Infection...

Bonjour à tous, voilà je crois être infecter par une sale bête, j'ai passer un coup de Hijeck This mais je ne sais pas lire le rapport... Quelqu'un pourrait "dechiffrer le rapport pour moi ?
Je vous remercie et à bientot !

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:11:42, on 12/09/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Atomic Alarm Clock\timeserv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
c:\hp\HPEZBTN\HPBtnSrv.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Windows\system32\svchost.exe
C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
C:\Windows\System32\TUProgSt.exe
C:\Windows\System32\svchost.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\vVX1000.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\rundll32.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\PROGRA~1\FREEDO~1\fdm.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Spyware Doctor\pctsGui.exe
C:\Program Files\Spyware Doctor\Update.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.trooner.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [VX1000] C:\Windows\vVX1000.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Global Startup: ZDWLan Utility.lnk = C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe
O8 - Extra context menu item: Tout télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Télécharger la sélection avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Télécharger la vidéo avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O15 - Trusted Zone: http://www.inoculer.com
O15 - Trusted Zone: http://www.secuser.com
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
O23 - Service: Avira Pare-feu (AntiVirFirewallService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe
O23 - Service: Avira AntiVir MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira AntiVir WebGuard (AntiVirWebService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
O23 - Service: Application Driver Auto Removal Service (01) (appdrvrem01) - Protection Technology - C:\Windows\System32\appdrvrem01.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Atomic Alarm Clock Time (AtomicAlarmClock) - Unknown owner - C:\Program Files\Atomic Alarm Clock\timeserv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
O23 - Service: Service Google Update (gupdate1ca29dcacb612b4) (gupdate1ca29dcacb612b4) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP Chasis Button Service (HPBtnSrv) - Unknown owner - c:\hp\HPEZBTN\HPBtnSrv.exe
O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 4 (TeamViewer4) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: @%SystemRoot%\System32\TUProgSt.exe,-1 (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\Windows\System32\TUProgSt.exe

--
End of file - 13282 bytes
Configuration: Windows Vista
Firefox 3.5.3

9 réponses

  1. Contributeur sécurité
    Tout d'abord ,tu as 2 antivirus ! Désinstalle Panda .

    Qu'est ce qui te fait penser que tu es infecté ?

    En attendant ,fait ceci :

    télécharge genproc

    double-clique sur GenProc.exe et poste le contenu du rapport qui s'ouvre .
    2
    1. Contributeur sécurité
      Hello ;

      Il va falloir analyser un ou des fichier(s) suspect(s) !

      Il se peut qu'il se trouvent dans les " dossiers cachés " du systeme.
      Il faut donc les rendre visibles pour le scan.

      Pour afficher les dossiers et fichiers cachés:

      Panneau de configuration > Options des dossiers > onglet Affichage.

      Coche Afficher les fichiers et dossiers cachés,
      Décoche Masquer les extensions de fichiers connus
      Décoche Masquer les fichiers protégés du Système.
      Un message de mise en garde va apparaitre. Clique sur OK pour confirmer ton choix.
      Les fichiers et dossiers cachés du système apparaitront alors dans l'explorateur Windows en transparence.

      Rends toi sur ce site :

      https://www.virustotal.com/gui/

      Clique sur parcourir et cherche ce fichier : C:\Program Files\Atomic Alarm Clock\timeserv.exe

      Clique sur Send File.

      Un rapport va s'élaborer ligne à ligne.

      Attends la fin. Il doit comprendre la taille du fichier envoyé.

      Sauvegarde le rapport avec le bloc-note.

      Copie le dans ta réponse.
      0
      1. Fichier timeserv.exe reçu le 2009.02.23 08:08:10 (UTC)
        Situation actuelle: terminé
        Résultat: 0/39 (0.00%)
        Formaté Formaté
        Impression des résultats Impression des résultats
        Antivirus Version Dernière mise à jour Résultat
        a-squared 4.0.0.93 2009.02.23 -
        AhnLab-V3 2009.2.23.1 2009.02.23 -
        AntiVir 7.9.0.87 2009.02.23 -
        Authentium 5.1.0.4 2009.02.22 -
        Avast 4.8.1335.0 2009.02.22 -
        AVG 8.0.0.237 2009.02.22 -
        BitDefender 7.2 2009.02.23 -
        CAT-QuickHeal 10.00 2009.02.22 -
        ClamAV 0.94.1 2009.02.23 -
        Comodo 983 2009.02.20 -
        DrWeb 4.44.0.09170 2009.02.23 -
        eSafe 7.0.17.0 2009.02.19 -
        eTrust-Vet 31.6.6368 2009.02.20 -
        F-Prot 4.4.4.56 2009.02.22 -
        F-Secure 8.0.14470.0 2009.02.23 -
        Fortinet 3.117.0.0 2009.02.23 -
        GData 19 2009.02.23 -
        Ikarus T3.1.1.45.0 2009.02.23 -
        K7AntiVirus 7.10.639 2009.02.21 -
        Kaspersky 7.0.0.125 2009.02.23 -
        McAfee 5533 2009.02.22 -
        McAfee+Artemis 5533 2009.02.22 -
        Microsoft 1.4306 2009.02.23 -
        NOD32 3880 2009.02.23 -
        Norman 6.00.06 2009.02.20 -
        nProtect 2009.1.8.0 2009.02.23 -
        Panda 10.0.0.10 2009.02.22 -
        PCTools 4.4.2.0 2009.02.22 -
        Prevx1 V2 2009.02.23 -
        Rising 21.18.01.00 2009.02.23 -
        SecureWeb-Gateway 6.7.6 2009.02.23 -
        Sophos 4.39.0 2009.02.23 -
        Sunbelt 3.2.1855.2 2009.02.17 -
        Symantec 10 2009.02.23 -
        TheHacker 6.3.2.4.263 2009.02.21 -
        TrendMicro 8.700.0.1004 2009.02.23 -
        VBA32 3.12.10.0 2009.02.22 -
        ViRobot 2009.2.20.1617 2009.02.20 -
        VirusBuster 4.5.11.0 2009.02.22 -
        Information additionnelle
        File size: 415744 bytes
        MD5 : db436dd9b111f404bb233ed3a376977e
        SHA1 : 46d93dcf0b469265c27bc9c37e79bcd6691d873b
        SHA256: d128d8bf920e3de9fd9c4242b96657f55e5a2ebd8484fa3e64927b2720cee960
        PEInfo: PE Structure information

        ( base data )
        entrypointaddress.: 0x456FF4
        timedatestamp.....: 0x2A425E19 (Sat Jun 20 00:22:17 1992)
        machinetype.......: 0x14C (Intel I386)

        ( 8 sections )
        name viradd virsiz rawdsiz ntrpy md5
        CODE 0x1000 0x5603C 0x56200 6.52 2ef76dd29280cb173939ee15ce5e1980
        DATA 0x58000 0x125C 0x1400 3.94 a430ad3130f18858576139252b281b95
        BSS 0x5A000 0xC19 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
        .idata 0x5B000 0x23AE 0x2400 5.03 72724493b0592095a2d8aa5b600dd33a
        .tls 0x5E000 0x10 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
        .rdata 0x5F000 0x18 0x200 0.20 24110d668a6d6f8e009605d0a2be4dfe
        .reloc 0x60000 0x62F8 0x6400 6.66 0815a67c06c6ca8a29a11fd9ed2c0884
        .rsrc 0x67000 0x5400 0x5400 4.17 4cf8c578d8e36094c42dc3a7d1ae0926

        ( 0 imports )

        ( 0 exports )
        TrID : File type identification
        Win32 Executable Borland Delphi 7 (69.1%)
        Win32 Executable Borland Delphi 6 (27.0%)
        Win32 Executable Delphi generic (1.5%)
        Win32 Executable Generic (0.8%)
        Win32 Dynamic Link Library (generic) (0.7%)
        ssdeep: 12288:1QAmKFrCzj0DjLNPd1X00TbGJjmqlnqSktAN/:1pzOADjLXm0WmKqSkON
        PEiD : -
        CWSandbox: http://research.sunbelt-software.com/...
        RDS : NSRL Reference Data Set

        Je te remercie pour ta disponibilité JFK ;)
        0
        1. Contributeur sécurité
          RAS pour ce fichier ,on va approfondir la recherche :

          Télécharge ici :

          http://images.malwareremoval.com/random/RSIT.exe

          random's system information tool (RSIT) par random/random et sauvegarde-le sur le Bureau.

          Double-clique sur RSIT.exe afin de lancer RSIT.

          Lis le contenu de l'écran Disclaimer puis clique sur Continue (si tu acceptes les conditions).

          Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

          Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

          Poste le contenu de log.txt (<<qui sera affiché)
          ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

          NB : Les rapports sont sauvegardés dans le dossier C:\rsit

          Aide en images si besoin
          0
          1. info.txt logfile of random's system information tool 1.06 2009-06-05 21:36:58

            ======Uninstall list======

            ActiveCheck component for HP Active Support Library-->MsiExec.exe /X{254C37AA-6B72-4300-84F6-98A82419187E}
            Ad-Aware-->"C:\ProgramData\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe" REMOVE=TRUE MODIFY=FALSE
            Ad-Aware-->C:\ProgramData\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
            Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
            Adobe Flash Player ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
            Adobe Reader 8.1.3 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81300000003}
            Adobe Shockwave Player-->C:\Windows\System32\Adobe\SHOCKW~1\UNWISE.EXE C:\Windows\System32\Adobe\SHOCKW~1\Install.log
            adsl TV-->C:\Program Files\adslTV\Uninstal.exe
            ALUpdate-->"C:\Program Files\ESTsoft\ALUpdate\unins000.exe"
            Apple Mobile Device Support-->MsiExec.exe /I{659B48CD-0608-4ED5-94C0-0B6C87114F10}
            Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
            Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
            ASIO4ALL-->C:\Program Files\ASIO4ALL v2\uninstall.exe
            Assistant de connexion Windows Live-->MsiExec.exe /I{D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
            Atomic Alarm Clock 5.85-->"C:\Program Files\Atomic Alarm Clock\unins000.exe"
            Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
            Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
            CamStudio 2.0 Fr-->"C:\Program Files\CamStudio\unins000.exe"
            CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
            Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
            Collab-->C:\Program Files\Image-Line\Collab\uninstall.exe
            Diskeeper Lite-->MsiExec.exe /X{A3F60446-48FB-48A8-B5FC-BB3430AEF806}
            DVD Play BD & HD DVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{45D707E9-F3C4-11D9-A373-0050BAE317E1}\Setup.exe" -uninstall
            FastStone MaxView 2.3-->C:\Program Files\FastStone MaxView\uninst.exe
            ffvfw (uninstall only)-->"C:\Program Files\ffvfw\uninstall.exe"
            FL Studio 8-->C:\Program Files\Image-Line\FL Studio 8\uninstall.exe
            Football Manager 2009-->"C:\Program Files\Steam\steam.exe" steam://uninstall/10540
            Free Video Dub version 1.4-->"C:\Program Files\DVDVideoSoft\Free Video Dub\unins000.exe"
            Galerie de photos Windows Live-->MsiExec.exe /X{A70FA218-6598-4AC9-813D-63597C5DD068}
            Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
            Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_BDA1448D3D255554.exe" /uninstall
            Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
            HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
            HiYo -->MsiExec.exe /X{8F3A13FC-DFDA-4001-A6C3-030495A1E66E} ARPVAL="UnInst" /qf /L*V "%temp%\HiYoUninstallLog.log"
            HiYo-->MsiExec.exe /X{8F3A13FC-DFDA-4001-A6C3-030495A1E66E}
            HP Active Support Library 32 bit components-->MsiExec.exe /I{6D3DB611-D5E8-4E4B-8952-0D3F549F9CC6}
            HP Active Support Library-->C:\Program Files\InstallShield Installation Information\{0A47BAFF-D4FF-4BD3-96CA-02A22EA62722}\setup.exe -runfromtemp -l0x0409
            HP Customer Experience Enhancements-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AB5E289E-76BF-4251-9F3F-9B763F681AE0}\setup.exe" -l0x9 -removeonly
            HP Customer Feedback-->MsiExec.exe /I{9DBA770F-BF73-4D39-B1DF-6035D95268FC}
            HP Easy Setup - Frontend-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40F7AED3-0C7D-4582-99F6-484A515C73F2}\setup.exe" -l0x9 -removeonly
            HP On-Screen Cap/Num/Scroll Lock Indicator-->C:\Windows\system32\OsdRemove.exe
            HP Photosmart Essential 2.01-->C:\Program Files\HP\Digital Imaging\PhotoSmartEssential\hpzscr01.exe -datfile hpqbud13.dat
            HP Picasso Media Center Add-In-->MsiExec.exe /I{55979C41-7D6A-49CC-B591-64AC1BBE2C8B}
            HP Total Care Advisor-->MsiExec.exe /X{0DDA7620-4F8B-43B3-8828-CA5EE292FA3B}
            HP Update-->MsiExec.exe /X{7059BDA7-E1DB-442C-B7A1-6144596720A4}
            HPAsset component for HP Active Support Library-->MsiExec.exe /X{669D4A35-146B-4314-89F1-1AC3D7B88367}
            IL Download Manager-->C:\Program Files\Image-Line\Downloader\uninstall.exe
            Intel(R) PRO Network Connections Drivers-->Prounstl.exe
            iTunes-->MsiExec.exe /I{CC5702D7-86E2-45A8-99D7-E8B976ADCC56}
            Java(TM) SE Runtime Environment 6 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
            K-Lite Codec Pack 4.4.2 (Full)-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
            LabelPrint-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\Setup.exe" -uninstall
            Le Centre de Contrôle de Licences de Syncrosoft-->C:\PROGRA~1\SYNCRO~1\UNWISE.EXE C:\PROGRA~1\SYNCRO~1\INSTALL.LOG
            LimeWire 4.18.1-->"C:\Program Files\LimeWire\uninstall.exe"
            Livebox-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FC7DDAAE-7F2B-4270-9BFD-5A130B667E9E}\Setup.exe" -l0x40c
            Logiciel Intel® Viiv™-->MsiExec.exe /X{6E7BF6EC-C3E7-43A7-8A03-0D204E3EC01B} /qb!
            Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
            Microsoft LifeCam-->MsiExec.exe /X{968D41C3-25BB-4632-A6DF-2E1C8F0143A4}
            Microsoft Office Word Viewer 2003-->MsiExec.exe /I{9085040C-6000-11D3-8CFE-0150048383C9}
            Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
            Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
            Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
            Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
            Microsoft Works-->MsiExec.exe /I{6B1CB38D-E2E4-4A30-933D-EFDEBA76AD9C}
            Mozilla Firefox (3.0.10)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
            MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
            MSXML 4.0 SP2 (KB941833)-->MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
            MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
            muvee autoProducer 6.0-->C:\Program Files\InstallShield Installation Information\{775B9052-3517-47FA-817D-1BB28363D43A}\setup.exe -runfromtemp -l0x040c -removeonly
            My Drivers 3.31-->"C:\Program Files\My Drivers\unins000.exe"
            NetXfer 2.82.450-->"C:\Program Files\Xi\NetXfer\unins000.exe"
            NVIDIA Drivers-->C:\Windows\system32\NVUNINST.EXE UninstallGUI
            Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
            Outils de diagnostic du matériel-->C:\Program Files\PC-Doctor 5 for Windows\uninst.exe
            PoiZone-->C:\Program Files\Image-Line\PoiZone\uninstall.exe
            Power2Go 5.0-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\Setup.exe" -uninstall
            PowerProducer-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\Setup.exe" -uninstall
            Python 2.5-->MsiExec.exe /I{0A2C5854-557E-48C8-835A-3B9F074BDCAA}
            QuickTime-->MsiExec.exe /I{C78EAC6F-7A73-452E-8134-DBB2165C5A68}
            Rapidshare Auto Downloader 3.4-->MsiExec.exe /I{121FC0B0-B11B-4234-9ED4-71A3D84A57EE}
            Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
            Safari-->MsiExec.exe /I{9C48DCA4-00C2-449C-88D8-B1EE1692B44F}
            SAMSUNG Mobile Modem Driver Set-->C:\Windows\system32\Samsung_USB_Drivers\3\SSCDUninstall.exe
            Samsung Mobile phone USB driver Software-->C:\Windows\system32\Samsung_USB_Drivers\5\SSSDUninstall.exe
            Skype™ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
            Solution de clavier multimédia amélioré-->C:\HP\KBD\Install.exe /u
            Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins001.exe"
            Spyware Doctor 6.0-->C:\Program Files\Spyware Doctor\unins000.exe /LOG
            Steam-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
            SyncroSoft Emu (Remove only)-->C:\Program Files\SyncroSoft\Pos\H2O\Uninst.exe
            TeamSpeak 2 RC2-->"C:\Program Files\Teamspeak2_RC2\unins000.exe"
            TmNationsForever-->"C:\Program Files\TmNationsForever\unins000.exe"
            Toxic Biohazard-->C:\Program Files\Image-Line\Toxic Biohazard\uninstall.exe
            Uninstall 1.0.0.1-->"C:\Program Files\Common Files\DVDVideoSoft\unins000.exe"
            VDownloader 0.81-->"C:\Program Files\VDOWNLOADER\unins000.exe"
            Version de démonstration de Microsoft Office Home and Student 2007-->c:\hp\bin\MSOffice\uninst2.cmd
            Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
            Visual C++ 2008 x86 Runtime - v9.0.30729.01-->C:\Windows\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
            VLC media player 0.9.9-->C:\Program Files\adslTV\uninstall.exe
            Vodafone WCDMA Composite Device Drive Software-->C:\Windows\system32\Samsung_USB_Drivers\4\SSVDUninstall.exe
            Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
            Windows Live Mail-->MsiExec.exe /I{C514C594-23AA-4F13-A070-DB8BDB27594F}
            Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
            Windows Live OneCare safety scanner-->"C:\Program Files\Windows Live Safety Center\UnInstall.exe"
            Windows Live OneCare safety scanner-->MsiExec.exe /X{FE0646A7-19D0-41B4-A2BB-2C35D644270D}
            Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
            Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
            Yahoo! Install Manager-->C:\Windows\system32\regsvr32 /u C:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL
            Zattoo 3.3.4 Beta-->C:\Program Files\Zattoo\uninst.exe
            ZyDAS IEEE 802.11 b+g Wireless LAN - USB-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{581CE7EA-A30D-0000-1211-088635773309}\setup.exe" -l0x9

            ======Hosts File======

            127.0.0.1 www.007guard.com
            127.0.0.1 007guard.com
            127.0.0.1 008i.com
            127.0.0.1 www.008k.com
            127.0.0.1 008k.com
            127.0.0.1 www.00hq.com
            127.0.0.1 00hq.com
            127.0.0.1 010402.com
            127.0.0.1 www.032439.com
            127.0.0.1 032439.com

            ======Security center information======

            AS: Spybot - Search and Destroy (disabled) (outdated)
            AS: Lavasoft Ad-Watch Live!
            AS: Windows Defender

            ======System event log======

            Computer Name: PC-de-Maison
            Event Code: 7026
            Message: Le pilote de démarrage système ou d'amorçage suivant n'a pas pu se charger :
            i8042prt
            Record Number: 124018
            Source Name: Service Control Manager
            Time Written: 20090605060554.000000-000
            Event Type: Erreur
            User:

            Computer Name: PC-de-Maison
            Event Code: 4227
            Message: TCP/IP n’a pas pu établir une connexion sortante car le point de terminaison local sélectionné a été récemment utilisé pour se connecter au même point de terminaison distant. Cette erreur se produit généralement lorsque les connexions sortantes sont ouvertes et fermées à un débit élevé, provoquant l’utilisation de tous les ports locaux disponibles et obligeant TCP/IP à réutiliser un port local pour une connexion sortante. Pour réduire le risque d’altération des données, la norme TCP/IP exige qu’un laps de temps minimal s’écoule entre des connexions successives d’un point de terminaison local à un point de terminaison distant.
            Record Number: 124073
            Source Name: Tcpip
            Time Written: 20090605170925.201743-000
            Event Type: Avertissement
            User:

            Computer Name: PC-de-Maison
            Event Code: 4227
            Message: TCP/IP n’a pas pu établir une connexion sortante car le point de terminaison local sélectionné a été récemment utilisé pour se connecter au même point de terminaison distant. Cette erreur se produit généralement lorsque les connexions sortantes sont ouvertes et fermées à un débit élevé, provoquant l’utilisation de tous les ports locaux disponibles et obligeant TCP/IP à réutiliser un port local pour une connexion sortante. Pour réduire le risque d’altération des données, la norme TCP/IP exige qu’un laps de temps minimal s’écoule entre des connexions successives d’un point de terminaison local à un point de terminaison distant.
            Record Number: 124075
            Source Name: Tcpip
            Time Written: 20090605172647.023743-000
            Event Type: Avertissement
            User:

            Computer Name: PC-de-Marshall
            Event Code: 7
            Message: Le périphérique \Device\Harddisk3\DR3 comporte un bloc défectueux.
            Record Number: 124076
            Source Name: disk
            Time Written: 20090605181631.958743-000
            Event Type: Erreur
            User:

            Computer Name: PC-de-Maison
            Event Code: 4227
            Message: TCP/IP n’a pas pu établir une connexion sortante car le point de terminaison local sélectionné a été récemment utilisé pour se connecter au même point de terminaison distant. Cette erreur se produit généralement lorsque les connexions sortantes sont ouvertes et fermées à un débit élevé, provoquant l’utilisation de tous les ports locaux disponibles et obligeant TCP/IP à réutiliser un port local pour une connexion sortante. Pour réduire le risque d’altération des données, la norme TCP/IP exige qu’un laps de temps minimal s’écoule entre des connexions successives d’un point de terminaison local à un point de terminaison distant.
            Record Number: 124079
            Source Name: Tcpip
            Time Written: 20090605183356.545743-000
            Event Type: Avertissement
            User:

            =====Application event log=====

            Computer Name: PC-de-Maison
            Event Code: 8194
            Message: Erreur du service de cliché instantané des volumes : erreur lors de l’interrogation de l’interface IVssWriterCallback. hr = 0x80070005. Cette erreur est souvent due à des paramètres de sécurité incorrects dans le processus du rédacteur ou du demandeur.

            Opération :
            Données du rédacteur en cours de collecte

            Contexte :
            ID de classe du rédacteur: {e8132975-6f93-4464-a53e-1050253ae220}
            Nom du rédacteur: System Writer
            ID d’instance du rédacteur: {14fd6810-edb5-486b-9f11-9599852ba581}
            Record Number: 78934
            Source Name: VSS
            Time Written: 20090605051802.000000-000
            Event Type: Erreur
            User:

            Computer Name: PC-de-Maison
            Event Code: 1530
            Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

            DÉTAIL -
            1 user registry handles leaked from \Registry\User\S-1-5-21-1340037868-3990466112-3182369322-1001:
            Process 5132 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1340037868-3990466112-3182369322-1001

            Record Number: 78946
            Source Name: Microsoft-Windows-User Profiles Service
            Time Written: 20090605060341.000000-000
            Event Type: Avertissement
            User: AUTORITE NT\SYSTEM

            Computer Name: PC-de-Maison
            Event Code: 1530
            Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

            DÉTAIL -
            1 user registry handles leaked from \Registry\User\S-1-5-21-1340037868-3990466112-3182369322-1001_Classes:
            Process 5132 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1340037868-3990466112-3182369322-1001_CLASSES

            Record Number: 78947
            Source Name: Microsoft-Windows-User Profiles Service
            Time Written: 20090605060341.000000-000
            Event Type: Avertissement
            User: AUTORITE NT\SYSTEM

            Computer Name: PC-de-Maison
            Event Code: 11
            Message: Échec de l'extraction de la liste racine tierce partie depuis le fichier CAB de mise à jour automatique à : <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> avec l'erreur : Un certificat requis n'est pas dans sa période de validité selon la vérification par rapport à l'horloge système en cours ou le tampon daté dans le fichier signé.
            .
            Record Number: 78977
            Source Name: Microsoft-Windows-CAPI2
            Time Written: 20090605060632.000000-000
            Event Type: Erreur
            User:

            Computer Name: PC-de-Maison
            Event Code: 1000
            Message: Application défaillante Explorer.EXE, version 6.0.6001.18164, horodatage 0x4907e242, module défaillant ntdll.dll, version 6.0.6001.18000, horodatage 0x4791a7a6, code d’exception 0xc0000374, décalage d’erreur 0x000b015d, ID du processus 0xf84, heure de début de l’application 0x01c9e5a3b48ad63c.
            Record Number: 79580
            Source Name: Application Error
            Time Written: 20090605165414.000000-000
            Event Type: Erreur
            User:

            =====Security event log=====

            Computer Name: PC-de-Maison
            Event Code: 4672
            Message: Privilèges spéciaux attribués à la nouvelle ouverture de session.

            Sujet :
            ID de sécurité : S-1-5-20
            Nom du compte : SERVICE RÉSEAU
            Domaine du compte : AUTORITE NT
            ID d’ouverture de session : 0x3e4

            Privilèges : SeAssignPrimaryTokenPrivilege
            SeAuditPrivilege
            SeImpersonatePrivilege
            Record Number: 27675
            Source Name: Microsoft-Windows-Security-Auditing
            Time Written: 20090130040922.936131-000
            Event Type: Succès de l'audit
            User:

            Computer Name: PC-de-Maison
            Event Code: 4648
            Message: Tentative d’ouverture de session en utilisant des informations d’identification explicites.

            Sujet :
            ID de sécurité : S-1-5-18
            Nom du compte : PC-DE-MAISON$
            Domaine du compte : WORKGROUP
            ID d’ouverture de session : 0x3e7
            GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

            Compte dont les informations d’identification ont été utilisées :
            Nom du compte : SYSTEM
            Domaine du compte : AUTORITE NT
            GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

            Serveur cible :
            Nom du serveur cible : localhost
            Informations supplémentaires : localhost

            Informations sur le processus :
            ID du processus : 0x2a0
            Nom du processus : C:\Windows\System32\services.exe

            Informations sur le réseau :
            Adresse du réseau : -
            Port : -

            Cet événement est généré lorsqu’un processus tente d’ouvrir une session pour un compte en spécifiant explicitement les informations d’identification de ce compte. Ceci se produit le plus souvent dans les configurations par lot comme les tâches planifiées, ou avec l’utilisation de la commande RUNAS.
            Record Number: 27676
            Source Name: Microsoft-Windows-Security-Auditing
            Time Written: 20090130040923.029731-000
            Event Type: Succès de l'audit
            User:

            Computer Name: PC-de-Maison
            Event Code: 4624
            Message: L’ouverture de session d’un compte s’est correctement déroulée.

            Sujet :
            ID de sécurité : S-1-5-18
            Nom du compte : PC-DE-MARSHALL$
            Domaine du compte : WORKGROUP
            ID d’ouverture de session : 0x3e7

            Type d’ouverture de session : 5

            Nouvelle ouverture de session :
            ID de sécurité : S-1-5-18
            Nom du compte : SYSTEM
            Domaine du compte : AUTORITE NT
            ID d’ouverture de session : 0x3e7
            GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

            Informations sur le processus :
            ID du processus : 0x2a0
            Nom du processus : C:\Windows\System32\services.exe

            Informations sur le réseau :
            Nom de la station de travail :
            Adresse du réseau source : -
            Port source : -

            Informations détaillées sur l’authentification :
            Processus d’ouverture de session : Advapi
            Package d’authentification : Negotiate
            Services en transit : -
            Nom du package (NTLM uniquement) : -
            Longueur de la clé : 0

            Cet événement est généré lors de la création d’une ouverture de session. Il est généré sur l’ordinateur sur lequel l’ouverture de session a été effectuée.

            Le champ Objet indique le compte sur le système local qui a demandé l’ouverture de session. Il s’agit le plus souvent d’un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

            Le champ Type d’ouverture de session indique le type d’ouverture de session qui s’est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

            Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s’est connecté.

            Les champs relatifs au réseau indiquent la provenance d’une demande d’ouverture de session à distance. Le nom de la station de travail n’étant pas toujours disponible, peut être laissé vide dans certains cas.

            Les champs relatifs aux informations d’authentification fournissent des détails sur cette demande d’ouverture de session spécifique.
            - Le GUID d’ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
            - Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d’ouverture de session.
            - Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
            - La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n’a été demandée.
            Record Number: 27677
            Source Name: Microsoft-Windows-Security-Auditing
            Time Written: 20090130040923.029731-000
            Event Type: Succès de l'audit
            User:

            Computer Name: PC-de-Maison
            Event Code: 4672
            Message: Privilèges spéciaux attribués à la nouvelle ouverture de session.

            Sujet :
            ID de sécurité : S-1-5-18
            Nom du compte : SYSTEM
            Domaine du compte : AUTORITE NT
            ID d’ouverture de session : 0x3e7

            Privilèges : SeAssignPrimaryTokenPrivilege
            SeTcbPrivilege
            SeSecurityPrivilege
            SeTakeOwnershipPrivilege
            SeLoadDriverPrivilege
            SeBackupPrivilege
            SeRestorePrivilege
            SeDebugPrivilege
            SeAuditPrivilege
            SeSystemEnvironmentPrivilege
            SeImpersonatePrivilege
            Record Number: 27678
            Source Name: Microsoft-Windows-Security-Auditing
            Time Written: 20090130040923.029731-000
            Event Type: Succès de l'audit
            User:

            Computer Name: PC-de-Maison
            Event Code: 4624
            Message: L’ouverture de session d’un compte s’est correctement déroulée.

            Sujet :
            ID de sécurité : S-1-5-18
            Nom du compte : PC-DE-MAISON$
            Domaine du compte : WORKGROUP
            ID d’ouverture de session : 0x3e7

            Type d’ouverture de session : 5

            Nouvelle ouverture de session :
            ID de sécurité : S-1-5-19
            Nom du compte : SERVICE LOCAL
            Domaine du compte : AUTORITE NT
            ID d’ouverture de session : 0x3e5
            GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

            Informations sur le processus :
            ID du processus : 0x2a0
            Nom du processus : C:\Windows\System32\services.exe

            Informations sur le réseau :
            Nom de la station de travail :
            Adresse du réseau source : -
            Port source : -

            Informations détaillées sur l’authentification :
            Processus d’ouverture de session : Advapi
            Package d’authentification : Negotiate
            Services en transit : -
            Nom du package (NTLM uniquement) : -
            Longueur de la clé : 0

            Cet événement est généré lors de la création d’une ouverture de session. Il est généré sur l’ordinateur sur lequel l’ouverture de session a été effectuée.

            Le champ Objet indique le compte sur le système local qui a demandé l’ouverture de session. Il s’agit le plus souvent d’un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

            Le champ Type d’ouverture de session indique le type d’ouverture de session qui s’est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

            Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s’est connecté.

            Les champs relatifs au réseau indiquent la provenance d’une demande d’ouverture de session à distance. Le nom de la station de travail n’étant pas toujours disponible, peut être laissé vide dans certains cas.

            Les champs relatifs aux informations d’authentification fournissent des détails sur cette demande d’ouverture de session spécifique.
            - Le GUID d’ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
            - Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d’ouverture de session.
            - Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
            - La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n’a été demandée.
            Record Number: 27679
            Source Name: Microsoft-Windows-Security-Auditing
            Time Written: 20090130040923.107732-000
            Event Type: Succès de l'audit
            User:

            ======Environment variables======

            "ComSpec"=%SystemRoot%\system32\cmd.exe
            "FP_NO_HOST_CHECK"=NO
            "OS"=Windows_NT
            "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\hp\bin\Python;C:\Program Files\QuickTime\QTSystem;C:\Program Files\Samsung\Samsung PC Studio 3;C:\Program Files\Smart Projects\IsoBuster;C:\Program Files\QuickTime\QTSystem;C:\Program Files\Executive Software\DiskeeperLite\;C:\Program Files\QuickTime\QTSystem\
            "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
            "PROCESSOR_ARCHITECTURE"=x86
            "TEMP"=%SystemRoot%\TEMP
            "TMP"=%SystemRoot%\TEMP
            "USERNAME"=SYSTEM
            "windir"=%SystemRoot%
            "PROCESSOR_LEVEL"=6
            "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 11, GenuineIntel
            "PROCESSOR_REVISION"=0f0b
            "NUMBER_OF_PROCESSORS"=4
            "PLATFORM"=HPD
            "PCBRAND"=Pavilion
            "OnlineServices"=Services en ligne
            "DiskeeperIcon"=C:\Program Files\Executive Software\DiskeeperLite\
            "CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_01\lib\ext\QTJava.zip
            "QTJAVA"=C:\Program Files\Java\jre1.6.0_01\lib\ext\QTJava.zip

            -----------------EOF-----------------

            Logfile of random's system information tool 1.06 (written by random/random)
            Run by Marshall at 2009-09-14 18:12:20
            Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
            System drive C: has 326 GB (69%) free of 470 GB
            Total RAM: 3071 MB (52% free)

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 18:12:41, on 14/09/2009
            Platform: Windows Vista SP2 (WinNT 6.00.1906)
            MSIE: Internet Explorer v8.00 (8.00.6001.18813)
            Boot mode: Normal

            Running processes:
            C:\Windows\System32\smss.exe
            C:\Windows\system32\csrss.exe
            C:\Windows\system32\wininit.exe
            C:\Windows\system32\csrss.exe
            C:\Windows\system32\services.exe
            C:\Windows\system32\lsass.exe
            C:\Windows\system32\lsm.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\winlogon.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\SLsvc.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Program Files\Avira\AntiVir Desktop\sched.exe
            C:\Windows\system32\svchost.exe
            C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe
            C:\Program Files\Avira\AntiVir Desktop\avguard.exe
            C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            C:\Program Files\Atomic Alarm Clock\timeserv.exe
            C:\Program Files\Bonjour\mDNSResponder.exe
            C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
            c:\hp\HPEZBTN\HPBtnSrv.exe
            c:\Program Files\Common Files\LightScribe\LSSrvc.exe
            C:\Program Files\Microsoft LifeCam\MSCamS32.exe
            C:\Program Files\Spyware Doctor\pctsAuxs.exe
            C:\Program Files\Spyware Doctor\pctsSvc.exe
            C:\Windows\system32\svchost.exe
            C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
            C:\Windows\System32\TUProgSt.exe
            C:\Windows\System32\svchost.exe
            C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
            C:\Windows\system32\WUDFHost.exe
            C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
            C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
            C:\Windows\system32\taskeng.exe
            C:\Windows\system32\Dwm.exe
            C:\Windows\system32\taskeng.exe
            C:\Windows\Explorer.EXE
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\Windows\RtHDVCpl.exe
            C:\Windows\System32\rundll32.exe
            C:\Program Files\Spyware Doctor\pctsTray.exe
            C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
            C:\Program Files\iTunes\iTunesHelper.exe
            C:\Windows\vVX1000.exe
            C:\Program Files\Windows Live\Messenger\msnmsgr.exe
            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            C:\Windows\ehome\ehtray.exe
            C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
            C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe
            C:\Windows\ehome\ehmsas.exe
            C:\Windows\System32\rundll32.exe
            C:\Windows\system32\wbem\wmiprvse.exe
            C:\Windows\system32\wbem\unsecapp.exe
            C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
            C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
            C:\Program Files\iPod\bin\iPodService.exe
            c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
            C:\Windows\servicing\TrustedInstaller.exe
            C:\Windows\system32\vssvc.exe
            C:\Windows\System32\svchost.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\Program Files\Windows Live\Messenger\usnsvc.exe
            C:\PROGRA~1\FREEDO~1\fdm.exe
            C:\Users\Marshall\Desktop\RSIT.exe
            C:\Windows\system32\wbem\wmiprvse.exe
            C:\Program Files\Trend Micro\HijackThis\Marshall.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.trooner.com/
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
            R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
            O1 - Hosts: ::1 localhost
            O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
            O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
            O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
            O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
            O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
            O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
            O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
            O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
            O4 - HKLM\..\Run: [VX1000] C:\Windows\vVX1000.exe
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
            O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
            O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
            O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
            O4 - Global Startup: ZDWLan Utility.lnk = C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe
            O8 - Extra context menu item: Tout télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
            O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
            O8 - Extra context menu item: Télécharger la sélection avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
            O8 - Extra context menu item: Télécharger la vidéo avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
            O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O13 - Gopher Prefix:
            O15 - Trusted Zone: http://www.inoculer.com
            O15 - Trusted Zone: http://www.secuser.com
            O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
            O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
            O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
            O23 - Service: Avira Pare-feu (AntiVirFirewallService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe
            O23 - Service: Avira AntiVir MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
            O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
            O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
            O23 - Service: Avira AntiVir WebGuard (AntiVirWebService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
            O23 - Service: Application Driver Auto Removal Service (01) (appdrvrem01) - Protection Technology - C:\Windows\System32\appdrvrem01.exe
            O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            O23 - Service: Atomic Alarm Clock Time (AtomicAlarmClock) - Unknown owner - C:\Program Files\Atomic Alarm Clock\timeserv.exe
            O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
            O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
            O23 - Service: Service Google Update (gupdate1ca29dcacb612b4) (gupdate1ca29dcacb612b4) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
            O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
            O23 - Service: HP Chasis Button Service (HPBtnSrv) - Unknown owner - c:\hp\HPEZBTN\HPBtnSrv.exe
            O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe
            O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
            O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
            O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
            O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
            O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
            O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
            O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
            O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
            O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
            O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
            O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
            O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
            O23 - Service: TeamViewer 4 (TeamViewer4) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
            O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe
            O23 - Service: @%SystemRoot%\System32\TUProgSt.exe,-1 (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\Windows\System32\TUProgSt.exe
            0
            1. Non non, j'en ai qu'un seul (antivir) mais j'ai passer un scan en ligne avec Panda, c'est peut êytre pour ça qu'il y à une trace de Panda. Je dois cliquer plusieurs fois avec la souris pour par exemple fermer une fenetre. Je ne peux pas faire derouler une page sans qu'elle se bloque et quand j'allume mon ordinateur la page de réinstallation reste 3/4 min au lieu de quelque seconde auparavant.

              Rapport GenProc 2.627 [1] - 14/09/2009 à 20:45:06
              @ Windows Vista Service Pack 2 - Mode normal
              @ Mozilla Firefox (3.5.3) [Navigateur par défaut]

              Dans CCleaner, clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures" ; par la suite, laisse-le avec ses réglages par défaut. C'est tout.

              # Etape 1/ Télécharge :

              - Toolbar-S&D https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cpVobGk5bHnxrhQ4yaoEUDJvOYNnEGyYjgqHZz5GqZLfutR3fMFPlsC3-CGIilfupPAguYATNyua3csodN_frdMK8sSzUpit10Yac-QJCOkMqJKkbdKcP6ySs8trWPgoNVIq4TGGWCe6o0txXQv-ZueJF9vZzw3RXsGwFYIqN2lvF2LPdQzS8mE1d5kWOVOz6EMzQuE5-lClSJM869uq3oc7-t7yg%3D%3D&attredirects=3 (Team IDN) sur ton Bureau.

              Redémarre en mode sans échec comme indiqué ici https://www.wekyo.com/demarrer-le-pc-en-mode-sans-echec-windows-7-et-8/ ; Choisis ta session courante *** Marshall *** (pour retrouver le rapport, clique sur le raccourci "Rapport GenProc[1]" sur ton bureau).

              # Etape 2/

              Lance Toolbar-S&D situé sur le Bureau. Tape sur "2" puis valide en appuyant sur "Entrée". Ne ferme pas la fenêtre lors de la suppression.

              # Etape 3/

              Lance CCleaner : "Nettoyeur"/"lancer le nettoyage" et c'est tout.

              # Etape 4/

              Redémarre normalement et poste, dans la même réponse :

              - Le contenu du rapport TB.txt situé dans C:\ ;
              - Un nouveau rapport HijackThis ;
              - Un nouveau rapport GenProc ;

              Précise les difficultés que tu as eu (ce que tu n'as pas pu faire...) ainsi que l'évolution de la situation.

              ~~ Arguments de la procédure ~~

              # Détections [1] GenProc 2.627 14/09/2009 à 20:45:33
              Toolbar:le 14/09/2009 à 20:46:42 "C:\Program Files\DAEMON Tools Toolbar"

              ----------------------------------------------------------------------
              Sites officiels GenProc : www.alt-shift-return.org et www.genproc.com
              ----------------------------------------------------------------------

              ~~ Fin à 20:47:14 ~~
              0
              1. Contributeur sécurité
                Suit les étapes décrites et poste moi les rapports de ToolbarSD .
                0
                1. Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 18:12:41, on 14/09/2009
                  Platform: Windows Vista SP2 (WinNT 6.00.1906)
                  MSIE: Internet Explorer v8.00 (8.00.6001.18813)
                  Boot mode: Normal

                  Running processes:
                  C:\Windows\System32\smss.exe
                  C:\Windows\system32\csrss.exe
                  C:\Windows\system32\wininit.exe
                  C:\Windows\system32\csrss.exe
                  C:\Windows\system32\services.exe
                  C:\Windows\system32\lsass.exe
                  C:\Windows\system32\lsm.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\system32\winlogon.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\SLsvc.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Program Files\Avira\AntiVir Desktop\sched.exe
                  C:\Windows\system32\svchost.exe
                  C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe
                  C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                  C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  C:\Program Files\Atomic Alarm Clock\timeserv.exe
                  C:\Program Files\Bonjour\mDNSResponder.exe
                  C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
                  c:\hp\HPEZBTN\HPBtnSrv.exe
                  c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                  C:\Program Files\Microsoft LifeCam\MSCamS32.exe
                  C:\Program Files\Spyware Doctor\pctsAuxs.exe
                  C:\Program Files\Spyware Doctor\pctsSvc.exe
                  C:\Windows\system32\svchost.exe
                  C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
                  C:\Windows\System32\TUProgSt.exe
                  C:\Windows\System32\svchost.exe
                  C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                  C:\Windows\system32\WUDFHost.exe
                  C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
                  C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\Explorer.EXE
                  C:\Program Files\Windows Defender\MSASCui.exe
                  C:\Windows\RtHDVCpl.exe
                  C:\Windows\System32\rundll32.exe
                  C:\Program Files\Spyware Doctor\pctsTray.exe
                  C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                  C:\Program Files\iTunes\iTunesHelper.exe
                  C:\Windows\vVX1000.exe
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  C:\Windows\ehome\ehtray.exe
                  C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
                  C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe
                  C:\Windows\ehome\ehmsas.exe
                  C:\Windows\System32\rundll32.exe
                  C:\Windows\system32\wbem\wmiprvse.exe
                  C:\Windows\system32\wbem\unsecapp.exe
                  C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
                  C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
                  C:\Program Files\iPod\bin\iPodService.exe
                  c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                  C:\Windows\servicing\TrustedInstaller.exe
                  C:\Windows\system32\vssvc.exe
                  C:\Windows\System32\svchost.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\Program Files\Windows Live\Messenger\usnsvc.exe
                  C:\PROGRA~1\FREEDO~1\fdm.exe
                  C:\Users\Marshall\Desktop\RSIT.exe
                  C:\Windows\system32\wbem\wmiprvse.exe
                  C:\Program Files\Trend Micro\HijackThis\Marshall.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.trooner.com/
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                  R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                  O1 - Hosts: ::1 localhost
                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
                  O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
                  O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                  O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                  O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                  O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                  O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                  O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                  O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
                  O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                  O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                  O4 - HKLM\..\Run: [VX1000] C:\Windows\vVX1000.exe
                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                  O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                  O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                  O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                  O4 - Global Startup: ZDWLan Utility.lnk = C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe
                  O8 - Extra context menu item: Tout télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
                  O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
                  O8 - Extra context menu item: Télécharger la sélection avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
                  O8 - Extra context menu item: Télécharger la vidéo avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
                  O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                  O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O13 - Gopher Prefix:
                  O15 - Trusted Zone: http://www.inoculer.com
                  O15 - Trusted Zone: http://www.secuser.com
                  O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
                  O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
                  O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                  O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
                  O23 - Service: Avira Pare-feu (AntiVirFirewallService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe
                  O23 - Service: Avira AntiVir MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
                  O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                  O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                  O23 - Service: Avira AntiVir WebGuard (AntiVirWebService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
                  O23 - Service: Application Driver Auto Removal Service (01) (appdrvrem01) - Protection Technology - C:\Windows\System32\appdrvrem01.exe
                  O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  O23 - Service: Atomic Alarm Clock Time (AtomicAlarmClock) - Unknown owner - C:\Program Files\Atomic Alarm Clock\timeserv.exe
                  O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                  O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
                  O23 - Service: Service Google Update (gupdate1ca29dcacb612b4) (gupdate1ca29dcacb612b4) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                  O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                  O23 - Service: HP Chasis Button Service (HPBtnSrv) - Unknown owner - c:\hp\HPEZBTN\HPBtnSrv.exe
                  O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe
                  O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                  O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                  O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
                  O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
                  O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
                  O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
                  O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
                  O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
                  O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                  O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
                  O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
                  O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
                  O23 - Service: TeamViewer 4 (TeamViewer4) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
                  O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe
                  O23 - Service: @%SystemRoot%\System32\TUProgSt.exe,-1 (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\Windows\System32\TUProgSt.exe
                  0
                  1. Contributeur sécurité
                    ok ,vu le nombre de cracks que tu possedes ....:(

                    Fait ceci :

                    Fais un scan en ligne Kaspersky avec Internet Explorer.
                    - Clique sur Démarrer Online-Scanner

                    - Clique maintenant sur J'accepte.
                    - Valide l'installation d'un ou de plusieurs ActiveX si c'est nécessaire.
                    - Patiente pendant l'installation des Mises à jour.
                    - Choisis par la suite l'analyse du Poste de travail.
                    - Sauvegarde puis colle le rapport généré en fin d'analyse.

                    AIDE : Configurer le contrôle des ActiveX

                    NOTE : Si tu reçois le message "La licence de Kaspersky On-line Scanner est périmée", va dans Ajout/Suppression de programmes puis désinstalle On-Line Scanner, reconnecte toi sur le site de Kaspersky pour retenter le scan en ligne.
                    0