Hacked by godzilla

Bonjour,
je viens de voir que ce truc est un"ver" que g depuis longtemps...je sais j'suis nul,j'aimerais le degager mais j'y connais vraiment rien,quelqu'un pour aider une novice?
merci par avance...
Configuration: Windows Vista Internet Explorer 7.0

26 réponses

Résumé de la discussion

Une personne utilisant Windows Vista et Internet Explorer 7 signale la présence d’un virus persistant et demande de l’aide pour s’en débarrasser dans un contexte où plusieurs outils et procédures sont proposés. Les réponses suggèrent d’utiliser des outils dédiés comme OTMoveIt3, de désactiver temporairement l’antivirus, puis de supprimer les éléments malveillants via des commandes et de consulter le rapport généré. D’autres conseils mentionnent USBFix, ToolsCleaner2 et des scans en ligne ou via HijackThis pour identifier les clés Run infectieuses et les fichiers persistants, avec des rapports à partager. En cas de doute, privilégier des antivirus gratuits et des outils reconnus et éviter les cracks, puis relancer un examen complet pour prévenir les infections futures.

Bobot (l’IA à votre service)
  1. Bon la ligne est toujours la,fais cette procedure

    ---> Désactive ton antivirus le temps de la manipulation car OTMoveIt3 est détecté comme une infection à tort.

    ---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :

    ---> Double-clique sur OTMoveIt3.exe afin de le lancer.

    ---> Copie (Ctrl+C) le texte suivant ci-dessous :

    :processes
    explorer.exe

    :files
    c:\recinfo\recinfo.exe

    :reg
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "recinfo253"=-

    :commands
    [purity]
    [emptytemp]
    [start explorer]
    [reboot]

    ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

    ---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

    Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
    Accepte en cliquant sur YES.

    ---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
    Le nom du rapport correspond au moment de sa création : date_heure.log
    1. comment je desactive l'anti virus?
  2. Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

    ! Déconnecte toi et ferme toutes tes applications en cours !

    Double-clique sur " RSIT.exe " pour le lancer .

    -> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

    * Devant l'option "List files/folders created ..." , tu choisis : 2 months

    * clique ensuite sur " Continue " pour lancer l'analyse ...

    -> laisse faire le scan et ne touche pas au PC ...

    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

    Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

    Important : poste un rapport, puis l'autre dans la réponse suivante
    Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum

    ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )
    1. voici les rapports...ca a ete laborieux!

      Logfile of random's system information tool 1.06 (written by random/random)
      Run by julien at 2009-05-06 00:12:08
      Microsoft® Windows Vista™ Édition Familiale Premium
      System drive C: has 49 GB (52%) free of 94 GB
      Total RAM: 2038 MB (57% free)

      HijackThis download failed

      ======Scheduled tasks folder======

      C:\Windows\tasks\Norton Internet Security - Analyse système complète - julien.job
      C:\Windows\tasks\User_Feed_Synchronization-{2FA3866A-D503-47BD-B94E-8769F528AF20}.job

      ======Registry dump======

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
      Aide pour le lien d'Adobe PDF Reader - c:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1E8A6170-7264-4D0F-BEAE-D42A53123C75}]
      c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll [2006-10-23 96984]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
      Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-10-22 320920]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
      Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
      Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-04-27 259696]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
      Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll [2009-04-17 668656]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
      Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll [2009-04-27 470512]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
      Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-10-22 34816]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
      {90222687-F593-4738-B738-FBEE9C7B26DF} - Show Norton Toolbar - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll [2006-10-23 565960]
      {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-04-27 259696]

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
      "Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2007-08-08 1006264]
      "IgfxTray"=C:\Windows\system32\igfxtray.exe [2007-04-04 138008]
      "HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2007-04-04 154392]
      "Persistence"=C:\Windows\system32\igfxpers.exe [2007-04-04 133912]
      "RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-03-14 4399104]
      "SMSERIAL"=C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe [2006-11-22 630784]
      "NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-02-26 153136]
      "ccApp"=c:\Program Files\Common Files\Symantec Shared\ccApp.exe [2006-10-25 107112]
      "osCheck"=c:\Program Files\Norton Internet Security\osCheck.exe [2006-10-27 22696]
      "recinfo253"=c:\RecInfo\RecInfo.exe [2007-06-06 2768896]
      "Symantec PIF AlertEng"=C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe [2008-01-29 583048]
      "SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-10-22 136600]

      [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
      "Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-10-21 1232896]
      "swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-02-11 39408]
      "MsnMsgr"=C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2007-10-18 5724184]
      "WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2006-11-02 201728]

      C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
      Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
      Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
      Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
      C:\Windows\system32\igfxdev.dll [2007-03-30 204800]

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
      "dontdisplaylastusername"=0
      "legalnoticecaption"=
      "legalnoticetext"=
      "shutdownwithoutlogon"=1
      "undockwithoutlogon"=1

      [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
      "NoDriveTypeAutoRun"=145

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0eaebf5d-1dbb-11de-a7df-00030d783bca}]
      shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe MS32DLL.dll.vbs

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{28b9531e-20c2-11dd-b6c6-00030d783bca}]
      shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe MS32DLL.dll.vbs

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{31e5ae9d-35b7-11de-8769-00030d783bca}]
      shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe MS32DLL.dll.vbs

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5e088f62-faa6-11dd-a4cb-00030d783bca}]
      shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe MS32DLL.dll.vbs

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c8298d2f-9963-11dd-8a8b-00030d783bca}]
      shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe MS32DLL.dll.vbs

      ======List of files/folders created in the last 2 months======

      2009-05-06 00:12:08 ----D---- C:\rsit
      2009-05-06 00:12:08 ----D---- C:\Program Files\trend micro
      2009-05-06 00:06:12 ----D---- C:\Users\julien\AppData\Roaming\Template
      2009-05-05 23:33:24 ----D---- C:\Program Files\CCleaner
      2009-04-17 13:24:51 ----A---- C:\Windows\system32\xolehlp.dll
      2009-04-17 13:24:51 ----A---- C:\Windows\system32\msdtcprx.dll
      2009-04-17 13:24:48 ----A---- C:\Windows\system32\winhttp.dll
      2009-04-15 20:08:33 ----A---- C:\Windows\system32\rpcss.dll
      2009-04-15 20:08:31 ----A---- C:\Windows\system32\ntoskrnl.exe
      2009-04-15 20:08:31 ----A---- C:\Windows\system32\ntkrnlpa.exe
      2009-04-15 20:08:30 ----A---- C:\Windows\system32\sdohlp.dll
      2009-04-15 20:08:30 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe
      2009-04-15 20:08:30 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll
      2009-04-15 20:08:30 ----A---- C:\Windows\system32\iasrecst.dll
      2009-04-15 20:08:30 ----A---- C:\Windows\system32\iasdatastore.dll
      2009-04-15 20:08:30 ----A---- C:\Windows\system32\iasads.dll
      2009-04-15 20:08:24 ----A---- C:\Windows\system32\lsasrv.dll
      2009-04-15 20:08:24 ----A---- C:\Windows\system32\kernel32.dll
      2009-04-15 20:08:23 ----A---- C:\Windows\system32\secur32.dll
      2009-04-15 20:08:23 ----A---- C:\Windows\system32\lsass.exe
      2009-04-15 20:08:23 ----A---- C:\Windows\system32\apilogen.dll
      2009-04-15 20:08:23 ----A---- C:\Windows\system32\amxread.dll
      2009-04-15 20:08:16 ----A---- C:\Windows\system32\mshtml.dll
      2009-04-15 20:08:15 ----A---- C:\Windows\system32\ieframe.dll
      2009-04-15 20:08:14 ----A---- C:\Windows\system32\urlmon.dll
      2009-04-15 20:08:14 ----A---- C:\Windows\system32\iertutil.dll
      2009-04-15 20:08:14 ----A---- C:\Windows\system32\iedkcs32.dll
      2009-04-15 20:08:14 ----A---- C:\Windows\system32\dxtmsft.dll
      2009-04-15 20:08:13 ----A---- C:\Windows\system32\wininet.dll
      2009-04-15 20:08:13 ----A---- C:\Windows\system32\occache.dll
      2009-04-15 20:08:13 ----A---- C:\Windows\system32\mshtmled.dll
      2009-04-15 20:08:13 ----A---- C:\Windows\system32\msfeeds.dll
      2009-04-15 20:08:13 ----A---- C:\Windows\system32\jsproxy.dll
      2009-04-15 20:08:13 ----A---- C:\Windows\system32\ieencode.dll
      2009-04-15 20:08:13 ----A---- C:\Windows\system32\ieaksie.dll
      2009-04-15 20:08:13 ----A---- C:\Windows\system32\dxtrans.dll
      2009-04-15 20:08:13 ----A---- C:\Windows\system32\admparse.dll
      2009-04-15 20:08:12 ----A---- C:\Windows\system32\pngfilt.dll
      2009-04-15 20:08:12 ----A---- C:\Windows\system32\mstime.dll
      2009-04-15 20:08:12 ----A---- C:\Windows\system32\mshtmler.dll
      2009-04-15 20:08:12 ----A---- C:\Windows\system32\ieUnatt.exe
      2009-04-15 20:08:12 ----A---- C:\Windows\system32\ieui.dll
      2009-04-15 20:08:12 ----A---- C:\Windows\system32\iesetup.dll
      2009-04-15 20:08:12 ----A---- C:\Windows\system32\iernonce.dll
      2009-04-15 20:08:12 ----A---- C:\Windows\system32\ieakui.dll
      2009-04-15 20:08:12 ----A---- C:\Windows\system32\ie4uinit.exe
      2009-04-15 20:08:12 ----A---- C:\Windows\system32\icardie.dll
      2009-04-15 20:08:12 ----A---- C:\Windows\system32\advpack.dll
      2009-04-15 20:08:11 ----A---- C:\Windows\system32\ieapfltr.dll
      2009-03-29 20:19:34 ----D---- C:\Users\julien\AppData\Roaming\dvdcss
      2009-03-20 22:02:03 ----D---- C:\Windows\Minidump
      2009-03-14 15:03:22 ----A---- C:\Windows\system32\infocardapi.dll
      2009-03-14 15:03:21 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
      2009-03-14 15:03:19 ----A---- C:\Windows\system32\icardagt.exe
      2009-03-14 15:03:18 ----A---- C:\Windows\system32\PresentationHostProxy.dll
      2009-03-14 15:03:18 ----A---- C:\Windows\system32\icardres.dll
      2009-03-14 15:03:16 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
      2009-03-14 15:03:13 ----A---- C:\Windows\system32\PresentationHost.exe
      2009-03-14 14:56:05 ----A---- C:\Windows\system32\dfshim.dll
      2009-03-14 14:56:01 ----A---- C:\Windows\system32\mscoree.dll
      2009-03-14 14:55:58 ----A---- C:\Windows\system32\netfxperf.dll
      2009-03-14 14:55:40 ----A---- C:\Windows\system32\mscorier.dll
      2009-03-14 14:55:33 ----A---- C:\Windows\system32\mscories.dll
      2009-03-11 17:00:14 ----A---- C:\Windows\system32\wmp.dll
      2009-03-11 17:00:12 ----A---- C:\Windows\system32\spwmp.dll
      2009-03-11 17:00:11 ----A---- C:\Windows\system32\wmploc.DLL
      2009-03-11 17:00:11 ----A---- C:\Windows\system32\dxmasf.dll
      2009-03-11 17:00:06 ----A---- C:\Windows\system32\schannel.dll

      ======List of files/folders modified in the last 2 months======

      2009-05-06 00:12:08 ----RD---- C:\Program Files
      2009-05-06 00:11:46 ----D---- C:\Windows\Temp
      2009-05-06 00:06:21 ----D---- C:\Windows\Prefetch
      2009-05-06 00:06:13 ----SD---- C:\Users\julien\AppData\Roaming\Microsoft
      2009-05-05 23:36:28 ----D---- C:\Windows\Debug
      2009-05-05 23:36:28 ----D---- C:\Windows
      2009-05-05 23:24:37 ----D---- C:\Windows\system32\Tasks
      2009-05-04 23:15:18 ----SHD---- C:\System Volume Information
      2009-05-04 18:16:19 ----SHD---- C:\Windows\Installer
      2009-05-04 12:46:19 ----D---- C:\Windows\System32
      2009-05-04 12:46:18 ----D---- C:\Windows\inf
      2009-05-04 12:46:18 ----A---- C:\Windows\system32\PerfStringBackup.INI
      2009-05-04 03:02:26 ----D---- C:\ProgramData\Microsoft Help
      2009-04-27 10:29:24 ----SD---- C:\Windows\Downloaded Program Files
      2009-04-21 22:18:36 ----D---- C:\Windows\system32\catroot2
      2009-04-21 20:47:26 ----D---- C:\Windows\winsxs
      2009-04-21 20:47:20 ----D---- C:\Windows\system32\catroot
      2009-04-20 05:51:24 ----D---- C:\Program Files\Windows Mail
      2009-04-20 05:51:23 ----D---- C:\Windows\system32\wbem
      2009-04-20 05:51:21 ----D---- C:\Windows\system32\manifeststore
      2009-04-20 05:51:20 ----D---- C:\Windows\AppPatch
      2009-04-20 05:51:19 ----D---- C:\Program Files\Internet Explorer
      2009-04-20 05:51:18 ----D---- C:\Windows\system32\migration
      2009-04-06 16:57:24 ----A---- C:\Windows\system32\mrt.exe
      2009-03-15 10:55:53 ----D---- C:\Windows\Microsoft.NET
      2009-03-15 10:55:44 ----RSD---- C:\Windows\assembly
      2009-03-14 15:22:46 ----D---- C:\Program Files\Windows Media Player
      2009-03-14 15:22:44 ----D---- C:\Windows\system32\fr-FR
      2009-03-14 15:22:35 ----D---- C:\Windows\system32\XPSViewer
      2009-03-14 15:22:35 ----D---- C:\Windows\system32\en-US
      2009-03-09 09:27:35 ----D---- C:\Program Files\Common Files\microsoft shared

      ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

      R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [2006-11-06 387432]
      R1 IDSvix86;Symantec Intrusion Prevention Driver; \??\C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20061025.029\IDSvix86.sys [2006-10-20 202872]
      R1 SPBBCDrv;SPBBCDrv; \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys [2006-10-06 406672]
      R1 SRTSPX;SRTSPX; C:\Windows\System32\Drivers\SRTSPX.SYS [2006-11-03 24184]
      R1 SYMTDI;SYMTDI; C:\Windows\System32\Drivers\SYMTDI.SYS [2006-10-24 185744]
      R3 CmBatt;Pilote pour Batterie à méthode de contrôle ACPI Microsoft; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-10-22 14208]
      R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-03-30 1671680]
      R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-03-14 1749152]
      R3 NAVENG;NAVENG; \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20061106.064\NAVENG.SYS [2006-11-06 79240]
      R3 NAVEX15;NAVEX15; \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20061106.064\NAVEX15.SYS [2006-11-06 831880]
      R3 NETw4v32;Pilote de carte Intel(R) Wireless WiFi Link pour Windows Vista 32 bits; C:\Windows\system32\DRIVERS\NETw4v32.sys [2007-02-25 2216448]
      R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2007-01-15 70144]
      R3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2006-11-22 982272]
      R3 SRTSP;SRTSP; C:\Windows\System32\Drivers\SRTSP.SYS [2006-11-03 245880]
      R3 SYMDNS;SYMDNS; C:\Windows\System32\Drivers\SYMDNS.SYS [2006-10-24 11792]
      R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT.SYS [2007-08-08 109744]
      R3 SYMFW;SYMFW; C:\Windows\System32\Drivers\SYMFW.SYS [2006-10-24 144784]
      R3 SYMIDS;SYMIDS; C:\Windows\System32\Drivers\SYMIDS.SYS [2006-10-24 38928]
      R3 SYMNDISV;SYMNDISV; C:\Windows\System32\Drivers\SYMNDISV.SYS [2006-10-24 37008]
      R3 SYMREDRV;SYMREDRV; C:\Windows\System32\Drivers\SYMREDRV.SYS [2006-10-24 26384]
      S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2006-11-02 5632]
      S3 HdAudAddService;Pilote de fonction UAA 1.1 Microsoft pour le service High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
      S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2006-11-02 8192]
      S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2006-11-02 5888]
      S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2006-11-02 5504]
      S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2006-11-02 6016]
      S3 NETw3v32;Pilote de carte Intel(R) PRO/Wireless 3945ABG pour Windows Vista 32 bits; C:\Windows\system32\DRIVERS\NETw3v32.sys [2006-11-02 1781760]
      S3 PCAMp50;PCAMp50 NDIS Protocol Driver; C:\Windows\System32\Drivers\PCAMp50.sys [2006-11-28 28224]
      S3 PCASp50;PCASp50 NDIS Protocol Driver; C:\Windows\System32\Drivers\PCASp50.sys [2006-11-28 27072]
      S3 SIS163u;SiS163 USB Wireless LAN Adapter Driver; C:\Windows\system32\DRIVERS\sis163u.sys [2007-01-25 218112]
      S3 SRTSPL;SRTSPL; C:\Windows\System32\Drivers\SRTSPL.SYS [2006-11-03 275576]
      S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2006-11-02 82560]
      S4 JRAID;JRAID; C:\Windows\system32\drivers\jraid.sys [2007-04-03 47872]
      S4 nvatabus;nvatabus; C:\Windows\system32\drivers\nvatabus.sys [2006-07-14 105088]
      S4 viamraid;viamraid; C:\Windows\system32\drivers\viamraid.sys [2006-03-31 100992]
      S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264]

      ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

      R2 ccEvtMgr;Symantec Event Manager; c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2006-10-25 107624]
      R2 ccSetMgr;Symantec Settings Manager; c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2006-10-25 107624]
      R2 CLTNetCnService;Symantec Lic NetConnect service; c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2006-10-25 107624]
      R2 LiveUpdate Notice Ex;LiveUpdate Notice Service Ex; c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2006-10-25 107624]
      R2 Planificateur LiveUpdate automatique;Planificateur LiveUpdate automatique; C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe [2007-09-26 554352]
      R2 SymAppCore;Symantec AppCore Service; c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe [2006-09-20 46736]
      R2 TestHandler;Fujitsu Siemens Computers Diagnostic Testhandler; C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe [2006-12-08 204800]
      R3 Symantec Core LC;Symantec Core LC; C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe [2007-08-08 1174152]
      S2 LiveUpdate Notice Service;LiveUpdate Notice Service; C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe [2008-01-29 583048]
      S3 comHost;COM Host; c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe [2006-10-13 49296]
      S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-04 182768]
      S3 ISPwdSvc;Validation de mot de passe Symantec IS; c:\Program Files\Norton Internet Security\isPwdSvc.exe [2006-10-27 80552]
      S3 LiveUpdate;LiveUpdate; C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE [2007-09-26 2999664]
      S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-02-26 267824]
      S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
      S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
      S3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
      S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]

      -----------------EOF-----------------
      1. et le deuxieme

        info.txt logfile of random's system information tool 1.06 2009-05-06 00:12:11

        ======Uninstall list======

        -->C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
        -->C:\Windows\UNNeroMediaHome.exe /UNINSTALL
        -->C:\Windows\UNNeroShowTime.exe /UNINSTALL
        -->C:\Windows\UNNeroVision.exe /UNINSTALL
        -->C:\Windows\UNRecode.exe /UNINSTALL
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {5A2F65A4-808F-4A1E-973E-92E17824982D}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {2AB528A5-BB1B-4EBE-8E51-AD0C4CD33CA9}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {B3F4DC34-7F60-4B7C-A79F-1C13012D99D4}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-00A1-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
        802.11 USB Wireless LAN Adapter-->C:\Windows\system32\unwlsdrv.exe SiS163u
        Activation Assistant for the 2007 Microsoft Office suites-->"C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
        Adobe Flash Player 9 ActiveX-->C:\Windows\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
        Adobe Photoshop 7.0-->C:\WINDOWS\ISUN040C.EXE -f"C:\Program Files\Adobe\Photoshop 7.0\Uninst.isu" -c"C:\Program Files\Adobe\Photoshop 7.0\Uninst.dll"
        Adobe Reader 8 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A80000000002}
        AppCore-->MsiExec.exe /I{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B}
        Assistant de connexion Windows Live-->MsiExec.exe /I{D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
        AV-->MsiExec.exe /I{F4DB525F-A986-4249-B98B-42A8066251CA}
        ccCommon-->MsiExec.exe /I{3CCAD2EF-CFF2-4637-82AA-AABF370282D3}
        CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
        Dongle Cameo-->C:\PROGRA~1\COMMON~1\France Telecom\DONGLE_CAMEO\0\uninstHardComponent.exe Uninstall.ini
        eMule-->"C:\Program Files\eMule\Uninstall.exe"
        FirstSteps Diagnostics-->MsiExec.exe /X{94D66D71-12F0-48A5-B46A-D4B835A0F1B7}
        Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
        Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_BDA1448D3D255554.exe" /uninstall
        Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
        Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
        Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
        Intel(R) Graphics Media Accelerator Driver-->C:\Windows\system32\igxpun.exe -uninstall
        Java(TM) 6 Update 10-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216010FF}
        LiveUpdate 3.2 (Symantec Corporation)-->"C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
        LiveUpdate Notice (Symantec Corporation)-->MsiExec.exe /X{DBA4DB9D-EE51-4944-A419-98AB1F1249C8}
        Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
        Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
        Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
        Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
        Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
        Microsoft Office Language Pack 2007 Service Pack 1 (SP1)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {EC50B538-CBE1-42E6-B7FE-87AA540AADFB}
        Microsoft Office OneNote MUI (French) 2007-->MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE}
        Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
        Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
        Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
        Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
        Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
        Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
        Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
        Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
        Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
        Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
        Microsoft Works-->MsiExec.exe /I{6B1CB38D-E2E4-4A30-933D-EFDEBA76AD9C}
        Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
        Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
        Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
        Motorola SM56 Data Fax Modem-->rundll32.exe sm56co6a.dll,SM56UnInstaller
        MSRedist-->MsiExec.exe /I{B7C61755-DB48-4003-948F-3D34DB8EAF69}
        MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
        MSXML 4.0 SP2 (KB941833)-->MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
        MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
        Nero 7 Essentials-->MsiExec.exe /X{81CD6232-10F5-4832-B3DA-1B88B1571036}
        Norton AntiVirus-->MsiExec.exe /X{830D8CBD-C668-49e2-A969-C2C2106332E0}
        Norton Confidential Browser Component-->MsiExec.exe /I{4843B611-8FCB-4428-8C23-31D0A5EAE164}
        Norton Confidential Web Protection Component-->MsiExec.exe /I{D353CC51-430D-4C6F-9B7E-52003DA1E05A}
        Norton Internet Security (Symantec Corporation)-->"C:\Program Files\Common Files\Symantec Shared\SymSetup\{5AA2CD16-706F-41f3-87C5-2B5A031F2B3B}_10_1_0_26\{5AA2CD16-706F-41f3-87C5-2B5A031F2B3B}.exe" /X
        Norton Internet Security-->MsiExec.exe /I{3672B097-EA69-4bfe-B92F-29AE6D9D2B34}
        Norton Internet Security-->MsiExec.exe /I{48185814-A224-447A-81DA-71BD20580E1B}
        Norton Internet Security-->MsiExec.exe /I{5AA2CD16-706F-41f3-87C5-2B5A031F2B3B}
        Norton Internet Security-->MsiExec.exe /I{E3EFA461-EB83-4C3B-9C47-2C1D58A01555}
        Norton Internet Security-->MsiExec.exe /I{E5EE9939-259F-4DE2-8023-5C49E16A4F43}
        Norton Protection Center-->MsiExec.exe /I{9A129ABC-A53A-4209-A21E-D5DEDFB7CCA8}
        Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
        Security Update for 2007 Microsoft Office System (KB951550)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {B243E9A5-ED77-4F1B-B338-2486FD82DC85}
        Security Update for 2007 Microsoft Office System (KB951944)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
        Security Update for 2007 Microsoft Office System (KB960003)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {F04F8702-18D0-458D-921E-146FB7CD38CF}
        Security Update for Microsoft Office Excel 2007 (KB959997)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {9EAC3AEC-5C81-4856-A05B-DE9DC236D740}
        Security Update for Microsoft Office OneNote 2007 (KB950130)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {F1B2401C-B610-4BF2-AA1C-52C55827A8F4}
        Security Update for Microsoft Office PowerPoint 2007 (KB951338)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {558B709B-821B-4FC5-90FC-9A8890641E77}
        Security Update for Microsoft Office system 2007 (KB954326)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F}
        Security Update for Microsoft Office system 2007 (KB956828)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {885E081B-72BD-4E76-8E98-30B4BE468FAC}
        Security Update for Microsoft Office Word 2007 (KB956358)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {4551666D-0FD6-4C69-8A81-1C6F2E64517C}
        SPBBC 32bit-->MsiExec.exe /I{77772678-817F-4401-9301-ED1D01A8DA56}
        Symantec Real Time Storage Protection Component-->MsiExec.exe /I{D6E6FA4A-5445-4850-8365-CF216C1CBB7A}
        SymNet-->MsiExec.exe /I{2DA85B02-13C0-4E6D-9A76-22E6B3DD0CB2}
        Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
        VLC media player 0.9.4-->C:\Program Files\VideoLAN\VLC\uninstall.exe
        Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
        Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}

        ======Security center information======

        AV: Norton Internet Security (outdated)
        FW: Norton Internet Security
        AS: Windows Defender (disabled) (outdated)
        AS: Norton Internet Security (outdated)

        ======System event log======

        Computer Name: PC-de-julien
        Event Code: 4
        Message: Le spouleur d’impression n’a pas pu rouvrir une connexion d’imprimante existante car il n’a pas pu lire les informations de configuration dans la clé de Registre S-1-5-18\Printers\Connections. Le spouleur d’impression n’a pas pu ouvrir la clé de Registre. Ceci peut se produire si la clé de Registre est endommagée ou absente, ou si le Registre est momentanément indisponible.
        Record Number: 68805
        Source Name: Microsoft-Windows-SpoolerWin32SPL
        Time Written: 20090505064032.000000-000
        Event Type: Avertissement
        User:

        Computer Name: PC-de-julien
        Event Code: 4
        Message: Le spouleur d’impression n’a pas pu rouvrir une connexion d’imprimante existante car il n’a pas pu lire les informations de configuration dans la clé de Registre S-1-5-18\Printers\Connections. Le spouleur d’impression n’a pas pu ouvrir la clé de Registre. Ceci peut se produire si la clé de Registre est endommagée ou absente, ou si le Registre est momentanément indisponible.
        Record Number: 68806
        Source Name: Microsoft-Windows-SpoolerWin32SPL
        Time Written: 20090505064032.000000-000
        Event Type: Avertissement
        User:

        Computer Name: PC-de-julien
        Event Code: 1003
        Message: Votre ordinateur n'a pas pu renouveler son adresse à partir du réseau (à partir du serveur DHCP) pour la carte réseau dont l'adresse réseau est 001B77BB5B7A. Il s'est produit l'erreur suivante :
        L'opération a été annulée par l'utilisateur.. Votre ordinateur va continuer à essayer d'obtenir sa propre adresse auprès du serveur d'adresse réseau (DHCP).
        Record Number: 68842
        Source Name: Microsoft-Windows-Dhcp-Client
        Time Written: 20090505114440.000000-000
        Event Type: Avertissement
        User:

        Computer Name: PC-de-julien
        Event Code: 6008
        Message: L'arrêt système précédant à 21:09:25 le 05/05/2009 n'était pas prévu.
        Record Number: 68969
        Source Name: EventLog
        Time Written: 20090505191044.000000-000
        Event Type: Erreur
        User:

        Computer Name: PC-de-julien
        Event Code: 1003
        Message: Votre ordinateur n'a pas pu renouveler son adresse à partir du réseau (à partir du serveur DHCP) pour la carte réseau dont l'adresse réseau est 001B77BB5B7A. Il s'est produit l'erreur suivante :
        L'opération a été annulée par l'utilisateur.. Votre ordinateur va continuer à essayer d'obtenir sa propre adresse auprès du serveur d'adresse réseau (DHCP).
        Record Number: 69097
        Source Name: Microsoft-Windows-Dhcp-Client
        Time Written: 20090505201911.000000-000
        Event Type: Avertissement
        User:

        =====Application event log=====

        Computer Name: PC-de-julien
        Event Code: 513
        Message: Les services de chiffrement ont échoué lors du traitement de l’appel OnIdentity() dans l’objet System Writer.

        Details:
        AddCoreCsiFiles : BeginFileEnumeration() failed.

        System Error:
        Accès refusé.
        .
        Record Number: 15054
        Source Name: Microsoft-Windows-CAPI2
        Time Written: 20090504010028.000000-000
        Event Type: Erreur
        User:

        Computer Name: PC-de-julien
        Event Code: 1530
        Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

        DÉTAIL -
        3 user registry handles leaked from \Registry\User\S-1-5-21-2967636040-3049119332-2149076952-1000:
        Process 5844 (\Device\HarddiskVolume2\Users\julien\AppData\Local\Temp\Low\Google Toolbar\gtbEEB9.tmp.exe) has opened key \REGISTRY\USER\S-1-5-21-2967636040-3049119332-2149076952-1000
        Process 5072 (\Device\HarddiskVolume2\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_BDA1448D3D255554.exe) has opened key \REGISTRY\USER\S-1-5-21-2967636040-3049119332-2149076952-1000
        Process 5072 (\Device\HarddiskVolume2\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_BDA1448D3D255554.exe) has opened key \REGISTRY\USER\S-1-5-21-2967636040-3049119332-2149076952-1000

        Record Number: 15125
        Source Name: Microsoft-Windows-User Profiles Service
        Time Written: 20090504161619.000000-000
        Event Type: Avertissement
        User: AUTORITE NT\SYSTEM

        Computer Name: PC-de-julien
        Event Code: 5007
        Message: Impossible d’analyser le fichier cible de la plateforme de signalement de problèmes Windows (fichier DLL contenant la liste des problèmes de l’ordinateur et nécessitant la collecte de données supplémentaires à des fins de diagnostic). Le code d’erreur était : 8014FFF9.
        Record Number: 15164
        Source Name: WerSvc
        Time Written: 20090504220913.000000-000
        Event Type: Erreur
        User:

        Computer Name: PC-de-julien
        Event Code: 5007
        Message: Impossible d’analyser le fichier cible de la plateforme de signalement de problèmes Windows (fichier DLL contenant la liste des problèmes de l’ordinateur et nécessitant la collecte de données supplémentaires à des fins de diagnostic). Le code d’erreur était : 8014FFF9.
        Record Number: 15217
        Source Name: WerSvc
        Time Written: 20090505075715.000000-000
        Event Type: Erreur
        User:

        Computer Name: PC-de-julien
        Event Code: 5007
        Message: Impossible d’analyser le fichier cible de la plateforme de signalement de problèmes Windows (fichier DLL contenant la liste des problèmes de l’ordinateur et nécessitant la collecte de données supplémentaires à des fins de diagnostic). Le code d’erreur était : 8014FFF9.
        Record Number: 15309
        Source Name: WerSvc
        Time Written: 20090505201912.000000-000
        Event Type: Erreur
        User:

        =====Security event log=====

        Computer Name: PC-de-julien
        Event Code: 4672
        Message: Privilèges spéciaux attribués à la nouvelle ouverture de session.

        Sujet :
        ID de sécurité : S-1-5-21-2967636040-3049119332-2149076952-1000
        Nom du compte : julien
        Domaine du compte : PC-de-julien
        ID d’ouverture de session : 0x6a0cf8

        Privilèges : SeSecurityPrivilege
        SeBackupPrivilege
        SeRestorePrivilege
        SeTakeOwnershipPrivilege
        SeDebugPrivilege
        SeSystemEnvironmentPrivilege
        SeLoadDriverPrivilege
        SeImpersonatePrivilege
        Record Number: 17216
        Source Name: Microsoft-Windows-Security-Auditing
        Time Written: 20090505201915.131600-000
        Event Type: Succès de l'audit
        User:

        Computer Name: PC-de-julien
        Event Code: 4634
        Message: Fermeture de session d’un compte.

        Sujet :
        ID de sécurité : S-1-5-21-2967636040-3049119332-2149076952-1000
        Nom du compte : julien
        Domaine du compte : PC-de-julien
        ID du compte : 0x6a0cf8

        Type d’ouverture de session : 7

        Cet événement est généré lorsqu’une session ouverte est supprimée. Il peut être associé à un événement d’ouverture de session en utilisant la valeur ID d’ouverture de session. Les ID d’ouverture de session ne sont uniques qu’entre les redémarrages sur un même ordinateur.
        Record Number: 17217
        Source Name: Microsoft-Windows-Security-Auditing
        Time Written: 20090505201915.131600-000
        Event Type: Succès de l'audit
        User:

        Computer Name: PC-de-julien
        Event Code: 4648
        Message: Tentative d’ouverture de session en utilisant des informations d’identification explicites.

        Sujet :
        ID de sécurité : S-1-5-18
        Nom du compte : PC-DE-JULIEN$
        Domaine du compte : WORKGROUP
        ID d’ouverture de session : 0x3e7
        GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

        Compte dont les informations d’identification ont été utilisées :
        Nom du compte : SYSTEM
        Domaine du compte : AUTORITE NT
        GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

        Serveur cible :
        Nom du serveur cible : localhost
        Informations supplémentaires : localhost

        Informations sur le processus :
        ID du processus : 0x280
        Nom du processus : C:\Windows\System32\services.exe

        Informations sur le réseau :
        Adresse du réseau : -
        Port : -

        Cet événement est généré lorsqu’un processus tente d’ouvrir une session pour un compte en spécifiant explicitement les informations d’identification de ce compte. Ceci se produit le plus souvent dans les configurations par lot comme les tâches planifiées, ou avec l’utilisation de la commande RUNAS.
        Record Number: 17218
        Source Name: Microsoft-Windows-Security-Auditing
        Time Written: 20090505201936.016600-000
        Event Type: Succès de l'audit
        User:

        Computer Name: PC-de-julien
        Event Code: 4624
        Message: L’ouverture de session d’un compte s’est correctement déroulée.

        Sujet :
        ID de sécurité : S-1-5-18
        Nom du compte : PC-DE-JULIEN$
        Domaine du compte : WORKGROUP
        ID d’ouverture de session : 0x3e7

        Type d’ouverture de session : 5

        Nouvelle ouverture de session :
        ID de sécurité : S-1-5-18
        Nom du compte : SYSTEM
        Domaine du compte : AUTORITE NT
        ID d’ouverture de session : 0x3e7
        GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

        Informations sur le processus :
        ID du processus : 0x280
        Nom du processus : C:\Windows\System32\services.exe

        Informations sur le réseau :
        Nom de la station de travail :
        Adresse du réseau source : -
        Port source : -

        Informations détaillées sur l’authentification :
        Processus d’ouverture de session : Advapi
        Package d’authentification : Negotiate
        Services en transit : -
        Nom du package (NTLM uniquement) : -
        Longueur de la clé : 0

        Cet événement est généré lors de la création d’une ouverture de session. Il est généré sur l’ordinateur sur lequel l’ouverture de session a été effectuée.

        Le champ Objet indique le compte sur le système local qui a demandé l’ouverture de session. Il s’agit le plus souvent d’un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

        Le champ Type d’ouverture de session indique le type d’ouverture de session qui s’est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

        Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s’est connecté.

        Les champs relatifs au réseau indiquent la provenance d’une demande d’ouverture de session à distance. Le nom de la station de travail n’étant pas toujours disponible, peut être laissé vide dans certains cas.

        Les champs relatifs aux informations d’authentification fournissent des détails sur cette demande d’ouverture de session spécifique.
        - Le GUID d’ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
        - Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d’ouverture de session.
        - Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
        - La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n’a été demandée.
        Record Number: 17219
        Source Name: Microsoft-Windows-Security-Auditing
        Time Written: 20090505201936.016600-000
        Event Type: Succès de l'audit
        User:

        Computer Name: PC-de-julien
        Event Code: 4672
        Message: Privilèges spéciaux attribués à la nouvelle ouverture de session.

        Sujet :
        ID de sécurité : S-1-5-18
        Nom du compte : SYSTEM
        Domaine du compte : AUTORITE NT
        ID d’ouverture de session : 0x3e7

        Privilèges : SeAssignPrimaryTokenPrivilege
        SeTcbPrivilege
        SeSecurityPrivilege
        SeTakeOwnershipPrivilege
        SeLoadDriverPrivilege
        SeBackupPrivilege
        SeRestorePrivilege
        SeDebugPrivilege
        SeAuditPrivilege
        SeSystemEnvironmentPrivilege
        SeImpersonatePrivilege
        Record Number: 17220
        Source Name: Microsoft-Windows-Security-Auditing
        Time Written: 20090505201936.016600-000
        Event Type: Succès de l'audit
        User:

        ======Environment variables======

        "ComSpec"=%SystemRoot%\system32\cmd.exe
        "FP_NO_HOST_CHECK"=NO
        "OS"=Windows_NT
        "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
        "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
        "PROCESSOR_ARCHITECTURE"=x86
        "TEMP"=%SystemRoot%\TEMP
        "TMP"=%SystemRoot%\TEMP
        "USERNAME"=SYSTEM
        "windir"=%SystemRoot%
        "PROCESSOR_LEVEL"=6
        "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
        "PROCESSOR_REVISION"=0f0d
        "NUMBER_OF_PROCESSORS"=2

        -----------------EOF-----------------
    2. Repostes un hijack this car il a planté sur le rsit

      HijackThis download failed

      Télécharges et installes le logiciel de diagnostic :

      ici Hijackthis
      ou ici Hijackthis
      ou ici Hijackthis

      ou renommé

      1- Cliques sur le setup pour lancer l'installe : laisses toi guider et ne modifies pas les paramètres d'installation .
      A la fin de l'installe , le prg ce lance automatiquement : fermes le en cliquant sur la croix rouge .
      Au final, tu dois avoir un raccourci sur ton bureau et aussi un cheminement comme :
      "C:\ program files\Trend Micro\HijackThis\HijackThis.exe " .

      tuto pour utilisation :(merci balltrap34)
      Regardes ici, c'est parfaitement expliqué en images ,

      ( Ne fixes encore AUCUNE ligne de ton plein gré, cela pourrait empêcher ton PC de fonctionner correctement )

      2- !! Déconnectes toi et fermes toute tes applications en cours !!

      Cliques sur le raccourci du bureau pour lancer le prg :
      fais un scan HijackThis en cliquant sur : "Do a system scan and save a logfile"

      --->copies-colles le rapport généré pour analyse
      1. Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 00:24:35, on 06/05/2009
        Platform: Windows Vista (WinNT 6.00.1904)
        MSIE: Internet Explorer v7.00 (7.00.6000.16830)
        Boot mode: Normal

        Running processes:
        C:\Windows\system32\Dwm.exe
        C:\Windows\Explorer.EXE
        C:\Windows\system32\taskeng.exe
        C:\Windows\System32\igfxtray.exe
        C:\Windows\System32\hkcmd.exe
        C:\Windows\System32\igfxpers.exe
        C:\Windows\RtHDVCpl.exe
        C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
        C:\Windows\system32\igfxsrvc.exe
        C:\Program Files\Common Files\Symantec Shared\ccApp.exe
        C:\Program Files\Java\jre6\bin\jusched.exe
        C:\Program Files\Windows Sidebar\sidebar.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\Windows Media Player\wmpnscfg.exe
        C:\Windows\system32\wbem\unsecapp.exe
        C:\Program Files\Internet Explorer\ieuser.exe
        C:\Windows\system32\conime.exe
        C:\Windows\system32\taskeng.exe
        c:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
        C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
        C:\Windows\system32\NOTEPAD.EXE
        C:\Windows\system32\NOTEPAD.EXE
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
        C:\Windows\system32\Macromed\Flash\FlashUtil9b.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
        C:\Windows\system32\SearchFilterHost.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Hacked by Godzilla
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
        R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll (file missing)
        O1 - Hosts: ::1 localhost
        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
        O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
        O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
        O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
        O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
        O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
        O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
        O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
        O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
        O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
        O4 - HKLM\..\Run: [osCheck] "c:\Program Files\Norton Internet Security\osCheck.exe"
        O4 - HKLM\..\Run: [recinfo253] c:\RecInfo\RecInfo.exe
        O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
        O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
        O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
        O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
        O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
        O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
        O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
        O13 - Gopher Prefix:
        O15 - Trusted Zone: http://*.mappy.com
        O15 - Trusted Zone: http://*.orange.fr
        O15 - Trusted Zone: http://rw.search.ke.voila.fr
        O15 - Trusted Zone: http://orange.weborama.fr
        O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
        O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://www.mypix.com/fr/fr/importer/ImageUploader4.cab
        O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
        O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
        O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
        O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
        O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
        O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: Validation de mot de passe Symantec IS (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
        O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
        O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
        O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
        O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
        O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
        O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
        O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
        O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Fujitsu Siemens Computers - C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe
    3. Bon plusieurs infections,on commence par l'infection des ports usb

      1/
      ####### | Install & recherche | #########

      Telecharge et install UsbFix de C_XX & Chiquitine29

      Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

      # Fais un clic droit sur le raccourci UsbFix présent sur ton bureau et choisi éxécuter en tant qu'administrateur .

      # Choisi l option 1 ( Recherche )

      # Laisse travailler l outil.

      # Ensuite post le rapport UsbFix.txt qui apparaitra.

      # Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

      ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

      # Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
      Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
      Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

      2/##### | Suppression | ######

      Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

      # Fais un clic droit sur le raccourci UsbFix présent sur ton bureau et choisi éxécuter en tant qu'administrateur .

      # choisi l option 2 ( Suppression )

      # Ton bureau disparaitra et le pc redémarrera .

      # Au redémarrage , UsbFix scannera ton pc , laisse travailler l outil.

      # Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .

      # Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

      ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

      ######### | Désinstallation | #########

      # Fais un clic droit sur le raccourci UsbFix présent sur ton bureau et choisi éxécuter en tant qu'administrateur .

      # Choisi l option 4 ( Désinstaller ) ....
      1. ############################## [ UsbFix V3.016 # Scan ]

        # User : julien (Administrateurs) # PC-DE-JULIEN
        # Update on 02/05/09 by Chiquitine29, C_XX & Chimay8
        # WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
        # Start at: 00:40:11 | 06/05/2009

        # Intel(R) Core(TM)2 Duo CPU T5250 @ 1.50GHz
        # Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6000 32-bit) #
        # Internet Explorer 7.0.6000.16830
        # Windows Firewall Status : Disabled
        # AV : Norton Internet Security 2007 [ Enabled | (!) Outdated ]
        # FW : Norton Internet Security[ Enabled ]2007

        # C:\ # Disque fixe local # 92,21 Go (47,59 Go free) [SYSTEM] # NTFS
        # D:\ # Disque fixe local # 45,12 Go (45,03 Go free) [DATA] # NTFS
        # E:\ # Disque CD-ROM
        # F:\ # Disque amovible # 7,45 Go (4,41 Go free) # FAT32

        ############################## [ Processus actifs ]

        C:\Windows\System32\smss.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\wininit.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\services.exe
        C:\Windows\system32\lsass.exe
        C:\Windows\system32\lsm.exe
        C:\Windows\system32\winlogon.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\SLsvc.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\svchost.exe
        c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
        c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
        C:\Windows\system32\Dwm.exe
        C:\Windows\Explorer.EXE
        C:\Windows\System32\spoolsv.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\taskeng.exe
        C:\Windows\System32\igfxtray.exe
        C:\Windows\System32\igfxpers.exe
        C:\Windows\RtHDVCpl.exe
        C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
        C:\Windows\system32\igfxsrvc.exe
        C:\Program Files\Common Files\Symantec Shared\ccApp.exe
        C:\Program Files\Java\jre6\bin\jusched.exe
        C:\Program Files\Windows Sidebar\sidebar.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\Windows Media Player\wmpnscfg.exe
        C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\SearchIndexer.exe
        C:\Windows\system32\taskeng.exe
        C:\Program Files\Windows Media Player\wmpnetwk.exe
        C:\Windows\system32\wbem\unsecapp.exe
        C:\Windows\system32\wbem\wmiprvse.exe
        C:\Program Files\Internet Explorer\ieuser.exe
        C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
        C:\Windows\system32\conime.exe
        C:\Windows\system32\taskeng.exe
        c:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
        C:\Windows\system32\Macromed\Flash\FlashUtil9b.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
        C:\Windows\explorer.exe
        C:\Windows\System32\mobsync.exe
        C:\Windows\system32\WUDFHost.exe
        C:\Windows\system32\wbem\wmiprvse.exe
        C:\Windows\system32\DllHost.exe

        ################## [ Registre # Startup ]

        HKCU_Main: "Local Page"="C:\\Windows\\system32\\blank.htm"
        HKCU_Main: "Search Page"="https://www.google.com/?gws_rd=ssl"
        HKCU_Main: "Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"
        HKCU_Main: "Window Title"="Hacked by Godzilla"
        HKLM_logon: "Userinit"="C:\\Windows\\system32\\userinit.exe,"
        HKLM_logon: "LegalNoticeCaption"=""
        HKLM_logon: "LegalNoticeText"=""
        HKLM_Run: Windows Defender=%ProgramFiles%\Windows Defender\MSASCui.exe -hide
        HKLM_Run: IgfxTray=C:\Windows\system32\igfxtray.exe
        HKLM_Run: HotKeysCmds=C:\Windows\system32\hkcmd.exe
        HKLM_Run: Persistence=C:\Windows\system32\igfxpers.exe
        HKLM_Run: RtHDVCpl=RtHDVCpl.exe
        HKLM_Run: SMSERIAL=C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
        HKLM_Run: NeroFilterCheck=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
        HKLM_Run: ccApp="c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
        HKLM_Run: osCheck="c:\Program Files\Norton Internet Security\osCheck.exe"
        HKLM_Run: recinfo253=c:\RecInfo\RecInfo.exe
        HKLM_Run: Symantec PIF AlertEng="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
        HKLM_Run: SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
        HKCU_Run: Sidebar=C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
        HKCU_Run: swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        HKCU_Run: MsnMsgr="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
        HKCU_Run: WMPNSCFG=C:\Program Files\Windows Media Player\WMPNSCFG.exe

        ################## [ Informations ]

        ################## [ Fichiers # Dossiers infectieux ]

        Found ! C:\RecInfo\RecInfo.exe
        Found ! D:\MS32DLL.dll.vbs
        Found ! D:\autorun.inf
        Found ! F:\MS32DLL.dll.vbs
        Found ! F:\autorun.inf

        ################## [ Registre # Clés Run infectieuses ]

        Found ! HKLM\software\microsoft\security center\\ "UacDisableNotify"
        # -> ( Value = 0x1 | Good = 0x0 Bad = 0x1 )

        ################## [ Registre # Mountpoints2 ]

        HKCU\Software\Microsoft\....\MountPoints2\{0eaebf5d-1dbb-11de-a7df-00030d783bca}\Shell\AutoRun\command
        HKCU\Software\Microsoft\....\MountPoints2\{28b9531e-20c2-11dd-b6c6-00030d783bca}\Shell\AutoRun\command
        HKCU\Software\Microsoft\....\MountPoints2\{31e5ae9d-35b7-11de-8769-00030d783bca}\Shell\AutoRun\command
        HKCU\Software\Microsoft\....\MountPoints2\{5e088f62-faa6-11dd-a4cb-00030d783bca}\Shell\AutoRun\command
        HKCU\Software\Microsoft\....\MountPoints2\{c8298d2f-9963-11dd-8a8b-00030d783bca}\Shell\AutoRun\command

        ################## [ ! Fin du rapport # UsbFix V3.016 ! ]
        1. Ok etape 2
          1. ############################## [ UsbFix V3.016 # Cleaning ]

            # User : julien (Administrateurs) # PC-DE-JULIEN
            # Update on 02/05/09 by Chiquitine29, C_XX & Chimay8
            # WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
            # Start at: 00:51:08 | 06/05/2009

            # Intel(R) Core(TM)2 Duo CPU T5250 @ 1.50GHz
            # Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6000 32-bit) #
            # Internet Explorer 7.0.6000.16830
            # Windows Firewall Status : Disabled
            # AV : Norton Internet Security 2007 [ Enabled | (!) Outdated ]
            # FW : Norton Internet Security[ Enabled ]2007

            # C:\ # Disque fixe local # 92,21 Go (47,63 Go free) [SYSTEM] # NTFS
            # D:\ # Disque fixe local # 45,12 Go (45,03 Go free) [DATA] # NTFS
            # E:\ # Disque CD-ROM
            # F:\ # Disque amovible # 7,45 Go (4,41 Go free) # FAT32

            ############################## [ Processus actifs ]

            C:\Windows\System32\smss.exe
            C:\Windows\system32\csrss.exe
            C:\Windows\system32\wininit.exe
            C:\Windows\system32\csrss.exe
            C:\Windows\system32\services.exe
            C:\Windows\system32\lsass.exe
            C:\Windows\system32\lsm.exe
            C:\Windows\system32\winlogon.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\SLsvc.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            C:\Windows\system32\Dwm.exe
            c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
            C:\Windows\Explorer.EXE
            C:\Windows\System32\spoolsv.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\taskeng.exe
            C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\SearchIndexer.exe
            C:\Windows\system32\WUDFHost.exe
            C:\Windows\system32\taskeng.exe
            C:\Windows\system32\runonce.exe
            C:\Windows\system32\conime.exe
            C:\Windows\system32\PresentationSettings.exe
            C:\Windows\system32\igfxsrvc.exe
            C:\Windows\system32\wbem\wmiprvse.exe

            ################## [ Fichiers # Dossiers infectieux ]

            Deleted ! F:\MS32DLL.dll.vbs
            Deleted ! F:\autorun.inf

            ################## [ Registre # Clés Run infectieuses ]

            ################## [ Registre # Mountpoints2 ]

            # -> Not Found !

            ################## [ Listing des fichiers présent ]

            [18/09/2006 23:43|--a------|24] - C:\autoexec.bat
            [02/11/2006 11:53|-rahs----|438840] - C:\bootmgr
            [08/08/2007 23:39|-ra-s----|8192] - C:\BOOTSECT.BAK
            [18/09/2006 23:43|--a------|10] - C:\config.sys
            [?|?|?] - C:\hiberfil.sys
            [?|?|?] - C:\pagefile.sys
            [08/08/2007 23:46|--a------|1277] - C:\Prodlog.txt
            [06/05/2009 00:52|--a------|2780] - C:\UsbFix.txt
            [22/04/2009 20:53|--a------|729954304] - F:\Vantage.Point.FRENCH.DVDRiP.XviD-LOST.avi
            [30/04/2009 14:02|--a------|368737274] - F:\Heroes.3x24.I.am.Sylar.VOstFR.HDTV.XviD-AlFleNi-TeaM-.avi
            [30/04/2009 03:59|--a------|362593718] - F:\Lost.5x13.Some.Like.It.Hoth.HDTV.XVID-AlFleNi-TeaM-[eMule-Box.com].avi
            [30/04/2009 17:13|--a------|362367074] - F:\Heroes.3x23.1961.VOstFR.HDTV.XviD-AlFleNi-TeaM-[eMule-Box.com].avi
            [30/04/2009 04:21|--a------|359282632] - F:\Heroes.3x25.An.Invisible.Thread.VOstFR.HDTV.XviD-AlFleNi-TeaM-[eMule-Box.com].avi
            [01/05/2009 01:37|--a------|368624150] - F:\Heroes.3x22.Turn.and.Face.the.Stranger.VOstFR.REPACK.HDTV.XviD-AlFleNi-TeaM--[eMule-Box.com].avi
            [01/05/2009 01:38|--a------|362581958] - F:\Lost.5x12.Dead.is.Dead.VOstFR.HDTV.XVID-AlFleNi-TeaM-[eMule-Box.com].avi
            [04/05/2009 12:44|--a------|1757184] - F:\URGENT_RECHERCHE_MAYA.doc

            ################## [ Vaccination ]

            # C:\autorun.inf -> Folder created by UsbFix.
            # D:\autorun.inf -> Folder created by UsbFix.
            # F:\autorun.inf -> Folder created by UsbFix.

            ################## [ Cracks / Keygens / Serials ]

            C:\ProgramData\Symantec\LiveUpdate\Downloads\1209776195jtun_hbpatch07.x00.full.zip

            ################## [ ! Fin du rapport # UsbFix V3.016 ! ]
          2. je suis vraiment lente hein! je sais je m'en excuse...merci de m'accorder ton temps.
        2. Prends pas un crack pour norton,il en faut pas la peine,tu as de tres bon antivirus gratuit type antivr largement meilleur que norton.

          Peux tu relancer un hijack this car l'infection ci dessous trouvé sur le 1er rapport n'a pas ete supprimé a priori

          Found ! C:\RecInfo\RecInfo.exe
          1. ############################## [ UsbFix V3.016 # Cleaning ]

            # User : julien (Administrateurs) # PC-DE-JULIEN
            # Update on 02/05/09 by Chiquitine29, C_XX & Chimay8
            # WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
            # Start at: 00:51:08 | 06/05/2009

            # Intel(R) Core(TM)2 Duo CPU T5250 @ 1.50GHz
            # Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6000 32-bit) #
            # Internet Explorer 7.0.6000.16830
            # Windows Firewall Status : Disabled
            # AV : Norton Internet Security 2007 [ Enabled | (!) Outdated ]
            # FW : Norton Internet Security[ Enabled ]2007

            # C:\ # Disque fixe local # 92,21 Go (47,63 Go free) [SYSTEM] # NTFS
            # D:\ # Disque fixe local # 45,12 Go (45,03 Go free) [DATA] # NTFS
            # E:\ # Disque CD-ROM
            # F:\ # Disque amovible # 7,45 Go (4,41 Go free) # FAT32

            ############################## [ Processus actifs ]

            C:\Windows\System32\smss.exe
            C:\Windows\system32\csrss.exe
            C:\Windows\system32\wininit.exe
            C:\Windows\system32\csrss.exe
            C:\Windows\system32\services.exe
            C:\Windows\system32\lsass.exe
            C:\Windows\system32\lsm.exe
            C:\Windows\system32\winlogon.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\SLsvc.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            C:\Windows\system32\Dwm.exe
            c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
            C:\Windows\Explorer.EXE
            C:\Windows\System32\spoolsv.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\taskeng.exe
            C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\SearchIndexer.exe
            C:\Windows\system32\WUDFHost.exe
            C:\Windows\system32\taskeng.exe
            C:\Windows\system32\runonce.exe
            C:\Windows\system32\conime.exe
            C:\Windows\system32\PresentationSettings.exe
            C:\Windows\system32\igfxsrvc.exe
            C:\Windows\system32\wbem\wmiprvse.exe

            ################## [ Fichiers # Dossiers infectieux ]

            Deleted ! F:\MS32DLL.dll.vbs
            Deleted ! F:\autorun.inf

            ################## [ Registre # Clés Run infectieuses ]

            ################## [ Registre # Mountpoints2 ]

            # -> Not Found !

            ################## [ Listing des fichiers présent ]

            [18/09/2006 23:43|--a------|24] - C:\autoexec.bat
            [02/11/2006 11:53|-rahs----|438840] - C:\bootmgr
            [08/08/2007 23:39|-ra-s----|8192] - C:\BOOTSECT.BAK
            [18/09/2006 23:43|--a------|10] - C:\config.sys
            [?|?|?] - C:\hiberfil.sys
            [?|?|?] - C:\pagefile.sys
            [08/08/2007 23:46|--a------|1277] - C:\Prodlog.txt
            [06/05/2009 00:52|--a------|2780] - C:\UsbFix.txt
            [22/04/2009 20:53|--a------|729954304] - F:\Vantage.Point.FRENCH.DVDRiP.XviD-LOST.avi
            [30/04/2009 14:02|--a------|368737274] - F:\Heroes.3x24.I.am.Sylar.VOstFR.HDTV.XviD-AlFleNi-TeaM-.avi
            [30/04/2009 03:59|--a------|362593718] - F:\Lost.5x13.Some.Like.It.Hoth.HDTV.XVID-AlFleNi-TeaM-[eMule-Box.com].avi
            [30/04/2009 17:13|--a------|362367074] - F:\Heroes.3x23.1961.VOstFR.HDTV.XviD-AlFleNi-TeaM-[eMule-Box.com].avi
            [30/04/2009 04:21|--a------|359282632] - F:\Heroes.3x25.An.Invisible.Thread.VOstFR.HDTV.XviD-AlFleNi-TeaM-[eMule-Box.com].avi
            [01/05/2009 01:37|--a------|368624150] - F:\Heroes.3x22.Turn.and.Face.the.Stranger.VOstFR.REPACK.HDTV.XviD-AlFleNi-TeaM--[eMule-Box.com].avi
            [01/05/2009 01:38|--a------|362581958] - F:\Lost.5x12.Dead.is.Dead.VOstFR.HDTV.XVID-AlFleNi-TeaM-[eMule-Box.com].avi
            [04/05/2009 12:44|--a------|1757184] - F:\URGENT_RECHERCHE_MAYA.doc

            ################## [ Vaccination ]

            # C:\autorun.inf -> Folder created by UsbFix.
            # D:\autorun.inf -> Folder created by UsbFix.
            # F:\autorun.inf -> Folder created by UsbFix.

            ################## [ Cracks / Keygens / Serials ]

            C:\ProgramData\Symantec\LiveUpdate\Downloads\1209776195jtun_hbpatch07.x00.full.zip

            ################## [ ! Fin du rapport # UsbFix V3.016 ! ]
          2. ############################## [ UsbFix V3.016 # Cleaning ]

            # User : julien (Administrateurs) # PC-DE-JULIEN
            # Update on 02/05/09 by Chiquitine29, C_XX & Chimay8
            # WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
            # Start at: 00:51:08 | 06/05/2009

            # Intel(R) Core(TM)2 Duo CPU T5250 @ 1.50GHz
            # Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6000 32-bit) #
            # Internet Explorer 7.0.6000.16830
            # Windows Firewall Status : Disabled
            # AV : Norton Internet Security 2007 [ Enabled | (!) Outdated ]
            # FW : Norton Internet Security[ Enabled ]2007

            # C:\ # Disque fixe local # 92,21 Go (47,63 Go free) [SYSTEM] # NTFS
            # D:\ # Disque fixe local # 45,12 Go (45,03 Go free) [DATA] # NTFS
            # E:\ # Disque CD-ROM
            # F:\ # Disque amovible # 7,45 Go (4,41 Go free) # FAT32

            ############################## [ Processus actifs ]

            C:\Windows\System32\smss.exe
            C:\Windows\system32\csrss.exe
            C:\Windows\system32\wininit.exe
            C:\Windows\system32\csrss.exe
            C:\Windows\system32\services.exe
            C:\Windows\system32\lsass.exe
            C:\Windows\system32\lsm.exe
            C:\Windows\system32\winlogon.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\SLsvc.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            C:\Windows\system32\Dwm.exe
            c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
            C:\Windows\Explorer.EXE
            C:\Windows\System32\spoolsv.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\taskeng.exe
            C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\SearchIndexer.exe
            C:\Windows\system32\WUDFHost.exe
            C:\Windows\system32\taskeng.exe
            C:\Windows\system32\runonce.exe
            C:\Windows\system32\conime.exe
            C:\Windows\system32\PresentationSettings.exe
            C:\Windows\system32\igfxsrvc.exe
            C:\Windows\system32\wbem\wmiprvse.exe

            ################## [ Fichiers # Dossiers infectieux ]

            Deleted ! F:\MS32DLL.dll.vbs
            Deleted ! F:\autorun.inf

            ################## [ Registre # Clés Run infectieuses ]

            ################## [ Registre # Mountpoints2 ]

            # -> Not Found !

            ################## [ Listing des fichiers présent ]

            [18/09/2006 23:43|--a------|24] - C:\autoexec.bat
            [02/11/2006 11:53|-rahs----|438840] - C:\bootmgr
            [08/08/2007 23:39|-ra-s----|8192] - C:\BOOTSECT.BAK
            [18/09/2006 23:43|--a------|10] - C:\config.sys
            [?|?|?] - C:\hiberfil.sys
            [?|?|?] - C:\pagefile.sys
            [08/08/2007 23:46|--a------|1277] - C:\Prodlog.txt
            [06/05/2009 00:52|--a------|2780] - C:\UsbFix.txt
            [22/04/2009 20:53|--a------|729954304] - F:\Vantage.Point.FRENCH.DVDRiP.XviD-LOST.avi
            [30/04/2009 14:02|--a------|368737274] - F:\Heroes.3x24.I.am.Sylar.VOstFR.HDTV.XviD-AlFleNi-TeaM-.avi
            [30/04/2009 03:59|--a------|362593718] - F:\Lost.5x13.Some.Like.It.Hoth.HDTV.XVID-AlFleNi-TeaM-[eMule-Box.com].avi
            [30/04/2009 17:13|--a------|362367074] - F:\Heroes.3x23.1961.VOstFR.HDTV.XviD-AlFleNi-TeaM-[eMule-Box.com].avi
            [30/04/2009 04:21|--a------|359282632] - F:\Heroes.3x25.An.Invisible.Thread.VOstFR.HDTV.XviD-AlFleNi-TeaM-[eMule-Box.com].avi
            [01/05/2009 01:37|--a------|368624150] - F:\Heroes.3x22.Turn.and.Face.the.Stranger.VOstFR.REPACK.HDTV.XviD-AlFleNi-TeaM--[eMule-Box.com].avi
            [01/05/2009 01:38|--a------|362581958] - F:\Lost.5x12.Dead.is.Dead.VOstFR.HDTV.XVID-AlFleNi-TeaM-[eMule-Box.com].avi
            [04/05/2009 12:44|--a------|1757184] - F:\URGENT_RECHERCHE_MAYA.doc

            ################## [ Vaccination ]

            # C:\autorun.inf -> Folder created by UsbFix.
            # D:\autorun.inf -> Folder created by UsbFix.
            # F:\autorun.inf -> Folder created by UsbFix.

            ################## [ Cracks / Keygens / Serials ]

            C:\ProgramData\Symantec\LiveUpdate\Downloads\1209776195jtun_hbpatch07.x00.full.zip

            ################## [ ! Fin du rapport # UsbFix V3.016 ! ]
          3. Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 01:01:39, on 06/05/2009
            Platform: Windows Vista (WinNT 6.00.1904)
            MSIE: Internet Explorer v7.00 (7.00.6000.16830)
            Boot mode: Normal

            Running processes:
            C:\Windows\system32\Dwm.exe
            C:\Windows\system32\taskeng.exe
            C:\Windows\system32\conime.exe
            C:\Windows\explorer.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Windows\system32\wbem\unsecapp.exe
            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Windows Live\Messenger\msnmsgr.exe
            C:\Program Files\trend micro\HijackThis\HijackThis.exe

            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
            R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll (file missing)
            O1 - Hosts: ::1 localhost
            O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
            O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
            O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
            O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
            O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
            O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
            O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
            O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
            O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
            O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
            O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
            O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
            O4 - HKLM\..\Run: [osCheck] "c:\Program Files\Norton Internet Security\osCheck.exe"
            O4 - HKLM\..\Run: [recinfo253] c:\RecInfo\RecInfo.exe
            O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
            O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
            O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
            O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
            O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
            O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
            O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
            O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
            O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
            O13 - Gopher Prefix:
            O15 - Trusted Zone: http://*.mappy.com
            O15 - Trusted Zone: http://*.orange.fr
            O15 - Trusted Zone: http://rw.search.ke.voila.fr
            O15 - Trusted Zone: http://orange.weborama.fr
            O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
            O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://www.mypix.com/fr/fr/importer/ImageUploader4.cab
            O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
            O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
            O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: Validation de mot de passe Symantec IS (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
            O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
            O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
            O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
            O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
            O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
            O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
            O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Fujitsu Siemens Computers - C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe
        3. Je t'ai demandé de relancer un hijack this pas un usbfix.Regardes le post 4
          1. Tu desactives le scan ou protection resident le temps de la procedure,tu as deux antivirus a priori Avast et norton,tu utilises lequel?Faudra desinstaller l'autre
            1. là je bloque, je savais pas que j'avais avast et g norton qui a expiré, en gros je sais pas quoi te repondre,je suis pas protégée alors!
              (qu'est ce que je me sens nulle)
              1. Desactives l'antivirus perimmé et fais la procedure ,esnuite onsupprimera avst et norton et on mettra un bon antivirus gratuit
                1. ========== PROCESSES ==========
                  Process explorer.exe killed successfully.
                  ========== FILES ==========
                  File/Folder c:\recinfo\recinfo.exe not found.
                  ========== REGISTRY ==========
                  Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\recinfo253 not found.
                  ========== COMMANDS ==========
                  User's Temp folder emptied.
                  User's Internet Explorer cache folder emptied.
                  Windows Temp folder emptied.
                  Temp folders emptied.
                  Explorer started successfully

                  OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 05062009_014201
              2. 1/Télécharge TOOLBAR S&D( de Eric_71/Team IDN ) sur ton bureau :

                ( Tuto : https://sites.google.com/site/toolbarsd/aideenimages )

                !! Déconnecte toi et ferme toutes tes applications en cours le temps de la manipe !!

                * Double-clique sur ToolBar SD.exe pour lancer l'outil et laisse toi guider ...
                --> Tapes ( option " recherche " ) puis tape sur [Entrée].

                Un rapport sera généré à la fin du processus : poste son contenu dans ta prochaine réponse

                ( le rapport est en outre sauvegardé ici -> C:\TB.txt )

                2/
                Relance Toolbar-S&D en double-cliquant sur le raccourci
                .
                Ø Tape sur "2" puis valide en appuyant sur "Entrée".

                ! Ne ferme pas la fenêtre lors de la suppression !

                Un rapport sera généré, poste son contenu ici.

                NOTE : Si ton Bureau ne réapparait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
                Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."
                Tape explorer puis valide.
                1. Ensuite:

                  réouvre hijackthis
                  fais scan only
                  coches ces lignes sur leur gauche:

                  O4 - HKLM\..\Run: [recinfo253] c:\RecInfo\RecInfo.exe

                  tu les coches et tu clic sur "fix checked"

                  et tu fermes le programme.

                  Ensuite:

                  Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

                  Télécharges :
                  Malwarebytes ou :
                  Malwarebytes

                  * Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

                  (NB : S'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX

                  * Potasses le Tuto pour te familiariser avec le prg :

                  ( cela dis, il est très simple d'utilisation ).

                  relance malwarebytes en suivant scrupuleusement ces consignes :

                  ! Déconnecte toi et ferme toutes applications en cours !

                  * Lance Malwarebyte's .

                  Fais un examen dit "Complet" .

                  --> Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
                  --> à la fin tu cliques sur "résultat" .
                  --> Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

                  Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

                  Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)
                  1. -----------\\ ToolBar S&D 1.2.8 XP/Vista

                    Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6000 )
                    X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU T5250 @ 1.50GHz )
                    BIOS : BIOS Version : 1.04C
                    USER : julien ( Administrator )
                    BOOT : Normal boot
                    Antivirus : Norton Internet Security 2007 (Activated)
                    Firewall : Norton Internet Security 2007 (Activated)
                    C:\ (Local Disk) - NTFS - Total:92 Go (Free:47 Go)
                    D:\ (Local Disk) - NTFS - Total:45 Go (Free:45 Go)
                    E:\ (CD or DVD)

                    "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
                    Option : [1] ( 06/05/2009| 1:56 )

                    [ UAC => 1 ]

                    -----------\\ Recherche de Fichiers / Dossiers ...

                    -----------\\ [..\Internet Explorer\Main]

                    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                    "Local Page"="C:\\Windows\\system32\\blank.htm"
                    "Search Page"="https://www.google.com/?gws_rd=ssl"
                    "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
                    "Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
                    "Url"="https://www.msn.com/fr-fr/actualite/"

                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                    "Start Page"="https://www.msn.com/fr-fr"
                    "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
                    "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                    "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"

                    --------------------\\ Recherche d'autres infections

                    Aucune autre infection trouvée !

                    [ UAC => 1 ]

                    1 - "C:\ToolBar SD\TB_1.txt" - 06/05/2009| 1:56 - Option : [1]

                    -----------\\ Fin du rapport a 1:56:54,32
                2. ca a l'air bien tout ca,bravo.

                  Malwarebytes' Anti-Malware 1.36
                  Version de la base de données: 2079
                  Windows 6.0.6000

                  06/05/2009 03:45:32
                  mbam-log-2009-05-06 (03-45-32).txt

                  Type de recherche: Examen complet (C:\|D:\|)
                  Eléments examinés: 148491
                  Temps écoulé: 1 hour(s), 15 minute(s), 6 second(s)

                  Processus mémoire infecté(s): 0
                  Module(s) mémoire infecté(s): 0
                  Clé(s) du Registre infectée(s): 0
                  Valeur(s) du Registre infectée(s): 0
                  Elément(s) de données du Registre infecté(s): 0
                  Dossier(s) infecté(s): 0
                  Fichier(s) infecté(s): 0

                  Processus mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Module(s) mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Clé(s) du Registre infectée(s):
                  (Aucun élément nuisible détecté)

                  Valeur(s) du Registre infectée(s):
                  (Aucun élément nuisible détecté)

                  Elément(s) de données du Registre infecté(s):
                  (Aucun élément nuisible détecté)

                  Dossier(s) infecté(s):
                  (Aucun élément nuisible détecté)

                  Fichier(s) infecté(s):
                  (Aucun élément nuisible détecté)
                  1. Bon ben ca parait pas mal,supprimes les logiciels de desinfection inutiles avec tool cleaner

                    http://www.commentcamarche.net/telecharger/telechargement 34055291 toolscleaner
                    ---> Télécharge ToolsCleaner2 sur ton Bureau.
                    * Double-clique sur ToolsCleaner2.exe pour le lancer.
                    * Clique sur Recherche et laisse le scan agir.
                    * Clique sur Suppression pour finaliser.
                    * Tu peux, si tu le souhaites, te servir des Options Facultatives.
                    * Clique sur Quitter pour obtenir le rapport.
                    * Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
                    _________________________________________________

                    Ensuite

                    Fais un scan en ligne ici Kasper Online (Avec Internet Explorer).

                    - En bas à droite, clique sur Démarrer Online-scanner.

                    - Dans la nouvelle fenêtre qui s'affiche, clique sur J'accepte.

                    - Accepte les Contrôles ActiveX.

                    - Choisis Poste de travail pour le scan.

                    - Celui-ci terminé, sauvegarde (Choisis fichier texte) et poste le rapport.

                    - Pour t'aider à utiliser le scan en ligne :

                    NOTE : Si tu reçois le message La licence de Kaspersky On-line Scanner est périmée, va dans Ajout/Suppression de programmes puis désinstalle On-Line Scanner, reconnecte-toi sur le site de Kaspersky pour retenter le scan en ligne.
                    1. bonsoir, me revoila.
                      alors g fait ce que tu m'as dit voici les deux rapports.

                      [ Rapport ToolsCleaner version 2.3.5 (par A.Rothstein & dj QUIOU) ]

                      --> Recherche:

                      C:\TB.txt: trouvé !
                      C:\Program Files\trend micro\HijackThis: trouvé !
                      C:\Program Files\trend micro\HijackThis\HijackThis.exe: trouvé !
                      C:\Program Files\trend micro\HijackThis\hijackthis.log: trouvé !
                      C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: trouvé !
                      C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\UsbFix: trouvé !
                      C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
                      C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UsbFix: trouvé !
                      C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
                      C:\Users\All Users\Microsoft\Windows\Start Menu\Programmes\HijackThis: trouvé !
                      C:\Users\All Users\Microsoft\Windows\Start Menu\Programmes\UsbFix: trouvé !
                      C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
                      C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\UsbFix: trouvé !
                      C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !

                      ---------------------------------
                      --> Suppression:

                      C:\Program Files\trend micro\HijackThis\HijackThis.exe: ERREUR DE SUPPRESSION !!
                      C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: ERREUR DE SUPPRESSION !!
                      C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: ERREUR DE SUPPRESSION !!
                      C:\TB.txt: ERREUR DE SUPPRESSION !!
                      C:\Program Files\trend micro\HijackThis\hijackthis.log: ERREUR DE SUPPRESSION !!
                      C:\Program Files\trend micro\HijackThis: ERREUR DE SUPPRESSION !!
                      C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: ERREUR DE SUPPRESSION !!
                      C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\UsbFix: ERREUR DE SUPPRESSION !!
                      C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: ERREUR DE SUPPRESSION !!
                      C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UsbFix: ERREUR DE SUPPRESSION !!
                      C:\Users\All Users\Microsoft\Windows\Start Menu\Programmes\HijackThis: ERREUR DE SUPPRESSION !!
                      C:\Users\All Users\Microsoft\Windows\Start Menu\Programmes\UsbFix: ERREUR DE SUPPRESSION !!
                      C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis: ERREUR DE SUPPRESSION !!
                      C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\UsbFix: ERREUR DE SUPPRESSION !!

                      pour le 2 eme g un message d'erreur:

                      Veuillez patienter pendant la mise à jour des définitions de virus...
                      Téléchargement en cours depuis l'URL: https://www.kaspersky.fr/downloads
                      Téléchargement de fichier distant: master.xml
                      Certains composants sont endommagés où ne sont pas correctement installé. Veuillez réinstaller l'application!

                      echec de la mise à jour !
                      1. Les logiciels de desinfection inutiles n'ont pas ete supprimés utilises ceci

                        Télécharge OTCleanIt de OldTimer sur ton Bureau

                        http://download.bleepingcomputer.com/oldtimer/OTCleanIt.exe

                        Lance OTCleanIt avec un double-clic (sous Vista, lance-le en cliquant droit sur OTCleanIt.exe et en sélectionnant "exécuter en tant qu'administrateur")

                        Appuie sur le bouton "CleanUp!"

                        A la question "begin cleanup process?", réponds "YES"

                        A la fin de l'opération, si OTCleanIt demande de redémarrer ("Do you want to reboot now?"), ferme ce que tu es en train de faire (internet, documents divers...) et clique sur "YES":

                        Au redémarrage, OTCleanIt aura supprimé les outils de désinfection, et se sera même auto-détruit!

                        Ensuite ,essaies de faire un scan ici

                        -> Scan BitDefender

                        Fais une analyse antivirus en ligne sur BitDefender avec Internet Explorer.:

                        BitDefender on line

                        * Clique en bas à gauche sur Scan on line.
                        * Accepte la licence et laisse-le installer l'Active x..
                        * Laisse-toi guider. Colle son rapport ici.
                        * Poste un nouveau rapport Hijackthis.

                        Aide
                        • 1
                        • 2