Probleme de pop up

Bonjour,

Je vous ecris car depuis quelques jours j'ai des popo ups qui apparaissent des que je navigue sur le web...Si quelqu'un peut m'aider...

Merci d'avance!!!

Ci-joint:rapport hijackthis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:50:05, on 13/05/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Nuance\PDF Professional 5\PdfPro5Hook.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Users\Andrew\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files\google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Users\Andrew\AppData\Local\kwmwy.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\ehome\ehmsas.exe
c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Andrew\Downloads\HiJackThis.exe

O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: PDFProFiltSrv - Nuance Communications, Inc. - C:\Program Files\Nuance\PDF Professional 5\PDFProFiltSrv.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

--
End of file - 3279 bytes

Encore merci!
Configuration: Windows Vista
Firefox 3.0.10

14 réponses

  1. Bonjour

    Il est incomplet ton rapport

    ++
    0
    1. Contributeur
      Salut,

      Ton rapport est incomplet

      Telecharges Navilog1 sur ton bureau :
      http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

      - Desactives la grarde de ton Antivirus celle de ton (es) antispyware (s)
      - Lances l'installation en executant le fichier téléchargé
      - Une fois installé, fermes tous les programmes en cours et double-cliques sur Navilog1.exe
      - Choisis la langue et presses la touche " entrée " de ton clavier
      - Une fenetre s'ouvre, presses 1 touche pour passer aux etapes suivantes
      - Le menu du fix s'ouvre, choisis l'option 1 et presses la touche " entrée "
      - Laisses le fix travailler et patientes jusqu'au message *** Analyse terminée le***
      - Un rapport c:\fixnavi.txt s'etablira, postes son contenu...
      0
      1. Contributeur
        Salut,

        - Sous vista, desactives le controle des comptes utilisateurs --> panneau de config --> comptes utilisateur --> desactiver le controle des comptes utilisateurs

        et ne double cliques pas, mais clique droit sur l'icone ( executer en tant qu'administrateur)
        0
        1. MERCI DE VOTRE AIDE!

          Résultat du scan:

          Search Navipromo version 3.7.7 commencé le 14/05/2009 à 8:22:55,44

          !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
          !!! Postez ce rapport sur le forum pour le faire analyser !!!
          !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

          Outil exécuté depuis C:\Program Files\navilog1

          Mise à jour le 12.05.2009 à 18h00 par IL-MAFIOSO

          Microsoft® Windows Vista™ Édition Intégrale ( v6.0.6001 ) Service Pack 1
          X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU T8300 @ 2.40GHz )
          BIOS : Phoenix ROM BIOS PLUS Version 1.10 A09
          USER : Andrew ( Administrator )
          BOOT : Normal boot

          C:\ (Local Disk) - NTFS - Total:220 Go (Free:47 Go)
          D:\ (Local Disk) - NTFS - Total:9 Go (Free:2 Go)
          E:\ (CD or DVD)

          Recherche executé en mode normal

          *** Recherche dossiers dans "C:\Windows" ***

          *** Recherche dossiers dans "C:\Program Files" ***

          *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

          *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1" ***

          *** Recherche dossiers dans "C:\ProgramData" ***

          *** Recherche dossiers dans "c:\users\andrew\appdata\roaming\micros~1\windows\startm~1\programs" ***

          *** Recherche dossiers dans "C:\Users\Andrew\AppData\Local\virtualstore\Program Files" ***

          *** Recherche dossiers dans "C:\Users\Andrew\AppData\Local" ***

          *** Recherche dossiers dans "C:\Users\Andrew\AppData\Roaming" ***

          *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
          pour + d'infos : http://www.gmer.net

          *** Recherche avec GenericNaviSearch ***
          !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
          !!! A vérifier impérativement avant toute suppression manuelle !!!

          * Recherche dans "C:\Windows\system32" *

          * Recherche dans "C:\Users\Andrew\AppData\Local\Microsoft" *

          * Recherche dans "C:\Users\Andrew\AppData\Local" *

          *** Recherche fichiers ***

          C:\Windows\system32\nvs2.inf trouvé !

          *** Recherche clés spécifiques dans le Registre ***
          !! Les clés trouvées ne sont pas forcément infectées !!

          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "ygymqks"="c:\\users\\andrew\\appdata\\local\\ygymqks.exe ygymqks"

          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "suseoyk"="\"c:\\users\\andrew\\appdata\\local\\suseoyk.exe\" suseoyk"

          *** Module de Recherche complémentaire ***
          (Recherche fichiers spécifiques)

          1)Recherche nouveaux fichiers Instant Access :

          2)Recherche Heuristique :

          * Dans "C:\Windows\system32" :

          * Dans "C:\Users\Andrew\AppData\Local\Microsoft" :

          * Dans "C:\Users\Andrew\AppData\Local" :

          suseoyk.exe trouvé !
          suseoyk.dat trouvé !
          suseoyk_nav.dat trouvé !
          suseoyk_navps.dat trouvé !
          ygymqks.dat trouvé !
          ygymqks_nav.dat trouvé !
          ygymqks_navfx.dat trouvé !
          ygymqks_navps.dat trouvé !

          3)Recherche Certificats :

          Certificat Egroup trouvé !
          Certificat Electronic-Group trouvé !
          Certificat Montorgueil absent !
          Certificat OOO-Favorit trouvé !
          Certificat Sunny-Day-Design-Ltd absent !

          4)Recherche autres dossiers et fichiers connus :

          *** Analyse terminée le 14/05/2009 à 8:38:06,13 ***

          Encore MERCI!

          "Tout a une fin sauf la banane qui en a deux"
          0
          1. Bonjour

            Veille à ce que le contrôle des comptes utilisateurs (UAC) soit désactivé.
            Fais un Clic-droit sur le raccourci Navilog1 présent sur ton bureau et choisis "Exécuter en tant qu'administrateur".

            Au menu principal, Fais le choix 2
            Laisse toi guider et patiente.
            Le fix va t'informer qu'il va alors redémarrer ton PC
            Ferme toutes les fenêtres ouvertes et enregistre tes documents personnels ouverts
            Appuie sur une touche comme demandé.
            (si ton Pc ne redémarre pas automatiquement, fais-le toi-même)
            Au redémarrage de ton PC, choisis ta session habituelle si nécessaire.
            Patiente jusqu'au message :
            *** Nettoyage Termine le ..... ***
            Le blocnote va s'ouvrir.
            Sauvegarde le rapport de manière à le retrouver
            Referme le blocnote. Ton bureau va réapparaître
            Copie colle le rapport

            PS :Si ton bureau ne réapparaît pas, fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.
            Puis rends-toi à l'onglet "processus". Clique en haut à gauche sur fichiers et choisis "exécuter"
            Tape explorer et valide. Cela te fera apparaître ton bureau


            + 1 log hijackthis COMPLET

            0
            1. Salut!
              Merci de ta réponse rapide!

              Voici le résultat du scan:

              Clean Navipromo version 3.7.7 commencé le 14/05/2009 à 9:21:08,31

              Outil exécuté depuis C:\Program Files\navilog1

              Mise à jour le 12.05.2009 à 18h00 par IL-MAFIOSO

              Microsoft® Windows Vista™ Édition Intégrale ( v6.0.6001 ) Service Pack 1
              X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU T8300 @ 2.40GHz )
              BIOS : Phoenix ROM BIOS PLUS Version 1.10 A09
              USER : Andrew ( Administrator )
              BOOT : Normal boot

              C:\ (Local Disk) - NTFS - Total:220 Go (Free:43 Go)
              D:\ (Local Disk) - NTFS - Total:9 Go (Free:2 Go)
              E:\ (CD or DVD)

              Mode suppression automatique
              avec prise en charge résultats Catchme et GNS

              Nettoyage exécuté au redémarrage de l'ordinateur

              *** fsbl1.txt non trouvé ***
              (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)

              *** Suppression avec sauvegardes résultats GenericNaviSearch ***

              * Suppression dans "C:\Windows\System32" *

              * Suppression dans "C:\Users\Andrew\AppData\Local\Microsoft" *

              * Suppression dans "C:\Users\Andrew\AppData\Local" *

              *** Suppression dossiers dans "C:\Windows" ***

              *** Suppression dossiers dans "C:\Program Files" ***

              *** Suppression dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

              *** Suppression dossiers dans "c:\progra~2\micros~1\windows\startm~1" ***

              *** Suppression dossiers dans "C:\ProgramData" ***

              *** Suppression dossiers dans c:\users\andrew\appdata\roaming\micros~1\windows\startm~1\programs ***

              *** Suppression dossiers dans "C:\Users\Andrew\AppData\Local\virtualstore\Program Files" ***

              *** Suppression dossiers dans "C:\Users\Andrew\AppData\Local" ***

              *** Suppression dossiers dans "C:\Users\Andrew\AppData\Roaming" ***

              *** Suppression fichiers ***

              C:\Windows\system32\nvs2.inf supprimé !

              *** Suppression fichiers temporaires ***

              Nettoyage contenu C:\Windows\Temp effectué !
              Nettoyage contenu C:\Users\Andrew\AppData\Local\Temp effectué !

              *** Traitement Recherche complémentaire ***
              (Recherche fichiers spécifiques)

              1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

              2)Recherche, création sauvegardes et suppression Heuristique :

              * Dans "C:\Windows\system32" *

              * Dans "C:\Users\Andrew\AppData\Local\Microsoft" *

              * Dans "C:\Users\Andrew\AppData\Local" *

              suseoyk.exe trouvé !
              Copie suseoyk.exe réalisée avec succès !
              suseoyk.exe supprimé !

              suseoyk.dat trouvé !
              Copie suseoyk.dat réalisée avec succès !
              suseoyk.dat supprimé !

              suseoyk_nav.dat trouvé !
              Copie suseoyk_nav.dat réalisée avec succès !
              suseoyk_nav.dat supprimé !

              suseoyk_navps.dat trouvé !
              Copie suseoyk_navps.dat réalisée avec succès !
              suseoyk_navps.dat supprimé !

              ygymqks.dat trouvé !
              Copie ygymqks.dat réalisée avec succès !
              ygymqks.dat supprimé !

              ygymqks_nav.dat trouvé !
              Copie ygymqks_nav.dat réalisée avec succès !
              ygymqks_nav.dat supprimé !

              ygymqks_navfx.dat trouvé !
              Copie ygymqks_navfx.dat réalisée avec succès !
              ygymqks_navfx.dat supprimé !

              ygymqks_navps.dat trouvé !
              Copie ygymqks_navps.dat réalisée avec succès !
              ygymqks_navps.dat supprimé !

              *** Sauvegarde du Registre vers dossier Safebackup ***

              sauvegarde du Registre réalisée avec succès !

              *** Nettoyage Registre ***

              Nettoyage Registre Ok

              *** Certificats ***

              Certificat Egroup supprimé !
              Certificat Electronic-Group supprimé !
              Certificat Montorgueil absent !
              Certificat OOO-Favorit supprimé !
              Certificat Sunny-Day-Design-Ltdt absent !

              *** Recherche autres dossiers et fichiers connus ***

              *** Nettoyage terminé le 14/05/2009 à 9:24:28,18 ***

              Encore merci!

              ” Quand l’homme est couché sur le dos, il ne doit pas cracher en l’air.”
              0
              1. Tu as aussi besoin de ce log Hijackthis (je l'espère complet!), si j'ai bien compris...

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 09:31:42, on 14/05/2009
                Platform: Windows Vista SP1 (WinNT 6.00.1905)
                MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                Boot mode: Normal

                Running processes:
                C:\Windows\system32\taskeng.exe
                C:\Windows\system32\Dwm.exe
                C:\Windows\Explorer.EXE
                C:\Windows\system32\conime.exe
                c:\PROGRA~1\mcafee.com\agent\mcagent.exe
                C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
                C:\Windows\System32\rundll32.exe
                C:\Windows\System32\rundll32.exe
                C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
                C:\Program Files\iTunes\iTunesHelper.exe
                C:\Program Files\Nuance\PDF Professional 5\PdfPro5Hook.exe
                C:\Program Files\Java\jre6\bin\jusched.exe
                C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                C:\Windows\ehome\ehtray.exe
                C:\Program Files\Windows Media Player\wmpnscfg.exe
                C:\Program Files\Dell Support Center\bin\sprtcmd.exe
                C:\Users\Andrew\AppData\Local\Google\Update\GoogleUpdate.exe
                C:\Program Files\google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
                C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
                C:\Program Files\Dell\QuickSet\quickset.exe
                C:\Windows\system32\wbem\unsecapp.exe
                C:\Windows\ehome\ehmsas.exe
                C:\Windows\System32\rundll32.exe
                c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
                C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
                C:\Windows\system32\SearchFilterHost.exe
                C:\Users\Andrew\Desktop\HiJackThis.exe

                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fr/0SEFRFR/SAOS02
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT1576177
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ads.eorezo.com/cgi-bin/advert/getads.cgi?x_format=redirect&x_dp_id=9
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                R3 - URLSearchHook: livetvbar Toolbar - {ad55c869-668e-457c-b270-0cfb2f61116f} - C:\Program Files\livetvbar\tblive.dll
                F2 - REG:system.ini: UserInit=userinit.exe,
                O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
                O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
                O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
                O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                O2 - BHO: livetvbar Toolbar - {ad55c869-668e-457c-b270-0cfb2f61116f} - C:\Program Files\livetvbar\tblive.dll
                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
                O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
                O2 - BHO: ZeonIEEventHelper Class - {DA986D7D-CCAF-47B2-84FE-BFA1549BEBF9} - C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll
                O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                O3 - Toolbar: Nuance PDF - {E3286BF1-E654-42FF-B4A6-5E111731DF6B} - C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll
                O3 - Toolbar: livetvbar Toolbar - {ad55c869-668e-457c-b270-0cfb2f61116f} - C:\Program Files\livetvbar\tblive.dll
                O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
                O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
                O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
                O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
                O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                O4 - HKLM\..\Run: [PDFHook] C:\Program Files\Nuance\PDF Professional 5\pdfpro5hook.exe
                O4 - HKLM\..\Run: [PDF5 Registry Controller] C:\Program Files\Nuance\PDF Professional 5\RegistryController.exe
                O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
                O4 - HKCU\..\Run: [update 000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000] %AppData%\wunauclt.exe
                O4 - HKCU\..\Run: [ setup] C:\Users\Andrew\Downloads\eMule\Incoming\Football Manager (2009).exe
                O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                O4 - HKCU\..\Run: [Google Update] "C:\Users\Andrew\AppData\Local\Google\Update\GoogleUpdate.exe" /c
                O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                O4 - HKCU\..\Policies\Explorer\Run: [Windows Printing Driver] doskeys.exe
                O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                O4 - Global Startup: BTTray.lnk = ?
                O4 - Global Startup: PHOTOfunSTUDIO -viewer-.lnk = C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
                O4 - Global Startup: QuickSet.lnk = ?
                O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIEAppend.HTML
                O8 - Extra context menu item: Ajouter le contenu des liens sélectionnés à un fichier PDF existant - res://C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIEAppendSelLinks.HTML
                O8 - Extra context menu item: Ajouter le contenu du lien à un fichier PDF existant - res://C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIEAppend.HTML
                O8 - Extra context menu item: Créer des fichiers PDF à partir des liens sélectionnés - res://C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIECaptureSelLinks.HTML
                O8 - Extra context menu item: Créer fichier PDF - res://C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIECapture.HTML
                O8 - Extra context menu item: Créer un fichier PDF depuis le contenu du lien - res://C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIECapture.HTML
                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
                O8 - Extra context menu item: Ouvrir avec Nuance PDF Converter 5.0 - res://C:\Program Files\Nuance\PDF Professional 5\cnvres_fre.dll /100
                O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                O13 - Gopher Prefix:
                O15 - Trusted Zone: http://*.mcafee.com
                O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
                O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
                O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
                O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
                O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
                O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
                O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
                O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
                O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
                O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
                O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
                O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
                O23 - Service: PDFProFiltSrv - Nuance Communications, Inc. - C:\Program Files\Nuance\PDF Professional 5\PDFProFiltSrv.exe
                O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
                O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
                O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
                O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                0
                1. Re

                  Tu l'as acheté McAfee ??

                  2) Télécharge Malwarebytes' Anti-Malware (MBAM) et enregistre le sur ton Bureau à partir de ce lien :

                  https://www.malwarebytes.com/
                  https://www.commentcamarche.net/telecharger/ 34055379 malwarebyte s anti malware
                  Tuto
                  https://forum.pcastuces.com/malwarebytes_antimalwares___tutoriel-f31s3.htm

                  3) A la fin du téléchargement, ferme toutes les fenêtres et programmes, y compris celui-ci.

                  4) Double-clique sur l'icône Download_mbam-setup.exe sur ton bureau pour démarrer le programme d'installation.

                  5) Pendant l'installation, suis les indications (en particulier le choix de la langue et l'autorisation d'accession à Internet). N'apporte aucune modification aux réglages par défaut et, en fin d'installation, vérifie que les options Update Malwarebytes' Anti-Malware et Launch Malwarebytes' Anti-Malware sont cochées.

                  6) MBAM démarrera automatiquement et enverra un message demandant à mettre à jour le programme avant de lancer une analyse. Comme MBAM se met automatiquement à jour en fin d'installation, clique sur OK pour fermer la boîte de dialogue. La fenêtre principale de MBAM s'affiche :

                  7) Dans l'onglet analyse, vérifie que "Exécuter un examen complet" est coché et clique sur le bouton Rechercher pour démarrer l'analyse.

                  8) MBAM analyse ton ordinateur. L'analyse peut prendre un certain temps. Il suffit de vérifier de temps en temps son avancement.

                  9) A la fin de l'analyse, un message s'affiche indiquant la fin de l'analyse. Clique sur OK pour poursuivre.

                  10) Si des malwares ont été détectés, leur liste s'affiche.
                  En cliquant sur Suppression (?) , MBAM va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.

                  11) MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Ferme le Bloc-notes. (Le rapport peut être retrouvé sous l'onglet Rapports/logs)

                  12) Ferme MBAM en cliquant sur Quitter.

                  13) Poste le rapport dans ta réponse

                  + 1 log Hijackthis

                  0
                  1. Re bonjour Marie.

                    Oui ma version de Mc Afee est une version payante, offert pendant deux ans par Dell lors de l'achat de mon ordi...

                    Voici le résultat de malware:

                    Malwarebytes' Anti-Malware 1.36
                    Version de la base de données: 2129
                    Windows 6.0.6001 Service Pack 1

                    14/05/2009 12:55:17
                    mbam-log-2009-05-14 (12-55-17).txt

                    Type de recherche: Examen complet (C:\|D:\|E:\|)
                    Eléments examinés: 216885
                    Temps écoulé: 2 hour(s), 34 minute(s), 57 second(s)

                    Processus mémoire infecté(s): 0
                    Module(s) mémoire infecté(s): 0
                    Clé(s) du Registre infectée(s): 2
                    Valeur(s) du Registre infectée(s): 1
                    Elément(s) de données du Registre infecté(s): 0
                    Dossier(s) infecté(s): 2
                    Fichier(s) infecté(s): 4

                    Processus mémoire infecté(s):
                    (Aucun élément nuisible détecté)

                    Module(s) mémoire infecté(s):
                    (Aucun élément nuisible détecté)

                    Clé(s) du Registre infectée(s):
                    HKEY_LOCAL_MACHINE\SOFTWARE\EoRezo (Rogue.Eorezo) -> Quarantined and deleted successfully.
                    HKEY_CURRENT_USER\SOFTWARE\advantage (Adware.Vomba) -> Quarantined and deleted successfully.

                    Valeur(s) du Registre infectée(s):
                    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\Windows Printing Driver (Trojan.Agent) -> Quarantined and deleted successfully.

                    Elément(s) de données du Registre infecté(s):
                    (Aucun élément nuisible détecté)

                    Dossier(s) infecté(s):
                    C:\Program Files\GalaPlayer (Trojan.Lop) -> Quarantined and deleted successfully.
                    C:\Program Files\Advantage (Adware.Advantage) -> Quarantined and deleted successfully.

                    Fichier(s) infecté(s):
                    C:\Windows\System32\rar.exe (Trojan.Backdoor) -> Quarantined and deleted successfully.
                    C:\Program Files\Advantage\AdVantage.htm (Adware.Advantage) -> Quarantined and deleted successfully.
                    C:\Program Files\Advantage\AdVUninst.exe (Adware.Advantage) -> Quarantined and deleted successfully.
                    C:\Program Files\EoRezo (Rogue.Eorezo) -> Delete on reboot.

                    et voici le dernier rapport de HIJACKTHIS:

                    Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 13:01:45, on 14/05/2009
                    Platform: Windows Vista SP1 (WinNT 6.00.1905)
                    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                    Boot mode: Normal

                    Running processes:
                    C:\Windows\system32\taskeng.exe
                    C:\Windows\system32\Dwm.exe
                    C:\Windows\Explorer.EXE
                    c:\PROGRA~1\mcafee.com\agent\mcagent.exe
                    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                    C:\Program Files\Dell Support Center\bin\sprtcmd.exe
                    C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
                    C:\Windows\System32\rundll32.exe
                    C:\Windows\System32\rundll32.exe
                    C:\Windows\System32\rundll32.exe
                    C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
                    C:\Program Files\iTunes\iTunesHelper.exe
                    C:\Program Files\Nuance\PDF Professional 5\PdfPro5Hook.exe
                    C:\Program Files\Java\jre6\bin\jusched.exe
                    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                    C:\Windows\ehome\ehtray.exe
                    C:\Program Files\Windows Media Player\wmpnscfg.exe
                    C:\Users\Andrew\AppData\Local\Google\Update\GoogleUpdate.exe
                    C:\Program Files\google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                    C:\Windows\ehome\ehmsas.exe
                    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
                    C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
                    C:\Program Files\Dell\QuickSet\quickset.exe
                    C:\Windows\system32\wbem\unsecapp.exe
                    c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
                    C:\Program Files\Mozilla Firefox\firefox.exe
                    C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
                    C:\Program Files\Dell Support Center\gs_agent\dsc.exe
                    C:\Users\Andrew\Desktop\HiJackThis.exe

                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=55729C844D6A45819CAD368B3E178C9F
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT1576177
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ww17.ads.eorezo.com/cgi-bin/advert/getads.cgi?x_format=redirect&x_dp_id=9
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                    R3 - URLSearchHook: livetvbar Toolbar - {ad55c869-668e-457c-b270-0cfb2f61116f} - C:\Program Files\livetvbar\tblive.dll
                    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                    O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                    O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
                    O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
                    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
                    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                    O2 - BHO: livetvbar Toolbar - {ad55c869-668e-457c-b270-0cfb2f61116f} - C:\Program Files\livetvbar\tblive.dll
                    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
                    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
                    O2 - BHO: ZeonIEEventHelper Class - {DA986D7D-CCAF-47B2-84FE-BFA1549BEBF9} - C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll
                    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                    O3 - Toolbar: Nuance PDF - {E3286BF1-E654-42FF-B4A6-5E111731DF6B} - C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll
                    O3 - Toolbar: livetvbar Toolbar - {ad55c869-668e-457c-b270-0cfb2f61116f} - C:\Program Files\livetvbar\tblive.dll
                    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                    O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
                    O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
                    O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
                    O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                    O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
                    O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                    O4 - HKLM\..\Run: [PDFHook] C:\Program Files\Nuance\PDF Professional 5\pdfpro5hook.exe
                    O4 - HKLM\..\Run: [PDF5 Registry Controller] C:\Program Files\Nuance\PDF Professional 5\RegistryController.exe
                    O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                    O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
                    O4 - HKCU\..\Run: [update 000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000] %AppData%\wunauclt.exe
                    O4 - HKCU\..\Run: [ setup] C:\Users\Andrew\Downloads\eMule\Incoming\Football Manager (2009).exe
                    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                    O4 - HKCU\..\Run: [Google Update] "C:\Users\Andrew\AppData\Local\Google\Update\GoogleUpdate.exe" /c
                    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                    O4 - Global Startup: BTTray.lnk = ?
                    O4 - Global Startup: PHOTOfunSTUDIO -viewer-.lnk = C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
                    O4 - Global Startup: QuickSet.lnk = ?
                    O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIEAppend.HTML
                    O8 - Extra context menu item: Ajouter le contenu des liens sélectionnés à un fichier PDF existant - res://C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIEAppendSelLinks.HTML
                    O8 - Extra context menu item: Ajouter le contenu du lien à un fichier PDF existant - res://C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIEAppend.HTML
                    O8 - Extra context menu item: Créer des fichiers PDF à partir des liens sélectionnés - res://C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIECaptureSelLinks.HTML
                    O8 - Extra context menu item: Créer fichier PDF - res://C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIECapture.HTML
                    O8 - Extra context menu item: Créer un fichier PDF depuis le contenu du lien - res://C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIECapture.HTML
                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                    O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                    O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
                    O8 - Extra context menu item: Ouvrir avec Nuance PDF Converter 5.0 - res://C:\Program Files\Nuance\PDF Professional 5\cnvres_fre.dll /100
                    O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                    O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                    O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                    O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                    O13 - Gopher Prefix:
                    O15 - Trusted Zone: http://*.mcafee.com
                    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                    O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
                    O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
                    O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
                    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                    O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                    O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
                    O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
                    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
                    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
                    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
                    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
                    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
                    O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
                    O23 - Service: PDFProFiltSrv - Nuance Communications, Inc. - C:\Program Files\Nuance\PDF Professional 5\PDFProFiltSrv.exe
                    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                    O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
                    O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
                    O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
                    O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                    0
                    1. Bonjour

                      1° Tu vas désactiver le contrôle des comptes d'utilisateurs.

                      Dans le Panneau de configuration, Affichage classique, Comptes d'utilisateurs, cliques sur Activer ou désactiver le contrôle des comptes d'utilisateurs.
                      Clique sur Contribuer.
                      Dans la fenêtre suivante, décoche Utiliser le contrôle des comptes d'utilisateurs pour vous aider à protéger votre ordinateur.
                      Il te sera demandé de redémarrer.

                      Télécharge SmitfraudFix
                      Utilitaire de S!Ri: Moe et balltrap34
                      http://siri.urz.free.fr/Fix/SmitfraudFix.php

                      http://www.malekal.com/tutorial_SmitFraudfix.php
                      et télécharge SmitfraudFix.exe.

                      Regarde le tuto

                      Exécute le en choisissant l’option 1,
                      il va générer un rapport
                      Copie/colle le sur le poste stp.

                      process.exe
                      est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
                      http://www.beyondlogic.org/consulting/processutil/processutil.htm


                      Bon courage
                      A++

                      0
                      1. MERCI Marie

                        Depuis les premiers manips j'ai plus de problemes de pop ups mais des fois des choses bizarre...genre la apres le dernier scan, en ralumant mon ordi, j'ai eu une fenetre qui me dis que mon wifi n'est pas compatible avec mon wilan et que je dois le modifier...ce que j'ai fais...Internet marche tjs dans tous les cas...

                        Voici le dernier rapport:

                        SmitFraudFix v2.416

                        Scan done at 18:51:18,88, 16/05/2009
                        Run from C:\Users\Andrew\Desktop\SmitfraudFix
                        OS: Microsoft Windows [version 6.0.6001] - Windows_NT
                        The filesystem type is NTFS
                        Fix run in normal mode

                        »»»»»»»»»»»»»»»»»»»»»»»» Process

                        C:\Windows\system32\csrss.exe
                        C:\Windows\system32\wininit.exe
                        C:\Windows\system32\csrss.exe
                        C:\Windows\system32\services.exe
                        C:\Windows\system32\lsass.exe
                        C:\Windows\system32\lsm.exe
                        C:\Windows\system32\winlogon.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\SLsvc.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Program Files\Protector Suite QL\upeksvr.exe
                        C:\Windows\system32\WLANExt.exe
                        C:\Windows\System32\spoolsv.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\taskeng.exe
                        C:\Windows\system32\Dwm.exe
                        C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
                        C:\Windows\system32\aestsrv.exe
                        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                        C:\Program Files\Bonjour\mDNSResponder.exe
                        C:\Windows\system32\svchost.exe
                        C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                        C:\Windows\Explorer.EXE
                        c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
                        C:\Windows\system32\taskeng.exe
                        C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
                        C:\Program Files\McAfee\MPF\MPFSrv.exe
                        C:\Program Files\McAfee\MSK\MskSrver.exe
                        C:\Program Files\Nuance\PDF Professional 5\PDFProFiltSrv.exe
                        C:\Windows\system32\svchost.exe
                        C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                        C:\Program Files\Dell Support Center\bin\sprtsvc.exe
                        C:\Windows\system32\STacSV.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\system32\SearchIndexer.exe
                        C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
                        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                        C:\Program Files\Dell Support Center\bin\sprtcmd.exe
                        C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
                        C:\Windows\System32\rundll32.exe
                        C:\Windows\System32\rundll32.exe
                        C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
                        C:\Windows\System32\rundll32.exe
                        c:\PROGRA~1\mcafee.com\agent\mcagent.exe
                        C:\Program Files\iTunes\iTunesHelper.exe
                        C:\Program Files\Nuance\PDF Professional 5\PdfPro5Hook.exe
                        C:\Windows\system32\wbem\wmiprvse.exe
                        C:\Program Files\Java\jre6\bin\jusched.exe
                        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                        C:\Windows\ehome\ehtray.exe
                        C:\Program Files\Windows Media Player\wmpnscfg.exe
                        C:\Program Files\Windows Media Player\wmpnetwk.exe
                        C:\Users\Andrew\AppData\Local\Google\Update\GoogleUpdate.exe
                        C:\Program Files\google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                        C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
                        C:\Windows\ehome\ehmsas.exe
                        C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
                        C:\Windows\system32\wbem\unsecapp.exe
                        c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
                        C:\Program Files\Dell\QuickSet\quickset.exe
                        C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
                        C:\Program Files\iPod\bin\iPodService.exe
                        c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
                        \\?\C:\Windows\system32\wbem\WMIADAP.EXE
                        C:\Windows\system32\SearchProtocolHost.exe
                        C:\Windows\system32\cmd.exe
                        C:\Windows\system32\SearchFilterHost.exe
                        C:\Windows\system32\conime.exe
                        c:\PROGRA~1\mcafee.com\agent\McUpdate.exe
                        C:\Windows\system32\wbem\wmiprvse.exe

                        »»»»»»»»»»»»»»»»»»»»»»»» hosts

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

                        C:\Windows\Tasks\At?.job FOUND !
                        C:\Windows\Tasks\At??.job FOUND !

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Andrew

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Andrew\AppData\Local\Temp

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Andrew\Application Data

                        »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Andrew\FAVORI~1

                        »»»»»»»»»»»»»»»»»»»»»»»» Desktop

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                        »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

                        »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

                        »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
                        !!!Attention, following keys are not inevitably infected!!!

                        o4Patch
                        Credits: Malware Analysis & Diagnostic
                        Code: S!Ri

                        »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                        !!!Attention, following keys are not inevitably infected!!!

                        IEDFix
                        Credits: Malware Analysis & Diagnostic
                        Code: S!Ri

                        »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
                        !!!Attention, following keys are not inevitably infected!!!

                        Agent.OMZ.Fix
                        Credits: Malware Analysis & Diagnostic
                        Code: S!Ri

                        »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                        !!!Attention, following keys are not inevitably infected!!!

                        VACFix
                        Credits: Malware Analysis & Diagnostic
                        Code: S!Ri

                        »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                        !!!Attention, following keys are not inevitably infected!!!

                        404Fix
                        Credits: Malware Analysis & Diagnostic
                        Code: S!Ri

                        »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                        !!!Attention, following keys are not inevitably infected!!!

                        SrchSTS.exe by S!Ri
                        Search SharedTaskScheduler's .dll

                        »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                        !!!Attention, following keys are not inevitably infected!!!

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                        "AppInit_DLLs"="C:\\PROGRA~1\\Google\\GOOGLE~1\\GOEC62~1.DLL"
                        "LoadAppInit_DLLs"=dword:00000001

                        »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                        !!!Attention, following keys are not inevitably infected!!!

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                        "Userinit"="C:\\Windows\\system32\\userinit.exe,"

                        »»»»»»»»»»»»»»»»»»»»»»»» RK

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

                        »»»»»»»»»»»»»»»»»»»»»»»» DNS

                        Description: Intel(R) Wireless WiFi Link 4965AGN
                        DNS Server Search Order: 192.168.1.1

                        HKLM\SYSTEM\CCS\Services\Tcpip\..\{A08C7B08-D4B5-4B56-B62C-ACF3A76166F9}: DhcpNameServer=10.72.0.68 10.72.0.69
                        HKLM\SYSTEM\CCS\Services\Tcpip\..\{A545AF36-C08B-4427-96F5-41CDDE65008E}: DhcpNameServer=192.168.1.1

                        »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

                        »»»»»»»»»»»»»»»»»»»»»»»» End

                        Merci de ton aide et bon week end!!!

                        ” Un homme doit avoir son ombre derrière lui.”
                        0
                    2. »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

                      C:\Windows\Tasks\At?.job FOUND !
                      C:\Windows\Tasks\At??.job FOUND !

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system


                      Nettoyage :
                      Démarre en mode sans échec :
                      Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter.
                      Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                      Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                      (Si F8 ne marche pas utilise la touche F5).

                      http://www.coupdepoucepc.com/modules/news/article.php?storyid=253
                      https://www.micro-astuce.com/depannage/demarrer-mode-sans-echec.php

                      ----------------------------------------------------------------------------
                      Relance le programme Smitfraud,
                      Cette fois choisit l’option 2, répond oui a tous ;
                      Sauvegarde le rapport,
                      Redémarre en mode normal,
                      copie/colle le rapport sauvegardé sur le forum

                      process.exe
                      est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
                      http://www.beyondlogic.org/consulting/processutil/processutil.htm

                      + un log Hijackthis en Mode Normal
                      0
                      1. Salut Marie

                        voici les rapports:

                        SmitFraudFix v2.416

                        Scan done at 11:17:33,96, 17/05/2009
                        Run from C:\Users\Andrew\Desktop\SmitfraudFix
                        OS: Microsoft Windows [version 6.0.6001] - Windows_NT
                        The filesystem type is NTFS
                        Fix run in safe mode

                        »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
                        !!!Attention, following keys are not inevitably infected!!!

                        SrchSTS.exe by S!Ri
                        Search SharedTaskScheduler's .dll

                        »»»»»»»»»»»»»»»»»»»»»»»» Killing process

                        »»»»»»»»»»»»»»»»»»»»»»»» hosts

                        127.0.0.1 www.mofa.go.jp/region/asia-paci/takeshima/index.html/
                        127.0.0.1 www.mofa.go.jp/policy/maritime/japan/index.html/
                        127.0.0.1 www.occidentalism.org
                        127.0.0.1 ndfsk.dyndns.org
                        127.0.0.1 www.uriminzokkiri.com
                        127.0.0.1 www.kcckp.net/external_k
                        127.0.0.1 www.tongpo.com
                        127.0.0.1 www.travel-northkorea.com
                        127.0.0.1 wing.zero.ad.jp/~zbf10400
                        127.0.0.1 www.dprknta.com
                        127.0.0.1 www.korea-np.co.jp
                        ...

                        »»»»»»»»»»»»»»»»»»»»»»»» VACFix

                        VACFix
                        Credits: Malware Analysis & Diagnostic
                        Code: S!Ri

                        »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                        S!Ri's WS2Fix: LSP not Found.

                        »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                        GenericRenosFix by S!Ri

                        »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

                        C:\Windows\Tasks\At?.job Deleted

                        »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                        IEDFix
                        Credits: Malware Analysis & Diagnostic
                        Code: S!Ri

                        »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix

                        Agent.OMZ.Fix
                        Credits: Malware Analysis & Diagnostic
                        Code: S!Ri

                        »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

                        404Fix
                        Credits: Malware Analysis & Diagnostic
                        Code: S!Ri

                        »»»»»»»»»»»»»»»»»»»»»»»» RK

                        »»»»»»»»»»»»»»»»»»»»»»»» DNS

                        HKLM\SYSTEM\CCS\Services\Tcpip\..\{A08C7B08-D4B5-4B56-B62C-ACF3A76166F9}: DhcpNameServer=10.72.0.68 10.72.0.69
                        HKLM\SYSTEM\CCS\Services\Tcpip\..\{A545AF36-C08B-4427-96F5-41CDDE65008E}: DhcpNameServer=192.168.1.1

                        »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files

                        »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                        !!!Attention, following keys are not inevitably infected!!!

                        »»»»»»»»»»»»»»»»»»»»»»»» RK.2

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        Registry Cleaning done.

                        »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
                        !!!Attention, following keys are not inevitably infected!!!

                        SrchSTS.exe by S!Ri
                        Search SharedTaskScheduler's .dll

                        »»»»»»»»»»»»»»»»»»»»»»»» End

                        Et comme d'hab le HIJACKTHIS:

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 11:24:09, on 17/05/2009
                        Platform: Windows Vista SP1 (WinNT 6.00.1905)
                        MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                        Boot mode: Normal

                        Running processes:
                        C:\Windows\system32\taskeng.exe
                        C:\Windows\system32\Dwm.exe
                        C:\Windows\Explorer.EXE
                        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                        C:\Program Files\Dell Support Center\bin\sprtcmd.exe
                        c:\PROGRA~1\mcafee.com\agent\mcagent.exe
                        C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
                        C:\Windows\System32\rundll32.exe
                        C:\Windows\System32\rundll32.exe
                        C:\Windows\System32\rundll32.exe
                        C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
                        C:\Program Files\iTunes\iTunesHelper.exe
                        C:\Program Files\Nuance\PDF Professional 5\PdfPro5Hook.exe
                        C:\Program Files\Java\jre6\bin\jusched.exe
                        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                        C:\Windows\ehome\ehtray.exe
                        C:\Program Files\Windows Media Player\wmpnscfg.exe
                        C:\Users\Andrew\AppData\Local\Google\Update\GoogleUpdate.exe
                        C:\Program Files\google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                        C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
                        C:\Windows\ehome\ehmsas.exe
                        C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
                        C:\Program Files\Dell\QuickSet\quickset.exe
                        C:\Windows\system32\wbem\unsecapp.exe
                        c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
                        C:\Program Files\Dell Support Center\gs_agent\dsc.exe
                        c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
                        C:\Windows\system32\SearchFilterHost.exe
                        C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
                        C:\Windows\system32\SearchProtocolHost.exe
                        C:\Users\Andrew\Desktop\HiJackThis.exe

                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                        R3 - URLSearchHook: livetvbar Toolbar - {ad55c869-668e-457c-b270-0cfb2f61116f} - C:\Program Files\livetvbar\tblive.dll
                        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                        O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                        O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
                        O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
                        O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
                        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                        O2 - BHO: livetvbar Toolbar - {ad55c869-668e-457c-b270-0cfb2f61116f} - C:\Program Files\livetvbar\tblive.dll
                        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
                        O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                        O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
                        O2 - BHO: ZeonIEEventHelper Class - {DA986D7D-CCAF-47B2-84FE-BFA1549BEBF9} - C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll
                        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                        O3 - Toolbar: Nuance PDF - {E3286BF1-E654-42FF-B4A6-5E111731DF6B} - C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll
                        O3 - Toolbar: livetvbar Toolbar - {ad55c869-668e-457c-b270-0cfb2f61116f} - C:\Program Files\livetvbar\tblive.dll
                        O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                        O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
                        O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
                        O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
                        O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                        O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
                        O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
                        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                        O4 - HKLM\..\Run: [PDFHook] C:\Program Files\Nuance\PDF Professional 5\pdfpro5hook.exe
                        O4 - HKLM\..\Run: [PDF5 Registry Controller] C:\Program Files\Nuance\PDF Professional 5\RegistryController.exe
                        O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                        O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                        O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
                        O4 - HKCU\..\Run: [update 000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000] %AppData%\wunauclt.exe
                        O4 - HKCU\..\Run: [ setup] C:\Users\Andrew\Downloads\eMule\Incoming\Football Manager (2009).exe
                        O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                        O4 - HKCU\..\Run: [Google Update] "C:\Users\Andrew\AppData\Local\Google\Update\GoogleUpdate.exe" /c
                        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                        O4 - Global Startup: BTTray.lnk = ?
                        O4 - Global Startup: PHOTOfunSTUDIO -viewer-.lnk = C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
                        O4 - Global Startup: QuickSet.lnk = ?
                        O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIEAppend.HTML
                        O8 - Extra context menu item: Ajouter le contenu des liens sélectionnés à un fichier PDF existant - res://C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIEAppendSelLinks.HTML
                        O8 - Extra context menu item: Ajouter le contenu du lien à un fichier PDF existant - res://C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIEAppend.HTML
                        O8 - Extra context menu item: Créer des fichiers PDF à partir des liens sélectionnés - res://C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIECaptureSelLinks.HTML
                        O8 - Extra context menu item: Créer fichier PDF - res://C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIECapture.HTML
                        O8 - Extra context menu item: Créer un fichier PDF depuis le contenu du lien - res://C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIECapture.HTML
                        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                        O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                        O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
                        O8 - Extra context menu item: Ouvrir avec Nuance PDF Converter 5.0 - res://C:\Program Files\Nuance\PDF Professional 5\cnvres_fre.dll /100
                        O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                        O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                        O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                        O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                        O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                        O13 - Gopher Prefix:
                        O15 - Trusted Zone: http://*.mcafee.com
                        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                        O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                        O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
                        O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
                        O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
                        O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                        O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                        O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                        O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                        O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
                        O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                        O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
                        O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
                        O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
                        O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
                        O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
                        O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
                        O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
                        O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
                        O23 - Service: PDFProFiltSrv - Nuance Communications, Inc. - C:\Program Files\Nuance\PDF Professional 5\PDFProFiltSrv.exe
                        O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                        O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
                        O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
                        O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
                        O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                        0
                        1. Salut

                          Télécharge Zeb-Restore

                          http://telechargement.zebulon.fr/zeb-restore.html

                          enregistre ce fichier sur le bureau.

                          -Clic droit Zeb-Restore.zip ==> Extraire tout choisis comme lieu d'enregistrement le bureau.
                          -Ouvre le dossier ZR_1.0.0.37 ==> double clic sur Zeb-Restore.exe
                          - Coche la case devant : Réinitialiser Fichier Hosts
                          - Ne coche aucune autre case
                          -Clique sur Restaurer
                          -Redémarre ton PC+++

                          Relance smitfraud option 2 pour vérifier.

                          Tu l'as acheté McAfee ?
                          0
                          1. Bonjour Marie

                            Oui je l'ai acheté Mc Afee.

                            Voila le nouveau rapport smitfraud:

                            SmitFraudFix v2.416

                            Scan done at 9:24:34,42, 18/05/2009
                            Run from C:\Users\Andrew\Desktop\SmitfraudFix
                            OS: Microsoft Windows [version 6.0.6001] - Windows_NT
                            The filesystem type is NTFS
                            Fix run in normal mode

                            »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
                            !!!Attention, following keys are not inevitably infected!!!

                            SrchSTS.exe by S!Ri
                            Search SharedTaskScheduler's .dll

                            »»»»»»»»»»»»»»»»»»»»»»»» Killing process

                            »»»»»»»»»»»»»»»»»»»»»»»» hosts

                            127.0.0.1 localhost

                            »»»»»»»»»»»»»»»»»»»»»»»» VACFix

                            VACFix
                            Credits: Malware Analysis & Diagnostic
                            Code: S!Ri

                            »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                            S!Ri's WS2Fix: LSP not Found.

                            »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                            GenericRenosFix by S!Ri

                            »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

                            »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                            IEDFix

                            Et un nouveau HIJACKTHIS au cas ou:

                            Logfile of Trend Micro HijackThis v2.0.2
                            Scan saved at 09:29:38, on 18/05/2009
                            Platform: Windows Vista SP1 (WinNT 6.00.1905)
                            MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                            Boot mode: Normal

                            Running processes:
                            C:\Windows\system32\taskeng.exe
                            C:\Windows\system32\Dwm.exe
                            C:\Windows\Explorer.EXE
                            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                            C:\Program Files\Dell Support Center\bin\sprtcmd.exe
                            C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
                            C:\Windows\System32\rundll32.exe
                            C:\Windows\System32\rundll32.exe
                            C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
                            C:\Program Files\iTunes\iTunesHelper.exe
                            C:\Program Files\Nuance\PDF Professional 5\PdfPro5Hook.exe
                            C:\Program Files\McAfee.com\Agent\mcagent.exe
                            C:\Program Files\Java\jre6\bin\jusched.exe
                            C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                            C:\Windows\ehome\ehtray.exe
                            C:\Program Files\Windows Media Player\wmpnscfg.exe
                            C:\Users\Andrew\AppData\Local\Google\Update\GoogleUpdate.exe
                            C:\Program Files\google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                            C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
                            C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
                            C:\Program Files\Dell\QuickSet\quickset.exe
                            C:\Windows\ehome\ehmsas.exe
                            C:\Windows\System32\rundll32.exe
                            c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
                            C:\Program Files\Dell Support Center\gs_agent\dsc.exe
                            C:\Users\Andrew\Desktop\HiJackThis.exe
                            C:\Program Files\Synaptics\SynTP\SynTPHelper.exe

                            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                            R3 - URLSearchHook: livetvbar Toolbar - {ad55c869-668e-457c-b270-0cfb2f61116f} - C:\Program Files\livetvbar\tblive.dll
                            O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                            O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                            O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
                            O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
                            O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
                            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                            O2 - BHO: livetvbar Toolbar - {ad55c869-668e-457c-b270-0cfb2f61116f} - C:\Program Files\livetvbar\tblive.dll
                            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
                            O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                            O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
                            O2 - BHO: ZeonIEEventHelper Class - {DA986D7D-CCAF-47B2-84FE-BFA1549BEBF9} - C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll
                            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                            O3 - Toolbar: Nuance PDF - {E3286BF1-E654-42FF-B4A6-5E111731DF6B} - C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll
                            O3 - Toolbar: livetvbar Toolbar - {ad55c869-668e-457c-b270-0cfb2f61116f} - C:\Program Files\livetvbar\tblive.dll
                            O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                            O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                            O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
                            O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
                            O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
                            O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                            O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
                            O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
                            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                            O4 - HKLM\..\Run: [PDFHook] C:\Program Files\Nuance\PDF Professional 5\pdfpro5hook.exe
                            O4 - HKLM\..\Run: [PDF5 Registry Controller] C:\Program Files\Nuance\PDF Professional 5\RegistryController.exe
                            O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
                            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                            O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                            O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
                            O4 - HKCU\..\Run: [update 000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000] %AppData%\wunauclt.exe
                            O4 - HKCU\..\Run: [ setup] C:\Users\Andrew\Downloads\eMule\Incoming\Football Manager (2009).exe
                            O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                            O4 - HKCU\..\Run: [Google Update] "C:\Users\Andrew\AppData\Local\Google\Update\GoogleUpdate.exe" /c
                            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                            O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                            O4 - Global Startup: BTTray.lnk = ?
                            O4 - Global Startup: PHOTOfunSTUDIO -viewer-.lnk = C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
                            O4 - Global Startup: QuickSet.lnk = ?
                            O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIEAppend.HTML
                            O8 - Extra context menu item: Ajouter le contenu des liens sélectionnés à un fichier PDF existant - res://C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIEAppendSelLinks.HTML
                            O8 - Extra context menu item: Ajouter le contenu du lien à un fichier PDF existant - res://C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIEAppend.HTML
                            O8 - Extra context menu item: Créer des fichiers PDF à partir des liens sélectionnés - res://C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIECaptureSelLinks.HTML
                            O8 - Extra context menu item: Créer fichier PDF - res://C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIECapture.HTML
                            O8 - Extra context menu item: Créer un fichier PDF depuis le contenu du lien - res://C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIECapture.HTML
                            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                            O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                            O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
                            O8 - Extra context menu item: Ouvrir avec Nuance PDF Converter 5.0 - res://C:\Program Files\Nuance\PDF Professional 5\cnvres_fre.dll /100
                            O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                            O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                            O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                            O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                            O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                            O13 - Gopher Prefix:
                            O15 - Trusted Zone: http://*.mcafee.com
                            O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                            O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                            O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
                            O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
                            O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
                            O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                            O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                            O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                            O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                            O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
                            O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                            O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
                            O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
                            O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
                            O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
                            O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
                            O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
                            O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
                            O23 - Service: PDFProFiltSrv - Nuance Communications, Inc. - C:\Program Files\Nuance\PDF Professional 5\PDFProFiltSrv.exe
                            O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                            O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
                            O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
                            O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
                            O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                            0