VISTA rame!!! impossible de naviguer dessus!

Bonjour tous le monde,
je fais appel à vous car j'ai un problème depuis quelques mois avec mon ordi sous Vista.
Ordinateur acheté neuf, il a moins de 1 ans, il rame bcp, je peux rien faire dessus, écrire sur word impossible, il écrit une lettre et beug,
sur internet c'est pire, quand il démarre, il met plus de 10 minutes, bref j'ai vraiment besoin d'aide.

Pour info, j'ai réussi à désinstaller avast pour installer anti vir, mais le problème c'est qui beug telement que je peux mêm pas mettre à jour anti vir, ni le configurer, donc premièrement, est-ce que je peux faire tout ça en mode sans échec?

Ensuite, il faut savoir que j'ai plus de 70 processus, et l'UC rempli à 100%!
Voilà, je peux même pas faire une analyse anti virus, mais avast avait détecté un chevale de troie!

Help me please,
thanks.

40 réponses

Résumé de la discussion

Un ordinateur sous Vista présente un ralentissement important, avec plus de 70 processus actifs et des blocages d’écriture, rendant Word et la navigation parfois impossibles. La situation suggère une infection ou des programmes indésirables, et plusieurs conseils recommandent Malwarebytes Anti-Malware pour détecter et supprimer les éléments nuisibles, notamment Rogue.Spyware-Secure. Le rapport montre des éléments infectés dans le dossier Start Menu et propose de les mettre en quarantaine, avec d’autres outils comme RSIT ou UsbFix pour compléter l’analyse hors ligne. En complément, certaines réponses préconisent l’exécution en mode administrateur et la déconnexion d’Internet pendant l’analyse pour empêcher les tentatives de contamination ou de fuite.

Bobot (l’IA à votre service)
  1. Re,
    je l'ai télécharger sur le bureau, et en le lançan j'ai eu un message bizarre en anglais (assez long)
    je crois que cela n'a pas marché mais je poste quand même le rapport
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 12:14:59, on 19/01/2009
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v7.00 (7.00.6001.18000)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\hp\support\hpsysdrv.exe
    C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
    C:\Windows\RtHDVCpl.exe
    C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
    C:\Program Files\Portrait Displays\HP My Display\dthtml.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
    C:\Windows\ehome\ehtray.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Windows\system32\schtasks.exe
    c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
    C:\Windows\system32\conime.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe
    C:\Windows\system32\jusched.exe
    C:\Program Files\Internet Explorer\ieuser.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\hp\kbd\kbd.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe
    C:\Windows\system32\wuauclt.exe
    C:\Users\Moi\Desktop\HiJackThis.exe

    O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
    O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
    0
    1. Contributeur sécurité
      en effet recommence et cette fois tu clic droit sur l'icone hijackthis sur ton bureau puis executer en administrateur et relance un scan et poste le rapport
      0
      1. J'ai fais comme tu m'as dit, message: HijackThis is already running!
        Sa veut dire quoi ça? il rame tellement que sa veut pas marcher!!!
        0
        1. Contributeur sécurité
          redemarre ton PC, ensuite clic droit sur l'icone hijackthis qui doit etre placer sur ton bureau et choisit executer en administrateur et poste le rapport
          0
          1. Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 12:46:37, on 19/01/2009
            Platform: Windows Vista SP1 (WinNT 6.00.1905)
            MSIE: Internet Explorer v7.00 (7.00.6001.18000)
            Boot mode: Normal

            Running processes:
            C:\Windows\system32\taskeng.exe
            C:\Windows\system32\Dwm.exe
            C:\Windows\Explorer.EXE
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\hp\support\hpsysdrv.exe
            C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
            C:\Windows\RtHDVCpl.exe
            C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
            C:\Program Files\Portrait Displays\HP My Display\dthtml.exe
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
            C:\Program Files\Windows Sidebar\sidebar.exe
            C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
            C:\Windows\ehome\ehtray.exe
            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            C:\Windows\system32\schtasks.exe
            c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
            C:\Windows\system32\conime.exe
            C:\Windows\system32\jusched.exe
            C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe
            C:\Windows\ehome\ehmsas.exe
            C:\hp\kbd\kbd.exe
            C:\Users\Moi\Desktop\HiJackThis.exe
            C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
            C:\Windows\system32\wuauclt.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fwww.msn.fr%2fimg%2ffr%2ffr-fr%2fdivertissement%2fcelebrites%2fgalery%2fwentworth02.jpg%3f
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
            O1 - Hosts: ::1 localhost
            O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
            O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
            O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
            O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
            O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
            O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
            O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
            O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
            O4 - HKLM\..\Run: [StartCCC] "c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
            O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
            O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
            O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
            O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
            O4 - HKLM\..\Run: [DT HPW] C:\Program Files\Portrait Displays\HP My Display\DTHtml.exe -startup_folder
            O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
            O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
            O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun
            O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
            O4 - HKCU\..\Run: [mxbowtujn] c:\users\marzoug\appdata\local\mxbowtujn.exe mxbowtujn
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
            O8 - Extra context menu item: &Recherche AOL Toolbar - c:\program files\aol\aol toolbar 5.0\resources\fr-fr\local\search.html
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
            O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
            O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
            O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
            O13 - Gopher Prefix:
            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
            O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
            O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
            O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
            O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
            O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
            O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
            0
            1. Search Navipromo version 3.7.1 commencé le 19/01/2009 à 13:01:14,23

              !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
              !!! Postez ce rapport sur le forum pour le faire analyser !!!
              !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

              Outil exécuté depuis C:\Program Files\navilog1

              Mise à jour le 02.01.2009 à 19h00 par IL-MAFIOSO

              Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
              X86-based PC ( Multiprocessor Free : AMD Athlon(tm) 64 X2 Dual Core Processor 4200+ )
              BIOS : Phoenix - AwardBIOS v6.00PG
              USER : Moi ( Administrator )
              BOOT : Normal boot

              C:\ (Local Disk) - NTFS - Total:222 Go (Free:185 Go)
              D:\ (Local Disk) - NTFS - Total:10 Go (Free:1 Go)
              E:\ (CD or DVD)
              F:\ (USB)
              G:\ (USB)
              H:\ (USB)
              I:\ (USB)

              Recherche executé en mode normal

              *** Recherche Programmes installés ***

              *** Recherche dossiers dans "C:\Windows" ***

              *** Recherche dossiers dans "C:\Program Files" ***

              *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

              *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1" ***

              *** Recherche dossiers dans "C:\ProgramData" ***

              *** Recherche dossiers dans "c:\users\moi\appdata\roaming\micros~1\windows\startm~1\programs" ***

              *** Recherche dossiers dans "C:\Users\Moi\AppData\Local\virtualstore\Program Files" ***

              *** Recherche dossiers dans "C:\Users\Moi\AppData\Local" ***

              *** Recherche dossiers dans "C:\Users\Moi\AppData\Roaming" ***

              *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
              pour + d'infos : http://www.gmer.net

              *** Recherche avec GenericNaviSearch ***
              !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
              !!! A vérifier impérativement avant toute suppression manuelle !!!

              * Recherche dans "C:\Windows\system32" *

              * Recherche dans "C:\Users\Moi\AppData\Local\Microsoft" *

              * Recherche dans "C:\Users\Moi\AppData\Local" *

              *** Recherche fichiers ***

              C:\Windows\system32\nvs2.inf trouvé !

              *** Recherche clés spécifiques dans le Registre ***
              !! Les clés trouvées ne sont pas forcément infectées !!

              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "mxbowtujn"="c:\\users\\moi\\appdata\\local\\mxbowtujn.exe mxbowtujn"

              *** Module de Recherche complémentaire ***
              (Recherche fichiers spécifiques)

              1)Recherche nouveaux fichiers Instant Access :

              2)Recherche Heuristique :

              * Dans "C:\Windows\system32" :

              * Dans "C:\Users\Moi\AppData\Local\Microsoft" :

              * Dans "C:\Users\Moi\AppData\Local" :

              mxbowtujn.dat trouvé !
              mxbowtujn_nav.dat trouvé !
              mxbowtujn_navps.dat trouvé !

              3)Recherche Certificats :

              Certificat Egroup trouvé !
              Certificat Electronic-Group trouvé !
              Certificat Montorgueil absent !
              Certificat OOO-Favorit trouvé !
              Certificat Sunny-Day-Design-Ltd absent !

              4)Recherche autres dossiers et fichiers connus :

              *** Analyse terminée le 19/01/2009 à 13:13:19,44 ***
              0
              1. Contributeur sécurité
                re

                deconnecte toi, d'internet, ferme toutes tes application et relance en option 2 et poste le rapport

                puis

                Télécharge Random's System Information Tool (RSIT) par random/random et sauvegarde-le sur ton Bureau.
                http://images.malwareremoval.com/random/RSIT.exe
                Clique sur Continue
                Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.
                Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront poste les 2 rapports SEPAREMENT
                0
                1. voiici le rapport avec Navilog:
                  Clean Navipromo version 3.7.1 commencé le 19/01/2009 à 13:58:43,05

                  Outil exécuté depuis C:\Program Files\navilog1

                  Mise à jour le 02.01.2009 à 19h00 par IL-MAFIOSO

                  Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
                  X86-based PC ( Multiprocessor Free : AMD Athlon(tm) 64 X2 Dual Core Processor 4200+ )
                  BIOS : Phoenix - AwardBIOS v6.00PG
                  USER : Moi ( Administrator )
                  BOOT : Normal boot

                  C:\ (Local Disk) - NTFS - Total:222 Go (Free:185 Go)
                  D:\ (Local Disk) - NTFS - Total:10 Go (Free:1 Go)
                  E:\ (CD or DVD)
                  F:\ (USB)
                  G:\ (USB)
                  H:\ (USB)
                  I:\ (USB)

                  Mode suppression automatique
                  avec prise en charge résultats Catchme et GNS

                  Nettoyage exécuté au redémarrage de l'ordinateur

                  *** fsbl1.txt non trouvé ***
                  (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)

                  *** Suppression avec sauvegardes résultats GenericNaviSearch ***

                  * Suppression dans "C:\Windows\System32" *

                  * Suppression dans "C:\Users\Moi\AppData\Local\Microsoft" *

                  * Suppression dans "C:\Users\Moi\AppData\Local" *

                  *** Suppression dossiers dans "C:\Windows" ***

                  *** Suppression dossiers dans "C:\Program Files" ***

                  *** Suppression dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

                  *** Suppression dossiers dans "c:\progra~2\micros~1\windows\startm~1" ***

                  *** Suppression dossiers dans "C:\ProgramData" ***

                  *** Suppression dossiers dans c:\users\moi\appdata\roaming\micros~1\windows\startm~1\programs ***

                  *** Suppression dossiers dans "C:\Users\Moi\AppData\Local\virtualstore\Program Files" ***

                  *** Suppression dossiers dans "C:\Users\Moi\AppData\Local" ***

                  *** Suppression dossiers dans "C:\Users\Moi\AppData\Roaming" ***

                  *** Suppression fichiers ***

                  C:\Windows\system32\nvs2.inf supprimé !

                  *** Suppression fichiers temporaires ***

                  Nettoyage contenu C:\Windows\Temp effectué !
                  Nettoyage contenu C:\Users\Moi\AppData\Local\Temp effectué !

                  *** Traitement Recherche complémentaire ***
                  (Recherche fichiers spécifiques)

                  1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

                  2)Recherche, création sauvegardes et suppression Heuristique :

                  * Dans "C:\Windows\system32" *

                  * Dans "C:\Users\Moi\AppData\Local\Microsoft" *

                  * Dans "C:\Users\Moi\AppData\Local" *

                  mxbowtujn.dat trouvé !
                  Copie mxbowtujn.dat réalisée avec succès !
                  mxbowtujn.dat supprimé !

                  mxbowtujn_nav.dat trouvé !
                  Copie mxbowtujn_nav.dat réalisée avec succès !
                  mxbowtujn_nav.dat supprimé !

                  mxbowtujn_navps.dat trouvé !
                  Copie mxbowtujn_navps.dat réalisée avec succès !
                  mxbowtujn_navps.dat supprimé !

                  *** Sauvegarde du Registre vers dossier Safebackup ***

                  sauvegarde du Registre réalisée avec succès !

                  *** Nettoyage Registre ***

                  Nettoyage Registre Ok

                  *** Certificats ***

                  Certificat Egroup supprimé !
                  Certificat Electronic-Group supprimé !
                  Certificat Montorgueil absent !
                  Certificat OOO-Favorit supprimé !
                  Certificat Sunny-Day-Design-Ltdt absent !

                  *** Recherche autres dossiers et fichiers connus ***

                  *** Nettoyage terminé le 19/01/2009 à 14:04:18,41 ***
                  0
                  1. ensuite avec RSIT, ba j'attend tjrs, là la barre de progression reste à "LISTING ENVENT LOGS"
                    je pense qu'il a beugé encore une foi :(
                    0
                    1. voici le rapport final:

                      Logfile of random's system information tool 1.05 (written by random/random)
                      Run by Moi at 2009-01-19 14:43:17
                      Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
                      System drive C: has 190 GB (83%) free of 228 GB
                      Total RAM: 2046 MB (66% free)

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 14:59:48, on 19/01/2009
                      Platform: Windows Vista SP1 (WinNT 6.00.1905)
                      MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                      Boot mode: Normal

                      Running processes:
                      C:\Windows\system32\taskeng.exe
                      C:\Windows\system32\Dwm.exe
                      C:\Windows\Explorer.EXE
                      C:\Program Files\Windows Defender\MSASCui.exe
                      C:\hp\support\hpsysdrv.exe
                      C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
                      C:\Windows\RtHDVCpl.exe
                      C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                      C:\Program Files\Portrait Displays\HP My Display\dthtml.exe
                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                      C:\Program Files\Windows Sidebar\sidebar.exe
                      C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
                      C:\Windows\ehome\ehtray.exe
                      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      C:\Windows\system32\schtasks.exe
                      C:\Windows\system32\conime.exe
                      C:\Windows\ehome\ehmsas.exe
                      C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe
                      C:\Windows\system32\jusched.exe
                      C:\Windows\system32\wuauclt.exe
                      C:\hp\kbd\kbd.exe
                      C:\Users\Moi\Desktop\RSIT.exe
                      C:\Users\Moi\Desktop\Marzoug.exe
                      C:\Program Files\Internet Explorer\ieuser.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                      C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fwww.msn.fr%2fimg%2ffr%2ffr-fr%2fdivertissement%2fcelebrites%2fgalery%2fwentworth02.jpg%3f
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                      O1 - Hosts: ::1 localhost
                      O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                      O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
                      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
                      O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
                      O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                      O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
                      O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
                      O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
                      O4 - HKLM\..\Run: [StartCCC] "c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
                      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                      O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                      O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
                      O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                      O4 - HKLM\..\Run: [DT HPW] C:\Program Files\Portrait Displays\HP My Display\DTHtml.exe -startup_folder
                      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                      O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun
                      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                      O8 - Extra context menu item: &Recherche AOL Toolbar - c:\program files\aol\aol toolbar 5.0\resources\fr-fr\local\search.html
                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                      O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                      O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                      O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
                      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                      O13 - Gopher Prefix:
                      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                      O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                      O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                      O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
                      O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
                      O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                      0
                      1. Contributeur sécurité
                        ne tiens pas compte du poste 14 et

                        Telecharge UsbFix sur ton bureau http://sd-1.archive-host.com/membres/up/116615172019703188/UsbFix.exe
                        Lance l installation avec les parametres par default

                        Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir
                        clic sur le raccourci UsbFix sur ton bureau
                        choisi l option 1 (nettoyage)
                        Le pc va redémarer
                        Apres redémarrage post le rapport UsbFix.txt dans C
                        le logiciel est detecté par certains antivirus si c'est le cas ignore l'alerte et desactive tes defense le temps du scan
                        0
                        1. Logfile of random's system information tool 1.05 (written by random/random)
                          Run by Moi at 2009-01-19 15:11:05
                          Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
                          System drive C: has 190 GB (83%) free of 228 GB
                          Total RAM: 2046 MB (62% free)

                          Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 15:11:53, on 19/01/2009
                          Platform: Windows Vista SP1 (WinNT 6.00.1905)
                          MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                          Boot mode: Normal

                          Running processes:
                          C:\Windows\system32\taskeng.exe
                          C:\Windows\system32\Dwm.exe
                          C:\Windows\Explorer.EXE
                          C:\Program Files\Windows Defender\MSASCui.exe
                          C:\hp\support\hpsysdrv.exe
                          C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
                          C:\Windows\RtHDVCpl.exe
                          C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                          C:\Program Files\Portrait Displays\HP My Display\dthtml.exe
                          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                          C:\Program Files\Windows Sidebar\sidebar.exe
                          C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
                          C:\Windows\ehome\ehtray.exe
                          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          C:\Windows\system32\schtasks.exe
                          C:\Windows\system32\conime.exe
                          C:\Windows\ehome\ehmsas.exe
                          C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe
                          C:\Windows\system32\jusched.exe
                          C:\Windows\system32\wuauclt.exe
                          C:\hp\kbd\kbd.exe
                          C:\Program Files\Internet Explorer\ieuser.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                          C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe
                          C:\Users\Moi\Desktop\RSIT.exe
                          C:\Users\Moi\Desktop\Marzoug.exe

                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fwww.msn.fr%2fimg%2ffr%2ffr-fr%2fdivertissement%2fcelebrites%2fgalery%2fwentworth02.jpg%3f
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                          O1 - Hosts: ::1 localhost
                          O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
                          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                          O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
                          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
                          O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
                          O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
                          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                          O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
                          O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
                          O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
                          O4 - HKLM\..\Run: [StartCCC] "c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
                          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                          O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                          O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
                          O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                          O4 - HKLM\..\Run: [DT HPW] C:\Program Files\Portrait Displays\HP My Display\DTHtml.exe -startup_folder
                          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                          O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun
                          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                          O8 - Extra context menu item: &Recherche AOL Toolbar - c:\program files\aol\aol toolbar 5.0\resources\fr-fr\local\search.html
                          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                          O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                          O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                          O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
                          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                          O13 - Gopher Prefix:
                          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                          O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                          O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                          O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
                          O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
                          O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
                          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                          0
                          1. "Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir "

                            C'est à dire? j'ai pas compris? sa veut dire ke jdoi branché ma clé USB?
                            0
                            1. Contributeur sécurité
                              clef usb, appareil photo que tu branche dessus, tout tes donnée externe oui
                              0
                              1. si t,on engin a moins d,un 1an a l,achat ....il est encore garanti !!
                                0
                            2. ok voici le rapport:

                              -------------- UsbFix V2.414.3 ---------------

                              * User : Moi - PC-DE-MOI
                              * Outils mis a jours le 18/01/2009 par Chiquitine29 et Chimay8
                              * Recherche effectuée à 15:47:22 le 19/01/2009
                              * Windows Vista - Internet Explorer 7.0.6001.18000

                              --------------- [ Processus actifs ] ----------------

                              C:\Windows\System32\smss.exe
                              C:\Windows\system32\csrss.exe
                              C:\Windows\system32\wininit.exe
                              C:\Windows\system32\csrss.exe
                              C:\Windows\system32\services.exe
                              C:\Windows\system32\lsass.exe
                              C:\Windows\system32\lsm.exe
                              C:\Windows\system32\winlogon.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\System32\svchost.exe
                              C:\Windows\system32\LogonUI.exe
                              C:\Windows\system32\Ati2evxx.exe
                              C:\Windows\System32\svchost.exe
                              C:\Windows\System32\svchost.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\system32\SLsvc.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\system32\Ati2evxx.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\System32\spoolsv.exe
                              C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                              C:\Windows\system32\svchost.exe
                              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                              C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
                              C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\System32\svchost.exe
                              C:\Windows\system32\SearchIndexer.exe
                              C:\Windows\system32\WUDFHost.exe
                              C:\Windows\system32\taskeng.exe
                              C:\Windows\system32\userinit.exe
                              C:\Windows\system32\Dwm.exe
                              C:\Windows\Explorer.EXE
                              C:\Windows\system32\runonce.exe

                              --------------- [ Informations lecteurs ] ----------------

                              C: - Lecteur fixe
                              D: - Lecteur fixe
                              E: - Lecteur de CD-ROM
                              H: - Lecteur amovible
                              J: - Lecteur amovible
                              K: - Lecteur de CD-ROM

                              +- Contenu de l'autorun : K:\autorun.inf

                              [AutoRun]
                              open=LaunchU3.exe
                              icon=LaunchU3.exe,0

                              [Definitions]
                              Launchpad=LaunchPad.exe

                              [CopyFiles]
                              FileNumber=1
                              File1=LaunchPad.zip

                              --------------- [ Lecteur C ] ----------------

                              C: - Lecteur fixe

                              +- Listing des fichiers présents :

                              [08/01/2008 10:44][--a------] C:\autoexec.bat
                              [19/01/2009 14:27][--a------] C:\cleannavi.txt
                              [19/01/2009 14:27][--a------] C:\fixnavi.txt
                              [19/01/2009 14:27][--a------] C:\UsbFix.txt
                              [18/09/2006 22:43][--a------] C:\config.sys
                              [18/09/2006 22:43][--a------] C:\hiberfil.sys
                              [18/09/2006 22:43][--a------] C:\pagefile.sys

                              --------------- [ Lecteur D ] ----------------

                              D: - Lecteur fixe

                              +- Listing des fichiers présents :

                              [19/06/2007 16:22][---hs----] D:\Desktop.ini
                              [19/06/2007 16:22][---hs----] D:\pcdr.ini
                              [19/06/2007 16:22][---hs----] D:\RESTORE.INI
                              [18/07/2007 09:42][---hs----] D:\SystemRecovery.txt

                              --------------- [ Lecteur E ] ----------------

                              E: - Lecteur de CD-ROM

                              +- Listing des fichiers présents :

                              --------------- [ Lecteur H ] ----------------

                              H: - Lecteur amovible

                              +- Listing des fichiers présents :

                              --------------- [ Lecteur J ] ----------------

                              J: - Lecteur amovible

                              +- Listing des fichiers présents :

                              [25/08/2006 00:04][--a------] J:\LaunchU3.exe

                              --------------- [ Lecteur K ] ----------------

                              K: - Lecteur de CD-ROM

                              +- Listing des fichiers présents :

                              [13/02/2006 20:09][-r-------] K:\LaunchU3.exe
                              [13/02/2006 20:08][-r-------] K:\autorun.inf

                              --------------- [ Registre / Startup ] ----------------

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                              "Userinit"="C:\\Windows\\system32\\userinit.exe,"

                              [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                              "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                              "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"

                              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
                              Sidebar=C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                              HPAdvisor=C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun
                              ehTray.exe=C:\Windows\ehome\ehTray.exe
                              swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\OsdMaestro=
                              ModelName=5189URF
                              Version=1.00.007
                              Language=1 (0x1)
                              HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\OsdMaestro\Config=
                              DisplayLabel=0 (0x0)
                              TaskbarIcon=1 (0x1)
                              ShowLockOSD=1 (0x1)

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
                              Windows Defender=%ProgramFiles%\Windows Defender\MSASCui.exe -hide
                              hpsysdrv=c:\hp\support\hpsysdrv.exe
                              KBD=C:\HP\KBD\KbdStub.EXE
                              OsdMaestro="C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
                              StartCCC="c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
                              RtHDVCpl=RtHDVCpl.exe
                              HP Health Check Scheduler=[ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                              SunJavaUpdateReg="C:\Windows\system32\jureg.exe"
                              HP Software Update=c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                              <NO NAME>=
                              DT HPW=C:\Program Files\Portrait Displays\HP My Display\DTHtml.exe -startup_folder
                              avgnt="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min

                              --------------- [ Registre / Mountpoint2 ] ----------------

                              Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\K\Shell\AutoRun\command
                              Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3c7bbd42-f8fb-11dc-8940-001e8c979b1a}\Shell\AutoRun\command
                              Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6b3f4c21-fe49-11dc-9492-001e8c979b1a}\Shell\AutoRun\command

                              --------------- [ Nettoyage des disques ] ----------------

                              Echec de la supression !! - [13/02/2006 20:08] K:\autorun.inf
                              Echec de la supression !! - [13/02/2006 20:08] K:\autorun.inf

                              --------------- [ Resumé ] ----------------

                              -> /!\ Le resultat doit etre interprété par un spécialiste /!\

                              [08/01/2008 10:44][--a------] C:\autoexec.bat
                              [19/06/2007 16:22][---hs----] D:\Desktop.ini
                              [19/06/2007 16:22][---hs----] D:\pcdr.ini
                              [19/06/2007 16:22][---hs----] D:\RESTORE.INI
                              [25/08/2006 00:04][--a------] J:\LaunchU3.exe
                              [13/02/2006 20:09][-r-------] K:\LaunchU3.exe
                              [13/02/2006 20:08][-r-------] K:\autorun.inf

                              --------------- [ Vaccination ] ----------------

                              C:\autorun.inf -> Dossier autorun.inf crée par UsbFix !
                              D:\autorun.inf -> Dossier autorun.inf crée par UsbFix !
                              H:\autorun.inf -> Dossier autorun.inf crée par UsbFix !
                              J:\autorun.inf -> Dossier autorun.inf crée par UsbFix !

                              --------------- ! Fin du rapport ! ----------------
                              0
                              • 1
                              • 2