Redirection sur btcar, popeo et autre site

Bonjour,j'ai depuis quelques temps des pb de navigation,je demande une requete avec Google, ce dernier me redirige sur un autre sitre du genre btcar,popeo, meme a caractere porno,il y a une quinzaine,j'ai scanné avec malwerbytes qui ma trouver 24 fichiers verole, mise en quarantaine, et suppression, le systeme est redevenu stable quelque jours et rebelotte ça merdouille a nouveau Merci pour votre aide.

Système windows xp, firefox 3.5.5 AVAST en protection résidente
Configuration: Windows XP
Firefox 3.5.5

20 réponses

Résumé de la discussion

Plusieurs messages décrivent des redirections de recherche et une navigation Internet instable sous Windows XP, provoquées par des infections ciblant des fichiers VBS et des barres d’outils malveillantes. Les échanges recommandent d’analyser les fichiers suspects sur VirusTotal, de supprimer ou mettre en quarantaine via Malwarebytes, puis d’éradiquer les barres d’outils indésirables et d’effectuer une désinfection avec RSIT et HijackThis. Parmi les éléments constatés figuraient des scripts .vbs dans C:\Windows\System32 et des fichiers temporaires, accompagnés de rapports de scan listant des programmes tenaces et des composants Avast ou des modules Java obsolètes. En outre, certains échanges insistent sur l’importance de décocher les cases d’installation pour éviter les toolbars, et recommandent de redémarrer après chaque étape de désinfection pour éviter une réinfection.

Bobot (l’IA à votre service)
  1. Salut,

    Fais ce qui suit :

    * Télécharge Random's system information tool (RSIT) et enregistre le sur ton bureau.
    * Double clique sur RSIT.exe pour lancer l'outil.
    * Clique sur ' continue ' à l'écran Disclaimer.
    * Si l'outil HIjackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.
    * Une fois le scan fini , 2 rapports vont apparaitre. Poste le contenu des 2 rapports.

    ( C:\RSIT\log.txt & C:\RSIT\info.txt )

    (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
    0
    1. Bonsoir,merci de m'aider.Hier,J'ai télécharger RSIT suite a une conversation sur ce forum car quelqu'un avait le même problème.donc ci joint le fichier log et info d'hier.Remarque, en relançant le RSIT une deuxième fois, j'obtient qu'un seul fichier avec entre autre le fameux HIJACK THIS.Je te transmet l'ensemble et bonne pioche, moi, je ne suis qu'un néophyte.@+MERCI BEAUCOUP
      info.txt /logfile of random's system information tool 1.06 2009-12-07 21:33:20

      ======Uninstall list======

      -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
      -->c:\WINDOWS\system32\\MSIEXEC.EXE /x {075473F5-846A-448B-BCB3-104AA1760205}
      -->c:\WINDOWS\system32\\MSIEXEC.EXE /x {AB708C9B-97C8-4AC9-899B-DBF226AC9382}
      -->c:\WINDOWS\system32\\MSIEXEC.EXE /x {B12665F4-4E93-4AB4-B7FC-37053B524629}
      -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{28B97CAB-828F-49D8-A30A-675476F9BA92}\setup.exe" -l0x40c /cont -removeonly
      -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3D173DC5-4AE5-4B3F-9819-3977DD11B1D0}\setup.exe" -l0x40c -removeonly
      -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4E7DC12A-3597-4A94-9429-F6C6987361B1}\setup.exe" -l0x40c -removeonly
      -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6813C983-427E-4511-8456-E98FCAA1A125}\setup.exe" -l0x40c -removeonly
      -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7DADB304-AF20-48C3-A780-4B4133A08817}\setup.exe" -l0x40c -removeonly
      -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9C423CF6-2DAA-4A37-94B8-59D7ECC7DB13}\setup.exe" -l0x40c -removeonly
      -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B34B6E67-FCDD-4E03-8742-B5701427FAFB}\setup.exe" -l0x40c -removeonly
      -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C9EFF51A-C925-4F1A-9DEB-DB5F970DE983}\setup.exe" -l0x40c -removeonly
      -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FA6CC4B4-7741-4F8D-8E81-15C4BAB9869B}\setup.exe" -l0x40c -removeonly
      -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
      1000 mots pour apprendre à lire V 2.3-->C:\educampa\unins000.exe
      7-Zip 4.57-->"C:\Program Files\7-Zip\Uninstall.exe"
      Adobe AIR-->C:\Program Files\Fichiers communs\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
      Adobe AIR-->MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
      Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
      Adobe Reader 7.0.5 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A70500000002}
      Adobe Shockwave Player 11.5-->"C:\WINDOWS\system32\Adobe\Shockwave 11\uninstaller.exe"
      Amélioration de nos services-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{23012310-3E05-46A5-88A9-C6CBCABCAC79} /l1036
      ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
      avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
      bayardKids-->MsiExec.exe /X{5531FE19-3757-5A61-C0A1-CA8BE9FBB9D4}
      CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
      Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
      Dealio Toolbar v4.0.1-->MsiExec.exe /X{94C3BB3A-56A1-43DE-A242-8B41F46E97EF}
      Diner Dash-->"C:\Program Files\Diner Dash\Uninstall.exe"
      Dis-moi Adi CM2-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{75579BE1-DD40-429F-BB3F-A4E45CB4BDF3}\setup.exe" -l0x40c -removeonly
      Enhanced Multimedia Keyboard Solution-->C:\HP\KBD\Install.exe /remove
      FormatFactory 2.15-->C:\Program Files\FreeTime\FormatFactory\uninst.exe
      Gimp Pack Mode 2.4.2-->"C:\Program Files\Gimp Pack Mode\unins000.exe"
      Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_E582EA556D8DE101.exe" /uninstall
      Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
      HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
      HP Appareils photos Photosmart 6.0-->C:\Program Files\HP\Digital Imaging\{5D61626A-BD55-4e42-82EE-4AE89D8FD050}\setup\hpzscr01.exe -datfile hpiscr01.dat
      HP Boot Optimizer-->MsiExec.exe /X{1341D838-719C-4A05-B50F-49420CA1B4BB}
      HP Deskjet Printer Preload-->MsiExec.exe /I{2C5D07FB-31A2-4F2D-9FDA-0B24ACD42BD0}
      HP Document Viewer 6.1-->C:\Program Files\HP\Digital Imaging\DocumentViewer\hpzscr01.exe -datfile hpqbud04.dat
      HP DVD Play 2.1-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{45D707E9-F3C4-11D9-A373-0050BAE317E1}\Setup.exe" -uninstall
      HP Imaging Device Functions 7.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
      HP Photosmart 330,380,420,470,7800,8000,8200 Series-->C:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\setup\hpzscr01.exe -d MsiRollbackUninstaller -datfile hphscr08.dat
      HP Photosmart Premier Software 6.5-->C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
      HP PSC & OfficeJet 5.3.B-->"C:\Program Files\HP\Digital Imaging\{5B79CFD1-6845-4158-9D7D-6BE89DF2C135}\setup\hpzscr01.exe" -datfile hposcr07.dat
      HP PSC & OfficeJet 6.1.A-->"C:\Program Files\HP\Digital Imaging\{E5A8DDAB-AE80-48C6-A75B-D0FAB83B299D}\setup\hpzscr01.exe" -datfile hposcr08.dat
      HP Software Update-->MsiExec.exe /X{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}
      HP Solution Center and Imaging Support Tools 6.1-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
      IncrediMail-->C:\Program Files\IncrediMail\bin\ImSetup.exe /remove /addon:IncrediMail /log:IncMail.log
      InfraRecorder-->C:\Program Files\InfraRecorder\uninstall.exe
      J2SE Runtime Environment 5.0 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150050}
      Java(TM) 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
      Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
      LimeWire 4.18.3-->"C:\Program Files\LimeWire\uninstall.exe"
      livebox-->C:\Program Files\InstallShield Installation Information\{17342E3B-0818-4A6F-BFF8-99476605ADD6}\Setup.exe -runfromtemp -l0x040c -removeonly
      Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
      Memonix version 1.5-->"C:\Program Files\Memonix\unins000.exe"
      Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
      Microsoft .NET Framework 1.1 Security Update (KB953297)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M953297\M953297Uninstall.msp"
      Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
      Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
      Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
      Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
      Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
      Microsoft Office XP Professional avec FrontPage-->MsiExec.exe /I{9028040C-6000-11D3-8CFE-0050048383C9}
      Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
      Microsoft Works-->MsiExec.exe /I{A059DE09-1B49-4450-B340-7AE097EC3F04}
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB969897)-->"C:\WINDOWS\ie7updates\KB969897-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB972260)-->"C:\WINDOWS\ie7updates\KB972260-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB974455)-->"C:\WINDOWS\ie7updates\KB974455-IE7\spuninst\spuninst.exe"
      Mise à jour pour Windows Internet Explorer 7 (KB976749)-->"C:\WINDOWS\ie7updates\KB976749-IE7\spuninst\spuninst.exe"
      mission vétérinaire - les animaux du zoo-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B4F60A06-9D56-4815-9FBF-D16DEEF11B61}\setup.exe" -l0x40c -removeonly
      Mission Vétérinaire - les animaux familiers-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4F96844B-C3E4-476A-8EBC-9CBF6DC608BE}\setup.exe" -l0x40c -removeonly
      Mozilla Firefox (3.5.5)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
      Mozilla Thunderbird (2.0.0.14)-->C:\Program Files\Mozilla Thunderbird\uninstall\helper.exe
      MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
      MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
      MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
      muvee autoProducer 5.0-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{27428D1B-8CBA-4EEA-B9C0-A23CA7B4FCC1}\setup.exe" -l0x40c
      MyDSC2-->C:\Program Files\InstallShield Installation Information\{83D96ED0-98AA-4515-8DDC-816F3EFDD104}\setup.exe -runfromtemp -l0x040c -removeonly
      OpenOffice.org 2.3-->MsiExec.exe /I{B087B0C3-F595-485A-B86B-73326BA8693A}
      Panneau de contrôle ATI-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
      PowerCinema-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\Setup.exe" -uninstall
      QuickTime-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{C21D5524-A970-42FA-AC8A-59B8C7CDCA31} /l1036
      Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
      Search Settings 1.2.2-->MsiExec.exe /X{0B1AAC97-8563-41D9-AE47-58E6A222F0E1}
      Services Internet-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{5CFD7508-7774-48FE-8280-7A3C0AE71755} /l1036
      Shop for HP Supplies-->C:\Program Files\HP\Digital Imaging\HPSSupply\hpzscr01.exe -datfile hpqbud16.dat
      Sonic Express Labeler-->MsiExec.exe /X{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
      Sonic MyDVD Plus-->MsiExec.exe /X{21657574-BD54-48A2-9450-EB03B2C7FC29}
      Sonic RecordNow Audio-->MsiExec.exe /X{AB708C9B-97C8-4AC9-899B-DBF226AC9382}
      Sonic RecordNow Copy-->MsiExec.exe /X{B12665F4-4E93-4AB4-B7FC-37053B524629}
      Sonic RecordNow Data-->MsiExec.exe /X{075473F5-846A-448B-BCB3-104AA1760205}
      Sonic Update Manager-->MsiExec.exe /X{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
      Sony Picture Utility-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D5068583-D569-468B-9755-5FBF5848F46F}\setup.exe" -l0x40c /removeonly uninstall -removeonly
      Sony USB Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5C29CB8B-AC1E-4114-8D68-9CD080140D4A}\setup.exe" -l0x40c UNINSTALL -removeonly
      VideoLAN VLC media player 0.8.6e-->C:\Program Files\VideoLAN\VLC\uninstall.exe
      Windows Defender-->MsiExec.exe /I{A06275F4-324B-4E85-95E6-87B2CD729401}
      Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
      Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
      Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
      Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
      XnView 1.93.1-->"C:\Program Files\XnView\unins000.exe"

      ======Security center information======

      AV: avast! antivirus 4.8.1368 [VPS 091207-0]

      ======System event log======

      Computer Name: NOM-EB85C523610
      Event Code: 32
      Message: L'assemblage dépendant Microsoft.VC80.MFCLOC ne peut pas être trouvé. La dernière erreur était L'assemblage référencé n'est pas installé sur votre système.

      Record Number: 377834
      Source Name: SideBySide
      Time Written: 20091206103206.000000+060
      Event Type: erreur
      User:

      Computer Name: NOM-EB85C523610
      Event Code: 59
      Message: Generate Activation Context a échoué pour C:\Program Files\IncrediMail\bin\MFC80U.DLL.
      Message d'erreur de référence : Opération réussie.
      .

      Record Number: 377833
      Source Name: SideBySide
      Time Written: 20091206103206.000000+060
      Event Type: erreur
      User:

      Computer Name: NOM-EB85C523610
      Event Code: 59
      Message: Resolve Partial Assembly a échoué pour Microsoft.VC80.MFCLOC.
      Message d'erreur de référence : L'assemblage référencé n'est pas installé sur votre système.
      .

      Record Number: 377832
      Source Name: SideBySide
      Time Written: 20091206103206.000000+060
      Event Type: erreur
      User:

      Computer Name: NOM-EB85C523610
      Event Code: 32
      Message: L'assemblage dépendant Microsoft.VC80.MFCLOC ne peut pas être trouvé. La dernière erreur était L'assemblage référencé n'est pas installé sur votre système.

      Record Number: 377831
      Source Name: SideBySide
      Time Written: 20091206103206.000000+060
      Event Type: erreur
      User:

      Computer Name: NOM-EB85C523610
      Event Code: 59
      Message: Generate Activation Context a échoué pour C:\Program Files\IncrediMail\bin\MFC80U.DLL.
      Message d'erreur de référence : Opération réussie.
      .

      Record Number: 377830
      Source Name: SideBySide
      Time Written: 20091206103205.000000+060
      Event Type: erreur
      User:

      =====Application event log=====

      Computer Name: NOM-EB85C523610
      Event Code: 4
      Message: The LightScribe Service started successfully.

      Record Number: 4018
      Source Name: LightScribeService
      Time Written: 20081203072720.000000+060
      Event Type: Informations
      User:

      Computer Name: NOM-EB85C523610
      Event Code: 1517
      Message: Windows a sauvegardé le Registre utilisateur NOM-EB85C523610\HP_Propriétaire alors qu'une application ou un service utilisait toujours le Registre pendant la fermeture de la session. La mémoire utilisée par le Registre de l'utilisateur n'a pas été libérée. le Registre sera déchargé lorsqu'il ne sera plus utilisé.

      Cela est souvent causé par des services s'exécutant en tant que compte d'utilisateur, essayez de configurer les services pour s'exécuter dans le compte service réseau ou service local.

      Record Number: 4017
      Source Name: Userenv
      Time Written: 20081203064923.000000+060
      Event Type: Avertissement
      User: AUTORITE NT\SYSTEM

      Computer Name: NOM-EB85C523610
      Event Code: 1524
      Message: Windows ne peut pas décharger vos classes fichier de Registre - il est en cours d'utilisation par d'autres applications ou services. Le fichier sera déchargé quand il ne sera plus utilisé.

      Record Number: 4016
      Source Name: Userenv
      Time Written: 20081203064922.000000+060
      Event Type: Avertissement
      User: NOM-EB85C523610\HP_Propriétaire

      Computer Name: NOM-EB85C523610
      Event Code: 1800
      Message: Le service Centre de sécurité Windows a démarré.

      Record Number: 4015
      Source Name: SecurityCenter
      Time Written: 20081203062024.000000+060
      Event Type: Informations
      User:

      Computer Name: NOM-EB85C523610
      Event Code: 0
      Message:
      Record Number: 4014
      Source Name: CLSched
      Time Written: 20081203062018.000000+060
      Event Type: Informations
      User:

      ======Environment variables======

      "ComSpec"=%SystemRoot%\system32\cmd.exe
      "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;c:\Python22;C:\Program Files\ATI Technologies\ATI Control Panel;C:\Program Files\QuickTime\QTSystem\
      "windir"=%SystemRoot%
      "FP_NO_HOST_CHECK"=NO
      "OS"=Windows_NT
      "PROCESSOR_ARCHITECTURE"=x86
      "PROCESSOR_LEVEL"=15
      "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 9, GenuineIntel
      "PROCESSOR_REVISION"=0409
      "NUMBER_OF_PROCESSORS"=2
      "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
      "TEMP"=%SystemRoot%\TEMP
      "TMP"=%SystemRoot%\TEMP
      "SonicCentral"=c:\Program Files\Fichiers communs\Sonic Shared\Sonic Central\
      "CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip
      "QTJAVA"=C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip

      -----------------EOF-----------------
      Logfile of random's system information tool 1.06 (written by random/random)
      Run by HP_Propriétaire at 2009-12-07 21:32:59
      Microsoft Windows XP Édition familiale Service Pack 3
      System drive C: has 53 GB (75%) free of 71 GB
      Total RAM: 959 MB (49% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 21:33:18, on 07/12/2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16915)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Windows Defender\MsMpEng.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\QuickTime\qttask.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\Alwil Software\Avast4\ashDisp.exe
      C:\Program Files\IncrediMail\bin\IMApp.exe
      C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
      C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
      C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
      C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      F:\Mes documents\Téléchargements\RSIT.exe
      C:\Program Files\trend micro\HP_Propriétaire.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://fr.search.yahoo.com/?fr=cb-hp06
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.mirarsearch.com/?useie5=1&q=
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.mirarsearch.com/?useie5=1&q=
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.duxot.com/
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://fr.search.yahoo.com/?fr=cb-hp06
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb128\SearchSettings.dll
      O2 - BHO: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\DealioToolbarIE.dll
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
      O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
      O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb128\SearchSettings.dll
      O3 - Toolbar: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\DealioToolbarIE.dll
      O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
      O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
      O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
      O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1
      O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
      O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
      O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\Shockwave 11\SwHelper_1151601.exe -Update -1151601 -"Mozilla/5.0_(Windows;_U;_Windows_NT_5.1;_fr;_rv:1.9.1.5)_Gecko/20091102_Firefox/3.5.5" -"http://www8.agame.com/..."
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
      O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
      O4 - Global Startup: Raccourci vers ashDisp.lnk = C:\Program Files\Alwil Software\Avast4\ashDisp.exe
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
      O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
      O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
      O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
      0
      1. Salut,

        Tu ordinateur est bien infecté.

        Tu as des toolbars infectées sur ton ordinateur => searchsettings

        Lorsque tu installes un programme gratuit ou non sur ton ordinateur, il faut de plus en plus souvent cocher ou décocher des cases pour ne pas autoriser l'installation d'une toolbar. Fais donc bien attention lors de l'installation d'un programme.

        A lire sur les toolbars

        On va commencer la désinfection de ton ordinateur, fais ceci stp :

        Télécharge ToolbarSD (de Team IDN) sur ton Bureau
        * Lance l'installation du programme en exécutant le fichier téléchargé.
        * Double-clique maintenant sur le raccourci de Toolbar-S&D.
        * Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
        * Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
        * Poste le rapport généré. (C:\TB.txt)
        0
        1. -----------\\ ToolBar S&D 1.2.9 XP/Vista

          Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
          X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) 4 CPU 3.06GHz )
          BIOS : BIOS Date: 06/01/2006 Ver: 08.00.12
          USER : HP_Propriétaire ( Administrator )
          BOOT : Normal boot
          Antivirus : avast! antivirus 4.8.1368 [VPS 091208-1] 4.8.1368 (Activated)
          C:\ (Local Disk) - NTFS - Total:68 Go (Free:51 Go)
          D:\ (Local Disk) - FAT32 - Total:6 Go (Free:0 Go)
          E:\ (CD or DVD)
          F:\ (Local Disk) - NTFS - Total:111 Go (Free:84 Go)
          G:\ (USB)
          H:\ (USB)
          I:\ (USB)
          J:\ (USB)
          M:\ (USB)

          "C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
          Option : [1] ( 08/12/2009|21:14 )

          -----------\\ Recherche de Fichiers / Dossiers ...

          -----------\\ Extensions

          (HP_Propri‚taire) - {0538E3E3-7E9B-4d49-8831-A227C80A7AD3} => forecastfox
          (HP_Propri‚taire) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
          (HP_Propri‚taire) - {9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC} => local_install
          (HP_Propri‚taire) - {ada4b710-8346-4b82-8199-5de2b400a6ae} => reminderfox
          (HP_Propri‚taire) - {c894c08f-799e-4199-a003-eea64e1f43c7} => xulcache
          (HP_Propri‚taire) - {4dce973c-25a5-4657-8e37-6c2a85c24a7e} => contactssidebar
          (HP_Propri‚taire) - {9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC} => local_install

          -----------\\ [..\Internet Explorer\Main]

          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
          "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
          "Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
          "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
          "Search Bar"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
          "SearchMigratedDefaultURL"="https://www.google.com/webhp?gws_rd=ssl{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
          "Start Page"="https://www.msn.com/fr-fr"

          Bonsoir, sitôt dit sitôt fait,à toi de jouer ......merci

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
          "Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
          "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
          "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
          "Start Page"="https://www.msn.com/fr-fr"
          "Search Bar"="http://www.bing.com/spresults.aspx"

          --------------------\\ Recherche d'autres infections

          Aucune autre infection trouvée !

          1 - "C:\ToolBar SD\TB_1.txt" - 08/12/2009|21:15 - Option : [1]

          -----------\\ Fin du rapport a 21:15:36,70
          0
          1. bonsoir

            2009-11-17 20:43:43 ----A---- C:\WINDOWS\system32\rvYJnN8ZMgHb2Pu.vbs
            2009-11-17 11:57:26 ----A---- C:\WINDOWS\system32\2nfeg.vbs
            2009-11-16 21:35:10 ----A---- C:\WINDOWS\system32\kBdqN.vbs
            2009-11-16 15:15:08 ----A---- C:\WINDOWS\system32\jbbYvHWlTpTTf.vbs
            2009-11-16 07:12:23 ----A---- C:\WINDOWS\system32\B7fc0EDUvom9Iv3.vbs
            2009-11-15 12:57:36 ----A---- C:\WINDOWS\system32\32.tmp
            2009-11-15 11:35:31 ----A---- C:\WINDOWS\system32\uOFiDY1.vbs
            2009-11-15 11:32:51 ----A---- C:\WINDOWS\system32\2.tmp
            2009-11-14 18:26:48 ----A---- C:\WINDOWS\system32\97.tmp
            2009-11-14 14:16:52 ----A---- C:\WINDOWS\system32\5fgRRegcWvcxr.vbs
            2009-11-14 14:00:20 ----A---- C:\WINDOWS\system32\zpXSc.vbs
            2009-11-13 09:26:10 ----A---- C:\WINDOWS\system32\bujEiuD.vbs
            2009-11-12 14:37:09 ----A---- C:\WINDOWS\system32\YDtuU.vbs
            2009-11-11 05:09:32 ----A---- C:\WINDOWS\system32\1CF.tmp
            2009-11-07 20:43:32 ----A---- C:\WINDOWS\system32\UKDRxFzyWmpXU.vbs
            2009-11-12 19:58:15 ----D---- C:\WINDOWS\system32\FxsTmp


            Bizarre ces fichiers
            Bob, ce serai bien de rester sur ce sujet
            0
        2. Ok pas de problème, J'ai plus de contact avec lainvi qui ma demander de lancer Toolbar SD.
          0
          1. Allo docteur,j'suis tout seul !!!!!
            0
            1. oui le docteur arrive
              pourrai tu me refaire un RSIT pour que je puisse voir
              pourrai tu héberger le rapport sur ci joint.fr
              0
            2. T'inquiète pas, je ne suis pas H24 sur mon pc.

              Salut nathandre, je trouve aussi ces fichiers bizarres pas d'infos pour le moment. !?? Si tu as quelque chose, passe nous voir. ;)

              Bon on continue :

              * Relance Toolbar-S&D en double-cliquant sur le raccourci.
              * Tape sur "2" puis valide en appuyant sur "Entrée".

              /!\ Ne ferme pas la fenêtre lors de la suppression /!\
              * Un rapport sera généré, poste son contenu ici.

              * NOTE : Si ton Bureau ne réapparait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
              Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."
              Tape explorer puis valide.

              ======================================================================

              Ensuite fais ceci :

              * Télécharge AD-Removeret enregistre le fichier d installation sur ton bureau
              * Double clique sur le fichier d'installation de AD-Remover, le programme s'installera automatiquement.
              * Sous Vista : clic droit sur AD-Remover et sélectionner "Exécuter en tant qu'administrateur"
              * Au menu principal choisi l'option "L" et tape sur [entrée] .
              * Laisse travailler l'outil et ne touche à rien ...
              * Poste le rapport qui apparait à la fin.

              ( le rapport est sauvegardé aussi sous C:\Ad-report.log )

              (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

              Note :

              Process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
              Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
              Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

              ======================================================================

              Je vois que tu as déjà utilisé Navilog1, tu peux me donner le rapport qui se trouve ici :

              C:\cleannavi.txt
              0
          2. Coucou, voila avec RSIT le rapport qui a généré quelque chose avec HijackThis

            Logfile of random's system information tool 1.06 (written by random/random)
            Run by HP_Propriétaire at 2009-12-08 22:36:49
            Microsoft Windows XP Édition familiale Service Pack 3
            System drive C: has 53 GB (75%) free of 71 GB
            Total RAM: 959 MB (53% free)

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 22:36:50, on 08/12/2009
            Platform: Windows XP SP3 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16915)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Windows Defender\MsMpEng.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\Program Files\Alwil Software\Avast4\ashServ.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
            C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
            C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
            C:\Program Files\QuickTime\qttask.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            C:\Program Files\Alwil Software\Avast4\ashDisp.exe
            C:\Program Files\IncrediMail\bin\IMApp.exe
            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\explorer.exe
            C:\Program Files\IncrediMail\bin\IncMail.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\Program Files\CCleaner\CCleaner.exe
            C:\WINDOWS\system32\wuauclt.exe
            F:\Mes documents\Téléchargements\RSIT(3).exe
            C:\Program Files\trend micro\HijackThis\HP_Propriétaire.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
            R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
            O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
            O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
            O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
            O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
            O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1
            O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
            O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
            O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\Shockwave 11\SwHelper_1151601.exe -Update -1151601 -"Mozilla/5.0_(Windows;_U;_Windows_NT_5.1;_fr;_rv:1.9.1.5)_Gecko/20091102_Firefox/3.5.5" -"http://www8.agame.com/..."
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
            O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
            O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
            O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
            O4 - Global Startup: Raccourci vers ashDisp.lnk = C:\Program Files\Alwil Software\Avast4\ashDisp.exe
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
            O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
            O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
            O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
            O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
            O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
            O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
            O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
            O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
            0
            1. Et voila le fichier demandé, excuse j'ai grenouillé pas mal de temps pour le retrouver
              -----------\\ ToolBar S&D 1.2.9 XP/Vista

              Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
              X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) 4 CPU 3.06GHz )
              BIOS : BIOS Date: 06/01/2006 Ver: 08.00.12
              USER : HP_Propriétaire ( Administrator )
              BOOT : Normal boot
              Antivirus : avast! antivirus 4.8.1368 [VPS 091208-1] 4.8.1368 (Activated)
              C:\ (Local Disk) - NTFS - Total:68 Go (Free:51 Go)
              D:\ (Local Disk) - FAT32 - Total:6 Go (Free:0 Go)
              E:\ (CD or DVD)
              F:\ (Local Disk) - NTFS - Total:111 Go (Free:84 Go)

              "C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
              Option : [2] ( 08/12/2009|22:56 )

              -----------\\ Recherche de Fichiers / Dossiers ...

              -----------\\ Extensions

              (HP_Propri‚taire) - {0538E3E3-7E9B-4d49-8831-A227C80A7AD3} => forecastfox
              (HP_Propri‚taire) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
              (HP_Propri‚taire) - {9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC} => local_install
              (HP_Propri‚taire) - {ada4b710-8346-4b82-8199-5de2b400a6ae} => reminderfox
              (HP_Propri‚taire) - {c894c08f-799e-4199-a003-eea64e1f43c7} => xulcache
              (HP_Propri‚taire) - {4dce973c-25a5-4657-8e37-6c2a85c24a7e} => contactssidebar
              (HP_Propri‚taire) - {9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC} => local_install

              -----------\\ [..\Internet Explorer\Main]

              [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
              "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
              "Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
              "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
              "Search Bar"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
              "SearchMigratedDefaultURL"="https://www.google.com/webhp?gws_rd=ssl{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
              "Start Page"="https://www.msn.com/fr-fr"

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
              "Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
              "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
              "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
              "Start Page"="https://www.msn.com/fr-fr/"
              "Search Bar"="http://www.bing.com/spresults.aspx"

              --------------------\\ Recherche d'autres infections

              Aucune autre infection trouvée !

              1 - "C:\ToolBar SD\TB_1.txt" - 08/12/2009|21:15 - Option : [1]
              2 - "C:\ToolBar SD\TB_2.txt" - 08/12/2009|22:46 - Option : [2]
              3 - "C:\ToolBar SD\TB_3.txt" - 08/12/2009|22:57 - Option : [2]

              -----------\\ Fin du rapport a 22:57:13,81
              0
              1. Va falloir rester sur ce sujet et non sur celui-ci, ça va vite devenir pénible de te courir après et en plus tu pollue les désinfections en cours sur les autres sujets....C'est toi qui voit, je veux bien t'aider mais il faut y mettre du tien et faire ce que l'on te demande.

                Si tu souhaite repartir sur de bonnes bases fais ce que je te demande ci-dessous :

                Poste moi les rapport de AD-remover et navilog1 comme demandé précédemment....
                0
                1. Le fichier est du 16/11 veux tu un plus récent ?

                  Fix Navipromo version 4.0.5 commencé le 16/11/2009 21:47:30,93

                  !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                  !!! Postez ce rapport sur le forum pour le faire analyser !!!

                  Outil exécuté depuis C:\Program Files\navilog1

                  Mise à jour le 10.11.2009 à 18h00 par IL-MAFIOSO

                  Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
                  X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) 4 CPU 3.06GHz )
                  BIOS : BIOS Date: 06/01/2006 Ver: 08.00.12
                  USER : HP_Propriétaire ( Administrator )
                  BOOT : Normal boot

                  Antivirus : avast! antivirus 4.8.1351 [VPS 091116-1] 4.8.1351 (Activated)

                  C:\ (Local Disk) - NTFS - Total:68 Go (Free:51 Go)
                  D:\ (Local Disk) - FAT32 - Total:6 Go (Free:0 Go)
                  E:\ (CD or DVD)
                  F:\ (Local Disk) - NTFS - Total:111 Go (Free:86 Go)
                  G:\ (USB)
                  H:\ (USB)
                  I:\ (USB)
                  J:\ (USB)

                  Recherche executée en mode normal

                  [b]Aucune Infection Navipromo/Egdaccess trouvée/b

                  *** Scan terminé 16/11/2009 21:47:52,57 ***
                  0
                  1. non ça pas la peine de me donner un plus récent.

                    Par contre le rapport ad-remover m'intéresse
                    0
                    1. Désolé pour ces disfonctionnement, mais je ne suis pas un as du micro.Bon restons calme et voyon voir,alors le fichier AD REMOVER,je ne sais plus où il est .....HELP
                      0
                      1. .Voilà, je l'ai trouvé.

                        ======= RAPPORT D'AD-REMOVER 1.1.4.6_E | UNIQUEMENT XP/VISTA/7 =======
                        .
                        Mit à jour par C_XX le 07.12.2009 à 21:14
                        Contact: AdRemover.contact@gmail.com
                        Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
                        .
                        Lancé à: 20:51:12, 08/12/2009 | Mode Normal | Option: CLEAN
                        Exécuté de: C:\Program Files\Ad-Remover\
                        Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
                        Nom du PC: NOM-EB85C523610 | Utilisateur actuel: HP_Propri‚taire
                        .
                        ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
                        .

                        C:\DOCUME~1\HP_PRO~1\APPLIC~1\Dealio
                        C:\DOCUME~1\HP_PRO~1\APPLIC~1\EoRezo
                        C:\DOCUME~1\HP_PRO~1\APPLIC~1\ItsLabel
                        C:\DOCUME~1\HP_PRO~1\APPLIC~1\Search Settings
                        C:\Program Files\Dealio Toolbar
                        C:\Program Files\EoRezo
                        C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}
                        C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com
                        C:\Program Files\Search Settings
                        C:\Windows\Installer\243530.msi
                        C:\Windows\Installer\243538.msi

                        (!) -- Fichiers temporaires supprimés.

                        .
                        HKCU\software\appdatalow\software\Dealio
                        HKCU\software\EoRezo
                        HKCU\software\ItsLabel
                        HKCU\software\microsoft\internet explorer\searchscopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}
                        HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440}
                        HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
                        HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}
                        HKCU\software\Search Settings
                        HKLM\Software\Classes\CLSID\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}
                        HKLM\Software\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
                        HKLM\Software\Classes\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}
                        HKLM\software\classes\SearchSettings.BHO
                        HKLM\software\classes\SearchSettings.BHO.1
                        HKLM\Software\Classes\TypeLib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}
                        HKLM\Software\Classes\TypeLib\{CD082CCA-086F-4FD8-8FD7-247A0DBBD1CC}
                        HKLM\software\Dealio
                        HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SearchSettings
                        HKLM\software\microsoft\windows\currentversion\uninstall\{0B1AAC97-8563-41D9-AE47-58E6A222F0E1}
                        HKLM\software\microsoft\windows\currentversion\uninstall\{94C3BB3A-56A1-43DE-A242-8B41F46E97EF}
                        HKLM\software\Search Settings
                        .
                        HKCU\..\Toolbar\ShellBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} (Clé de registre orpheline)
                        HKCU\..\Toolbar\WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} (Clé de registre orpheline)
                        .
                        ============== Scan additionnel ==============
                        .
                        .
                        * Mozilla FireFox Version 3.5.5 [fr] *
                        .
                        Nom du profil: eijaor6z.default (HP_Propri‚taire)
                        .
                        (HP_PRO~1, prefs.js) Browser.download.lastDir, F:\Mes documents
                        (HP_PRO~1, prefs.js) Browser.search.defaultenginename, Google
                        (HP_PRO~1, prefs.js) Browser.search.selectedEngine, Google Language: FR
                        (HP_PRO~1, prefs.js) Browser.startup.homepage, hxxp://www.google.fr
                        .
                        (HP_PRO~1, prefs.js) EFFACE - Browser.search.defaultengine, Ask.com
                        (HP_PRO~1, prefs.js) EFFACE - Browser.search.order.1, Ask.com
                        .
                        .
                        * Internet Explorer Version 7.0.5730.13 *
                        .
                        [HKEY_CURRENT_USER\..\Internet Explorer\Main]
                        .
                        Do404Search: 01000000
                        Local Page: C:\WINDOWS\system32\blank.htm
                        Show_ToolBar: yes
                        Enable Browser Extensions: yes
                        Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                        Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                        Search Bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                        Use Custom Search URL: 1 (0x1)
                        Start Page: hxxp://fr.msn.com/
                        .
                        [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
                        .
                        Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                        Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                        Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                        Delete_Temp_Files_On_Exit: yes
                        Local Page: %SystemRoot%\system32\blank.htm
                        Start Page: hxxp://fr.msn.com/
                        Search Bar: hxxp://search.msn.com/spbasic.htm
                        Use Custom Search URL: 1 (0x1)
                        .
                        [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
                        .
                        Tabs: res://ieframe.dll/tabswelcome.htm
                        .
                        ===================================
                        .
                        4547 Octet(s) - C:\Ad-Report-CLEAN[1].log
                        .
                        0 Fichier(s) - C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp
                        4 Fichier(s) - C:\WINDOWS\Temp
                        .
                        17 Fichier(s) - C:\Program Files\Ad-Remover\BACKUP
                        204 Fichier(s) - C:\Program Files\Ad-Remover\QUARANTINE
                        .
                        Fin à: 20:57:43 | 08/12/2009 - CLEAN[1]
                        .
                        ============== E.O.F ==============
                        .
                        0
                        1. Fais un nouveau rapport avec RSIT, tu n'auras que le rapport log.txt qui va apparaître, c'est normal.

                          Poste son contenu dans ta prochaine réponse.
                          0
                      2. Voilà le bébé....

                        Logfile of random's system information tool 1.06 (written by random/random)
                        Run by HP_Propriétaire at 2009-12-08 23:24:27
                        Microsoft Windows XP Édition familiale Service Pack 3
                        System drive C: has 53 GB (75%) free of 71 GB
                        Total RAM: 959 MB (50% free)

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 23:24:31, on 08/12/2009
                        Platform: Windows XP SP3 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v7.00 (7.00.6000.16915)
                        Boot mode: Normal

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\Ati2evxx.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\Program Files\Windows Defender\MsMpEng.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
                        C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
                        C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\Ati2evxx.exe
                        C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
                        C:\Program Files\QuickTime\qttask.exe
                        C:\WINDOWS\system32\ctfmon.exe
                        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                        C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                        C:\Program Files\IncrediMail\bin\IMApp.exe
                        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\explorer.exe
                        C:\Program Files\IncrediMail\bin\IncMail.exe
                        C:\Program Files\Mozilla Firefox\firefox.exe
                        F:\Mes documents\Téléchargements\RSIT.exe
                        C:\Program Files\trend micro\HijackThis\HP_Propriétaire.exe

                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                        R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/...
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                        R3 - Default URLSearchHook is missing
                        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                        O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
                        O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                        O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
                        O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
                        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                        O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
                        O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1
                        O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                        O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
                        O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\Shockwave 11\SwHelper_1151601.exe -Update -1151601 -"Mozilla/5.0_(Windows;_U;_Windows_NT_5.1;_fr;_rv:1.9.1.5)_Gecko/20091102_Firefox/3.5.5" -"http://www8.agame.com/..."
                        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                        O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
                        O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
                        O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                        O4 - Global Startup: Raccourci vers ashDisp.lnk = C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                        O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                        O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
                        O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
                        O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
                        O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE

                        End of file - 7535 bytes

                        Scheduled tasks folder

                        C:\WINDOWS\tasks\MP Scheduled Scan.job

                        Registry dump

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
                        AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2005-09-23 63136]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
                        SSVHelper Class - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll [2007-09-25 501136]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
                        Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-11-17 256112]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
                        Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll [2009-11-24 764912]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
                        Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll [2009-11-17 458736]

                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                        "QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2009-11-03 282624]
                        "ISUSPM Startup"=C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe [2004-08-09 221184]
                        "Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2009-09-10 1312080]

                        [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
                        "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
                        "IncrediMail"=C:\Program Files\IncrediMail\bin\IncMail.exe [2009-02-02 251264]
                        "updateMgr"=C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe [2005-08-18 307200]
                        "swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-04-02 68856]
                        "WOOKIT"=C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx []

                        [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
                        "Shockwave Updater"=C:\WINDOWS\system32\Adobe\Shockwave 11\SwHelper_1151601.exe [2009-07-31 468408]

                        C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
                        Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE
                        Raccourci vers ashDisp.lnk - C:\Program Files\Alwil Software\Avast4\ashDisp.exe

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
                        C:\WINDOWS\system32\Ati2evxx.dll [2006-02-07 61440]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
                        UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 240128]
                        WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
                        "{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"=C:\PROGRA~1\WINDOW~4\MpShHook.dll [2006-11-03 83224]

                        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]

                        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]

                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                        "dontdisplaylastusername"=0
                        "legalnoticecaption"=
                        "legalnoticetext"=
                        "shutdownwithoutlogon"=1
                        "undockwithoutlogon"=1

                        [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                        "NoDriveTypeAutoRun"=95000000
                        "NoFavoritesMenu"=0

                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                        "HonorAutoRunSetting"=

                        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                        "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                        "C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
                        "C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
                        "C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
                        "C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
                        "C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
                        "C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
                        "C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
                        "C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe"
                        "C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe"
                        "C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
                        "C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
                        "C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe"
                        "C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
                        "C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
                        "C:\Program Files\CyberLink\PowerCinema\PowerCinema.exe"="C:\Program Files\CyberLink\PowerCinema\PowerCinema.exe:*:Enabled:CyberLink PowerCinema"
                        "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"="C:\Program Files\CyberLink\PowerCinema\PCMService.exe:*:Enabled:CyberLink PowerCinema Resident Program"
                        "C:\Program Files\AOL 9.0\waol.exe"="C:\Program Files\AOL 9.0\waol.exe:*:Enabled:AOL France"
                        "C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe"="C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe:*:Enabled:Kaspersky AV Scanner"
                        "C:\Program Files\IncrediMail\bin\ImApp.exe"="C:\Program Files\IncrediMail\bin\ImApp.exe:*:Enabled:IncrediMail"
                        "C:\Program Files\IncrediMail\bin\IncMail.exe"="C:\Program Files\IncrediMail\bin\IncMail.exe:*:Enabled:IncrediMail"
                        "C:\Program Files\IncrediMail\bin\ImpCnt.exe"="C:\Program Files\IncrediMail\bin\ImpCnt.exe:*:Enabled:IncrediMail"
                        "C:\Documents and Settings\HP_Propriétaire\Bureau\LimeWire\LimeWire.exe"="C:\Documents and Settings\HP_Propriétaire\Bureau\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
                        "C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
                        "C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"
                        "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                        "C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Disabled:Firefox"
                        "C:\Documents and Settings\HP_Propriétaire\Local Settings\Temp\ImInstaller\3d_magic_installer.exe"="C:\Documents and Settings\HP_Propriétaire\Local Settings\Temp\ImInstaller\3d_magic_installer.exe:*:Enabled:IncrediMail Installer"
                        "C:\WINDOWS\explorer.exe"="C:\WINDOWS\explorer.exe:*:Enabled:Windows Shell"

                        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                        "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                        "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

                        List of files/folders created in the last 2 months

                        2009-12-08 21:14:57 ----A---- C:\TB.txt
                        2009-12-08 21:14:17 ----D---- C:\ToolBar SD
                        2009-12-08 20:51:09 ----D---- C:\Program Files\Ad-Remover
                        2009-12-07 21:32:59 ----D---- C:\rsit
                        2009-12-07 21:32:59 ----D---- C:\Program Files\trend micro
                        2009-12-06 13:18:18 ----D---- C:\Program Files\SAGEM
                        2009-12-06 13:18:11 ----D---- C:\Documents and Settings\HP_Propriétaire\Application Data\InstallShield
                        2009-12-06 13:18:04 ----D---- C:\Program Files\Securitoo
                        2009-12-06 12:05:24 ----SHD---- C:\Config.Msi
                        2009-12-06 12:03:06 ----D---- C:\Program Files\Microsoft AntiSpyware
                        2009-12-06 12:02:35 ----D---- C:\WINDOWS\Downloaded Installations
                        2009-12-04 20:31:47 ----A---- C:\WINDOWS\system32\WING.DLL
                        2009-11-17 20:54:39 ----D---- C:\Documents and Settings\HP_Propriétaire\Application Data\Malwarebytes
                        2009-11-17 20:54:32 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
                        2009-11-17 20:54:32 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
                        2009-11-17 20:43:43 ----A---- C:\WINDOWS\system32\rvYJnN8ZMgHb2Pu.vbs
                        2009-11-17 11:57:26 ----A---- C:\WINDOWS\system32\2nfeg.vbs
                        2009-11-16 21:45:52 ----A---- C:\cleannavi.txt
                        2009-11-16 21:45:19 ----D---- C:\Program Files\Navilog1
                        2009-11-16 21:35:10 ----A---- C:\WINDOWS\system32\kBdqN.vbs
                        2009-11-16 15:15:08 ----A---- C:\WINDOWS\system32\jbbYvHWlTpTTf.vbs
                        2009-11-16 07:12:23 ----A---- C:\WINDOWS\system32\B7fc0EDUvom9Iv3.vbs
                        2009-11-15 12:57:36 ----A---- C:\WINDOWS\system32\32.tmp
                        2009-11-15 11:35:31 ----A---- C:\WINDOWS\system32\uOFiDY1.vbs
                        2009-11-15 11:32:51 ----A---- C:\WINDOWS\system32\2.tmp
                        2009-11-14 18:26:48 ----A---- C:\WINDOWS\system32\97.tmp
                        2009-11-14 14:16:52 ----A---- C:\WINDOWS\system32\5fgRRegcWvcxr.vbs
                        2009-11-14 14:00:20 ----A---- C:\WINDOWS\system32\zpXSc.vbs
                        2009-11-13 09:26:10 ----A---- C:\WINDOWS\system32\bujEiuD.vbs
                        2009-11-12 14:37:09 ----A---- C:\WINDOWS\system32\YDtuU.vbs
                        2009-11-11 05:09:32 ----A---- C:\WINDOWS\system32\1CF.tmp
                        2009-11-07 20:43:32 ----A---- C:\WINDOWS\system32\UKDRxFzyWmpXU.vbs
                        2009-11-03 17:43:49 ----D---- C:\Program Files\FreeTime
                        2009-11-03 10:41:09 ----D---- C:\Program Files\QuickTime
                        2009-10-24 16:59:15 ----D---- C:\Documents and Settings\HP_Propriétaire\Application Data\HouseCall 6.6
                        2009-10-11 13:56:24 ----A---- C:\WINDOWS\system32\WMAFile.dll
                        2009-10-11 13:56:24 ----A---- C:\WINDOWS\system32\AudPlayer.dll
                        2009-10-11 13:56:24 ----A---- C:\WINDOWS\system32\AudioVisu.dll
                        2009-10-11 13:56:24 ----A---- C:\WINDOWS\system32\AudioRecord.dll
                        2009-10-11 13:56:24 ----A---- C:\WINDOWS\system32\AudioInfos.dll
                        2009-10-11 13:56:24 ----A---- C:\WINDOWS\system32\AudFile.dll
                        2009-10-11 13:56:24 ----A---- C:\WINDOWS\system32\AudDisplay.dll
                        2009-10-11 13:56:24 ----A---- C:\WINDOWS\system32\AudDesign.dll
                        2009-10-11 13:56:23 ----A---- C:\WINDOWS\system32\TABCTFR.DLL
                        2009-10-11 13:56:23 ----A---- C:\WINDOWS\system32\inetfr.DLL
                        2009-10-11 13:56:22 ----D---- C:\Program Files\Free Audio Pack
                        2009-10-11 13:56:22 ----A---- C:\WINDOWS\system32\MSCMCFR.DLL
                        2009-10-11 13:56:22 ----A---- C:\WINDOWS\system32\Mscc2fr.dll

                        List of files/folders modified in the last 2 months

                        2009-12-08 23:24:27 ----D---- C:\WINDOWS\Temp
                        2009-12-08 22:58:14 ----D---- C:\Program Files\Mozilla Firefox
                        2009-12-08 22:46:00 ----D---- C:\WINDOWS\Prefetch
                        2009-12-08 22:29:10 ----D---- C:\Documents and Settings\HP_Propriétaire\Application Data\OpenOffice.org2
                        2009-12-08 22:16:28 ----AD---- C:\WINDOWS
                        2009-12-08 20:57:09 ----SHD---- C:\WINDOWS\Installer
                        2009-12-08 20:56:32 ----D---- C:\Program Files
                        2009-12-08 08:08:31 ----D---- C:\WINDOWS\Tasks
                        2009-12-07 22:29:32 ----N---- C:\WINDOWS\SchedLgU.Txt
                        2009-12-07 17:16:31 ----D---- C:\Program Files\Wanadoo
                        2009-12-07 17:16:03 ----D---- C:\Program Files\CCleaner
                        2009-12-07 17:15:54 ----D---- C:\WINDOWS\system32
                        2009-12-07 17:12:38 ----D---- C:\WINDOWS\system32\CatRoot2
                        2009-12-07 16:44:39 ----D---- C:\WINDOWS\inf
                        2009-12-06 14:01:25 ----D---- C:\WINDOWS\system32\LogFiles
                        2009-12-06 13:18:17 ----HD---- C:\Program Files\InstallShield Installation Information
                        2009-12-04 20:31:47 ----D---- C:\WINDOWS\system
                        2009-12-03 21:16:41 ----D---- C:\Documents and Settings\HP_Propriétaire\Application Data\LimeWire
                        2009-11-25 18:01:09 ----D---- C:\WINDOWS\system32\dllcache
                        2009-11-25 18:00:31 ----HD---- C:\WINDOWS\$hf_mig$
                        2009-11-25 18:00:22 ----D---- C:\WINDOWS\WinSxS
                        2009-11-25 00:54:29 ----A---- C:\WINDOWS\system32\aswBoot.exe
                        2009-11-17 20:54:34 ----D---- C:\WINDOWS\system32\drivers
                        2009-11-17 19:58:02 ----D---- C:\Program Files\Google
                        2009-11-17 19:57:03 ----D---- C:\Documents and Settings\HP_Propriétaire\Application Data\Google
                        2009-11-17 19:43:07 ----D---- C:\Documents and Settings\All Users\Application Data\Google
                        2009-11-14 16:28:26 ----D---- C:\Documents and Settings\HP_Propriétaire\Application Data\Microsoft
                        2009-11-12 22:07:22 ----D---- C:\WINDOWS\Debug
                        2009-11-12 19:58:15 ----D---- C:\WINDOWS\system32\FxsTmp
                        2009-11-09 20:10:42 ----D---- C:\Python22
                        2009-11-09 19:51:23 ----D---- C:\Program Files\Fichiers communs\Real
                        2009-11-09 19:51:21 ----D---- C:\Documents and Settings\HP_Propriétaire\Application Data\Real
                        2009-11-09 19:51:15 ----D---- C:\Program Files\Fichiers communs
                        2009-11-09 12:43:24 ----D---- C:\Program Files\Mozilla Thunderbird
                        2009-11-07 08:40:23 ----D---- C:\Program Files\Mindscape
                        2009-11-07 08:36:34 ----D---- C:\WINDOWS\Downloaded Program Files
                        2009-11-05 18:36:21 ----A---- C:\WINDOWS\system32\MRT.exe
                        2009-11-04 08:18:44 ----D---- C:\WINDOWS\ie7updates
                        2009-11-03 10:43:21 ----D---- C:\WINDOWS\system32\fr-fr
                        2009-11-03 10:43:21 ----D---- C:\Program Files\Internet Explorer
                        2009-11-02 20:42:06 ----N---- C:\WINDOWS\system32\MpSigStub.exe
                        2009-10-28 16:07:15 ----N---- C:\WINDOWS\system32\tzchange.exe
                        2009-10-25 10:59:13 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
                        2009-10-24 17:06:39 ----A---- C:\WINDOWS\KA.INI
                        2009-10-21 05:07:57 ----A---- C:\WINDOWS\system32\mshtml.dll
                        2009-10-20 16:21:00 ----D---- C:\WINDOWS\system32\Macromed

                        ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

                        R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2009-11-25 27408]
                        R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2009-11-25 114768]
                        R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2009-11-25 48560]
                        R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40576]
                        R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-11-25 20560]
                        R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2009-11-25 94160]
                        R3 Arp1394;Protocole client ARP 1394; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
                        R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2009-11-25 23120]
                        R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2006-02-07 1480704]
                        R3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
                        R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-03-08 4246016]
                        R3 NIC1394;Pilote réseau 1394; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
                        R3 Ps2;PS2; C:\WINDOWS\system32\DRIVERS\PS2.sys [2005-12-12 19072]
                        R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2006-01-18 80512]
                        R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
                        R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
                        R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
                        R3 usbohci;Pilote miniport de contrôleur hôte ouvert USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
                        R3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
                        R3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
                        S1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14720]
                        S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
                        S3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
                        S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2005-10-27 49664]
                        S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2005-10-27 16496]
                        S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-10-27 21568]
                        S3 ltmodem5;LT Modem Driver; C:\WINDOWS\system32\DRIVERS\ltmdmnt.sys [2004-08-03 607452]
                        S3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
                        S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
                        S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
                        S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
                        S3 PCAMPR5;PCAMPR5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\PCAMPR5.SYS []
                        S3 PCANDIS5;PCANDIS5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\PCANDIS5.SYS []
                        S3 PCD5SRVC{8A863ACB-F5F6CC6A-05010003};PCD5SRVC{8A863ACB-F5F6CC6A-05010003} - PCDR Kernel Mode Service Helper Driver; \??\C:\PROGRA~1\PC-DOC~1\PCD5SRVC.pkms []
                        S3 rtl8139;Pilote NT de carte Realtek PCI Fast Ethernet à base RTL8139(A/B/C); C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
                        S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
                        S3 SQTECH905C;DualCamera; C:\WINDOWS\System32\Drivers\Capt905c.sys [2007-08-21 32512]
                        S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
                        S3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
                        S3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
                        S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
                        S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
                        S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

                        ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

                        R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-11-25 18752]
                        R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2006-02-07 405504]
                        R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-11-25 138680]
                        R2 CLCapSvc;CyberLink Background Capture Service (CBCS); C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe [2006-02-24 266338]
                        R2 CLSched;CyberLink Task Scheduler (CTS); C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe [2006-02-24 114784]
                        R2 CyberLink Media Library Service;CyberLink Media Library Service; C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe [2006-02-24 1073152]
                        R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe [2006-03-23 73728]
                        R2 WinDefend;Windows Defender; C:\Program Files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
                        R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-11-25 254040]
                        R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-11-25 352920]
                        S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE [2007-08-09 73728]
                        S3 aspnet_state;Service d'état ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
                        S3 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-14 268800]
                        S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-11-17 182768]
                        S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
                        S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]
                        S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]

                        -----------------EOF-----------------
                        0
                        1. Bonsoir lainvi, excuse mais demain, je me lève tôt, boulot oblige, bonne soirée à toi, merci pour ton aide et a demain soir vers 20h30 si tu veux.Merci de me consacrer du temps.BYE
                          0
                          1. Bonsoi lainvi, j'espère que je ne te dérange pas trop, je t'ai envoyé le rapport demandé comme convenu,j'attends de tes nouvelles
                            0
                            1. bonsoir bob
                              pour avancer lainvi
                              C:\WINDOWS\system32\rvYJnN8ZMgHb2Pu.vbs
                              C:\WINDOWS\system32\2nfeg.vbs
                              C:\WINDOWS\system32\kBdqN.vbs


                              pourrai tu analyser ces fichiers sur le site Virus Total
                              0
                          2. Bonsoir nat,j'ai essayé de contacter lainvi mais je ne sais pas où il est.Concernant les toolbars qu trainait dans mon pc, j'ai éliminer dealio toobar par executer.....regedit.......car autrement j'y avais pas accès.Puis sur un conseil d'un pote qui connait l'informatique(plus que moi),je suis en train de scanner mon pc avec le lien ci après sur ses conseils et là ça rame pas mal

                            http://www.microsoft.com/downloads/details.aspx?FamilyId=AD724AE0-E72D-4F54-9AB3-75B8EB148356&displaylang=fr

                            Page officielle MicroSoft

                            Autrement je scanne et des que c'est fini,je regarde ce que tu me demandes.Si je ne répond pas, c'est que certainement le scan n'est pas fini.Merci et à+.Je me sentais un peu seul face à mon pb non résolu.......
                            0
                            1. Oups le lien a disparu, désolé, c'est :

                              http://www.microsoft.com/downloads/details.aspx?FamilyId=AD724AE0-E72D-4F54-9AB3-75B8EB148356&displaylang=fr

                              Voilà,;@+
                              0
                              1. on t'a conseillé cela ?
                                0
                            2. Bonsoir nat, ouais on m'a dit fait le, tu ne risques rien de le faire.Néanmoins, comment faire pour envoyer les fichiers sources sur virus total?J'ai remarqué également qu'ils ont un fichier exe qui scan tout.
                              @+
                              0
                              1. bonsoir
                                quand tu es sur virus total, tu cliques sur parcourir
                                dans la fenêtre qui s'ouvre, tu recherches les fichiers, et tu cliques sur ouvrir
                                clique sur envoyer le fichier
                                0
                              2. @Utilisateur anonymeBingo, du trojan,

                                oMrAPeVHzwUii.vbs_-Trojan.VBS.Tra reçu le 2009.12.01 10:51:47 (UTC)
                                Situation actuelle: terminé

                                Fichier oMrAPeVHzwUii.vbs_-Trojan.VBS.Tra reçu le 2009.12.01 10:51:47 (UTC)
                                Situation actuelle: terminé

                                Fichier oMrAPeVHzwUii.vbs_-Trojan.VBS.Tra reçu le 2009.12.01 10:51:47 (UTC)
                                Situation actuelle: terminé

                                et il me semble que j'en ai vu un autre du style :

                                Fichier oMrAPeVHzwUii.vbs_-Trojan.VBS.Tra reçu le 2009.12.01 10:51:47 (UTC)
                                Situation actuelle: terminé

                                Bref, il me semble qu'il y en a d'autres, que faire? Merci NAT
                                0
                              3. @Utilisateur anonymeSalut à tous les deux,

                                merci nathandre d'avoir pris la suite, je n'étais pas dispo, je te laisse finir tu as le sujet bien en main, je n'attendais pas moins de toi.

                                Toutes mes excuses Bob01. ;)

                                Bonne chasse !!
                                0
                            3. j'avais le meme probleme et je viens de trouver la solution
                              -desinstalle firefox (dans le quel je pense tu as la google toolbar)
                              -redemarre
                              -sers toi de internet explorer et tu verras que tu n'es plus redirigé
                              -reinstalle firefox depuis là (je sais c'est pas le site officiel)
                              https://www.01net.com/telecharger/windows/Internet/navigateur/fiches/25711.html
                              -et la c'est le bonheur , mais je n'ai pas reessayer de remettre la barre d'outil google

                              dis moi si c'est bon pour toi
                              0