Fenetre de pub et ordi verolé

Bonjour,
J'ai besoin d'aide je reçoie des pub en permanence et lorsque je suis une page internet elle change toute seule
j'ai Antivir j'utilise régulierement ccleaner et Malwarebytes mais rien ni fait.
Merci d'avance
Christophe
Configuration: Windows XP
Internet Explorer 7.0

21 réponses

  1. Contributeur sécurité
    slt,

    Télécharge ici :

    http://images.malwareremoval.com/random/RSIT.exe

    random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

    Double-clique sur RSIT.exe afin de lancer RSIT.

    Clique Continue à l'écran Disclaimer.

    Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

    Poste le contenu de log.txt (<<qui sera affiché)
    ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

    NB : Les rapports sont sauvegardés dans le dossier C:\rsit
    0
    1. Logfile of random's system information tool 1.05 (written by random/random)
      Run by c at 2009-03-08 10:13:11
      Microsoft Windows XP Professionnel Service Pack 3
      System drive C: has 54 GB (81%) free of 66 GB
      Total RAM: 511 MB (44% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 10:13:17, on 08/03/2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16791)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\WINDOWS\System32\LVCOMSX.EXE
      C:\Program Files\Logitech\Video\LogiTray.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\EoRezo\EoEngine.exe
      C:\Documents and Settings\c\Application Data\eoRezo\SoftwareUpdate\SoftwareUpdateHP.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\WINDOWS\system32\dla\tfswctrl.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Documents and Settings\c\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
      C:\Program Files\Logitech\Video\FxSvr2.exe
      C:\Documents and Settings\c\Application Data\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\nvsvc32.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
      C:\WINDOWS\system32\slserv.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\WINDOWS\System32\wbem\wmiapsrv.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
      C:\Program Files\Crazy Browser\Crazy Browser.exe
      C:\Documents and Settings\c\Local Settings\Temporary Internet Files\Content.IE5\86GT347Y\RSIT[1].exe
      C:\Program Files\Trend Micro\HijackThis\c.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://lo.st#first
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
      O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
      O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
      O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
      O2 - BHO: EoBHO - {C7B76B90-3455-4AE6-A752-EAC4D19689E5} - C:\Program Files\EoRezo\EoAdv\EoRezoBHO.dll
      O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
      O2 - BHO: (no name) - {d639308d-9862-8615-4053-2e2c6fb10050} - (no file)
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
      O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
      O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
      O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [EoEngine] "C:\Program Files\EoRezo\EoEngine.exe"
      O4 - HKLM\..\Run: [SoftwareHelper] C:\Documents and Settings\c\Application Data\eoRezo\SoftwareUpdate\SoftwareUpdateHP.exe
      O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
      O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
      O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
      O4 - Startup: Outil de notification Live Search.lnk = C:\Documents and Settings\c\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra button: Sélection intelligente HP - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
      O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - https://sdlc-esd.oracle.com/ESD5/JSCDL/jre/6u11-b90/jinstall-6u11-windows-i586-jc.cab?GroupName=JSC&FilePath=/ESD5/JSCDL/jre/6u11-b90/jinstall-6u11-windows-i586-jc.cab&BHost=javadl.sun.com&File=jinstall-6u11-windows-i586-jc.cab&AuthParam=1580990370_ae51af1f2e3e7c78a0fbe2e88da6073d&ext=.cab
      O20 - AppInit_DLLs: C:\WINDOWS\System32\kbdla32.dll
      O20 - Winlogon Notify: a46937ad515 - C:\WINDOWS\System32\kbdla32.dll (file missing)
      O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
      O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
      0
      1. info.txt logfile of random's system information tool 1.05 2009-03-08 10:13:20

        ======Uninstall list======

        -->C:\WINDOWS\system32\\MSIEXEC.EXE /I {09DA4F91-2A09-4232-AB8C-6BC740096DE3} REMOVE=UpdateMgrFeature
        -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
        -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
        -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
        32 Bit HP CIO Components Installer-->MsiExec.exe /I{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}
        7-Zip 4.64-->"C:\Program Files\7-Zip\Uninstall.exe"
        Adobe Flash Player 10 ActiveX-->C:\WINDOWS\System32\Macromed\Flash\uninstall_activeX.exe
        Adobe Reader 9 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A90000000001}
        Apple Mobile Device Support-->MsiExec.exe /I{EC4455AB-F155-4CC1-A4C5-88F3777F9886}
        Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
        Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
        Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
        Bonjour-->MsiExec.exe /I{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}
        CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
        Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
        Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
        Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
        Crazy Browser version 2.0.1-->"C:\Program Files\Crazy Browser\unins000.exe"
        DVD Shrink 3.1.7-->"C:\Program Files\DVD Shrink\unins000.exe"
        eoEngine 9.1-->"C:\Program Files\EoRezo\unins000.exe"
        Galerie de photos Windows Live-->MsiExec.exe /X{44E54A81-9D91-4AA1-9417-80AFF134F5FF}
        Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_0531C63A913CC9D1.exe" /uninstall
        HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
        Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
        HP Customer Participation Program 10.0-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
        HP Deskjet F2200 All-In-One Driver Software 10.0 Rel .3-->C:\Program Files\HP\Digital Imaging\{D77D43B5-ED55-426b-B67B-E21F804F6102}\setup\hpzscr01.exe -datfile hposcr27.dat -onestop
        HP Imaging Device Functions 10.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
        HP Photosmart Essential 2.5-->C:\Program Files\HP\Digital Imaging\PhotoSmartEssential\hpzscr01.exe -datfile hpqbud13.dat
        HP Smart Web Printing-->C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpzscr01.exe -datfile hpqbud15.dat
        HP Solution Center 10.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
        HP Update-->MsiExec.exe /X{FE57DE70-95DE-4B64-9266-84DA811053DB}
        Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
        Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
        iTunes-->MsiExec.exe /I{F5C63795-2708-4D15-BF18-5ABBFF7DFFC8}
        Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
        Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
        Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
        LimeWire 4.18.8-->"C:\Program Files\LimeWire\uninstall.exe"
        Logiciel QuickCam de Logitech-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C43048A9-742C-4DAD-90D2-E3B53C9DB825}\setup.exe" -l0x40c
        Ludi-->C:\Program Files\Ludi\uninstall.exe
        Ma-Config.com-->MsiExec.exe /X{EC7FE2ED-F305-41B7-90B8-3DAE9E35307A}
        Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
        Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
        Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
        Microsoft AutoRoute 2005-->MsiExec.exe /I{67E4EE98-59F4-4220-89A6-A20AF5BEC689}
        Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
        Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
        Microsoft Search Enhancement Pack-->MsiExec.exe /I{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}
        Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
        Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
        Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
        Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
        Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
        Milehighads Games Collection-->C:\Program Files\Milehighads Games Collection\uninstall.exe
        Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media 8 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP8$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media 9 (KB911565)-->"C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB913433)-->C:\WINDOWS\System32\MacroMed\Flash\genuinst.exe C:\WINDOWS\System32\MacroMed\Flash\KB913433.inf
        Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958215)-->"C:\WINDOWS\$NtUninstallKB958215$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960714)-->"C:\WINDOWS\$NtUninstallKB960714$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
        MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
        MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
        NVIDIA Drivers-->C:\WINDOWS\System32\nvudisp.exe UninstallGUI
        Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
        Programme de gestion Camera de Logitech®-->"C:\Program Files\Fichiers communs\Logitech\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT
        QuickTime-->MsiExec.exe /I{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}
        Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" -l0x40c -removeonly
        RON Too1 Milehighads-->C:\WINDOWS\System32\ulaypreaiefod.exe
        Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
        Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
        Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
        Shop for HP Supplies-->C:\Program Files\HP\Digital Imaging\HPSSupply\hpzscr01.exe -datfile hpqbud16.dat
        SoftwareUpdate 1.0-->"C:\Documents and Settings\c\Application Data\eoRezo\SoftwareUpdate\unins000.exe"
        Sonic DLA-->MsiExec.exe /I{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
        Sonic RecordNow! Plus-->MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}
        Sonic Update Manager-->MsiExec.exe /I{09DA4F91-2A09-4232-AB8C-6BC740096DE3}
        VideoLAN VLC media player 0.8.2-->C:\Program Files\VideoLAN\VLC\uninstall.exe
        Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
        Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
        Windows Live Contrôle parental-->MsiExec.exe /X{D6A2DDE3-9D7C-412C-932A-756580D29919}
        Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
        Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
        Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
        Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
        Windows Live Writer-->MsiExec.exe /X{2231CE39-B963-4B9D-823A-F412ECA637B1}
        Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
        Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
        Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
        Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"

        ======Security center information======

        AV: Avira AntiVir PersonalEdition Classic

        System event log

        Computer Name: VALLET-ZCQYLRDH
        Event Code: 7036
        Message: Le service Google Updater Service est entré dans l'état : en cours d'exécution.

        Record Number: 3848
        Source Name: Service Control Manager
        Time Written: 20090214135945.000000+060
        Event Type: Informations
        User:

        Computer Name: VALLET-ZCQYLRDH
        Event Code: 7035
        Message: Un contrôle Démarrer a correctement été envoyé au service Google Updater Service.

        Record Number: 3847
        Source Name: Service Control Manager
        Time Written: 20090214135945.000000+060
        Event Type: Informations
        User: AUTORITE NT\SYSTEM

        Computer Name: VALLET-ZCQYLRDH
        Event Code: 7036
        Message: Le service Service COM de gravage de CD IMAPI est entré dans l'état : arrêté.

        Record Number: 3846
        Source Name: Service Control Manager
        Time Written: 20090214135642.000000+060
        Event Type: Informations
        User:

        Computer Name: VALLET-ZCQYLRDH
        Event Code: 257
        Message: Un délai a expiré lors de l'envoi de la notification de modification de périphérique cible à la fenêtre de "C:\WINDOWS\Explorer.EXE"

        Record Number: 3845
        Source Name: PlugPlayManager
        Time Written: 20090214133536.000000+060
        Event Type: Avertissement
        User:

        Computer Name: VALLET-ZCQYLRDH
        Event Code: 7036
        Message: Le service Hôte de périphérique universel Plug-and-Play est entré dans l'état : en cours d'exécution.

        Record Number: 3844
        Source Name: Service Control Manager
        Time Written: 20090214133440.000000+060
        Event Type: Informations
        User:

        Application event log

        Computer Name: VALLET-ZCQYLRDH
        Event Code: 0
        Message:
        Record Number: 1031
        Source Name: SeaPort
        Time Written: 20090222154115.000000+060
        Event Type: Informations
        User:

        Computer Name: VALLET-ZCQYLRDH
        Event Code: 1
        Message:
        Record Number: 1030
        Source Name: Bonjour Service
        Time Written: 20090222154108.000000+060
        Event Type: Informations
        User:

        Computer Name: VALLET-ZCQYLRDH
        Event Code: 1002
        Message: Application bloquée Crazy Browser.exe, version 2.0.1.0, module bloqué hungapp, version 0.0.0.0, adresse de blocage 0x00000000.

        Record Number: 1029
        Source Name: Application Hang
        Time Written: 20090222131052.000000+060
        Event Type: erreur
        User:

        Computer Name: VALLET-ZCQYLRDH
        Event Code: 0
        Message:
        Record Number: 1028
        Source Name: gusvc
        Time Written: 20090222115643.000000+060
        Event Type: Informations
        User:

        Computer Name: VALLET-ZCQYLRDH
        Event Code: 0
        Message:
        Record Number: 1027
        Source Name: gusvc
        Time Written: 20090222115443.000000+060
        Event Type: Informations
        User:

        ======Environment variables======

        "ComSpec"=%SystemRoot%\system32\cmd.exe
        "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
        "windir"=%SystemRoot%
        "OS"=Windows_NT
        "PROCESSOR_ARCHITECTURE"=x86
        "PROCESSOR_LEVEL"=6
        "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 8 Stepping 1, AuthenticAMD
        "PROCESSOR_REVISION"=0801
        "NUMBER_OF_PROCESSORS"=1
        "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
        "TEMP"=%SystemRoot%\TEMP
        "TMP"=%SystemRoot%\TEMP
        "FP_NO_HOST_CHECK"=NO
        "CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
        "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

        -----------------EOF-----------------
        0
        1. Contributeur sécurité
          ok tu as mis eorezo qui est nefaste

          Télécharges AD-Remover ( de Cyrildu17 / C_XX ) sur ton bureau :
          http://sd-1.archive-host.com/membres/up/16506160323759868/AD-R.exe

          /!\ Déconnectes toi et fermes toutes applications en cours

          ● Double clique sur le programme d'installation , et installe le dans son emplacement par défaut. ( C:\Program files )
          ● Double clique sur l'icône Ad-removersituée sur ton bureau
          ● Au menu principal choisi l'option "A"
          ● Postes le rapport qui apparait à la fin .

          ( le rapport est sauvegardé aussi sous C:\Ad-report(date).log )

          (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

          Note :

          "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
          Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
          Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

          ___________

          analyse ce ficheir sur virus totla et colle le rapport https://www.virustotal.com/gui/

          C:\WINDOWS\System32\kbdla32.dll

          je me mets ceci de coté:
          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
          "AppInit_DLLS"="C:\WINDOWS\System32\kbdla32.dll"

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\a46937ad515]
          C:\WINDOWS\System32\kbdla32.dll []
          0
          1. Désole un peu long mais l'ordi a bogué

            ------- LOGFILE OF AD-REMOVER 1.1.1.6 | ONLY XP/VISTA -------

            Updated by C_XX on 07/03/2009 at 21:40

            Start at: 11:31:06 | Dim 08/03/2009 | Boot mode: Normal Boot
            Option: SCAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
            Operating System: Microsoft® Windows XP™ Service Pack 3 (version 5.1.2600)
            Computer Name: VALLET-ZCQYLRDH
            Current User: c - Administrator
            Drive(s):
            - C:\ (File System: NTFS)
            - D:\ (File System: NTFS)
            System Drive: C:\
            Windows Directory: C:\WINDOWS\
            System Directory: C:\WINDOWS\System32\

            --- Running Processes: 50

            +-----------------| Boonty/Boonty Games Elements Found:

            .
            .

            +-----------------| Eorezo Elements Found:

            HKCR\AppID\{362A53B2-2913-4F8A-82F5-7E0A23FDC6F9}
            HKCR\AppID\EoRezoBHO.DLL
            HKCR\CLSID\{C7B76B90-3455-4AE6-A752-EAC4D19689E5}
            HKCR\EoRezoBHO.EoBho
            HKCR\EoRezoBHO.EoBho.1
            HKCR\Typelib\{B6ACB3F1-6A83-432C-B854-3E1056F87F4E}
            HKCU\Software\EoRezo
            HKLM\Software\EoRezo
            HKLM\Software\Classes\AppID\{362A53B2-2913-4F8A-82F5-7E0A23FDC6F9}
            HKLM\Software\Classes\AppID\EoRezoBHO.DLL
            HKLM\Software\Classes\CLSID\{C7B76B90-3455-4AE6-A752-EAC4D19689E5}
            HKLM\Software\Classes\EoRezoBHO.EoBho
            HKLM\Software\Classes\EoRezoBHO.EoBho.1
            HKLM\Software\Classes\TypeLib\{B6ACB3F1-6A83-432C-B854-3E1056F87F4E}
            HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C7B76B90-3455-4AE6-A752-EAC4D19689E5}
            HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\eoEngine_is1
            HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdate_is1
            HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Eoengine
            HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Softwarehelper
            .
            C:\Program Files\EoRezo
            C:\Documents and Settings\c\Application Data\EoRezo

            +-----------------| Infected Poker Softwares Elements Found:

            .

            +-----------------| FunWebProducts/MyWay/MyWebSearch Elements Found:

            .
            .

            +-----------------| It's TV Elements Found:

            .

            +-----------------| Sweetim Elements Found:

            .

            +-----------------| Other Adwares Found:

            .
            .

            +-----------------| Added Scan:

            ---- Internet Explorer Version 7.0.5730.13 ----

            +-[HKEY_CURRENT_USER\..\Internet Explorer\Main]

            Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
            Start page: hxxp://fr.msn.com/

            +-[HKEY_USERS\S-1-5-21-602162358-362288127-725345543-1003\..\Internet Explorer\Main]

            Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
            Start page: hxxp://fr.msn.com/

            +-[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

            Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=69157
            Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
            Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
            Start page: hxxp://go.microsoft.com/fwlink/?LinkId=69157

            +-[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

            Tabs: hxxp://y.lo.st

            +---------------------------------------------------------------------------+

            [~2979 Bytes] - C:\Ad-Report-Scan-08.03.2009.log

            - C:\Program Files\Ad-remover\TOOLS\BACKUP
            - C:\Program Files\Ad-remover\TOOLS\QUARANTINE

            End at: 11:33:07 | 08/03/2009
            .
            +-----------------| E.O.F - 68 Lines
            .
            0
            1. 0 bytes size received / Se ha recibido un archivo vacio
              0
              1. Antivirus Version Dernière mise à jour Résultat
                a-squared 4.0.0.101 2009.03.08 -
                AhnLab-V3 5.0.0.2 2009.02.27 -
                AntiVir 7.9.0.105 2009.03.07 -
                Authentium 5.1.0.4 2009.03.07 -
                Avast 4.8.1335.0 2009.03.08 -
                AVG 8.0.0.237 2009.03.07 -
                BitDefender 7.2 2009.03.08 -
                CAT-QuickHeal 10.00 2009.03.07 -
                ClamAV 0.94.1 2009.03.06 -
                Comodo 1037 2009.03.08 -
                DrWeb 4.44.0.09170 2009.03.08 -
                eSafe 7.0.17.0 2009.03.05 -
                eTrust-Vet 31.6.6386 2009.03.06 -
                F-Prot 4.4.4.56 2009.03.07 -
                F-Secure 8.0.14470.0 2009.03.08 -
                Fortinet 3.117.0.0 2009.03.08 -
                GData 19 2009.03.08 -
                Ikarus T3.1.1.45.0 2009.03.08 -
                K7AntiVirus 7.10.663 2009.03.07 -
                Kaspersky 7.0.0.125 2009.03.08 -
                McAfee 5546 2009.03.07 -
                McAfee+Artemis 5546 2009.03.07 -
                Microsoft 1.4405 2009.03.08 -
                NOD32 3917 2009.03.07 -
                Norman 6.00.06 2009.03.06 -
                nProtect 2009.1.8.0 2009.03.08 -
                Panda 10.0.0.10 2009.03.07 -
                PCTools 4.4.2.0 2009.03.07 -
                Prevx1 V2 2009.03.08 -
                Rising 21.19.42.00 2009.03.06 -
                SecureWeb-Gateway 6.7.6 2009.03.07 -
                Sophos 4.39.0 2009.03.08 -
                Sunbelt 3.2.1858.2 2009.03.08 -
                Symantec 1.4.4.12 2009.03.08 -
                TheHacker 6.3.2.7.275 2009.03.07 -
                TrendMicro 8.700.0.1004 2009.03.06 -
                VBA32 3.12.10.1 2009.03.08 -
                ViRobot 2009.3.7.1639 2009.03.07 -
                VirusBuster 4.5.11.0 2009.03.07 -
                Information additionnelle
                File size: 6656 bytes
                MD5...: a8470fe45ff308ce53828301976a13cb
                SHA1..: a9fe99d67e690717e7dfe42f4efac1e352affc52
                SHA256: 4c2ed39b7da827fa6ad4183ff79d64f5a86f2f18a51cc484fea8cb2d1f304d3f
                SHA512: 349f87748d52e4ed11354d99295232c79f499100d746aca4e711cec0c7962966
                0b3618d5457aa3b2818593805be1b6be24b449a0fde5005d9686cf34d0e907e1
                ssdeep: 48:qvrz0y2IoAAgync/y3hUTR5GRw9eL2Fj4A3cuf/JVdnFvfSF9dXRB78v3uZW1
                m5s:5y27caxUl5GetFBhdE9dYuW002ZWw0n

                PEiD..: -
                TrID..: File type identification
                Generic Win/DOS Executable (49.9%)
                DOS Executable Generic (49.8%)
                Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
                PEInfo: PE Structure information

                ( base data )
                entrypointaddress.: 0x0
                timedatestamp.....: 0x3b7d9313 (Fri Aug 17 21:56:35 2001)
                machinetype.......: 0x14c (I386)

                ( 3 sections )
                name viradd virsiz rawdsiz ntrpy md5
                .data 0x1000 0xd40 0xe00 4.08 7eb3bb36026c86c2b4647e134bcef6ba
                .rsrc 0x2000 0x408 0x600 2.47 c9129a6977f44024b1981f97224e6918
                .reloc 0x3000 0xb4 0x200 2.36 c9284c13bf9d62d8c486f4ca8d907ed3

                ( 0 imports )

                ( 1 exports )
                KbdLayerDescriptor
                0
                1. Contributeur sécurité
                  ! Déconnectes toi et fermes toutes applications en cours !

                  ● Relances "Ad-remover" : au menu principal choisi l'option "B" .

                  --> le programme va travailler ...

                  ● Postes le rapport qui apparait à la fin + un nouvel Hijackthis pour analyse ...

                  ( le rapport est sauvegardé aussi sous C:\Ad-report(date).log )

                  (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                  /!\ Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides)

                  /!\ Déconnecte-toi et ferme toutes applications en cours /!\

                  Double-clique sur AD-Remover pour le lancer : au menu principal, choisis l'option B.

                  Coche à l'écran de sélection :
                  http://sd-1.archive-host.com/membres/up/16506160323759868/Ca­pturer-ADR.JPG

                  Suppression Eorezo

                  Puis choisis S, le programme va travailler.

                  Poste le rapport qui apparaît à la fin.

                  (Le rapport est sauvegardé aussi sous C:\Ad-report.log)

                  /!\ Si le Bureau ne réapparaît pas, presse Ctrl + Alt + Suppr, Onglet "Fichier", "Nouvelle tâche", tape explorer.exe et valide) /!\

                  Note :

                  "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                  Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                  Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...)

                  __________________

                  télécharge OTMoveIt
                  http://oldtimer.geekstogo.com/OTMoveIt3.exe (de Old_Timer) sur ton Bureau.

                  double-clique sur OTMoveIt.exe pour le lancer.
                  copie la liste qui se trouve en citation ci-dessous,
                  et colle-la dans le cadre de gauche de OTMoveIt :Paste instruction for items to be moved.
                  (attention bien mettre :files)

                  :files
                  C:\WINDOWS\System32\kbdla32.dll
                  :reg
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                  "AppInit_DLLS"=-
                  [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\a46937ad515]
                  :commands
                  [purity]
                  [emptytemp]
                  [start explorer]

                  clique sur MoveIt! pour lancer la suppression.
                  le résultat apparaitra dans le cadre "Results".
                  clique sur Exit pour fermer.
                  poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

                  il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.
                  ______________________

                  remets un rapport RSIt et dis si encore des pubs
                  0
                  1. ------- LOGFILE OF AD-REMOVER 1.1.1.6 | ONLY XP/VISTA -------

                    Updated by C_XX on 07/03/2009 at 21:40

                    *** LIMITED TO ***

                    Boonty/BoontyGames
                    Eorezo
                    Infected Poker Softwares
                    FunWebProduct/MyWay/MyWebSearch
                    It's TV
                    Sweetim
                    Other Adwares

                    ******************

                    Start at: 12:07:00 | Dim 08/03/2009 | Boot mode: Normal Boot
                    Option: CLEAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
                    Operating System: Microsoft® Windows XP™ Service Pack 3 (version 5.1.2600)
                    Computer Name: VALLET-ZCQYLRDH
                    Current User: c - Administrator
                    Drive(s):
                    - C:\ (File System: NTFS)
                    - D:\ (File System: NTFS)
                    System Drive: C:\
                    Windows Directory: C:\WINDOWS\
                    System Directory: C:\WINDOWS\System32\

                    --- Running Processes: 48

                    (!) ---- IE start pages/Tabs reset

                    +-----------------| Boonty/Boonty Games Elements Deleted :

                    .
                    .

                    +-----------------| Eorezo Elements Deleted :

                    HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Eoengine
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Softwarehelper
                    HKCR\AppID\{362A53B2-2913-4F8A-82F5-7E0A23FDC6F9}
                    HKCR\AppID\EoRezoBHO.DLL
                    HKCR\CLSID\{C7B76B90-3455-4AE6-A752-EAC4D19689E5}
                    HKCR\EoRezoBHO.EoBho
                    HKCR\EoRezoBHO.EoBho.1
                    HKCR\Typelib\{B6ACB3F1-6A83-432C-B854-3E1056F87F4E}
                    HKCU\Software\EoRezo
                    HKLM\Software\EoRezo
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C7B76B90-3455-4AE6-A752-EAC4D19689E5}
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\eoEngine_is1
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdate_is1
                    .
                    C:\Program Files\EoRezo
                    C:\Documents and Settings\c\Application Data\EoRezo
                    C:\Documents and Settings\c\Cookies\c@eorezo[2].txt

                    +-----------------| Infected Poker Softwares Elements Deleted :

                    .

                    +-----------------| FunWebProducts/MyWay/MyWebSearch Elements Deleted :

                    .
                    .

                    +-----------------| It's TV Elements Deleted :

                    .

                    +-----------------| Sweetim Elements Deleted :

                    .

                    +-----------------| Other Adwares Deleted:

                    .
                    .

                    (!) ---- Temp files deleted.
                    (!) ---- Recycle bin emptied in all drives.

                    +-----------------| Added Scan :

                    ---- Internet Explorer Version 7.0.5730.13 ----

                    +-[HKEY_CURRENT_USER\..\Internet Explorer\Main]

                    Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                    Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                    Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                    Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                    Start page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

                    +-[HKEY_USERS\S-1-5-21-602162358-362288127-725345543-1003\..\Internet Explorer\Main]

                    Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                    Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                    Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                    Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                    Start page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

                    +-[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

                    Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                    Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                    Search bar: hxxp://search.msn.com/spbasic.htm
                    Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                    Start page: hxxp://fr.msn.com/

                    +-[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

                    Tabs: hxxp://ieframe.dll/tabswelcome.htm

                    +---------------------------------------------------------------------------+

                    [~3642 Bytes] - C:\Ad-Report-Clean-08.03.2009.log
                    [~3200 Bytes] - C:\Ad-Report-Scan-08.03.2009.log

                    - C:\Program Files\Ad-remover\TOOLS\BACKUP
                    - C:\Program Files\Ad-remover\TOOLS\QUARANTINE

                    End at: 12:09:01 | 08/03/2009
                    .
                    +-----------------| E.O.F - 82 Lines
                    .
                    0
                    1. Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 12:37:27, on 08/03/2009
                      Platform: Windows XP SP3 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v7.00 (7.00.6000.16791)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                      C:\Program Files\Java\jre6\bin\jusched.exe
                      C:\WINDOWS\System32\LVCOMSX.EXE
                      C:\Program Files\Logitech\Video\LogiTray.exe
                      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                      C:\Program Files\iTunes\iTunesHelper.exe
                      C:\WINDOWS\system32\dla\tfswctrl.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Documents and Settings\c\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
                      C:\Documents and Settings\c\Application Data\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
                      C:\Program Files\Logitech\Video\FxSvr2.exe
                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      C:\Program Files\Bonjour\mDNSResponder.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\Java\jre6\bin\jqs.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\System32\nvsvc32.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                      C:\WINDOWS\system32\slserv.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\iPod\bin\iPodService.exe
                      C:\WINDOWS\System32\wbem\wmiapsrv.exe
                      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                      C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
                      C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
                      C:\WINDOWS\explorer.exe
                      C:\Program Files\Crazy Browser\Crazy Browser.exe
                      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://lo.st#first
                      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
                      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                      O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
                      O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
                      O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
                      O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
                      O2 - BHO: (no name) - {d639308d-9862-8615-4053-2e2c6fb10050} - (no file)
                      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                      O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                      O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
                      O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                      O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                      O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
                      O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
                      O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
                      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                      O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
                      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                      O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
                      O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
                      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
                      O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
                      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                      O4 - Startup: Outil de notification Live Search.lnk = C:\Documents and Settings\c\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
                      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                      O9 - Extra button: Sélection intelligente HP - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
                      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
                      O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - https://sdlc-esd.oracle.com/ESD5/JSCDL/jre/6u11-b90/jinstall-6u11-windows-i586-jc.cab?GroupName=JSC&FilePath=/ESD5/JSCDL/jre/6u11-b90/jinstall-6u11-windows-i586-jc.cab&BHost=javadl.sun.com&File=jinstall-6u11-windows-i586-jc.cab&AuthParam=1580990370_ae51af1f2e3e7c78a0fbe2e88da6073d&ext=.cab
                      O20 - AppInit_DLLs: C:\WINDOWS\System32\kbdla32.dll
                      O20 - Winlogon Notify: a46937ad515 - C:\WINDOWS\System32\kbdla32.dll (file missing)
                      O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                      O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                      O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
                      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                      O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
                      0
                      1. ========== FILES ==========
                        File/Folder C:\WINDOWS\System32\kbdla32.dll not found.
                        ========== REGISTRY ==========
                        Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLS deleted successfully.
                        Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\a46937ad515\\ deleted successfully.
                        ========== COMMANDS ==========
                        User's Temp folder emptied.
                        User's Temporary Internet Files folder emptied.
                        User's Internet Explorer cache folder emptied.
                        Local Service Temp folder emptied.
                        File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
                        Local Service Temporary Internet Files folder emptied.
                        File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_75c.dat scheduled to be deleted on reboot.
                        Windows Temp folder emptied.
                        Java cache emptied.
                        Temp folders emptied.
                        Explorer started successfully

                        OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 03082009_124017

                        Files moved on Reboot...
                        File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
                        File C:\WINDOWS\temp\Perflib_Perfdata_75c.dat not found!
                        0
                        1. Contributeur sécurité
                          tu n'as pas fais dans le bon ordre:

                          remets un rapport RSIt et dis si encore des pubs
                          0
                          1. c'est ce rapport qu'il te faut?

                            ========== FILES ==========
                            File/Folder C:\WINDOWS\System32\kbdla32.dll not found.
                            ========== REGISTRY ==========
                            Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLS not found.
                            Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\a46937ad515\\ not found.
                            ========== COMMANDS ==========
                            User's Temp folder emptied.
                            User's Temporary Internet Files folder emptied.
                            User's Internet Explorer cache folder emptied.
                            Local Service Temp folder emptied.
                            File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
                            Local Service Temporary Internet Files folder emptied.
                            File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_588.dat scheduled to be deleted on reboot.
                            Windows Temp folder emptied.
                            Java cache emptied.
                            Temp folders emptied.
                            Explorer started successfully

                            OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 03082009_185308

                            Files moved on Reboot...
                            File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
                            File C:\WINDOWS\temp\Perflib_Perfdata_588.dat not found!
                            0
                            1. non j'ai trouvé

                              Logfile of random's system information tool 1.05 (written by random/random)
                              Run by c at 2009-03-08 18:58:50
                              Microsoft Windows XP Professionnel Service Pack 3
                              System drive C: has 57 GB (85%) free of 66 GB
                              Total RAM: 511 MB (42% free)

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 18:58:57, on 08/03/2009
                              Platform: Windows XP SP3 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v7.00 (7.00.6000.16791)
                              Boot mode: Normal

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                              C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              C:\Program Files\Bonjour\mDNSResponder.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\Program Files\Java\jre6\bin\jqs.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\System32\nvsvc32.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                              C:\WINDOWS\system32\slserv.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\Java\jre6\bin\jusched.exe
                              C:\WINDOWS\System32\LVCOMSX.EXE
                              C:\Program Files\Logitech\Video\LogiTray.exe
                              C:\WINDOWS\SOUNDMAN.EXE
                              C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                              C:\WINDOWS\system32\rundll32.exe
                              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                              C:\Program Files\iTunes\iTunesHelper.exe
                              C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
                              C:\WINDOWS\system32\dla\tfswctrl.exe
                              C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe
                              C:\WINDOWS\system32\ctfmon.exe
                              C:\Program Files\Logitech\Video\FxSvr2.exe
                              C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                              C:\Documents and Settings\c\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
                              C:\Documents and Settings\c\Application Data\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
                              C:\Program Files\Crazy Browser\Crazy Browser.exe
                              C:\WINDOWS\system32\wuauclt.exe
                              C:\WINDOWS\System32\wbem\wmiapsrv.exe
                              C:\Program Files\iPod\bin\iPodService.exe
                              C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                              C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
                              C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
                              C:\Documents and Settings\c\Bureau\RSIT.exe
                              C:\Program Files\Trend Micro\HijackThis\c.exe

                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://lo.st#first
                              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                              O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
                              O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                              O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                              O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
                              O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
                              O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
                              O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
                              O2 - BHO: (no name) - {d639308d-9862-8615-4053-2e2c6fb10050} - (no file)
                              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                              O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                              O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                              O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
                              O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                              O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                              O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
                              O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
                              O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
                              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                              O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                              O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
                              O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                              O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                              O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
                              O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                              O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
                              O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
                              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                              O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
                              O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
                              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                              O4 - Startup: Outil de notification Live Search.lnk = C:\Documents and Settings\c\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
                              O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                              O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                              O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                              O9 - Extra button: Sélection intelligente HP - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
                              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
                              O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - https://sdlc-esd.oracle.com/ESD5/JSCDL/jre/6u11-b90/jinstall-6u11-windows-i586-jc.cab?GroupName=JSC&FilePath=/ESD5/JSCDL/jre/6u11-b90/jinstall-6u11-windows-i586-jc.cab&BHost=javadl.sun.com&File=jinstall-6u11-windows-i586-jc.cab&AuthParam=1580990370_ae51af1f2e3e7c78a0fbe2e88da6073d&ext=.cab
                              O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                              O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                              O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                              O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                              O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
                              O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                              O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
                              0
                              1. info.txt logfile of random's system information tool 1.05 2009-03-08 18:59:00

                                ======Uninstall list======

                                -->C:\WINDOWS\system32\\MSIEXEC.EXE /I {09DA4F91-2A09-4232-AB8C-6BC740096DE3} REMOVE=UpdateMgrFeature
                                -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
                                -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
                                -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
                                32 Bit HP CIO Components Installer-->MsiExec.exe /I{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}
                                7-Zip 4.64-->"C:\Program Files\7-Zip\Uninstall.exe"
                                Adobe Flash Player 10 ActiveX-->C:\WINDOWS\System32\Macromed\Flash\uninstall_activeX.exe
                                Adobe Reader 9 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A90000000001}
                                Apple Mobile Device Support-->MsiExec.exe /I{EC4455AB-F155-4CC1-A4C5-88F3777F9886}
                                Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
                                Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
                                Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
                                Bonjour-->MsiExec.exe /I{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}
                                CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
                                Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
                                Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
                                Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
                                Crazy Browser version 2.0.1-->"C:\Program Files\Crazy Browser\unins000.exe"
                                DVD Shrink 3.1.7-->"C:\Program Files\DVD Shrink\unins000.exe"
                                Galerie de photos Windows Live-->MsiExec.exe /X{44E54A81-9D91-4AA1-9417-80AFF134F5FF}
                                Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_0531C63A913CC9D1.exe" /uninstall
                                HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
                                Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
                                HP Customer Participation Program 10.0-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
                                HP Deskjet F2200 All-In-One Driver Software 10.0 Rel .3-->C:\Program Files\HP\Digital Imaging\{D77D43B5-ED55-426b-B67B-E21F804F6102}\setup\hpzscr01.exe -datfile hposcr27.dat -onestop
                                HP Imaging Device Functions 10.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
                                HP Photosmart Essential 2.5-->C:\Program Files\HP\Digital Imaging\PhotoSmartEssential\hpzscr01.exe -datfile hpqbud13.dat
                                HP Smart Web Printing-->C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpzscr01.exe -datfile hpqbud15.dat
                                HP Solution Center 10.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
                                HP Update-->MsiExec.exe /X{FE57DE70-95DE-4B64-9266-84DA811053DB}
                                Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
                                Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
                                iTunes-->MsiExec.exe /I{F5C63795-2708-4D15-BF18-5ABBFF7DFFC8}
                                Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
                                Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
                                Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
                                LimeWire 4.18.8-->"C:\Program Files\LimeWire\uninstall.exe"
                                Logiciel QuickCam de Logitech-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C43048A9-742C-4DAD-90D2-E3B53C9DB825}\setup.exe" -l0x40c
                                Ludi-->C:\Program Files\Ludi\uninstall.exe
                                Ma-Config.com-->MsiExec.exe /X{EC7FE2ED-F305-41B7-90B8-3DAE9E35307A}
                                Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
                                Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
                                Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
                                Microsoft AutoRoute 2005-->MsiExec.exe /I{67E4EE98-59F4-4220-89A6-A20AF5BEC689}
                                Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
                                Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
                                Microsoft Search Enhancement Pack-->MsiExec.exe /I{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}
                                Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
                                Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
                                Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
                                Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
                                Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
                                Milehighads Games Collection-->C:\Program Files\Milehighads Games Collection\uninstall.exe
                                Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Lecteur Windows Media 8 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP8$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Lecteur Windows Media 9 (KB911565)-->"C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB913433)-->C:\WINDOWS\System32\MacroMed\Flash\genuinst.exe C:\WINDOWS\System32\MacroMed\Flash\KB913433.inf
                                Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB958215)-->"C:\WINDOWS\$NtUninstallKB958215$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB960714)-->"C:\WINDOWS\$NtUninstallKB960714$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
                                Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
                                Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
                                Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
                                MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
                                MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                                NVIDIA Drivers-->C:\WINDOWS\System32\nvudisp.exe UninstallGUI
                                Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
                                Programme de gestion Camera de Logitech®-->"C:\Program Files\Fichiers communs\Logitech\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT
                                QuickTime-->MsiExec.exe /I{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}
                                Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" -l0x40c -removeonly
                                RON Too1 Milehighads-->C:\WINDOWS\System32\ulaypreaiefod.exe
                                Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                                Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                                Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
                                Shop for HP Supplies-->C:\Program Files\HP\Digital Imaging\HPSSupply\hpzscr01.exe -datfile hpqbud16.dat
                                Sonic DLA-->MsiExec.exe /I{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
                                Sonic RecordNow! Plus-->MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}
                                Sonic Update Manager-->MsiExec.exe /I{09DA4F91-2A09-4232-AB8C-6BC740096DE3}
                                VideoLAN VLC media player 0.8.2-->C:\Program Files\VideoLAN\VLC\uninstall.exe
                                Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
                                Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
                                Windows Live Contrôle parental-->MsiExec.exe /X{D6A2DDE3-9D7C-412C-932A-756580D29919}
                                Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
                                Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
                                Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
                                Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
                                Windows Live Writer-->MsiExec.exe /X{2231CE39-B963-4B9D-823A-F412ECA637B1}
                                Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
                                Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
                                Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
                                Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"

                                ======Security center information======

                                AV: Avira AntiVir PersonalEdition Classic

                                System event log

                                Computer Name: VALLET-ZCQYLRDH
                                Event Code: 18
                                Message: TIMEOUT<svchost.exe> C:\...po_DJAIO3F2200_DD.ini

                                Record Number: 3964
                                Source Name: avgntflt
                                Time Written: 20090216114455.000000+060
                                Event Type: Avertissement
                                User:

                                Computer Name: VALLET-ZCQYLRDH
                                Event Code: 18
                                Message: TIMEOUT<spoolsv.exe>

                                Record Number: 3963
                                Source Name: avgntflt
                                Time Written: 20090216114428.000000+060
                                Event Type: Avertissement
                                User:

                                Computer Name: VALLET-ZCQYLRDH
                                Event Code: 18
                                Message: TIMEOUT<iexplore.exe> C:\...tension\QUERYDAT.XML

                                Record Number: 3962
                                Source Name: avgntflt
                                Time Written: 20090216114358.000000+060
                                Event Type: Avertissement
                                User:

                                Computer Name: VALLET-ZCQYLRDH
                                Event Code: 18
                                Message: TIMEOUT<iexplore.exe>

                                Record Number: 3961
                                Source Name: avgntflt
                                Time Written: 20090216114325.000000+060
                                Event Type: Avertissement
                                User:

                                Computer Name: VALLET-ZCQYLRDH
                                Event Code: 18
                                Message: TIMEOUT<avwsc.exe> C:\...tion Classic\rctext.dll

                                Record Number: 3960
                                Source Name: avgntflt
                                Time Written: 20090216114251.000000+060
                                Event Type: Avertissement
                                User:

                                Application event log

                                Computer Name: VALLET-ZCQYLRDH
                                Event Code: 0
                                Message:
                                Record Number: 1073
                                Source Name: hpqcxs08
                                Time Written: 20090223164945.000000+060
                                Event Type: Informations
                                User:

                                Computer Name: VALLET-ZCQYLRDH
                                Event Code: 1800
                                Message: Le service Centre de sécurité Windows a démarré.

                                Record Number: 1072
                                Source Name: SecurityCenter
                                Time Written: 20090223164825.000000+060
                                Event Type: Informations
                                User:

                                Computer Name: VALLET-ZCQYLRDH
                                Event Code: 4096
                                Message: Le service AntiVir a bien démarré!

                                Record Number: 1071
                                Source Name: Avira AntiVir
                                Time Written: 20090223164821.000000+060
                                Event Type: Informations
                                User: AUTORITE NT\SYSTEM

                                Computer Name: VALLET-ZCQYLRDH
                                Event Code: 1
                                Message:
                                Record Number: 1070
                                Source Name: Bonjour Service
                                Time Written: 20090223164819.000000+060
                                Event Type: Informations
                                User:

                                Computer Name: VALLET-ZCQYLRDH
                                Event Code: 0
                                Message:
                                Record Number: 1069
                                Source Name: SeaPort
                                Time Written: 20090223164819.000000+060
                                Event Type: Informations
                                User:

                                ======Environment variables======

                                "ComSpec"=%SystemRoot%\system32\cmd.exe
                                "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
                                "windir"=%SystemRoot%
                                "OS"=Windows_NT
                                "PROCESSOR_ARCHITECTURE"=x86
                                "PROCESSOR_LEVEL"=6
                                "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 8 Stepping 1, AuthenticAMD
                                "PROCESSOR_REVISION"=0801
                                "NUMBER_OF_PROCESSORS"=1
                                "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
                                "TEMP"=%SystemRoot%\TEMP
                                "TMP"=%SystemRoot%\TEMP
                                "FP_NO_HOST_CHECK"=NO
                                "CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
                                "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

                                -----------------EOF-----------------
                                0
                                1. Contributeur sécurité
                                  ok parfait

                                  encore des soucis?

                                  antivir et malwarebyte ne trouvaient aucune infection?
                                  0
                                  1. je ne pense pas pas de pub et une vitesse correct

                                    Merci pour tout
                                    Christophe
                                    0
                                    1. Contributeur sécurité
                                      Télécharge ToolsCleaner sur ton bureau.
                                      --> http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
                                      # Clique sur Recherche et laisse le scan agir ...
                                      # Clique sur Suppression pour finaliser.
                                      # Tu peux, si tu le souhaites, te servir des Options facultatives.
                                      # Clique sur Quitter pour obtenir le rapport.
                                      # Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
                                      0
                                      1. [ Rapport ToolsCleaner version 2.3.2 (par A.Rothstein & dj QUIOU) ]

                                        -->- Recherche:

                                        ---------------------------------
                                        -->- Suppression:
                                        0
                                        1. Contributeur sécurité
                                          tool cleaner a tout viré?
                                          0
                                          • 1
                                          • 2