Probleme virus centre de securité

Nanorabitt -  
 Utilisateur anonyme -
Bonjour,
J'ai un virus centre de sécurité qui squat mon ordinateur comment puis-je m'en débarrassé ?
Quelqu'un pourrais-t-il m'aider svp. Merci d"avance !!
Configuration: Windows XP
Firefox 3.5.5

11 réponses

  1. Utilisateur anonyme
     
    Salut,

    On va analyser ton PC :

    • Télécharge RSIT de Random/Random, et enregistre le sur ton Bureau.

    • Sous XP : Double clique sur RSIT.exe
    • Sous Vista/7 : Fais un clic droit sur RSIT.exe et sélectionne "Exécuter en tant qu'administrateur"

    • Clique sur Continue à l'écran Disclaimer.

    • Si l'outil HijackThis n'est pas présent sur ton PC, RSIT le téléchargera (autorise l'accès dans ton pare-feu s'il te le demande) et tu devras accepter la licence en cliquant sur le bouton accept.

    • Une fois le scan terminé, deux rapports vont apparaître : poste les dans deux messages séparés.

    ▲ Les rapports sont sauvegardés dans C:\rsit\info.txt et C:\rsit\log.txt

    Aide en images
    0
  2. Utilisateur anonyme
     
    0
    1. Nanorabitt
       
      merci de m'aider c'est simpa. j'ai les rapport je fait quoi maintenant ?
      0
      1. Nanorabitt > Nanorabitt
         
        ha mince lol javais pas vu "le post les" ^^ bon ba voici le premier rapport:

        info.txt logfile of random's system information tool 1.06 2009-11-20 14:37:34

        ======Uninstall list======

        -->"C:\Program Files\InstallShield Installation Information\{1A91D1FA-B9B3-4556-9878-5C61059A19B2}\setup.exe" REMOVEALL
        -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
        -->c:\WINDOWS\system32\\MSIEXEC.EXE /x {075473F5-846A-448B-BCB3-104AA1760205}
        -->c:\WINDOWS\system32\\MSIEXEC.EXE /x {AB708C9B-97C8-4AC9-899B-DBF226AC9382}
        -->c:\WINDOWS\system32\\MSIEXEC.EXE /x {B12665F4-4E93-4AB4-B7FC-37053B524629}
        -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
        Adobe AIR-->C:\Program Files\Fichiers communs\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
        Adobe AIR-->MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
        Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
        Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
        Adobe Reader 9.2 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A92000000001}
        Adobe Shockwave Player 11-->C:\WINDOWS\system32\adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
        Agent de contrôle Marche.fr-->msiexec /qb /x {AF5CCB23-941E-58F4-A39D-598C0FE6A96D}
        Agent de contrôle Marche.fr-->MsiExec.exe /I{AF5CCB23-941E-58F4-A39D-598C0FE6A96D}
        ALTools Update-->"C:\Program Files\ESTsoft\ALUpdate\unins000.exe"
        ALZip-->"C:\Program Files\ESTsoft\ALZip\unins000.exe"
        AoA Audio Extractor 1.0-->"C:\Program Files\AoA Audio Extractor\unins000.exe"
        Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
        ASUS Europa II Hybrid Capture Driver-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{22E0D334-F2DA-425A-A6C1-84C5DDA0AC49}
        avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
        Big Fish Games Client-->C:\Program Files\bfgclient\Uninstall.exe
        Blender (remove only)-->"C:\Program Files\Blender Foundation\Blender\uninstall.exe"
        Bonjour-->MsiExec.exe /I{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}
        Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
        Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
        Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
        Correctif pour Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
        Correctif pour Windows XP (KB970653-v3)-->"C:\WINDOWS\$NtUninstallKB970653-v3$\spuninst\spuninst.exe"
        Danger Next Door: Miss Teri Tale's Adventure-->"C:\Program Files\Danger Next Door - Miss Teri Tale's Adventure\Uninstall.exe"
        Dealio Toolbar v4.0.1-->MsiExec.exe /X{94C3BB3A-56A1-43DE-A242-8B41F46E97EF}
        EAX4 Unified Redist-->MsiExec.exe /X{89661B04-C646-4412-B6D3-5E19F02F1F37}
        eMule-->"C:\Program Files\eMule\Uninstall.exe"
        Enhanced Multimedia Keyboard Solution-->C:\HP\KBD\Install.exe /u
        eoEngine 9.1-->"C:\Program Files\EoRezo\unins000.exe"
        Extension de Windows Live Toolbar (Windows Live Toolbar)-->MsiExec.exe /X{0CA6047C-D28B-4295-834A-07C52BA20C2D}
        eye-->C:\Program Files\Ofb1\Uninstall.exe
        Fast Browser Search (My Tattoons)-->regsvr32 /u /s "C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll"
        Free Mp3 Wma Converter V 1.81-->"C:\Program Files\Free Audio Pack\unins000.exe"
        Freeze.com Toolbar-->regsvr32 /u /s "C:\Program Files\Freeze.com Toolbar\freeze_int.dll"
        Fusion-->C:\WINDOWS\system32\sdbinst.exe -u "C:\WINDOWS\AppPatch\Custom\{cf63012b-64a2-47ce-8d9c-38c25fc36080}.sdb"
        GamesBar 2.0.1.12-->C:\Program Files\GamesBar\uninst.exe
        Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_0E996B068B56FCA2.exe" /uninstall
        Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
        Hercules DualPix Exchange Webcam-->C:\Program Files\InstallShield Installation Information\{04BEFF7A-DF5D-4E49-AB46-BA3D3BE49FCB}\setup.exe -runfromtemp -l0x040c -removeonly
        High Definition Audio - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
        HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
        HiYo -->MsiExec.exe /X{1353AD69-6F86-484F-B56B-3508F60ACCC4} ARPVAL="UnInst" /qf /L*V "%temp%\HiYoUninstallLog.log"
        HiYo-->MsiExec.exe /X{1353AD69-6F86-484F-B56B-3508F60ACCC4}
        Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
        Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
        Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
        HP Appareils photos Photosmart 5.0-->C:\Program Files\HP\Digital Imaging\{C83A12B9-B31B-461A-BBD4-CE9B988094F1}\setup\hpzscr01.exe -datfile hpiscr01.dat
        HP Deskjet Printer Preload-->MsiExec.exe /I{2C5D07FB-31A2-4F2D-9FDA-0B24ACD42BD0}
        HP Document Viewer 5.3-->C:\Program Files\HP\Digital Imaging\DocumentViewer\hpzscr01.exe -datfile hpqbud04.dat
        HP Extended Capabilities 5.3-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
        HP Image Zone 5.3-->C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
        HP Image Zone Express-->MsiExec.exe /X{FE64AE29-0883-4C70-8388-DC026019C900}
        HP Imaging Device Functions 5.3-->C:\Program Files\HP\Digital Imaging\DigitalImagingMonitor\hpzscr01.exe -datfile hpqbud01.dat
        HP Product Assistant-->MsiExec.exe /I{36FDBE6E-6684-462B-AE98-9A39A1B200CC}
        HP PSC & OfficeJet 5.3.A-->"C:\Program Files\HP\Digital Imaging\{3E386744-10FA-44b2-98C9-DF7A270DECB3}\setup\hpzscr01.exe" -datfile hposcr06.dat
        HP PSC & OfficeJet 5.3.B-->"C:\Program Files\HP\Digital Imaging\{5B79CFD1-6845-4158-9D7D-6BE89DF2C135}\setup\hpzscr01.exe" -datfile hposcr07.dat
        HP Solution Center & Imaging Support Tools 5.3-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
        HP Update-->MsiExec.exe /X{818ABC3C-635C-4651-8183-D0E9640B7DD1}
        iminent-en Toolbar-->C:\PROGRA~1\IMINEN~1\UNWISE.EXE C:\PROGRA~1\IMINEN~1\INSTALL.LOG
        Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
        Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
        J2SE Runtime Environment 5.0-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150000}
        Java(TM) 6 Update 17-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216013FF}
        Java(TM) 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
        Java(TM) 6 Update 4-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160040}
        Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
        Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
        LG PC Suite II-->C:\Program Files\InstallShield Installation Information\{14DCD95A-EBA3-4BF0-B7EF-533852E99BE6}\setup.exe -runfromtemp -l0x040c -removeonly
        LG USB Modem driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C3ABE126-2BB2-4246-BFE1-6797679B3579}\setup.exe" -l0x40c LG -removeonly
        LimeWire 5.2.12-->"C:\Program Files\LimeWire\uninstall.exe"
        livebox-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{17342E3B-0818-4A6F-BFF8-99476605ADD6}\Setup.exe" -l0x40c
        MediaBar-->C:\Program Files\iMeshMediabarTb\uninstall.exe
        Menus intelligents (Windows Live Toolbar)-->MsiExec.exe /X{0CC70FEF-5068-4CD5-B4DE-86FFD98EC929}
        Messenger Plus! Live & Sponsor (CiD)-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
        Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
        Microsoft .NET Framework 1.1 Security Update (KB953297)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M953297\M953297Uninstall.msp"
        Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
        Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
        Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
        Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
        Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
        Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
        Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
        Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
        Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
        Microsoft Kernel-Mode Driver Framework Feature Pack 1.7-->"C:\WINDOWS\$NtUninstallWdf01007$\spuninst\spuninst.exe"
        Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
        Microsoft Search Enhancement Pack-->MsiExec.exe /X{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
        Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
        Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
        Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
        Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
        Microsoft Text-to-Speech Engine 4.0 (English)-->RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\msTTS.inf, Uninstall
        Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
        Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
        Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
        Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media (KB954155)-->"C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media (KB968816)-->"C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media 10 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB969897)-->"C:\WINDOWS\ie7updates\KB969897-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 8 (KB969897)-->"C:\WINDOWS\ie8updates\KB969897-IE8\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 8 (KB971961)-->"C:\WINDOWS\ie8updates\KB971961-IE8\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 8 (KB972260)-->"C:\WINDOWS\ie8updates\KB972260-IE8\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 8 (KB974455)-->"C:\WINDOWS\ie8updates\KB974455-IE8\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956744)-->"C:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956844)-->"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958869)-->"C:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB961371)-->"C:\WINDOWS\$NtUninstallKB961371$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB969059)-->"C:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB969898)-->"C:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB969947)-->"C:\WINDOWS\$NtUninstallKB969947$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB971486)-->"C:\WINDOWS\$NtUninstallKB971486$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB971557)-->"C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB973346)-->"C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB973354)-->"C:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB973507)-->"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB973525)-->"C:\WINDOWS\$NtUninstallKB973525$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB973869)-->"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB974112)-->"C:\WINDOWS\$NtUninstallKB974112$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB974571)-->"C:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB975025)-->"C:\WINDOWS\$NtUninstallKB975025$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB975467)-->"C:\WINDOWS\$NtUninstallKB975467$\spuninst\spuninst.exe"
        Mise à jour pour Windows Internet Explorer 8 (KB971180)-->"C:\WINDOWS\ie8updates\KB971180-IE8\spuninst\spuninst.exe"
        Mise à jour pour Windows Internet Explorer 8 (KB976749)-->"C:\WINDOWS\ie8updates\KB976749-IE8\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB961503)-->"C:\WINDOWS\$NtUninstallKB961503$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB968389)-->"C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB973815)-->"C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
        Mozilla Firefox (3.5.5)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
        MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
        MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
        MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
        Mystery Age: Le Bâton Impérial-->"C:\Program Files\Mystery Age - Le Baton Imperial\Uninstall.exe"
        Netlog Music Tool-->C:\Program Files\Netlog Music Tool\Uninstaller.exe
        Norton Internet Security-->MsiExec.exe /I{AADFE0B9-F905-4d5f-A144-0ADB2EFA747B}
        Norton Internet Security-->MsiExec.exe /I{C9D599E1-6B68-4a1f-8A4F-A1DB433DB1BF}
        NVIDIA Drivers-->C:\WINDOWS\system32\nvudisp.exe UninstallGUI
        OpenAL-->"C:\Program Files\OpenAL\oalinst.exe" /U
        OpenOffice.org 3.1-->MsiExec.exe /I{0FA44E79-CD7D-4E8D-A2EE-26FE05F509B6}
        Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
        PC-Doctor 5 for Windows-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{AB61A692-5543-4C48-979B-8CEA1C52FE9C} /l1036
        RPG Maker VX 1.02-->"C:\Program Files\RPG Maker VX\unins001.exe"
        RPG Maker VX RTP-->"C:\Program Files\RPG Maker VX\unins000.exe"
        SafeCast Shared Components-->C:\Program Files\Fichiers communs\Macrovision Shared\SafeCast\Install\CDAC13BA.EXE /uninstall
        Samsung USB Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{86D6A20D-3910-4441-A3E5-EB6977251C86}\Setup.exe" anything
        Search Settings 1.2.2-->MsiExec.exe /X{0B1AAC97-8563-41D9-AE47-58E6A222F0E1}
        Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
        Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
        Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
        SoftwareUpdate 1.0-->"C:\Documents and Settings\HP_Propriétaire\Application Data\eoRezo\SoftwareUpdate\unins000.exe"
        Sonic Express Labeler-->MsiExec.exe /I{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
        Sonic RecordNow Audio-->MsiExec.exe /I{AB708C9B-97C8-4AC9-899B-DBF226AC9382}
        Sonic RecordNow Copy-->MsiExec.exe /I{B12665F4-4E93-4AB4-B7FC-37053B524629}
        Sonic RecordNow Data-->MsiExec.exe /I{075473F5-846A-448B-BCB3-104AA1760205}
        Sonic Update Manager-->MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
        Surligneur (Windows Live Toolbar)-->MsiExec.exe /X{81B5F83F-2291-48B0-8375-36B63A9BF5B0}
        SweetIM for Messenger 2.6-->MsiExec.exe /X{A1E4213E-06AD-4C58-8315-92F11531D960}
        SweetIM Toolbar for Internet Explorer 3.3-->MsiExec.exe /X{266C7330-C0F4-49E5-8F20-A56F9F822875}
        Téléchargeur de SPORE fr-->"C:\Program Files\Téléchargeur de SPORE\unins000.exe"
        Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
        Update for Windows XP (KB953356)-->"C:\WINDOWS\$NtUninstallKB953356$\spuninst\spuninst.exe"
        VLC media player 1.0.0-->C:\Program Files\VideoLAN\VLC\uninstall.exe
        Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
        Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
        Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
        Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
        Windows Live Favorites pour Windows Live Toolbar-->MsiExec.exe /X{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}
        Windows Live Messenger-->MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
        Windows Live OneCare safety scanner-->RunDll32.exe "C:\Program Files\Windows Live Safety Center\wlscCore.dll",UninstallFunction WLSC_SCANNER_PRODUCT
        Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
        Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
        Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
        Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
        Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
        Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"

        ======Hosts File======

        127.0.0.1 www.007guard.com
        127.0.0.1 007guard.com
        127.0.0.1 008i.com
        127.0.0.1 www.008k.com
        127.0.0.1 008k.com
        127.0.0.1 www.00hq.com
        127.0.0.1 00hq.com
        127.0.0.1 010402.com
        127.0.0.1 www.032439.com
        127.0.0.1 032439.com

        ======Security center information======

        AV: Norton Internet Security
        AV: avast! antivirus 4.8.1356 [VPS 091120-0]
        FW: Norton Internet Security

        ======System event log======

        Computer Name: NOM-EB85C523610
        Event Code: 7036
        Message: Le service Pml Driver HPZ12 est entré dans l'état : en cours d'exécution.

        Record Number: 451501
        Source Name: Service Control Manager
        Time Written: 20091118123908.000000+060
        Event Type: Informations
        User:

        Computer Name: NOM-EB85C523610
        Event Code: 7035
        Message: Un contrôle Démarrer a correctement été envoyé au service Pml Driver HPZ12.

        Record Number: 451500
        Source Name: Service Control Manager
        Time Written: 20091118123908.000000+060
        Event Type: Informations
        User: NOM-EB85C523610\HP_Propriétaire

        Computer Name: NOM-EB85C523610
        Event Code: 7036
        Message: Le service Pml Driver HPZ12 est entré dans l'état : arrêté.

        Record Number: 451499
        Source Name: Service Control Manager
        Time Written: 20091118123708.000000+060
        Event Type: Informations
        User:

        Computer Name: NOM-EB85C523610
        Event Code: 7036
        Message: Le service Pml Driver HPZ12 est entré dans l'état : en cours d'exécution.

        Record Number: 451498
        Source Name: Service Control Manager
        Time Written: 20091118123708.000000+060
        Event Type: Informations
        User:

        Computer Name: NOM-EB85C523610
        Event Code: 7035
        Message: Un contrôle Démarrer a correctement été envoyé au service Pml Driver HPZ12.

        Record Number: 451497
        Source Name: Service Control Manager
        Time Written: 20091118123708.000000+060
        Event Type: Informations
        User: NOM-EB85C523610\HP_Propriétaire

        =====Application event log=====

        Computer Name: NOM-EB85C523610
        Event Code: 1019
        Message: Finish registering ASP.NET (version 2.0.50727.0). Detailed registration logs can be found in C:\WINDOWS\TEMP\ASPNETSetup_00001.log

        Record Number: 29552
        Source Name: ASP.NET 2.0.50727.0
        Time Written: 20090823002341.000000+120
        Event Type: Informations
        User:

        Computer Name: NOM-EB85C523610
        Event Code: 1020
        Message: Updates to the IIS metabase were aborted because IIS is either not installed or is disabled on this machine. To configure ASP.NET to run in IIS, please install or enable IIS and re-register ASP.NET using aspnet_regiis.exe /i.

        Record Number: 29551
        Source Name: ASP.NET 2.0.50727.0
        Time Written: 20090823002341.000000+120
        Event Type: Avertissement
        User:

        Computer Name: NOM-EB85C523610
        Event Code: 1000
        Message: Les compteurs de performances pour le service ASP.NET (ASP.NET) ont été chargés.
        Les données d'enregistrement contiennent les nouvelles valeurs d'index
        assignées à ce service.

        Record Number: 29550
        Source Name: LoadPerf
        Time Written: 20090823002340.000000+120
        Event Type: Informations
        User:

        Computer Name: NOM-EB85C523610
        Event Code: 1001
        Message: Les compteurs de performances pour le service ASP.NET (ASP.NET) ont été supprimés.
        Les données d'enregistrement contiennent les nouvelles valeurs du dernier compteur système
        et les dernières entrées du registre d'aide.

        Record Number: 29549
        Source Name: LoadPerf
        Time Written: 20090823002340.000000+120
        Event Type: Informations
        User:

        Computer Name: NOM-EB85C523610
        Event Code: 1000
        Message: Les compteurs de performances pour le service ASP.NET_2.0.50727 (ASP.NET_2.0.50727) ont été chargés.
        Les données d'enregistrement contiennent les nouvelles valeurs d'index
        assignées à ce service.

        Record Number: 29548
        Source Name: LoadPerf
        Time Written: 20090823002340.000000+120
        Event Type: Informations
        User:

        ======Environment variables======

        "ComSpec"=%SystemRoot%\system32\cmd.exe
        "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;c:\Python22;C:\Program Files\ESTsoft\ALZip
        "windir"=%SystemRoot%
        "FP_NO_HOST_CHECK"=NO
        "OS"=Windows_NT
        "PROCESSOR_ARCHITECTURE"=x86
        "PROCESSOR_LEVEL"=15
        "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 47 Stepping 2, AuthenticAMD
        "PROCESSOR_REVISION"=2f02
        "NUMBER_OF_PROCESSORS"=1
        "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
        "TEMP"=%SystemRoot%\TEMP
        "TMP"=%SystemRoot%\TEMP
        "SonicCentral"=c:\Program Files\Fichiers communs\Sonic Shared\Sonic Central\

        -----------------EOF-----------------
        0
      2. Nanorabitt > Nanorabitt
         
        et voici le second :

        Logfile of random's system information tool 1.06 (written by random/random)
        Run by HP_Propriétaire at 2009-11-20 14:37:01
        Microsoft Windows XP Édition familiale Service Pack 3
        System drive C: has 106 GB (73%) free of 145 GB
        Total RAM: 510 MB (21% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 14:37:23, on 20/11/2009
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v8.00 (8.00.6001.18702)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\WINDOWS\system32\drivers\CDAC11BA.EXE
        C:\Program Files\Java\jre6\bin\jqs.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\WINDOWS\system32\wbem\wmiapsrv.exe
        C:\Program Files\EoRezo\EoEngine.exe
        C:\Documents and Settings\HP_Propriétaire\Application Data\eoRezo\SoftwareUpdate\SoftwareUpdateHP.exe
        C:\Program Files\SweetIM\Messenger\SweetIM.exe
        C:\Program Files\Hercules\DualPix Exchange\Camservice.exe
        C:\Program Files\Search Settings\SearchSettings.exe
        C:\Program Files\HiYo\bin\HiYo.exe
        C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
        C:\WINDOWS\system32\RUNDLL32.EXE
        C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
        C:\Program Files\Java\jre6\bin\jusched.exe
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\WINDOWS\system32\m0suq8wt.exe
        C:\Program Files\eMule\emule.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Documents and Settings\HP_Propriétaire\Mes documents\Téléchargements\RSIT.exe
        C:\Program Files\Trend Micro\HijackThis\HP_Propriétaire.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://y.lo.st
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://y.lo.st
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb128\SearchSettings.dll
        F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Documents and Settings\HP_Propriétaire\kpy.exe \o
        O2 - BHO: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\DealioToolbarIE.dll
        O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
        O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
        O2 - BHO: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL (file missing)
        O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
        O2 - BHO: IMBooster4web-en Toolbar - {6a7400d6-6615-4a06-a4d1-48979fa6e868} - C:\Program Files\iminent-en\tbimi0.dll
        O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: (no name) - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - (no file)
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
        O2 - BHO: MediaBar - {ABB49B3B-AB7D-4ED0-9135-93FD5AA4F69F} - C:\Program Files\iMeshMediabarTb\iMeshMediaBarDx.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
        O2 - BHO: EoBHO - {C7B76B90-3455-4AE6-A752-EAC4D19689E5} - C:\Program Files\EoRezo\EoAdv\EoRezoBHO.dll
        O2 - BHO: GamesBarBHO Class - {CB0D163C-E9F4-4236-9496-0597E24B23A5} - C:\Program Files\GamesBar\oberontb.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
        O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb128\SearchSettings.dll
        O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
        O3 - Toolbar: Freeze.com Toolbar - {B7D3E479-CC68-42B5-A338-938ECE35F419} - C:\Program Files\Freeze.com Toolbar\freeze_int.dll (file missing)
        O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (file missing)
        O3 - Toolbar: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL (file missing)
        O3 - Toolbar: IMBooster4web-en Toolbar - {6a7400d6-6615-4a06-a4d1-48979fa6e868} - C:\Program Files\iminent-en\tbimi0.dll
        O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
        O3 - Toolbar: GamesBar - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - C:\Program Files\GamesBar\oberontb.dll
        O3 - Toolbar: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\DealioToolbarIE.dll
        O3 - Toolbar: MediaBar - {ABB49B3B-AB7D-4ED0-9135-93FD5AA4F69F} - C:\Program Files\iMeshMediabarTb\iMeshMediaBarDx.dll
        O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [PlatriumWeather] "C:\Program Files\Platrium\bin\1.2.103.0\Weather.exe" -auto
        O4 - HKLM\..\Run: [EoEngine] "C:\Program Files\EoRezo\EoEngine.exe"
        O4 - HKLM\..\Run: [SoftwareHelper] C:\Documents and Settings\HP_Propriétaire\Application Data\eoRezo\SoftwareUpdate\SoftwareUpdateHP.exe
        O4 - HKLM\..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe
        O4 - HKLM\..\Run: [IMBooster] C:\Program Files\Iminent\IMBooster\IMBooster.exe /warmup
        O4 - HKLM\..\Run: [CamserviceDP] C:\Program Files\Hercules\DualPix Exchange\Camservice.exe /startup
        O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
        O4 - HKLM\..\Run: [Hiyo] C:\Program Files\HiYo\bin\HiYo.exe /RunFromStartup
        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKCU\..\Run: [WOOKIT] C:\Program Files\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [Magentic] C:\PROGRA~1\Magentic\bin\Magentic.exe /c
        O4 - HKCU\..\Run: [Netlog Music Tool] "C:\Program Files\Netlog Music Tool\NetlogMusicTool.exe"
        O4 - HKCU\..\Run: [Lyad] C:\Program Files\Lyad Messenger\lyad_messenger.exe autostart
        O4 - HKCU\..\Run: [m0suq8wt.exe] C:\WINDOWS\system32\m0suq8wt.exe
        O4 - HKCU\..\Run: [PC Speed Maximizer] C:\Program Files\PC Speed Maximizer\SPMTray.exe
        O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
        O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
        O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~2.EXE -Update -1103471 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; SIMBAR={CD336790-67B7-4A18-9B47-B229DCD0BAEF}; GTB6.3; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 1.1.4322; Hotbar 10.2.217.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)" -"http://www.jeuxjeuxjeux.fr/jeu/se+jeter/street+dive.html"
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
        O9 - Extra button: (no name) - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files\GamesBar\oberontb.dll
        O9 - Extra 'Tools' menuitem: GamesBar - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files\GamesBar\oberontb.dll
        O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
        O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra button: Cool Hand Poker - {00000000-0000-0000-0000-000000000000} - C:\MicroGaming\Poker\coolhandMPP\MPPoker.exe (file missing) (HKCU)
        O16 - DPF: CabBuilder - http://ak.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
        O16 - DPF: {011F473E-0880-43D4-99F3-F490A84128AE} (GenimoWebGames Control) - http://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--8e806481-bf9c-4ef7-98ad-5066b6369c46/online/ButterflyEscape/GenimoWebGamesControl.cab
        O16 - DPF: {049A470D-F818-4E34-B14D-E4E237DADCF8} (CPlayFirstFashionDasControl Object) - http://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--b557f986-1eeb-4ade-a24f-fd83da495e78/online/fashion_dash/fr/fashiondashweb.1.0.0.21.cab
        O16 - DPF: {21BB8360-F943-447E-98F3-3C22345375A7} (CPlayFirstChocolatierControl Object) - http://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--25e36d6d-547a-413a-a6e7-4f9d4dfbf23b/online/chocolatier/fr/ChocolatierWeb.1.0.0.13.cab
        O16 - DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} - http://activex.camfrogweb.com/advanced/2.0.2.3/cfweb_activex.camfrogweb.com-advanced-2.0.2.3_instmodule.exe
        O16 - DPF: {24757662-8772-4986-8E5A-A1C939CDF219} (CPlayFirstSweetopiaControl Object) - http://games.bigfishgames.com/fr_sweetopia/online/Sweetopia.1.0.0.22_fr.cab
        O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} (PogoWebLauncher Control) - http://fr.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB
        O16 - DPF: {38AB6A6C-CC4C-4F9E-A3DD-3C5681EF18A1} (SonyOnlineInstallerX) - http://www-cdn.freerealms.com/gamedata/FreeRealmsInstaller.cab?v=1030
        O16 - DPF: {49E67060-2C0D-415E-94C7-52A49F73B2F1} (CPlayFirstPiratePoppersControl Object) - file:///C:/Documents%20and%20Settings/HP_Propriétaire/Local%20Settings/Application%20Data/Oberon%20Media/Oberon%20Games%20Host/PiratePoppers.1.0.0.39.cab
        O16 - DPF: {596B26AA-E941-4FB5-8F91-0762447578F0} (CPlayFirstdreamControl Object) - http://games.bigfishgames.com/fr_dream-chronicles/online/dream.1.0.0.17_fr.cab
        O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
        O16 - DPF: {6C7CAD20-85AA-475A-AC0D-303C4A9A69CE} (CPlayFirstGreatChocoControl Object) - http://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--5dfe157e-2ed1-4a52-9e87-19c46fc3f9fb/online/the_great_chocolate_chase/fr/greatchocolatechaseweb.1.0.0.13.cab
        O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
        O16 - DPF: {775879E2-7309-4619-BB02-AADE41F4B690} (CPlayFirstdreamControl Object) - http://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--9b4e31a2-26b0-4209-92b6-ee687a2aabd4/online/dream_chronicles/fr/dreamweb.1.0.0.9.cab
        O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://games.bigfishgames.com/fr_luxoramunrising/online/mjolauncher.cab
        O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
        O16 - DPF: {8ADC4409-4FBF-4224-B73F-2392C721BCB4} (GenimoWebGames Control) - http://games.bigfishgames.com/...
        O16 - DPF: {8FA2192F-B95D-40E3-898F-8D7ABB8E00D0} (SpinTop Games Launcher) - http://www.msnjeux.com/online2/MSN_INTL_FRANCE/mystery_solitaire/SpinTopGamesLauncher.cab
        O16 - DPF: {935F9B04-0C7B-4454-A391-348C54AD7ADD} (Jolly Bear Games Player) - http://games.bigfishgames.com/...
        O16 - DPF: {BAC761D3-DFFD-4DB4-A01D-173346E090A7} (CPlayFirstzenerchiControl Object) - http://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--451a1c1a-17be-4a81-bec4-8e56bd2037e3/online/zenerchi/fr/ZenerchiWeb.1.0.0.10.cab
        O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
        O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxentelechargement.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
        O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.com/Register/Branding/olr3313/OCX/v1018/flashax.cab
        O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - file:///C:/Documents%20and%20Settings/HP_Propriétaire/Local%20Settings/Application%20Data/Oberon%20Media/Oberon%20Games%20Host/popcaploader_v10.cab
        O16 - DPF: {E1342154-4889-42B5-BEF6-19237577048F} (OberongamesLoader Object) - http://msnfr.oberon-media.com/online2/MSN_INTL_FRANCE/bejeweled2/Oberongamesloader.cab
        O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
        O16 - DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} (Flash Casino Helper Control) - https://plugins.valueactive.eu/flashax/iefax.cab
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
        O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
        O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
        O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
        0
  3. Utilisateur anonyme
     
    Tu as effectivement un paquet d'infections.

    Commence par çà :

    • Télécharge et enregistre le fichier sur ton bureau Ad-Remover

    • Sous XP : Double clique sur AD-R.exe
    • Sous Vista/7 : Fais un clic droit sur AD-R.exe et sélectionne "Exécuter en tant qu'administrateur"

    • Clique sur Oui dans la fenêtre d'avertisement

    • Au menu principal choisi l'option "Lancer le nettoyage" (avec la touche L) et tape sur la touche entrée.

    • Patiente pendant que l'outil fait son travail

    • Appuie sur une touche quand le programme te le demande

    Puis on continue avec le ToolBars :

    Note : les Toolbars son généralement proposées en accompagnement d'autres logiciels à leur installation.
    Quand tu installes un logiciel, prends le temps de lire les options d'installation et décoche les programmes additionnels inutiles (ne clique pas bêtement sur "suivant").


    • Télécharge ToolbarS&D (de la Team IDN) sur ton Bureau

    • Sous XP : Double clique sur ToolBarSD.exe
    • Sous Vista/7 : Fais un clic droit sur ToolBarSD.exe et sélectionne "Exécuter en tant qu'administrateur"

    • Appuie sur la touche F pour sélectionner le français et valide avec la touche Entrée.

    • Clique sur OK dans la fenêtre d'avertisement

    • Choisis l'option "Suppression" en appuyant sur la touche 2 et valide avec la touche Entrée

    /!\ Ne ferme pas la fenêtre lors de la suppression /!\

    • Un rapport va s'ouvrir à la fin du processus, copie/colle le dans ta réponse

    Le rapport est sauvegardé dans C:\TB.txt
    • Un rapport va s'ouvrir, copie/colle le dans ta réponse

    Le rapport est sauvegardé dans C:\Ad-report.log

    Note :
    Process.exe est détecté par certains antivirus comme étant un RiskTool.
    Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
    0
    1. Nanorabitt
       
      voici le rappor de toolbar s&d:


      -----------\\ ToolBar S&D 1.2.9 XP/Vista

      Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
      X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3200+ )
      BIOS : Phoenix - Award BIOS v6.00PG
      USER : HP_Propriétaire ( Administrator )
      BOOT : Normal boot
      Antivirus : avast! antivirus 4.8.1356 [VPS 091120-0] 4.8.1356 (Activated)
      Firewall : Norton Internet Security 2005 (Activated)
      C:\ (Local Disk) - NTFS - Total:142 Go (Free:102 Go)
      D:\ (Local Disk) - FAT32 - Total:6 Go (Free:2 Go)
      E:\ (CD or DVD)
      F:\ (USB)
      G:\ (USB)
      H:\ (USB)
      I:\ (USB)

      "C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
      Option : [2] ( 20/11/2009|20:35 )

      -----------\\ SUPPRESSION

      Supprime! - C:\DOCUME~1\ALLUSE~1\MENUDÉ~1\PROGRA~1\GamesBar
      Supprime! - C:\DOCUME~1\HP_PRO~1\APPLIC~1\Search Settings\kb128
      Supprime! - C:\DOCUME~1\HP_PRO~1\APPLIC~1\Search Settings

      -----------\\ Recherche de Fichiers / Dossiers ...


      -----------\\ Extensions

      (All Users) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar

      (HP_Propri‚taire) - {20a82645-c095-46ed-80e3-08825760534b} => chrome_user
      (HP_Propri‚taire) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
      (HP_Propri‚taire) - {635abd67-4fe9-1b23-4f01-e679fa7484c1} => ytoolbar


      -----------\\ [..\Internet Explorer\Main]

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
      "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
      "SearchMigratedDefaultURL"="https://www.google.com/webhp?gws_rd=ssl{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
      "Start Page Redirect Cache"="https://www.msn.com/fr-fr?ocid=iehp"
      "Search Bar"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
      "Start Page"="http://y.lo.st"
      "Default_search_url"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
      "Default_page_url"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
      "First Home Page"="http://y.lo.st"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
      "Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
      "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
      "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
      "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
      "Start Page"="https://www.msn.com/fr-fr/"
      "Search bar"="http://www.bing.com/spresults.aspx"


      --------------------\\ Recherche d'autres infections


      Aucune autre infection trouvée !


      1 - "C:\ToolBar SD\TB_1.txt" - 20/11/2009|22:56 - Option : [2]

      -----------\\ Fin du rapport a 22:57:14,87
      0
      1. Nanorabitt > Nanorabitt
         
        et voici lautre :

        .
        ======= RAPPORT D'AD-REMOVER 1.1.4.6_D | UNIQUEMENT XP/VISTA/7 =======
        .
        Mit à jour par C_XX le 20.11.2009 à 7:00
        Contact: AdRemover.contact@gmail.com
        Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
        .
        Lancé à: 15:30:52, 20/11/2009 | Mode Normal | Option: CLEAN
        Exécuté de: C:\Program Files\Ad-Remover\
        Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
        Nom du PC: NOM-EB85C523610 | Utilisateur actuel: HP_Propri‚taire
        .
        ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
        .
        C:\DOCUME~1\HP_PRO~1\APPLIC~1\Agi
        C:\DOCUME~1\HP_PRO~1\APPLIC~1\Dealio
        C:\DOCUME~1\HP_PRO~1\APPLIC~1\EoRezo
        C:\DOCUME~1\HP_PRO~1\APPLIC~1\ItsLabel
        C:\DOCUME~1\HP_PRO~1\APPLIC~1\Search Settings ... [b]ERREUR SUPPRESSION !![/b]
        C:\DOCUME~1\ALLUSE~1\APPLIC~1\gamesbar
        C:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM
        C:\WINDOWS\Installer\{E1B94435-241E-4519-B1C3-C4DD9EB352A2}
        C:\Program Files\Dealio Toolbar
        C:\Program Files\EoRezo
        C:\Program Files\GamesBar
        C:\Program Files\iMeshMediabarTb
        C:\Program Files\Iminent
        C:\Program Files\Search Guard PlusU
        C:\Program Files\Search Settings
        C:\Program Files\SGPSA
        C:\Program Files\SweetIM ... [b]ERREUR SUPPRESSION !![/b]
        C:\Windows\Installer\1892fb8.msi
        C:\Windows\Installer\1892fbf.msi
        C:\Windows\Installer\4657b.msi
        C:\Windows\Installer\e49c5d.msi
        C:\WINDOWS\Prefetch\ITSTV.EXE-0D33853B.pf
        C:\WINDOWS\Prefetch\SEARCHSETTINGS.EXE-30EFBC20.pf
        C:\WINDOWS\Prefetch\SOFTWAREUPDATEHP.EXE-17DC3287.pf
        C:\WINDOWS\Prefetch\SWEETIM.EXE-19615F6D.pf
        C:\DOCUME~1\HP_PRO~1\Cookies\hp_propri‚taire@ads.eorezo[2].txt
        C:\DOCUME~1\HP_PRO~1\Cookies\hp_propri‚taire@eorezo[2].txt
        .
        HKCU\software\appdatalow\AskBarDis
        HKCU\software\appdatalow\AskHomepage
        HKCU\software\appdatalow\software\Dealio
        HKCU\software\Casino Tropez
        HKCU\software\EoRezo
        HKCU\software\Europa Casino
        HKCU\software\GamesBar
        HKCU\software\iMesh
        HKCU\software\Iminent
        HKCU\software\ItsLabel
        HKCU\Software\Microsoft\Internet Explorer\Explorer Bars\{2AA2FBF8-9C76-4E97-A226-25C5F4AB6358}
        HKCU\Software\Microsoft\Internet Explorer\Explorer Bars\{A7CDDCDC-BEEB-4685-A062-978F5E07CEEE}
        HKCU\Software\Microsoft\Internet Explorer\LowRegistry\BHO iMesh
        HKCU\software\microsoft\internet explorer\searchscopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}
        HKCU\software\microsoft\internet explorer\searchscopes\{19F2B849-4ADE-4d4b-85F9-C31C643DBDE9}
        HKCU\software\microsoft\internet explorer\searchscopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A59}
        HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{B7D3E479-CC68-42B5-A338-938ECE35F419}
        HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440}
        HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EEE6C35B-6118-11DC-9C72-001320C79847}
        HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
        HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{100eb1fd-d03e-47fd-81f3-ee91287f9465}
        HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1a93c934-025b-4c3a-b38e-9654a7003239}
        HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}
        HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6F282B65-56BF-4BD1-A8B2-A4449A05863D}
        HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{b7d3e479-cc68-42b5-a338-938ece35f419}
        HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C5428486-50A0-4A02-9D20-520B59A9F9B2}
        HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C5428486-50A0-4A02-9D20-520B59A9F9B3}
        HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847}
        HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847}
        HKCU\software\Search Settings
        HKCU\software\SweetIM
        HKLM\software\Casino Tropez
        HKLM\software\classes\appid\{362A53B2-2913-4F8A-82F5-7E0A23FDC6F9}
        HKLM\software\classes\appid\EoRezoBHO.DLL
        HKLM\Software\Classes\CLSID\{27BF8F8D-58B8-D41C-F913-B7EEB57EF6F6}
        HKLM\Software\Classes\CLSID\{57CADC46-58FF-4105-B733-5A9F3FC9783C}
        HKLM\Software\Classes\CLSID\{6A7400D6-6615-4A06-A4D1-48979FA6E868}
        HKLM\Software\Classes\CLSID\{6F282B65-56BF-4BD1-A8B2-A4449A05863D}
        HKLM\Software\Classes\CLSID\{ABB49B3B-AB7D-4ED0-9135-93FD5AA4F69F}
        HKLM\Software\Classes\CLSID\{C7B76B90-3455-4AE6-A752-EAC4D19689E5}
        HKLM\Software\Classes\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}
        HKLM\Software\Classes\CLSID\{CB0D163C-E9F4-4236-9496-0597E24B23A5}
        HKLM\Software\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
        HKLM\software\classes\EoRezoBHO.EoBho
        HKLM\software\classes\EoRezoBHO.EoBho.1
        HKLM\software\classes\installer\Products\E3124E1ADA6085C43851291F51139D06
        HKLM\Software\Classes\Interface\{819DB72D-1C28-4387-9778-E2FF3DC86F74}
        HKLM\Software\Classes\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}
        HKLM\software\classes\MediaPlayer.GraphicsUtils
        HKLM\software\classes\MediaPlayer.GraphicsUtils.1
        HKLM\software\classes\MgMediaPlayer.GifAnimator
        HKLM\software\classes\MgMediaPlayer.GifAnimator.1
        HKLM\software\classes\Oberontb.Band
        HKLM\software\classes\Oberontb.Band.1
        HKLM\software\classes\SearchSettings.BHO
        HKLM\software\classes\SearchSettings.BHO.1
        HKLM\software\classes\SWEETIE.IEToolbar
        HKLM\software\classes\SWEETIE.IEToolbar.1
        HKLM\software\classes\SWEETIE.SWEETIE
        HKLM\software\classes\SWEETIE.SWEETIE.3
        HKLM\software\classes\SweetIM_URLSearchHook.ToolbarURLSearchHook
        HKLM\software\classes\SweetIM_URLSearchHook.ToolbarURLSearchHook.1
        HKLM\software\classes\Toolbar3.SWEETIE
        HKLM\software\classes\Toolbar3.SWEETIE.1
        HKLM\Software\Classes\TypeLib\{4509D3CC-B642-4745-B030-645B79522C6D}
        HKLM\Software\Classes\TypeLib\{77AA25E8-6083-4949-A831-9CB11861DC10}
        HKLM\Software\Classes\TypeLib\{96F7FABC-5789-EFA4-B6ED-1272F4C1D27B}
        HKLM\Software\Classes\TypeLib\{AD76633E-E50D-4844-9E7F-4DFBC7C18467}
        HKLM\Software\Classes\TypeLib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}
        HKLM\Software\Classes\TypeLib\{B6ACB3F1-6A83-432C-B854-3E1056F87F4E}
        HKLM\Software\Classes\TypeLib\{CD082CCA-086F-4FD8-8FD7-247A0DBBD1CC}
        HKLM\software\classes\URLSearchHook.ToolbarURLSearchHook
        HKLM\software\classes\URLSearchHook.ToolbarURLSearchHook.1
        HKLM\software\Dealio
        HKLM\software\EoRezo
        HKLM\software\Europa Casino
        HKLM\software\GamesBar
        HKLM\software\GamesBarSetup
        HKLM\software\Iminent
        HKLM\software\ItsLabel
        HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2A9467B4-C085-11DD-BC92-869555D89593}
        HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
        HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}
        HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{6F282B65-56BF-4BD1-A8B2-A4449A05863D}
        HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{ABB49B3B-AB7D-4ED0-9135-93FD5AA4F69F}
        HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{B7D3E479-CC68-42B5-A338-938ECE35F419}
        HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{EEE6C35B-6118-11DC-9C72-001320C79847}
        HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\OBget.exe
        HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\SweetIM.exe
        HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6A7400D6-6615-4A06-A4D1-48979FA6E868}
        HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ABB49B3B-AB7D-4ED0-9135-93FD5AA4F69F}
        HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C7B76B90-3455-4AE6-A752-EAC4D19689E5}
        HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CB0D163C-E9F4-4236-9496-0597E24B23A5}
        HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\02F47BF73B948514FAACADD8CBBDF37D
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\07D5290CDBDAE4242926B8E6CA650501
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\080D9F5E1E95FEE4794CE438E635239E
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\08E33F7B61DEFF24BB9673ED7D467636
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\0E3D8A5B48622A445A7DF73FEFF32C3F
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\1AC67655DD68F8240B2860F2D511EBD8
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\1E264E0A5959A1C46BA9175A878B12EA
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\2E6768B6932D112438F047C54D180635
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\34EDDB1BFB3A2D448845F3EFD0F15A43
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\351716A953E21214898904032EAE2E81
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\427EA997C413D1D47907CBFC7B2DB432
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\4318DF19719275242801CBE292063A4C
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\45FC115D1FEAEF849A4E1610D6EC8BF0
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\46A5861A389ADB844AF89E31BC9DF0A1
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\49B0E1A6FF50BBE4289E4E23DE6EA0C7
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\4CCCAC049F34D0540AAC13011398BEDB
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\5C4389D0BFB302C479DE4178BD5D9EBA
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\5D19F074C042AD34BAB463D4175A062E
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\5D2B09BDEF4FE54418E6F3373CDBC7AC
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\61B65D3397A1FBF4CB1571B5E4F6B5B0
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\68E8A05C60DD9254591DBD16C94EDDBF
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\697E782CF574CC34CBB9566440BA12BC
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\6AE27A8613CF7EA4782F2886F67295E5
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\7CE172051F585E04187BCB97570BFA74
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\86A901BA5265452499DCBF719C378EE3
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\88ABD1CD5C40EC84789A7F6EF86DAC5E
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\9A4B7EF3789F871419D9302583B20C15
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\A189D17A469616C4688D23E192996267
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\A6C53B0F76C44004A8F36716213017DB
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\B59F2D8189784CC46A4597F2842480B0
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\BD746FB95FB8E5B45BF66BE54D5FD91F
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\CCF399FCD6D2D3F46BF02A1378654FC9
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\D149C1355C98DE24E82CEFBD996FE06A
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\DB59FDB786388EA4D897F3EE715683AC
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\DB8DAD19CFBCC2049A4477183787E8C5
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\E1C820A74ED67374BA048B52CB3C3804
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\E337925F629CF4C4FB08F3D9674DD839
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\EC65F200D112357449C8B1BC3CFA03D0
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\F327D0C73C0973644A21E8CC852267A0
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Products\E3124E1ADA6085C43851291F51139D06
        HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform\\Hotbar 10.2.217.0
        HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\EoEngine
        HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\IMBooster
        HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\PlatriumWeather
        HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SearchSettings
        HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SoftwareHelper
        HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SweetIM
        HKLM\software\microsoft\windows\currentversion\uninstall\{0B1AAC97-8563-41D9-AE47-58E6A222F0E1}
        HKLM\software\microsoft\windows\currentversion\uninstall\{266C7330-C0F4-49E5-8F20-A56F9F822875}
        HKLM\software\microsoft\windows\currentversion\uninstall\{94C3BB3A-56A1-43DE-A242-8B41F46E97EF}
        HKLM\software\microsoft\windows\currentversion\uninstall\{A1E4213E-06AD-4C58-8315-92F11531D960}
        HKLM\software\microsoft\windows\currentversion\uninstall\eoEngine_is1
        HKLM\software\microsoft\windows\currentversion\uninstall\GamesBar
        HKLM\software\microsoft\windows\currentversion\uninstall\imeshmediabartb
        HKLM\software\microsoft\windows\currentversion\uninstall\SoftwareUpdate_is1
        HKLM\software\OneStepSearch
        HKLM\software\Search Settings
        HKLM\software\SweetIM
        HKLM\software\Trymedia Systems

        (!) -- Fichiers temporaires supprimés.

        .
        ============== Scan additionnel ==============
        .
        .
        * Mozilla FireFox Version 3.5.5 [fr] *
        .
        Nom du profil: 7znnlv4h.default (HP_Propri‚taire)
        .
        (HP_PRO~1, Invalidprefs.js) Browser.search.defaultenginename, Google
        (HP_PRO~1, Invalidprefs.js) Browser.search.defaulturl, hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
        (HP_PRO~1, Invalidprefs.js) Browser.search.selectedEngine, Google
        (HP_PRO~1, Invalidprefs.js) Browser.startup.homepage, hxxp://lo.st#home
        .
        (HP_PRO~1, Invalidprefs.js) EFFACE - Browser.startup.homepage, hxxp://lo.st#home
        .
        (HP_PRO~1, prefs.js) Browser.search.defaultenginename, MyStart Rechercher
        (HP_PRO~1, prefs.js) Browser.search.defaulturl, hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
        (HP_PRO~1, prefs.js) Browser.search.selectedEngine, MyStart Rechercher
        (HP_PRO~1, prefs.js) Browser.startup.homepage, hxxp://y.lo.st
        (HP_PRO~1, prefs.js) Browser.search.defaultenginename, MyStart Rechercher
        (HP_PRO~1, prefs.js) Browser.search.defaulturl, hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
        (HP_PRO~1, prefs.js) Browser.search.selectedEngine, MyStart Rechercher
        (HP_PRO~1, prefs.js) Browser.startup.homepage, hxxp://mystart.hiyo.com/
        (HP_PRO~1, prefs.js) Browser.search.selectedEngine, MyStart Rechercher
        (HP_PRO~1, prefs.js) Browser.startup.homepage, hxxp://mystart.hiyo.com/
        (HP_PRO~1, prefs.js) Browser.search.selectedEngine, MyStart Rechercher
        .
        (HP_PRO~1, prefs.js) EFFACE - Browser.startup.homepage, hxxp://y.lo.st
        .
        .
        .
        * Internet Explorer Version 8.0.6001.18702 *
        .
        [HKEY_CURRENT_USER\..\Internet Explorer\Main]
        .
        Start Page Redirect Cache: hxxp://fr.msn.com/?ocid=iehp
        Start Page Redirect Cache_TIMESTAMP: NARY a6cf65037008ca01
        Start Page Redirect Cache AcceptLangs: fr
        Search Bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
        SearchAssistant:
        Start Page: hxxp://y.lo.st
        Default_search_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
        Default_page_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
        First Home Page: hxxp://y.lo.st
        .
        [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
        .
        Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
        Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
        Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
        Start Page: hxxp://fr.msn.com/
        Search bar: hxxp://search.msn.com/spbasic.htm
        .
        [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
        .
        Tabs: res://ieframe.dll/tabswelcome.htm
        .
        ============== Suspect (Cracks, Serials, ...) ==============
        .
        C:\Documents and Settings\HP_Propri‚taire\Favoris\Serials & keys - unlocks the world.url
        .
        ===================================
        .
        17880 Octet(s) - C:\Ad-Report-CLEAN[1].log
        .
        5 Fichier(s) - C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp
        4 Fichier(s) - C:\WINDOWS\Temp
        .
        19 Fichier(s) - C:\Program Files\Ad-Remover\BACKUP
        709 Fichier(s) - C:\Program Files\Ad-Remover\QUARANTINE
        .
        Fin à: 19:53:21 | 20/11/2009 - CLEAN[1]
        .
        ============== E.O.F ==============
        .
        0
  4. Utilisateur anonyme
     
    Ok, refais un rapport RSIT, seul le fichier log.txt va s'ouvrir, copie/colle le dans ta réponse.
    0
    1. Nanorabitt
       
      voici le rapport log :

      Logfile of random's system information tool 1.06 (written by random/random)
      Run by HP_Propriétaire at 2009-11-21 09:43:30
      Microsoft Windows XP Édition familiale Service Pack 3
      System drive C: has 105 GB (72%) free of 145 GB
      Total RAM: 510 MB (7% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 09:44:26, on 21/11/2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Hercules\DualPix Exchange\Camservice.exe
      C:\Program Files\HiYo\bin\HiYo.exe
      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Netlog Music Tool\NetlogMusicTool.exe
      C:\WINDOWS\system32\m0suq8wt.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\WINDOWS\system32\drivers\CDAC11BA.EXE
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\system32\wbem\wmiapsrv.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Windows Live\Contacts\wlcomm.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Documents and Settings\HP_Propriétaire\Mes documents\Téléchargements\RSIT(2).exe
      C:\Program Files\Trend Micro\HijackThis\HP_Propriétaire.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lo.st/
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - Default URLSearchHook is missing
      F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Documents and Settings\HP_Propriétaire\kpy.exe \o
      O2 - BHO: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\DealioToolbarIE.dll (file missing)
      O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
      O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: (no name) - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - (no file)
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O3 - Toolbar: (no name) - {6a7400d6-6615-4a06-a4d1-48979fa6e868} - (no file)
      O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [CamserviceDP] C:\Program Files\Hercules\DualPix Exchange\Camservice.exe /startup
      O4 - HKLM\..\Run: [Hiyo] C:\Program Files\HiYo\bin\HiYo.exe /RunFromStartup
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKCU\..\Run: [WOOKIT] C:\Program Files\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [Magentic] C:\PROGRA~1\Magentic\bin\Magentic.exe /c
      O4 - HKCU\..\Run: [Netlog Music Tool] "C:\Program Files\Netlog Music Tool\NetlogMusicTool.exe"
      O4 - HKCU\..\Run: [Lyad] C:\Program Files\Lyad Messenger\lyad_messenger.exe autostart
      O4 - HKCU\..\Run: [m0suq8wt.exe] C:\WINDOWS\system32\m0suq8wt.exe
      O4 - HKCU\..\Run: [PC Speed Maximizer] C:\Program Files\PC Speed Maximizer\SPMTray.exe
      O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
      O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
      O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~2.EXE -Update -1103471 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; SIMBAR={CD336790-67B7-4A18-9B47-B229DCD0BAEF}; GTB6.3; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 1.1.4322; Hotbar 10.2.217.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)" -"http://www.jeuxjeuxjeux.fr/jeu/se+jeter/street+dive.html"
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
      O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
      O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra button: Cool Hand Poker - {00000000-0000-0000-0000-000000000000} - C:\MicroGaming\Poker\coolhandMPP\MPPoker.exe (file missing) (HKCU)
      O16 - DPF: CabBuilder - http://ak.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
      O16 - DPF: {011F473E-0880-43D4-99F3-F490A84128AE} (GenimoWebGames Control) - http://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--8e806481-bf9c-4ef7-98ad-5066b6369c46/online/ButterflyEscape/GenimoWebGamesControl.cab
      O16 - DPF: {049A470D-F818-4E34-B14D-E4E237DADCF8} (CPlayFirstFashionDasControl Object) - http://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--b557f986-1eeb-4ade-a24f-fd83da495e78/online/fashion_dash/fr/fashiondashweb.1.0.0.21.cab
      O16 - DPF: {21BB8360-F943-447E-98F3-3C22345375A7} (CPlayFirstChocolatierControl Object) - http://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--25e36d6d-547a-413a-a6e7-4f9d4dfbf23b/online/chocolatier/fr/ChocolatierWeb.1.0.0.13.cab
      O16 - DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} - http://activex.camfrogweb.com/advanced/2.0.2.3/cfweb_activex.camfrogweb.com-advanced-2.0.2.3_instmodule.exe
      O16 - DPF: {24757662-8772-4986-8E5A-A1C939CDF219} (CPlayFirstSweetopiaControl Object) - http://games.bigfishgames.com/fr_sweetopia/online/Sweetopia.1.0.0.22_fr.cab
      O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} (PogoWebLauncher Control) - http://fr.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB
      O16 - DPF: {38AB6A6C-CC4C-4F9E-A3DD-3C5681EF18A1} (SonyOnlineInstallerX) - http://www-cdn.freerealms.com/gamedata/FreeRealmsInstaller.cab?v=1030
      O16 - DPF: {49E67060-2C0D-415E-94C7-52A49F73B2F1} (CPlayFirstPiratePoppersControl Object) - file:///C:/Documents%20and%20Settings/HP_Propriétaire/Local%20Settings/Application%20Data/Oberon%20Media/Oberon%20Games%20Host/PiratePoppers.1.0.0.39.cab
      O16 - DPF: {596B26AA-E941-4FB5-8F91-0762447578F0} (CPlayFirstdreamControl Object) - http://games.bigfishgames.com/fr_dream-chronicles/online/dream.1.0.0.17_fr.cab
      O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
      O16 - DPF: {6C7CAD20-85AA-475A-AC0D-303C4A9A69CE} (CPlayFirstGreatChocoControl Object) - http://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--5dfe157e-2ed1-4a52-9e87-19c46fc3f9fb/online/the_great_chocolate_chase/fr/greatchocolatechaseweb.1.0.0.13.cab
      O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
      O16 - DPF: {775879E2-7309-4619-BB02-AADE41F4B690} (CPlayFirstdreamControl Object) - http://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--9b4e31a2-26b0-4209-92b6-ee687a2aabd4/online/dream_chronicles/fr/dreamweb.1.0.0.9.cab
      O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://games.bigfishgames.com/fr_luxoramunrising/online/mjolauncher.cab
      O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
      O16 - DPF: {8ADC4409-4FBF-4224-B73F-2392C721BCB4} (GenimoWebGames Control) - http://games.bigfishgames.com/...
      O16 - DPF: {8FA2192F-B95D-40E3-898F-8D7ABB8E00D0} (SpinTop Games Launcher) - http://www.msnjeux.com/online2/MSN_INTL_FRANCE/mystery_solitaire/SpinTopGamesLauncher.cab
      O16 - DPF: {935F9B04-0C7B-4454-A391-348C54AD7ADD} (Jolly Bear Games Player) - http://games.bigfishgames.com/...
      O16 - DPF: {BAC761D3-DFFD-4DB4-A01D-173346E090A7} (CPlayFirstzenerchiControl Object) - http://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--451a1c1a-17be-4a81-bec4-8e56bd2037e3/online/zenerchi/fr/ZenerchiWeb.1.0.0.10.cab
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
      O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxentelechargement.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.com/Register/Branding/olr3313/OCX/v1018/flashax.cab
      O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - file:///C:/Documents%20and%20Settings/HP_Propriétaire/Local%20Settings/Application%20Data/Oberon%20Media/Oberon%20Games%20Host/popcaploader_v10.cab
      O16 - DPF: {E1342154-4889-42B5-BEF6-19237577048F} (OberongamesLoader Object) - http://msnfr.oberon-media.com/online2/MSN_INTL_FRANCE/bejeweled2/Oberongamesloader.cab
      O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
      O16 - DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} (Flash Casino Helper Control) - https://plugins.valueactive.eu/flashax/iefax.cab
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
      O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
      0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. Utilisateur anonyme
     
    On va analyser un fichier :

    • Va sur le site VirusTotal

    • Clique sur le bouton "parcourir"

    • Recherche le fichier présent ici ==> C:\WINDOWS\system32\m0suq8wt.exe

    • Clique sur le bouton "Envoyer le fichier"

    • Patiente pendant le scan du fichier

    • Copie le rapport dans ta réponse

    Si tu ne le trouves pas, il va falloir afficher les fichiers cachés comme ceci :

    Affichage des fichiers/dossiers cachés :

    • Va dans le menu démarrer
    • Clique sur Poste de travail (ou Ordinateur si tu es sous Vista)
    • Clique l'onglet Affichage
    • Clique sur le menu "Outils "
    • Clique sur "Options des dossiers... "
    • Puis clique sur l'onglet "Affichage"
    • Coche la case "Afficher les fichiers et dossiers cachés"
    • Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"
    • Clique lur Oui au message d'alerte
    • Clique sur le bouton "OK"
    0
    1. Nanorabitt
       
      voici le rapport :

      a-squared 4.5.0.41 2009.11.20 Trojan.Win32.FakeSmoke!IK
      AhnLab-V3 5.0.0.2 2009.11.19 -
      AntiVir 7.9.1.72 2009.11.19 -
      Antiy-AVL 2.0.3.7 2009.11.19 -
      Authentium 5.2.0.5 2009.11.19 -
      Avast 4.8.1351.0 2009.11.19 -
      AVG 8.5.0.425 2009.11.19 SHeur2.BSTK
      BitDefender 7.2 2009.11.20 -
      CAT-QuickHeal 10.00 2009.11.19 (Suspicious) - DNAScan
      ClamAV 0.94.1 2009.11.20 -
      Comodo 2983 2009.11.19 Heur.Suspicious
      DrWeb 5.0.0.12182 2009.11.19 -
      eSafe 7.0.17.0 2009.11.19 Win32.TrojanFakeSmok
      eTrust-Vet 35.1.7131 2009.11.19 -
      F-Prot 4.5.1.85 2009.11.19 -
      F-Secure 9.0.15370.0 2009.11.17 -
      Fortinet 3.120.0.0 2009.11.19 -
      GData 19 2009.11.20 -
      Ikarus T3.1.1.74.0 2009.11.20 Trojan.Win32.FakeSmoke
      Jiangmin 11.0.800 2009.11.19 -
      K7AntiVirus 7.10.900 2009.11.19 -
      Kaspersky 7.0.0.125 2009.11.20 Trojan.Win32.FraudPack.aarc
      McAfee 5807 2009.11.19 -
      McAfee+Artemis 5807 2009.11.19 Artemis!30636E1B86FC
      McAfee-GW-Edition 6.8.5 2009.11.19 -
      Microsoft 1.5302 2009.11.19 Trojan:Win32/FakeSmoke
      NOD32 4623 2009.11.19 a variant of Win32/Kryptik.AVO
      Norman 6.03.02 2009.11.19 W32/FakeAV.X!genr
      nProtect 2009.1.8.0 2009.11.19 -
      Panda 10.0.2.2 2009.11.20 Trj/CI.A
      PCTools 7.0.3.5 2009.11.20 Application.Maybe_RogueAV
      Prevx 3.0 2009.11.20 Medium Risk Malware
      Rising 22.22.04.01 2009.11.20 -
      Sophos 4.47.0 2009.11.20 Mal/FakeAV-BQ
      Sunbelt 3.2.1858.2 2009.11.19 Trojan.Win32.Generic!SB.0
      Symantec 1.4.4.12 2009.11.20 -
      TheHacker 6.5.0.2.074 2009.11.19 -
      TrendMicro 9.0.0.1003 2009.11.19 -
      VBA32 3.12.12.0 2009.11.20 -
      ViRobot 2009.11.19.2045 2009.11.19 -
      VirusBuster 5.0.21.0 2009.11.19 -
      Information additionnelle
      File size: 373760 bytes
      MD5 : 30636e1b86fc280bf30acfbb2716c87e
      SHA1 : d5cefc20f0abf0a3727cca87412cab68a1636a66
      SHA256: 64821d615e7ecc25abbf3128b39eba6f7bc20c9bd50212ab05ea37c3f01858c4
      PEInfo: PE Structure information

      ( base data )
      entrypointaddress.: 0x1000
      timedatestamp.....: 0x42C92820 (Mon Jul 4 14:14:24 2005)
      machinetype.......: 0x14C (Intel I386)

      ( 3 sections )
      name viradd virsiz rawdsiz ntrpy md5
      .text 0x1000 0xE4000 0x56E00 7.98 be327dc61f451be6cca7e1c5c7e72f4e
      .rdata 0xE5000 0x1000 0x600 6.33 25c62add973ef6b9970ea8f12acee45c
      .rsrc 0xE6000 0x4000 0x3C00 5.47 8120ddfdcb33b397cad1c9e3d87cefd1

      ( 1 imports )

      > kernel32.dll: GetCurrentProcess, VirtualProtect

      ( 0 exports )
      TrID : File type identification
      Clipper DOS Executable (33.4%)
      Generic Win/DOS Executable (33.2%)
      DOS Executable Generic (33.1%)
      Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
      ssdeep: 6144:36sgZOdcdJvolAvhzIPuPR4ra7uquaN3dX+/VVLotb4kPk7g3WJyTmNrvFjPp:K7ZOadOAtIP24rsNNuLk4hEmmazFDp
      Prevx Info: http://info.prevx.com/aboutprogramtext.asp?PX5=65C1543E004941B1B48205CCCB875D001E0AA33D
      PEiD : -
      RDS : NSRL Reference Data Set
      -
      0
  7. Utilisateur anonyme
     
    D'accord, la suite :

    • Télécharge OTM (de Old_Timer) sur ton Bureau

    • Sous XP : Double clique sur OTM.exe
    • Sous Vista : Fais un clic droit sur OTM.exe et sélectionne "Exécuter en tant qu'administrateur"

    • Assure toi que la case Unregister Dll's and Ocx's soit bien cochée

    • Copie la liste ci-dessous et colle-la dans le cadre jaune (celui de gauche) de OTM sous Paste Instructions for Items to be Moved

    :processes
    explorer.exe
    
    :files
    C:\WINDOWS\system32\m0suq8wt.exe
    C:\WINDOWS\tasks\rpc.job
    C:\WINDOWS\89eviz858.exe
    C:\WINDOWS\system32\768dow9l5ader2164z.exe
    C:\WINDOWS\2738virus5z9.dll
    C:\WINDOWS\system32\121055acktz9l24.dll
    C:\WINDOWS\system32\5z72thre9t16133.exe
    C:\WINDOWS\4z65t9ief799.dll
    C:\WINDOWS\4267not9a-5irus61z.dll
    C:\WINDOWS\system32\4c99thiefz35.exe
    C:\WINDOWS\7795hack9oo54z2.dll
    C:\WINDOWS\system32\22759virzs5b.exe
    C:\WINDOWS\system32\3275zha9ktool4a.exe
    C:\WINDOWS\system32\54e45aczdoor9544.exe
    C:\WINDOWS\6724vi9zs59b.exe
    C:\WINDOWS\system32\5e9a5zw9loader2778.exe
    C:\WINDOWS\system32\727doznload9r1958.exe
    C:\WINDOWS\6918thre5t2362z.dll
    C:\WINDOWS\27372woz9505.exe
    C:\WINDOWS\z36sp51d9.dll
    C:\WINDOWS\system32\3835spamzot649.dll
    C:\WINDOWS\system32\22798sp5mzot6a.dll
    C:\WINDOWS\530s9amzot4b25.dll
    C:\WINDOWS\51e9zpy5are797.dll
    C:\WINDOWS\32941h5cktool418z.exe
    C:\WINDOWS\318355pz459.dll
    C:\WINDOWS\29345worm5cz9.dll
    C:\WINDOWS\2538z9pambot15f5.dll
    C:\WINDOWS\1872z9r5j72a.dll
    C:\WINDOWS\z325vir1679.dll
    C:\WINDOWS\system32\z964959rus2ee.exe
    C:\WINDOWS\system32\96473haz5toola8.dll
    C:\WINDOWS\system32\55z5a5d9are2677.exe
    C:\WINDOWS\system32\2979zvirus950.dll
    C:\WINDOWS\system32\1z121s5y96c.exe
    C:\WINDOWS\4e43b5ck9ooz2147.exe
    C:\WINDOWS\171z9spy3795.exe
    C:\WINDOWS\z021worm295.exe
    C:\WINDOWS\system32\1d07dzwnl5ade9141.dll
    C:\WINDOWS\5509hazktool12c9.exe
    C:\WINDOWS\2a17spzware1985.dll
    C:\WINDOWS\2594zhacktool3cc.dll
    C:\WINDOWS\236z55irus4c9.dll
    C:\WINDOWS\system32\8870zp59c6.exe
    C:\WINDOWS\9zf9v5r269.dll
    C:\WINDOWS\79a3threat54296z.dll
    C:\WINDOWS\791bviz5058.exe
    C:\WINDOWS\7684zackt5ol5fc9.exe
    C:\WINDOWS\15210not-a-59rus156z.dll
    C:\WINDOWS\z709vir2053.dll
    C:\WINDOWS\system32\489spyz5e.exe
    C:\WINDOWS\system32\3cc25dzwar9796.exe
    C:\WINDOWS\system32\30496hack9ozl5da5.exe
    C:\WINDOWS\system32\1z871s9y53b.exe
    C:\WINDOWS\system32\15z45wo9mf4.dll
    C:\WINDOWS\system32\157795pz595.exe
    C:\WINDOWS\7969wor5zc9.dll
    C:\WINDOWS\6760wz5927d.dll
    C:\WINDOWS\56909spz5ed.exe
    C:\WINDOWS\25b5backdoor92z.dll
    C:\WINDOWS\147dth5zat167739.exe
    C:\WINDOWS\319399i5uz4a4.exe
    C:\WINDOWS\d69dow5loadez27579.dll
    C:\WINDOWS\system32\22544nz9-a-virus75c.exe
    C:\WINDOWS\system32\5z9fsp95are2616.dll
    C:\WINDOWS\1a1s5yw9ze870.dll
    C:\WINDOWS\906virus51ez.exe
    C:\WINDOWS\system32\3752tzr5at28159.dll
    C:\WINDOWS\system32\25196spazbotba.exe
    C:\WINDOWS\5cb0spyw5r93z8.exe
    C:\WINDOWS\494fthreaz24568.exe
    
    :Reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "m0suq8wt.exe"=-
    
    :commands
    [purity]
    [emptytemp]
    [start explorer]
    


    • Clique sur le bouton MoveIt! pour lancer la suppression.

    • Clique sur le bouton OK de la fenêtre "Fix Complete"

    • Un rapport s'ouvre, copie/colle le dans ta réponse

    • Si le programme te demande de redémarrer, accepte en cliquant sur Yes

    Le rapport est sauvegardé dans C:\_OTM\MovedFiles
    0
    1. Nanorabitt
       
      voici le rapport :

      All processes killed
      Error: Unable to interpret <C:\WINDOWS\system32\727doznload9r1958.exe> in the current context!
      Error: Unable to interpret <C:\WINDOWS\6918thre5t2362z.dll> in the current context!
      Error: Unable to interpret <C:\WINDOWS\27372woz9505.exe> in the current context!
      Error: Unable to interpret <C:\WINDOWS\z36sp51d9.dll> in the current context!
      Error: Unable to interpret <C:\WINDOWS\system32\3835spamzot649.dll> in the current context!
      Error: Unable to interpret <C:\WINDOWS\system32\22798sp5mzot6a.dll> in the current context!
      Error: Unable to interpret <C:\WINDOWS\530s9amzot4b25.dll> in the current context!
      Error: Unable to interpret <C:\WINDOWS\51e9zpy5are797.dll> in the current context!
      Error: Unable to interpret <C:\WINDOWS\32941h5cktool418z.exe> in the current context!
      Error: Unable to interpret <C:\WINDOWS\318355pz459.dll> in the current context!
      Error: Unable to interpret <C:\WINDOWS\29345worm5cz9.dll> in the current context!
      Error: Unable to interpret <C:\WINDOWS\2538z9pambot15f5.dll> in the current context!
      Error: Unable to interpret <C:\WINDOWS\1872z9r5j72a.dll> in the current context!
      Error: Unable to interpret <C:\WINDOWS\z325vir1679.dll> in the current context!
      Error: Unable to interpret <C:\WINDOWS\system32\z964959rus2ee.exe> in the current context!
      Error: Unable to interpret <C:\WINDOWS\system32\96473haz5toola8.dll> in the current context!
      Error: Unable to interpret <C:\WINDOWS\system32\55z5a5d9are2677.exe> in the current context!
      Error: Unable to interpret <C:\WINDOWS\system32\2979zvirus950.dll> in the current context!
      Error: Unable to interpret <C:\WINDOWS\system32\1z121s5y96c.exe> in the current context!
      Error: Unable to interpret <C:\WINDOWS\4e43b5ck9ooz2147.exe> in the current context!
      Error: Unable to interpret <C:\WINDOWS\171z9spy3795.exe> in the current context!
      Error: Unable to interpret <C:\WINDOWS\z021worm295.exe> in the current context!
      Error: Unable to interpret <C:\WINDOWS\system32\1d07dzwnl5ade9141.dll> in the current context!
      Error: Unable to interpret <C:\WINDOWS\5509hazktool12c9.exe> in the current context!
      Error: Unable to interpret <C:\WINDOWS\2a17spzware1985.dll> in the current context!
      Error: Unable to interpret <C:\WINDOWS\2594zhacktool3cc.dll> in the current context!
      Error: Unable to interpret <C:\WINDOWS\236z55irus4c9.dll> in the current context!
      Error: Unable to interpret <C:\WINDOWS\system32\8870zp59c6.exe> in the current context!
      Error: Unable to interpret <C:\WINDOWS\9zf9v5r269.dll> in the current context!
      Error: Unable to interpret <C:\WINDOWS\79a3threat54296z.dll> in the current context!
      Error: Unable to interpret <C:\WINDOWS\791bviz5058.exe> in the current context!
      Error: Unable to interpret <C:\WINDOWS\7684zackt5ol5fc9.exe> in the current context!
      Error: Unable to interpret <C:\WINDOWS\15210not-a-59rus156z.dll> in the current context!
      Error: Unable to interpret <C:\WINDOWS\z709vir2053.dll> in the current context!
      Error: Unable to interpret <C:\WINDOWS\system32\489spyz5e.exe> in the current context!
      Error: Unable to interpret <C:\WINDOWS\system32\3cc25dzwar9796.exe> in the current context!
      Error: Unable to interpret <C:\WINDOWS\system32\30496hack9ozl5da5.exe> in the current context!
      Error: Unable to interpret <C:\WINDOWS\system32\1z871s9y53b.exe> in the current context!
      Error: Unable to interpret <C:\WINDOWS\system32\15z45wo9mf4.dll> in the current context!
      Error: Unable to interpret <C:\WINDOWS\system32\157795pz595.exe> in the current context!
      Error: Unable to interpret <C:\WINDOWS\7969wor5zc9.dll> in the current context!
      Error: Unable to interpret <C:\WINDOWS\6760wz5927d.dll> in the current context!
      Error: Unable to interpret <C:\WINDOWS\56909spz5ed.exe> in the current context!
      Error: Unable to interpret <C:\WINDOWS\25b5backdoor92z.dll> in the current context!
      Error: Unable to interpret <C:\WINDOWS\147dth5zat167739.exe> in the current context!
      Error: Unable to interpret <C:\WINDOWS\319399i5uz4a4.exe> in the current context!
      Error: Unable to interpret <C:\WINDOWS\d69dow5loadez27579.dll> in the current context!
      Error: Unable to interpret <C:\WINDOWS\system32\22544nz9-a-virus75c.exe> in the current context!
      Error: Unable to interpret <C:\WINDOWS\system32\5z9fsp95are2616.dll> in the current context!
      Error: Unable to interpret <C:\WINDOWS\1a1s5yw9ze870.dll> in the current context!
      Error: Unable to interpret <C:\WINDOWS\906virus51ez.exe> in the current context!
      Error: Unable to interpret <C:\WINDOWS\system32\3752tzr5at28159.dll> in the current context!
      Error: Unable to interpret <C:\WINDOWS\system32\25196spazbotba.exe> in the current context!
      Error: Unable to interpret <C:\WINDOWS\5cb0spyw5r93z8.exe> in the current context!
      Error: Unable to interpret <C:\WINDOWS\494fthreaz24568.exe> in the current context!
      ========== REGISTRY ==========
      Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\m0suq8wt.exe deleted successfully.
      ========== COMMANDS ==========

      [EMPTYTEMP]

      User: All Users

      User: Default User
      ->Temp folder emptied: 18150 bytes
      ->Temporary Internet Files folder emptied: 32902 bytes

      User: HP_Propritaire

      User: HP_Propriétaire
      ->Temp folder emptied: 73297787 bytes
      ->Temporary Internet Files folder emptied: 423752 bytes
      ->Java cache emptied: 0 bytes
      ->FireFox cache emptied: 113651861 bytes
      ->Google Chrome cache emptied: 5876068 bytes

      User: HP_PropriÚtaire

      User: HP_Propri‚taire
      ->Temporary Internet Files folder emptied: 33191 bytes

      User: HP_Propri�taire

      User: LocalService
      ->Temp folder emptied: 115616 bytes
      ->Temporary Internet Files folder emptied: 3028420 bytes

      User: NetworkService
      ->Temp folder emptied: 66016 bytes
      ->Temporary Internet Files folder emptied: 33170 bytes

      %systemdrive% .tmp files removed: 0 bytes
      %systemroot% .tmp files removed: 19569 bytes
      %systemroot%\System32 .tmp files removed: 5279744 bytes
      Windows Temp folder emptied: 32768 bytes
      %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 13530910 bytes
      %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
      RecycleBin emptied: 0 bytes

      Total Files Cleaned = 205,49 mb


      OTM by OldTimer - Version 3.1.2.0 log created on 11212009_103926
      All processes killed

      OTM by OldTimer - Version 3.1.2.0 log created on 11212009_103926
      All processes killed

      OTM by OldTimer - Version 3.1.2.0 log created on 11212009_103926
      All processes killed

      OTM by OldTimer - Version 3.1.2.0 log created on 11212009_103926
      All processes killed

      OTM by OldTimer - Version 3.1.2.0 log created on 11212009_103926
      All processes killed

      OTM by OldTimer - Version 3.1.2.0 log created on 11212009_103925

      Files moved on Reboot...
      File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
      C:\WINDOWS\temp\Perflib_Perfdata_46c.dat moved successfully.

      Registry entries deleted on Reboot...
      0
  8. Utilisateur anonyme
     
    Le script n'a pas fonctionné, essaie de le recopier à partir de ce lien ==> http://www.cijoint.fr/cj200911/cijA04CoGj.txt
    0
    1. Nanorabitt
       
      ok :

      :processes
      explorer.exe

      :files
      C:\WINDOWS\system32\m0suq8wt.exe
      C:\WINDOWS\tasks\rpc.job
      C:\WINDOWS\89eviz858.exe
      C:\WINDOWS\system32\768dow9l5ader2164z.exe
      C:\WINDOWS\2738virus5z9.dll
      C:\WINDOWS\system32\121055acktz9l24.dll
      C:\WINDOWS\system32\5z72thre9t16133.exe
      C:\WINDOWS\4z65t9ief799.dll
      C:\WINDOWS\4267not9a-5irus61z.dll
      C:\WINDOWS\system32\4c99thiefz35.exe
      C:\WINDOWS\7795hack9oo54z2.dll
      C:\WINDOWS\system32\22759virzs5b.exe
      C:\WINDOWS\system32\3275zha9ktool4a.exe
      C:\WINDOWS\system32\54e45aczdoor9544.exe
      C:\WINDOWS\6724vi9zs59b.exe
      C:\WINDOWS\system32\5e9a5zw9loader2778.exe
      C:\WINDOWS\system32\727doznload9r1958.exe
      C:\WINDOWS\6918thre5t2362z.dll
      C:\WINDOWS\27372woz9505.exe
      C:\WINDOWS\z36sp51d9.dll
      C:\WINDOWS\system32\3835spamzot649.dll
      C:\WINDOWS\system32\22798sp5mzot6a.dll
      C:\WINDOWS\530s9amzot4b25.dll
      C:\WINDOWS\51e9zpy5are797.dll
      C:\WINDOWS\32941h5cktool418z.exe
      C:\WINDOWS\318355pz459.dll
      C:\WINDOWS\29345worm5cz9.dll
      C:\WINDOWS\2538z9pambot15f5.dll
      C:\WINDOWS\1872z9r5j72a.dll
      C:\WINDOWS\z325vir1679.dll
      C:\WINDOWS\system32\z964959rus2ee.exe
      C:\WINDOWS\system32\96473haz5toola8.dll
      C:\WINDOWS\system32\55z5a5d9are2677.exe
      C:\WINDOWS\system32\2979zvirus950.dll
      C:\WINDOWS\system32\1z121s5y96c.exe
      C:\WINDOWS\4e43b5ck9ooz2147.exe
      C:\WINDOWS\171z9spy3795.exe
      C:\WINDOWS\z021worm295.exe
      C:\WINDOWS\system32\1d07dzwnl5ade9141.dll
      C:\WINDOWS\5509hazktool12c9.exe
      C:\WINDOWS\2a17spzware1985.dll
      C:\WINDOWS\2594zhacktool3cc.dll
      C:\WINDOWS\236z55irus4c9.dll
      C:\WINDOWS\system32\8870zp59c6.exe
      C:\WINDOWS\9zf9v5r269.dll
      C:\WINDOWS\79a3threat54296z.dll
      C:\WINDOWS\791bviz5058.exe
      C:\WINDOWS\7684zackt5ol5fc9.exe
      C:\WINDOWS\15210not-a-59rus156z.dll
      C:\WINDOWS\z709vir2053.dll
      C:\WINDOWS\system32\489spyz5e.exe
      C:\WINDOWS\system32\3cc25dzwar9796.exe
      C:\WINDOWS\system32\30496hack9ozl5da5.exe
      C:\WINDOWS\system32\1z871s9y53b.exe
      C:\WINDOWS\system32\15z45wo9mf4.dll
      C:\WINDOWS\system32\157795pz595.exe
      C:\WINDOWS\7969wor5zc9.dll
      C:\WINDOWS\6760wz5927d.dll
      C:\WINDOWS\56909spz5ed.exe
      C:\WINDOWS\25b5backdoor92z.dll
      C:\WINDOWS\147dth5zat167739.exe
      C:\WINDOWS\319399i5uz4a4.exe
      C:\WINDOWS\d69dow5loadez27579.dll
      C:\WINDOWS\system32\22544nz9-a-virus75c.exe
      C:\WINDOWS\system32\5z9fsp95are2616.dll
      C:\WINDOWS\1a1s5yw9ze870.dll
      C:\WINDOWS\906virus51ez.exe
      C:\WINDOWS\system32\3752tzr5at28159.dll
      C:\WINDOWS\system32\25196spazbotba.exe
      C:\WINDOWS\5cb0spyw5r93z8.exe
      C:\WINDOWS\494fthreaz24568.exe

      :commands
      [purity]
      [emptytemp]
      [start explorer]
      0
  9. Utilisateur anonyme
     
    Désolé j'ai mal expliqué.

    • Relance OTM

    • Sous XP : Double clique sur OTM.exe
    • Sous Vista : Fais un clic droit sur OTM.exe et sélectionne "Exécuter en tant qu'administrateur"

    • Assure toi que la case Unregister Dll's and Ocx's soit bien cochée

    • Copie la liste à partir de ce lien : http://www.cijoint.fr/cj200911/cijA04CoGj.txt

    • Clique sur le bouton MoveIt! pour lancer la suppression.

    • Clique sur le bouton OK de la fenêtre "Fix Complete"

    • Un rapport s'ouvre, copie/colle le dans ta réponse

    • Si le programme te demande de redémarrer, accepte en cliquant sur Yes

    Le rapport est sauvegardé dans C:\_OTM\MovedFiles
    0
    1. Nanorabitt
       
      je compren pa le lien ca me donne un rapport. je colle quoi et ou?
      0
  10. Utilisateur anonyme
     
    Tu dois copier/coller ce qu'il y a dans le lien dans le cadre jaune de OTM sous Paste Instructions for Items to be Moved.
    0
    1. Nanorabitt
       
      voici le rapport :


      All processes killed
      ========== PROCESSES ==========
      No active process named explorer.exe was found!
      ========== FILES ==========
      File/Folder C:\WINDOWS\system32\m0suq8wt.exe not found.
      File/Folder C:\WINDOWS\tasks\rpc.job not found.
      File/Folder C:\WINDOWS\89eviz858.exe not found.
      File/Folder C:\WINDOWS\system32\768dow9l5ader2164z.exe not found.
      File/Folder C:\WINDOWS\2738virus5z9.dll not found.
      File/Folder C:\WINDOWS\system32\121055acktz9l24.dll not found.
      File/Folder C:\WINDOWS\system32\5z72thre9t16133.exe not found.
      File/Folder C:\WINDOWS\4z65t9ief799.dll not found.
      File/Folder C:\WINDOWS\4267not9a-5irus61z.dll not found.
      File/Folder C:\WINDOWS\system32\4c99thiefz35.exe not found.
      File/Folder C:\WINDOWS\7795hack9oo54z2.dll not found.
      File/Folder C:\WINDOWS\system32\22759virzs5b.exe not found.
      File/Folder C:\WINDOWS\system32\3275zha9ktool4a.exe not found.
      File/Folder C:\WINDOWS\system32\54e45aczdoor9544.exe not found.
      File/Folder C:\WINDOWS\6724vi9zs59b.exe not found.
      File/Folder C:\WINDOWS\system32\5e9a5zw9loader2778.exe not found.
      File/Folder C:\WINDOWS\system32\727doznload9r1958.exe not found.
      File/Folder C:\WINDOWS\6918thre5t2362z.dll not found.
      File/Folder C:\WINDOWS\27372woz9505.exe not found.
      File/Folder C:\WINDOWS\z36sp51d9.dll not found.
      File/Folder C:\WINDOWS\system32\3835spamzot649.dll not found.
      File/Folder C:\WINDOWS\system32\22798sp5mzot6a.dll not found.
      File/Folder C:\WINDOWS\530s9amzot4b25.dll not found.
      File/Folder C:\WINDOWS\51e9zpy5are797.dll not found.
      File/Folder C:\WINDOWS\32941h5cktool418z.exe not found.
      File/Folder C:\WINDOWS\318355pz459.dll not found.
      File/Folder C:\WINDOWS\29345worm5cz9.dll not found.
      File/Folder C:\WINDOWS\2538z9pambot15f5.dll not found.
      File/Folder C:\WINDOWS\1872z9r5j72a.dll not found.
      File/Folder C:\WINDOWS\z325vir1679.dll not found.
      File/Folder C:\WINDOWS\system32\z964959rus2ee.exe not found.
      File/Folder C:\WINDOWS\system32\96473haz5toola8.dll not found.
      File/Folder C:\WINDOWS\system32\55z5a5d9are2677.exe not found.
      File/Folder C:\WINDOWS\system32\2979zvirus950.dll not found.
      File/Folder C:\WINDOWS\system32\1z121s5y96c.exe not found.
      File/Folder C:\WINDOWS\4e43b5ck9ooz2147.exe not found.
      File/Folder C:\WINDOWS\171z9spy3795.exe not found.
      File/Folder C:\WINDOWS\z021worm295.exe not found.
      File/Folder C:\WINDOWS\system32\1d07dzwnl5ade9141.dll not found.
      File/Folder C:\WINDOWS\5509hazktool12c9.exe not found.
      File/Folder C:\WINDOWS\2a17spzware1985.dll not found.
      File/Folder C:\WINDOWS\2594zhacktool3cc.dll not found.
      File/Folder C:\WINDOWS\236z55irus4c9.dll not found.
      File/Folder C:\WINDOWS\system32\8870zp59c6.exe not found.
      File/Folder C:\WINDOWS\9zf9v5r269.dll not found.
      File/Folder C:\WINDOWS\79a3threat54296z.dll not found.
      File/Folder C:\WINDOWS\791bviz5058.exe not found.
      File/Folder C:\WINDOWS\7684zackt5ol5fc9.exe not found.
      File/Folder C:\WINDOWS\15210not-a-59rus156z.dll not found.
      File/Folder C:\WINDOWS\z709vir2053.dll not found.
      File/Folder C:\WINDOWS\system32\489spyz5e.exe not found.
      File/Folder C:\WINDOWS\system32\3cc25dzwar9796.exe not found.
      File/Folder C:\WINDOWS\system32\30496hack9ozl5da5.exe not found.
      File/Folder C:\WINDOWS\system32\1z871s9y53b.exe not found.
      File/Folder C:\WINDOWS\system32\15z45wo9mf4.dll not found.
      File/Folder C:\WINDOWS\system32\157795pz595.exe not found.
      File/Folder C:\WINDOWS\7969wor5zc9.dll not found.
      File/Folder C:\WINDOWS\6760wz5927d.dll not found.
      File/Folder C:\WINDOWS\56909spz5ed.exe not found.
      File/Folder C:\WINDOWS\25b5backdoor92z.dll not found.
      File/Folder C:\WINDOWS\147dth5zat167739.exe not found.
      File/Folder C:\WINDOWS\319399i5uz4a4.exe not found.
      File/Folder C:\WINDOWS\d69dow5loadez27579.dll not found.
      File/Folder C:\WINDOWS\system32\22544nz9-a-virus75c.exe not found.
      File/Folder C:\WINDOWS\system32\5z9fsp95are2616.dll not found.
      File/Folder C:\WINDOWS\1a1s5yw9ze870.dll not found.
      File/Folder C:\WINDOWS\906virus51ez.exe not found.
      File/Folder C:\WINDOWS\system32\3752tzr5at28159.dll not found.
      File/Folder C:\WINDOWS\system32\25196spazbotba.exe not found.
      File/Folder C:\WINDOWS\5cb0spyw5r93z8.exe not found.
      File/Folder C:\WINDOWS\494fthreaz24568.exe not found.
      ========== COMMANDS ==========

      [EMPTYTEMP]

      User: All Users

      User: Default User
      ->Temp folder emptied: 0 bytes
      ->Temporary Internet Files folder emptied: 0 bytes

      User: HP_Propritaire

      User: HP_Propriétaire
      ->Temp folder emptied: 132755 bytes
      ->Temporary Internet Files folder emptied: 33170 bytes
      ->Java cache emptied: 0 bytes
      ->FireFox cache emptied: 15684356 bytes
      ->Google Chrome cache emptied: 0 bytes

      User: HP_PropriÚtaire

      User: HP_Propri‚taire
      ->Temporary Internet Files folder emptied: 0 bytes

      User: HP_Propri�taire

      User: LocalService
      ->Temp folder emptied: 66016 bytes
      ->Temporary Internet Files folder emptied: 33170 bytes

      User: NetworkService
      ->Temp folder emptied: 0 bytes
      ->Temporary Internet Files folder emptied: 33170 bytes

      %systemdrive% .tmp files removed: 0 bytes
      %systemroot% .tmp files removed: 0 bytes
      %systemroot%\System32 .tmp files removed: 0 bytes
      Windows Temp folder emptied: 16384 bytes
      %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
      %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
      RecycleBin emptied: 0 bytes

      Total Files Cleaned = 15,26 mb


      OTM by OldTimer - Version 3.1.2.0 log created on 11212009_112132

      Files moved on Reboot...
      File C:\WINDOWS\temp\_avast4_\Webshlock.txt not found!
      C:\WINDOWS\temp\Perflib_Perfdata_4c0.dat moved successfully.

      Registry entries deleted on Reboot...
      0
  11. Utilisateur anonyme
     
    Refais un rapport RSIT stp.
    0
    1. Nanorabitt
       
      voici le rapport :

      Logfile of random's system information tool 1.06 (written by random/random)
      Run by HP_Propriétaire at 2009-11-21 12:07:57
      Microsoft Windows XP Édition familiale Service Pack 3
      System drive C: has 106 GB (73%) free of 145 GB
      Total RAM: 510 MB (21% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 12:08:33, on 21/11/2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\WINDOWS\system32\drivers\CDAC11BA.EXE
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\notepad.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Hercules\DualPix Exchange\Camservice.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\Program Files\HiYo\bin\HiYo.exe
      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      C:\WINDOWS\system32\RUNDLL32.EXE
      C:\WINDOWS\system32\wbem\wmiapsrv.exe
      C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Documents and Settings\HP_Propriétaire\Mes documents\Téléchargements\RSIT(3).exe
      C:\Program Files\Trend Micro\HijackThis\HP_Propriétaire.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lo.st/
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - Default URLSearchHook is missing
      F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Documents and Settings\HP_Propriétaire\kpy.exe \o
      O2 - BHO: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\DealioToolbarIE.dll (file missing)
      O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
      O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: (no name) - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - (no file)
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O3 - Toolbar: (no name) - {6a7400d6-6615-4a06-a4d1-48979fa6e868} - (no file)
      O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [CamserviceDP] C:\Program Files\Hercules\DualPix Exchange\Camservice.exe /startup
      O4 - HKLM\..\Run: [Hiyo] C:\Program Files\HiYo\bin\HiYo.exe /RunFromStartup
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKCU\..\Run: [WOOKIT] C:\Program Files\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [Magentic] C:\PROGRA~1\Magentic\bin\Magentic.exe /c
      O4 - HKCU\..\Run: [Netlog Music Tool] "C:\Program Files\Netlog Music Tool\NetlogMusicTool.exe"
      O4 - HKCU\..\Run: [Lyad] C:\Program Files\Lyad Messenger\lyad_messenger.exe autostart
      O4 - HKCU\..\Run: [PC Speed Maximizer] C:\Program Files\PC Speed Maximizer\SPMTray.exe
      O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
      O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
      O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~2.EXE -Update -1103471 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; SIMBAR={CD336790-67B7-4A18-9B47-B229DCD0BAEF}; GTB6.3; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 1.1.4322; Hotbar 10.2.217.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)" -"http://www.jeuxjeuxjeux.fr/jeu/se+jeter/street+dive.html"
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
      O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
      O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra button: Cool Hand Poker - {00000000-0000-0000-0000-000000000000} - C:\MicroGaming\Poker\coolhandMPP\MPPoker.exe (file missing) (HKCU)
      O16 - DPF: CabBuilder - http://ak.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
      O16 - DPF: {011F473E-0880-43D4-99F3-F490A84128AE} (GenimoWebGames Control) - http://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--8e806481-bf9c-4ef7-98ad-5066b6369c46/online/ButterflyEscape/GenimoWebGamesControl.cab
      O16 - DPF: {049A470D-F818-4E34-B14D-E4E237DADCF8} (CPlayFirstFashionDasControl Object) - http://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--b557f986-1eeb-4ade-a24f-fd83da495e78/online/fashion_dash/fr/fashiondashweb.1.0.0.21.cab
      O16 - DPF: {21BB8360-F943-447E-98F3-3C22345375A7} (CPlayFirstChocolatierControl Object) - http://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--25e36d6d-547a-413a-a6e7-4f9d4dfbf23b/online/chocolatier/fr/ChocolatierWeb.1.0.0.13.cab
      O16 - DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} - http://activex.camfrogweb.com/advanced/2.0.2.3/cfweb_activex.camfrogweb.com-advanced-2.0.2.3_instmodule.exe
      O16 - DPF: {24757662-8772-4986-8E5A-A1C939CDF219} (CPlayFirstSweetopiaControl Object) - http://games.bigfishgames.com/fr_sweetopia/online/Sweetopia.1.0.0.22_fr.cab
      O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} (PogoWebLauncher Control) - http://fr.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB
      O16 - DPF: {38AB6A6C-CC4C-4F9E-A3DD-3C5681EF18A1} (SonyOnlineInstallerX) - http://www-cdn.freerealms.com/gamedata/FreeRealmsInstaller.cab?v=1030
      O16 - DPF: {49E67060-2C0D-415E-94C7-52A49F73B2F1} (CPlayFirstPiratePoppersControl Object) - file:///C:/Documents%20and%20Settings/HP_Propriétaire/Local%20Settings/Application%20Data/Oberon%20Media/Oberon%20Games%20Host/PiratePoppers.1.0.0.39.cab
      O16 - DPF: {596B26AA-E941-4FB5-8F91-0762447578F0} (CPlayFirstdreamControl Object) - http://games.bigfishgames.com/fr_dream-chronicles/online/dream.1.0.0.17_fr.cab
      O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
      O16 - DPF: {6C7CAD20-85AA-475A-AC0D-303C4A9A69CE} (CPlayFirstGreatChocoControl Object) - http://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--5dfe157e-2ed1-4a52-9e87-19c46fc3f9fb/online/the_great_chocolate_chase/fr/greatchocolatechaseweb.1.0.0.13.cab
      O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
      O16 - DPF: {775879E2-7309-4619-BB02-AADE41F4B690} (CPlayFirstdreamControl Object) - http://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--9b4e31a2-26b0-4209-92b6-ee687a2aabd4/online/dream_chronicles/fr/dreamweb.1.0.0.9.cab
      O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://games.bigfishgames.com/fr_luxoramunrising/online/mjolauncher.cab
      O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
      O16 - DPF: {8ADC4409-4FBF-4224-B73F-2392C721BCB4} (GenimoWebGames Control) - http://games.bigfishgames.com/...
      O16 - DPF: {8FA2192F-B95D-40E3-898F-8D7ABB8E00D0} (SpinTop Games Launcher) - http://www.msnjeux.com/online2/MSN_INTL_FRANCE/mystery_solitaire/SpinTopGamesLauncher.cab
      O16 - DPF: {935F9B04-0C7B-4454-A391-348C54AD7ADD} (Jolly Bear Games Player) - http://games.bigfishgames.com/...
      O16 - DPF: {BAC761D3-DFFD-4DB4-A01D-173346E090A7} (CPlayFirstzenerchiControl Object) - http://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--451a1c1a-17be-4a81-bec4-8e56bd2037e3/online/zenerchi/fr/ZenerchiWeb.1.0.0.10.cab
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
      O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxentelechargement.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.com/Register/Branding/olr3313/OCX/v1018/flashax.cab
      O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - file:///C:/Documents%20and%20Settings/HP_Propriétaire/Local%20Settings/Application%20Data/Oberon%20Media/Oberon%20Games%20Host/popcaploader_v10.cab
      O16 - DPF: {E1342154-4889-42B5-BEF6-19237577048F} (OberongamesLoader Object) - http://msnfr.oberon-media.com/online2/MSN_INTL_FRANCE/bejeweled2/Oberongamesloader.cab
      O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
      O16 - DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} (Flash Casino Helper Control) - https://plugins.valueactive.eu/flashax/iefax.cab
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
      O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
      0
  12. Utilisateur anonyme
     
    Bien tu as encore ces messages d'alerte ?

    On passe à la suite :

    Note : tu as une infection qui se propage par les disques amovibles.

    • Télécharge USBFix (de Chiquitine29 et C_XX) sur ton Bureau

    • Sous XP : Double clique sur UsbFix.exe
    • Sous Vista/7 : Fais un clic droit sur UsbFix.exe et sélectionne "Exécuter en tant qu'administrateur"

    • Appuie sur la touche F pour sélectionner le français et valide avec la touche Entrée.

    • Choisis l'option "Recherche" en appuyant sur la touche 1 et valide avec la touche Entrée

    Branche à ton PC tes disques amovibles (clé USB, disque dur externe, lecteur MP3, téléphone, etc...) suceptibles d'avoir été infectés sans les ouvrir quand l'outil te le demande et clique sur le bouton OK

    • Patiente pendant que l'outil travaille

    • A la fin du scan un rapport va s'ouvir, copie/colle le dans ta réponse

    Le rapport est sauvegardé dans C:\UsbFix.txt

    Note :
    Process.exe est détecté par certains antivirus comme étant un RiskTool.
    Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.


    Tutoriel recherche en images
    0