Virus.

Résolu
Bonjour, bonsoir,

cela fait un petit temps que je me dis que je dois poster sur le forum pour avoir la réponse, mais voilà, je repousse à chaque fois... La je me lance!

Donc voilà le topo, depuis un certain temps, lorsque je lance une recherche sur un moteur de recherche -google pour ne pas le citer- je tombe (on va dire une fois sur 10) sur une page où il est marqué "oops" avec une loupe et un message en anglais qui est le suivant:

"The page you tried to access does not exist on this server. This page may not exist due to the following reasons:

You are the owner of this web site and you have not uploaded (or incorrectly uploaded) your web site. For information on uploading your web site using FTP client software or web design software, click here for FTP Upload Information.

The URL that you have entered in your browser is incorrect. Please re-enter the URL and try again.

The Link that you clicked on incorrectly points to this page. Please contact the owner of this web site to inform them of this situation. "


Il va sans dire que cela est assez... Contraignant. Mais ce n'est pas tout, des fois, je suis sur internet et cette même page s'ouvre (et cette fois sans raison). J'ai aussi une autre page qui s'ouvre de temps de temps (je ne sais pas si le problème est lié). Mais j'ai essayé de bloqué cette dernière avec le logiciel pour bloquer les pages ( filtre parental) la seule différence c'est que la page est toute rouge...

Donc voilà, cela fait plusieurs mosi que ça dure et ça commence à m'énerver....

J'ai évidemment passer maintes fois des anti-virus, anti-spywar etc,... Sans succès.

Je me résigne donc,... Et j'implore votre aide...

Merci d'avance,

Loïc.

Ps: J'ai fait un screen de la page, je le donnerai si vous me le demander...
Configuration: Windows Vista Internet Explorer 7.0

50 réponses

Résumé de la discussion

Un utilisateur signale qu'une recherche sur Internet conduit parfois à une page affichant 'oops' avec une loupe et un message indiquant que la page n'existe pas sur le serveur. Plusieurs solutions proposées incluent l'utilisation d'outils de nettoyage système et l'exécution en mode sans échec, ainsi que la mise à jour de Java et le diagnostic de conflits entre antivirus. Parmi les réponses, certains recommandent RSIT et HijackThis pour générer des rapports et identifier des malwares, tandis que d'autres suggèrent d'écraser les infections en redémarrant en mode destruction. Le fil ne conclut pas sur une résolution, mais plusieurs intervenants insistent sur l'importance d'éviter les modifications manuelles risquées et de collecter les rapports pour un dépannage ultérieur.

Bobot (l’IA à votre service)
  1. Bonsoir,

    Pour voir cela:

    Télécharge RSIT (de random/random) sur le bureau :

    - Double clique sur RSIT.exe qui est sur le bureau
    - Clique sur "Continue" dans la fenêtre
    - RSIT téléchargera HijackThis si il n’est pas présent où détecté, alors il faudra accepter la licence
    - Poste le contenu de log.txt plus info.txt (réduit ds la barre de taches) à la fin de l’analyse .

    Les rapports sont dans le dossier ici C:\rsit
    a+

    1
    1. Si j'ai bien compris...

      Voici le log:Logfile of random's system information tool 1.06 (written by random/random)
      Run by Loic at 2009-12-15 21:27:03
      Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
      System drive C: has 65 GB (24%) free of 270 GB
      Total RAM: 3066 MB (51% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 21:27:19, on 15/12/2009
      Platform: Windows Vista SP2 (WinNT 6.00.1906)
      MSIE: Internet Explorer v8.00 (8.00.6001.18865)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\taskeng.exe
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Windows\RtHDVCpl.exe
      C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
      C:\Program Files\HomeCinema\PowerDVD\PDVDServ.exe
      C:\Windows\tsnp2uvc.exe
      C:\Program Files\EgisTec\VITAKEY\PdtWzd.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      C:\Program Files\Common Files\Real\Update_OB\realsched.exe
      C:\Program Files\Winamp\winampa.exe
      C:\Windows\WindowsMobile\wmdSync.exe
      C:\Program Files\FreePDF_XP\fpassist.exe
      C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
      C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
      C:\Windows\system32\wbem\unsecapp.exe
      C:\Windows\System32\rundll32.exe
      C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe
      C:\Program Files\Microsoft Security Essentials\msseces.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Windows\ehome\ehtray.exe
      C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Users\Loic\AppData\Local\TempImages\ISPR108.exe
      C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
      C:\Program Files\Electronic Arts\EADM\Core.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe
      C:\Windows\ehome\ehmsas.exe
      C:\Program Files\EgisTec\VITAKEY\PwdBank.exe
      C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlNotifyIcon.exe
      C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
      C:\Windows\System32\mobsync.exe
      C:\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe
      C:\Program Files\Windows Live\Contacts\wlcomm.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Windows\system32\conime.exe
      C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
      C:\Windows\system32\Macromed\Flash\FlashUtil10d.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Users\Loic\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IALOPSUG\RSIT[1].exe
      C:\Program Files\trend micro\Loic.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.aldi.com/
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?pc=mssh&form=msshhp&ocid=onepro&homepage=http%3a%2f%2fwww.google.be%2f
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.aldi.com/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://troner.net/
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.thepickapp.com/search.htm
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      O1 - Hosts: ::1 localhost
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
      O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
      O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
      O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
      O4 - HKLM\..\Run: [mwlDaemon] C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
      O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\HomeCinema\PowerDVD\PDVDServ.exe"
      O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\HomeCinema\PowerDVD\Language\Language.exe"
      O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\HomeCinema\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\HomeCinema\YouCam" update "Software\CyberLink\YouCam\2.0"
      O4 - HKLM\..\Run: [tsnp2uvc] C:\Windows\tsnp2uvc.exe
      O4 - HKLM\..\Run: [VitaKeyPdtWzd] C:\Program Files\EgisTec\VITAKEY\PdtWzd.exe
      O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
      O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\GoogleEULA\EULALauncher.exe
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
      O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
      O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
      O4 - HKLM\..\Run: [FreePDF Assistant] C:\Program Files\FreePDF_XP\fpassist.exe
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
      O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
      O4 - HKLM\..\Run: [Skytel] Skytel.exe
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [MobileConnect] %programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
      O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
      O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
      O4 - HKCU\..\Run: [IEPR] C:\Users\Loic\AppData\Local\TempImages\ISPR108.exe
      O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
      O4 - HKCU\..\Run: [Google Update] "C:\Users\Loic\AppData\Local\Google\Update\GoogleUpdate.exe" /c
      O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
      O4 - Global Startup: McAfee Security Scan.lnk = ?
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
      O13 - Gopher Prefix:
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/VistaMSNPUpldfr-be.cab
      O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
      O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
      O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
      O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
      O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
      O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
      O23 - Service: Service Google Update (gupdate1ca2381a0949663) (gupdate1ca2381a0949663) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: EgisTec Service (IGBASVC) - Unknown owner - C:\Program Files\EgisTec\VITAKEY\BASVC.exe
      O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
      O23 - Service: MyWinLocker Service (MWLService) - EgisTec Inc. - C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe
      O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
      O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
      O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
      O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
      O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe
      O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
      O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
      O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
      O23 - Service: Vodafone Mobile Connect Service (VMCService) - Vodafone - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
      0
      1. • Télécharge USBFIX http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe­

        (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptibles d'avoir été infectés sans les ouvrir

        • Double clic sur le raccourci UsbFix présent sur ton bureau .

        • Au menu principal choisis l'option " F " pour français et tape sur [entrée] .

        • Au second menu Choisis l'option " 1 " (recherche) et tape sur [entrée]

        • Laisse travailler l'outil.

        • Ensuite post le rapport UsbFix.txt qui apparaitra.

        • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

        ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

        • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
        Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
        Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

        a+

        0
        1. Voilà :)

          ############################## | UsbFix V6.063 |

          User : Loic (Administrateurs) # PC-DE-LOIC
          Update on 14/12/2009 by Chiquitine29, C_XX & Chimay8
          Start at: 14:00:11 | 16/12/2009
          Website : http://pagesperso-orange.fr/NosTools/index.html
          Contact : FindyKill.Contact@gmail.com

          Intel(R) Core(TM)2 Duo CPU T5800 @ 2.00GHz
          Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
          Internet Explorer 8.0.6001.18865
          Windows Firewall Status : Enabled

          C:\ -> Disque fixe local # 263,92 Go (65,81 Go free) [BOOT] # NTFS
          D:\ -> Disque fixe local # 34,16 Go (19,04 Go free) [RECOVER] # FAT32
          E:\ -> Disque CD-ROM
          F:\ -> Disque amovible
          G:\ -> Disque amovible # 1,91 Go (1,53 Go free) # FAT

          ############################## | Processus actifs |

          C:\Windows\System32\smss.exe 444
          C:\Windows\system32\csrss.exe 592
          C:\Windows\system32\wininit.exe 644
          C:\Windows\system32\csrss.exe 656
          C:\Windows\system32\services.exe 692
          C:\Windows\system32\lsass.exe 704
          C:\Windows\system32\lsm.exe 712
          C:\Windows\system32\svchost.exe 864
          C:\Windows\system32\nvvsvc.exe 932
          C:\Windows\system32\svchost.exe 960
          c:\Program Files\Microsoft Security Essentials\MsMpEng.exe 1004
          C:\Windows\System32\svchost.exe 1128
          C:\Windows\System32\svchost.exe 1176
          C:\Windows\system32\svchost.exe 1196
          C:\Windows\system32\svchost.exe 1292
          C:\Windows\system32\SLsvc.exe 1308
          C:\Windows\system32\svchost.exe 1356
          C:\Windows\system32\winlogon.exe 1464
          C:\Windows\system32\svchost.exe 1524
          C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe 1680
          C:\Windows\system32\rundll32.exe 1760
          C:\Program Files\EgisTec\VITAKEY\CompPtcVUI.exe 1820
          C:\Windows\System32\spoolsv.exe 1908
          C:\Program Files\Avira\AntiVir Desktop\sched.exe 1944
          C:\Windows\system32\svchost.exe 1964
          C:\Program Files\Avira\AntiVir Desktop\avguard.exe 1216
          C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 660
          C:\Program Files\Bonjour\mDNSResponder.exe 1420
          C:\Windows\system32\svchost.exe 1536
          C:\Program Files\EgisTec\VITAKEY\BASVC.exe 1928
          C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe 2152
          C:\Program Files\EgisTec\MyWinLocker 3\x86\MWLService.exe 2180
          C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe 2200
          C:\Windows\system32\IoctlSvc.exe 2300
          C:\Windows\system32\svchost.exe 2312
          C:\Windows\system32\PSIService.exe 2336
          C:\Program Files\CyberLink\Shared Files\RichVideo.exe 2360
          C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 2388
          C:\Windows\system32\svchost.exe 2480
          C:\Windows\System32\svchost.exe 2548
          C:\Windows\system32\SearchIndexer.exe 2568
          C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe 2620
          C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe 2796
          C:\Windows\system32\wbem\wmiprvse.exe 2964
          C:\Windows\system32\WUDFHost.exe 3004
          C:\Windows\system32\wbem\unsecapp.exe 3240
          C:\Windows\system32\wbem\wmiprvse.exe 3256
          C:\Windows\system32\taskeng.exe 3364
          C:\Windows\system32\Dwm.exe 3648
          C:\Windows\Explorer.EXE 1436
          C:\Windows\system32\taskeng.exe 3900
          C:\Windows\RtHDVCpl.exe 2876
          C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe 3440
          C:\Program Files\HomeCinema\PowerDVD\PDVDServ.exe 3620
          C:\Windows\tsnp2uvc.exe 2128
          C:\Program Files\EgisTec\VITAKEY\PdtWzd.exe 2120
          C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe 4040
          C:\Program Files\Windows Media Player\wmpnscfg.exe 2616
          C:\Program Files\Common Files\Real\Update_OB\realsched.exe 2712
          C:\Program Files\Windows Media Player\wmpnetwk.exe 2816
          C:\Program Files\Winamp\winampa.exe 3944
          C:\Windows\WindowsMobile\wmdSync.exe 2852
          C:\Program Files\FreePDF_XP\fpassist.exe 3020
          C:\Program Files\Avira\AntiVir Desktop\avgnt.exe 476
          C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe 3584
          C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe 3452
          C:\Windows\system32\wbem\unsecapp.exe 3724
          C:\Windows\System32\rundll32.exe 1332
          C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe 3064
          C:\Program Files\Microsoft Security Essentials\msseces.exe 3572
          C:\Program Files\iTunes\iTunesHelper.exe 3052
          C:\Program Files\Windows Sidebar\sidebar.exe 1788
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe 900
          C:\Windows\ehome\ehtray.exe 3128
          C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe 1656
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe 3976
          C:\Users\Loic\AppData\Local\TempImages\ISPR108.exe 2960
          C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe 2012
          C:\Program Files\Electronic Arts\EADM\Core.exe 1936
          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe 2268
          C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe 4112
          C:\Windows\system32\svchost.exe 4372
          C:\Windows\ehome\ehmsas.exe 4808
          C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlNotifyIcon.exe 5232
          C:\Program Files\EgisTec\VITAKEY\PwdBank.exe 5628
          C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe 5712
          C:\Program Files\iPod\bin\iPodService.exe 5852
          C:\Program Files\Windows Live\Contacts\wlcomm.exe 2504
          C:\Program Files\Internet Explorer\iexplore.exe 5880
          C:\Program Files\Internet Explorer\iexplore.exe 3884
          C:\Windows\system32\conime.exe 5972
          C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe 5128
          C:\Windows\system32\Macromed\Flash\FlashUtil10d.exe 1696
          C:\Program Files\Internet Explorer\iexplore.exe 1096
          C:\Program Files\Internet Explorer\iexplore.exe 2496
          C:\Windows\system32\taskeng.exe 4172

          ################## | Fichiers # Dossiers infectieux |

          ################## | Registre # Clés infectieuses |

          ################## | Registre # Mountpoints2 |

          HKCU\..\..\Explorer\MountPoints2\G
          shell\AutoRun\command =G:\setup_vmc_lite.exe /checkApplicationPresence

          HKCU\..\..\Explorer\MountPoints2\{0697ca39-81a4-11de-82cc-001f160aff8e}
          shell\AutoRun\command =G:\setup_vmc_lite.exe /checkApplicationPresence

          HKCU\..\..\Explorer\MountPoints2\{1ea73536-dcd6-11de-80b6-001f160aff8e}
          shell\AutoRun\command =G:\w9uxx92.exe
          shell\open\Command =G:\w9uxx92.exe

          HKCU\..\..\Explorer\MountPoints2\{7691030c-803e-11de-8e6c-001f160aff8e}
          shell\AutoRun\command =G:\setup_vmc_lite.exe /checkApplicationPresence

          HKCU\..\..\Explorer\MountPoints2\{9fef053b-4b97-11de-957d-001f160aff8e}
          shell\Auto\command =setup.exe
          shell\AutoRun\command =C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL setup.exe

          HKCU\..\..\Explorer\MountPoints2\{a763d1b9-8f03-11de-9617-00a0c6000000}
          shell\AutoRun\command =G:\setup_vmc_lite.exe /checkApplicationPresence

          HKCU\..\..\Explorer\MountPoints2\{b2236ebc-8032-11de-9e20-001f160aff8e}
          shell\AutoRun\command =H:\setup_vmc_lite.exe /checkApplicationPresence

          HKCU\..\..\Explorer\MountPoints2\{b2236ec7-8032-11de-9e20-001f160aff8e}
          shell\AutoRun\command =G:\setup_vmc_lite.exe /checkApplicationPresence

          HKCU\..\..\Explorer\MountPoints2\{c557242e-120b-11de-ad2a-001f160aff8e}
          shell\AutoRun\command =G:\LaunchU3.exe -a

          ################## | Cracks / Keygens / Serials |

          "C:\Loic\Musique Ordi\Musique papa\incomming\FTP.Expert.v3.80.2.FR.Incl-Keygen\ftpexpert3.exe"
          14/02/2008 05:55 |Size 5571016 |Crc32 59621086 |Md5 346ba07c89db7fd18c38403b979523dc

          "C:\Loic\Application non scanner\Winrar_3.71_crack_pifoman.zip"
          -> Contain : Crack.exe 23919 DFLT-X 9% 21712 29-09-2007 17:27:14 f68d6cf5

          "C:\Loic\Musique Ordi\Musique papa\incomming\FTP Expert 3.50.0 FR + keygen + manuel + tutoriel.rar"
          -> contain : FTP Expert 3.50.0 FR + keygen + manuel + tutoriel\ftpexpert3.exe

          "C:\Loic\Musique Ordi\Musique papa\incomming\FTP Expert 3.50.0 FR + keygen + manuel + tutoriel.rar"
          -> contain : FTP Expert 3.50.0 FR + keygen + manuel + tutoriel\FTPExpert3_Keygen.exe

          "C:\Loic\Musique Ordi\Musique papa\incomming\FTP Expert 3.50.0 FR + keygen + manuel + tutoriel.rar"
          -> contain : FTP Expert 3.50.0 FR + keygen + manuel + tutoriel\setup.exe

          "C:\Loic\Musique Ordi\Musique papa\incomming\FTP.Expert.v3.80.2.FR.Incl-Keygen.rar"
          -> contain : ftpexpert3.exe

          "C:\Loic\Musique Ordi\Musique papa\incomming\FTP.Expert.v3.80.2.FR.Incl-Keygen.rar"
          -> contain : Keygen\Keygen FTP Expert 3.xx.exe

          ################## | ! Fin du rapport # UsbFix V6.063 ! |

          Merci beaucoup de m'aider :)
          0
      2. (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d avoir été infectés sans les ouvrir
        • Double clic sur le raccourci UsbFix présent sur ton bureau

        • Au menu principal choisis l'option " F " pour français et tape sur [entrée] .

        • Au second menu Choisis l'option " 2 " ( Suppression ) et tape sur [entrée]

        • Ton bureau disparaitra et le pc redémarrera .

        • Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.

        • Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .

        • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

        ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

        a+
        0
        1. ############################## | UsbFix V6.064 |

          User : Loic (Administrateurs) # PC-DE-LOIC
          Update on 16/12/2009 by Chiquitine29, C_XX & Chimay8
          Start at: 16:59:00 | 16/12/2009
          Website : http://pagesperso-orange.fr/NosTools/index.html
          Contact : FindyKill.Contact@gmail.com

          Intel(R) Core(TM)2 Duo CPU T5800 @ 2.00GHz
          Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
          Internet Explorer 8.0.6001.18865
          Windows Firewall Status : Enabled

          C:\ -> Disque fixe local # 263,92 Go (62,62 Go free) [BOOT] # NTFS
          D:\ -> Disque fixe local # 34,16 Go (19,04 Go free) [RECOVER] # FAT32
          E:\ -> Disque CD-ROM
          F:\ -> Disque amovible
          G:\ -> Disque amovible # 1,91 Go (1,53 Go free) # FAT
          J:\ -> Disque amovible

          ############################## | Processus actifs |

          C:\Windows\System32\smss.exe 500
          C:\Windows\system32\csrss.exe 600
          C:\Windows\system32\csrss.exe 652
          C:\Windows\system32\wininit.exe 660
          C:\Windows\system32\services.exe 704
          C:\Windows\system32\lsass.exe 728
          C:\Windows\system32\lsm.exe 740
          C:\Windows\system32\winlogon.exe 768
          C:\Windows\system32\svchost.exe 916
          C:\Windows\system32\nvvsvc.exe 980
          C:\Windows\system32\svchost.exe 1008
          c:\Program Files\Microsoft Security Essentials\MsMpEng.exe 1044
          C:\Windows\System32\svchost.exe 1208
          C:\Windows\System32\svchost.exe 1264
          C:\Windows\system32\svchost.exe 1300
          C:\Windows\system32\svchost.exe 1412
          C:\Windows\system32\SLsvc.exe 1428
          C:\Windows\system32\rundll32.exe 1500
          C:\Windows\system32\svchost.exe 1524
          C:\Windows\system32\svchost.exe 1672
          C:\Program Files\EgisTec\VITAKEY\CompPtcVUI.exe 1680
          C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe 1824
          C:\Windows\System32\spoolsv.exe 380
          C:\Program Files\Avira\AntiVir Desktop\sched.exe 544
          C:\Windows\system32\svchost.exe 556
          C:\Program Files\Avira\AntiVir Desktop\avguard.exe 1944
          C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 1956
          C:\Program Files\Bonjour\mDNSResponder.exe 1976
          C:\Windows\system32\svchost.exe 1988
          C:\Program Files\EgisTec\VITAKEY\BASVC.exe 2136
          C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe 2176
          C:\Program Files\EgisTec\MyWinLocker 3\x86\MWLService.exe 2216
          C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe 2232
          C:\Windows\system32\IoctlSvc.exe 2276
          C:\Windows\system32\svchost.exe 2288
          C:\Windows\system32\PSIService.exe 2328
          C:\Program Files\CyberLink\Shared Files\RichVideo.exe 2372
          C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 2424
          C:\Windows\system32\svchost.exe 2484
          C:\Windows\System32\svchost.exe 2540
          C:\Windows\system32\SearchIndexer.exe 2572
          C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe 2788
          C:\Windows\system32\wbem\wmiprvse.exe 3032
          C:\Windows\system32\wbem\wmiprvse.exe 3440
          C:\Windows\system32\wbem\unsecapp.exe 3460
          C:\Windows\system32\taskeng.exe 3104
          C:\Windows\system32\svchost.exe 3944
          C:\Program Files\Windows Media Player\wmpnetwk.exe 3988
          C:\Windows\system32\WUDFHost.exe 3892
          C:\Windows\system32\Dwm.exe 716
          C:\Windows\system32\taskeng.exe 3756
          C:\Windows\Explorer.EXE 3964
          C:\Windows\system32\runonce.exe 2676
          C:\Windows\system32\conime.exe 904
          C:\Windows\system32\PresentationSettings.exe 3860

          ################## | Fichiers # Dossiers infectieux |

          Supprimé ! C:\$Recycle.Bin\S-1-5-20
          Supprimé ! C:\$Recycle.Bin\S-1-5-21-410467421-2488857862-1770528685-1000
          Supprimé ! C:\Recycler\S-1-5-18

          ################## | Registre # Clés infectieuses |

          ################## | Registre # Mountpoints2 |

          Supprimé ! HKCU\...\Explorer\MountPoints2\G\Shell\AutoRun\Command
          Supprimé ! HKCU\...\Explorer\MountPoints2\{0697ca39-81a4-11de-82cc-001f160aff8e}\Shell\AutoRun\Command
          Supprimé ! HKCU\...\Explorer\MountPoints2\{1ea73536-dcd6-11de-80b6-001f160aff8e}\Shell\AutoRun\Command
          Supprimé ! HKCU\...\Explorer\MountPoints2\{7691030c-803e-11de-8e6c-001f160aff8e}\Shell\AutoRun\Command
          Supprimé ! HKCU\...\Explorer\MountPoints2\{9fef053b-4b97-11de-957d-001f160aff8e}\Shell\Auto\Command
          Supprimé ! HKCU\...\Explorer\MountPoints2\{a763d1b9-8f03-11de-9617-00a0c6000000}\Shell\AutoRun\Command
          Supprimé ! HKCU\...\Explorer\MountPoints2\{b2236ebc-8032-11de-9e20-001f160aff8e}\Shell\AutoRun\Command
          Supprimé ! HKCU\...\Explorer\MountPoints2\{b2236ec7-8032-11de-9e20-001f160aff8e}\Shell\AutoRun\Command
          Supprimé ! HKCU\...\Explorer\MountPoints2\{c557242e-120b-11de-ad2a-001f160aff8e}\Shell\AutoRun\Command

          ################## | Listing des fichiers présent |

          [16/12/2009 15:04|--a------|34940] C:\aaw7boot.log
          [18/09/2006 22:43|--a------|24] C:\autoexec.bat
          [11/04/2009 07:36|-rahs----|333257] C:\bootmgr
          [31/08/2008 22:10|-ra-s----|8192] C:\BOOTSECT.BAK
          [18/09/2006 22:43|--a------|10] C:\config.sys
          [14/08/2009 13:28|--a------|183] C:\fpRedmon.log
          [19/09/2008 08:46|--a------|0] C:\france.dat
          [?|?|?] C:\hiberfil.sys
          [22/09/2008 10:43|-rahs----|0] C:\IO.SYS
          [22/09/2008 10:43|-rahs----|0] C:\MSDOS.SYS
          [29/02/2004 16:44|--a------|52576] C:\orange.bmp
          [?|?|?] C:\pagefile.sys
          [17/08/2009 06:45|--a------|2047] C:\rollback.ini
          [03/03/2009 22:57|--a------|1963] C:\TB.txt
          [16/12/2009 17:07|--a------|5203] C:\UsbFix.txt
          [21/08/2008 11:50|-rah-----|672] D:\autoexec.bat
          [03/07/2000 09:06|-rah-----|512] D:\WinMe.bin
          [12/08/1998 01:09|-rah-----|20016] D:\xmsdsk.exe
          [25/06/2001 09:54|-rah-----|57856] D:\chkcd.exe
          [15/05/1998 20:01|-rah-----|5431] D:\CHOICE.COM
          [05/05/1999 22:22|--a------|96370] D:\Command.com
          [08/02/2007 10:49|-rah-----|112] D:\CONFIG.SYS
          [15/05/1998 20:01|-rah-----|30742] D:\COUNTRY.SYS
          [25/06/2001 08:41|-rah-----|20473] D:\cwsdpmi.exe
          [15/05/1998 20:01|-rah-----|17191] D:\DISPLAY.SYS
          [08/06/2000 17:00|-rah-----|68871] D:\DRVSPACE.BIN
          [15/05/1998 20:01|-rah-----|58870] D:\EGA.CPI
          [08/06/2000 17:00|-rah-----|53767] D:\EXTRACT.EXE
          [08/06/2000 17:00|-rah-----|66060] D:\FDISK.EXE
          [08/06/2000 17:00|-rah-----|8073] D:\FINDCD.EXE
          [23/04/1999 22:22|-rah-----|64425] D:\FLASHPT.SYS
          [15/05/1998 20:01|-rah-----|33447] D:\HIMEM.SYS
          [01/09/2001 13:39|-rah-----|222390] D:\Io.sys
          [01/09/2001 13:39|-rah-----|2048] D:\JO.SYS
          [15/05/1998 20:01|-rah-----|20023] D:\KEYB.COM
          [15/05/1998 20:01|-rah-----|34566] D:\KEYBOARD.SYS
          [15/05/1998 20:01|-rah-----|29815] D:\MODE.COM
          [16/12/1999 03:01|-rah-----|37681] D:\MOUSE.COM
          [27/01/2000 11:14|-rah-----|15] D:\MOUSE.INI
          [08/06/2000 17:00|-rah-----|25473] D:\MSCDEX.EXE
          [08/06/2000 17:00|-rah-----|4] D:\MSDOS.SYS
          [15/05/1998 20:01|-rah-----|41302] D:\OAKCDROM.SYS
          [29/09/2000 13:04|--a------|21] D:\REBOOT.COM
          [28/04/1998 18:18|-rah-----|20] D:\RESTART.COM
          [22/12/2006 12:16|-rah-----|2126649] D:\sysb.bin
          [04/08/2009 15:44|--ah-----|177] D:\BOOTLOG.PRV
          [07/05/2007 09:57|-rah-----|93878] D:\logo.sys
          [04/08/2009 15:44|--ah-----|177] D:\BOOTLOG.TXT
          [18/09/2007 11:53|--a------|29] D:\REBOOTPC.BAT
          [22/09/2008 20:29|--a------|97] D:\SWCONF.dat
          [21/07/1999 13:30|-rah-----|1469] D:\SUBST.COM
          [08/06/2009 17:57|--ah-----|162] D:\~$amiti‚.docx
          [23/06/2009 20:46|--ah-----|162] D:\~$ taire.docx
          [23/06/2009 20:54|--ah-----|162] D:\~$ secret du metro.doc
          [02/06/2009 18:13|--ah-----|4096] G:\._.Trashes

          ################## | Vaccination |

          # C:\autorun.inf -> Dossier créé par UsbFix.
          # D:\autorun.inf -> Dossier créé par UsbFix.

          ################## | Cracks / Keygens / Serials |

          "C:\Loic\Musique Ordi\Musique papa\incomming\FTP.Expert.v3.80.2.FR.Incl-Keygen\ftpexpert3.exe"
          14/02/2008 05:55 |Size 5571016 |Crc32 59621086 |Md5 346ba07c89db7fd18c38403b979523dc

          "C:\Loic\Application non scanner\Winrar_3.71_crack_pifoman.zip"
          -> Contain : Crack.exe 23919 DFLT-X 9% 21712 29-09-2007 17:27:14 f68d6cf5

          "C:\Loic\Musique Ordi\Musique papa\incomming\FTP Expert 3.50.0 FR + keygen + manuel + tutoriel.rar"
          -> contain : FTP Expert 3.50.0 FR + keygen + manuel + tutoriel\ftpexpert3.exe

          "C:\Loic\Musique Ordi\Musique papa\incomming\FTP Expert 3.50.0 FR + keygen + manuel + tutoriel.rar"
          -> contain : FTP Expert 3.50.0 FR + keygen + manuel + tutoriel\FTPExpert3_Keygen.exe

          "C:\Loic\Musique Ordi\Musique papa\incomming\FTP Expert 3.50.0 FR + keygen + manuel + tutoriel.rar"
          -> contain : FTP Expert 3.50.0 FR + keygen + manuel + tutoriel\setup.exe

          "C:\Loic\Musique Ordi\Musique papa\incomming\FTP.Expert.v3.80.2.FR.Incl-Keygen.rar"
          -> contain : ftpexpert3.exe

          "C:\Loic\Musique Ordi\Musique papa\incomming\FTP.Expert.v3.80.2.FR.Incl-Keygen.rar"
          -> contain : Keygen\Keygen FTP Expert 3.xx.exe

          ################## | Upload |

          Veuillez envoyer le fichier : C:\Users\Loic\Desktop\UsbFix_Upload_Me_PC-de-Loic.zip : https://www.ionos.fr/?affiliate_id=77097
          Merci pour votre contribution .

          Par contre, le programme me demande d'envoyer un certain fichier...
          Dois-je le faire?
          0
      3. Par contre, le programme me demande d'envoyer un certain fichier... 
        Dois-je le faire?


        ==> Fais le...Cela contribuera à améliorer l'outil que tu viens d'utiliser !

        Fais ensuite un scan avec cet antispyware :
        Malwarebytes + tutoriel

        Tu l´installes; mets le a jour...(onglet mise a jour)
        Click maintenant sur l´onglet recherche et coche la case :
        "Executer un examen rapide".
        Puis click sur "rechercher".
        Laisses le scanner le pc...
        A la fin du scan, clique sur Afficher les résultats
        Si des elements on ete trouvés :
        > click sur supprimer la selection.
        si il t´es demandé de redemarrer > click sur "oui".
        A la fin un rapport va s´ouvrir;
        sauvegarde le de maniere a le retrouver en vue de le poster sur le forum.
        Copies et colles le rapport stp.

        a+

        0
        1. Malwarebytes' Anti-Malware 1.42
          Version de la base de données: 3368
          Windows 6.0.6002 Service Pack 2
          Internet Explorer 8.0.6001.18865

          16/12/2009 19:54:57
          mbam-log-2009-12-16 (19-54-53).txt

          Type de recherche: Examen rapide
          Eléments examinés: 98058
          Temps écoulé: 9 minute(s), 40 second(s)

          Processus mémoire infecté(s): 0
          Module(s) mémoire infecté(s): 0
          Clé(s) du Registre infectée(s): 12
          Valeur(s) du Registre infectée(s): 1
          Elément(s) de données du Registre infecté(s): 0
          Dossier(s) infecté(s): 0
          Fichier(s) infecté(s): 0

          Processus mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Module(s) mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Clé(s) du Registre infectée(s):
          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> No action taken.
          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> No action taken.
          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{d9c9a8c9-460d-4343-888e-ae02bcc3ce57} (Adware.SpeedApps) -> No action taken.
          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> No action taken.
          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> No action taken.
          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{d9c9a8c9-460d-4343-888e-ae02bcc3ce57} (Adware.SpeedApps) -> No action taken.
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> No action taken.
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> No action taken.

          Valeur(s) du Registre infectée(s):
          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\iepr (Trojan.Agent) -> No action taken.

          Elément(s) de données du Registre infecté(s):
          (Aucun élément nuisible détecté)

          Dossier(s) infecté(s):
          (Aucun élément nuisible détecté)

          Fichier(s) infecté(s):
          (Aucun élément nuisible détecté)
          0
      4. ==> -> No action taken.

        Donc rien n'a été supprimé!

        ==> Reprends Malwarebytes et > click sur supprimer la selection.

        --> Postes moi le nouveau rapport généré !!!

        a+

        0
        1. Malwarebytes' Anti-Malware 1.42
          Version de la base de données: 3368
          Windows 6.0.6002 Service Pack 2
          Internet Explorer 8.0.6001.18865

          16/12/2009 20:46:33
          mbam-log-2009-12-16 (20-46-33).txt

          Type de recherche: Examen rapide
          Eléments examinés: 98759
          Temps écoulé: 7 minute(s), 2 second(s)

          Processus mémoire infecté(s): 0
          Module(s) mémoire infecté(s): 1
          Clé(s) du Registre infectée(s): 0
          Valeur(s) du Registre infectée(s): 0
          Elément(s) de données du Registre infecté(s): 0
          Dossier(s) infecté(s): 0
          Fichier(s) infecté(s): 1

          Processus mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Module(s) mémoire infecté(s):
          C:\Program Files\Windows Live\Messenger\msimg32.dll (Adware.MyWebSearch) -> Delete on reboot.

          Clé(s) du Registre infectée(s):
          (Aucun élément nuisible détecté)

          Valeur(s) du Registre infectée(s):
          (Aucun élément nuisible détecté)

          Elément(s) de données du Registre infecté(s):
          (Aucun élément nuisible détecté)

          Dossier(s) infecté(s):
          (Aucun élément nuisible détecté)

          Fichier(s) infecté(s):
          C:\Program Files\Windows Live\Messenger\msimg32.dll (Adware.MyWebSearch) -> Delete on reboot.

          Bizarre, il m'en trouve seulement deux... Mais, je pense que je me suis trompé tout à l'heure et que je t'ai juste passé le rapport de recherche mais pas celui de supression... M'enfin, je ne sais pas...
          0
          1. Fais ceci:

            Desactives ton antivirus le temps de la manip ainsi que ton parefeu si présent

            Télécharges List&Kill'em et enregistre le sur ton bureau

            http://sd-1.archive-host.com/membres/up/829108531491024/List_Killem.zip

            dezippes-le , (clic droit/ extraire.....)

            Il ne necessite pas d'installation

            double clic (clic droit "executer en tant qu'administrateur" pour Vista) pour lancer le scan

            choisis la langue puis choisis l'option 1 = Mode Recherche

            laisses travailler l'outil

            colles le contenu dans ta prochaine réponse , un fois la fenetre refermée :

            C:\List'em.txt

            a+
            0
            1. Voilà ;)

              List'em by g3n-h@ckm@n 1.1.5.2

              Thx to Chiquitine29.....& CCM team

              User : Loic (Administrateurs) # PC-DE-LOIC
              Update on 14/12/2009 by g3n-h@ckm@n ::::: 00:00
              Start at: 21:19:01 | 16/12/2009
              Contact : g3n-h@ckm@n sur CCM

              Intel(R) Core(TM)2 Duo CPU T5800 @ 2.00GHz
              Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
              Internet Explorer 8.0.6001.18865
              Windows Firewall Status : Disabled

              C:\ -> Disque fixe local | 263,92 Go (62,77 Go free) [BOOT] | NTFS
              D:\ -> Disque fixe local | 34,16 Go (19,04 Go free) [RECOVER] | FAT32
              E:\ -> Disque CD-ROM
              F:\ -> Disque amovible
              G:\ -> Disque amovible | 1,91 Go (1,53 Go free) | FAT

              ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

              C:\Windows\System32\smss.exe 500
              C:\Windows\system32\csrss.exe 592
              C:\Windows\system32\wininit.exe 648
              C:\Windows\system32\csrss.exe 660
              C:\Windows\system32\services.exe 696
              C:\Windows\system32\lsass.exe 708
              C:\Windows\system32\lsm.exe 720
              C:\Windows\system32\svchost.exe 860
              C:\Windows\system32\nvvsvc.exe 928
              C:\Windows\system32\svchost.exe 960
              c:\Program Files\Microsoft Security Essentials\MsMpEng.exe 992
              C:\Windows\System32\svchost.exe 1088
              C:\Windows\System32\svchost.exe 1148
              C:\Windows\system32\svchost.exe 1184
              C:\Windows\system32\svchost.exe 1280
              C:\Windows\system32\SLsvc.exe 1296
              C:\Windows\system32\svchost.exe 1344
              C:\Windows\system32\winlogon.exe 1444
              C:\Windows\system32\svchost.exe 1512
              C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe 1676
              C:\Windows\system32\rundll32.exe 1720
              C:\Program Files\EgisTec\VITAKEY\CompPtcVUI.exe 1760
              C:\Windows\System32\spoolsv.exe 1900
              C:\Program Files\Avira\AntiVir Desktop\sched.exe 1928
              C:\Windows\system32\svchost.exe 1944
              C:\Program Files\Avira\AntiVir Desktop\avguard.exe 556
              C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 1032
              C:\Program Files\Bonjour\mDNSResponder.exe 1196
              C:\Windows\system32\svchost.exe 1368
              C:\Program Files\EgisTec\VITAKEY\BASVC.exe 848
              C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe 2148
              C:\Program Files\EgisTec\MyWinLocker 3\x86\MWLService.exe 2196
              C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe 2208
              C:\Windows\system32\IoctlSvc.exe 2264
              C:\Windows\system32\svchost.exe 2280
              C:\Windows\system32\PSIService.exe 2324
              C:\Program Files\CyberLink\Shared Files\RichVideo.exe 2348
              C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 2364
              C:\Windows\system32\svchost.exe 2416
              C:\Windows\System32\svchost.exe 2464
              C:\Windows\system32\SearchIndexer.exe 2488
              C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe 2552
              C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe 2816
              C:\Windows\system32\WUDFHost.exe 2912
              C:\Windows\system32\wbem\wmiprvse.exe 2944
              C:\Windows\system32\wbem\unsecapp.exe 3268
              C:\Windows\system32\wbem\wmiprvse.exe 3280
              C:\Windows\system32\taskeng.exe 3392
              C:\Windows\system32\Dwm.exe 3960
              C:\Windows\Explorer.EXE 3996
              C:\Windows\system32\taskeng.exe 1324
              C:\Windows\System32\mobsync.exe 3276
              C:\Windows\RtHDVCpl.exe 3608
              C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe 3684
              C:\Program Files\HomeCinema\PowerDVD\PDVDServ.exe 3728
              C:\Windows\tsnp2uvc.exe 2300
              C:\Program Files\EgisTec\VITAKEY\PdtWzd.exe 1660
              C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe 2780
              C:\Program Files\Common Files\Real\Update_OB\realsched.exe 1604
              C:\Program Files\Winamp\winampa.exe 2132
              C:\Windows\WindowsMobile\wmdSync.exe 2444
              C:\Windows\system32\svchost.exe 1424
              C:\Program Files\FreePDF_XP\fpassist.exe 2728
              C:\Program Files\Windows Media Player\wmpnscfg.exe 1588
              C:\Program Files\Avira\AntiVir Desktop\avgnt.exe 3576
              C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe 3604
              C:\Windows\System32\rundll32.exe 3452
              C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe 2028
              C:\Program Files\Windows Media Player\wmpnetwk.exe 3904
              C:\Program Files\Microsoft Security Essentials\msseces.exe 1084
              C:\Program Files\iTunes\iTunesHelper.exe 1056
              C:\Program Files\Windows Sidebar\sidebar.exe 4004
              C:\Program Files\Windows Live\Messenger\msnmsgr.exe 3328
              C:\Windows\ehome\ehtray.exe 4140
              C:\Windows\system32\wbem\unsecapp.exe 4148
              C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe 4160
              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe 4172
              C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe 4220
              C:\Program Files\Electronic Arts\EADM\Core.exe 4348
              C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe 4404
              C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe 4492
              C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe 4560
              C:\Windows\ehome\ehmsas.exe 4572
              C:\Program Files\EgisTec\VITAKEY\PwdBank.exe 4988
              C:\Program Files\iPod\bin\iPodService.exe 5940
              C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlNotifyIcon.exe 6136
              C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe 2812
              C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe 2584
              C:\Program Files\Windows Live\Contacts\wlcomm.exe 5884
              C:\Program Files\Internet Explorer\iexplore.exe 4628
              C:\Program Files\Internet Explorer\iexplore.exe 584
              C:\Windows\system32\conime.exe 4400
              C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe 3860
              C:\Windows\system32\Macromed\Flash\FlashUtil10d.exe 5740
              C:\Windows\system32\NOTEPAD.EXE 4216
              C:\Program Files\Internet Explorer\iexplore.exe 3360
              C:\Program Files\Internet Explorer\iexplore.exe 3948
              C:\Program Files\Dofus\Dofus.exe 5308
              C:\Program Files\Dofus\dofus.dll 6892
              C:\Program Files\Internet Explorer\iexplore.exe 7772
              C:\Windows\system32\FirewallControlPanel.exe 6724
              C:\Windows\system32\SearchProtocolHost.exe 7056
              C:\Windows\system32\SearchFilterHost.exe 7060
              C:\Program Files\WinRAR\WinRAR.exe 6264
              C:\Users\Loic\AppData\Local\Temp\Rar$EX00.763\List_Kill'em.exe 7504
              C:\Windows\system32\cmd.exe 796
              C:\Users\Loic\AppData\Local\Temp\C12D.tmp\pv.exe 2376

              ======================
              Keys "Run"
              ======================
              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              Sidebar REG_SZ C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
              msnmsgr REG_SZ "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
              ehTray.exe REG_SZ C:\Windows\ehome\ehTray.exe
              IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} REG_SZ "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
              swg REG_SZ "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
              ISUSPM REG_SZ "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
              Google Update REG_SZ "C:\Users\Loic\AppData\Local\Google\Update\GoogleUpdate.exe" /c
              EA Core REG_SZ "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
              SpybotSD TeaTimer REG_SZ C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              WMPNSCFG REG_SZ C:\Program Files\Windows Media Player\WMPNSCFG.exe

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              Windows Defender REG_EXPAND_SZ %ProgramFiles%\Windows Defender\MSASCui.exe -hide
              RtHDVCpl REG_SZ RtHDVCpl.exe
              mwlDaemon REG_SZ C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
              RemoteControl REG_SZ "C:\Program Files\HomeCinema\PowerDVD\PDVDServ.exe"
              LanguageShortcut REG_SZ "C:\Program Files\HomeCinema\PowerDVD\Language\Language.exe"
              UCam_Menu REG_SZ "C:\Program Files\HomeCinema\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\HomeCinema\YouCam" update "Software\CyberLink\YouCam\2.0"
              tsnp2uvc REG_SZ C:\Windows\tsnp2uvc.exe
              VitaKeyPdtWzd REG_SZ C:\Program Files\EgisTec\VITAKEY\PdtWzd.exe
              Google Desktop Search REG_SZ "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
              toolbar_eula_launcher REG_SZ C:\Program Files\GoogleEULA\EULALauncher.exe
              TkBellExe REG_SZ "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
              AppleSyncNotifier REG_SZ C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
              WinampAgent REG_SZ "C:\Program Files\Winamp\winampa.exe"
              Windows Mobile-based device management REG_EXPAND_SZ %windir%\WindowsMobile\wmdSync.exe
              FreePDF Assistant REG_SZ C:\Program Files\FreePDF_XP\fpassist.exe
              avgnt REG_SZ "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
              Ad-Watch REG_SZ C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
              Skytel REG_SZ Skytel.exe
              NvCplDaemon REG_SZ RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
              NvMediaCenter REG_SZ RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
              MobileConnect REG_EXPAND_SZ %programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent
              QuickTime Task REG_SZ "C:\Program Files\QuickTime\QTTask.exe" -atboottime
              MSSE REG_SZ "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide
              iTunesHelper REG_SZ "C:\Program Files\iTunes\iTunesHelper.exe"

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

              =====================
              Other Keys
              =====================
              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
              ConsentPromptBehaviorAdmin REG_DWORD 2 (0x2)
              ConsentPromptBehaviorUser REG_DWORD 1 (0x1)
              EnableInstallerDetection REG_DWORD 1 (0x1)
              EnableLUA REG_DWORD 1 (0x1)
              EnableSecureUIAPaths REG_DWORD 1 (0x1)
              EnableVirtualization REG_DWORD 1 (0x1)
              PromptOnSecureDesktop REG_DWORD 1 (0x1)
              ValidateAdminCodeSignatures REG_DWORD 0 (0x0)
              dontdisplaylastusername REG_DWORD 0 (0x0)
              legalnoticecaption REG_SZ
              legalnoticetext REG_SZ
              scforceoption REG_DWORD 0 (0x0)
              shutdownwithoutlogon REG_DWORD 1 (0x1)
              undockwithoutlogon REG_DWORD 1 (0x1)
              FilterAdministratorToken REG_DWORD 0 (0x0)
              EnableUIADesktopToggle REG_DWORD 0 (0x0)

              ===============
              [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
              NoDriveAutoRun REG_DWORD 128 (0x80)
              NoDriveTypeAutoRun REG_DWORD 128 (0x80)
              HonorAutoRunSetting REG_DWORD 0 (0x0)

              ===============
              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
              BindDirectlyToPropertySetStorage REG_DWORD 0 (0x0)
              NoDriveAutoRun REG_DWORD 128 (0x80)
              NoDriveTypeAutoRun REG_DWORD 128 (0x80)
              HonorAutoRunSetting REG_DWORD 0 (0x0)

              ===============
              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
              AppInit_DLLS REG_SZ C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL

              ===============

              ===============
              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

              ===============
              [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

              [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

              ===============
              BHO :
              ======
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{53707962-6F74-2D53-2644-206D7942484F}]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]

              ================
              Internet Explorer :
              ================
              [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
              Start Page REG_SZ https://www.msn.com/fr-fr

              [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
              Start Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

              ========
              Services
              ========
              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

              Ndisuio : 0x3
              EapHost : 0x3
              Wlansvc : 0x2
              SharedAccess : 0x3
              windefend : 0x2
              wuauserv : 0x2
              wscsvc : 0x2

              =========

              =======
              Drive :
              =======

              D‚fragmenteur de disque Windows
              Copyright (c) 2006 Microsoft Corp.

              Rapport d'analyse pour le volume C: BOOT

              Taille du volume = 264 Go
              Espace libre = 62.78 Go
              tendue d'espace libre la plus grande = 51.37 Go
              Pourcentage de fragmentation des fichiers = 2 %

              Remarqueÿ: sur les volumes NTFS, les fragments de fichiers de plus de 64ÿMo ne sont pas inclus dans les statistiques de fragmentation.

              Il n'est pas n‚cessaire de d‚fragmenter ce volume.

              ¤¤¤¤¤¤¤¤¤¤ Files/folders :

              C:\Program Files\Circle Developement
              C:\Program Files\Windows Live\Messenger\Riched20.dll

              ¤¤¤¤¤¤¤¤¤¤ Keys :

              HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser "{3041d03e-fd4b-44e0-b742-2d9b88305f98}"
              HKCR\CLSID\{b0de3308-5d5a-470d-81b9-634fc078393b}
              HKCU\Software\AppDataLow\AskBarDis
              HKLM\Software\Classes\CLSID\{b0de3308-5d5a-470d-81b9-634fc078393b}
              HKLM\Software\Classes\TypeLib\{4B1C1E16-6B34-430E-B074-5928ECA4C150}

              =========
              Rootkits
              =========

              catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
              Rootkit scan 2009-12-16 21:25:42
              Windows 6.0.6002 Service Pack 2 NTFS

              scanning hidden processes ...

              scanning hidden services & system hive ...

              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0015aff71f88]
              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0015aff71f8d]
              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0015aff71f9d]
              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0015affc2bb6]
              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\0015aff71f88]
              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\0015aff71f8d]
              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\0015aff71f9d]
              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\0015affc2bb6]

              scanning hidden registry entries ...

              scanning hidden files ...

              scan completed successfully
              hidden processes: 0
              hidden services: 0
              hidden files: 0

              Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

              device: opened successfully
              user: MBR read successfully
              kernel: MBR read successfully
              user & kernel MBR OK

              ==========
              Programs
              ==========

              Activation Assistant for the 2007 Microsoft Office suites
              Adobe
              Apple Software Update
              Avira
              AviSynth 2.5
              AVS4YOU
              Bonjour
              CCleaner
              Circle Developement
              Common Files
              Conduit
              Corel
              CyberLink
              desktop.ini
              directx
              Dofus
              Dofus 2
              Dofus 2 Online
              DofusBeta
              EgisTec
              Electronic Arts
              eMule
              Fichiers communs
              FreePDF_XP
              GamersFirst
              GameSpy Arcade
              Google
              GoogleEULA
              Gpotato.eu
              gs
              Guitar Pro 5
              HomeCinema
              InstallShield Installation Information
              Intel
              Internet Explorer
              iPod
              iTunes
              Java
              jeu
              K-Lite Codec Pack
              Lavalys
              Lavasoft
              Malwarebytes' Anti-Malware
              McAfee Security Scan
              Messenger Plus! Live
              Microsoft
              Microsoft CAPICOM 2.1.0.2
              Microsoft Games
              Microsoft Office
              Microsoft Security Essentials
              Microsoft Silverlight
              Microsoft SQL Server Compact Edition
              Microsoft Sync Framework
              Microsoft Visual Studio
              Microsoft Visual Studio 8
              Microsoft Works
              Microsoft.NET
              Movie Maker
              Mozilla Firefox
              MSBuild
              MSXML 4.0
              Nero
              NeroInstall.bak
              PhotoFiltre
              Pyro Studios
              QuickTime
              Real
              Realtek
              Reference Assemblies
              Safari
              SEGA
              Skype
              Spybot - Search & Destroy
              Steam
              trend micro
              Uninstall Information
              Utilitaire de configuration iPhone
              VALVe
              Vodafone
              Wakfu
              Winamp
              Windows Calendar
              Windows Collaboration
              Windows Defender
              Windows Journal
              Windows Live
              Windows Live SkyDrive
              Windows Mail
              Windows Media Player
              Windows NT
              Windows Photo Gallery
              Windows Portable Devices
              Windows Sidebar
              WinRAR
              Yahoo!

              ============
              Lecteur C:
              ============

              $Recycle.Bin
              11f278d313e7e3384676
              206c9b78c07343127f
              30972e9fa8004d6a45
              8abcd9b174c14072cee5ae
              aaw7boot.log
              autoexec.bat
              autorun.inf
              Boot
              bootmgr
              BOOTSECT.BAK
              config.sys
              Documents and Settings
              f82077b76a4225fd1c
              fpRedmon.log
              france.dat
              Hebergeur
              hiberfil.sys
              IDE
              Intel
              intern
              IO.SYS
              Ipod Alex
              Kill'em
              List'em.txt
              Loic
              MSDOS.SYS
              MSOCache
              MyWinLockerData
              orange.bmp
              pagefile.sys
              Papa
              PerfLogs
              Program Files
              ProgramData
              RECYCLER
              rollback.ini
              rsit
              Sarah
              Sierra
              System Volume Information
              TB.txt
              test
              UsbFix
              UsbFix.txt
              Users
              Windows

              ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
              0
              1. REDEMARRE EN MODE SANS ECHEC

                Relance List&Kill'em (clic droit pour vista),

                mais cette fois-ci :

                choisis l'option 2 = Mode Destruction

                laisse travailler l'outil

                apres les verifications , un rapport va s'ouvrir.

                ferme-le.

                un deuxieme rapport va s'ouvrir ,

                colle son contenu dans ta reponse apres avoir redemarré en mode normal

                a+

                0
                1. Il n'y a eu qu'un seul rapport... Je le joint quand même...

                  Kill'em by g3n-h@ckm@n 1.1.5.2

                  User : Loic (Administrateurs) # PC-DE-LOIC
                  Update on 14/12/2009 by g3n-h@ckm@n ::::: 00:00
                  Start at: 22:22:18 | 16/12/2009
                  Contact : g3n-h@ckm@n sur CCM

                  Intel(R) Core(TM)2 Duo CPU T5800 @ 2.00GHz
                  Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
                  Internet Explorer 8.0.6001.18865
                  Windows Firewall Status : Enabled

                  C:\ -> Disque fixe local | 263,92 Go (63,16 Go free) [BOOT] | NTFS
                  D:\ -> Disque fixe local | 34,16 Go (19,04 Go free) [RECOVER] | FAT32
                  E:\ -> Disque CD-ROM
                  F:\ -> Disque amovible
                  G:\ -> Disque amovible | 1,91 Go (1,53 Go free) | FAT

                  ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                  C:\Windows\System32\smss.exe 436
                  C:\Windows\system32\csrss.exe 592
                  C:\Windows\system32\wininit.exe 648
                  C:\Windows\system32\csrss.exe 660
                  C:\Windows\system32\services.exe 696
                  C:\Windows\system32\lsass.exe 708
                  C:\Windows\system32\lsm.exe 720
                  C:\Windows\system32\svchost.exe 860
                  C:\Windows\system32\nvvsvc.exe 928
                  C:\Windows\system32\svchost.exe 956
                  c:\Program Files\Microsoft Security Essentials\MsMpEng.exe 996
                  C:\Windows\System32\svchost.exe 1120
                  C:\Windows\System32\svchost.exe 1184
                  C:\Windows\system32\svchost.exe 1204
                  C:\Windows\system32\svchost.exe 1276
                  C:\Windows\system32\SLsvc.exe 1292
                  C:\Windows\system32\svchost.exe 1340
                  C:\Windows\system32\winlogon.exe 1452
                  C:\Windows\system32\svchost.exe 1524
                  C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe 1668
                  C:\Windows\system32\rundll32.exe 1764
                  C:\Program Files\EgisTec\VITAKEY\CompPtcVUI.exe 1832
                  C:\Windows\System32\spoolsv.exe 1880
                  C:\Program Files\Avira\AntiVir Desktop\sched.exe 1940
                  C:\Windows\system32\svchost.exe 1960
                  C:\Program Files\Avira\AntiVir Desktop\avguard.exe 580
                  C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 940
                  C:\Program Files\Bonjour\mDNSResponder.exe 1116
                  C:\Windows\system32\svchost.exe 1244
                  C:\Program Files\EgisTec\VITAKEY\BASVC.exe 2108
                  C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe 2220
                  C:\Program Files\EgisTec\MyWinLocker 3\x86\MWLService.exe 2292
                  C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe 2320
                  C:\Windows\system32\IoctlSvc.exe 2428
                  C:\Windows\system32\svchost.exe 2456
                  C:\Windows\system32\PSIService.exe 2472
                  C:\Program Files\CyberLink\Shared Files\RichVideo.exe 2500
                  C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 2572
                  C:\Windows\system32\svchost.exe 2800
                  C:\Windows\System32\svchost.exe 2828
                  C:\Windows\system32\SearchIndexer.exe 2884
                  C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe 2948
                  C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe 3028
                  C:\Windows\system32\WUDFHost.exe 3176
                  C:\Windows\system32\wbem\wmiprvse.exe 3392
                  C:\Windows\system32\wbem\unsecapp.exe 3488
                  C:\Windows\system32\taskeng.exe 3536
                  C:\Windows\system32\Dwm.exe 3548
                  C:\Windows\system32\wbem\wmiprvse.exe 3584
                  C:\Windows\Explorer.EXE 3680
                  C:\Windows\system32\taskeng.exe 3888
                  C:\Windows\RtHDVCpl.exe 3772
                  C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe 692
                  C:\Program Files\HomeCinema\PowerDVD\PDVDServ.exe 2772
                  C:\Windows\tsnp2uvc.exe 2340
                  C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe 4000
                  C:\Program Files\EgisTec\VITAKEY\PdtWzd.exe 428
                  C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe 2620
                  C:\Program Files\Common Files\Real\Update_OB\realsched.exe 1744
                  C:\Program Files\Winamp\winampa.exe 2252
                  C:\Windows\WindowsMobile\wmdSync.exe 2376
                  C:\Program Files\FreePDF_XP\fpassist.exe 4080
                  C:\Program Files\Avira\AntiVir Desktop\avgnt.exe 3480
                  C:\Windows\System32\rundll32.exe 3288
                  C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe 4040
                  C:\Program Files\Microsoft Security Essentials\msseces.exe 4084
                  C:\Program Files\iTunes\iTunesHelper.exe 3776
                  C:\Program Files\Windows Sidebar\sidebar.exe 1732
                  C:\Windows\ehome\ehtray.exe 3432
                  C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe 1700
                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe 4060
                  C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe 2208
                  C:\Program Files\Electronic Arts\EADM\Core.exe 4004
                  C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe 1788
                  C:\Program Files\Windows Media Player\wmpnscfg.exe 3360
                  C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe 2908
                  C:\Windows\ehome\ehmsas.exe 1740
                  C:\Windows\system32\wbem\unsecapp.exe 5928
                  C:\Windows\system32\svchost.exe 4324
                  C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlNotifyIcon.exe 2596
                  C:\Windows\System32\mobsync.exe 4608
                  C:\Program Files\EgisTec\VITAKEY\PwdBank.exe 4960
                  C:\Program Files\Windows Media Player\wmpnetwk.exe 4652
                  C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe 5172
                  C:\Program Files\iPod\bin\iPodService.exe 5288
                  \\?\C:\Windows\system32\wbem\WMIADAP.EXE 1316
                  C:\Program Files\WinRAR\WinRAR.exe 2380
                  C:\Users\Loic\AppData\Local\Temp\Rar$EX00.955\List_Kill'em.exe 5264
                  C:\Windows\system32\conime.exe 5244
                  C:\Windows\system32\cmd.exe 4944
                  C:\Windows\system32\SearchProtocolHost.exe 5724
                  C:\Windows\system32\SearchFilterHost.exe 5008
                  C:\Users\Loic\AppData\Local\Temp\A7F1.tmp\pv.exe 5064

                  Detections :
                  ==========

                  ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                  "C:\Program Files\Circle Developement"
                  "C:\Program Files\Windows Live\Messenger\Riched20.dll"

                  ¤¤¤¤¤¤¤¤¤¤ Files/folders deleted :

                  Quarantine :

                  Circle Developement.Kill'em
                  riched20.dll.Kill'em

                  ==============
                  host file OK !
                  ==============

                  ========
                  Registry
                  ========
                  Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{3041d03e-fd4b-44e0-b742-2d9b88305f98}
                  Deleted : HKCR\CLSID\{b0de3308-5d5a-470d-81b9-634fc078393b}
                  Deleted : HKCU\Software\AppDataLow\AskBarDis
                  Deleted : HKLM\Software\Classes\TypeLib\{4B1C1E16-6B34-430E-B074-5928ECA4C150}

                  ============
                  Disk Cleaned
                  ============

                  ================
                  Prefetch cleaned
                  ================

                  ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                  0
                  1. voila mon site sa vous réglera surement votre prob j'ai eu le meme (mon frère) ^^'
                    0
                    1. hmmmm? Pardon mais, quel site?
                      0
                      1. Relances RSIT et colles le rapport stp !!

                        a+
                        0
                        1. Voilà

                          Logfile of random's system information tool 1.06 (written by random/random)
                          Run by Loic at 2009-12-16 23:14:10
                          Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
                          System drive C: has 65 GB (24%) free of 270 GB
                          Total RAM: 3066 MB (44% free)

                          Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 23:14:27, on 16/12/2009
                          Platform: Windows Vista SP2 (WinNT 6.00.1906)
                          MSIE: Internet Explorer v8.00 (8.00.6001.18865)
                          Boot mode: Normal

                          Running processes:
                          C:\Windows\system32\taskeng.exe
                          C:\Windows\system32\Dwm.exe
                          C:\Windows\Explorer.EXE
                          C:\Windows\RtHDVCpl.exe
                          C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
                          C:\Program Files\HomeCinema\PowerDVD\PDVDServ.exe
                          C:\Windows\tsnp2uvc.exe
                          C:\Program Files\EgisTec\VITAKEY\PdtWzd.exe
                          C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                          C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                          C:\Program Files\Winamp\winampa.exe
                          C:\Windows\WindowsMobile\wmdSync.exe
                          C:\Program Files\FreePDF_XP\fpassist.exe
                          C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                          C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
                          C:\Windows\System32\rundll32.exe
                          C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe
                          C:\Program Files\Microsoft Security Essentials\msseces.exe
                          C:\Program Files\iTunes\iTunesHelper.exe
                          C:\Program Files\Windows Sidebar\sidebar.exe
                          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                          C:\Windows\ehome\ehtray.exe
                          C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
                          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
                          C:\Program Files\Electronic Arts\EADM\Core.exe
                          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                          C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe
                          C:\Windows\system32\wbem\unsecapp.exe
                          C:\Program Files\Windows Media Player\wmpnscfg.exe
                          C:\Windows\ehome\ehmsas.exe
                          C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
                          C:\Program Files\EgisTec\VITAKEY\PwdBank.exe
                          C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlNotifyIcon.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Windows\system32\conime.exe
                          C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
                          C:\Windows\system32\Macromed\Flash\FlashUtil10d.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
                          C:\Program Files\Microsoft\Office Live\OfficeLiveSignIn.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Program Files\Windows Live\Contacts\wlcomm.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Program Files\iTunes\iTunes.exe
                          C:\Users\Loic\Downloads\RSIT.exe
                          C:\Program Files\Trend Micro\HijackThis\Loic.exe

                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.aldi.com/
                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.aldi.com/
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                          R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.thepickapp.com/search.htm
                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
                          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                          R3 - URLSearchHook: Yahoo! Barre d'outils - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                          O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                          O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                          O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                          O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                          O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
                          O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
                          O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                          O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
                          O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                          O3 - Toolbar: Yahoo! Barre d'outils - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                          O4 - HKLM\..\Run: [mwlDaemon] C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
                          O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\HomeCinema\PowerDVD\PDVDServ.exe"
                          O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\HomeCinema\PowerDVD\Language\Language.exe"
                          O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\HomeCinema\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\HomeCinema\YouCam" update "Software\CyberLink\YouCam\2.0"
                          O4 - HKLM\..\Run: [tsnp2uvc] C:\Windows\tsnp2uvc.exe
                          O4 - HKLM\..\Run: [VitaKeyPdtWzd] C:\Program Files\EgisTec\VITAKEY\PdtWzd.exe
                          O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                          O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\GoogleEULA\EULALauncher.exe
                          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                          O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
                          O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                          O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
                          O4 - HKLM\..\Run: [FreePDF Assistant] C:\Program Files\FreePDF_XP\fpassist.exe
                          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                          O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
                          O4 - HKLM\..\Run: [Skytel] Skytel.exe
                          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                          O4 - HKLM\..\Run: [MobileConnect] %programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent
                          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                          O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide
                          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                          O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
                          O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                          O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
                          O4 - HKCU\..\Run: [Google Update] "C:\Users\Loic\AppData\Local\Google\Update\GoogleUpdate.exe" /c
                          O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
                          O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                          O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                          O4 - Global Startup: McAfee Security Scan.lnk = ?
                          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                          O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                          O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                          O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                          O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                          O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                          O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
                          O13 - Gopher Prefix:
                          O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} (Shockwave ActiveX Control) -
                          O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} -
                          O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} -
                          O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} -
                          O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
                          O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} -
                          O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
                          O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                          O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                          O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
                          O23 - Service: Service Google Update (gupdate1ca2381a0949663) (gupdate1ca2381a0949663) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                          O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                          O23 - Service: EgisTec Service (IGBASVC) - Unknown owner - C:\Program Files\EgisTec\VITAKEY\BASVC.exe
                          O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                          O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
                          O23 - Service: MyWinLocker Service (MWLService) - EgisTec Inc. - C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe
                          O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                          O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
                          O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
                          O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
                          O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe
                          O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                          O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                          O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
                          O23 - Service: Vodafone Mobile Connect Service (VMCService) - Vodafone - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
                          0
                          1. Donnes des nouvelles du pc stp...

                            a+

                            0
                            1. Des nouvelles? Je refais un RSIT?

                              EDIT:

                              Imbécile que je suis... Excuse moi, je pensais qu'on en avait pas fini avec cela...

                              Pour l'instant, plus de problème, mais je vais attendre la fin de la journée mais je pense bien que le virus à pris la poudre d'escampette... Je mettrai donc tantôt ou demain "résolu".

                              Merci beaucoup d'avoir accordé de ton temps pour aider un novice!

                              Au plaisir,

                              Loïc alias Sewell
                              0
                              1. Ok,

                                Mets Java à jour

                                Pour desinstaller les outils utilisés
                                Telecharge ToolsCleaner2--> http://pc-system.fr/
                                -Une fois téléchargé, installe-le et lance-le
                                -Clique sur Recherche et laisse le scan se terminer
                                -Clique sur SUPPRESSION
                                -Clique sur Quitter pour que le rapport puisse se créer
                                -Poste moi le rapport se trouvant ici--> C:\TCleaner.txt

                                a+
                                0
                                1. Lorsque je mets "quitter" il me dit qu'il n'a pas accès à C:\le_dossier_dont_je_me_souviens_plus_du_nom

                                  Je désactive pare-feu et anti-virus?
                                  0
                                  1. Relances ToolsCleaner par un clic droit puis choisis "exécuter en tant qu'administrateur"

                                    a+
                                    0
                                    • 1
                                    • 2
                                    • 3