Uc 100%

Bonjour,
je sait il y a beaucoup de sujets sur ce probleme mais aucun d'eux n'a resolu le mien qui est :
depuis quelque temps quand je demarre mon ordi j'ai l'uc qui est exploité a 100% notament par svchost.exe, apres 5min l'uc revien a la normale je crois que c'est un virus ou trojan, et il se peux que le probleme vienne de mon antivirus kaspersky 2010 que je vien d'installer ya pas longtemp, et de temp en temps j'ai ce probleme d'uc quand je travaille ou quand je navique sur internet, j'ai aussi remarqué que mon ordi a perdu un peu de vitesse

merci de votre aide
Configuration: Windows XP Internet Explorer 7.0
kaspersky internet security 2010
RAM 1G

21 réponses

  1. Contributeur sécurité
    bonjour, oui possible car kaspersky est un peut gourmant et ram !!
    0
    1. ce ne peut pas etre un ver ?
      0
      1. Contributeur sécurité
        si tu crain une infection malgrés le plus performant des anti-virus poste un RSIT pour voir cela

        • Télécharge Random's System Information Tool (RSIT) de Random/Random, et enregistre le sur ton Bureau.
        • Double clique sur RSIT.exe pour lancer l'outil.
        • Clique sur "Continue" à l'écran Disclaimer.
        • Si l'outil HijackThis n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu s'il te le demande) et tu devras accepter la licence.
        • Une fois le scan terminé, deux rapports vont apparaître : poste les dans deux messages séparés stp

        ps:Les rapports se trouvent à cet endroit:

        C:\rsit\info.txt

        C:\rsit\log.txt

        Tutoriel pour t'aider

        0
        1. ok merci je vais le faire
          0
          1. desolé pour l'attente voila les rapports

            le premier

            info.txt logfile of random's system information tool 1.06 2009-09-20 17:21:42

            ======Uninstall list======

            -->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
            -->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
            -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
            Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
            Adobe Flash Player 10 Plugin-->MsiExec.exe /X{ECA1A3B6-898F-4DCE-9F04-714CF3BA126B}
            Adobe Reader 9.1 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A91000000001}
            Advertising Center-->MsiExec.exe /X{b2ec4a38-b545-4a00-8214-13fe0e915e6d}
            Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
            AviSynth 2.5-->"C:\Program Files\AviSynth 2.5\Uninstall.exe"
            CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
            Cleaner 5 EZ-->C:\WINDOWS\unvise32.exe C:\Program Files\Cleaner 5 EZ\uninstal.log
            Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
            Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
            Correctif pour Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
            Correctif pour Windows XP (KB970653-v3)-->"C:\WINDOWS\$NtUninstallKB970653-v3$\spuninst\spuninst.exe"
            DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
            DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
            DivX Plus DirectShow Filters-->C:\Program Files\DivX\DivXDSFiltersUninstall.exe /DSFILTERS
            DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
            DVD Decoder Pak for Windows XP-->MsiExec.exe /X{92C5DB3D-9D6F-4324-BB11-57825F4C2635}
            Fast Browser Search (My Tattoons)-->regsvr32 /u /s "C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll"
            Free Download Manager 3.0-->"C:\Program Files\Free Download Manager\unins000.exe"
            Google Chrome-->"C:\Program Files\Google\Chrome\Application\3.0.195.21\Installer\setup.exe" --uninstall --system-level
            Google Toolbar for Firefox-->MsiExec.exe /X{2CCBABCB-6427-4A55-B091-49864623C43F}
            Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_E582EA556D8DE101.exe" /uninstall
            Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
            Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
            HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
            Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
            Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
            Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
            Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
            Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
            Intel(R) Extreme Graphics 2 Driver-->RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2572
            Java(TM) 6 Update 15-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216014FF}
            Kaspersky Internet Security 2010-->MsiExec.exe /I{9D8B0949-7C47-476F-9F06-F900D3B078EA}
            Kaspersky Internet Security 2010-->MsiExec.exe /I{9D8B0949-7C47-476F-9F06-F900D3B078EA}
            Kit de Connexion MENARA-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AB25E068-C7A2-482F-A3BC-588A5869844D}\setup.exe" -l0x40c ControlPanel
            K-Lite Mega Codec Pack 5.1.0-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
            Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
            Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
            Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
            Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
            Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
            Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
            Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
            Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
            Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
            Microsoft Office InfoPath MUI (French) 2007-->MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}
            Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
            Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
            Microsoft Office Professional Plus 2007-->"C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
            Microsoft Office Professional Plus 2007-->MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}
            Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
            Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
            Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
            Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
            Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
            Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
            Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
            Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
            Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
            Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
            Microsoft SQL Server 2005 Express Edition (SONY_MEDIAMGR2)-->MsiExec.exe /I{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}
            Microsoft SQL Server 2005-->"c:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\ARPWrapper.exe" /Remove
            Microsoft SQL Server Native Client-->MsiExec.exe /I{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}
            Microsoft SQL Server Setup Support Files (English)-->MsiExec.exe /X{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}
            Microsoft SQL Server VSS Writer-->MsiExec.exe /I{56B4002F-671C-49F4-984C-C760FE3806B5}
            Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
            Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
            Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
            Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Lecteur Windows Media (KB968816)-->"C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Lecteur Windows Media (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB969897)-->"C:\WINDOWS\ie7updates\KB969897-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 8 (KB969897)-->"C:\WINDOWS\ie8updates\KB969897-IE8\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 8 (KB971961)-->"C:\WINDOWS\ie8updates\KB971961-IE8\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 8 (KB972260)-->"C:\WINDOWS\ie8updates\KB972260-IE8\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB956744)-->"C:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB956844)-->"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB958215)-->"C:\WINDOWS\$NtUninstallKB958215$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB960714)-->"C:\WINDOWS\$NtUninstallKB960714$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB961371)-->"C:\WINDOWS\$NtUninstallKB961371$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB969898)-->"C:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB971557)-->"C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB973346)-->"C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB973354)-->"C:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB973507)-->"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB973869)-->"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
            Mise à jour pour Windows Internet Explorer 8 (KB971930)-->"C:\WINDOWS\ie8updates\KB971930-IE8\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB961503)-->"C:\WINDOWS\$NtUninstallKB961503$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB968389)-->"C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB973815)-->"C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
            Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - FRA\install.exe
            MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
            MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
            MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
            MSXML 4.0 SP2 and SOAP Toolkit 3.0-->MsiExec.exe /I{32343DB6-9A52-40C9-87E4-5E7C79791C87}
            MSXML 6.0 Parser-->MsiExec.exe /I{A43BF6A5-D5F0-4AAA-BF41-65995063EC44}
            MySQL Connector/ODBC 3.51-->MsiExec.exe /I{0CB3C535-1171-4A20-B549-E2CB5DEB9723}
            Nero 9 Trial-->C:\Program Files\Fichiers communs\Nero\Nero ProductInstaller 4\SetupX.exe REMOVESERIALNUMBER="8M01-209M-AH6P-5UW0-WHAW-C53X-473X-79MH"
            Nero CoverDesigner-->MsiExec.exe /X{62ac81f6-bdd3-4110-9d36-3e9eaab40999}
            Nero Installer-->MsiExec.exe /X{e8a80433-302b-4ff1-815d-fcc8eac482ff}
            Nero Recode-->MsiExec.exe /X{359cfc0a-beb1-440d-95ba-cf63a86da34f}
            Nero StartSmart-->MsiExec.exe /X{7748ac8c-18e3-43bb-959b-088faea16fb2}
            Nero Vision-->MsiExec.exe /X{43e39830-1826-415d-8bae-86845787b54b}
            Nero WaveEditor-->MsiExec.exe /X{a209525b-3377-43f4-b886-32f6b6e7356f}
            NeroBurningROM-->MsiExec.exe /X{d025a639-b9c9-417d-8531-208859000af8}
            NeroExpress-->MsiExec.exe /X{595a3116-40bb-4e0f-a2e8-d7951da56270}
            neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
            Notepad++-->C:\Program Files\Notepad++\uninstall.exe
            Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
            Package de pilotes Windows - MobileTop (sshpmdm) Modem (12/06/2005 2.4.0)-->C:\PROGRA~1\DIFX\7B44739871F4D539FA473F57A832EA4B6A59EF06\DPInst.exe /u C:\WINDOWS\system32\DRVSTORE\shpacm_7EC0F399201103077F3FFB84BBD51AE2588894D9\shpacm.inf
            Package de pilotes Windows - MobileTop (sshpusb) USB (12/06/2005 2.4.0)-->C:\PROGRA~1\DIFX\7B44739871F4D539FA473F57A832EA4B6A59EF06\DPInst.exe /u C:\WINDOWS\system32\DRVSTORE\shpusb_38B1C9B64C9368D24AD0CD8D7030BACD9384F055\shpusb.inf
            PremiereAVSPlugin 1.5-->C:\Downloads\Software\Premiere AVS Plugin uninst.exe
            RichFX Player-->RunDll32 C:\PROGRA~1\COMMON~1\RichFX\npvpg004.dll,Uninstall_Player
            Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
            Sony Media Manager 2.3-->MsiExec.exe /X{07B562FD-E90D-4DC8-89E8-75C706D06E2B}
            SoundTrax-->MsiExec.exe /X{c5a7cb6c-e76d-408f-ba0e-85605420fe9d}
            TeamSpeak 2 RC2-->"C:\Program Files\Teamspeak2_RC2\unins000.exe"
            Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
            Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
            Update for Outlook 2007 Junk Email Filter (kb973514)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {03B11C77-336F-43B4-9B43-79890BA84504}
            VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
            Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
            Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
            Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
            Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
            Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
            Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
            Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
            Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
            Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
            WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
            World of Warcraft-->C:\Program Files\Fichiers communs\Blizzard Entertainment\World of Warcraft\Uninstall.exe
            XML Paper Specification Shared Components Language Pack 1.0-->"C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe"

            ======Security center information======

            AV: Kaspersky Internet Security
            FW: Kaspersky Internet Security

            ======System event log======

            Computer Name: MAROC-20AFAD566
            Event Code: 7036
            Message: Le service Gestionnaire de connexions d'accès distant est entré dans l'état : en cours d'exécution.

            Record Number: 10553
            Source Name: Service Control Manager
            Time Written: 20090820182957.000000+060
            Event Type: Informations
            User:

            Computer Name: MAROC-20AFAD566
            Event Code: 7035
            Message: Un contrôle Démarrer a correctement été envoyé au service Gestionnaire de connexions d'accès distant.

            Record Number: 10552
            Source Name: Service Control Manager
            Time Written: 20090820182954.000000+060
            Event Type: Informations
            User: AUTORITE NT\SYSTEM

            Computer Name: MAROC-20AFAD566
            Event Code: 7036
            Message: Le service Téléphonie est entré dans l'état : en cours d'exécution.

            Record Number: 10551
            Source Name: Service Control Manager
            Time Written: 20090820182954.000000+060
            Event Type: Informations
            User:

            Computer Name: MAROC-20AFAD566
            Event Code: 7036
            Message: Le service Service COM de gravage de CD IMAPI est entré dans l'état : en cours d'exécution.

            Record Number: 10550
            Source Name: Service Control Manager
            Time Written: 20090820182954.000000+060
            Event Type: Informations
            User:

            Computer Name: MAROC-20AFAD566
            Event Code: 7036
            Message: Le service Service de découvertes SSDP est entré dans l'état : en cours d'exécution.

            Record Number: 10549
            Source Name: Service Control Manager
            Time Written: 20090820182954.000000+060
            Event Type: Informations
            User:

            =====Application event log=====

            Computer Name: MAROC-20AFAD566
            Event Code: 1022
            Message: Produit : Microsoft Office Professional Plus 2007 - La mise à jour 'Update for Outlook 2007 Junk Email Filter (kb962871)' a été installée.

            Record Number: 582
            Source Name: MsiInstaller
            Time Written: 20090313140232.000000+000
            Event Type: Informations
            User: MAROC-20AFAD566\amine

            Computer Name: MAROC-20AFAD566
            Event Code: 1800
            Message: Le service Centre de sécurité Windows a démarré.

            Record Number: 581
            Source Name: SecurityCenter
            Time Written: 20090313135729.000000+000
            Event Type: Informations
            User:

            Computer Name: MAROC-20AFAD566
            Event Code: 0
            Message:
            Record Number: 580
            Source Name: gusvc
            Time Written: 20090313070901.000000+000
            Event Type: Informations
            User:

            Computer Name: MAROC-20AFAD566
            Event Code: 0
            Message:
            Record Number: 579
            Source Name: gusvc
            Time Written: 20090313070701.000000+000
            Event Type: Informations
            User:

            Computer Name: MAROC-20AFAD566
            Event Code: 1800
            Message: Le service Centre de sécurité Windows a démarré.

            Record Number: 578
            Source Name: SecurityCenter
            Time Written: 20090313060647.000000+000
            Event Type: Informations
            User:

            ======Environment variables======

            "ComSpec"=%SystemRoot%\system32\cmd.exe
            "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Samsung\Samsung PC Studio 5\;c:\Program Files\Microsoft SQL Server\90\Tools\binn\;C:\Program Files\Fichiers communs\DivX Shared\
            "windir"=%SystemRoot%
            "FP_NO_HOST_CHECK"=NO
            "OS"=Windows_NT
            "PROCESSOR_ARCHITECTURE"=x86
            "PROCESSOR_LEVEL"=15
            "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 2 Stepping 9, GenuineIntel
            "PROCESSOR_REVISION"=0209
            "NUMBER_OF_PROCESSORS"=1
            "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
            "TEMP"=%SystemRoot%\TEMP
            "TMP"=%SystemRoot%\TEMP

            -----------------EOF-----------------

            le deuxieme

            Logfile of random's system information tool 1.06 (written by random/random)
            Run by amine at 2009-09-20 17:21:21
            Microsoft Windows XP Professionnel Service Pack 3
            System drive C: has 2 GB (6%) free of 36 GB
            Total RAM: 1015 MB (44% free)

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 17:21:38, on 20-09-2009
            Platform: Windows XP SP3 (WinNT 5.01.2600)
            MSIE: Internet Explorer v8.00 (8.00.6001.18702)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Java\jre6\bin\jqs.exe
            C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe
            c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\igfxtray.exe
            C:\WINDOWS\system32\hkcmd.exe
            C:\WINDOWS\system32\igfxpers.exe
            C:\Program Files\Java\jre6\bin\jusched.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Windows Live\Messenger\msnmsgr.exe
            C:\Program Files\Free Download Manager\fdm.exe
            C:\Program Files\Menara\dslmon.exe
            C:\WINDOWS\system32\taskmgr.exe
            C:\Program Files\Windows Live\Contacts\wlcomm.exe
            C:\Program Files\Internet Explorer\IEXPLORE.EXE
            C:\Program Files\Internet Explorer\IEXPLORE.EXE
            c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
            C:\Program Files\Internet Explorer\IEXPLORE.EXE
            C:\Downloads\Software\RSIT.exe
            C:\Program Files\trend micro\amine.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.menara.ma/
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Menara
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
            O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
            O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
            O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
            O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll
            O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
            O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
            O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
            O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
            O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
            O2 - BHO: Search Assistant - {F0626A63-410B-45E2-99A1-3F2475B2D695} - C:\Program Files\SGPSA\BHO.dll
            O2 - BHO: XBTBPos00 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll (file missing)
            O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
            O3 - Toolbar: Fast Browser Search Toolbar - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll (file missing)
            O4 - HKLM\..\Run: [igfxtray] "C:\WINDOWS\system32\igfxtray.exe"
            O4 - HKLM\..\Run: [igfxhkcmd] "C:\WINDOWS\system32\hkcmd.exe"
            O4 - HKLM\..\Run: [igfxpers] "C:\WINDOWS\system32\igfxpers.exe"
            O4 - HKLM\..\Run: [Bar] C:\Downloads\Software\MediaPlayerUpgrade.exe
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
            O4 - HKLM\..\Run: [Microsoft Update] msnmsg.exe
            O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe"
            O4 - HKLM\..\RunServices: [Microsoft Update] msnmsg.exe
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
            O4 - HKCU\..\Run: [Software Informer] "C:\Program Files\Software Informer\softinfo.exe" -autorun
            O4 - HKCU\..\Run: [Free Download Manager] "C:\Program Files\Free Download Manager\fdm.exe" -autorun
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
            O4 - Global Startup: DSLMON.lnk = C:\Program Files\Menara\dslmon.exe
            O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
            O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
            O8 - Extra context menu item: Tout télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
            O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
            O8 - Extra context menu item: Télécharger la sélection avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
            O8 - Extra context menu item: Télécharger la vidéo avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
            O9 - Extra button: &Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
            O9 - Extra button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
            O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/WebfettiInitialSetup1.0.1.1.cab
            O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
            O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://www.catalog.update.microsoft.com/ClientControl/en/x86/MuCatalogWebControl.cab?1233765419187
            O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} (Battlefield Heroes Updater) - https://www.battlefieldheroes.com/static/updater/BFHUpdater_4.0.23.0.cab
            O17 - HKLM\System\CCS\Services\Tcpip\..\{8FCF1711-F3F1-47B8-9D26-41E6643E12CB}: NameServer = 62.251.229.223 62.251.229.237
            O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~2\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~2\kloehk.dll
            O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
            O23 - Service: ???? ????? Google (gupdate1ca33f781dd5dec) (gupdate1ca33f781dd5dec) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
            O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
            O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe
            0
            1. Contributeur sécurité
              ok tu passes usbfix option 1 et 2 et toolbar S&D et tu postes un nouveau log.txt de RSIT , Merci

              1) pour usbfix

              • Télécharge et install http://sd-1.archive-host.com/membres/up/127028005715545653/UsbFix.exe de C_XX & Chiquitine29

              (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

              • Double clic sur le raccourci UsbFix présent sur ton bureau .

              • Choisis l'option 1 ( Recherche )

              • Laisse travailler l'outil.

              • Ensuite post le rapport UsbFix.txt qui apparaitra.

              • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

              ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

              • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
              Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
              Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

              • Tuto : http://pagesperso-orange.fr/NosTools/usbfix.html

              ##################### | Suppression | option 2############

              (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d avoir été infectés sans les ouvrir

              • Double clic sur le raccourci UsbFix présent sur ton bureau

              • choisis l'option 2 ( Suppression )

              • Ton bureau disparaitra et le pc redémarrera .

              • Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.

              • Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .

              • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

              ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

              . UsbFix te proposera d'uploader un dossier compressé à cette adresse : https://www.androidworld.fr/

              Ce dossier a été créé par UsbFix et est enregistré sur ton bureau.

              Merci de l'envoyer à l'adresse indiquée afin d'aider l'auteur de UsbFix dans ses recherches.

              Merci d'avance pour ta contribution !!

              2) pour tollbar

              Télécharge ToolBar-S&D ( Merci à Eric_71, Angeldark, Sham_Rock et XmichouX )
              https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cpVobGk5bHnxrhQ4yaoEUDJvOYNnEGyYjgqHZz5GqZLfutR3fMFPlsC3-CGIilfupPAguYATNyua3csodN_frdMK8sSzUpit10Yac-QJCOkMqJKkbdKcP6ySs8trWPgoNVIq4TGGWCe6o0txXQv-ZueJF9vZzw3RXsGwFYIqN2lvF2LPdQzS8mE1d5kWOVOz6EMzQuE5-lClSJM869uq3oc7-t7yg%3D%3D&attredirects=3

              Lances l'installation du programme en exécutant le fichier téléchargé.
              Double-clique maintenant sur le raccourci de Toolbar-S&D.
              Sélectionnes la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
              Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
              Postes le rapport généré. (C:\TB.txt)

              Suppression option 2

              Relance Toolbar-S&D en double-cliquant sur le raccourci. Tape sur "2" puis valide en appuyant sur "Entrée".
              ! Ne ferme pas la fenêtre lors de la suppression !
              Un rapport sera généré, poste son contenu ici.

              NOTE : Si ton Bureau ne réapparait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
              Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."
              Tape explorer puis valide.

              Aide en images: https://sites.google.com/site/toolbarsd/aideenimages

              3) relances RSIT et poste le log.txt

              0
              1. le lien pour telecharger usb fix http://sd-1.archive-host.com/membres/up/127028005715545653/UsbFix.exe
                ne fonctionne pas :s
                0
                1. Contributeur sécurité
                  bizare il fonctionne chez moi je te le poste je l'ai renommé cela peut permettre de contrer l'infection http://sd-1.archive-host.com/membres/up/89820622056365782/jacusb.exe tu le télécharge sur ton bureau et tu suis la procédure comme pour usbfix
                  0
                  1. ba non je ne peux toujours pas le telecharger ca me met internet explorer ne pux pas afficher la page, ca se pourais que le probleme vient de la ? je telecharge firefox ?
                    0
                    1. Contributeur sécurité
                      sinon poste un Email et après mangé je te le postes par Email en piéce jointe tu mets mon pseudo @hotmail.fr
                      0
                      1. je n'ai pas bien compri ^^" je t'ai envoyé mon adresse email par mp j'attend ta reponse, bon appetit
                        0
                        1. quand je dezip le fichier ya beaucoup de dossier et d'application qui apparaissent comme "bypass.exe" le dossier "fich" le dossier "tools" par contre je ne trouve pas l'aplication set up

                          merci de ton aide je sait je suis trop supide ^^"
                          0
                          1. Contributeur sécurité
                            ok je ne pensais pas qu'il se dézipait comme cela tans ce cas tu double clique sur l'icône marqué usbfix
                            0
                            1. j'ai selectionné l'option 1 voila le rapport (enfin)^^

                              ############################## | UsbFix V6.035 |

                              User : amine (Administrateurs) # MAROC-20AFAD566
                              Update on 20/09/2009 by Chiquitine29, C_XX & Chimay8
                              Start at: 20:24:45 | 20-09-2009
                              Website : http://pagesperso-orange.fr/NosTools/index.html

                              Intel(R) Pentium(R) 4 CPU 2.66GHz
                              Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
                              Internet Explorer 8.0.6001.18702
                              Windows Firewall Status : Disabled
                              AV : Kaspersky Internet Security 9.0.0.463 [ Enabled | Updated ]
                              FW : Kaspersky Internet Security[ Enabled ]9.0.0.463

                              A:\ -> Lecteur de disquettes 3 ½ pouces
                              C:\ -> Disque fixe local # 34.97 Go (2.01 Go free) # NTFS
                              D:\ -> Disque CD-ROM

                              ############################## | Processus actifs |

                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\csrss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\Program Files\Java\jre6\bin\jqs.exe
                              C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe
                              c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
                              c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\igfxtray.exe
                              C:\WINDOWS\system32\igfxpers.exe
                              C:\Program Files\Java\jre6\bin\jusched.exe
                              C:\WINDOWS\system32\ctfmon.exe
                              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                              C:\Program Files\Free Download Manager\fdm.exe
                              C:\Program Files\Menara\dslmon.exe
                              C:\WINDOWS\system32\taskmgr.exe
                              C:\WINDOWS\System32\alg.exe
                              C:\Program Files\Windows Live\Contacts\wlcomm.exe
                              C:\Program Files\Internet Explorer\IEXPLORE.EXE
                              C:\Program Files\Internet Explorer\IEXPLORE.EXE
                              C:\Program Files\Internet Explorer\IEXPLORE.EXE
                              c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
                              C:\WINDOWS\system32\wbem\wmiprvse.exe

                              ################## | Fichiers # Dossiers infectieux |

                              C:\WINDOWS\admintxt.txt

                              ################## | Registre # Clés Run infectieuses |

                              [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableRegistryTools"
                              [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableTaskMgr"

                              ################## | Registre # Mountpoints2 |

                              HKCU\..\..\Explorer\MountPoints2\{3a1b8f7a-f373-11dd-ad7a-4d6564696130}
                              Shell\AutoRun\command =GuelmimG.bat
                              Shell\explore\Command =GuelmimG.bat -e
                              Shell\open\Command =GuelmimG.bat

                              ################## | ! Fin du rapport # UsbFix V6.035 ! |
                              0
                              1. Contributeur sécurité
                                tu refait pareil et option 2 et tu fais toolbar après
                                0
                                1. apres l'option 2

                                  voila le rapport

                                  ############################## | UsbFix V6.035 |

                                  User : amine (Administrateurs) # MAROC-20AFAD566
                                  Update on 20/09/2009 by Chiquitine29, C_XX & Chimay8
                                  Start at: 20:31:00 | 20-09-2009
                                  Website : http://pagesperso-orange.fr/NosTools/index.html

                                  Intel(R) Pentium(R) 4 CPU 2.66GHz
                                  Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
                                  Internet Explorer 8.0.6001.18702
                                  Windows Firewall Status : Enabled
                                  AV : Kaspersky Internet Security 9.0.0.463 [ Enabled | Updated ]
                                  FW : Kaspersky Internet Security[ Enabled ]9.0.0.463

                                  A:\ -> Lecteur de disquettes 3 ½ pouces
                                  C:\ -> Disque fixe local # 34.97 Go (1.99 Go free) # NTFS
                                  D:\ -> Disque CD-ROM

                                  ############################## | Processus actifs |

                                  C:\WINDOWS\System32\smss.exe
                                  C:\WINDOWS\system32\csrss.exe
                                  C:\WINDOWS\system32\winlogon.exe
                                  C:\WINDOWS\system32\services.exe
                                  C:\WINDOWS\system32\lsass.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\Explorer.EXE
                                  C:\WINDOWS\system32\spoolsv.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\Program Files\Java\jre6\bin\jqs.exe
                                  C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe
                                  C:\Program Files\Google\Update\GoogleUpdate.exe
                                  c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
                                  c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\Program Files\Google\Update\GoogleUpdate.exe
                                  C:\WINDOWS\system32\wbem\wmiprvse.exe
                                  C:\WINDOWS\System32\alg.exe

                                  ################## | Fichiers # Dossiers infectieux |

                                  Supprimé ! C:\WINDOWS\admintxt.txt

                                  ################## | Registre # Clés Run infectieuses |

                                  Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableRegistryTools"
                                  Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableTaskMgr"

                                  ################## | Registre # Mountpoints2 |

                                  Supprimé ! HKCU\...\Explorer\MountPoints2\{3a1b8f7a-f373-11dd-ad7a-4d6564696130}\Shell\AutoRun\Command

                                  ################## | Listing des fichiers présent |

                                  [02/03/2009 08:09 PM|--a------|0] C:\AUTOEXEC.BAT
                                  [02/03/2009 08:04 PM|---hs----|212] C:\boot.ini
                                  [08/28/2001 12:00 PM|-rahs----|4952] C:\Bootfont.bin
                                  [02/21/2009 05:57 PM|--a------|74] C:\CMLoader.log
                                  [03/23/2009 07:48 PM|--a------|0] C:\cmserver.log
                                  [02/03/2009 08:09 PM|--a------|0] C:\CONFIG.SYS
                                  [03/23/2009 07:48 PM|--a------|0] C:\conmgr.log
                                  [02/05/2009 01:58 PM|--a------|216790] C:\coreuninstall.log
                                  [02/03/2009 08:09 PM|-rahs----|0] C:\IO.SYS
                                  [02/03/2009 08:09 PM|-rahs----|0] C:\MSDOS.SYS
                                  [08/03/2004 10:38 PM|-rahs----|47564] C:\NTDETECT.COM
                                  [02/08/2009 06:23 PM|-rahs----|252240] C:\ntldr
                                  [?|?|?] C:\pagefile.sys
                                  [09/20/2009 08:33 PM|--a------|2846] C:\UsbFix.txt

                                  ################## | Vaccination |

                                  # C:\autorun.inf -> Folder created by UsbFix.

                                  ################## | ! Fin du rapport # UsbFix V6.035 ! |
                                  0
                                  1. pour l'option 1 de toolbar voila le rapport

                                    -----------\\ ToolBar S&D 1.2.9 XP/Vista

                                    Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
                                    X86-based PC ( Uniprocessor Free : Intel(R) Pentium(R) 4 CPU 2.66GHz )
                                    BIOS : Phoenix FirstBios(tm) Desktop Pro Version 2.0 for IBM ThinkCentre.
                                    USER : amine ( Administrator )
                                    BOOT : Normal boot
                                    Antivirus : Kaspersky Internet Security 9.0.0.463 (Activated)
                                    Firewall : Kaspersky Internet Security 9.0.0.463 (Activated)
                                    A:\ (USB)
                                    C:\ (Local Disk) - NTFS - Total:34 Go (Free:2 Go)
                                    D:\ (CD or DVD)

                                    "C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
                                    Option : [1] ( Sun 09/20/2009|20:42 )

                                    -----------\\ Recherche de Fichiers / Dossiers ...

                                    C:\Program Files\MyWebSearch
                                    C:\Program Files\MyWebSearch\bar
                                    C:\Program Files\MyWebSearch\SrchAstt
                                    C:\Program Files\MyWebSearch\bar\1.bin
                                    C:\Program Files\MyWebSearch\bar\Settings
                                    C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
                                    C:\Program Files\MyWebSearch\SrchAstt\1.bin
                                    C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
                                    C:\DOCUME~1\amine\Cookies\amine@mywebsearch[2].txt
                                    C:\WINDOWS\iun6002.exe

                                    -----------\\ Extensions

                                    (amine) - {20a82645-c095-46ed-80e3-08825760534b} => chrome_user

                                    -----------\\ [..\Internet Explorer\Main]

                                    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                                    "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
                                    "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
                                    "Search Page"="https://www.google.com/?gws_rd=ssl"
                                    "Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"

                                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                                    "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
                                    "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                                    "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                                    "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
                                    "Start Page"="https://www.msn.com/fr-fr"

                                    --------------------\\ Recherche d'autres infections

                                    Aucune autre infection trouvée !

                                    1 - "C:\ToolBar SD\TB_1.txt" - Sun 09/20/2009|20:43 - Option : [1]

                                    -----------\\ Fin du rapport a 20:43:23.70
                                    0
                                    1. je sais pas pourquoi mais mon ordi a planté en cour de l'option 2(suppression) de toolbar je refait l'option 2 ?
                                      0
                                      1. Contributeur sécurité
                                        si problème fais la en mode sans echec , bon moi dodo boulot dans 8h
                                        0
                                        1. et la pres ce plantage g un new prob c que mon inrternet commence a ramer^^ j'attend ta reponse je sait pas de quoi ca vien, merci et desolé pour la perte de temp, c'est tres gentil de ta part^^, a dmain
                                          0
                                          • 1
                                          • 2