Infection

Résolu
Bonjour,
j'ai un petit problème avec mon ordi, il tourne a fond dès que je suis connecté à internet,
voici mon rapport
C'est grave docteur?????
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:59:32, on 25/03/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Fichiers communs\InstallShield\UpdateService\isuspm.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\NDAS\System\ndasmgmt.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\NDAS\System\ndassvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\...\Bureau\zaSetup_fr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfre0.dll
R3 - URLSearchHook: IsoBuster Toolbar - {266fcdca-7bb3-4da7-b3bf-f845dea2ebd6} - C:\Program Files\IsoBuster\tbIso1.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: IsoBuster Toolbar - {266fcdca-7bb3-4da7-b3bf-f845dea2ebd6} - C:\Program Files\IsoBuster\tbIso1.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfre0.dll
O3 - Toolbar: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfre0.dll
O3 - Toolbar: IsoBuster Toolbar - {266fcdca-7bb3-4da7-b3bf-f845dea2ebd6} - C:\Program Files\IsoBuster\tbIso1.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: NDAS Device Management.lnk = C:\Program Files\NDAS\System\ndasmgmt.exe
O8 - Extra context menu item: &Télécharger avec NetTransport - C:\Program Files\Xi\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: Add to AMV Converter... - C:\Program Files\MP3 Player Utilities 4.05\AMVConverter\grab.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.05\MediaManager\grab.html
O8 - Extra context menu item: Tout t&élécharger avec NetTransport - C:\Program Files\Xi\NetTransport 2\NTAddList.html
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe (file missing)
O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe (file missing)
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://download.microsoft.com/download/C/B/F/CBF23A2C-3E55-4664-BC5C-762780D79BA0/OGAControl.cab
O16 - DPF: {070CA17A-4BD2-4612-83B4-32B1B9159B47} (ULiveCtrl Control) - http://uc.sina.com.cn/download/live/weblive2.4.0.0.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} (Microsoft Genuine Advantage Self Support Tool) - http://download.microsoft.com/download/7/4/9/749b0dc5-2175-4d5b-a6dd-9c4bc923683e/Selfhelpcontrol.cab
O16 - DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} - http://fr.midas.games.yahoo.net/ctl/kingcomie.cab
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: NDAS Service (ndassvc) - XIMETA, Inc. - C:\Program Files\NDAS\System\ndassvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

End of file - 12164 bytes

22 réponses

  1. salut :

    Mets Internet Explorer a jour cers la version 7 via windows update

    ensuite :

    Télécharge TOOLBAR S&D ( de Eric_71/Team IDN ) sur ton bureau :

    !! Déconnecte toi et ferme toutes tes applications en cours le temps de la manipe !!

    * Double-clique sur ToolBar SD.exe pour lancer l'outil et laisse toi guider ...
    --> Tapes ( option " recherche " ) puis tape sur [Entrée].

    Un rapport sera généré à la fin du processus : poste son contenu dans ta prochaine réponse

    ( le rapport est en outre sauvegardé ici -> C:\TB.txt )

    Tutoriel
    0
    1. Merci c'est cool de m'aider
      voici le rapport

      -----------\\ ToolBar S&D 1.2.8 XP/Vista

      Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
      X86-based PC ( Multiprocessor Free : AMD Turion(tm) 64 X2 Mobile Technology TL-50 )
      BIOS : PhoenixBIOS 4.0 Release 6.1
      USER : ... ( Administrator )
      BOOT : Normal boot
      Antivirus : avast! antivirus 4.7.1029 [VPS 080103-0] 4.7.1029 (Activated)
      Firewall : ZoneAlarm Firewall 7.0.483.000 (Not Activated)
      C:\ (Local Disk) - NTFS - Total:102 Go (Free:3 Go)
      D:\ (Local Disk) - FAT32 - Total:8 Go (Free:1 Go)
      E:\ (CD or DVD)
      F:\ (CD or DVD)
      H:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
      I:\ (USB) - FAT - Total:1929 Mo (Free:0 Go)

      "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
      Option : [1] ( 25/03/2009|10:20 )

      -----------\\ Recherche de Fichiers / Dossiers ...

      -----------\\ Extensions

      (All Users) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar

      (...) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
      (...) - {991A772A-BA13-4c1d-A9EF-F897F31DEC7D} => megaupload

      -----------\\ [..\Internet Explorer\Main]

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
      "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
      "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
      "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
      "Search Bar"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
      "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
      "Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
      "Default_Search_URL"="https://actus.sfr.fr"
      "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
      "Local Page"="C:\\windows\\system32\\blank.htm"
      "Start Page"="https://www.msn.com/fr-fr"

      --------------------\\ Recherche d'autres infections

      --------------------\\ Cracks & Keygens ..

      C:\DOCUME~1\LETACO~1\Application Data\uTorrent\Football_Manager_2008.CRACK-HATRED.torrent
      C:\DOCUME~1\LETACO~1\Application Data\uTorrent\ZoneAlarm Security Suite 7.0.483 + Keygen [dArt].torrent
      C:\DOCUME~1\LETACO~1\Bureau\Age of Empires III\Cracks
      C:\DOCUME~1\LETACO~1\Bureau\Age of Empires III\Cracks\age3.exe
      C:\DOCUME~1\LETACO~1\Bureau\Age of Empires III\Cracks\age3x.exe
      C:\DOCUME~1\LETACO~1\Bureau\Age of Empires III\Cracks\age3y.exe
      C:\DOCUME~1\LETACO~1\Mes documents\Ma musique\iTunes\iTunes Music\Compilations\Life After Death [Disc 2]\2-05 Ten Crack Commandments.m4a
      C:\DOCUME~1\LETACO~1\Temporary Internet Files\Content.IE5\4ZUVEFSB\145588_crackspace_the_place_for_hip_hop_cracktv_honey_dips_keisha_cambell_1[1].jpg
      C:\DOCUME~1\LETACO~1\Temporary Internet Files\Content.IE5\BJERMPEV\146430_crackspace_the_place_for_hip_hop_cracktv_honey_dips_pinky_ice_la_fox_lacey_duvall_pt_4_1[1].jpg
      C:\DOCUME~1\LETACO~1\Temporary Internet Files\Content.IE5\GHMBSHQN\144235_brooke_haven_mark_ashley_crack_addict_1[2].jpg
      C:\DOCUME~1\LETACO~1\Temporary Internet Files\Content.IE5\M116NMTO\145499_crackspace_the_place_for_hip_hop_cracktv_honey_dips_ice_la_fox_havana_ginger_1[1].jpg
      C:\DOCUME~1\LETACO~1\Temporary Internet Files\Content.IE5\M116NMTO\146009_crackspace_the_place_for_hip_hop_cracktv_honey_dips_victoria_lan_1[1].jpg
      C:\DOCUME~1\LETACO~1\Temporary Internet Files\Content.IE5\OHWXI349\145499_crackspace_the_place_for_hip_hop_cracktv_honey_dips_ice_la_fox_havana_ginger_1[1].jpg
      C:\DOCUME~1\LETACO~1\Temporary Internet Files\Content.IE5\P7N3510E\145123_crackspace_the_place_for_hip_hop_cracktv_honey_dips_pinky5_1[1].jpg
      C:\DOCUME~1\LETACO~1\Temporary Internet Files\Content.IE5\PGKZ1P45\145499_crackspace_the_place_for_hip_hop_cracktv_honey_dips_ice_la_fox_havana_ginger_1[1].jpg
      C:\DOCUME~1\LETACO~1\Temporary Internet Files\Content.IE5\WXQ7OTAV\144192_crackspace_the_place_for_hip_hop_cracktv_honey_dips_kahfee_kakkes_1[1].jpg

      1 - "C:\ToolBar SD\TB_1.txt" - 25/03/2009|10:21 - Option : [1]

      -----------\\ Fin du rapport a 10:21:47,56
      0
      1. C:\DOCUME~1\LETACO~1\Application Data\uTorrent\Football_Manager_2008.CRACK-HATRED.torrent
        C:\DOCUME~1\LETACO~1\Application Data\uTorrent\ZoneAlarm Security Suite 7.0.483 + Keygen [dArt].torrent
        C:\DOCUME~1\LETACO~1\Bureau\Age of Empires III\Cracks
        C:\DOCUME~1\LETACO~1\Bureau\Age of Empires III\Cracks\age3.exe
        C:\DOCUME~1\LETACO~1\Bureau\Age of Empires III\Cracks\age3x.exe
        C:\DOCUME~1\LETACO~1\Bureau\Age of Empires III\Cracks\age3y.exe
        C:\DOCUME~1\LETACO~1\Mes documents\Ma musique\iTunes\iTunes Music\Compilations\Life After Death [Disc 2]\2-05 Ten Crack Commandments.m4a
        C:\DOCUME~1\LETACO~1\Temporary Internet Files\Content.IE5\4ZUVEFSB\145588_crackspace_the_place_for_hip_hop_cracktv_honey_dips_keisha_cambell_1[1].jpg
        C:\DOCUME~1\LETACO~1\Temporary Internet Files\Content.IE5\BJERMPEV\146430_crackspace_the_place_for_hip_hop_cracktv_honey_dips_pinky_ice_la_fox_lacey_duvall_pt_4_1[1].jpg
        C:\DOCUME~1\LETACO~1\Temporary Internet Files\Content.IE5\GHMBSHQN\144235_brooke_haven_mark_ashley_crack_addict_1[2].jpg
        C:\DOCUME~1\LETACO~1\Temporary Internet Files\Content.IE5\M116NMTO\145499_crackspace_the_place_for_hip_hop_cracktv_honey_dips_ice_la_fox_havana_ginger_1[1].jpg
        C:\DOCUME~1\LETACO~1\Temporary Internet Files\Content.IE5\M116NMTO\146009_crackspace_the_place_for_hip_hop_cracktv_honey_dips_victoria_lan_1[1].jpg
        C:\DOCUME~1\LETACO~1\Temporary Internet Files\Content.IE5\OHWXI349\145499_crackspace_the_place_for_hip_hop_cracktv_honey_dips_ice_la_fox_havana_ginger_1[1].jpg
        C:\DOCUME~1\LETACO~1\Temporary Internet Files\Content.IE5\P7N3510E\145123_crackspace_the_place_for_hip_hop_cracktv_honey_dips_pinky5_1[1].jpg
        C:\DOCUME~1\LETACO~1\Temporary Internet Files\Content.IE5\PGKZ1P45\145499_crackspace_the_place_for_hip_hop_cracktv_honey_dips_ice_la_fox_havana_ginger_1[1].jpg
        C:\DOCUME~1\LETACO~1\Temporary Internet Files\Content.IE5\WXQ7OTAV\144192_crackspace_the_place_for_hip_hop_cracktv_honey_dips_kahfee_kakkes_1[1].jpg


        supprimes tout ceci source d'infection puis :

        Télécharge Superantispyware (SAS)

        Choisis "enregistrer" et enregistre-le sur ton bureau.

        Double-clique sur l'icône d'installation qui vient de se créer et suis les instructions.

        Créé une icône sur le bureau.

        Double-clique sur l'icône de SAS (une tête dans un cercle rouge barré) pour le lancer.

        - Si l'outil te demande de mettre à jour le programme ("update the program definitions", clique sur yes.
        - Sous Configuration and Preferences, clique sur le bouton "Preferences"
        - Clique sur l'onglet "Scanning Control "
        - Dans "Scanner Options ", assure toi que la case devant lles lignes suivantes est cochée :

        Close browsers before scanning
        Scan for tracking cookies
        Terminate memory threats before quarantining
        - Laisse les autres lignes décochées.

        - Clique sur le bouton "Close" pour quitter l'écran du centre de contrôle.

        - Dans la fenêtre principale, clique, dans "Scan for Harmful Software", sur "Scan your computer".

        Dans la colonne de gauche, coche C:\Fixed Drive.

        Dans la colonne de droite, sous "Complete scan", clique sur "Perform Complete Scan"

        Clique sur "next" pour lancer le scan. Patiente pendant la durée du scan.

        A la fin du scan, une fenêtre de résultats s'ouvre . Clique sur OK.

        Assure toi que toutes les lignes de la fenêtre blanche sont cochées et clique sur "Next".

        Tout ce qui a été trouvé sera mis en quarantaine. S'il t'es demandé de redémarrer l'ordi ("reboot"), clique sur Yes.

        Pour recopier les informations sur le forum, fais ceci :

        - après le redémarrage de l'ordi, double-clique sur l'icône pour lancer SAS.
        - Clique sur "Preferences" puis sur l'onglet "Statistics/Logs ".
        - Dans "scanners logs", double-clique sur SUPERAntiSpyware Scan Log.

        - Le rapport va s'ouvrir dans ton éditeur de texte par défaut.

        - Copie son contenu dans ta réponse.

        Regarde bien le tuto SUPERAntiSpyware il est très bien expliqué.
        0
        1. Désolé pour le temps de réaction mais ça a mis du temps pour scanner et je suis en cours (donc je dois suivre un minimun) enfin bref voilà ce que j'ai eu.

          SUPERAntiSpyware Scan Log
          https://www.superantispyware.com/

          Generated 03/25/2009 at 12:15 PM

          Application Version : 4.25.1014

          Core Rules Database Version : 3784
          Trace Rules Database Version: 1741

          Scan type : Complete Scan
          Total Scan Time : 01:07:51

          Memory items scanned : 644
          Memory threats detected : 0
          Registry items scanned : 6694
          Registry threats detected : 1
          File items scanned : 43141
          File threats detected : 0

          Trojan.DNSChanger-Codec
          HKU\S-1-5-21-130983651-2345873076-838504687-1005\Software\fcn
          0
          1. Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

            Télécharges :
            Malwarebytes ou :
            Malwarebytes

            * Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

            (NB : S'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX

            * Potasses le Tuto pour te familiariser avec le prg :

            ( cela dis, il est très simple d'utilisation ).

            relance malwarebytes en suivant scrupuleusement ces consignes :

            ! Déconnecte toi et ferme toutes applications en cours !

            * Lance Malwarebyte's .

            Fais un examen dit "Complet" .

            --> Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
            --> à la fin tu cliques sur "résultat" .
            --> Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

            Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

            Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)

            0
            1. voici ce que j'ai obtenu,

              Malwarebytes' Anti-Malware 1.34
              Version de la base de données: 1896
              Windows 5.1.2600 Service Pack 3

              25/03/2009 16:43:23
              mbam-log-2009-03-25 (16-43-23).txt

              Type de recherche: Examen complet (C:\|D:\|I:\|)
              Eléments examinés: 157191
              Temps écoulé: 1 hour(s), 9 minute(s), 32 second(s)

              Processus mémoire infecté(s): 0
              Module(s) mémoire infecté(s): 0
              Clé(s) du Registre infectée(s): 1
              Valeur(s) du Registre infectée(s): 0
              Elément(s) de données du Registre infecté(s): 0
              Dossier(s) infecté(s): 0
              Fichier(s) infecté(s): 2

              Processus mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Module(s) mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Clé(s) du Registre infectée(s):
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\free-downloads.net toolbar (Adware.Trace) -> Quarantined and deleted successfully.

              Valeur(s) du Registre infectée(s):
              (Aucun élément nuisible détecté)

              Elément(s) de données du Registre infecté(s):
              (Aucun élément nuisible détecté)

              Dossier(s) infecté(s):
              (Aucun élément nuisible détecté)

              Fichier(s) infecté(s):
              C:\Program Files\free-downloads.net\free-downloads.netToolbarHelper.exe (Adware.Speedapps) -> Quarantined and deleted successfully.
              C:\Program Files\IsoBuster\IsoBusterToolbarHelper.exe (Adware.Speedapps) -> Quarantined and deleted successfully.
              0
              1. c'est grave docteur????
                0
                1. Ok merci gen-hackman, je pense qu'on en a fini, vu que tu ne répond pas c'est que ça doit être bon.
                  Merci pour ton aide, mon ordi continu a faire un peu de bruit mais ça c'est bien calmé.
                  0
                  1. salut non nous n'avaons pas fini mais vu que ca faisait 24 h non stop que j'etais là , je me suis permis de me reposer un peu bref :

                    Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

                    ! Déconnecte toi et ferme toutes tes applications en cours !

                    Double-clique sur " RSIT.exe " pour le lancer .

                    -> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

                    * Devant l'option "List files/folders created ..." , tu choisis : 2 months

                    * clique ensuite sur " Continue " pour lancer l'analyse ...

                    -> laisse faire le scan et ne touche pas au PC ...

                    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

                    Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

                    Important : poste un rapport, puis l'autre dans la réponse suivante
                    Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum

                    ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )
                    0
                    1. suivi du deuxième, info.txt
                      info.txt logfile of random's system information tool 1.05 2009-01-03 16:45:52

                      Uninstall list

                      -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
                      -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {075473F5-846A-448B-BCB3-104AA1760205}
                      -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {AB708C9B-97C8-4AC9-899B-DBF226AC9382}
                      -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {B12665F4-4E93-4AB4-B7FC-37053B524629}
                      -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{939F8208-C8CE-4AFF-B7BA-ACEB2E74A6CB}\Setup.exe"
                      -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
                      Adobe Acrobat Reader 3.01-->C:\WINDOWS\unin040c.exe -fC:\Acrobat3\Reader\DeIsL1.isu
                      Adobe Flash Player 9-->C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
                      Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
                      Adobe Reader 7.1.0 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A71000000002}
                      Amélioration de nos services-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{23012310-3E05-46A5-88A9-C6CBCABCAC79} /l1036
                      Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
                      Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
                      Assistant de connexion Windows Live-->MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
                      Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
                      BetClic Poker-->C:\PROGRA~1\BETCLI~1\UNWISE.EXE C:\PROGRA~1\BETCLI~1\INSTALL.LOG
                      Conexant HD Audio-->C:\Program Files\CONEXANT\CNXT_HDAUDIO\HXFSETUP.EXE -U -IAt8VEN5a.inf
                      Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
                      Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
                      DivX Content Uploader-->C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
                      DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
                      Gestionnaire Internet-->C:\PROGRA~1\Wanadoo\uninstall.exe
                      Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
                      HijackThis 2.0.2-->"C:\Documents and Settings\...\Bureau\HijackThis.exe" /uninstall
                      Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
                      HP Extended Capabilities 4.7-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
                      HP Help and Support-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}\setup.exe" -l0x40c -removeonly
                      HP Imaging Device Functions 6.0-->C:\Program Files\HP\Digital Imaging\DigitalImagingMonitor\hpzscr01.exe -datfile hpqbud01.dat
                      HP Photosmart Premier Software 6.0-->C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
                      HP PSC & OfficeJet 4.7-->"C:\Program Files\HP\Digital Imaging\{342C7C88-D335-4bc2-8CF1-281857629CE2}\setup\hpzscr01.exe" -datfile hposcr05.dat
                      HP Quick Launch Buttons 6.10 A2-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{34D2AB40-150D-475D-AE32-BD23FB5EE355}\setup.exe" -l0x40c -removeonly uninst
                      HP QuickPlay 2.3-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{45D707E9-F3C4-11D9-A373-0050BAE317E1}\setup.exe" -uninstall
                      HP Update-->MsiExec.exe /X{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}
                      HP User Guides 0032-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E276E05A-FFE8-485B-A005-42E76EA72AC4}\Setup.exe" -l0x40c -removeonly
                      HP Wireless Assistant 2.00 G2-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4302B2DD-D958-40E3-BAF3-B07FFE1978CE}\setup.exe" -l0x40c hpquninst
                      IsoBuster 2.4-->"C:\Program Files\Smart Projects\IsoBuster\Uninst\unins000.exe"
                      iTunes-->MsiExec.exe /I{553E56C3-7AA1-45FE-A2FC-2C43DC27F765}
                      J2SE Runtime Environment 5.0 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}
                      Java(TM) 6 Update 10-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216010FF}
                      Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
                      Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
                      Macromedia Flash Player 8-->MsiExec.exe /X{6815FCDD-401D-481E-BA88-31B4754C2B46}
                      Macromedia Shockwave Player-->MsiExec.exe /X{838A1BC9-95CA-4880-9BE3-2A7D23600A2B}
                      Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
                      Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
                      Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                      Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                      Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
                      Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
                      Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9111040C-6000-11D3-8CFE-0150048383C9}
                      Microsoft Silverlight-->MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
                      Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
                      Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
                      Microsoft Works-->MsiExec.exe /I{A059DE09-1B49-4450-B340-7AE097EC3F04}
                      Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Lecteur Windows Media 10 (KB911565)-->"C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Lecteur Windows Media 10 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Lecteur Windows Media 10 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB950759)-->"C:\WINDOWS\$NtUninstallKB950759$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB953838)-->"C:\WINDOWS\$NtUninstallKB953838$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB956390)-->"C:\WINDOWS\$NtUninstallKB956390$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB958215)-->"C:\WINDOWS\$NtUninstallKB958215$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB960714)-->"C:\WINDOWS\$NtUninstallKB960714$\spuninst\spuninst.exe"
                      Mise à jour pour Lecteur Windows Media 10 (KB910393)-->"C:\WINDOWS\$NtUninstallKB910393$\spuninst\spuninst.exe"
                      Mise à jour pour Lecteur Windows Media 10 (KB913800)-->"C:\WINDOWS\$NtUninstallKB913800$\spuninst\spuninst.exe"
                      Mise à jour pour Lecteur Windows Media 10 (KB926251)-->"C:\WINDOWS\$NtUninstallKB926251$\spuninst\spuninst.exe"
                      Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
                      Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
                      Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
                      Mozilla Firefox (3.0.5)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                      MP3 Player Utilities 4.05-->MsiExec.exe /I{8B9852AF-B0B0-47B7-9BC5-89A95D77B6C9}
                      MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
                      MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
                      MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                      MSXML4 Parser-->MsiExec.exe /I{01501EBA-EC35-4F9F-8889-3BE346E5DA13}
                      Navigateur Orange-->C:\PROGRA~1\Wanadoo\Shell.exe inst\uninst_FTBrowser.shl
                      Navilog1 3.7.1-->"C:\Program Files\Navilog1\unins000.exe"
                      NDAS Software 3.20.1523-->MsiExec.exe /I{07C16B8B-AE11-4515-888F-0BD2E0A9F2AD}
                      Neuf - Kit de connexion-->C:\Program Files\Neuf\Kit\uninstall.exe
                      NVIDIA Drivers-->C:\WINDOWS\system32\nvudisp.exe UninstallGUI
                      OpenOffice.org Installer 1.0-->MsiExec.exe /X{3A2AF807-9F9F-43C9-A24A-17B617238B74}
                      Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
                      Packard Bell Data Secure-->C:\APPS\DataSecure\Uninstall.exe
                      QuickTime-->MsiExec.exe /I{8DC42D05-680B-41B0-8878-6C14D24602DB}
                      Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                      Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                      Soft Data Fax Modem with SmartCP-->C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_14F1&DEV_5045_at8ven5m\HXFSETUP.EXE -U -IAt8VEN5m.inf
                      Sonic Audio Module-->MsiExec.exe /I{AB708C9B-97C8-4AC9-899B-DBF226AC9382}
                      Sonic Copy Module-->MsiExec.exe /I{B12665F4-4E93-4AB4-B7FC-37053B524629}
                      Sonic Data Module-->MsiExec.exe /I{075473F5-846A-448B-BCB3-104AA1760205}
                      Sonic Express Labeler-->MsiExec.exe /I{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
                      Sonic MyDVD Plus-->MsiExec.exe /I{21657574-BD54-48A2-9450-EB03B2C7FC29}
                      Sonic Update Manager-->MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
                      SonicAC3Encoder-->MsiExec.exe /I{52FBAE98-D389-4281-8C14-21B4046CCB4E}
                      SonicMPEGEncoder-->MsiExec.exe /I{B16AF568-A644-483C-A6DA-5028CD019C8C}
                      SopCast 3.0.1-->C:\Program Files\SopCast\uninst.exe
                      Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
                      TVAnts 1.0-->C:\PROGRA~1\TVAnts\UNWISE.EXE C:\PROGRA~1\TVAnts\INSTALL.LOG
                      UsbFix-->C:\Program Files\UsbFix\Uninstal.exe
                      VideoLAN VLC media player 0.8.6c-->C:\Program Files\VideoLAN\VLC\uninstall.exe
                      Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
                      Windows Live Mail-->MsiExec.exe /I{C514C594-23AA-4F13-A070-DB8BDB27594F}
                      Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
                      Windows Media Connect-->"C:\WINDOWS\$NtUninstallWMCSetup$\spuninst\spuninst.exe"
                      Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
                      Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
                      Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
                      Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
                      Windows XP Media Center Edition 2005 KB925766-->"C:\WINDOWS\$NtUninstallKB925766$\spuninst\spuninst.exe"
                      Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
                      ZoneAlarm Pro-->C:\Program Files\Zone Labs\ZoneAlarm\zauninst.exe

                      Security center information

                      AV: ZoneAlarm Security Suite Antivirus (disabled)
                      AV: Avira AntiVir PersonalEdition
                      AV: avast! antivirus 4.7.1029 [VPS 080103-0]
                      FW: ZoneAlarm Pro Firewall (disabled)

                      System event log

                      Computer Name: TOM
                      Event Code: 7035
                      Message: Un contrôle Démarrer a correctement été envoyé au service Pml Driver HPZ12.

                      Record Number: 20947
                      Source Name: Service Control Manager
                      Time Written: 20081227172924.000000+060
                      Event Type: Informations
                      User: TOM\...

                      Computer Name: TOM
                      Event Code: 7036
                      Message: Le service Pml Driver HPZ12 est entré dans l'état : en cours d'exécution.

                      Record Number: 20946
                      Source Name: Service Control Manager
                      Time Written: 20081227172924.000000+060
                      Event Type: Informations
                      User:

                      Computer Name: TOM
                      Event Code: 7036
                      Message: Le service Pml Driver HPZ12 est entré dans l'état : arrêté.

                      Record Number: 20945
                      Source Name: Service Control Manager
                      Time Written: 20081227172724.000000+060
                      Event Type: Informations
                      User:

                      Computer Name: TOM
                      Event Code: 7035
                      Message: Un contrôle Démarrer a correctement été envoyé au service Pml Driver HPZ12.

                      Record Number: 20944
                      Source Name: Service Control Manager
                      Time Written: 20081227172724.000000+060
                      Event Type: Informations
                      User: TOM\...

                      Computer Name: TOM
                      Event Code: 7036
                      Message: Le service Pml Driver HPZ12 est entré dans l'état : en cours d'exécution.

                      Record Number: 20943
                      Source Name: Service Control Manager
                      Time Written: 20081227172724.000000+060
                      Event Type: Informations
                      User:

                      Application event log

                      Computer Name: TOM
                      Event Code: 100
                      Message: wuauclt (2784) Le moteur de base de données 5.01.2600.2180 est démarré.

                      Record Number: 1685
                      Source Name: ESENT
                      Time Written: 20081227182025.000000+060
                      Event Type: Informations
                      User:

                      Computer Name: TOM
                      Event Code: 101
                      Message: wuauclt (3364) Le moteur de base de données est arrêté.

                      Record Number: 1684
                      Source Name: ESENT
                      Time Written: 20081227172911.000000+060
                      Event Type: Informations
                      User:

                      Computer Name: TOM
                      Event Code: 103
                      Message: wuaueng.dll (3364) SUS20ClientDataStore: Le moteur de base de données a arrêté une instance (0).

                      Record Number: 1683
                      Source Name: ESENT
                      Time Written: 20081227172911.000000+060
                      Event Type: Informations
                      User:

                      Computer Name: TOM
                      Event Code: 1000
                      Message: Les compteurs de performances pour le service WmiApRpl (WmiApRpl) ont été chargés.
                      Les données d'enregistrement contiennent les nouvelles valeurs d'index
                      assignées à ce service.

                      Record Number: 1682
                      Source Name: LoadPerf
                      Time Written: 20081227172740.000000+060
                      Event Type: Informations
                      User:

                      Computer Name: TOM
                      Event Code: 1001
                      Message: Les compteurs de performances pour le service WmiApRpl (WmiApRpl) ont été supprimés.
                      Les données d'enregistrement contiennent les nouvelles valeurs du dernier compteur système
                      et les dernières entrées du registre d'aide.

                      Record Number: 1681
                      Source Name: LoadPerf
                      Time Written: 20081227172740.000000+060
                      Event Type: Informations
                      User:

                      Environment variables

                      "ComSpec"=%SystemRoot%\system32\cmd.exe
                      "Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\QuickTime\QTSystem;C:\Program Files\Smart Projects\IsoBuster;C:\Program Files\QuickTime\QTSystem\
                      "windir"=%SystemRoot%
                      "FP_NO_HOST_CHECK"=NO
                      "OS"=Windows_NT
                      "PROCESSOR_ARCHITECTURE"=x86
                      "PROCESSOR_LEVEL"=15
                      "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 72 Stepping 2, AuthenticAMD
                      "PROCESSOR_REVISION"=4802
                      "NUMBER_OF_PROCESSORS"=2
                      "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
                      "TEMP"=%SystemRoot%\TEMP
                      "TMP"=%SystemRoot%\TEMP
                      "SonicCentral"=C:\Program Files\Fichiers communs\Sonic Shared\Sonic Central\
                      "PCTYPE"=PAVILION
                      "PLATFORM"=MCD
                      "tvdumpflags"=8
                      "CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip
                      "QTJAVA"=C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip

                      -----------------EOF-----------------
                      0
                      1. et bien !!!! ca c est du rapport lol

                        Ton lecteur H est ton lecteur cd si je ne m'abuse ?

                        désinstalle isobuster Toolbar

                        Mets Internet Explorer à Jour = Windows update

                        Clique sur le menu Demarrer /Panneau de configuration/Options des dossiers/ puis dans l'onglet Affichage
                        - Coche Afficher les fichiers et dossiers cachés
                        - Décoche Masquer les extensions des fichiers dont le type est connu
                        - Décoche Masquer les fichiers protégés du système d'exploitation (recommandé)
                        clique sur Appliquer, puis OK.

                        N'oublie pas de recacher à nouveau les fichiers cachés et protégés du système d'exploitation en fin de désinfection, c'est important

                        Fais analyser le(s) fichier(s) suivants sur Virustotal :

                        Virus Total

                        * Clique sur Parcourir en haut, choisis Poste de travail et cherche ce fichier :

                        C:\WINDOWS\system32\drivers\a83ojri9.sys

                        * Clique maintenant sur Envoyer le fichier. et laisse travailler tant que "Situation actuelle : en cours d'analyse" est affiché.
                        * Il est possible que le fichier soit mis en file d'attente en raison d'un grand nombre de demandes d'analyses. En ce cas, il te faudra patienter sans actualiser la page.
                        * Lorsque l'analyse est terminée ("Situation actuelle: terminé"), clique sur Formaté
                        * Une nouvelle fenêtre de ton navigateur va apparaître
                        * Clique alors sur les deux fleches
                        * Fais un clic droit sur la page, et choisis Sélectionner tout, puis copier
                        * Enfin colle le résultat dans ta prochaine réponse.

                        * Fais la même chose avec ces fichiers :

                        C:\WINDOWS\system32\drivers\aluoz3k0.sys

                        Note : Pour analyser un autre fichier, clique en bas sur Autre fichier.

                        ensuite :


                        ---> Désactive ton antivirus le temps de la manipulation car OTMoveIt3 est détecté comme une infection à tort.

                        ---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :

                        ---> Double-clique sur OTMoveIt3.exe afin de le lancer.

                        ---> Copie (Ctrl+C) le texte suivant ci-dessous :



                        :processes
                        explorer.exe

                        :reg
                        [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                        "nwiz"=-
                        "MsmqIntCert"=-
                        "HP Software Update"=-
                        "Cpqset"=-
                        "ISUSScheduler"=-
                        "iTunesHelper"=-
                        "QuickTime Task"=-
                        "Adobe Reader Speed Launcher"=-
                        "SunJavaUpdateSched"=-
                        [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
                        "fsm"=-
                        "MsnMsgr"=-
                        [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
                        [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e4d3dce2-faa2-11dd-a244-001b24bb41c2}]

                        :commands
                        [purity]
                        [emptytemp]
                        [start explorer]
                        [reboot]


                        ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

                        ---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

                        Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
                        Accepte en cliquant sur YES.

                        ---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
                        Le nom du rapport correspond au moment de sa création : date_heure.log

                        ensuite afin de fixer des lignes inutiles :

                        réouvre hijackthis
                        fais scan only
                        coches ces lignes sur leur gauche si presentes:

                        O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                        O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe (file missing)
                        O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe (file missing)
                        O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                        O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
                        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                        O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
                        O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
                        O2 - BHO: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfre0.dll
                        O3 - Toolbar: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfre0.dll
                        O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                        O2 - BHO: IsoBuster Toolbar - {266fcdca-7bb3-4da7-b3bf-f845dea2ebd6} - C:\Program Files\IsoBuster\tbIso1.dll
                        R3 - URLSearchHook: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfre0.dll
                        R3 - URLSearchHook: IsoBuster Toolbar - {266fcdca-7bb3-4da7-b3bf-f845dea2ebd6} - C:\Program Files\IsoBuster\tbIso1.dll

                        tu les coches et tu clic sur "fix checked"

                        et tu fermes le programme.

                        celles qui commencent par 04 - seront certainement pas toutes presentes c'est normal , je les y ai rajoutées par "securité".
                        0
                        1. j'ai mis a jour ie via windows update, en revanche ensuite je n'arrive pas à retrouver les fichiers suivants

                          C:\WINDOWS\system32\drivers\aluoz3k0.sys

                          C:\WINDOWS\system32\drivers\a83ojri9.sys
                          pour les faire analyser, j'ai pourtant bien coché la case afficher les fichiers cachés et décocher les deux autres (qui étaient déjà décochés)

                          qu'est ce que je fais, je continue la suite ou on essaie autrement?

                          Mon lecteur H est un lecteur virtuel qui me permet de lire des images .iso
                          mon lecteur est le E (Normalement)
                          0
                          1. Alors voilà le rapport,

                            ========== PROCESSES ==========
                            Process explorer.exe killed successfully.
                            ========== REGISTRY ==========
                            Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}\\ deleted successfully.
                            Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\nwiz deleted successfully.
                            Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\MsmqIntCert deleted successfully.
                            Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\HP Software Update deleted successfully.
                            Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Cpqset deleted successfully.
                            Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ISUSScheduler deleted successfully.
                            Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\iTunesHelper deleted successfully.
                            Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task deleted successfully.
                            Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe Reader Speed Launcher deleted successfully.
                            Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched deleted successfully.
                            Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\fsm deleted successfully.
                            Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\MsnMsgr deleted successfully.
                            Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}\\ deleted successfully.
                            Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e4d3dce2-faa2-11dd-a244-001b24bb41c2}\\ deleted successfully.
                            ========== COMMANDS ==========
                            File delete failed. C:\DOCUME~1\LETACO~1\LOCALS~1\Temp\etilqs_AHAtQ4cGw9NwxQ8IbpWj scheduled to be deleted on reboot.
                            File delete failed. C:\DOCUME~1\LETACO~1\LOCALS~1\Temp\hpodvd09.log scheduled to be deleted on reboot.
                            File delete failed. C:\DOCUME~1\LETACO~1\LOCALS~1\Temp\~DFCE91.tmp scheduled to be deleted on reboot.
                            User's Temp folder emptied.
                            User's Temporary Internet Files folder emptied.
                            User's Internet Explorer cache folder emptied.
                            Local Service Temp folder emptied.
                            File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
                            Local Service Temporary Internet Files folder emptied.
                            File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_13c.dat scheduled to be deleted on reboot.
                            File delete failed. C:\WINDOWS\temp\ZLT005ee.TMP scheduled to be deleted on reboot.
                            File delete failed. C:\WINDOWS\temp\ZLT02572.TMP scheduled to be deleted on reboot.
                            Windows Temp folder emptied.
                            Java cache emptied.
                            File delete failed. C:\Documents and Settings\...\Local Settings\Application Data\Mozilla\Firefox\Profiles\n0rg3p0h.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
                            File delete failed. C:\Documents and Settings\...\Local Settings\Application Data\Mozilla\Firefox\Profiles\n0rg3p0h.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
                            File delete failed. C:\Documents and Settings\...\Local Settings\Application Data\Mozilla\Firefox\Profiles\n0rg3p0h.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
                            File delete failed. C:\Documents and Settings\...\Local Settings\Application Data\Mozilla\Firefox\Profiles\n0rg3p0h.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
                            File delete failed. C:\Documents and Settings\...\Local Settings\Application Data\Mozilla\Firefox\Profiles\n0rg3p0h.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
                            FireFox cache emptied.
                            Temp folders emptied.
                            Explorer started successfully

                            OTMoveIt3 by OldTimer - Version 1.0.9.0 log created on 03262009_141543

                            Files moved on Reboot...
                            File C:\DOCUME~1\LETACO~1\LOCALS~1\Temp\etilqs_AHAtQ4cGw9NwxQ8IbpWj not found!
                            C:\DOCUME~1\LETACO~1\LOCALS~1\Temp\hpodvd09.log moved successfully.
                            File C:\DOCUME~1\LETACO~1\LOCALS~1\Temp\~DFCE91.tmp not found!
                            File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
                            File C:\WINDOWS\temp\Perflib_Perfdata_13c.dat not found!
                            C:\WINDOWS\temp\ZLT005ee.TMP moved successfully.
                            C:\WINDOWS\temp\ZLT02572.TMP moved successfully.
                            C:\Documents and Settings\...\Local Settings\Application Data\Mozilla\Firefox\Profiles\n0rg3p0h.default\Cache\_CACHE_001_ moved successfully.
                            C:\Documents and Settings\...\Local Settings\Application Data\Mozilla\Firefox\Profiles\n0rg3p0h.default\Cache\_CACHE_002_ moved successfully.
                            C:\Documents and Settings\...\Local Settings\Application Data\Mozilla\Firefox\Profiles\n0rg3p0h.default\Cache\_CACHE_003_ moved successfully.
                            C:\Documents and Settings\...\Local Settings\Application Data\Mozilla\Firefox\Profiles\n0rg3p0h.default\Cache\_CACHE_MAP_ moved successfully.
                            C:\Documents and Settings\...\Local Settings\Application Data\Mozilla\Firefox\Profiles\n0rg3p0h.default\urlclassifier3.sqlite moved successfully.
                            0
                            1. t'es tu occupé des lignes à fixer dans hijackthis par la suite ?

                              relances rsit stp et dis si des soucis persistent ou si changement il y a eu

                              0
                              1. voila le rapport info.txt

                                info.txt logfile of random's system information tool 1.05 2009-01-03 16:45:52

                                Uninstall list

                                -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
                                -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {075473F5-846A-448B-BCB3-104AA1760205}
                                -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {AB708C9B-97C8-4AC9-899B-DBF226AC9382}
                                -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {B12665F4-4E93-4AB4-B7FC-37053B524629}
                                -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{939F8208-C8CE-4AFF-B7BA-ACEB2E74A6CB}\Setup.exe"
                                -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
                                Adobe Acrobat Reader 3.01-->C:\WINDOWS\unin040c.exe -fC:\Acrobat3\Reader\DeIsL1.isu
                                Adobe Flash Player 9-->C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
                                Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
                                Adobe Reader 7.1.0 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A71000000002}
                                Amélioration de nos services-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{23012310-3E05-46A5-88A9-C6CBCABCAC79} /l1036
                                Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
                                Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
                                Assistant de connexion Windows Live-->MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
                                Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
                                BetClic Poker-->C:\PROGRA~1\BETCLI~1\UNWISE.EXE C:\PROGRA~1\BETCLI~1\INSTALL.LOG
                                Conexant HD Audio-->C:\Program Files\CONEXANT\CNXT_HDAUDIO\HXFSETUP.EXE -U -IAt8VEN5a.inf
                                Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
                                Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
                                DivX Content Uploader-->C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
                                DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
                                Gestionnaire Internet-->C:\PROGRA~1\Wanadoo\uninstall.exe
                                Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
                                HijackThis 2.0.2-->"C:\Documents and Settings\...\Bureau\HijackThis.exe" /uninstall
                                Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
                                HP Extended Capabilities 4.7-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
                                HP Help and Support-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}\setup.exe" -l0x40c -removeonly
                                HP Imaging Device Functions 6.0-->C:\Program Files\HP\Digital Imaging\DigitalImagingMonitor\hpzscr01.exe -datfile hpqbud01.dat
                                HP Photosmart Premier Software 6.0-->C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
                                HP PSC & OfficeJet 4.7-->"C:\Program Files\HP\Digital Imaging\{342C7C88-D335-4bc2-8CF1-281857629CE2}\setup\hpzscr01.exe" -datfile hposcr05.dat
                                HP Quick Launch Buttons 6.10 A2-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{34D2AB40-150D-475D-AE32-BD23FB5EE355}\setup.exe" -l0x40c -removeonly uninst
                                HP QuickPlay 2.3-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{45D707E9-F3C4-11D9-A373-0050BAE317E1}\setup.exe" -uninstall
                                HP Update-->MsiExec.exe /X{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}
                                HP User Guides 0032-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E276E05A-FFE8-485B-A005-42E76EA72AC4}\Setup.exe" -l0x40c -removeonly
                                HP Wireless Assistant 2.00 G2-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4302B2DD-D958-40E3-BAF3-B07FFE1978CE}\setup.exe" -l0x40c hpquninst
                                IsoBuster 2.4-->"C:\Program Files\Smart Projects\IsoBuster\Uninst\unins000.exe"
                                iTunes-->MsiExec.exe /I{553E56C3-7AA1-45FE-A2FC-2C43DC27F765}
                                J2SE Runtime Environment 5.0 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}
                                Java(TM) 6 Update 10-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216010FF}
                                Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
                                Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
                                Macromedia Flash Player 8-->MsiExec.exe /X{6815FCDD-401D-481E-BA88-31B4754C2B46}
                                Macromedia Shockwave Player-->MsiExec.exe /X{838A1BC9-95CA-4880-9BE3-2A7D23600A2B}
                                Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
                                Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
                                Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                                Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                                Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
                                Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
                                Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9111040C-6000-11D3-8CFE-0150048383C9}
                                Microsoft Silverlight-->MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
                                Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
                                Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
                                Microsoft Works-->MsiExec.exe /I{A059DE09-1B49-4450-B340-7AE097EC3F04}
                                Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Lecteur Windows Media 10 (KB911565)-->"C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Lecteur Windows Media 10 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Lecteur Windows Media 10 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB950759)-->"C:\WINDOWS\$NtUninstallKB950759$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB953838)-->"C:\WINDOWS\$NtUninstallKB953838$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB956390)-->"C:\WINDOWS\$NtUninstallKB956390$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB958215)-->"C:\WINDOWS\$NtUninstallKB958215$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
                                Mise à jour de sécurité pour Windows XP (KB960714)-->"C:\WINDOWS\$NtUninstallKB960714$\spuninst\spuninst.exe"
                                Mise à jour pour Lecteur Windows Media 10 (KB910393)-->"C:\WINDOWS\$NtUninstallKB910393$\spuninst\spuninst.exe"
                                Mise à jour pour Lecteur Windows Media 10 (KB913800)-->"C:\WINDOWS\$NtUninstallKB913800$\spuninst\spuninst.exe"
                                Mise à jour pour Lecteur Windows Media 10 (KB926251)-->"C:\WINDOWS\$NtUninstallKB926251$\spuninst\spuninst.exe"
                                Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
                                Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
                                Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
                                Mozilla Firefox (3.0.5)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                                MP3 Player Utilities 4.05-->MsiExec.exe /I{8B9852AF-B0B0-47B7-9BC5-89A95D77B6C9}
                                MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
                                MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
                                MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                                MSXML4 Parser-->MsiExec.exe /I{01501EBA-EC35-4F9F-8889-3BE346E5DA13}
                                Navigateur Orange-->C:\PROGRA~1\Wanadoo\Shell.exe inst\uninst_FTBrowser.shl
                                Navilog1 3.7.1-->"C:\Program Files\Navilog1\unins000.exe"
                                NDAS Software 3.20.1523-->MsiExec.exe /I{07C16B8B-AE11-4515-888F-0BD2E0A9F2AD}
                                Neuf - Kit de connexion-->C:\Program Files\Neuf\Kit\uninstall.exe
                                NVIDIA Drivers-->C:\WINDOWS\system32\nvudisp.exe UninstallGUI
                                OpenOffice.org Installer 1.0-->MsiExec.exe /X{3A2AF807-9F9F-43C9-A24A-17B617238B74}
                                Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
                                Packard Bell Data Secure-->C:\APPS\DataSecure\Uninstall.exe
                                QuickTime-->MsiExec.exe /I{8DC42D05-680B-41B0-8878-6C14D24602DB}
                                Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                                Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                                Soft Data Fax Modem with SmartCP-->C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_14F1&DEV_5045_at8ven5m\HXFSETUP.EXE -U -IAt8VEN5m.inf
                                Sonic Audio Module-->MsiExec.exe /I{AB708C9B-97C8-4AC9-899B-DBF226AC9382}
                                Sonic Copy Module-->MsiExec.exe /I{B12665F4-4E93-4AB4-B7FC-37053B524629}
                                Sonic Data Module-->MsiExec.exe /I{075473F5-846A-448B-BCB3-104AA1760205}
                                Sonic Express Labeler-->MsiExec.exe /I{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
                                Sonic MyDVD Plus-->MsiExec.exe /I{21657574-BD54-48A2-9450-EB03B2C7FC29}
                                Sonic Update Manager-->MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
                                SonicAC3Encoder-->MsiExec.exe /I{52FBAE98-D389-4281-8C14-21B4046CCB4E}
                                SonicMPEGEncoder-->MsiExec.exe /I{B16AF568-A644-483C-A6DA-5028CD019C8C}
                                SopCast 3.0.1-->C:\Program Files\SopCast\uninst.exe
                                Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
                                TVAnts 1.0-->C:\PROGRA~1\TVAnts\UNWISE.EXE C:\PROGRA~1\TVAnts\INSTALL.LOG
                                UsbFix-->C:\Program Files\UsbFix\Uninstal.exe
                                VideoLAN VLC media player 0.8.6c-->C:\Program Files\VideoLAN\VLC\uninstall.exe
                                Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
                                Windows Live Mail-->MsiExec.exe /I{C514C594-23AA-4F13-A070-DB8BDB27594F}
                                Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
                                Windows Media Connect-->"C:\WINDOWS\$NtUninstallWMCSetup$\spuninst\spuninst.exe"
                                Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
                                Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
                                Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
                                Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
                                Windows XP Media Center Edition 2005 KB925766-->"C:\WINDOWS\$NtUninstallKB925766$\spuninst\spuninst.exe"
                                Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
                                ZoneAlarm Pro-->C:\Program Files\Zone Labs\ZoneAlarm\zauninst.exe

                                Security center information

                                AV: ZoneAlarm Security Suite Antivirus (disabled)
                                AV: Avira AntiVir PersonalEdition
                                AV: avast! antivirus 4.7.1029 [VPS 080103-0]
                                FW: ZoneAlarm Pro Firewall (disabled)

                                System event log

                                Computer Name: TOM
                                Event Code: 7035
                                Message: Un contrôle Démarrer a correctement été envoyé au service Pml Driver HPZ12.

                                Record Number: 20947
                                Source Name: Service Control Manager
                                Time Written: 20081227172924.000000+060
                                Event Type: Informations
                                User: TOM\...

                                Computer Name: TOM
                                Event Code: 7036
                                Message: Le service Pml Driver HPZ12 est entré dans l'état : en cours d'exécution.

                                Record Number: 20946
                                Source Name: Service Control Manager
                                Time Written: 20081227172924.000000+060
                                Event Type: Informations
                                User:

                                Computer Name: TOM
                                Event Code: 7036
                                Message: Le service Pml Driver HPZ12 est entré dans l'état : arrêté.

                                Record Number: 20945
                                Source Name: Service Control Manager
                                Time Written: 20081227172724.000000+060
                                Event Type: Informations
                                User:

                                Computer Name: TOM
                                Event Code: 7035
                                Message: Un contrôle Démarrer a correctement été envoyé au service Pml Driver HPZ12.

                                Record Number: 20944
                                Source Name: Service Control Manager
                                Time Written: 20081227172724.000000+060
                                Event Type: Informations
                                User: TOM\...

                                Computer Name: TOM
                                Event Code: 7036
                                Message: Le service Pml Driver HPZ12 est entré dans l'état : en cours d'exécution.

                                Record Number: 20943
                                Source Name: Service Control Manager
                                Time Written: 20081227172724.000000+060
                                Event Type: Informations
                                User:

                                Application event log

                                Computer Name: TOM
                                Event Code: 100
                                Message: wuauclt (2784) Le moteur de base de données 5.01.2600.2180 est démarré.

                                Record Number: 1685
                                Source Name: ESENT
                                Time Written: 20081227182025.000000+060
                                Event Type: Informations
                                User:

                                Computer Name: TOM
                                Event Code: 101
                                Message: wuauclt (3364) Le moteur de base de données est arrêté.

                                Record Number: 1684
                                Source Name: ESENT
                                Time Written: 20081227172911.000000+060
                                Event Type: Informations
                                User:

                                Computer Name: TOM
                                Event Code: 103
                                Message: wuaueng.dll (3364) SUS20ClientDataStore: Le moteur de base de données a arrêté une instance (0).

                                Record Number: 1683
                                Source Name: ESENT
                                Time Written: 20081227172911.000000+060
                                Event Type: Informations
                                User:

                                Computer Name: TOM
                                Event Code: 1000
                                Message: Les compteurs de performances pour le service WmiApRpl (WmiApRpl) ont été chargés.
                                Les données d'enregistrement contiennent les nouvelles valeurs d'index
                                assignées à ce service.

                                Record Number: 1682
                                Source Name: LoadPerf
                                Time Written: 20081227172740.000000+060
                                Event Type: Informations
                                User:

                                Computer Name: TOM
                                Event Code: 1001
                                Message: Les compteurs de performances pour le service WmiApRpl (WmiApRpl) ont été supprimés.
                                Les données d'enregistrement contiennent les nouvelles valeurs du dernier compteur système
                                et les dernières entrées du registre d'aide.

                                Record Number: 1681
                                Source Name: LoadPerf
                                Time Written: 20081227172740.000000+060
                                Event Type: Informations
                                User:

                                Environment variables

                                "ComSpec"=%SystemRoot%\system32\cmd.exe
                                "Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\QuickTime\QTSystem;C:\Program Files\Smart Projects\IsoBuster;C:\Program Files\QuickTime\QTSystem\
                                "windir"=%SystemRoot%
                                "FP_NO_HOST_CHECK"=NO
                                "OS"=Windows_NT
                                "PROCESSOR_ARCHITECTURE"=x86
                                "PROCESSOR_LEVEL"=15
                                "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 72 Stepping 2, AuthenticAMD
                                "PROCESSOR_REVISION"=4802
                                "NUMBER_OF_PROCESSORS"=2
                                "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
                                "TEMP"=%SystemRoot%\TEMP
                                "TMP"=%SystemRoot%\TEMP
                                "SonicCentral"=C:\Program Files\Fichiers communs\Sonic Shared\Sonic Central\
                                "PCTYPE"=PAVILION
                                "PLATFORM"=MCD
                                "tvdumpflags"=8
                                "CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip
                                "QTJAVA"=C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip

                                -----------------EOF-----------------
                                0
                                1. ok oui pour ton UC attends d avoir moins de prog lancés mais 45 % est raisonnable en journee

                                  je pense qu'on peut nettoyer maintenant :

                                  Télécharge :ATF Cleaner par Atribune

                                  Double-clique ATF-Cleaner.exe afin de lancer le programme.
                                  Sous l'onglet Main, choisis : Select All
                                  Clique sur le bouton Empty Selected
                                  Si tu utilises le navigateur Firefox :
                                  Clique Firefox au haut et choisis : Select All
                                  Clique le bouton Empty Selected
                                  NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.
                                  Si tu utilises le navigateur Opera :
                                  Clique Opera au haut et choisis : Select All
                                  Clique le bouton Empty Selected
                                  NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.
                                  Clique Exit, du menu prinicipal, afin de fermer le programme.
                                  Pour obtenir du Support technique, double-clique l'adresse électronique située au bas de chacun des menus.

                                  __________________________________________________

                                  ---> Télécharge ToolCleaner2 sur ton Bureau.
                                  * Double-clique sur ToolsCleaner2.exe pour le lancer.
                                  * Clique sur Recherche et laisse le scan agir.
                                  * Clique sur Suppression pour finaliser.
                                  * Tu peux, si tu le souhaites, te servir des Options Facultatives.
                                  * Clique sur Quitter pour obtenir le rapport.
                                  * Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
                                  _________________________________________________

                                  supprime toolscleaner2 manuellement
                                  ________________________________________________

                                  ---> Télécharge et installe CCleaner (N'installe pas la Yahoo Toolbar) :

                                  * Lance-le. Va dans Options puis Avancé et décoche la case Effacer uniquement les fichiers etc....
                                  * Va dans Nettoyeur, choisis Analyse. Une fois terminé, lance le nettoyage.
                                  * Ensuite, choisis Registre, puis Chercher des erreurs. Une fois terminé, répare toutes les erreurs tant de fois qu il en trouve a l analyse(Sauvegarde la base de registre).
                                  * Veille a ce que dans les options le reglage soit au demarrage de windows et réglé sur "effacement securisé" 35 passes (guttman)
                                  __________________________________________________

                                  Attention : ne pas toucher au PC pendant qu'il travaille !

                                  B-Nettoyage et Défragmentation de tes Disques
                                  *Nettoyage :
                                  Clic droit sur "poste de travail" ==>"ouvrir" ==>clic droit sur le disque C ==>Propriétés ==>onglet "Général"
                                  Cliques sur le bouton "nettoyage de disque", OK
                                  tu le fais pour chacun de tes disques
                                  ________________________________________________

                                  *Vérifications des erreurs :
                                  Clic droit sur "poste de travail" ==>"ouvrir" ==>clic droit sur le disque C ==>Propriétés ==>onglet "Outil"
                                  "Vérifier maintenant", une boîte s'ouvre, cocher les cases :
                                  -réparer automatiquement les erreurs...
                                  -rechercher et tenter une récupération...
                                  --->Démarrer, ok
                                  Note : s'il te dis de redémarrer ton Pc pour le faire , tu redémarres et tu laisses faire, cela prend un peu de temps c'est normal
                                  tu le fais pour chacun de tes disques
                                  ________________________________________________

                                  ensuite toujours dans le même onglet tu choisis :
                                  *Défragmentation :
                                  "défragmenter maintenant", OK
                                  une boîte s'ouvre, tu sélectionnes le disque à défragmenter, et tu cliques sur "analyser", puis après l'analyse, "défragmenter" . OK
                                  tu le fais pour chacun de tes disques
                                  _______________________________________________

                                  Note : si tu as un utilitaire pour défragmenter , utilises le à la place

                                  pour ce faire Defraggler est proposé :
                                  _________________________________________________

                                  > Peux-tu vérifier Console Java ? :

                                  , et installer la nouvelle version si besoin est (dans ce cas désinstalle avant l'ancienne version).
                                  Pour info. ou en cas de problème :

                                  Tuto

                                  voici pour desinstaller :

                                  JavaRa

                                  Décompresse le fichier sur le Bureau (Clic droit > Extraire tout).
                                  * Double-clique sur le répertoire JavaRa.
                                  * Puis double-clique sur le fichier JavaRa.exe (le exe peut ne pas s'afficher).
                                  * Choisis Français puis clique sur Select.
                                  * Clique sur Recherche de mises à jour.
                                  * Sélectionne Mettre à jour via jucheck.exe puis clique sur Rechercher.
                                  * Autorise le processus à se connecter s'il le demande, clique sur Installer et suis les instructions d'installation qui prennent quelques minutes.
                                  * L'installation est terminée, reviens à l'écran de JavaRa et clique sur Effacer les anciennes versions.
                                  * Clique sur Oui pour confirmer. Laisse travailler et clique ensuite sur OK, puis une deuxième fois sur OK.
                                  * Un rapport va s'ouvrir. Poste-le dans ta prochaine réponse.
                                  * Ferme l'application.

                                  Note : le rapport se trouve aussi dans C:\ sous le nom JavaRa.log.

                                  _________________________________________________

                                  > Mets à jour Adobe Reader si ce n'est pas le cas (désinstalle avant la version antérieure)
                                  __________________________________________________

                                  > Tu peux aussi vider ta corbeille,quoi que Ccleaner le fasse tout seul
                                  _____________________________________________________

                                  > Si nous avons utilisé MalwaresByte's Anti-Malware : vide sa quarantaine.
                                  - Lance le programme puis clique sur <Quarantaine>.
                                  - Sélectionne tous les éléments puis clique sur <supprime>.
                                  - Quitte la programme.
                                  ______________________________________________________

                                  >si tu as installé Antivir :

                                  Configuration de Antivir (Merci a Nico):

                                  clic droit sur son icone dans la barre des taches et séléctionner Configurer Antivir.

                                  cocher la case : Mode Expert.

                                  => Cliquer sur Scanner dans le volet de gauche :

                                  > Dans "Fichiers" séléctionner Tous les fichiers.

                                  > Dans procédure de recherche, cocher Autoriser l'arrêt, et dans "priorité scanner" séléctionner Elevé.

                                  > Dans "Autres réglages" cocher toutes les cases.

                                  NE SURTOUT PAS OUBLIER LA RECHERCHE DES ROOTKIT QUI EST TRES IMPORTANTE !

                                  => Cliquer sur "Recherche" dans le volet de gauche et appliquer les mêmes paramètres que précédemment.

                                  => Dérouler "Recherche" en cliquant sur le +. Cliquer sur "Heuristique" :

                                  > Cocher "Heuristique de MacroVirus" et "Heuristique fichier Win32" avec degré d'indentification ELEVE !

                                  => Dans le volet de gauche, dérouler "Guard" puis dérouler "Recherche" :

                                  > Cocher "Heuristique de MacroVirus" et "Heuristique fichier Win32" avec degré d'identification ELEVE !
                                  ________________________________________________________

                                  > Idem pour ton antivirus : vide sa quarantaine si ce n'est pas déjà fait
                                  ______________________________________________________

                                  > Désactive et réactive la restauration de système, pour cela : suis les instructions du lien :

                                  Lien XP

                                  Lien Vista
                                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

                                  Quelques conseils et recommandations pour l'avenir :

                                  > Passe un coup de MalwareByte's Anti-Malware de temps en temps (1 fois par semaine , suivant l'utilisation que tu fais de ton PC.
                                  - Utilise aussi tes autres logiciels de protection (scannes antivirus, antispywares...). N'oublie pas de faire les mises à jour avant de les utiliser.
                                  - Pense aussi à faire une défragmentation de tes disques durs de temps en temps (garde suffisamment d'espace sur C:\ (1/3 de libre pour être à l'aise))
                                  _____________

                                  > Pour bien protéger ton PC :
                                  [1 seul Antivirus] + [1 seul Pare feu (/!\ les routeurs et box en possèdent un)] + [Un bon Antispyware avec immunisation] + [Mises à Jour récentes Windows et Logiciels de Protection] + [Utilisation de Firefox -ou autres- (Internet Explorer présente des failles de sécurité qui mettent longtemps avant d'être corrigées mais il faut absolument le conserver pour les mises à jour Windows et Windows live Messenger)]

                                  PS : En fait la meilleure des protections c'est toi même : ce que tu fais avec ton PC : où tu surfes, télécharges...ect....
                                  Les virus utilisent les failles de ton PC pour infecter un système

                                  dans le souhait de vouloir desinstaller un antivirus au profit d'un autre , voici quelques liens :

                                  Desinstaller Antivir
                                  Desinstaller Avast
                                  Desinstaller BitDefender
                                  Desinstaller Norton
                                  Desinstaller Kaspersky
                                  Desinstaller AVG

                                  ou tout en un :

                                  Désinstallation Antivirus , Parefeu , Antispyware
                                  _____________

                                  >lien utile

                                  >SpywareBlaster = petit logiciel qui bloque l'installation d'activeX nuisibles au PC.(Fonctionne en arrière plan)

                                  ____________

                                  Si tu as Vista n'oublie pas de réactiver le controle des comptes des utilisateurs(UAC)
                                  ___________

                                  Si tu as Spybot S&D et que nous avons desactive le "Tea-timer" tu peux le réactiver
                                  ____________

                                  Voila,
                                  Bonne lecture, à bientot,une fois tout ceci fait tu peux mettre le topic en resolu

                                  Gen-hackman

                                  0
                                  • 1
                                  • 2