Infection fakeAV-AH trj

Résolu
Bonjour,
Mon Anti virus avast m'indique que mon ordi est infecté par un virus fake AV-AH trj et me propose de le mettre en quarantaine. Mais depuis ce virus revient sans arrêt par l'intermédiaire d'une fenêtre. Et je n'arrive pas à m'en débarasser définitivement.
Voici ce qu'indique la mise en quarentaine:
Temporary internet files/low/content/IE5./AT78sb5P
Temporary internet files/low/content/IE5./1NVPw5ZO
Est ce que vous pourriez svp m'aider? D'avance je vous remercie.
Système d'exploitation :Vista
Configuration: Windows Vista Internet Explorer 8.0

40 réponses

Résumé de la discussion

Une infection signalée par un antivirus affiche une menace factice et une fenêtre persistance, sur un système Windows Vista avec Internet Explorer 8, et la quarantaine désigne des fichiers temporaires comme origine du problème. Les analyses montrent des éléments malveillants quarantinés par Malwarebytes (Trojan.Agent, Worm.KoobFace, Malware.Trace), tandis que les rapports RSIT et HijackThis révèlent des extensions et des scripts liés à des barres d’outils et des entrées de démarrage. En outre, les journaux détaillent de nombreuses barres d’outils et composants au démarrage, des modifs de pages d’accueil et de recherche, ainsi qu’un fichier en cours d’analyse dans une file d’attente, signe d’intervention en cours.

Bobot (l’IA à votre service)
  1. Bonjour

    Fais ceci stp :

    I)Telecharger random's system information tool: (RSIT)

    Téléchargement de RSIT ici

    1)Double cliquer sur l’icône RSIT.exe .
    2)Cliquer sur "continue".
    3)L’analyse terminée, deux fichiers s’ouvriront, poste moi les 2 rapports stp.
    4)Si les 2 fichiers ne s’ouvrent pas, va dans C:\rsit , tu y trouvera les 2 fichiers info.txt et log.txt.
    0
    1. Merci pour ton aide. Voici les rapports:
      Logfile of random's system information tool 1.06 (written by random/random)
      Run by chris at 2009-08-11 10:49:57
      Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
      System drive C: has 227 GB (76%) free of 298 GB
      Total RAM: 1918 MB (49% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 10:50:08, on 11/08/2009
      Platform: Windows Vista SP1 (WinNT 6.00.1905)
      MSIE: Internet Explorer v8.00 (8.00.6001.18813)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\Dwm.exe
      C:\Windows\system32\taskeng.exe
      C:\Windows\Explorer.EXE
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\hp\support\hpsysdrv.exe
      C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
      C:\WINDOWS\RtHDVCpl.exe
      C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
      C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
      C:\Program Files\Alwil Software\Avast4\ashDisp.exe
      C:\WINDOWS\System32\rundll32.exe
      C:\WINDOWS\pp10.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\WINDOWS\ehome\ehtray.exe
      C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Windows\system32\schtasks.exe
      C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
      C:\Windows\ehome\ehmsas.exe
      C:\Windows\system32\jusched.exe
      C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
      C:\hp\kbd\kbd.exe
      C:\Windows\system32\conime.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Alwil Software\Avast4\ashChest.exe
      C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Windows Live Toolbar\msn_sl.exe
      C:\Windows\system32\SearchFilterHost.exe
      C:\Users\chris\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JXXJ6H4X\RSIT[1].exe
      C:\Program Files\trend micro\chris.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/nl-be?cobrand=hp.msn.com&ocid=HPDHP&pc=HPDTDF&checklang=1
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/nl-be?cobrand=hp.msn.com&ocid=HPDHP&pc=HPDTDF&checklang=1
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      O1 - Hosts: ::1 localhost
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
      O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
      O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
      O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
      O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
      O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
      O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      O4 - HKLM\..\Run: [sysldtray] c:\windows\ld12.exe
      O4 - HKLM\..\Run: [pp] c:\windows\pp10.exe
      O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
      O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
      O4 - HKCU\..\Run: [VeohPlugin] "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
      O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
      O4 - HKCU\..\Run: [Spyware & Adware Removal] "C:\Program Files\Spyware & Adware Removal\SAR.exe" NoHint
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
      O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
      O13 - Gopher Prefix:
      O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: Service Google Update (gupdate1c9c39b824dbafb) (gupdate1c9c39b824dbafb) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
      O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
      O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
      O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
      O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
      O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
      O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
      0
      1. Et voici le deuxième:
        nfo.txt logfile of random's system information tool 1.06 2009-08-11 10:50:11

        ======Uninstall list======

        -->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
        -->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
        Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
        Adobe Flash Player 10 Plugin-->MsiExec.exe /X{ECA1A3B6-898F-4DCE-9F04-714CF3BA126B}
        Adobe Reader 8.1.0 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81000000003}
        Adobe® Photoshop® Album Edition Découverte 3.0-->MsiExec.exe /I{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}
        Assistant de connexion Windows Live-->MsiExec.exe /I{D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
        avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
        Disc2Phone-->MsiExec.exe /I{FFAB5ABB-8AAB-42E2-847F-1743E51E01E9}
        DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
        DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
        DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
        DivX Plus DirectShow Filters-->C:\Program Files\DivX\DivXDSFiltersUninstall.exe /DSFILTERS
        DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
        eMule-->"C:\Program Files\eMule\Uninstall.exe"
        Google Chrome-->"C:\Program Files\Google\Chrome\Application\2.0.172.39\Installer\setup.exe" --uninstall --system-level
        Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_E582EA556D8DE101.exe" /uninstall
        Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
        Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
        Hemera Products-->C:\PROGRA~1\HEMERA~1\UNWISE.EXE C:\PROGRA~1\HEMERA~1\INSTALL.LOG
        Hewlett-Packard Active Check-->MsiExec.exe /X{254C37AA-6B72-4300-84F6-98A82419187E}
        Hewlett-Packard Asset Agent for Health Check-->MsiExec.exe /X{669D4A35-146B-4314-89F1-1AC3D7B88367}
        HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
        Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
        Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
        HP Active Support Library 32 bit components-->MsiExec.exe /I{6D3DB611-D5E8-4E4B-8952-0D3F549F9CC6}
        HP Active Support Library-->C:\Program Files\InstallShield Installation Information\{0A47BAFF-D4FF-4BD3-96CA-02A22EA62722}\setup.exe -runfromtemp -l0x0409
        HP Customer Experience Enhancements-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AB5E289E-76BF-4251-9F3F-9B763F681AE0}\setup.exe" -l0x9 -removeonly
        HP Customer Feedback-->MsiExec.exe /I{9DBA770F-BF73-4D39-B1DF-6035D95268FC}
        HP Easy Setup - Frontend-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40F7AED3-0C7D-4582-99F6-484A515C73F2}\setup.exe" -l0x9 -removeonly
        HP On-Screen Cap/Num/Scroll Lock Indicator-->C:\Windows\system32\OsdRemove.exe
        HP Photosmart Essential 2.01-->C:\Program Files\HP\Digital Imaging\PhotoSmartEssential\hpzscr01.exe -datfile hpqbud13.dat
        HP Picasso Media Center Add-In-->MsiExec.exe /I{55979C41-7D6A-49CC-B591-64AC1BBE2C8B}
        HP Product Detection-->MsiExec.exe /X{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}
        HP Total Care Advisor-->MsiExec.exe /X{0DDA7620-4F8B-43B3-8828-CA5EE292FA3B}
        HP Update-->MsiExec.exe /X{7059BDA7-E1DB-442C-B7A1-6144596720A4}
        Java(TM) SE Runtime Environment 6 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
        LimeWire 5.1.4-->"C:\Program Files\LimeWire\uninstall.exe"
        LiveUpdate 3.2 (Symantec Corporation)-->"C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
        LiveUpdate Notice (Symantec Corporation)-->MsiExec.exe /X{DBA4DB9D-EE51-4944-A419-98AB1F1249C8}
        Microsoft .NET Framework 1.1 Hotfix (KB929729)-->"C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\M929729\M929729Uninstall.msp"
        Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
        Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
        Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
        Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
        Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
        Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
        Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
        Microsoft Works-->MsiExec.exe /I{6B1CB38D-E2E4-4A30-933D-EFDEBA76AD9C}
        MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
        MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
        muvee autoProducer 6.0-->C:\Program Files\InstallShield Installation Information\{14AF024E-2E3B-49D0-A175-D1C1A06B155A}\setup.exe -runfromtemp -l0x040c -removeonly
        MyRo Points 4-->C:\Program Files\Puntenboek\Setup.inf /r
        NVIDIA Drivers-->C:\Windows\system32\NVUNINST.EXE UninstallGUI
        OpenOffice.org 2.4-->MsiExec.exe /I{B6694BAA-7604-46AA-A41F-B5F1E6DADE7A}
        Outils de diagnostic du matériel-->C:\Program Files\PC-Doctor 5 for Windows\uninst.exe
        Python 2.5-->MsiExec.exe /I{0A2C5854-557E-48C8-835A-3B9F074BDCAA}
        Readiris 7.5-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9BFFB382-0B2C-11D6-AB3E-000102B0F79A}\setup.exe" -l0x40c
        Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
        Roxio Activation Module-->MsiExec.exe /I{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}
        Roxio Creator Audio-->MsiExec.exe /X{83FFCFC7-88C6-41c6-8752-958A45325C82}
        Roxio Creator Basic v9-->MsiExec.exe /X{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}
        Roxio Creator Copy-->MsiExec.exe /X{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}
        Roxio Creator Data-->MsiExec.exe /X{0D397393-9B50-4c52-84D5-77E344289F87}
        Roxio Creator EasyArchive-->MsiExec.exe /X{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}
        Roxio Creator Tools-->MsiExec.exe /X{0394CDC8-FABD-4ed8-B104-03393876DFDF}
        Roxio Express Labeler 3-->MsiExec.exe /X{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
        Roxio MyDVD Basic v9-->MsiExec.exe /X{938B1CD7-7C60-491E-AA90-1F1888168240}
        Solution de clavier multimédia amélioré-->C:\HP\KBD\Install.exe /u
        VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
        Veoh Web Player Beta-->"C:\Program Files\Veoh Networks\VeohWebPlayer\uninst.exe"
        Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
        Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
        Windows Live Toolbar-->"C:\Program Files\Windows Live Toolbar\UnInstall.exe" {0A8C97AD-DEED-4894-B446-3ABA95A77D0D}
        Windows Live Toolbar-->MsiExec.exe /X{0A8C97AD-DEED-4894-B446-3ABA95A77D0D}

        ======Security center information======

        AV: avast! antivirus 4.8.1229 [VPS 090102-0]
        AS: Windows Defender
        AS: avast! antivirus 4.8.1229 [VPS 090102-0]

        ======System event log======

        Computer Name: PC-de-chris
        Event Code: 6008
        Message: L'arrêt système précédant à 14:26:50 le 2/08/2008 n'était pas prévu.
        Record Number: 22692
        Source Name: EventLog
        Time Written: 20080802123250.000000-000
        Event Type: Erreur
        User:

        Computer Name: PC-de-chris
        Event Code: 1003
        Message:
        Record Number: 22696
        Source Name: Microsoft-Windows-Dhcp-Client
        Time Written: 20080802123252.000000-000
        Event Type: Avertissement
        User:

        Computer Name: PC-de-chris
        Event Code: 1002
        Message: Le bail de l'adresse IP 192.168.1.2 pour la carte réseau dont l'adresse réseau est 001E90015947 a été refusé par le serveur DHCP 192.168.1.1 (celui-ci a envoyé un message DHCPNACK).
        Record Number: 22697
        Source Name: Microsoft-Windows-Dhcp-Client
        Time Written: 20080802123252.000000-000
        Event Type: Erreur
        User:

        Computer Name: PC-de-chris
        Event Code: 15016
        Message: Impossible d’initialiser le package de sécurité Kerberos pour l’authentification côté serveur. Le champ de données contient le numéro de l’erreur.
        Record Number: 22698
        Source Name: Microsoft-Windows-HttpEvent
        Time Written: 20080802123256.643535-000
        Event Type: Erreur
        User:

        Computer Name: PC-de-chris
        Event Code: 6008
        Message: L'arrêt système précédant à 19:00:44 le 2/08/2008 n'était pas prévu.
        Record Number: 22799
        Source Name: EventLog
        Time Written: 20080803005117.000000-000
        Event Type: Erreur
        User:

        =====Application event log=====

        Computer Name: PC-de-chris
        Event Code: 8194
        Message: Erreur du service de cliché instantané des volumes : erreur lors de l’interrogation de l’interface IVssWriterCallback. hr = 0x80070005. Cette erreur est souvent due à des paramètres de sécurité incorrects dans le processus du rédacteur ou du demandeur.

        Opération :
        Données du rédacteur en cours de collecte

        Contexte :
        ID de classe du rédacteur: {e8132975-6f93-4464-a53e-1050253ae220}
        Nom du rédacteur: System Writer
        ID d’instance du rédacteur: {1271e85a-b016-4634-bd73-7b58e11492c3}
        Record Number: 18574
        Source Name: VSS
        Time Written: 20090810192416.000000-000
        Event Type: Erreur
        User:

        Computer Name: PC-de-chris
        Event Code: 1000
        Message: Application défaillante product.exe, version 2.0.2.1, horodatage 0x48e31b07, module défaillant Spywarefighter.dll, version 2.0.9.9, horodatage 0x48e31b25, code d’exception 0xc0000005, décalage d’erreur 0x0000d56a, ID du processus 0x1488, heure de début de l’application 0x01ca1a01f5fefe87.
        Record Number: 18674
        Source Name: Application Error
        Time Written: 20090810213431.000000-000
        Event Type: Erreur
        User:

        Computer Name: PC-de-chris
        Event Code: 11
        Message: Échec de l'extraction de la liste racine tierce partie depuis le fichier CAB de mise à jour automatique à : <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> avec l'erreur : Un certificat requis n'est pas dans sa période de validité selon la vérification par rapport à l'horloge système en cours ou le tampon daté dans le fichier signé.
        .
        Record Number: 18706
        Source Name: Microsoft-Windows-CAPI2
        Time Written: 20090811005731.000000-000
        Event Type: Erreur
        User:

        Computer Name: PC-de-chris
        Event Code: 1002
        Message: Le programme ToolsCleaner2.exe version 0.0.0.0 a cessé d’interagir avec Windows et a été fermé. Pour déterminer si des informations supplémentaires sont disponibles, consultez l’historique du problème dans l’application Rapports et solutions aux problèmes du Panneau de configuration. ID de processus : 1398 Heure de début : 01ca1a5332a6cb40 Heure de fin : 31
        Record Number: 18715
        Source Name: Application Hang
        Time Written: 20090811071658.000000-000
        Event Type: Erreur
        User:

        Computer Name: PC-de-chris
        Event Code: 11
        Message: Échec de l'extraction de la liste racine tierce partie depuis le fichier CAB de mise à jour automatique à : <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> avec l'erreur : Un certificat requis n'est pas dans sa période de validité selon la vérification par rapport à l'horloge système en cours ou le tampon daté dans le fichier signé.
        .
        Record Number: 18718
        Source Name: Microsoft-Windows-CAPI2
        Time Written: 20090811083406.000000-000
        Event Type: Erreur
        User:

        =====Security event log=====

        Computer Name: PC-de-chris
        Event Code: 1108
        Message: Le service de journalisation des événements a rencontré une erreur lors du traitement d’un événement entrant publié à partir de Microsoft-Windows-Security-Auditing.
        Record Number: 23821
        Source Name: Microsoft-Windows-Eventlog
        Time Written: 20090622093950.169400-000
        Event Type: Succès de l'audit
        User:

        Computer Name: PC-de-chris
        Event Code: 1108
        Message: Le service de journalisation des événements a rencontré une erreur lors du traitement d’un événement entrant publié à partir de Microsoft-Windows-Security-Auditing.
        Record Number: 23822
        Source Name: Microsoft-Windows-Eventlog
        Time Written: 20090622093950.169400-000
        Event Type: Succès de l'audit
        User:

        Computer Name: PC-de-chris
        Event Code: 1108
        Message: Le service de journalisation des événements a rencontré une erreur lors du traitement d’un événement entrant publié à partir de Microsoft-Windows-Security-Auditing.
        Record Number: 23823
        Source Name: Microsoft-Windows-Eventlog
        Time Written: 20090622093950.169400-000
        Event Type: Succès de l'audit
        User:

        Computer Name: PC-de-chris
        Event Code: 1108
        Message: Le service de journalisation des événements a rencontré une erreur lors du traitement d’un événement entrant publié à partir de Microsoft-Windows-Security-Auditing.
        Record Number: 23824
        Source Name: Microsoft-Windows-Eventlog
        Time Written: 20090622093950.169400-000
        Event Type: Succès de l'audit
        User:

        Computer Name: PC-de-chris
        Event Code: 1108
        Message: Le service de journalisation des événements a rencontré une erreur lors du traitement d’un événement entrant publié à partir de Microsoft-Windows-Security-Auditing.
        Record Number: 23825
        Source Name: Microsoft-Windows-Eventlog
        Time Written: 20090622093950.169400-000
        Event Type: Succès de l'audit
        User:

        ======Environment variables======

        "ComSpec"=%SystemRoot%\system32\cmd.exe
        "FP_NO_HOST_CHECK"=NO
        "OS"=Windows_NT
        "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\hp\bin\Python;c:\Program Files\Common Files\Roxio Shared\DLLShared\;c:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\;C:\Program Files\Common Files\DivX Shared\
        "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
        "PROCESSOR_ARCHITECTURE"=x86
        "TEMP"=%SystemRoot%\TEMP
        "TMP"=%SystemRoot%\TEMP
        "USERNAME"=SYSTEM
        "windir"=%SystemRoot%
        "PROCESSOR_LEVEL"=15
        "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 107 Stepping 1, AuthenticAMD
        "PROCESSOR_REVISION"=6b01
        "NUMBER_OF_PROCESSORS"=2
        "RoxioCentral"=c:\Program Files\Common Files\Roxio Shared\9.0\Roxio Central33\
        "PLATFORM"=HPD
        "PCBRAND"=Pavilion
        "OnlineServices"=Services en ligne

        -----------------EOF-----------------
        Merci
        0
        1. Tu as pas mal de backdoor sur ton pc, on va enlevé tous ça.

          I)Télécharge OTM :

          http://www.geekstogo.com/forum/files/file/402-otm-oldtimers-move-it/

          Double-cliquer sur OTM.exe pour le lancer.
          Copier la liste qui se trouve en gras ci-dessous et colle-la dans le cadre de gauche de OTM sous "Paste Instructions for Items to be Moved".

          Instructions:

          :Processes
          ld12.exe
          pp10.exe
          SAR.exe

          :Reg
          [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "sysldtray"=-
          "pp"=-
          [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "Spyware & Adware Removal"=-

          :Files
          c:\windows\ld12.exe
          c:\windows\pp10.exe
          C:\Program Files\Spyware & Adware Removal

          :Commands
          [emptytemp]
          [start explorer]


          cliquer sur MoveIt! pour lancer la suppression.
          Le résultat apparaitra dans le cadre "Results".
          Cliquer sur "Exit" pour fermer.
          Envoi moi le rapport stp.
          0
          1. Voici le rapport OTM:
            All processes killed
            Error: Unable to interpret <Instructions: > in the current context!
            ========== PROCESSES ==========
            No active process named ld12.exe was found!
            No active process named pp10.exe was found!
            No active process named SAR.exe was found!
            ========== REGISTRY ==========
            Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\sysldtray scheduled to be deleted on reboot.
            Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\pp scheduled to be deleted on reboot.
            Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Spyware & Adware Removal not found.
            ========== FILES ==========
            File/Folder c:\windows\ld12.exe not found.
            File/Folder c:\windows\pp10.exe not found.
            File/Folder C:\Program Files\Spyware & Adware Removal not found.
            ========== COMMANDS ==========

            [EMPTYTEMP]

            User: All Users

            User: chris
            File delete failed. C:\Users\chris\AppData\Local\Temp\BITF1DC.tmp scheduled to be deleted on reboot.
            ->Temp folder emptied: 36256346 bytes
            ->Temporary Internet Files folder emptied: 1474604 bytes
            ->Java cache emptied: 0 bytes
            ->Google Chrome cache emptied: 0 bytes

            User: Default
            ->Temp folder emptied: 0 bytes
            File delete failed. C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZF0SOE0W\desktop.ini scheduled to be deleted on reboot.
            File delete failed. C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HHZXP0BA\desktop.ini scheduled to be deleted on reboot.
            File delete failed. C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6242M2DG\desktop.ini scheduled to be deleted on reboot.
            File delete failed. C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4YLOWQ4Y\desktop.ini scheduled to be deleted on reboot.
            File delete failed. C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini scheduled to be deleted on reboot.
            File delete failed. C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
            File delete failed. C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini scheduled to be deleted on reboot.
            ->Temporary Internet Files folder emptied: 33170 bytes

            User: Default User
            ->Temp folder emptied: 0 bytes
            File delete failed. C:\Users\Default User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZF0SOE0W\desktop.ini scheduled to be deleted on reboot.
            File delete failed. C:\Users\Default User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HHZXP0BA\desktop.ini scheduled to be deleted on reboot.
            File delete failed. C:\Users\Default User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6242M2DG\desktop.ini scheduled to be deleted on reboot.
            File delete failed. C:\Users\Default User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4YLOWQ4Y\desktop.ini scheduled to be deleted on reboot.
            File delete failed. C:\Users\Default User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini scheduled to be deleted on reboot.
            File delete failed. C:\Users\Default User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
            File delete failed. C:\Users\Default User\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini scheduled to be deleted on reboot.
            ->Temporary Internet Files folder emptied: 33170 bytes

            User: Public

            %systemdrive% .tmp files removed: 0 bytes
            %systemroot% .tmp files removed: 0 bytes
            %systemroot%\System32 .tmp files removed: 0 bytes
            Windows Temp folder emptied: 0 bytes
            RecycleBin emptied: 0 bytes

            Total Files Cleaned = 36,05 mb

            OTM by OldTimer - Version 3.0.0.6 log created on 08112009_140254

            Files moved on Reboot...
            File C:\Users\chris\AppData\Local\Temp\BITF1DC.tmp not found!
            File move failed. C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZF0SOE0W\desktop.ini scheduled to be moved on reboot.
            File move failed. C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HHZXP0BA\desktop.ini scheduled to be moved on reboot.
            File move failed. C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6242M2DG\desktop.ini scheduled to be moved on reboot.
            File move failed. C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4YLOWQ4Y\desktop.ini scheduled to be moved on reboot.
            File move failed. C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini scheduled to be moved on reboot.
            File move failed. C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini scheduled to be moved on reboot.
            File move failed. C:\Users\Default User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZF0SOE0W\desktop.ini scheduled to be moved on reboot.
            File move failed. C:\Users\Default User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HHZXP0BA\desktop.ini scheduled to be moved on reboot.
            File move failed. C:\Users\Default User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6242M2DG\desktop.ini scheduled to be moved on reboot.
            File move failed. C:\Users\Default User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4YLOWQ4Y\desktop.ini scheduled to be moved on reboot.
            File move failed. C:\Users\Default User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini scheduled to be moved on reboot.
            File move failed. C:\Users\Default User\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini scheduled to be moved on reboot.

            Registry entries deleted on Reboot...
            Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\sysldtray scheduled to be deleted on reboot.
            Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\pp scheduled to be deleted on reboot.
            Merci
            0
            1. Peut tu mereposter un nouveau rapport RSIT stp.
              0
              1. Merci de m'aider, entre temps, un collègue m'a conseillé d'enlever avast pour installer Avira antivir personnal. J'ai lancé un scan et il a trouvé pas mal de choses. J'espère que j'ai bien fait.
                Voici le nouveau rapport RSIT:
                Logfile of random's system information tool 1.06 (written by random/random)
                Run by chris at 2009-08-11 14:23:13
                Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
                System drive C: has 228 GB (77%) free of 298 GB
                Total RAM: 1918 MB (45% free)

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 14:23:55, on 11/08/2009
                Platform: Windows Vista SP1 (WinNT 6.00.1905)
                MSIE: Internet Explorer v8.00 (8.00.6001.18813)
                Boot mode: Normal

                Running processes:
                C:\Windows\system32\taskeng.exe
                C:\Windows\system32\Dwm.exe
                C:\Windows\Explorer.EXE
                C:\Program Files\Windows Defender\MSASCui.exe
                C:\hp\support\hpsysdrv.exe
                C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
                C:\WINDOWS\RtHDVCpl.exe
                C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
                C:\Windows\system32\schtasks.exe
                C:\WINDOWS\System32\rundll32.exe
                C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                C:\Program Files\Windows Sidebar\sidebar.exe
                C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                C:\WINDOWS\ehome\ehtray.exe
                C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
                C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                C:\Windows\system32\jusched.exe
                C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
                C:\Windows\ehome\ehmsas.exe
                C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
                C:\hp\kbd\kbd.exe
                C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\program files\avira\antivir desktop\avcenter.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Windows\system32\SearchFilterHost.exe
                C:\Users\chris\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C5L6BAJU\RSIT[1].exe
                C:\Program Files\trend micro\chris.exe

                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/nl-be?cobrand=hp.msn.com&ocid=HPDHP&pc=HPDTDF&checklang=1
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/nl-be?cobrand=hp.msn.com&ocid=HPDHP&pc=HPDTDF&checklang=1
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                O1 - Hosts: ::1 localhost
                O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
                O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
                O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
                O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
                O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
                O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                O4 - HKLM\..\Run: [sysldtray] c:\windows\ld12.exe
                O4 - HKLM\..\Run: [pp] c:\windows\pp10.exe
                O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
                O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                O4 - HKCU\..\Run: [VeohPlugin] "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
                O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
                O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                O13 - Gopher Prefix:
                O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                O23 - Service: Service Google Update (gupdate1c9c39b824dbafb) (gupdate1c9c39b824dbafb) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
                O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                0
                1. Contributeur sécurité
                  Salut vous deux,

                  pour suivre ...

                  ===============

                  xx-juju74,

                  *ton script OTM est foireux ...

                  *ne pas oublier : Vista !

                  =)

                  0
                  1. Bonjour ske69,

                    Qu-es-ce que l'on doit mettre dans le script sous vista alors ?
                    0
                    1. Contributeur sécurité
                      Re,

                      infection Koobface ....

                      tu as mi des termes en trop dans le script ... Il y manque des éléments ... L'UAC doit être désactivé ... ;)

                      Chris 2009,

                      fait ceci dans l'ordre stp :

                      1- protocole à suivre pour Windows Vista :

                      *Désactiver le contrôle des comptes utilisateurs ou UAC (le réactiver seulement à la fin de la désinfection) :

                      Aller dans "démarrer" puis "panneau de configuration" :
                      --->Sur la droite de la fenêtre , cliques sur " affichage classique "
                      --->Double-Cliquer sur l'icône "Comptes d'utilisateurs"
                      --->Cliquer ensuite sur "Activer ou désactiver le contrôle ..." .
                      --->Décocher la case "utlisiser le contrôle ..." et cliquer sur OK .
                      --->Redémarrer le PC !

                      Tutos :
                      http://pagesperso-orange.fr/NosTools/uac_vista.html
                      https://forum.malekal.com/viewtopic.php?f=59&t=6517

                      * Important :
                      Pour installer ou pour lancer les outils, que tu utiliseras au court de la désinfection, fais toujours ainsi :
                      clique DROIT ( sur le setup d'installe ou sur l'outil ) -> choisis " Exécuter entant qu'administrateur " .
                      Fais ceci systématiquement ! ...

                      une fois ceci fait et pris en compte , enchaine :

                      ==========================

                      2- ! Déconnecte toi et ferme toutes tes applications en cours !

                      Double clique sur "OTM.exe" pour ouvrir le prg .
                      Puis copie ce qui se trouve en citation ci-dessous,

                      :Services
                      browserctldrv
                      browserctl

                      :Reg
                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                      "sysldtray"=-
                      "pp"=-

                      :Files
                      C:\Program Files\BrowserCtl

                      :Commands
                      [purity]
                      [emptytemp]
                      [Reboot]


                      et colle le dans le cadre de gauche de OTM :
                      Paste Instructions for items to be moved.
                      (ne touche à rien d'autre !)

                      -> clique sur MoveIt! pour lancer la suppression.
                      -> laisse travailler l'outil ...

                      -> une fois finis , un petite fenêtre s'ouvre : clique sur " Yes " .

                      Ton PC va redémarrer de lui même pour finir la suppression ...

                      Lors du redémarrage , si on te demande d'autoriser l'exécution d' OTM , accepte ( pour que l'outil finisse son boulot ... ).

                      -->Poste le contenu du rapport qui se trouve dans le dossier "C:\_OTM\MovedFiles"
                      ( " xxxx2009_xxxxxx.log " où les "x" correspondent au jour et à l'heure de l'utilisation ).

                      ======================

                      3- Vérifie ceci et fait les modifs si nécessaire :

                      *Sur Firefox, Menu Editions / Préférences puis onglet Avancés.
                      Cliquez sur Réseau et Paramètres.
                      Choisissez "Ne pas mettre de Proxy".

                      *Sur Internet Explorer, menu Outils / Options Internet.
                      Onglet Connexions puis en bas, désactiver le proxy.

                      =========================

                      4- Redémarre l'ordinateur !

                      Puis refais un scan RSIT , poste le nouveau rapport "Log.txt" obtenu et attends la suite ....

                      0
                      1. Bonjour sKe69,
                        Je te remercie de m'aider avec xx-juju74.J'ai fait tout ce que tu m'as dit. Voici le rapport:
                        All processes killed
                        Error: Unable to interpret <Services > in the current context!
                        Error: Unable to interpret <browserctldrv > in the current context!
                        Error: Unable to interpret <browserctl > in the current context!
                        ========== REGISTRY ==========
                        Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\sysldtray deleted successfully.
                        Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\pp deleted successfully.
                        ========== FILES ==========
                        C:\Program Files\BrowserCtl moved successfully.
                        ========== COMMANDS ==========

                        [EMPTYTEMP]

                        User: All Users

                        User: chris
                        ->Temp folder emptied: 36281652 bytes
                        File delete failed. C:\Users\chris\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
                        ->Temporary Internet Files folder emptied: 1597270 bytes
                        ->Java cache emptied: 0 bytes
                        ->Google Chrome cache emptied: 0 bytes

                        User: Default
                        ->Temp folder emptied: 0 bytes
                        ->Temporary Internet Files folder emptied: 33170 bytes

                        User: Default User
                        ->Temp folder emptied: 0 bytes
                        ->Temporary Internet Files folder emptied: 0 bytes

                        User: Public

                        %systemdrive% .tmp files removed: 0 bytes
                        %systemroot% .tmp files removed: 0 bytes
                        %systemroot%\System32 .tmp files removed: 0 bytes
                        Windows Temp folder emptied: 24869991 bytes
                        RecycleBin emptied: 0 bytes

                        Total Files Cleaned = 59,87 mb
                        0
                        1. Re, je n'ai ps réussi à faire les modifs, je ne sais pas exactement ou je dois aller. Je suis débutant...
                          Voici le nouveau rapport RSIT:
                          Logfile of random's system information tool 1.06 (written by random/random)
                          Run by chris at 2009-08-11 15:41:49
                          Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
                          System drive C: has 227 GB (76%) free of 298 GB
                          Total RAM: 1918 MB (54% free)

                          Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 15:42:10, on 11/08/2009
                          Platform: Windows Vista SP1 (WinNT 6.00.1905)
                          MSIE: Internet Explorer v8.00 (8.00.6001.18813)
                          Boot mode: Normal

                          Running processes:
                          C:\Windows\system32\Dwm.exe
                          C:\Windows\Explorer.EXE
                          C:\Windows\system32\taskeng.exe
                          C:\Program Files\Windows Defender\MSASCui.exe
                          C:\hp\support\hpsysdrv.exe
                          C:\hp\KBD\KbdStub.exe
                          C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
                          C:\WINDOWS\RtHDVCpl.exe
                          C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                          C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
                          C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                          C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
                          C:\Windows\system32\schtasks.exe
                          C:\WINDOWS\System32\rundll32.exe
                          C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                          C:\Program Files\Windows Sidebar\sidebar.exe
                          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                          C:\WINDOWS\ehome\ehtray.exe
                          C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
                          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          C:\Windows\system32\jusched.exe
                          C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
                          C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
                          C:\Windows\ehome\ehmsas.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Program Files\Windows Live Toolbar\msn_sl.exe
                          C:\Windows\system32\SearchProtocolHost.exe
                          C:\Windows\system32\SearchFilterHost.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Users\chris\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7FNKWGYR\RSIT[1].exe
                          C:\Program Files\trend micro\chris.exe

                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/nl-be?cobrand=hp.msn.com&ocid=HPDHP&pc=HPDTDF&checklang=1
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/nl-be?cobrand=hp.msn.com&ocid=HPDHP&pc=HPDTDF&checklang=1
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                          O1 - Hosts: ::1 localhost
                          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                          O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                          O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                          O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
                          O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                          O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
                          O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
                          O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
                          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                          O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                          O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
                          O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                          O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
                          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                          O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
                          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                          O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                          O4 - HKCU\..\Run: [VeohPlugin] "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
                          O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                          O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
                          O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                          O13 - Gopher Prefix:
                          O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                          O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                          O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                          O23 - Service: Service Google Update (gupdate1c9c39b824dbafb) (gupdate1c9c39b824dbafb) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                          O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                          O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                          O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                          O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                          O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
                          O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                          O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                          O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                          0
                          1. Contributeur sécurité
                            re,

                            tu n'as pas copier/coller correctement le script dans OTM ! ... ( tu as oublié les " : " devant Services ... )

                            donc recommence avec ce qui suit :

                            1- ! Déconnecte toi et ferme toutes tes applications en cours !

                            Double clique sur "OTM.exe" pour ouvrir le prg .
                            Puis copie ce qui se trouve en citation ci-dessous,

                            :Services
                            browserctldrv
                            browserctl

                            :Commands
                            [Reboot]


                            et colle le dans le cadre de gauche de OTM :
                            Paste Instructions for items to be moved.
                            (ne touche à rien d'autre !)

                            -> clique sur MoveIt! pour lancer la suppression.
                            -> laisse travailler l'outil ...

                            -> une fois finis , un petite fenêtre s'ouvre : clique sur " Yes " .

                            Ton PC va redémarrer de lui même pour finir la suppression ...

                            Lors du redémarrage , si on te demande d'autoriser l'exécution d' OTM , accepte ( pour que l'outil finisse son boulot ... ).

                            -->Poste le contenu du rapport qui se trouve dans le dossier "C:\_OTM\MovedFiles"
                            ( " xxxx2009_xxxxxx.log " où les "x" correspondent au jour et à l'heure de l'utilisation ).

                            ========================

                            2- Pour les navigateurs :

                            *ouvre Firefox ( si tu l'as bien sûr) ,
                            - clique sur le menu "outil" / choisis "option".
                            - dans cette fenêtre, Clique sur l'onglet "avancé"
                            - dans cette autre fenêtre , choisis le sous menu " réseau "
                            - au niveau de l'necadré "conexion" , clique sur "paramètre".
                            > là tu coches "Ne pas mettre de Proxy" puis clique sur "OK"

                            *ouvre Internet Explorer,
                            - clique sur le menu Outils / choisis "Options Internet".
                            - va sur l'onglet "Connexions" puis en bas, désactiver le proxy si besoin et valide la modif .

                            ========================

                            3- refais un scan RSIT et poste le nouveau "log.txt" obtenu pour analyse ....

                            0
                            1. Sorry!
                              All processes killed
                              ========== SERVICES/DRIVERS ==========
                              Service\Driver browserctldrv not found.
                              Service\Driver browserctldrv not found.
                              Service\Driver browserctl not found.
                              Service\Driver browserctl not found.
                              ========== REGISTRY ==========
                              Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\sysldtray not found.
                              Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\pp not found.
                              ========== FILES ==========
                              File/Folder C:\Program Files\BrowserCtl not found.
                              ========== COMMANDS ==========

                              [EMPTYTEMP]

                              User: All Users

                              User: chris
                              ->Temp folder emptied: 139225 bytes
                              ->Temporary Internet Files folder emptied: 3396999 bytes
                              ->Java cache emptied: 0 bytes
                              ->Google Chrome cache emptied: 0 bytes

                              User: Default
                              ->Temp folder emptied: 0 bytes
                              ->Temporary Internet Files folder emptied: 0 bytes

                              User: Default User
                              ->Temp folder emptied: 0 bytes
                              ->Temporary Internet Files folder emptied: 0 bytes

                              User: Public

                              %systemdrive% .tmp files removed: 0 bytes
                              %systemroot% .tmp files removed: 0 bytes
                              %systemroot%\System32 .tmp files removed: 0 bytes
                              Windows Temp folder emptied: 632 bytes
                              RecycleBin emptied: 0 bytes

                              Total Files Cleaned = 3,37 mb

                              OTM by OldTimer - Version 3.0.0.6 log created on 08112009_161614

                              Files moved on Reboot...

                              Registry entries deleted on Reboot...
                              0
                              1. Voici le RSIT:
                                Logfile of random's system information tool 1.06 (written by random/random)
                                Run by chris at 2009-08-11 16:20:43
                                Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
                                System drive C: has 227 GB (76%) free of 298 GB
                                Total RAM: 1918 MB (53% free)

                                Logfile of Trend Micro HijackThis v2.0.2
                                Scan saved at 16:21:05, on 11/08/2009
                                Platform: Windows Vista SP1 (WinNT 6.00.1905)
                                MSIE: Internet Explorer v8.00 (8.00.6001.18813)
                                Boot mode: Normal

                                Running processes:
                                C:\Windows\system32\Dwm.exe
                                C:\Windows\Explorer.EXE
                                C:\Windows\system32\taskeng.exe
                                C:\Windows\notepad.exe
                                C:\Program Files\Windows Defender\MSASCui.exe
                                C:\hp\support\hpsysdrv.exe
                                C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
                                C:\WINDOWS\RtHDVCpl.exe
                                C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
                                C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                                C:\Windows\system32\schtasks.exe
                                C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
                                C:\WINDOWS\System32\rundll32.exe
                                C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                                C:\Program Files\Windows Sidebar\sidebar.exe
                                C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                C:\WINDOWS\ehome\ehtray.exe
                                C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
                                C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                C:\Windows\system32\jusched.exe
                                C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
                                C:\Windows\ehome\ehmsas.exe
                                C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
                                C:\Program Files\Internet Explorer\iexplore.exe
                                C:\Program Files\Internet Explorer\iexplore.exe
                                C:\Program Files\Internet Explorer\iexplore.exe
                                C:\Windows\system32\SearchProtocolHost.exe
                                C:\hp\kbd\kbd.exe
                                C:\Program Files\Windows Live Toolbar\msn_sl.exe
                                C:\Users\chris\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZNLLAD59\RSIT[1].exe
                                C:\Program Files\trend micro\chris.exe

                                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/nl-be?cobrand=hp.msn.com&ocid=HPDHP&pc=HPDTDF&checklang=1
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/nl-be?cobrand=hp.msn.com&ocid=HPDHP&pc=HPDTDF&checklang=1
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                O1 - Hosts: ::1 localhost
                                O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                                O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
                                O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                                O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
                                O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
                                O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
                                O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                                O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
                                O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                                O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
                                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                                O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                                O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                                O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
                                O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                                O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                                O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                                O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                O4 - HKCU\..\Run: [VeohPlugin] "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
                                O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                                O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
                                O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                                O13 - Gopher Prefix:
                                O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                                O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                                O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                                O23 - Service: Service Google Update (gupdate1c9c39b824dbafb) (gupdate1c9c39b824dbafb) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                                O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                                O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                                O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                                O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
                                O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                                O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                                O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                                0
                                1. Contributeur sécurité
                                  re,

                                  voilà qui est mieux ....

                                  la suite dans l'ordre :

                                  1- Télécharge CCleaner :
                                  https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/
                                  ou https://www.pcastuces.com/logitheque/ccleaner.htm
                                  Ce logiciel va permettre de supprimer tous les fichiers temporaires et de corriger ton registre .
                                  Lors de l'installation:
                                  -choisis bien "français" en langue .
                                  -avant de cliquer sur le bouton "installer", décoche toutes les "options supplémentaires" sauf les 2 premières.

                                  Un tuto ( aide ):
                                  http://perso.orange.fr/jesses/Docs/Logiciels/CCleaner.htm

                                  ---> Utilisation:
                                  *Décocher dans le menu Options - sous-menu Avancé :
                                  Effacer uniquement les fichiers, du dossier temp de Windows, plus vieux que 48 heures .

                                  ! déconnecte toi et ferme toutes applications en cours !

                                  * va dans "nettoyeur" : fais -analyse- puis -nettoyage-
                                  * va dans "registre" : fais -chercher les erreurs- et -réparer toutes les erreurs-
                                  ( plusieurs fois jusqu'à ce qu'il n'y est plus d'erreur ) .

                                  ( CCleaner : soft à garder sur son PC , super utile pour de bons nettoyages ... )

                                  ========================

                                  2- Télécharge MalwareByte's :
                                  ici https://www.commentcamarche.net/telecharger/securite/14361-malwarebytes-anti-malware/
                                  ou ici : http://www.malwarebytes.org/mbam.php

                                  * Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'instale ) et mets le à jour .

                                  (NB : S'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : https://www.malekal.com/tutorial-aboutbuster/ )

                                  * Potasse le tuto pour te familiariser avec le prg :
                                  https://forum.pcastuces.com/sujet.asp?f=31&s=3
                                  ( cela dis, il est très simple d'utilisation ).

                                  ! Déconnecte toi et ferme toutes applications en cours !

                                  * Lance Malwarebyte's .

                                  Fais un examen dit "Rapide" .

                                  --> Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
                                  --> à la fin tu cliques sur "résultat" .
                                  --> Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

                                  Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

                                  Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date),
                                  accompagné d'un nouveau rapport RSIT ( log.txt ) pour analyse ...

                                  0
                                  1. Voici le rapport:
                                    Malwarebytes' Anti-Malware 1.40
                                    Version de la base de données: 2602
                                    Windows 6.0.6001 Service Pack 1

                                    11/08/2009 17:08:32
                                    mbam-log-2009-08-11 (17-08-32).txt

                                    Type de recherche: Examen rapide
                                    Eléments examinés: 79129
                                    Temps écoulé: 4 minute(s), 6 second(s)

                                    Processus mémoire infecté(s): 0
                                    Module(s) mémoire infecté(s): 0
                                    Clé(s) du Registre infectée(s): 0
                                    Valeur(s) du Registre infectée(s): 1
                                    Elément(s) de données du Registre infecté(s): 0
                                    Dossier(s) infecté(s): 0
                                    Fichier(s) infecté(s): 3

                                    Processus mémoire infecté(s):
                                    (Aucun élément nuisible détecté)

                                    Module(s) mémoire infecté(s):
                                    (Aucun élément nuisible détecté)

                                    Clé(s) du Registre infectée(s):
                                    (Aucun élément nuisible détecté)

                                    Valeur(s) du Registre infectée(s):
                                    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\browserctl (Trojan.Agent) -> Quarantined and deleted successfully.

                                    Elément(s) de données du Registre infecté(s):
                                    (Aucun élément nuisible détecté)

                                    Dossier(s) infecté(s):
                                    (Aucun élément nuisible détecté)

                                    Fichier(s) infecté(s):
                                    C:\WINDOWS\010112010146120114.fx (Worm.KoobFace) -> Quarantined and deleted successfully.
                                    C:\WINDOWS\934fdfg34fgjf23 (Worm.KoobFace) -> Quarantined and deleted successfully.
                                    C:\WINDOWS\prxid93ps.dat (Malware.Trace) -> Quarantined and deleted successfully.

                                    Et voici le RSIT:
                                    Logfile of random's system information tool 1.06 (written by random/random)
                                    Run by chris at 2009-08-11 17:14:03
                                    Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
                                    System drive C: has 227 GB (76%) free of 298 GB
                                    Total RAM: 1918 MB (52% free)

                                    Logfile of Trend Micro HijackThis v2.0.2
                                    Scan saved at 17:14:13, on 11/08/2009
                                    Platform: Windows Vista SP1 (WinNT 6.00.1905)
                                    MSIE: Internet Explorer v8.00 (8.00.6001.18813)
                                    Boot mode: Normal

                                    Running processes:
                                    C:\Windows\system32\Dwm.exe
                                    C:\Windows\Explorer.EXE
                                    C:\Windows\system32\taskeng.exe
                                    C:\Program Files\Windows Defender\MSASCui.exe
                                    C:\hp\support\hpsysdrv.exe
                                    C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
                                    C:\WINDOWS\RtHDVCpl.exe
                                    C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
                                    C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                                    C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
                                    C:\WINDOWS\System32\rundll32.exe
                                    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                                    C:\Windows\system32\schtasks.exe
                                    C:\Program Files\Windows Sidebar\sidebar.exe
                                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                    C:\WINDOWS\ehome\ehtray.exe
                                    C:\Windows\ehome\ehmsas.exe
                                    C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
                                    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                    C:\Windows\system32\jusched.exe
                                    C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
                                    C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
                                    C:\Windows\system32\NOTEPAD.EXE
                                    C:\Program Files\Internet Explorer\iexplore.exe
                                    C:\Program Files\Internet Explorer\iexplore.exe
                                    C:\Program Files\Internet Explorer\iexplore.exe
                                    C:\hp\kbd\kbd.exe
                                    C:\Users\chris\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\N3NM0CVE\RSIT[1].exe
                                    C:\Program Files\trend micro\chris.exe

                                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/nl-be?cobrand=hp.msn.com&ocid=HPDHP&pc=HPDTDF&checklang=1
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/nl-be?cobrand=hp.msn.com&ocid=HPDHP&pc=HPDTDF&checklang=1
                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                    O1 - Hosts: ::1 localhost
                                    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                                    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                    O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
                                    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                                    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                    O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
                                    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
                                    O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
                                    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                                    O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                    O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
                                    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                                    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
                                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                                    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                                    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                                    O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
                                    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                                    O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                                    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                                    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                    O4 - HKCU\..\Run: [VeohPlugin] "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
                                    O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                                    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                                    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                    O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
                                    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                                    O13 - Gopher Prefix:
                                    O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                                    O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                                    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                                    O23 - Service: Service Google Update (gupdate1c9c39b824dbafb) (gupdate1c9c39b824dbafb) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                                    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                    O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                                    O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                                    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                                    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
                                    O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                                    O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                                    O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                                    0
                                    1. Contributeur sécurité
                                      bien ....

                                      dis nous comment va le PC ... du mieux ?

                                      puis fait ce qui suit dans l'ordre :

                                      1- Supprime tout ce qui se trouve dans la quarantaine de Malwarebytes .

                                      =================

                                      2- Tu as des restes de Norton qu'il faut nettoyer :

                                      Télécharge Norton removal tool sur ton bureau :
                                      ftp://ftp.symantec.com/public/francais/removal_tools/Norton_Removal_Tool.exe

                                      Déconnecte toi .
                                      Ensuite désinstalle Norton avec "Norton removal tool": tu double-cliques dessus et tu te laisses guider ... il faut le désinstaller correctement ( fais la manipe 2 fois si possible ).

                                      =================

                                      3- Télécharge GenProc (de Jean-Chretien1 et Narco4) sur ton bureau (et pas ailleur !) :
                                      http://www.genproc.com/GenProc.exe

                                      !! ferme tes applications en cours !!

                                      * clique droit / " executer entant qu'admin..." sur GenProc.exe pour lancer le scan et laisse faire...

                                      * A la question "faites vous aidez sur un forum..." > clique sur " oui " .

                                      -> poste le contenu du rapport qui s'ouvre ...

                                      Aide en images ici : http://www.alt-shift-return.org/Info/GenProc-HowTo.html

                                      IMPORTANT : poste le rapport et ne fais rien d'autre pour l'instant ( souvant il faut ajouter des consignes à la manipe indiquée pour que cela fonctionne parfaitement ) .

                                      0
                                      1. Mon pc à l'air de fonctionner bien mieux, merci! J'étais loin de m'imaginer toutes les saloperies qui y avaient dessus. J'ai bien fait de changer d'antivirus!
                                        Rapport GenProc 2.613 [1] - mar. 11/08/2009 à 17:38:20
                                        @ Windows Vista Service Pack 1 - Mode normal
                                        @ Internet Explorer (8.0.6001.18813) [Navigateur par défaut]

                                        GenProc n'a détecté aucune infection caractéristique et suggère de suivre la procédure suivante :

                                        Fais scanner le(s) fichier(s) suivant(s) sur ce site https://www.virustotal.com/gui/ :

                                        C:\Windows\0535251103110107106.xry

                                        et poste le(s) rapport(s) obtenu(s) dans ta prochaine réponse.

                                        ~~~~ INFORMATION COMPLEMENTAIRE ~~~~

                                        Logfile of Trend Micro HijackThis v2.0.2
                                        Scan saved at 17:39:17, on 11/08/2009
                                        Platform: Windows Vista SP1 (WinNT 6.00.1905)
                                        MSIE: Internet Explorer v8.00 (8.00.6001.18813)
                                        Boot mode: Normal

                                        Running processes:
                                        C:\Windows\system32\Dwm.exe
                                        C:\Windows\system32\taskeng.exe
                                        C:\Windows\Explorer.EXE
                                        C:\Program Files\Windows Defender\MSASCui.exe
                                        C:\hp\support\hpsysdrv.exe
                                        C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
                                        C:\WINDOWS\RtHDVCpl.exe
                                        C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
                                        C:\WINDOWS\System32\rundll32.exe
                                        C:\Windows\system32\schtasks.exe
                                        C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                                        C:\Program Files\Windows Sidebar\sidebar.exe
                                        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                        C:\WINDOWS\ehome\ehtray.exe
                                        C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
                                        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                        C:\Windows\ehome\ehmsas.exe
                                        C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
                                        C:\Windows\system32\jusched.exe
                                        C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
                                        C:\hp\kbd\kbd.exe
                                        C:\Program Files\Internet Explorer\iexplore.exe
                                        C:\Program Files\Internet Explorer\iexplore.exe
                                        C:\Program Files\Internet Explorer\iexplore.exe
                                        C:\Windows\system32\cmd.exe
                                        C:\Windows\system32\conime.exe
                                        C:\Windows\system32\SearchFilterHost.exe
                                        C:\Genproc\outil\chris_GenProc.exe

                                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/nl-be?cobrand=hp.msn.com&ocid=HPDHP&pc=HPDTDF&checklang=1
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/nl-be?cobrand=hp.msn.com&ocid=HPDHP&pc=HPDTDF&checklang=1
                                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                        O1 - Hosts: ::1 localhost
                                        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                                        O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                        O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                        O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
                                        O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                                        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                        O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
                                        O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
                                        O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
                                        O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                                        O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                                        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                        O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
                                        O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
                                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                                        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                                        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                                        O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
                                        O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                                        O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                                        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                                        O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                        O4 - HKCU\..\Run: [VeohPlugin] "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
                                        O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                                        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                                        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                        O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
                                        O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                                        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                                        O13 - Gopher Prefix:
                                        O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                                        O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                                        O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                                        O23 - Service: Service Google Update (gupdate1c9c39b824dbafb) (gupdate1c9c39b824dbafb) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                                        O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                        O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                        O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
                                        O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
                                        O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                                        O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                                        0
                                        1. Mon pc à l'air de fonctionner bien mieux, merci! J'étais loin de m'imaginer toutes les saloperies qui y avaient dessus. J'ai bien fait de changer d'antivirus!
                                          Rapport GenProc 2.613 [1] - mar. 11/08/2009 à 17:38:20
                                          @ Windows Vista Service Pack 1 - Mode normal
                                          @ Internet Explorer (8.0.6001.18813) [Navigateur par défaut]

                                          GenProc n'a détecté aucune infection caractéristique et suggère de suivre la procédure suivante :

                                          Fais scanner le(s) fichier(s) suivant(s) sur ce site https://www.virustotal.com/gui/ :

                                          C:\Windows\0535251103110107106.xry

                                          et poste le(s) rapport(s) obtenu(s) dans ta prochaine réponse.

                                          ~~~~ INFORMATION COMPLEMENTAIRE ~~~~

                                          Logfile of Trend Micro HijackThis v2.0.2
                                          Scan saved at 17:39:17, on 11/08/2009
                                          Platform: Windows Vista SP1 (WinNT 6.00.1905)
                                          MSIE: Internet Explorer v8.00 (8.00.6001.18813)
                                          Boot mode: Normal

                                          Running processes:
                                          C:\Windows\system32\Dwm.exe
                                          C:\Windows\system32\taskeng.exe
                                          C:\Windows\Explorer.EXE
                                          C:\Program Files\Windows Defender\MSASCui.exe
                                          C:\hp\support\hpsysdrv.exe
                                          C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
                                          C:\WINDOWS\RtHDVCpl.exe
                                          C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
                                          C:\WINDOWS\System32\rundll32.exe
                                          C:\Windows\system32\schtasks.exe
                                          C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                                          C:\Program Files\Windows Sidebar\sidebar.exe
                                          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                          C:\WINDOWS\ehome\ehtray.exe
                                          C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
                                          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                          C:\Windows\ehome\ehmsas.exe
                                          C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
                                          C:\Windows\system32\jusched.exe
                                          C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
                                          C:\hp\kbd\kbd.exe
                                          C:\Program Files\Internet Explorer\iexplore.exe
                                          C:\Program Files\Internet Explorer\iexplore.exe
                                          C:\Program Files\Internet Explorer\iexplore.exe
                                          C:\Windows\system32\cmd.exe
                                          C:\Windows\system32\conime.exe
                                          C:\Windows\system32\SearchFilterHost.exe
                                          C:\Genproc\outil\chris_GenProc.exe

                                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
                                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/nl-be?cobrand=hp.msn.com&ocid=HPDHP&pc=HPDTDF&checklang=1
                                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/nl-be?cobrand=hp.msn.com&ocid=HPDHP&pc=HPDTDF&checklang=1
                                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                          O1 - Hosts: ::1 localhost
                                          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                                          O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                          O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                          O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
                                          O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                                          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                          O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
                                          O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
                                          O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
                                          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                                          O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                                          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                          O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
                                          O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
                                          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                                          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                                          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                                          O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
                                          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                                          O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                                          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                                          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                          O4 - HKCU\..\Run: [VeohPlugin] "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
                                          O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                                          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                                          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                          O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
                                          O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                                          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                                          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                                          O13 - Gopher Prefix:
                                          O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                                          O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                                          O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                                          O23 - Service: Service Google Update (gupdate1c9c39b824dbafb) (gupdate1c9c39b824dbafb) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                                          O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                          O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                          O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
                                          O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
                                          O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                                          O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                                          0
                                          • 1
                                          • 2