Skintrim

Bonjour,
depuis qq tps avast détecte skintream et je n'arrive pas à m'en débarasser. Est ce que qqun peut m'aider. Merci
Configuration: Windows Vista Internet Explorer 7.0

19 réponses

  1. Contributeur sécurité
    salut

    Télécharge ici :

    http://images.malwareremoval.com/random/RSIT.exe

    random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

    Double-clique sur RSIT.exe afin de lancer RSIT.

    Clique Continue à l'écran Disclaimer.

    Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

    Poste le contenu de log.txt (<<qui sera affiché)
    ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

    NB : Les rapports sont sauvegardés dans le dossier C:\rsit
    0
    1. Logfile of random's system information tool 1.06 (written by random/random)
      Run by André at 2009-09-16 17:00:14
      Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
      System drive C: has 73 GB (49%) free of 147 GB
      Total RAM: 1014 MB (18% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 17:01:36, on 16/09/2009
      Platform: Windows Vista SP1 (WinNT 6.00.1905)
      MSIE: Internet Explorer v8.00 (8.00.6001.18813)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\Dwm.exe
      C:\Windows\system32\taskeng.exe
      C:\Windows\Explorer.EXE
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\hp\support\hpsysdrv.exe
      C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
      C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
      C:\Windows\RtHDVCpl.exe
      C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Alwil Software\Avast4\ashDisp.exe
      C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
      C:\Windows\System32\hkcmd.exe
      C:\Windows\System32\igfxpers.exe
      C:\Program Files\Common Files\Real\Update_OB\realsched.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Windows\ehome\ehtray.exe
      C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
      C:\Users\André\AppData\Local\eamkcio.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Windows\system32\igfxsrvc.exe
      C:\Windows\ehome\ehmsas.exe
      C:\Program Files\vghd\VirtuaGirl_downloader.exe
      C:\Program Files\Windows Live\Contacts\wlcomm.exe
      C:\hp\kbd\kbd.exe
      C:\Program Files\Windows Mail\WinMail.exe
      C:\Windows\system32\wuauclt.exe
      C:\Program Files\Google\Chrome\Application\chrome.exe
      C:\Program Files\Google\Chrome\Application\chrome.exe
      C:\Program Files\Google\Chrome\Application\chrome.exe
      C:\Program Files\Google\Chrome\Application\chrome.exe
      C:\Users\André\Documents\Downloads\RSIT.exe
      C:\Windows\system32\SearchFilterHost.exe
      C:\Program Files\trend micro\André.exe
      C:\Windows\System32\wsqmcons.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/webhp?gws_rd=ssl#max4
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O1 - Hosts: ::1 localhost
      O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
      O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: BHO Barre de Confiance - {988B07F5-7392-455A-8A1F-64935CB8B6ED} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O3 - Toolbar: Barre de confiance - {55BDF3B0-C0A8-481A-B8A6-01CD2BE0F3FD} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
      O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
      O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
      O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
      O4 - HKLM\..\Run: [CCUTRAYICON] FactoryMode
      O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      O4 - HKLM\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALuNotify.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
      O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
      O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
      O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
      O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
      O4 - HKCU\..\Run: [eamkcio] "c:\users\andré\appdata\local\eamkcio.exe" eamkcio
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
      O4 - Startup: DesktopVideoPlayer.LNK = C:\Program Files\vghd\vghd.exe
      O13 - Gopher Prefix:
      O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://ushousecall02.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
      O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
      O23 - Service: Service Google Update (gupdate1c9ae565ffe3ec0) (gupdate1c9ae565ffe3ec0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
      O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
      O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe
      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
      O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
      O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
      O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
      O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
      O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
      0
      1. Contributeur sécurité
        Télécharge et installe UsbFix de C_XX & Chiquitine29 :

        Tu utilises vista, tu dois donc désactiver l'UAC avant d'utiliser ces logiciels.

        # Désactiver le contrôle des comptes utilisateurs (le réactiver à la fin de la désinfection) :
        # Aller dans démarrer puis Panneau de configuration.
        # Double-cliquer sur l'icône "Comptes d'utilisateurs".
        # Cliquer ensuite sur désactiver et valider.

        ici un tuto

        https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

        lien de téléchargement


        http://sd-1.archive-host.com/membres/up/127028005715545653/UsbFix.exe

        Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...)sans les ouvrir !

        *fait un clique droit sur UsbFix.exe présent sur le bureau.et exécute le en tant qu'administrateur

        Tape F pour français , et pressez enter pour valider

        Dans le second menu qui apparait

        * Choisis l’option 1 (Recherche)

        * Laisse travailler l’outil.cela peut prendre plusieurs minutes, soit patient
        * Ensuite poste l’intégralité du rapport UsbFix.txt qui apparaîtra.

        Notes :
        - Le rapport UsbFix.txt est sauvegardé a la racine du disque. (C:\UsbFix.txt)

        (CTRL+A Pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller sur le forum).

        - "Process.exe", une composante de l’outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s’agit pas d’un virus, mais d’un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d’où l’alerte émise par ces antivirus.
        0
        1. VOILA LE RAPPORT USBFIX.TXT
          Merci
          ############################## | UsbFix V6.033 |

          User : André (Administrateurs) # PC-DE-BUREAU
          Update on 14/09/2009 by Chiquitine29, C_XX & Chimay8
          Start at: 18:05:54 | 16/09/2009
          Website : http://pagesperso-orange.fr/NosTools/index.html

          Intel(R) Pentium(R) D CPU 3.00GHz
          Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
          Internet Explorer 8.0.6001.18813
          Windows Firewall Status : Enabled
          AV : avast! antivirus 4.8.1229 [VPS 081201-0] 4.8.1229 [ Enabled | Updated ]

          C:\ -> Disque fixe local # 143,88 Go (70,5 Go free) [HP] # NTFS
          D:\ -> Disque fixe local # 5,17 Go (899,61 Mo free) [Recovery] # NTFS
          E:\ -> Disque CD-ROM # 621,05 Mo (0 Mo free) [BOMPARD] # UDF
          F:\ -> Disque amovible
          G:\ -> Disque amovible
          H:\ -> Disque amovible
          I:\ -> Disque amovible
          J:\ -> Disque amovible # 976,12 Mo (914,78 Mo free) # FAT

          ############################## | Processus actifs |

          C:\Windows\System32\smss.exe
          C:\Windows\system32\csrss.exe
          C:\Windows\system32\csrss.exe
          C:\Windows\system32\wininit.exe
          C:\Windows\system32\services.exe
          C:\Windows\system32\lsass.exe
          C:\Windows\system32\lsm.exe
          C:\Windows\system32\winlogon.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\SLsvc.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\Windows\System32\spoolsv.exe
          C:\Windows\system32\svchost.exe
          C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
          C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
          c:\Program Files\Common Files\LightScribe\LSSrvc.exe
          C:\Windows\system32\svchost.exe
          C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
          C:\Windows\system32\svchost.exe
          C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\SearchIndexer.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\Windows\system32\WUDFHost.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\system32\Dwm.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\Explorer.EXE
          C:\Program Files\Windows Defender\MSASCui.exe
          C:\hp\support\hpsysdrv.exe
          C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
          C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
          C:\Windows\RtHDVCpl.exe
          C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
          C:\Program Files\QuickTime\qttask.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\Program Files\Alwil Software\Avast4\ashDisp.exe
          C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
          C:\Windows\System32\igfxpers.exe
          C:\Program Files\Common Files\Real\Update_OB\realsched.exe
          C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
          C:\Program Files\Java\jre6\bin\jusched.exe
          C:\Program Files\Windows Sidebar\sidebar.exe
          C:\Windows\ehome\ehtray.exe
          C:\Windows\system32\igfxsrvc.exe
          C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
          C:\Users\André\AppData\Local\eamkcio.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\iPod\bin\iPodService.exe
          C:\Windows\ehome\ehmsas.exe
          C:\Program Files\vghd\VirtuaGirl_downloader.exe
          C:\Windows\system32\wbem\wmiprvse.exe
          C:\Program Files\Windows Mail\WinMail.exe
          C:\Program Files\Windows Live\Contacts\wlcomm.exe
          C:\Windows\system32\wbem\wmiprvse.exe
          C:\hp\kbd\kbd.exe
          C:\Program Files\Google\Chrome\Application\chrome.exe
          C:\Program Files\Google\Chrome\Application\chrome.exe
          C:\Windows\system32\wuauclt.exe
          C:\Windows\system32\conime.exe

          ################## | Fichiers # Dossiers infectieux |

          D:\desktop.ini

          ################## | Registre # Clés Run infectieuses |

          ################## | Registre # Mountpoints2 |

          HKCU\..\..\Explorer\MountPoints2\{12a7651c-ba35-11dd-9f1f-001a925d23a3}
          shell\Auto\command =cmd /C launch.bat
          shell\AutoRun\command =C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL cmd /C launch.bat

          HKCU\..\..\Explorer\MountPoints2\{7e9c44f4-bc8e-11dc-b309-001a925d23a3}
          shell\AutoRun\command =J:\InstallTomTomHOME.exe

          HKCU\..\..\Explorer\MountPoints2\{e623e40c-8344-11de-9048-001a925d23a3}
          shell\Auto\command =J:\launcher.exe
          shell\AutoRun\command =C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL J:\launcher.exe

          ################## | ! Fin du rapport # UsbFix V6.033 ! |
          0
          1. Contributeur sécurité
            relance usbfix

            Choisie l'option 2(Suppression)toujours avec un clique droit et exécute le en tant qu'administrateur

            Le bureau disparait et le pc redémarre
            Patiente le temps du scan.
            le rapport UsbFix.txt est sauvegardé à la racine du disque
            Faites en un copier/coller dans le bloc notes pour le poster.
            0
            1. Et voila ...

              ############################## | UsbFix V6.033 |

              User : André (Administrateurs) # PC-DE-BUREAU
              Update on 14/09/2009 by Chiquitine29, C_XX & Chimay8
              Start at: 19:00:05 | 16/09/2009
              Website : http://pagesperso-orange.fr/NosTools/index.html

              Intel(R) Pentium(R) D CPU 3.00GHz
              Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
              Internet Explorer 8.0.6001.18813
              Windows Firewall Status : Enabled
              AV : avast! antivirus 4.8.1229 [VPS 081201-0] 4.8.1229 [ Enabled | Updated ]

              C:\ -> Disque fixe local # 143,88 Go (70,43 Go free) [HP] # NTFS
              D:\ -> Disque fixe local # 5,17 Go (899,61 Mo free) [Recovery] # NTFS
              E:\ -> Disque CD-ROM # 621,05 Mo (0 Mo free) [BOMPARD] # UDF
              F:\ -> Disque amovible
              G:\ -> Disque amovible
              H:\ -> Disque amovible
              I:\ -> Disque amovible
              J:\ -> Disque amovible # 976,12 Mo (914,78 Mo free) # FAT

              ############################## | Processus actifs |

              C:\Windows\System32\smss.exe
              C:\Windows\system32\csrss.exe
              C:\Windows\system32\wininit.exe
              C:\Windows\system32\csrss.exe
              C:\Windows\system32\services.exe
              C:\Windows\system32\lsass.exe
              C:\Windows\system32\lsm.exe
              C:\Windows\system32\winlogon.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\LogonUI.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\SLsvc.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\Windows\System32\spoolsv.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
              C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
              c:\Program Files\Common Files\LightScribe\LSSrvc.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\SearchIndexer.exe
              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              C:\Windows\system32\WUDFHost.exe
              C:\Windows\system32\taskeng.exe
              C:\Windows\system32\taskeng.exe
              C:\Windows\system32\userinit.exe
              C:\Windows\system32\Dwm.exe
              C:\Windows\Explorer.EXE
              C:\Windows\system32\runonce.exe
              C:\Windows\system32\conime.exe
              C:\Windows\system32\wbem\wmiprvse.exe

              ################## | Fichiers # Dossiers infectieux |

              Supprimé ! D:\desktop.ini

              ################## | Registre # Clés Run infectieuses |

              ################## | Registre # Mountpoints2 |

              Supprimé ! HKCU\...\Explorer\MountPoints2\{12a7651c-ba35-11dd-9f1f-001a925d23a3}\Shell\Auto\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{7e9c44f4-bc8e-11dc-b309-001a925d23a3}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{e623e40c-8344-11de-9048-001a925d23a3}\Shell\Auto\Command

              ################## | Listing des fichiers présent |

              [18/09/2006 23:43|--a------|24] C:\autoexec.bat
              [19/01/2008 09:45|-rahs----|333203] C:\bootmgr
              [31/10/2008 01:57|-ra-s----|8192] C:\BOOTSECT.BAK
              [18/09/2006 23:43|--a------|10] C:\config.sys
              [16/05/2007 17:49|---hs----|5381] C:\ffastun.ffa
              [16/05/2007 17:49|---hs----|188416] C:\ffastun.ffl
              [16/05/2007 17:49|--ah-----|86016] C:\ffastun.ffo
              [16/05/2007 17:49|---hs----|4608000] C:\ffastun0.ffx
              [?|?|?] C:\hiberfil.sys
              [16/05/2007 17:40|-rahs----|0] C:\IO.SYS
              [16/05/2007 17:40|-rahs----|0] C:\MSDOS.SYS
              [?|?|?] C:\pagefile.sys
              [30/10/2008 17:14|--a------|402] C:\RHDSetup.log
              [16/09/2009 19:03|--a------|3837] C:\UsbFix.txt
              [04/10/2006 01:02|--ahs----|438328] D:\boo.mgr
              [02/11/2006 02:53|--ahs----|438840] D:\bootmgr
              [16/05/2007 17:47|--ah-----|4109] D:\ffastun.ffa
              [16/05/2007 17:47|--ah-----|8192] D:\ffastun.ffl
              [16/05/2007 17:47|--ah-----|4096] D:\ffastun.ffo
              [16/05/2007 17:47|--ah-----|4096] D:\ffastun0.ffx
              [31/10/2008 03:08|--ahs----|106] D:\MASTER.LOG
              [15/05/2007 21:17|--ah-----|487] D:\pcdr.ini
              [10/09/2002 14:58|--ahs----|181616] D:\Protect.ed
              [31/10/2008 03:08|--ahs----|44] D:\RESTORE.INI
              [18/10/2006 12:09|--ahs----|34] D:\SystemRecovery.txt

              ################## | Upload |

              Veuillez envoyer le fichier : C:\Users\ANDR~1\Desktop\UsbFix_Upload_Me_PC-de-bureau.zip : https://www.androidworld.fr/
              Merci pour votre contribution .
              0
              1. Contributeur sécurité
                envoie le fichier comme demander a la fin du rapport

                télécharge malwarbyte http://www.malwarebytes.org/mbam/program/mbam-setup.exe

                a l'installation vérifie que mise a jour et lancer programme et scan complet sont bien cocher


                Une fois a jour, le programme va se lancer; clic sur l´onglet paramètre, et coche la case : "Arrêter internet explorer pendant la suppression".

                A la fin du scan clique sur Afficher les résultats

                Suppression des éléments détectés >>>> clique sur Supprimer la sélection ou supprimer tout
                S'il t'es demandé de redémarrer >>> clique sur "Yes"


                Et tu poste le rapport générer

                Par Manque De Curiosité On Risque De Mourir Ignorant;Tu es libre de penser que tu es C..,
                Mais C.. de penser que ­tu es libre...Merci a australe13
                0
                1. Contributeur sécurité
                  salut

                  on a pas fini y'a quelque reste
                  0
                  1. Contributeur sécurité
                    SALUT

                    tu peut m'envoyer le rapport malwarbyte et un nouveau rapport rsit
                    0
                    1. Désolé de ne pas avoir répondu plus vite mais j'étais au travail.

                      Malwarebytes' Anti-Malware 1.41
                      Version de la base de données: 2812
                      Windows 6.0.6001 Service Pack 1

                      16/09/2009 20:40:10
                      mbam-log-2009-09-16 (20-40-10).txt

                      Type de recherche: Examen complet (C:\|D:\|)
                      Eléments examinés: 271358
                      Temps écoulé: 1 hour(s), 12 minute(s), 32 second(s)

                      Processus mémoire infecté(s): 0
                      Module(s) mémoire infecté(s): 0
                      Clé(s) du Registre infectée(s): 2
                      Valeur(s) du Registre infectée(s): 1
                      Elément(s) de données du Registre infecté(s): 0
                      Dossier(s) infecté(s): 0
                      Fichier(s) infecté(s): 3

                      Processus mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Module(s) mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Clé(s) du Registre infectée(s):
                      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\SOFTWARE\fcn (Rogue.Residue) -> Quarantined and deleted successfully.

                      Valeur(s) du Registre infectée(s):
                      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\eamkcio (Trojan.Agent.H) -> Quarantined and deleted successfully.

                      Elément(s) de données du Registre infecté(s):
                      (Aucun élément nuisible détecté)

                      Dossier(s) infecté(s):
                      (Aucun élément nuisible détecté)

                      Fichier(s) infecté(s):
                      c:\Users\André\AppData\Local\eamkcio.exe (Trojan.Agent.H) -> Delete on reboot.
                      C:\Users\André\Local Settings\Application Data\eamkcio_nav.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
                      C:\Users\André\Local Settings\Application Data\eamkcio_navps.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.

                      Logfile of random's system information tool 1.06 (written by random/random)
                      Run by André at 2009-09-17 21:01:07
                      Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
                      System drive C: has 71 GB (48%) free of 147 GB
                      Total RAM: 1014 MB (26% free)

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 21:01:50, on 17/09/2009
                      Platform: Windows Vista SP1 (WinNT 6.00.1905)
                      MSIE: Internet Explorer v8.00 (8.00.6001.18813)
                      Boot mode: Normal

                      Running processes:
                      C:\Windows\system32\Dwm.exe
                      C:\Windows\system32\taskeng.exe
                      C:\Windows\Explorer.EXE
                      C:\Windows\System32\mobsync.exe
                      C:\Program Files\Windows Defender\MSASCui.exe
                      C:\hp\support\hpsysdrv.exe
                      C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
                      C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                      C:\Windows\RtHDVCpl.exe
                      C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                      C:\Program Files\QuickTime\qttask.exe
                      C:\Program Files\iTunes\iTunesHelper.exe
                      C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                      C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
                      C:\Windows\System32\hkcmd.exe
                      C:\Windows\System32\igfxpers.exe
                      C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                      C:\Program Files\Java\jre6\bin\jusched.exe
                      C:\Windows\system32\igfxsrvc.exe
                      C:\Program Files\Windows Sidebar\sidebar.exe
                      C:\Windows\ehome\ehtray.exe
                      C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                      C:\Program Files\Windows Mail\WinMail.exe
                      C:\Windows\ehome\ehmsas.exe
                      C:\Program Files\Windows Live\Contacts\wlcomm.exe
                      C:\hp\kbd\kbd.exe
                      C:\Windows\system32\wuauclt.exe
                      C:\Program Files\Google\Chrome\Application\chrome.exe
                      C:\Program Files\Google\Chrome\Application\chrome.exe
                      C:\Program Files\Google\Chrome\Application\chrome.exe
                      C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
                      C:\Windows\system32\NOTEPAD.EXE
                      C:\Program Files\Google\Chrome\Application\chrome.exe
                      C:\Users\André\Documents\Downloads\RSIT (1).exe
                      C:\Program Files\trend micro\André.exe

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                      O1 - Hosts: ::1 localhost
                      O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                      O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                      O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: BHO Barre de Confiance - {988B07F5-7392-455A-8A1F-64935CB8B6ED} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                      O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                      O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                      O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                      O3 - Toolbar: Barre de confiance - {55BDF3B0-C0A8-481A-B8A6-01CD2BE0F3FD} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
                      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                      O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                      O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
                      O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
                      O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
                      O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
                      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                      O4 - HKLM\..\Run: [CCUTRAYICON] FactoryMode
                      O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
                      O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                      O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                      O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                      O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
                      O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
                      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                      O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
                      O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
                      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                      O13 - Gopher Prefix:
                      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                      O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
                      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                      O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
                      O23 - Service: Service Google Update (gupdate1c9ae565ffe3ec0) (gupdate1c9ae565ffe3ec0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                      O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                      O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe
                      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                      O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
                      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                      O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
                      O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
                      O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                      O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
                      O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                      O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
                      0
                      1. Contributeur sécurité
                        télécharge navilog1 sur le bureau :
                        http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

                        1° clique droit sur navilog1.exe présent sur ton bureau et excute le en tant qu'administrateur
                        2° Sélectionnez la langue désirée dans le menu puis valide le choix par la touche « entrer »
                        3° Petit message d’avertissement, appuie sur une touche pour passe à la suite
                        4° un nouveau avertissement, appuie sur une touche pour suivre
                        5° Vérification de l’installation de Navilog1 : si tout est bon, appuie sur une touche pour continuer
                        Choisir option 1 : recherche/désinfection automatique
                        7° La recherche va se lancer automatiquement et peut durée quelques minutes, patiente
                        8° Une fois l’analyse terminé, fermez et enregistre ton travail en cours, puis appuie sur une touche pour que le pc puisse démarrer
                        9° Au redémarrage du pc, Navilog va supprimer ce qu’il a trouvé, patiente quelques instants.

                        Un rapport est génère par l'outil. Il se trouve à cette emplacement :

                        démarrer »/ordinateur/c:/ cleannavi.txt
                        0
                        1. Fix Navipromo version 4.0.2 commencé le 17/09/2009 22:27:42,22

                          !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                          !!! Postez ce rapport sur le forum pour le faire analyser !!!

                          Outil exécuté depuis C:\Program Files\navilog1

                          Mise à jour le 27.08.2009 à 11h00 par IL-MAFIOSO

                          Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
                          X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) D CPU 3.00GHz )
                          BIOS : Phoenix - AwardBIOS v6.00PG
                          USER : André ( Administrator )
                          BOOT : Normal boot

                          Antivirus : avast! antivirus 4.8.1229 [VPS 081201-0] 4.8.1229 (Activated)

                          C:\ (Local Disk) - NTFS - Total:143 Go (Free:69 Go)
                          D:\ (Local Disk) - NTFS - Total:5 Go (Free:0 Go)
                          E:\ (CD or DVD) - UDF - Total:0 Go (Free:0 Go)
                          F:\ (USB)
                          G:\ (USB)
                          H:\ (USB)
                          I:\ (USB)

                          Recherche executée en mode normal

                          Nettoyage exécuté au redémarrage de l'ordinateur

                          C:\Users\Andr‚\AppData\Local\eamkcio.dat supprimé !

                          Nettoyage contenu C:\Windows\Temp effectué !
                          Nettoyage contenu C:\Users\ANDR~1\AppData\Local\Temp effectué !

                          *** Sauvegarde du Registre vers dossier Safebackup ***

                          sauvegarde du Registre réalisée avec succès !

                          *** Nettoyage Registre ***

                          Nettoyage Registre Ok

                          Certificat Egroup supprimé !
                          Certificat Electronic-Group supprimé !
                          Certificat OOO-Favorit supprimé !

                          *** Scan terminé 17/09/2009 22:51:30,34 ***
                          0
                          1. Contributeur sécurité
                            pour nettoyer les fix qui ont servit

                            Ferme toutes les applications en cours, puis télécharge ToolsCleaner2 sur ton Bureau.
                            https://www.commentcamarche.net/telecharger/securite/22061-toolscleaner/

                            Double clique sur ToolsCleaner2.exe >
                            puis Recherche
                            et sur Suppression
                            Note : ton bureau va disparaître, c'est normal. S'il n'apparaît pas à la fin du scan, fais la manip suivante :

                            CTRL+ALT+SUPP pour ouvrir le Gestionnaire des tâches.
                            Puis rends toi à l'onglet "Processus". Clique en haut à gauche sur Fichiers et choisis "Exécuter"

                            Tape explorer.exe et valide. Cela fera re-apparaître le Bureau

                            tu poste le rapport générer après suppression
                            0
                            1. rapport obtenu après avoir fait 2 fois la procédure
                              [ Rapport ToolsCleaner version 2.3.10 (par A.Rothstein & dj QUIOU) ]

                              --> Recherche:

                              C:\cleannavi.txt: trouvé !
                              C:\UsbFix.txt: trouvé !
                              C:\Program Files\Navilog1: trouvé !
                              C:\Program Files\Navilog1\Navilog1.bat: trouvé !
                              C:\Program Files\Navilog1\catchme.exe: trouvé !
                              C:\Program Files\trend micro\HijackThis.exe: trouvé !
                              C:\Program Files\trend micro\hijackthis.log: trouvé !

                              ---------------------------------
                              --> Suppression:

                              C:\Program Files\Navilog1\Navilog1.bat: ERREUR DE SUPPRESSION !!
                              C:\Program Files\Navilog1\catchme.exe: ERREUR DE SUPPRESSION !!
                              C:\Program Files\trend micro\HijackThis.exe: ERREUR DE SUPPRESSION !!
                              C:\cleannavi.txt: ERREUR DE SUPPRESSION !!
                              C:\UsbFix.txt: ERREUR DE SUPPRESSION !!
                              C:\Program Files\trend micro\hijackthis.log: ERREUR DE SUPPRESSION !!
                              C:\Program Files\Navilog1: ERREUR DE SUPPRESSION !!
                              0
                              1. Contributeur sécurité
                                bonjour

                                tu redémarre et tu relance toolscleaner avec un clic droit et exécute le en tant qu'administrateur

                                Par Manque De Curiosité On Risque De Mourir Ignorant;Tu es libre de penser que tu es C..,
                                Mais C.. de penser que ­tu es libre...Merci a australe13
                                0
                                1. -> Suppression:

                                  C:\Program Files\Navilog1\Navilog1.bat: supprimé !
                                  C:\Program Files\Navilog1\catchme.exe: supprimé !
                                  C:\Program Files\trend micro\HijackThis.exe: supprimé !
                                  C:\cleannavi.txt: supprimé !
                                  C:\UsbFix.txt: supprimé !
                                  C:\Program Files\trend micro\hijackthis.log: supprimé !
                                  C:\Program Files\Navilog1: supprimé !

                                  Je crois que j'ai enfin compris : je ne le lançais pas en tant qu'administrateur.
                                  Merci pour ton aide
                                  0
                                  1. Contributeur sécurité
                                    Ok

                                    tu va télécharger Ccleaner https://www.ccleaner.com/ccleaner/download

                                    ouvre "Ccleaner" vas dans l'onglet "Option" puis "Avancé" puis décoches "Effacer uniquement les fichiers, du dossier temp de Windows, plus vieux que 48 heures."

                                    . Puis vas dans l'onglet "Nettoyeur" fais "Analyse" puis "Lancer le nettoyage".
                                    Puis vas dans l'onglet "Registre" puis fait "Chercher des erreurs" puis "Réparer les erreurs sélectionnée"
                                    . Tu refais tous ca 4-5 fois (le nettoyage et le registre).

                                    Puis reste dans "Ccleaner" puis va dans "Option" puis "Propriété" puis coches "Nettoyer automatiquement l'ordinateur au démarrage".

                                    içi mode d'emploi pour ccleaner

                                    https://www.malekal.com/tutoriel-ccleaner/
                                    0