
                  EasyPHP 2.0b1-->"C:\Program Files\EasyPHP 2.0b1\unins000.exe"
                  Eudora-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7710A70A-8AC1-4CD6-8FEE-A786389C5CBE}\setup.exe" -l0x40c
                  EVEREST Home Edition v2.20-->"C:\Program Files\Lavalys\EVEREST Home Edition\unins000.exe"
                  FileZilla Client 3.0.1-->C:\Program Files\FileZilla Client\uninstall.exe
                  Gimp 2.6.2 Debug-->"C:\Program Files\GIMP-2.0\setup\unins001.exe"
                  Google SketchUp 6-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{98736A65-3C79-49EC-B7E9-A3C77774B0E6}\setup.exe" -l0x40c -removeonly
                  Google SketchUp 6-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B3D8B2F8-3C2C-45BC-933E-8B60E78F6684}\setup.exe" -l0x40c -removeonly
                  Google Toolbar for Internet Explorer-->MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
                  Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar2.dll"
                  GSAS & EXPGUI-->"C:\WINDOWS\lsb_un20.exe" /C=UC /N=GSAS & EXPGUI
                  GTK+ 2.10.13 runtime environment-->"C:\Program Files\Common Files\GTK\2.0\setup\unins000.exe"
                  HijackThis 2.0.2-->"D:\Documents and Settings\Administrator\Desktop\HijackThis.exe" /uninstall
                  HKL CHANNEL 5 service pack 9-->"C:\Program files\Channel5\Uninstall\59\unins000.exe"
                  HKL CHANNEL 5.0.4-->"C:\Program files\Channel5\Uninstall\50\unins000.exe"
                  HKL CHANNEL5 Main installer 5.0.4-->"C:\Program files\Channel5\Uninstall\CH5Main\unins000.exe"
                  HKL HASP copy protection 5.0.1-->"C:\Program files\Channel5\Uninstall\HI\unins000.exe"
                  Hotfix for Microsoft .NET Framework 3.0 (KB932471)-->C:\WINDOWS\system32\msiexec.exe /promptrestart /uninstall {ECD292A0-0347-4244-8C24-5DBCE990FB40} /package {BAF78226-3200-4DB4-BE33-4D922A799840}
                  Hotfix for Windows Internet Explorer 7 (KB929798)-->"C:\WINDOWS\ie7updates\KB929798-IE7\spuninst\spuninst.exe"
                  Hotfix for Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
                  Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
                  HP USB Disk Storage Format Tool-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0E0DF90C-D0BA-4C89-9262-AD78D1A3DE51}\Setup.exe" -l0x9
                  ImageJ 1.40g-->"C:\Program Files\ImageJ\unins000.exe"
                  InfraRecorder-->C:\Program Files\InfraRecorder\uninstall.exe
                  Inkscape 0.46-->C:\Program Files\Inkscape\Uninstall.exe
                  Intel(R) PRO Network Connections Drivers-->Prounstl.exe
                  IrfanView (remove only)-->C:\Program Files\IrfanView\iv_uninstall.exe
                  iTunes-->MsiExec.exe /I{B045B608-4A47-4C77-9EAD-06C394503306}
                  JabRef 2.3.1-->C:\Program Files\JabRef\uninstall.exe
                  Java DB 10.3.1.4-->MsiExec.exe /X{CD49361E-3FE6-457E-90A1-9C59E29B5D02}
                  Java(TM) 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
                  Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
                  Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
                  Java(TM) SE Development Kit 6 Update 6-->MsiExec.exe /I{32A3A4F4-B792-11D6-A78A-00B0D0160060}
                  KaleidaGraph 4.0-->C:\WINDOWS\unvise32.exe C:\Program Files\KaleidaGraph 4.0\uninstal.log
                  MATLAB Family of Products Release 14-->C:\MATLAB701\uninstall\uninstall.exe C:\MATLAB701\
                  McAfee AntiSpyware Enterprise Module-->"C:\Program Files\McAfee\VirusScan Enterprise\scan32.exe" /UninstallMAS
                  McAfee VirusScan Enterprise-->MsiExec.exe /I{35C03C04-3F1F-42C2-A989-A757EE691F65}
                  Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
                  Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                  Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                  Microsoft .NET Framework 2.0 Service Pack 1 Language Pack - ESN-->MsiExec.exe /I{BB0DCC5E-7477-3350-B5F5-7CE64E1E83B6}
                  Microsoft .NET Framework 2.0 Service Pack 1 Language Pack - FRA-->MsiExec.exe /I{3F7924B9-D148-3141-87B1-68F36043A940}
                  Microsoft .NET Framework 2.0 Service Pack 1 Language Pack - NLD-->MsiExec.exe /I{220C5102-2566-337F-9E9B-C81C5C761BA2}
                  Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
                  Microsoft .NET Framework 3.0 Service Pack 1 Language Pack - ESN-->MsiExec.exe /I{12E0A949-8861-35F8-B7ED-5658788A7BFE}
                  Microsoft .NET Framework 3.0 Service Pack 1 Language Pack - FRA-->MsiExec.exe /I{511DF669-2930-30C0-8EB6-552887E29EC8}
                  Microsoft .NET Framework 3.0 Service Pack 1 Language Pack - NLD-->MsiExec.exe /I{8C788975-88ED-3C52-A188-6C944E9BD07D}
                  Microsoft .NET Framework 3.0 Service Pack 1-->MsiExec.exe /I{2BA00471-0328-3743-93BD-FA813353A783}
                  Microsoft .NET Framework 3.5 Language Pack - esn-->MsiExec.exe /I{298B7460-A43A-3083-B295-75547FC68392}
                  Microsoft .NET Framework 3.5 Language Pack - fra-->MsiExec.exe /I{5B76AEA2-D4E5-3B55-B965-ACC36AE0EAFC}
                  Microsoft .NET Framework 3.5 Language Pack - nld-->MsiExec.exe /I{A395750A-78D7-36D1-A59D-1A0B601D4BDC}
                  Microsoft .NET Framework 3.5-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5\setup.exe
                  Microsoft .NET Framework 3.5-->MsiExec.exe /I{2FC099BD-AC9B-33EB-809C-D332E1B27C40}
                  Microsoft Office 2003 Dutch User Interface Pack-->MsiExec.exe /I{901E0413-6000-11D3-8CFE-0150048383C9}
                  Microsoft Office 2003 French User Interface Pack-->MsiExec.exe /I{901E040C-6000-11D3-8CFE-0150048383C9}
                  Microsoft Office 2003 Spanish User Interface Pack-->MsiExec.exe /I{901E0C0A-6000-11D3-8CFE-0150048383C9}
                  Microsoft Office Professional Edition 2003-->MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
                  Microsoft Silverlight-->MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
                  Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
                  Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022-->MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
                  Module linguistique Microsoft .NET Framework 3.5 - fra-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack - fra\setup.exe
                  Mozilla Firefox (3.0.5)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                  Mozilla Sunbird (0.5)-->C:\Program Files\Mozilla Sunbird\uninstall\uninst.exe
                  Mozilla Thunderbird (2.0.0.18)-->C:\Program Files\Mozilla Thunderbird\uninstall\helper.exe
                  MSXML 4.0 SP2 (KB925672)-->MsiExec.exe /I{A9CF9052-F4A0-475D-A00F-A8388C62DD63}
                  MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
                  MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
                  MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                  MSXML 6.0 Parser (KB933579)-->MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
                  neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
                  Netscape Communicator 4.7-->C:\WINDOWS\cd32.exe 4.7 (fr)
                  Notepad++-->C:\Program Files\Notepad++\uninstall.exe
                  Nvu 1.0-->"C:\Program Files\Nvu\unins000.exe"
                  ODF Add-in for Microsoft Word-->MsiExec.exe /I{E6738F45-D704-4D83-9E51-24695E717D09}
                  OGA Notifier 1.7.0102.0-->MsiExec.exe /I{049F2E8F-D5EC-4133-87FA-8E94837D8D0C}
                  OpenOffice.org 2.4-->MsiExec.exe /I{B6694BAA-7604-46AA-A41F-B5F1E6DADE7A}
                  Paquete de idioma de Microsoft .NET Framework 3.5 - esn-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack - esn\setup.exe
                  PDF Settings-->MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
                  PDFCreator-->C:\Program Files\PDFCreator\unins000.exe
                  PowerDVD 5.5-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\Setup.exe" -uninstall
                  PuTTY version 0.60-->"C:\Program Files\PuTTY\unins000.exe"
                  QuickTime-->MsiExec.exe /I{08CA9554-B5FE-4313-938F-D4A417B81175}
                  SAP Front End-->"C:\WINDOWS\SAPwksta\setup\sapsetup.exe" /uninstall
                  SciFinder Scholar 2007-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\SFSCHLR\Uninstall\SETUP.EXE" -l0x9
                  SecureW2 TTLS Client 3.3.3 for Windows-->C:\Program Files\SecureW2\SecureW2 TTLS Client\Uninstall.exe
                  Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                  Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                  Security Update for Windows Internet Explorer 7 (KB928090)-->"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
                  Security Update for Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
                  Security Update for Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
                  Security Update for Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
                  Security Update for Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
                  Security Update for Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
                  Security Update for Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
                  Security Update for Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
                  Security Update for Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
                  Security Update for Windows Media Player (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
                  Security Update for Windows Media Player 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
                  Security Update for Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
                  Security Update for Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
                  Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
                  Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
                  Security Update for Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
                  Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
                  Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
                  Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
                  Security Update for Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
                  Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
                  Security Update for Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
                  Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
                  Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
                  Security Update for Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
                  Security Update for Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
                  Security Update for Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
                  Security Update for Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
                  Security Update for Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
                  Security Update for Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
                  Security Update for Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
                  Security Update for Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
                  Security Update for Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
                  Security Update for Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
                  Security Update for Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
                  Security Update for Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
                  Shared Add-in Extensibility Update for Microsoft .NET Framework 2.0 (KB908002)-->MsiExec.exe /X{09959E11-AD5D-408E-96AF-E3346954D6B8}
                  Shared Add-in Support Update for Microsoft .NET Framework 2.0 (KB908002)-->MsiExec.exe /X{64F3B15C-24C7-4B2B-9B72-65CCBBD7F06B}
                  Sibelius Scorch-->MsiExec.exe /I{51C65CD6-A344-41B5-81E2-3CCAC8024F68}
                  SigmaPlot 10.0-->MsiExec.exe /I{43224D30-5941-47A4-9AD7-9250EE794396}
                  Sonic RecordNow! Plus-->MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}
                  Sonic Update Manager-->MsiExec.exe /I{09DA4F91-2A09-4232-AB8C-6BC740096DE3}
                  Spelling Dictionaries Support For Adobe Reader 8-->MsiExec.exe /I{AC76BA86-7AD7-5464-3428-800000000003}
                  Spybot - Search & Destroy 1.4-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
                  Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins001.exe"
                  Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
                  Taalpakket voor Microsoft .NET Framework 3.5 - NL-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack - nld\setup.exe
                  Type1027 TWAIN Driver Ver.3-->C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\TWAIN_32\Ricoh_V3\NeoRC2E\Uninst.isu -c"C:\WINDOWS\TWAIN_32\Ricoh_V3\NeoRC2E\cbmp.dll"
                  Update for Windows XP (KB943729)-->"C:\WINDOWS\$NtUninstallKB943729$\spuninst\spuninst.exe"
                  Update for Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
                  Update for Windows XP (KB951618-v2)-->"C:\WINDOWS\$NtUninstallKB951618-v2$\spuninst\spuninst.exe"
                  Update for Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
                  Update for Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
                  User Profile Hive Cleanup Service-->MsiExec.exe /I{FF77941A-2BFA-4A18-BE2E-69B9498E4D55}
                  VideoLAN VLC media player 0.8.6f-->C:\Program Files\VideoLAN\VLC\uninstall.exe
                  Windows Internet Explorer 7 Multilingual User Interface (MUI)-->"C:\WINDOWS\ie7updates\IE7-MUI\spuninst\spuninst.exe"
                  Windows Live Messenger-->MsiExec.exe /I{E22885AB-B503-46E2-8437-73BBC6BC5487}
                  Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
                  Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
                  Windows Presentation Foundation-->MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
                  Windows Rights Management Client Backwards Compatibility SP2-->MsiExec.exe /X{EC905264-BCFE-423B-9C42-C3A106266790}
                  Windows Rights Management Client with Service Pack 2-->MsiExec.exe /X{BDCF27CA-BFC4-4F49-8D24-A925C9505AB8}
                  Windows Support Tools-->MsiExec.exe /I{89B078C4-50B0-453E-BF53-3A7E6A0D85FA}
                  Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
                  WinSCP 4.0.4-->"C:\Program Files\WinSCP3\unins000.exe"
                  XML Paper Specification Shared Components Language Pack 1.0-->"C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe"
                  ZEN Media Explorer-->"C:\Program Files\Creative Installation Information\ZEN_MTP_MEDIA_EXPLORER\Setup.exe" /remove /nolog/l0x040c
                  ZENcast Organizer-->"C:\Program Files\Creative Installation Information\ZENCAST_ORGANIZER\Setup.exe" /remove /nolog/l0x040c
                  Zetes card kit-->"C:\Program Files\ZetesCardkit\uninstall.exe"

                  ======Security center information======

                  AV: VirusScan Enterprise + AntiSpyware Enterprise

                  System event log

                  Computer Name: PH-DUFOUR
                  Event Code: 7035
                  Message: Un contrôle Démarrer a correctement été envoyé au service Windows Image Acquisition (WIA).

                  Record Number: 1725
                  Source Name: Service Control Manager
                  Time Written: 20080411140359.000000+120
                  Event Type: information
                  User: AUTORITE NT\SYSTEM

                  Computer Name: PH-DUFOUR
                  Event Code: 7036
                  Message: Le service Service COM de gravage de CD IMAPI est entré dans l'état : arrêté.

                  Record Number: 1724
                  Source Name: Service Control Manager
                  Time Written: 20080411140355.000000+120
                  Event Type: information
                  User:

                  Computer Name: PH-DUFOUR
                  Event Code: 7036
                  Message: Le service Service COM de gravage de CD IMAPI est entré dans l'état : en cours d'exécution.

                  Record Number: 1723
                  Source Name: Service Control Manager
                  Time Written: 20080411140349.000000+120
                  Event Type: information
                  User:

                  Computer Name: PH-DUFOUR
                  Event Code: 7035
                  Message: Un contrôle Démarrer a correctement été envoyé au service Service COM de gravage de CD IMAPI.

                  Record Number: 1722
                  Source Name: Service Control Manager
                  Time Written: 20080411140349.000000+120
                  Event Type: information
                  User: AUTORITE NT\SYSTEM

                  Computer Name: PH-DUFOUR
                  Event Code: 7036
                  Message: Le service McAfee McShield est entré dans l'état : en cours d'exécution.

                  Record Number: 1721
                  Source Name: Service Control Manager
                  Time Written: 20080411135400.000000+120
                  Event Type: information
                  User:

                  Application event log

                  Computer Name: UNIVERSI-7C07A5
                  Event Code: 0
                  Message:
                  Record Number: 5
                  Source Name: sshd
                  Time Written: 20080409112522.000000+120
                  Event Type: information
                  User: AUTORITE NT\SYSTEM

                  Computer Name: UNIVERSI-7C07A5
                  Event Code: 1800
                  Message: Le service Centre de sécurité Windows a démarré.

                  Record Number: 4
                  Source Name: SecurityCenter
                  Time Written: 20080409112312.000000+120
                  Event Type: information
                  User:

                  Computer Name: UNIVERSI-7C07A5
                  Event Code: 5000
                  Message: Service McShield démarré.

                  Version du moteur : 5200.2160

                  Version du fichier DAT : 5134.0000

                  Nombre de signatures dans le fichier EXTRA.DAT : Aucun

                  Nom des menaces pouvant être détectées par EXTRA.DAT : Aucun

                  Record Number: 3
                  Source Name: McLogEvent
                  Time Written: 20080409112309.000000+120
                  Event Type: information
                  User: AUTORITE NT\SYSTEM

                  Computer Name: UNIVERSI-7C07A5
                  Event Code: 1001
                  Message: User profile hive cleanup service version 1.6.30.0 started successfully.

                  Record Number: 2
                  Source Name: UPHClean
                  Time Written: 20080409112309.000000+120
                  Event Type: information
                  User:

                  Computer Name: UNIVERSI-7C07A5
                  Event Code: 2
                  Message: Le service a démarré.

                  Record Number: 1
                  Source Name: Service de contrôle à distance LANDesk
                  Time Written: 20080409112305.000000+120
                  Event Type: information
                  User:

                  ======Environment variables======

                  "ComSpec"=%SystemRoot%\system32\cmd.exe
                  "CYGWIN"=ntsec tty
                  "DEFLOGDIR"=D:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection
                  "FP_NO_HOST_CHECK"=NO
                  "LANG"=fr
                  "LDMS_LOCAL_DIR"=C:\Program Files\LANDesk\LDClient\Data
                  "NUMBER_OF_PROCESSORS"=2
                  "OS"=Windows_NT
                  "Path"=C:\oracle\ora92\bin;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Common Files\GTK\2.0\bin;C:\Program Files\Common Files\Adaptec Shared\System;C:\Cygwin\bin;C:\Program Files\Support Tools\;C:\qbasic;C:\Program Files\QuickTime\QTSystem\;C:\cygwin;C:\MATLAB701\bin\win32;
                  "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
                  "PROCESSOR_ARCHITECTURE"=x86
                  "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 11, GenuineIntel
                  "PROCESSOR_LEVEL"=6
                  "PROCESSOR_REVISION"=0f0b
                  "TEMP"=%SystemRoot%\TEMP
                  "TMP"=%SystemRoot%\TEMP
                  "VSEDEFLOGDIR"=D:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection
                  "windir"=%SystemRoot%
                  "CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip
                  "QTJAVA"=C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip

                  -----------------EOF-----------------

                  Et voici le contenu du fichier log.txt :

                  Logfile of random's system information tool 1.05 (written by random/random)
                  Run by Administrateur at 2009-01-05 12:08:10
                  Microsoft Windows XP Professionnel Service Pack 3
                  System drive C: has 58 GB (76%) free of 76 GB
                  Total RAM: 2002 MB (67% free)

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 12:08:12, on 5/01/2009
                  Platform: Windows XP SP3 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.20935)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  C:\Program Files\Bonjour\mDNSResponder.exe
                  C:\Program Files\LANDesk\Shared Files\residentagent.exe
                  C:\WINDOWS\system32\CTsvcCDA.exe
                  C:\Program Files\LANDesk\LDClient\LocalSch.EXE
                  C:\WINDOWS\system32\CBA\pds.exe
                  C:\Program Files\LANDesk\LDClient\tmcsvc.exe
                  C:\PROGRA~1\LANDesk\LDClient\issuser.exe
                  C:\MATLAB701\webserver\bin\win32\matlabserver.exe
                  C:\Program Files\McAfee\Common Framework\FrameworkService.exe
                  C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
                  C:\PROGRA~1\LANDesk\LDClient\collector.exe
                  C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
                  C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                  C:\cygwin\bin\cygrunsrv.exe
                  C:\Program Files\LANDesk\LDClient\softmon.exe
                  C:\cygwin\bin\rsync.exe
                  C:\cygwin\bin\cygrunsrv.exe
                  C:\Program Files\UPHClean\uphclean.exe
                  C:\cygwin\usr\sbin\sshd.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
                  C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
                  C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                  C:\Program Files\LANDesk\LDClient\webportal\sdclientmonitor.exe
                  C:\Program Files\iTunes\iTunesHelper.exe
                  C:\PROGRA~1\LANDesk\LDClient\rcgui.exe
                  C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  C:\Program Files\Analog Devices\Core\smax4pnp.exe
                  C:\WINDOWS\system32\igfxtray.exe
                  C:\WINDOWS\system32\hkcmd.exe
                  C:\WINDOWS\system32\igfxpers.exe
                  C:\WINDOWS\system32\igfxsrvc.exe
                  C:\Program Files\McAfee\Common Framework\UdaterUI.exe
                  C:\Program Files\McAfee\Common Framework\McTray.exe
                  C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
                  C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\Program Files\DAEMON Tools Lite\daemon.exe
                  C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
                  C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
                  C:\Program Files\iPod\bin\iPodService.exe
                  G:\RSIT.exe
                  D:\Documents and Settings\Administrator\Desktop\Administrateur.exe

                  R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://uclouvain.be/fr/index.html
                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                  R3 - URLSearchHook: (no name) - {BE89472C-B803-4D1D-9A9A-0A63660E0FE3} - C:\PROGRA~1\COPERN~1\COPERN~1.DLL
                  F2 - REG:system.ini: UserInit=userinit.exe,
                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                  O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                  O3 - Toolbar: Copernic Agent - {F2E259E8-0FC8-438C-A6E0-342DD80FA53E} - C:\Program Files\Copernic Agent\CopernicAgentExt.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                  O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                  O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                  O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                  O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
                  O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
                  O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
                  O4 - HKLM\..\Run: [Zetes Card kit Certificate Installer] "C:\Program Files\ZetesCardkit\tools\CheckCardkitTray.exe"
                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                  O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
                  O4 - HKLM\..\Run: [IntelAPMClient] "C:\Program Files\LANDesk\LDClient\amclient.exe" /apm /s /ro /Retry=2 /Tspan=60 /Rstart
                  O4 - HKLM\..\Run: [SDClientMonitor] "C:\Program Files\LANDesk\LDClient\webportal\sdclientmonitor.exe"
                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                  O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
                  O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
                  O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
                  O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                  O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                  O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
                  O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\Run: [CTCheck] C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                  O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
                  O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
                  O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SYSTEM')
                  O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientAXDisabler] cmd.exe /C "%systemroot%\Installer\TSClientMsiTrans\tscdsbl.bat" (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'Default user')
                  O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
                  O8 - Extra context menu item: Chercher avec Copernic Agent - res://C:\Program Files\Copernic Agent\CopernicAgentExt.rdl/INTEGRATION_MENU_SEARCHEXT
                  O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                  O9 - Extra button: (no name) - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRA~1\COPERN~1\COPERN~1.EXE
                  O9 - Extra 'Tools' menuitem: Démarrer Copernic Agent - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRA~1\COPERN~1\COPERN~1.EXE
                  O9 - Extra button: Copernic Agent - {688DC797-DC11-46A7-9F1B-445F4F58CE6E} - C:\PROGRA~1\COPERN~1\COPERN~1.EXE
                  O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                  O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                  O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                  O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
                  O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su2/ocx/15035/CTPID.cab
                  O17 - HKLM\System\CCS\Services\Tcpip\..\{9BFBD6F0-4C03-498B-A0DB-A713017188E4}: NameServer = 130.104.1.1,130.104.1.2
                  O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                  O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                  O23 - Service: LANDesk(R) Management Agent (CBA8) - LANDesk Software, Ltd. - C:\Program Files\LANDesk\Shared Files\residentagent.exe
                  O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
                  O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: Intel Local Scheduler Service - LANDesk Software, Ltd. - C:\Program Files\LANDesk\LDClient\LocalSch.EXE
                  O23 - Service: Intel PDS - LANDesk Software Ltd. - C:\WINDOWS\system32\CBA\pds.exe
                  O23 - Service: Multicast LANDesk ciblé (Intel Targeted Multicast) - LANDesk Software, Ltd. - C:\Program Files\LANDesk\LDClient\tmcsvc.exe
                  O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                  O23 - Service: Service de contrôle à distance LANDesk (ISSUSER) - LANDesk Software, Ltd. - C:\PROGRA~1\LANDesk\LDClient\issuser.exe
                  O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\MATLAB701\webserver\bin\win32\matlabserver.exe
                  O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
                  O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
                  O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
                  O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
                  O23 - Service: OracleOraHome92ClientCache - Unknown owner - C:\oracle\ora92\BIN\ONRSD.EXE
                  O23 - Service: Rsync daemon (Rsyncd) - Unknown owner - C:\cygwin\bin\cygrunsrv.exe
                  O23 - Service: LANDesk(R) Software Monitoring Service (Softmon) - LANDesk Software, Ltd. - C:\Program Files\LANDesk\LDClient\softmon.exe
                  O23 - Service: CYGWIN sshd (sshd) - Unknown owner - C:\cygwin\bin\cygrunsrv.exe
                  0
                  1. Pas de souci, le voici :

                    Logfile of random's system information tool 1.05 (written by random/random)
                    Run by Administrateur at 2009-01-05 12:08:10
                    Microsoft Windows XP Professionnel Service Pack 3
                    System drive C: has 58 GB (76%) free of 76 GB
                    Total RAM: 2002 MB (67% free)

                    Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 12:08:12, on 5/01/2009
                    Platform: Windows XP SP3 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v7.00 (7.00.6000.20935)
                    Boot mode: Normal

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                    C:\Program Files\Bonjour\mDNSResponder.exe
                    C:\Program Files\LANDesk\Shared Files\residentagent.exe
                    C:\WINDOWS\system32\CTsvcCDA.exe
                    C:\Program Files\LANDesk\LDClient\LocalSch.EXE
                    C:\WINDOWS\system32\CBA\pds.exe
                    C:\Program Files\LANDesk\LDClient\tmcsvc.exe
                    C:\PROGRA~1\LANDesk\LDClient\issuser.exe
                    C:\MATLAB701\webserver\bin\win32\matlabserver.exe
                    C:\Program Files\McAfee\Common Framework\FrameworkService.exe
                    C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
                    C:\PROGRA~1\LANDesk\LDClient\collector.exe
                    C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
                    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                    C:\cygwin\bin\cygrunsrv.exe
                    C:\Program Files\LANDesk\LDClient\softmon.exe
                    C:\cygwin\bin\rsync.exe
                    C:\cygwin\bin\cygrunsrv.exe
                    C:\Program Files\UPHClean\uphclean.exe
                    C:\cygwin\usr\sbin\sshd.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
                    C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
                    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                    C:\Program Files\LANDesk\LDClient\webportal\sdclientmonitor.exe
                    C:\Program Files\iTunes\iTunesHelper.exe
                    C:\PROGRA~1\LANDesk\LDClient\rcgui.exe
                    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                    C:\Program Files\Analog Devices\Core\smax4pnp.exe
                    C:\WINDOWS\system32\igfxtray.exe
                    C:\WINDOWS\system32\hkcmd.exe
                    C:\WINDOWS\system32\igfxpers.exe
                    C:\WINDOWS\system32\igfxsrvc.exe
                    C:\Program Files\McAfee\Common Framework\UdaterUI.exe
                    C:\Program Files\McAfee\Common Framework\McTray.exe
                    C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
                    C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
                    C:\Program Files\Mozilla Firefox\firefox.exe
                    C:\Program Files\DAEMON Tools Lite\daemon.exe
                    C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
                    C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
                    C:\Program Files\iPod\bin\iPodService.exe
                    G:\RSIT.exe
                    D:\Documents and Settings\Administrator\Desktop\Administrateur.exe

                    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://uclouvain.be/fr/index.html
                    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                    R3 - URLSearchHook: (no name) - {BE89472C-B803-4D1D-9A9A-0A63660E0FE3} - C:\PROGRA~1\COPERN~1\COPERN~1.DLL
                    F2 - REG:system.ini: UserInit=userinit.exe,
                    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                    O3 - Toolbar: Copernic Agent - {F2E259E8-0FC8-438C-A6E0-342DD80FA53E} - C:\Program Files\Copernic Agent\CopernicAgentExt.dll
                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                    O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
                    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
                    O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
                    O4 - HKLM\..\Run: [Zetes Card kit Certificate Installer] "C:\Program Files\ZetesCardkit\tools\CheckCardkitTray.exe"
                    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                    O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
                    O4 - HKLM\..\Run: [IntelAPMClient] "C:\Program Files\LANDesk\LDClient\amclient.exe" /apm /s /ro /Retry=2 /Tspan=60 /Rstart
                    O4 - HKLM\..\Run: [SDClientMonitor] "C:\Program Files\LANDesk\LDClient\webportal\sdclientmonitor.exe"
                    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                    O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
                    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
                    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
                    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                    O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
                    O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                    O4 - HKLM\..\Run: [CTCheck] C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                    O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
                    O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
                    O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SYSTEM')
                    O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientAXDisabler] cmd.exe /C "%systemroot%\Installer\TSClientMsiTrans\tscdsbl.bat" (User 'SYSTEM')
                    O4 - HKUS\.DEFAULT\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'Default user')
                    O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
                    O8 - Extra context menu item: Chercher avec Copernic Agent - res://C:\Program Files\Copernic Agent\CopernicAgentExt.rdl/INTEGRATION_MENU_SEARCHEXT
                    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                    O9 - Extra button: (no name) - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRA~1\COPERN~1\COPERN~1.EXE
                    O9 - Extra 'Tools' menuitem: Démarrer Copernic Agent - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRA~1\COPERN~1\COPERN~1.EXE
                    O9 - Extra button: Copernic Agent - {688DC797-DC11-46A7-9F1B-445F4F58CE6E} - C:\PROGRA~1\COPERN~1\COPERN~1.EXE
                    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
                    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su2/ocx/15035/CTPID.cab
                    O17 - HKLM\System\CCS\Services\Tcpip\..\{9BFBD6F0-4C03-498B-A0DB-A713017188E4}: NameServer = 130.104.1.1,130.104.1.2
                    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                    O23 - Service: LANDesk(R) Management Agent (CBA8) - LANDesk Software, Ltd. - C:\Program Files\LANDesk\Shared Files\residentagent.exe
                    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
                    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                    O23 - Service: Intel Local Scheduler Service - LANDesk Software, Ltd. - C:\Program Files\LANDesk\LDClient\LocalSch.EXE
                    O23 - Service: Intel PDS - LANDesk Software Ltd. - C:\WINDOWS\system32\CBA\pds.exe
                    O23 - Service: Multicast LANDesk ciblé (Intel Targeted Multicast) - LANDesk Software, Ltd. - C:\Program Files\LANDesk\LDClient\tmcsvc.exe
                    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                    O23 - Service: Service de contrôle à distance LANDesk (ISSUSER) - LANDesk Software, Ltd. - C:\PROGRA~1\LANDesk\LDClient\issuser.exe
                    O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\MATLAB701\webserver\bin\win32\matlabserver.exe
                    O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
                    O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
                    O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
                    O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
                    O23 - Service: OracleOraHome92ClientCache - Unknown owner - C:\oracle\ora92\BIN\ONRSD.EXE
                    O23 - Service: Rsync daemon (Rsyncd) - Unknown owner - C:\cygwin\bin\cygrunsrv.exe
                    O23 - Service: LANDesk(R) Software Monitoring Service (Softmon) - LANDesk Software, Ltd. - C:\Program Files\LANDesk\LDClient\softmon.exe
                    O23 - Service: CYGWIN sshd (sshd) - Unknown owner - C:\cygwin\bin\cygrunsrv.exe
                    0
                    1. Re,

                      Vire AD-AWARE et fait ce qui suit:

                      ▶ Télécharge CCleaner (N'installe pas la Yahoo Toolbar) :
                      CCLEANER

                      ▶ Lance-le. Va dans "Options" puis "Avancé",

                      ▶ Tu décoches la case "Effacer uniquement les fichiers etc...".

                      ▶ Tu vas dans "Nettoyeur", tu fais "Analyse". Une fois terminé, tu lances le nettoyage.

                      ▶ Tu vas dans "Registre", tu fais "Chercher des erreurs".

                      Une fois terminé, tu répares toutes les erreurs sans sauvegarder la base de registre.

                      ▶ Un tuto ( aide )
                      xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
                      ▶ Télécharge et installe MalwareByte's Anti-Malware
                      Malwarebyte

                      ▶ Mets le à jour

                      ▶ Double clique sur le raccourci de MalwareByte's Anti-Malware qui est sur le bureau.

                      ▶ Sélectionne Exécuter un examen complet si ce n'est pas déjà fait

                      ▶ clique sur Rechercher

                      ▶ Une fois le scan terminé, une fenêtre s'ouvre, clique sur sur Ok

                      ▶ Si MalwareByte's n'a rien détecté, clique sur Ok Un rapport va apparaître ferme-le.

                      ▶ Si MalwareByte's a détecté des infections, clique sur Afficher les résultats ensuite sur Supprimer la sélection

                      ▶ Enregistre le rapport sur ton Bureau comme cela il sera plus facile à retrouver, poste ensuite ce rapport.

                      Note : Si MalwareByte's a besoin de redémarrer pour terminer la suppression, accepte en cliquant sur Ok

                      Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.

                      Tutoriel pour MalwareByte's
                      0
                      1. J'ai lancé Ccleaner par contre, je n'arrive pas à installer malwarebyte. Il est bien téléchargé mais lorsque je double-clique dessus, il ne se passe rien.
                        Est-ce qu'il y a quelque chose que je peux faire pour faciliter l'ouverture de ce programme ?
                        0
                        1. Re,

                          Essai sa pour vérifier un truc:

                          FindyKill de Chiquitine29

                          ▶ Fais un clique droit sur le lien et choisis ( "enregistrer la cible sous ...." )( , destination le bureau .

                          ▶ ( Note importante : si tu as le prg Elibagla sur ton PC , supprimes le ( risque de conflit entre les deux outils ) .

                          ▶ Laisse toi guider pour l'installer.

                          ▶ Double clic sur " FindyKill." pour lancer l'outil .

                          ▶ Choisis La langue:F pour français

                          ▶ Choisis l'option 1 . Puis laisses travailler ...

                          ▶ Une fois terminé, postes le rapport FindyKill.txt qui est généré ...

                          ( Note : le rapport est sauvegardé à la racine du disque -> C:\FindyKill.txt )

                          Les-risques-securitaires-du-peer-to-peer

                          Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.
                          0
                          1. Voila ce que donne FindyKill :

                            ----------------- FindyKill V4.710 ------------------

                            * User : Administrateur - PH-DUFOUR
                            * Emplacement : C:\Program Files\FindyKill
                            * Outils Mis a jours le 21/12/08 par Chiquitine29
                            * Recherche effectuée à 12:35:51 le lun. 05/01/2009
                            * Windows XP - Internet Explorer 7.0.5730.11

                            ((((((((((((((((( *** Recherche *** ))))))))))))))))))

                            --------------- [ Processus actifs ] ----------------

                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\csrss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\WINDOWS\System32\SCardSvr.exe
                            C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                            C:\Program Files\Bonjour\mDNSResponder.exe
                            C:\Program Files\LANDesk\Shared Files\residentagent.exe
                            C:\WINDOWS\system32\CTsvcCDA.exe
                            C:\Program Files\LANDesk\LDClient\LocalSch.EXE
                            C:\WINDOWS\system32\CBA\pds.exe
                            C:\Program Files\LANDesk\LDClient\tmcsvc.exe
                            C:\PROGRA~1\LANDesk\LDClient\issuser.exe
                            C:\MATLAB701\webserver\bin\win32\matlabserver.exe
                            C:\Program Files\McAfee\Common Framework\FrameworkService.exe
                            c:\matlab701\bin\win32\matlab.exe
                            C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
                            C:\PROGRA~1\LANDesk\LDClient\collector.exe
                            C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
                            C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                            C:\cygwin\bin\cygrunsrv.exe
                            C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
                            C:\Program Files\LANDesk\LDClient\softmon.exe
                            C:\cygwin\bin\rsync.exe
                            C:\cygwin\bin\cygrunsrv.exe
                            C:\Program Files\UPHClean\uphclean.exe
                            C:\cygwin\usr\sbin\sshd.exe
                            C:\WINDOWS\Explorer.EXE
                            C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
                            C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
                            C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                            C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
                            C:\Program Files\LANDesk\LDClient\webportal\sdclientmonitor.exe
                            C:\Program Files\iTunes\iTunesHelper.exe
                            C:\PROGRA~1\LANDesk\LDClient\rcgui.exe
                            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                            C:\Program Files\Analog Devices\Core\smax4pnp.exe
                            C:\WINDOWS\system32\igfxtray.exe
                            C:\WINDOWS\System32\alg.exe
                            C:\WINDOWS\system32\igfxpers.exe
                            C:\WINDOWS\system32\igfxsrvc.exe
                            C:\Program Files\McAfee\Common Framework\UdaterUI.exe
                            C:\Program Files\McAfee\Common Framework\McTray.exe
                            C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
                            C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
                            C:\Program Files\DAEMON Tools Lite\daemon.exe
                            C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
                            C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
                            C:\Program Files\iPod\bin\iPodService.exe
                            C:\Program Files\Mozilla Firefox\firefox.exe

                            --------------- [ Fichiers/Dossiers infectieux ] ----------------

                            »»»» Presence des fichiers dans C:

                            »»»» Presence des fichiers dans C:\WINDOWS

                            »»»» Presence des fichiers dans C:\WINDOWS\Prefetch

                            Found ! - C:\WINDOWS\Prefetch\O4PATCH.EXE-27B8335B.pf

                            »»»» Presence des fichiers dans C:\WINDOWS\system32

                            »»»» Presence des fichiers dans C:\WINDOWS\system32\config\systemprofile\AppData\Roaming

                            »»»» Presence des fichiers dans C:\WINDOWS\system32\drivers

                            »»»» Presence des fichiers dans D:\Documents and Settings\Administrator\Application Data

                            »»»» Presence des fichiers dans D:\DOCUME~1\ADMINI~1\LOCALS~1\Temp

                            »»»» Presence des fichiers dans D:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5

                            --------------- [ Registre / Startup ] ----------------

                            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
                            CTSyncU.exe="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
                            DAEMON Tools Lite="C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
                            HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\AdobeUpdater=
                            <NO NAME>=

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
                            IMJPMIG8.1="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                            PHIME2002ASync=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                            PHIME2002A=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                            AdaptecDirectCD=C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
                            UpdateManager="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
                            DVDLauncher="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
                            Zetes Card kit Certificate Installer="C:\Program Files\ZetesCardkit\tools\CheckCardkitTray.exe"
                            TkBellExe="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                            ShStatEXE="C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
                            IntelAPMClient="C:\Program Files\LANDesk\LDClient\amclient.exe" /apm /s /ro /Retry=2 /Tspan=60 /Rstart
                            SDClientMonitor="C:\Program Files\LANDesk\LDClient\webportal\sdclientmonitor.exe"
                            iTunesHelper="C:\Program Files\iTunes\iTunesHelper.exe"
                            IMEKRMIG6.1=C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
                            MSPY2002=C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
                            SynTPEnh=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                            SoundMAXPnP=C:\Program Files\Analog Devices\Core\smax4pnp.exe
                            IgfxTray=C:\WINDOWS\system32\igfxtray.exe
                            HotKeysCmds=C:\WINDOWS\system32\hkcmd.exe
                            Persistence=C:\WINDOWS\system32\igfxpers.exe
                            McAfeeUpdaterUI="C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
                            Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                            CTCheck=C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
                            QuickTime Task="C:\Program Files\QuickTime\QTTask.exe" -atboottime
                            HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
                            <NO NAME>=
                            HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
                            Installed=1
                            <NO NAME>=
                            HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
                            NoChange=1
                            Installed=1
                            <NO NAME>=
                            HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
                            Installed=1
                            <NO NAME>=

                            --------------- [ Registre / Clés infectieuses ] ----------------

                            --------------- [ Etat / Services ] ----------------

                            +- Services : [ Auto=2 / Demande=3 / Désactivé=4 ]

                            Ndisuio - Type de démarrage = 3

                            EapHost - Type de démarrage = 3

                            Ip6Fw - Type de démarrage = 3

                            SharedAccess - Type de démarrage = 2

                            wuauserv - Type de démarrage = 2

                            wscsvc - Type de démarrage = 2

                            --------------- [ Recherche dans supports amovibles] ----------------

                            +- Informations :

                            C: - Fixed Drive

                            D: - Fixed Drive

                            G: - Removable Drive

                            +- presence des fichiers :

                            --------------- [ Registre / Mountpoint2 ] ----------------

                            Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7ba60bd7-078a-11dd-b4b5-000ffe9fa2c5}\Shell\AutoRun\command

                            ------------------- ! Fin du rapport ! --------------------
                            0
                            1. Re,

                              Findykill de chiquitine29 option 2:

                              ▶ Branche tes disques amovibles à ton PC ( (clefs USB, disque dur externe, etc...) sans les ouvrir

                              ▶ Double-clique sur le raccourci FindyKill sur ton bureau

                              ▶ Au menu principal, choisisl'option 2 (Suppression)

                              /!\ Il y aura 2 redémarrages, laisse travailler l'outil jusqu'à l'apparition du message "nettoyage effectué" /!\

                              ▶ Ensuite, poste le rapport FindyKill.txt

                              Note : le rapport FindyKill.txt est sauvegardé à la racine du disque.

                              Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.
                              0
                              1. Voila ce que donne le rapport de FindyKill (après l'option 2) :

                                ----------------- FindyKill V4.710 ------------------

                                * User : Administrateur - PH-DUFOUR
                                * executed from : C:\Program Files\FindyKill
                                * Update on 21/12/08 par Chiquitine29
                                * Start at 12:48:34 the lun. 05/01/2009
                                * Windows XP - Internet Explorer 7.0.5730.11

                                ((((((((((((((( *** deleting *** ))))))))))))))))))

                                --------------- [ Active Processes ] ----------------

                                C:\WINDOWS\System32\smss.exe
                                C:\WINDOWS\system32\csrss.exe
                                C:\WINDOWS\system32\winlogon.exe
                                C:\WINDOWS\system32\services.exe
                                C:\WINDOWS\system32\lsass.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\system32\spoolsv.exe
                                C:\WINDOWS\System32\SCardSvr.exe
                                C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                C:\Program Files\Bonjour\mDNSResponder.exe
                                C:\Program Files\LANDesk\Shared Files\residentagent.exe
                                C:\WINDOWS\system32\CTsvcCDA.exe
                                C:\Program Files\LANDesk\Shared Files\rainstall.exe
                                C:\Program Files\LANDesk\LDClient\LocalSch.EXE
                                C:\WINDOWS\system32\CBA\pds.exe
                                C:\Program Files\LANDesk\LDClient\tmcsvc.exe
                                C:\PROGRA~1\LANDesk\LDClient\issuser.exe
                                C:\MATLAB701\webserver\bin\win32\matlabserver.exe
                                C:\WINDOWS\system32\userinit.exe
                                C:\PROGRA~1\LANDesk\LDClient\miniscan.exe
                                C:\Program Files\McAfee\Common Framework\FrameworkService.exe
                                C:\Program Files\LANDesk\LDClient\LDIScn32.EXE
                                c:\matlab701\bin\win32\matlab.exe
                                C:\WINDOWS\system32\OGAVerify.exe
                                C:\Program Files\LANDesk\Shared Files\proxyhost.exe
                                C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
                                C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
                                C:\PROGRA~1\LANDesk\LDClient\collector.exe
                                C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                                C:\PROGRA~1\LANDesk\LDClient\LDregwatch.exe
                                C:\PROGRA~1\LANDesk\LDClient\LDInventoryProvider.exe
                                C:\cygwin\bin\cygrunsrv.exe
                                C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
                                C:\Program Files\LANDesk\LDClient\softmon.exe
                                C:\cygwin\bin\rsync.exe
                                C:\cygwin\bin\cygrunsrv.exe
                                C:\Program Files\UPHClean\uphclean.exe
                                C:\cygwin\usr\sbin\sshd.exe
                                C:\WINDOWS\system32\wbem\wmiprvse.exe

                                --------------- [ Infected files / folders ] ----------------

                                »»»» Supression files in C:

                                »»»» Supression files in C:\WINDOWS

                                »»»» Supression files in C:\WINDOWS\Prefetch

                                Deleted ! - C:\WINDOWS\prefetch\O4PATCH.EXE-27B8335B.pf

                                »»»» Supression files in C:\WINDOWS\system32

                                »»»» Supression files in C:\WINDOWS\system32\config\systemprofile\AppData\Roaming

                                »»»» Supression files in C:\WINDOWS\system32\drivers

                                »»»» Supression files in D:\Documents and Settings\Administrator\Application Data

                                »»»» Supression files in D:\DOCUME~1\ADMINI~1\LOCALS~1\Temp

                                »»»» Supression files in D:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5

                                --------------- [ Registry / Infected keys ] ----------------

                                Deleted ! - HKEY_CURRENT_CONFIG\System\CurrentControlSet\Enum\ROOT\LEGACY_SROSA

                                --------------- [ States / Restarting of services ] ----------------

                                +- Services : [ Auto=2 / Request=3 / Disable=4 ]

                                Ndisuio - Type of startup = 3

                                EapHost - Type of startup = 2

                                Ip6Fw - Type of startup = 2

                                SharedAccess - Type of startup = 2

                                wuauserv - Type of startup = 2

                                wscsvc - Type of startup = 2

                                --------------- [ Cleaning removable drives ] ----------------

                                +- Informations :

                                C: - Fixed Drive

                                D: - Fixed Drive

                                G: - Removable Drive

                                +- deleting files :

                                --------------- [ Registry / Mountpoint2 ] ----------------

                                Deleted ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7ba60bd7-078a-11dd-b4b5-000ffe9fa2c5}\Shell\AutoRun\command

                                --------------- [ Searching Cracks / Keygen ] ----------------

                                ---------------- ! End of report ! ------------------
                                0
                                1. Il n'y a pas de changement, malwarebyte ne veut pas se lancer...
                                  0
                                  1. Re,

                                    Combofix. Attention, ce logiciel est très puissant, une mauvaise utilisation peut faire des dégâts...

                                    Fais exactement ce qui suit :

                                    Télécharge ComboFix (de sUBs) sur ton Bureau (et pas ailleurs !) :
                                    Fais un clic droit sur ce lien et choisis "enregistrer la cible sous ... " : dans la fenêtre qui s'ouvre tape C-Fix, choisis le bureau comme destination et valide :

                                    --------------------------------------------- [ ! ATTENTION ! ] ----------------------------------------------------------
                                    !! déconnecte toi, ferme toutes tes applications en cours et DESACTIVE TOUTES TES DEFENCES (anti-virus, antispyware, pare-feu) le temps de la manipulation (si jamais tu en as et que je ne les ai pas vu sur le rapport hijackthis....)

                                    ---> Surtout, si tu rencontres des difficultés à ce niveau là, dis le moi avant de poursuivre...

                                    --->Je te conseil d'installer la console de récupération.(Voir le tutoriel).

                                    Tuto ici : TUTO
                                    ---------------------------------------------------------------------------------------------------------------------------------

                                    Ensuite :

                                    Double-clique sur C-Fix.exe (= combofix.exe ) .

                                    Appuie sur une touche pour démarrer le scan .

                                    Attention : n'utilise pas ta souris ni ton clavier pendant que le programme tourne. Cela pourrait figer l'ordi ---> si un message d'erreur windows apparait à un moment : clique sur la croix rouge en haut à droite de la fenêtre pour la fermer

                                    Le rapport sera crée dans: C:\Combofix.txt , poste le ici stp

                                    Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.
                                    0
                                    1. Je n'arrive pas à télécharger ComboFix. Quand je fais un clic droit sur le lien puis 'enregistrer la cible du lien sous', je reçois un message d'erreur "Le téléchargement ne peut pas être enregistré car une erreur inconnue est survenue".
                                      J'ai essayer de trouver un autre lien sur internet mais soit j'ai le même problème, soit la page ne peut pas être affichée (ou je suis redirigé vers une page qui n'a rien à voir).
                                      0
                                      • 1
                                      • 2