Probleme apparement de virus (mon ordi rame)

Résolu
Bonjour, Je viens vers vous aprés avoir résolu un problème de branchement de clé pour le Wifi (voir discussion). Seulement maintenant j'ai un autre souci. Mon ordi rame pas mal sur internet et lorsque je l'allume il faut que je clic sur "connexion reseau" et que je clic sur "réparer" pour avoir enfin le reseau. de plus de tps en tps j'ai un message (lié a cette nouvelle clé wifi) "an unsupported operation was attempted". Et dernière chose lorsque je met l'ordi en veille il plante sur l'ecran bleu "préparation à la mise en veille". Smart91 m'a conseillé de me diriger vers vous (je reprécise mon faible niveau en informatique).
Mon fils à un portable qui utilise le meme reseau que le mien, et pour lui tous va bien. dans l'attente merci
Configuration: Windows XP
Firefox 3.0.15

32 réponses

Résumé de la discussion

Des problèmes sur un PC sous Windows XP provoquent lenteurs Internet, une connexion réseau à réparer au démarrage et message 'an unsupported operation was attempted', ainsi qu'écran bleu à la mise en veille. Des solutions proposées incluent l'exécution d'outils de diagnostic et la consultation de rapports système, ainsi que l'élimination potentielle de programmes indésirables au démarrage et la vérification des paramètres réseau. D'autres interventions consistent à partager des rapports techniques et des journaux système, notamment des logs générés par des outils comme HijackThis, afin d'identifier d'éventuels composants malveillants ou des conflits de configuration. En cas de persistance, l'examen du démarrage et de la sécurité peut être nécessaire, car la présence de services tiers et de modules peut influencer les symptômes.

Bobot (l’IA à votre service)
  1. bonjour

    Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

    -> http://images.malwareremoval.com/random/RSIT.exe

    ! Déconnecte toi et ferme toutes tes applications en cours !

    Double-clique sur " RSIT.exe " pour le lancer .

    -> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

    * Devant l'option "List files/folders created ..." , tu choisis : 2 months

    * clique ensuite sur " Continue " pour lancer l'analyse ...

    -> laisse faire le scan et ne touche pas au PC ...

    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

    Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

    Important : poste un rapport, puis l'autre dans la réponse suivante
    Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum

    ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )
    0
    1. merci, voila le premier
      info.txt logfile of random's system information tool 1.06 2009-11-14 16:24:49

      ======Uninstall list======

      -->"c:\apps\skype\phone\unins000.exe"
      -->C:\PROGRA~1\Norman\NORMAN~1\UNWISE.EXE C:\PROGRA~1\Norman\NORMAN~1\INSTALL.LOG
      -->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
      -->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
      -->C:\Program Files\Learn2.com\StRunner\stuninst.exe
      -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
      -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
      -->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
      -->MsiExec.exe /I{8B543A39-9401-44F4-B572-069E64C15189}
      -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\Setup.EXE" -uninstall
      -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3F9CFBD8-8F77-4DCD-8CB5-CDD5F653C872}\setup.exe" -l0x40c
      -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4F1DA6BF-3614-48A1-9970-9E90F646789E}\setup.exe" -l0x40c
      -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5A065EA0-0EEC-4E94-A2A0-40812576C122}\setup.exe" -l0x40c
      -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5AFA4872-16B2-419E-ADCA-8E96E739115D}\setup.exe" -l0x40c
      -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C151CE54-E7EA-4804-854B-F515368B0798}\setup.exe" -l0x40c
      -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0A32C786-85DE-48F8-9E54-848B3E34A90C}\setup.exe" -l0x40c -removeonly
      -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
      32 Bit HP CIO Components Installer-->MsiExec.exe /I{2614F54E-A828-49FA-93BA-45A3F756BFAA}
      Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
      Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
      Adobe Reader 7.0.9 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A70900000002}
      Alexandra Ledermann 4-->C:\Program Files\Ubi Soft\Lexis Numérique\Alexandra Ledermann 4\Desinst.exe
      Analyseur et SDK MSXML 4.0 SP2-->MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
      Apple Software Update-->MsiExec.exe /I{74EC78BC-B379-4E29-9006-8F161DCAABA6}
      Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
      Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
      ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
      Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE
      AVS DVD Player version 2.4-->"C:\Program Files\AVSMedia\DVDPlayer\unins000.exe"
      Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
      Codeur Windows Media Série 9-->MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
      Coffret de pilotes Logitech Webcam Software-->"C:\Program Files\Fichiers communs\LogiShrd\LogiDriverStore\lvdrivers\12.0.1278\LgDrvInst.exe" -remove -instdir"C:\Program Files\Fichiers communs\LogiShrd\LogiDriverStore\lvdrivers\" -enumdelay=200 -enabledifx -forcedelete -usbhubsfirst -forceremove -cumulativeremove -promptuninstall -arpregkey"lvdrivers_12.0" /clone_wait /hide_progress
      Compatibility Pack for the 2007 Office system-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
      Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
      Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
      Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
      Correctif pour Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
      Correctif pour Windows XP (KB970653-v3)-->"C:\WINDOWS\$NtUninstallKB970653-v3$\spuninst\spuninst.exe"
      Disc2Phone-->MsiExec.exe /I{FFAB5ABB-8AAB-42E2-847F-1743E51E01E9}
      Dofus 1.25.0-->C:\Program Files\Dofus\uninstall.exe
      Encyclopaedia Universalis-->"D:\Program Files\Encyclopaedia Universalis\Encyclopaedia Universalis\Uninstall_Encyclopaedia Universalis\Désinstaller Encyclopaedia Universalis 2009.exe"
      Enjoy 5e-->C:\WINDOWS\Enjoy 5e Uninstaller.exe
      Enjoy 6e-->C:\WINDOWS\Enjoy 6e Uninstaller.exe
      eoEngine 4.4-->"C:\Program Files\eoRezo\unins000.exe"
      eoWeather 4.2-->"C:\Program Files\eoRezo\EoAdv\unins000.exe"
      FileZilla Client 3.2.7.1-->C:\Program Files\FileZilla FTP Client\uninstall.exe
      FpTest 3.2-->D:\FpTest\uninst.exe
      Freeplayer-->C:\Program Files\Freeplayer\Uninstall.exe
      Garmin Communicator Plugin-->MsiExec.exe /X{10B3936F-0E93-4431-8E7B-3FEA5DAC88C3}
      GIMP 2.6.4-->"D:\Program Files\GIMP-2.0\setup\unins000.exe"
      Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
      Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar4.dll"
      HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
      HomePlayer 1.5.8a-->D:\HomePlayer\uninst.exe
      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
      Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
      HP Customer Participation Program 11.0-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat -forcereboot
      HP Imaging Device Functions 11.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
      HP Photosmart C4400 All-In-One Driver Software 11.0 Rel .3-->C:\Program Files\HP\Digital Imaging\{86732AE7-CB91-4f15-B091-FBA3D3926CD6}\setup\hpzscr01.exe -datfile hposcr29.dat -onestop
      HP Photosmart Essential 3.0-->C:\Program Files\HP\Digital Imaging\PhotoSmartEssential\hpzscr01.exe -datfile hpqbud13.dat -forcereboot
      HP Smart Web Printing-->C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpzscr01.exe -datfile hpqbud15.dat
      HP Solution Center 11.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat -forcereboot
      HP Update-->MsiExec.exe /X{FE57DE70-95DE-4B64-9266-84DA811053DB}
      Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
      Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
      J2SE Runtime Environment 5.0 Update 10-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150100}
      J2SE Runtime Environment 5.0 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150020}
      J2SE Runtime Environment 5.0 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}
      Java(TM) 6 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160060}
      Java(TM) SE Runtime Environment 6 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
      LeClerc Photogenie-->"C:\Program Files\LeClerc\Photogenie\unins000.exe"
      Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
      Logitech Vid-->MsiExec.exe /I{4FBCEA31-5D18-4212-9231-DE7CF1BE7DBB}
      Logitech Webcam Software-->MsiExec.exe /I{AC96671C-2001-432C-9826-5266D84EF1DC}
      Macromedia Shockwave Player-->MsiExec.exe /X{7D1D6A24-65D4-454C-8815-4F08A5FFF12C}
      Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
      Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
      Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
      Microsoft .NET Framework 1.1 Security Update (KB953297)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M953297\M953297Uninstall.msp"
      Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
      Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
      Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
      Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
      Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
      Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
      Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
      Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
      Microsoft Money-->C:\Program Files\Microsoft Money 2005\MNYCoreFiles\Setup\uninst.exe /s:120
      Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
      Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
      Microsoft Sites publics français-->MsiExec.exe /I{B72B0ECE-F41E-4EC4-AA37-1A00640680BF}
      Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
      Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
      Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour le Codeur Windows Media (KB954156)-->"C:\WINDOWS\$NtUninstallKB954156_WM9L$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media (KB954155)-->"C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media (KB968816)-->"C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Step by Step Interactive Training (KB898458)-->"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB928090)-->"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB931768)-->"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB933566)-->"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB969897)-->"C:\WINDOWS\ie7updates\KB969897-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB972260)-->"C:\WINDOWS\ie7updates\KB972260-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB974455)-->"C:\WINDOWS\ie7updates\KB974455-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB953155)-->"C:\WINDOWS\$NtUninstallKB953155$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956744)-->"C:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956844)-->"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958869)-->"C:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB961371)-->"C:\WINDOWS\$NtUninstallKB961371$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB969059)-->"C:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB969898)-->"C:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB969947)-->"C:\WINDOWS\$NtUninstallKB969947$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB971486)-->"C:\WINDOWS\$NtUninstallKB971486$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB971557)-->"C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB971961)-->"C:\WINDOWS\$NtUninstallKB971961$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB973346)-->"C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB973354)-->"C:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB973507)-->"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB973525)-->"C:\WINDOWS\$NtUninstallKB973525$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB973869)-->"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB974112)-->"C:\WINDOWS\$NtUninstallKB974112$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB974571)-->"C:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB975025)-->"C:\WINDOWS\$NtUninstallKB975025$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB975467)-->"C:\WINDOWS\$NtUninstallKB975467$\spuninst\spuninst.exe"
      Mise à jour pour Windows Internet Explorer 7 (KB976749)-->"C:\WINDOWS\ie7updates\KB976749-IE7\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB960763)-->"C:\WINDOWS\$NtUninstallKB960763$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB961503)-->"C:\WINDOWS\$NtUninstallKB961503$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB968389)-->"C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB973815)-->"C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
      Mozilla Firefox (3.0.15)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
      MP3 Player Utilities 3.79-->MsiExec.exe /I{7784A172-61F1-445E-8368-601607E0DD22}
      MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
      MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
      MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
      MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
      My Web Search (Smiley Central)-->rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsbar.dll,O
      Navilog1 3.6.0-->"C:\Program Files\Navilog1\unins000.exe"
      NETGEAR WG111v3 wireless USB 2.0 adapter-->C:\Program Files\InstallShield Installation Information\{5396FBD8-8BD7-47F9-92AE-F62F13D5A11D}\setup.exe -runfromtemp -l0x040c
      Netpass XP-->C:\Program Files\netpass\Uninstal.exe
      OCR Software by I.R.I.S. 11.0-->C:\Program Files\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
      OFFICE One 6.5-->c:\Program Files\OFFICE ONE6.5\program\setup.exe -deinstall
      Offre de services MSN-->C:\Program Files\MSN\MSNCoreFiles\Setup\msnunin.exe
      Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
      Pando-->MsiExec.exe /I{AB480DA0-7EE9-465D-9C12-4CDE65BF18FB}
      Panneau de contrôle ATI-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
      PosteRazor-->"D:\Program Files\PosteRazor\unins000.exe"
      QuickTime-->MsiExec.exe /I{95A890AA-B3B1-44B6-9C18-A8F7AB3EE7FC}
      Radio Media Player-->C:\Program Files\Windows Media Player\Plugins\Radios Media Player\uninst.exe
      Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\Setup.exe" -l0x40c REMOVE -removeonly
      SC Ver 2.67-->"C:\Program Files\SC\unins000.exe"
      Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
      Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
      Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
      Shop for HP Supplies-->C:\Program Files\HP\Digital Imaging\HPSSupply\hpzscr01.exe -datfile hpqbud16.dat
      Sonic MyDVD-->MsiExec.exe /I{21657574-BD54-48A2-9450-EB03B2C7FC29}
      TerraExplorer-->C:\Program Files\Skyline\TerraExplorer\Setup.exe [OP]/U
      TextBridge Classic-->"C:\PROGRA~1\TEXTBR~1\bin\setup.exe" -funinstal.ins
      Unlimited Video For PsP-->MsiExec.exe /I{537410A2-886A-4D55-9611-0A9B808FC70A}
      Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
      USB Flash Disk-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EDFEDAEF-95AA-11D7-A949-5254AB1235E1}\Setup.exe" -l0x9
      VideoLAN VLC media player 0.8.5-freehd-->C:\Program Files\VideoLAN\VLC\uninstall.exe
      Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
      Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
      Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
      Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
      Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
      Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
      Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"

      ======Security center information======

      AV: Norton AntiVirus 2005
      AV: AntiVir Desktop
      FW: Norton Internet Worm Protection
      FW: Norton Internet Security 2006

      ======System event log======

      Computer Name: AMELCLEM
      Event Code: 7035
      Message: Un contrôle Démarrer a correctement été envoyé au service Gestionnaire de connexions d'accès distant.

      Record Number: 10505
      Source Name: Service Control Manager
      Time Written: 20091016081414.000000+120
      Event Type: Informations
      User: AMELCLEM\Sylvain

      Computer Name: AMELCLEM
      Event Code: 7036
      Message: Le service Téléphonie est entré dans l'état : en cours d'exécution.

      Record Number: 10504
      Source Name: Service Control Manager
      Time Written: 20091016081414.000000+120
      Event Type: Informations
      User:

      Computer Name: AMELCLEM
      Event Code: 7035
      Message: Un contrôle Démarrer a correctement été envoyé au service Service de découvertes SSDP.

      Record Number: 10503
      Source Name: Service Control Manager
      Time Written: 20091016081413.000000+120
      Event Type: Informations
      User: AUTORITE NT\SYSTEM

      Computer Name: AMELCLEM
      Event Code: 7036
      Message: Le service Service COM de gravage de CD IMAPI est entré dans l'état : en cours d'exécution.

      Record Number: 10502
      Source Name: Service Control Manager
      Time Written: 20091016081413.000000+120
      Event Type: Informations
      User:

      Computer Name: AMELCLEM
      Event Code: 7035
      Message: Un contrôle Démarrer a correctement été envoyé au service Service COM de gravage de CD IMAPI.

      Record Number: 10501
      Source Name: Service Control Manager
      Time Written: 20091016081413.000000+120
      Event Type: Informations
      User: AUTORITE NT\SYSTEM

      =====Application event log=====

      Computer Name: AMELCLEM
      Event Code: 301
      Message: msnmsgr (2232) \\.\D:\Documents and Settings\Amélie\Local Settings\Application Data\Microsoft\Messenger\lili.loulouth@hotmail.fr\SharingMetadata\Working\database_C6C_5287_6C52_6B88\dfsr.db: Le moteur de base de données commence la relecture du fichier journal \\.\D:\Documents and Settings\Amélie\Local Settings\Application Data\Microsoft\Messenger\lili.loulouth@hotmail.fr\SharingMetadata\Working\database_C6C_5287_6C52_6B88\fsr.log.

      Record Number: 19466
      Source Name: ESENT
      Time Written: 20090215181434.000000+060
      Event Type: Informations
      User:

      Computer Name: AMELCLEM
      Event Code: 300
      Message: msnmsgr (2232) \\.\D:\Documents and Settings\Amélie\Local Settings\Application Data\Microsoft\Messenger\lili.loulouth@hotmail.fr\SharingMetadata\Working\database_C6C_5287_6C52_6B88\dfsr.db: Le moteur de base de données initialise la procédure de récupération.

      Record Number: 19465
      Source Name: ESENT
      Time Written: 20090215181434.000000+060
      Event Type: Informations
      User:

      Computer Name: AMELCLEM
      Event Code: 102
      Message: msnmsgr (2232) \\.\D:\Documents and Settings\Amélie\Local Settings\Application Data\Microsoft\Messenger\lili.loulouth@hotmail.fr\SharingMetadata\Working\database_C6C_5287_6C52_6B88\dfsr.db: Le moteur de base de données a démarré une nouvelle instance (0).

      Record Number: 19464
      Source Name: ESENT
      Time Written: 20090215181434.000000+060
      Event Type: Informations
      User:

      Computer Name: AMELCLEM
      Event Code: 100
      Message: msnmsgr (2232) Le moteur de base de données 5.01.2600.5512 est démarré.

      Record Number: 19463
      Source Name: ESENT
      Time Written: 20090215181434.000000+060
      Event Type: Informations
      User:

      Computer Name: AMELCLEM
      Event Code: 1001
      Message: Détecteur d'erreurs 1145434150.

      Record Number: 19462
      Source Name: Application Error
      Time Written: 20090215180002.000000+060
      Event Type: erreur
      User:

      ======Environment variables======

      "ComSpec"=%SystemRoot%\system32\cmd.exe
      "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\system32\WBEM;C:\ATI Technologies\ATI Control Panel;C:\Program Files\Fichiers communs\Ulead Systems\MPEG;C:\PROGRA~1\FICHIE~1\SONICS~1\;C:\Program Files\QuickTime\QTSystem\
      "windir"=%SystemRoot%
      "FP_NO_HOST_CHECK"=NO
      "OS"=Windows_NT
      "PROCESSOR_ARCHITECTURE"=x86
      "PROCESSOR_LEVEL"=15
      "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 47 Stepping 2, AuthenticAMD
      "PROCESSOR_REVISION"=2f02
      "NUMBER_OF_PROCESSORS"=1
      "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
      "TEMP"=%SystemRoot%\TEMP
      "TMP"=%SystemRoot%\TEMP
      "CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_01\lib\ext\QTJava.zip
      "QTJAVA"=C:\Program Files\Java\jre1.6.0_01\lib\ext\QTJava.zip

      -----------------EOF-----------------
      0
      1. salut, voila le deuxieme
        Logfile of random's system information tool 1.06 (written by random/random)
        Run by Sylvain at 2009-11-14 16:24:40
        Microsoft Windows XP Édition familiale Service Pack 3
        System drive C: has 10 GB (31%) free of 31 GB
        Total RAM: 1023 MB (53% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 16:24:46, on 14/11/2009
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16915)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Avira\AntiVir Desktop\sched.exe
        C:\Program Files\Avira\AntiVir Desktop\avguard.exe
        c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
        C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
        C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
        C:\WINDOWS\System32\GEARSec.exe
        c:\APPS\HIDSERVICE\HIDSERVICE.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
        c:\APPS\Powercinema\Kernel\TV\CLSched.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
        C:\Program Files\QuickTime\QTTask.exe
        C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
        C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
        C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe
        C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
        C:\WINDOWS\vsnpstd2.exe
        C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\Program Files\Logitech\Logitech Vid\vid.exe
        C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
        C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
        C:\Program Files\Outlook Express\msimn.exe
        C:\Program Files\Avira\AntiVir Desktop\update.exe
        D:\Documents and Settings\Sylvain\Bureau\RSIT.exe
        C:\Program Files\eden\HijackThis\Sylvain.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
        O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
        O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
        O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
        O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
        O2 - BHO: CInterceptor Object - {38D3FE60-3D53-4F37-BB0E-C7A97A26A156} - C:\Program Files\Pando Networks\Pando\PandoIEPlugin.dll
        O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
        O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\eoRezo\EoAdv\EoRezobho.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
        O2 - BHO: UrlHelper Class - {CFC4F59B-A2DA-4e12-B337-52A4F871E10C} - C:\Program Files\Shareaza Applications\Shareaza MediaBar\ShareazaIEHelper.dll (file missing)
        O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
        O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
        O3 - Toolbar: Shareaza MediaBar - {196C3A46-4758-433D-A600-802C804AF39C} - C:\Program Files\Shareaza Applications\Shareaza MediaBar\ShareazaMediaBar.dll (file missing)
        O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
        O4 - HKLM\..\Run: [nsvqrcf] c:\windows\system32\nsvqrcf.exe nsvqrcf
        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
        O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
        O4 - HKLM\..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL,UPF
        O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=2 /w /h
        O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
        O4 - HKLM\..\Run: [SNPSTD2] C:\WINDOWS\vsnpstd2.exe
        O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
        O4 - HKCU\..\Run: [Pando] "C:\Program Files\Pando Networks\Pando\Pando.exe" /Minimized
        O4 - HKCU\..\Run: [Logitech Vid] "C:\Program Files\Logitech\Logitech Vid\vid.exe" -bootmode
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O4 - Global Startup: Assistant Smart Wizard NETGEAR pour WG311v3.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
        O4 - Global Startup: NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
        O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZNfox000
        O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 3.79\AMVConverter\grab.html
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
        O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 3.79\MediaManager\grab.html
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
        O9 - Extra button: Traduction - {7A2EFD41-E6B3-11D2-89E3-00E0292EE574} - C:\Program Files\PROMT5\PROMTIE4\promtie5.htm
        O9 - Extra 'Tools' menuitem: Traduire - {7A2EFD41-E6B3-11D2-89E3-00E0292EE574} - C:\Program Files\PROMT5\PROMTIE4\promtie5.htm
        O9 - Extra button: (no name) - {7A2EFD41-E6B3-11D2-89E3-00E0292EE575} - C:\Program Files\PROMT5\PROMTIE4\options.htm
        O9 - Extra 'Tools' menuitem: Personnaliser les options de traduction - {7A2EFD41-E6B3-11D2-89E3-00E0292EE575} - C:\Program Files\PROMT5\PROMTIE4\options.htm
        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
        O9 - Extra button: Sélection intelligente HP - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
        O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
        O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
        O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
        O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
        O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
        O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
        O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
        O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
        O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
        O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
        O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
        O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
        O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
        O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
        O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
        O23 - Service: MysqlInventime - Unknown owner - C:\Apps\INVENT~1\mysql\bin\mysqld-nt.exe
        O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe
        O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
        O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
        0
        1. Contributeur sécurité
          Moi je commencerai par supprimer tout ce qui concerne "mywebsearch". Qu'en penses-tu totobetournes?

          Smart
          0
          1. re, pour moi pas de probleme, comment je fais ?
            0
            1. Contributeur sécurité
              Va sur le lien ci-dessous:
              http://www.malekal.com/MyWebSearch.php

              Smart
              0
              1. re, j'ai supprimé.
                Mais je pense qu'il s'agit plus d'une configuration ou un truc comme ma de ma clé. meme pour lire mes mails je bataille. et une fois sur deux je perd le reseau, je ne sais pas pourquoi
                0
                1. quelques lignes d infections my web search, eorezo et uner autre .

                  1)tu as 2 antivirus sur ton pc, c est un de trop vire norton.
                  utilise le lien pour bien enlever norton car il se met un peu partout et peut nuire au bon fonctionnement d antivir.
                  http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/fr_docid/20050414110429924?Open&src=&docid=20040413131641928&nsf=SUPPORT\INTER\nisintl.nsf&view=833aab0c51f1b15a88256da6006a0505&dtype=&prod=&ver=&osv=&osv_lvl=

                  2)pour voir télécharge combofix (par sUBs) ici :

                  http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                  et enregistre le sur le bureau.

                  déconnecte toi d'internet et ferme toutes tes applications.

                  désactive tes protections (antivirus, parefeu, garde en temps réel de l'antispyware)

                  double-clique sur combofix.exe et suis les instructions

                  à la fin, il va produire un rapport C:\ComboFix.txt

                  réactive ton parefeu, ton antivirus, la garde de ton antispyware

                  copie/colle le rapport C:\ComboFix.txt dans ta prochaine réponse.

                  Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi.

                  Tu as un tutoriel complet ici :

                  https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

                  3)telecharge cela et fait le fonctionner en option A.colle le rapport.

                  http://sd-1.archive-host.com/membres/up/16506160323759868/AD-R.exe

                  Déconnectes toi et fermes toutes applications en cours !

                  Relances "Ad-remover" : au menu principal choisi l'option "B" .
                  ? Ensuite coche: (le numero devant et entree)

                  Boonty/Boonty Games
                  eorezo
                  .......
                  Puis "S"

                  le programme va travailler ...

                  Postes le rapport qui apparait à la fin + un nouvel Hijackthis pour analyse ...

                  ( le rapport est sauvegardé aussi sous C:\Ad-report.log )

                  /!\ Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides) /!\
                  0
                  1. Salut, il y a un truc que je ne sais pas faire quand tu dit
                    "garde en temps réel de l'antispyware"
                    0
                    1. c est au cas ou tu aurais spybot ou equivalent avec une defence qui fonctionne des que ton pc s allume.c est bon.
                      0
                      1. salut, je viens aux nouvelles pour savoir ce que je dois faire à présent, car j'ai toujours des problèmes de connexions et surtout de lenteur. A chaque fois que j'allume mon PC il faut que je paramètre mon reseau pour avoir internet !!
                        0
                    2. salut, ok, voila le premier rapport combofix
                      ComboFix 09-11-16.01 - Sylvain 16/11/2009 16:01..1 - FAT32x86
                      Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1023.474 [GMT 1:00]
                      Lancé depuis: d:\documents and settings\Sylvain\Bureau\ComboFix.exe
                      AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
                      .

                      (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                      .

                      c:\program files\MyWebSearch
                      c:\program files\MyWebSearch\bar\History\search3
                      c:\program files\MyWebSearch\bar\Settings\s_pid.dat
                      c:\recycler\S-1-5-21-657302007-2249245105-1116331755-1003
                      c:\windows\system32\404Fix.exe
                      c:\windows\system32\dumphive.exe
                      c:\windows\system32\IEDFix.C.exe
                      c:\windows\system32\IEDFix.exe
                      c:\windows\system32\Process.exe
                      c:\windows\system32\SrchSTS.exe
                      c:\windows\system32\tmp.reg
                      c:\windows\system32\VACFix.exe
                      c:\windows\system32\VCCLSID.exe
                      c:\windows\system32\WS2Fix.exe
                      c:\windows\TEMP\logishrd\LVPrcInj01.dll

                      .
                      ((((((((((((((((((((((((((((( Fichiers créés du 2009-10-16 au 2009-11-16 ))))))))))))))))))))))))))))))))))))
                      .

                      2009-11-14 15:24 . 2009-11-14 15:24 -------- d-----w- C:\rsit
                      2009-11-12 18:04 . 2009-11-12 21:22 -------- d-----w- C:\OEMSettings
                      2009-11-12 17:12 . 2009-11-12 17:12 21035 ----a-w- c:\windows\system32\drivers\AegisP.sys
                      2009-11-12 17:12 . 2009-11-12 17:12 -------- d-----w- c:\program files\NETGEAR
                      2009-11-12 17:12 . 2009-11-12 17:12 -------- d-----w- c:\windows\Downloaded Installations

                      .
                      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                      .
                      2009-11-15 09:29 . 2005-11-06 23:37 -------- d-----w- d:\documents and settings\All Users\Application Data\Symantec
                      2009-11-14 20:21 . 2008-12-31 12:27 -------- d-----w- d:\documents and settings\Sylvain\Application Data\HPAppData
                      2009-11-14 20:21 . 2007-03-20 15:33 -------- d-----w- d:\documents and settings\Sylvain\Application Data\EoRezo
                      2009-11-12 21:20 . 2005-11-06 23:23 -------- d--h--w- c:\program files\InstallShield Installation Information
                      2009-11-11 16:38 . 2009-08-31 13:49 172018 ----a-w- d:\documents and settings\Sylvain\Application Data\mdbu.bin
                      2009-11-05 17:12 . 2004-08-16 16:41 86582 ----a-w- c:\windows\system32\perfc00C.dat
                      2009-11-05 17:12 . 2004-08-16 16:41 515112 ----a-w- c:\windows\system32\perfh00C.dat
                      2009-10-18 14:56 . 2007-12-18 18:13 -------- d-----w- c:\program files\Dofus
                      2009-09-11 14:18 . 2004-08-05 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
                      2009-09-04 21:04 . 2004-08-05 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
                      2009-09-04 15:17 . 2006-09-13 11:48 414492 ----a-w- c:\windows\Enjoy 6e Uninstaller.exe
                      2009-08-31 18:06 . 2005-12-31 16:53 100520 ----a-w- d:\documents and settings\Sylvain\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
                      2009-08-29 07:28 . 2004-08-05 12:00 832512 ----a-w- c:\windows\system32\wininet.dll
                      2009-08-29 07:28 . 2004-08-05 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
                      2009-08-29 07:28 . 2004-08-05 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
                      2009-08-28 18:37 . 2009-07-29 09:05 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
                      2009-08-26 08:01 . 2004-08-05 12:00 247326 ----a-w- c:\windows\system32\strmdll.dll
                      2007-03-12 21:19 . 2007-03-12 21:19 408665 ----a-w- c:\program files\instdb.inf
                      2007-03-12 21:19 . 2007-03-12 21:19 52883 ----a-w- c:\program files\setup.log
                      2007-03-12 21:19 . 2007-03-12 21:19 773 ----a-w- c:\program files\OFFICE One 6.5.lnk
                      2007-03-12 21:19 . 2007-03-12 21:19 761 ----a-w- c:\program files\OFFICE One Setup.lnk
                      2004-03-08 05:00 . 2004-03-08 05:00 7 ----a-r- c:\program files\ooversion.txt
                      2004-03-08 05:00 . 2004-03-08 05:00 20680 ----a-r- c:\program files\license.txt
                      2004-03-08 05:00 . 2004-03-08 05:00 17 ----a-r- c:\program files\license.html
                      2004-03-08 05:00 . 2004-03-08 05:00 15 ----a-r- c:\program files\readme.txt
                      2004-03-08 05:00 . 2004-03-08 05:00 0 ----a-r- c:\program files\readme.html
                      2007-01-28 22:55 . 2007-01-28 22:55 5 --sha-w- c:\windows\system32\dfafbecf8_s.dll
                      .

                      ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                      .
                      .
                      *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                      REGEDIT4

                      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-10 68856]
                      "updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
                      "Pando"="c:\program files\Pando Networks\Pando\Pando.exe" [2009-01-13 3699016]
                      "Logitech Vid"="c:\program files\Logitech\Logitech Vid\vid.exe" [2009-06-02 5451536]

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2005-11-06 180269]
                      "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-06-29 286720]
                      "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2008-03-25 49152]
                      "hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-03-13 81920]
                      "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
                      "SNPSTD2"="c:\windows\vsnpstd2.exe" [2004-08-30 286720]
                      "LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-05-08 2780432]

                      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                      "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

                      d:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                      Assistant Smart Wizard NETGEAR pour WG311v3.lnk - c:\program files\NETGEAR\WG111v3\WG111v3.exe [2008-7-1 1929216]
                      HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
                      Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
                      NETGEAR WG111v3 Smart Wizard.lnk - c:\program files\NETGEAR\WG111v3\WG111v3.exe [2008-7-1 1929216]
                      HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Norton Ghost 9.0
                      HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg

                      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
                      "DisableMonitoring"=dword:00000001

                      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
                      "DisableMonitoring"=dword:00000001

                      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                      "EnableFirewall"= 0 (0x0)

                      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                      "%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
                      "%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
                      "%windir%\\system32\\sessmgr.exe"=
                      "c:\\APPS\\Inventime\\my.exe"=
                      "c:\\APPS\\skype\\phone\\Skype.exe"=
                      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                      "c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
                      "c:\\Program Files\\Freeplayer\\vlc\\vlc.exe"=
                      "c:\\Program Files\\Pando Networks\\Pando\\pando.exe"=
                      "d:\\Program Files\\Encyclopaedia Universalis\\Encyclopaedia Universalis\\starter.exe"=
                      "c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqcopy2.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
                      "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
                      "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                      "c:\\Program Files\\FileZilla FTP Client\\filezilla.exe"=
                      "d:\\HomePlayer\\HomePlayer.exe"=
                      "d:\\HomePlayer\\VLC\\vlc.exe"=
                      "c:\\WINDOWS\\system32\\mmc.exe"=
                      "c:\\Program Files\\Logitech\\Logitech Vid\\Vid.exe"=

                      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
                      "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

                      R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [29/07/2009 10:05 108289]
                      R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [09/10/2007 13:13 38144]
                      R3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [07/11/2005 00:23 799744]
                      S0 PQV2i;PQV2i; [x]
                      S1 PQIMount;PQIMount; [x]
                      S2 MustekMA1908Driver;MustekMA1908Driver;\??\c:\windows\system32\drivers\ma1908.sys --> c:\windows\system32\drivers\ma1908.sys [?]
                      S3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\system32\drivers\wg111v3.sys [28/12/2007 15:02 287232]

                      --- Autres Services/Pilotes en mémoire ---

                      *NewlyCreated* - MBR
                      *Deregistered* - mbr

                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                      HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
                      hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
                      .
                      Contenu du dossier 'Tâches planifiées'

                      2009-11-10 c:\windows\Tasks\AppleSoftwareUpdate.job
                      - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-06-03 11:42]
                      .
                      .
                      ------- Examen supplémentaire -------
                      .
                      uStart Page = hxxp://www.google.fr/
                      uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
                      uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
                      IE: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZNfox000
                      IE: Add to AMV Convert Tool... - c:\program files\MP3 Player Utilities 3.79\AMVConverter\grab.html
                      IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                      IE: MediaManager tool grab multimedia file - c:\program files\MP3 Player Utilities 3.79\MediaManager\grab.html
                      IE: {{7A2EFD41-E6B3-11D2-89E3-00E0292EE574} - c:\program files\PROMT5\PROMTIE4\promtie5.htm
                      FF - ProfilePath - d:\documents and settings\Sylvain\Application Data\Mozilla\Firefox\Profiles\k4un3j3x.default\
                      FF - prefs.js: browser.search.selectedEngine - MyWebSearch
                      FF - prefs.js: keyword.URL - hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZNfox000&fl=0&ptb=uq99ciZPqS0pm0eC8IP7yw&url=https://hp.mywebsearch.com/mywebsearch/index.html
                      FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
                      .
                      - - - - ORPHELINS SUPPRIMES - - - -

                      BHO-{CFC4F59B-A2DA-4e12-B337-52A4F871E10C} - c:\program files\Shareaza Applications\Shareaza MediaBar\ShareazaIEHelper.dll
                      Toolbar-{196C3A46-4758-433D-A600-802C804AF39C} - c:\program files\Shareaza Applications\Shareaza MediaBar\ShareazaMediaBar.dll
                      WebBrowser-{196C3A46-4758-433D-A600-802C804AF39C} - c:\program files\Shareaza Applications\Shareaza MediaBar\ShareazaMediaBar.dll
                      AddRemove-HijackThis - c:\program files\Trend Micro\HijackThis\HijackThis.exe

                      **************************************************************************

                      catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                      Rootkit scan 2009-11-16 16:20
                      Windows 5.1.2600 Service Pack 3 NTFS

                      Recherche de processus cachés ...

                      Recherche d'éléments en démarrage automatique cachés ...

                      Recherche de fichiers cachés ...

                      Scan terminé avec succès
                      Fichiers cachés: 0

                      **************************************************************************

                      [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MysqlInventime]
                      "ImagePath"="c:\apps\INVENT~1\mysql\bin\mysqld-nt --defaults-file=c:\apps\Inventime\mysql\my.ini MysqlInventime"
                      .
                      --------------------- CLES DE REGISTRE BLOQUEES ---------------------

                      [HKEY_USERS\S-1-5-21-3041242532-4187237835-112036990-1007\Software\Microsoft\SystemCertificates\AddressBook*]
                      @Allowed: (Read) (RestrictedCode)
                      @Allowed: (Read) (RestrictedCode)

                      [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•9~*]
                      "C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
                      .
                      --------------------- DLLs chargées dans les processus actifs ---------------------

                      - - - - - - - > 'winlogon.exe'(552)
                      c:\windows\system32\Ati2evxx.dll

                      - - - - - - - > 'explorer.exe'(1536)
                      c:\windows\system32\eappprxy.dll
                      c:\windows\system32\WPDShServiceObj.dll
                      c:\windows\system32\PortableDeviceTypes.dll
                      c:\windows\system32\PortableDeviceApi.dll
                      .
                      ------------------------ Autres processus actifs ------------------------
                      .
                      c:\windows\system32\Ati2evxx.exe
                      c:\program files\Avira\AntiVir Desktop\avguard.exe
                      c:\apps\Powercinema\Kernel\TV\CLCapSvc.exe
                      c:\program files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
                      c:\windows\System32\GEARSec.exe
                      c:\program files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
                      c:\program files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
                      c:\apps\Powercinema\Kernel\TV\CLSched.exe
                      c:\windows\system32\Ati2evxx.exe
                      c:\program files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
                      c:\windows\system32\wscntfy.exe
                      c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
                      c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
                      c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
                      .
                      **************************************************************************
                      .
                      Heure de fin: 2009-11-16 16:25 - La machine a redémarré
                      ComboFix-quarantined-files.txt 2009-11-16 15:25

                      Avant-CF: 9 883 279 360 octets libres
                      Après-CF: 10 636 120 064 octets libres

                      - - End Of File - - CB24CC10DFB0868EADFEC159A195AFF0
                      0
                      1. BONJOUR

                        telecharge cela et fait le fonctionner en option A.colle le rapport.

                        http://sd-1.archive-host.com/membres/up/16506160323759868/AD-R.exe

                        Déconnectes toi et fermes toutes applications en cours !

                        Relances "Ad-remover" : au menu principal choisi l'option "B" .
                        ? Ensuite coche: (le numero devant et entree)

                        Boonty/Boonty Games
                        eorezo
                        .......
                        Puis "S"

                        le programme va travailler ...

                        Postes le rapport qui apparait à la fin + un nouvel Hijackthis pour analyse ...

                        ( le rapport est sauvegardé aussi sous C:\Ad-report.log )

                        /!\ Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides) /!\
                        0
                        1. salut, quand j'essaie de télécharger
                          http://sd-1.archive-host.com/membres/up/16506160323759868/AD­-R.exe
                          je tombe sur 404 not found
                          0
                          1. bonjour
                            je passe juste pour donner le lien
                            http://pagesperso-orange.fr/NosTools/C_XX/AD-R.exe
                            0
                        2. re, merci pour le lien. par contre je n'avais pas d'option "B" alors j'ai fait un scanner dont voici le rapport

                          .
                          ======= RAPPORT D'AD-REMOVER 1.1.4.6_D | UNIQUEMENT XP/VISTA/7 =======
                          .
                          Mit à jour par C_XX le 20.11.2009 à 7:00
                          Contact: AdRemover.contact@gmail.com
                          Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
                          .
                          Lancé à: 15:24:25, 20/11/2009 | Mode Normal | Option: SCAN
                          Exécuté de: C:\Program Files\Ad-Remover\
                          Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
                          Nom du PC: AMELCLEM | Utilisateur actuel: Sylvain
                          .
                          ============== ÉLÉMENT(S) TROUVÉ(S) ==============
                          .
                          D:\DOCUME~1\Sylvain\APPLIC~1\EoRezo
                          D:\DOCUME~1\Sylvain\APPLIC~1\ItsLabel
                          D:\DOCUME~1\Sylvain\APPLIC~1\Mozilla\Firefox\Profiles\k4un3j3x.default\searchplugins\mywebsearch.xml
                          C:\Program Files\EoRezo
                          C:\Program Files\Windows Live\Messenger\Riched20.dll
                          C:\Program Files\Windows Live\Messenger\Msimg32.dll
                          D:\DOCUME~1\Sylvain\Cookies\sylvain@ask[1].txt
                          D:\DOCUME~1\Sylvain\Cookies\sylvain@eurobarre[1].txt
                          D:\DOCUME~1\Sylvain\Cookies\sylvain@imgfarm[1].txt
                          D:\DOCUME~1\Sylvain\Cookies\sylvain@mysearch[2].txt
                          D:\DOCUME~1\Sylvain\Cookies\sylvain@mywebsearch[1].txt
                          D:\DOCUME~1\Sylvain\Cookies\sylvain@pacificpoker[1].txt
                          D:\DOCUME~1\Sylvain\Cookies\sylvain@popularscreensavers[1].txt
                          .
                          HKCU\software\EoRezo
                          HKCU\software\Fun Web Products
                          HKCU\software\ItsLabel
                          HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}
                          HKCU\software\MyWebSearch
                          HKLM\Software\Classes\CLSID\{64F56FC1-1272-44CD-BA6E-39723696E350}
                          HKLM\software\classes\EoRezoBHO.EoBho
                          HKLM\software\classes\EoRezoBHO.EoBho.1
                          HKLM\Software\Classes\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}
                          HKLM\Software\Classes\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}
                          HKLM\Software\Classes\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}
                          HKLM\Software\Classes\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}
                          HKLM\Software\Classes\TypeLib\{1FA7FC2D-1E2B-4220-A506-55B0CEE22DFD}
                          HKLM\Software\Classes\TypeLib\{B3A2ECDA-1487-4E7B-815E-D91E43AC79DC}
                          HKLM\Software\Classes\TypeLib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}
                          HKLM\Software\Classes\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}
                          HKLM\software\EoRezo
                          HKLM\software\Fun Web Products
                          HKLM\software\ItsLabel
                          HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481}
                          HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45DD-9B68-D6A12C30E5D7}
                          HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907}
                          HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48DD-9B6D-7A13A3E42127}
                          HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40FD-8DAE-FF14757F60C7}
                          HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA}
                          HKLM\Software\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll
                          HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}
                          HKLM\Software\Microsoft\Multimedia\WMPlayer\Schemes\f3pss
                          HKLM\software\microsoft\shared tools\msconfig\startupreg\seekmo
                          HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}
                          HKLM\software\microsoft\windows\currentversion\uninstall\eoEngine_is1
                          HKLM\software\microsoft\windows\currentversion\uninstall\eoWeather_is1
                          HKU\s-1-5-21-3041242532-4187237835-112036990-1007\software\EoRezo
                          HKU\s-1-5-21-3041242532-4187237835-112036990-1007\software\Fun Web Products
                          HKU\s-1-5-21-3041242532-4187237835-112036990-1007\software\ItsLabel
                          HKU\s-1-5-21-3041242532-4187237835-112036990-1007\software\MyWebSearch
                          .
                          ============== Scan additionnel ==============
                          .
                          .
                          * Mozilla FireFox Version 3.0.15 [fr] *
                          .
                          Nom du profil: k4un3j3x.default (Sylvain)
                          .
                          (Sylvain, prefs.js) Browser.download.lastDir, D:\Documents and Settings\All Users\Documents\photos pop
                          (Sylvain, prefs.js) Browser.search.selectedEngine, MyWebSearch
                          .
                          (Sylvain, prefs.js) TROUVE - Browser.search.selectedEngine, MyWebSearch
                          (Sylvain, prefs.js) TROUVE - Extensions.mywebsearch.openSearchURL, hxxp://search.mywebsearch.com/mywebsearch/opensearch.jhtml?id=ZNfox000&ptb=uq99ciZPqS0pm0eC8IP7yw
                          (Sylvain, prefs.js) TROUVE - Extensions.mywebsearch.prevKwdEnabled, true
                          (Sylvain, prefs.js) TROUVE - Extensions.mywebsearch.prevKwdURL, chrome://browser-region/locale/region.properties
                          (Sylvain, prefs.js) TROUVE - Keyword.URL, hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZNfox000&fl=0&ptb=uq99ciZPqS0pm0eC8IP7yw&url=hxxp://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st=kwd&searchfor=
                          .
                          .
                          * Internet Explorer Version 7.0.5730.11 *
                          .
                          [HKEY_CURRENT_USER\..\Internet Explorer\Main]
                          .
                          Start Page: hxxp://www.google.fr/
                          Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                          .
                          [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
                          .
                          Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=69157
                          Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
                          Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
                          Start Page: hxxp://go.microsoft.com/fwlink/?LinkId=69157
                          .
                          [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
                          .
                          Tabs: res://ieframe.dll/tabswelcome.htm
                          .
                          ===================================
                          .
                          5337 Octet(s) - C:\Ad-Report-SCAN[1].log
                          .
                          42 Fichier(s) - D:\DOCUME~1\Sylvain\LOCALS~1\Temp
                          4 Fichier(s) - C:\WINDOWS\Temp
                          .
                          2 Fichier(s) - C:\Program Files\Ad-Remover\BACKUP
                          0 Fichier(s) - C:\Program Files\Ad-Remover\QUARANTINE
                          .
                          Fin à: 15:33:57 | 20/11/2009 - SCAN[1]
                          .
                          ============== E.O.F ==============
                          .
                          fallait-il cela ?
                          0
                          1. maintenant fait la suppression et colle le rapport obtenu.
                            0
                            1. la suppression ?
                              0
                              1. option L
                                0
                            2. ok merci, voila le rapport

                              .
                              ======= RAPPORT D'AD-REMOVER 1.1.4.6_D | UNIQUEMENT XP/VISTA/7 =======
                              .
                              Mit à jour par C_XX le 20.11.2009 à 7:00
                              Contact: AdRemover.contact@gmail.com
                              Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
                              .
                              Lancé à: 16:02:48, 20/11/2009 | Mode Normal | Option: CLEAN
                              Exécuté de: C:\Program Files\Ad-Remover\
                              Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
                              Nom du PC: AMELCLEM | Utilisateur actuel: Sylvain
                              .
                              ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
                              .
                              D:\DOCUME~1\Sylvain\APPLIC~1\EoRezo
                              D:\DOCUME~1\Sylvain\APPLIC~1\ItsLabel
                              D:\DOCUME~1\Sylvain\APPLIC~1\Mozilla\Firefox\Profiles\k4un3j3x.default\searchplugins\mywebsearch.xml
                              C:\Program Files\EoRezo
                              C:\Program Files\Windows Live\Messenger\Riched20.dll
                              C:\Program Files\Windows Live\Messenger\Msimg32.dll
                              D:\DOCUME~1\Sylvain\Cookies\sylvain@ask[1].txt
                              D:\DOCUME~1\Sylvain\Cookies\sylvain@eurobarre[1].txt
                              D:\DOCUME~1\Sylvain\Cookies\sylvain@imgfarm[1].txt
                              D:\DOCUME~1\Sylvain\Cookies\sylvain@mysearch[2].txt
                              D:\DOCUME~1\Sylvain\Cookies\sylvain@mywebsearch[1].txt
                              D:\DOCUME~1\Sylvain\Cookies\sylvain@pacificpoker[1].txt
                              D:\DOCUME~1\Sylvain\Cookies\sylvain@popularscreensavers[1].txt
                              .
                              HKCU\software\EoRezo
                              HKCU\software\Fun Web Products
                              HKCU\software\ItsLabel
                              HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}
                              HKCU\software\MyWebSearch
                              HKLM\Software\Classes\CLSID\{64F56FC1-1272-44CD-BA6E-39723696E350}
                              HKLM\software\classes\EoRezoBHO.EoBho
                              HKLM\software\classes\EoRezoBHO.EoBho.1
                              HKLM\Software\Classes\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}
                              HKLM\Software\Classes\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}
                              HKLM\Software\Classes\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}
                              HKLM\Software\Classes\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}
                              HKLM\Software\Classes\TypeLib\{1FA7FC2D-1E2B-4220-A506-55B0CEE22DFD}
                              HKLM\Software\Classes\TypeLib\{B3A2ECDA-1487-4E7B-815E-D91E43AC79DC}
                              HKLM\Software\Classes\TypeLib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}
                              HKLM\Software\Classes\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}
                              HKLM\software\EoRezo
                              HKLM\software\Fun Web Products
                              HKLM\software\ItsLabel
                              HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481}
                              HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45DD-9B68-D6A12C30E5D7}
                              HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907}
                              HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48DD-9B6D-7A13A3E42127}
                              HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40FD-8DAE-FF14757F60C7}
                              HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA}
                              HKLM\Software\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll
                              HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}
                              HKLM\Software\Microsoft\Multimedia\WMPlayer\Schemes\f3pss
                              HKLM\software\microsoft\shared tools\msconfig\startupreg\seekmo
                              HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}
                              HKLM\software\microsoft\windows\currentversion\uninstall\eoEngine_is1
                              HKLM\software\microsoft\windows\currentversion\uninstall\eoWeather_is1

                              (!) -- Fichiers temporaires supprimés.

                              .
                              ============== Scan additionnel ==============
                              .
                              .
                              * Mozilla FireFox Version 3.0.15 [fr] *
                              .
                              Nom du profil: k4un3j3x.default (Sylvain)
                              .
                              (Sylvain, prefs.js) Browser.download.lastDir, D:\Documents and Settings\All Users\Documents\photos pop
                              (Sylvain, prefs.js) Browser.search.selectedEngine, MyWebSearch
                              .
                              (Sylvain, prefs.js) EFFACE - Browser.search.selectedEngine, MyWebSearch
                              (Sylvain, prefs.js) EFFACE - Extensions.mywebsearch.openSearchURL, hxxp://search.mywebsearch.com/mywebsearch/opensearch.jhtml?id=ZNfox000&ptb=uq99ciZPqS0pm0eC8IP7yw
                              (Sylvain, prefs.js) EFFACE - Extensions.mywebsearch.prevKwdEnabled, true
                              (Sylvain, prefs.js) EFFACE - Extensions.mywebsearch.prevKwdURL, chrome://browser-region/locale/region.properties
                              (Sylvain, prefs.js) EFFACE - Keyword.URL, hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZNfox000&fl=0&ptb=uq99ciZPqS0pm0eC8IP7yw&url=hxxp://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st=kwd&searchfor=
                              .
                              .
                              * Internet Explorer Version 7.0.5730.11 *
                              .
                              [HKEY_CURRENT_USER\..\Internet Explorer\Main]
                              .
                              Start Page: hxxp://fr.msn.com/
                              Default_search_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                              Default_page_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                              Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                              .
                              [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
                              .
                              Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                              Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                              Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                              Start Page: hxxp://fr.msn.com/
                              Search bar: hxxp://search.msn.com/spbasic.htm
                              .
                              [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
                              .
                              Tabs: res://ieframe.dll/tabswelcome.htm
                              .
                              ===================================
                              .
                              5310 Octet(s) - C:\Ad-Report-CLEAN[1].log
                              5664 Octet(s) - C:\Ad-Report-SCAN[1].log
                              .
                              3 Fichier(s) - D:\DOCUME~1\Sylvain\LOCALS~1\Temp
                              1 Fichier(s) - C:\WINDOWS\Temp
                              .
                              19 Fichier(s) - C:\Program Files\Ad-Remover\BACKUP
                              148 Fichier(s) - C:\Program Files\Ad-Remover\QUARANTINE
                              .
                              Fin à: 16:09:26 | 20/11/2009 - CLEAN[1]
                              .
                              ============== E.O.F ==============
                              .
                              0
                              1. bonjour
                                totobetourne semble être absent
                                pourrai tu refaire un RSIT
                                0
                            3. merci nathandre.

                              comment se comporte ton pc?
                              refais moi un rapport rsit, merci.
                              0
                              1. salut totobetourne
                                je te laisse continuer
                                0
                            4. Salut, désolé mais j'avais plein de boulot. Voila le rapport. En ce qui concerne mon ordi, il rame toujours (et aujourd'hui en l'allumant il m'a dit que je n'était plus protégé)

                              Logfile of random's system information tool 1.06 (written by random/random)
                              Run by Sylvain at 2009-11-22 16:51:22
                              Microsoft Windows XP Édition familiale Service Pack 3
                              System drive C: has 10 GB (34%) free of 31 GB
                              Total RAM: 1023 MB (55% free)

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 16:51:29, on 22/11/2009
                              Platform: Windows XP SP3 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v7.00 (7.00.6000.16915)
                              Boot mode: Normal

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\Ati2evxx.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\Program Files\Avira\AntiVir Desktop\sched.exe
                              C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                              c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
                              C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
                              C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
                              C:\WINDOWS\System32\GEARSec.exe
                              c:\APPS\HIDSERVICE\HIDSERVICE.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
                              c:\APPS\Powercinema\Kernel\TV\CLSched.exe
                              C:\WINDOWS\system32\Ati2evxx.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                              C:\Program Files\QuickTime\QTTask.exe
                              C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                              C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                              C:\WINDOWS\vsnpstd2.exe
                              C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
                              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              C:\Program Files\Logitech\Logitech Vid\vid.exe
                              C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
                              C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                              C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
                              C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
                              C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                              C:\WINDOWS\system32\wscntfy.exe
                              C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
                              C:\Program Files\Avira\AntiVir Desktop\update.exe
                              C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
                              D:\Documents and Settings\Sylvain\Bureau\RSIT.exe
                              C:\Program Files\eden\HijackThis\Sylvain.exe

                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                              O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                              O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
                              O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                              O2 - BHO: CInterceptor Object - {38D3FE60-3D53-4F37-BB0E-C7A97A26A156} - C:\Program Files\Pando Networks\Pando\PandoIEPlugin.dll
                              O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
                              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
                              O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
                              O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                              O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                              O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
                              O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                              O4 - HKLM\..\Run: [SNPSTD2] C:\WINDOWS\vsnpstd2.exe
                              O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide
                              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
                              O4 - HKCU\..\Run: [Pando] "C:\Program Files\Pando Networks\Pando\Pando.exe" /Minimized
                              O4 - HKCU\..\Run: [Logitech Vid] "C:\Program Files\Logitech\Logitech Vid\vid.exe" -bootmode
                              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                              O4 - Global Startup: Assistant Smart Wizard NETGEAR pour WG311v3.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
                              O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                              O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                              O4 - Global Startup: NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
                              O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 3.79\AMVConverter\grab.html
                              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                              O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 3.79\MediaManager\grab.html
                              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                              O9 - Extra button: Traduction - {7A2EFD41-E6B3-11D2-89E3-00E0292EE574} - C:\Program Files\PROMT5\PROMTIE4\promtie5.htm
                              O9 - Extra 'Tools' menuitem: Traduire - {7A2EFD41-E6B3-11D2-89E3-00E0292EE574} - C:\Program Files\PROMT5\PROMTIE4\promtie5.htm
                              O9 - Extra button: (no name) - {7A2EFD41-E6B3-11D2-89E3-00E0292EE575} - C:\Program Files\PROMT5\PROMTIE4\options.htm
                              O9 - Extra 'Tools' menuitem: Personnaliser les options de traduction - {7A2EFD41-E6B3-11D2-89E3-00E0292EE575} - C:\Program Files\PROMT5\PROMTIE4\options.htm
                              O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                              O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                              O9 - Extra button: Sélection intelligente HP - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
                              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
                              O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                              O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                              O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
                              O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
                              O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
                              O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                              O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
                              O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
                              O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
                              O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                              O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
                              O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                              O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                              O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
                              O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
                              O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
                              O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
                              O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
                              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                              O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
                              O23 - Service: MysqlInventime - Unknown owner - C:\Apps\INVENT~1\mysql\bin\mysqld-nt.exe
                              O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
                              0
                              1. bonsoir
                                personne ne t'es venu en aide

                                Télécharge malwarebytes' anti-malware
                                https://www.commentcamarche.net/telecharger/securite/14361-malwarebytes-anti-malware/
                                Enregistre le sur le bureau
                                Double-clique sur l'icône Download_mbam-setup.exe pour lancer le processus d'installation
                                Si la pare-feu demande l'autorisation de se connecter pour malwarebytes, accepte
                                Il va se mettre à jour une fois faite
                                Va dans l'onglet recherche
                                Sélectionne exécuter un examen complet
                                Clique sur rechercher
                                Le scan démarre
                                A la fin de l'analyse, le message s'affiche: L'examen s'est terminé normalement.
                                Clique sur afficher les résultats pour afficher les objets trouvés
                                Clique sur OK pour pousuivre
                                Si des malwares ont été détectés, cliquer sur afficher les résultats
                                Sélectionne tout (ou laisser coché)
                                Clique sur supprimer la sélection
                                Malwarebytes va détruire les fichiers et les clés de registre et en mettre une
                                copie dans la quarantaine
                                Malewarebytes va ouvrir le bloc-note et y copier le rapport
                                Redémarre le PC
                                Une fois redémarré, double-clique sur Malewarebytes
                                Va dans l'onglet rapport/log
                                Clique dessus pour l'afficher une fois affiché, cliquer sur édition en haut du
                                bloc-note puis sur sélectionner tout
                                Revient sur édition, puis sur copier et revient sur le forum et dans ta réponse
                                Clic droit dans le cadre de la réponse et coller
                                0
                                • 1
                                • 2