Paged'accueil internet

Bonsoir a tous.
Cela fait plus d'une semaine que je n'arrive pas a remettre ma page d'acceueil orange .
ca me mais toujour une page lo.st, de plus j bloqué lé publicité et ca me les ouvre kan méme.
Quelqun a t il une solution.
merci bocoup
Configuration: Windows Vista

21 réponses

Résumé de la discussion

Problème persistant : la page d'accueil orange ne se charge plus et laisse apparaître lo.st, tandis que les publicités se réouvrent malgré le blocage, sous Windows Vista. Plusieurs intervenants proposent des outils de nettoyage et désinfection comme RSIT et UsbFix, accompagnés de procédures pour désactiver temporairement le contrôle des comptes utilisateur et nettoyer les éléments indésirables. D'autres conseils évoquent des suppressions manuelles de dossiers associés à des programmes indésirables et l'usage d'outils d'élimination supplémentaires, puis le redémarrage et la vérification des rapports. Certaines réponses mentionnent l'installation de mises à jour et la restauration du système, ainsi que des rapports détaillés générés par les outils pour guider la suite des actions.

Bobot (l’IA à votre service)
  1. Modérateur
    Salut,
    Tu as téléchargé un logiciel sur Eorezo et c'est ce qui t'a infecté !

    ********

    Désactive l’UAC (User Account Control) le temps de la désinfection.
    Démarrer > Panneau de configuration > Comptes d’utilisateurs > Désactiver le contrôle des comptes d’utilisateur.
    (Manipulation inverse pour le remettre en fin de désinfection).
    (Cela va permettre aux outils de désinfection de travailler correctement).

    ********

    Télécharge Random’s System Information Tool (RSIT) de random/random et enregistre l’exécutable sur le Bureau.
    = = = = >>> En cliquant ici <<< = = = =

    * Clique droit sur RSIT.exe puis sélectionne ‘Exécuter en tant qu’administrateur‘ pour le lancer.
    * Une première fenêtre s’ouvre, clique alors sur Continue (Disclaimer).
    * Si la dernière version de HijackThis n’est pas détectée sur ton PC, RSIT le téléchargera et te demandera d’accepter la licence.
    * Lorsque l’analyse sera terminée, deux fichiers texte s’ouvriront (probablement avec le bloc-notes).
    * Poste le contenu de log.txt et de info.txt.
    1. Bonsoir, je n'ai jamais eu ton e mail ou tu mavé répondu je vien de le recevoir.
      Je vien de faire ce ke tu ma dit de faire, je tenvoie donc le rapport.

      log texte :

      Logfile of random's system information tool 1.06 (written by random/random)
      Run by Ophélie at 2010-02-22 21:38:34
      Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
      System drive C: has 438 GB (73%) free of 597 GB
      Total RAM: 3071 MB (64% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 21:39:06, on 22/02/2010
      Platform: Windows Vista SP1 (WinNT 6.00.1905)
      MSIE: Internet Explorer v7.00 (7.00.6001.18000)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Windows\system32\taskeng.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Windows\RtHDVCpl.exe
      C:\Program Files\PACKARD BELL\SetUpMyPC\SmpSys.exe
      C:\Program Files\Search Guard Plus\SearchGuardPlus.exe
      C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      C:\Program Files\Alwil Software\Avast4\ashDisp.exe
      C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
      C:\Program Files\Agence Exclusive\Agence.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Windows\System32\spool\drivers\w32x86\3\E_FATIACE.EXE
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Windows\ehome\ehtray.exe
      C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
      C:\Philips\GoGear SA018 Device Manager\GoGear_SA018_DeviceManager.exe
      C:\Program Files\OpenOffice.org 3\program\soffice.exe
      C:\Program Files\OpenOffice.org 3\program\soffice.bin
      C:\Windows\ehome\ehmsas.exe
      C:\Windows\system32\conime.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Windows\system32\SearchFilterHost.exe
      C:\Users\Ophélie\Downloads\RSIT.exe
      C:\Program Files\trend micro\Ophélie.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.packardbell.com/rdr.aspx?b=ACPW&l=040c&s=1&o=vp32&d=1208&m=imedia_d3610_fr
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://y.lo.st
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.packardbell.com/rdr.aspx?b=ACPW&l=040c&s=1&o=vp32&d=1208&m=imedia_d3610_fr
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yoower.com/
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll (file missing)
      R3 - URLSearchHook: SearchHelper Class - {91C18ED5-5E1C-4AE5-A148-A861DE8C8E16} - C:\Program Files\SGPSA\mtwb3sh.dll
      F2 - REG:system.ini: UserInit=C:\Windows\system32\ezShellStart.exe
      O1 - Hosts: ::1 localhost
      O2 - BHO: AEBHO - {0495F4D7-9FE3-4456-AA9D-1D57E78DF5F0} - C:\Program Files\Agence Exclusive\AgenceBHO.dll
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O2 - BHO: XBTBPos00 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll
      O3 - Toolbar: Fast Browser Search Toolbar - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll
      O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
      O4 - HKLM\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetupMyPC\SmpSys.exe
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
      O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\OrangeHSS\Systray\SystrayApp.exe"
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [ContentTransferWMDetector.exe] C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
      O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
      O4 - HKLM\..\Run: [Agence] "C:\Program Files\Agence Exclusive\Agence.exe"
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /F "C:\Windows\TEMP\E_S7658.tmp" /EF "HKLM"
      O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\PACKARD BELL\SetUpMyPC\SmpSys.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
      O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
      O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
      O4 - Global Startup: NETGEAR WG111v2 Smart Wizard.lnk = ?
      O4 - Global Startup: Philips GoGear SA018 Device Manager.lnk = ?
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
      O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
      O13 - Gopher Prefix:
      O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
      O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
      O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\PACKARDBELL\Packard Bell Recovery Management\Service\ETService.exe
      O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      O23 - Service: Google Desktop Manager 5.9.911.3589 (GoogleDesktopManager-110309-193829) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
      O23 - Service: SCM_Service - Unknown owner - C:\Windows\System32\WinService.exe
    2. re,

      info texte :

      info.txt logfile of random's system information tool 1.06 2010-02-22 21:39:08

      ======Uninstall list======

      -->"C:\Program Files\InstallShield Installation Information\{8F1B6239-FEA0-450A-A950-B05276CE177C}\setup.exe" -runfromtemp -l0x040c -removeonly
      -->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
      -->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
      Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
      Adobe Flash Player 10 Plugin-->MsiExec.exe /X{ECA1A3B6-898F-4DCE-9F04-714CF3BA126B}
      Adobe Photoshop Elements 6.0-->msiexec /I {F54AC413-D2C6-4A24-B324-370C223C6250}
      Adobe Reader 9.2 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A92000000001}
      Adobe Shockwave Player 11.5-->"C:\Windows\system32\Adobe\Shockwave 11\uninstaller.exe"
      Ad-Remover By C_XX-->"C:\Ad-Remover\Un-ADR.exe"
      Agence 1.0-->"C:\Program Files\Agence Exclusive\unins000.exe"
      Apple Application Support-->MsiExec.exe /I{3FA365DF-2D68-45ED-8F83-8C8A33E65143}
      Apple Mobile Device Support-->MsiExec.exe /I{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}
      Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
      Assistant de connexion Windows Live-->MsiExec.exe /I{D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
      avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
      Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
      Content Transfer-->MsiExec.exe /X{CFADE4AF-C0CF-4A04-A776-741318F1658F}
      DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
      DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
      DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
      DivX Plus DirectShow Filters-->C:\Program Files\DivX\DivXDSFiltersUninstall.exe /DSFILTERS
      DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
      EasyBits Magic Desktop-->C:\Windows\system32\ezMDUninstall.exe
      EPSON Attach To Email-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{20C45B32-5AB6-46A4-94EF-58950CAF05E5} /l1033 ADDREMOVEDLG
      EPSON Copy Utility 3-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{67EDD823-135A-4D59-87BD-950616D6E857}\SETUP.EXE" -l0x40c -UnInstall
      EPSON Easy Photo Print-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5DA7BC15-18D3-41A0-9F59-838DA3EAEF17}\SETUP.EXE" -l0x40c UNINST
      EPSON File Manager-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E86BC406-944E-41F6-ADE6-2C136734C96B}\Setup.exe" -l0x40c UNINST
      EPSON Image Clip Palette-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{314F6D08-A8B7-11D8-8446-0050BA1D384D}\Setup.exe" -l0x40c -u
      EPSON Logiciel imprimante-->C:\Windows\system32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
      EPSON Scan Assistant-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}\Setup.exe" -l0x40c -u
      EPSON Scan-->C:\Program Files\epson\escndv\setup\setup.exe /r
      EPSON Web-To-Page-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}\SETUP.EXE" -l0x40c -anything
      ESDX3800 Guide d'utilisation-->C:\Program Files\EPSON\TPMANUAL\ESDX3800\USE_G\DOCUNINS.EXE
      Fast Browser Search (My Web Tattoo)-->regsvr32 /u /s "C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll"
      GoGear SA018 Device Manager-->C:\Program Files\InstallShield Installation Information\{DC19A2BC-9698-430E-AD50-456B837B1BCD}\setup.exe -runfromtemp -l0x040c -removeonly
      Google Desktop-->C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
      Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_E85CDE7661A53A6A.exe" /uninstall
      Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
      Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
      HDReg France-->MsiExec.exe /I{0ED40D2A-7131-4FE7-941E-5C329336F712}
      HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
      iTunes-->MsiExec.exe /I{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}
      Java(TM) 6 Update 17-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216016FF}
      Jouer à Disney Winnie l’Ourson La Chasse au Miel de Tigrou-->C:\Windows\IsUn040c.exe -fC:\PROGRA~1\DISNEY~1\DISNEY~1\DeIsL1.isu
      Le code de la route-->C:\Windows\unin040c.exe -f"C:\Program Files\Ediser\Le code de la route\DeIsL1.isu" -c"C:\Program Files\Ediser\Le code de la route\_ISREG32.DLL"
      Le Livre de la Jungle, Groove Party-->C:\Windows\IsUn040c.exe -fC:\PROGRA~1\DISNEY~1\LELIVR~1\DeIsL1.isu
      Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
      MetaBoli-->"C:\Program Files\InstallShield Installation Information\{709817E4-5439-4206-8738-796B34B623BD}\setup.exe" -runfromtemp -l0x040c -removeonly
      Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
      Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
      Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
      Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
      Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
      Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
      Microsoft Office Home and Student-->C:\Program files\Microsoft Office\RunCmd.exe Office_Uninstall.cmd
      Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
      Microsoft Office OneNote MUI (French) 2007-->MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE}
      Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
      Microsoft Office PowerPoint Viewer 2007 (French)-->MsiExec.exe /X{95120000-00AF-040C-0000-0000000FF1CE}
      Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
      Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
      Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
      Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
      Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
      Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
      Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
      Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
      Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
      Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
      Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
      Microsoft Works 9.0 SE-->C:\Program files\Microsoft Office\RunCmd.exe Works_Uninstall.cmd
      Microsoft Works-->MsiExec.exe /I{0214A441-A4AB-43A8-8DEF-2F73C5364673}
      Module de compatibilité pour Microsoft Office System 2007-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
      Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
      Mon Conte de Fées-->C:\Windows\IsUn040c.exe -fC:\PROGRA~3\DISNEY~1\DISNEY~1\DeIsL1.isu
      MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
      MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
      neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
      NETGEAR WG111v2 wireless USB 2.0 adapter-->C:\Program Files\InstallShield Installation Information\{4102037D-E8E0-48E0-B203-E521D194FB71}\setup.exe -runfromtemp -l0x0009 -removeonly
      Norton Internet Security-->MsiExec.exe /I{7B15D70E-9449-4CFB-B9BC-798465B2BD5C}
      NVIDIA Drivers-->C:\Windows\system32\nvuninst.exe UninstallGUI
      OpenOffice.org 3.1-->MsiExec.exe /I{0FA44E79-CD7D-4E8D-A2EE-26FE05F509B6}
      Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
      Packard Bell Recovery Management-->"C:\Program Files\InstallShield Installation Information\{7F811A54-5A09-4579-90E1-C93498E230D9}\setup.exe" -runfromtemp -l0x040c -removeonly
      PDF-XChange 3-->"C:\Program Files\Tracker Software\PDF-XChange 3\unins000.exe"
      QuickTime-->MsiExec.exe /I{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}
      Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -removeonly
      SAMSUNG Mobile Modem Driver Set-->C:\Windows\system32\Samsung_USB_Drivers\3\SSCDUninstall.exe
      Samsung Mobile phone USB driver Software-->C:\Windows\system32\Samsung_USB_Drivers\5\SSSDUninstall.exe
      SAMSUNG Mobile USB Modem 1.0 Software-->C:\Windows\system32\Samsung_USB_Drivers\1\SS_Uninstall.exe
      SAMSUNG Mobile USB Modem Software-->C:\Windows\system32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
      Samsung PC Studio 3 USB Driver Installer-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}\setup.exe" -l0x40c -removeonly
      Samsung PC Studio 3-->"C:\Program Files\InstallShield Installation Information\{C4A4722E-79F9-417C-BD72-8D359A090C97}\setup.exe" -runfromtemp -l0x040c -removeonly
      Samsung Samples Installer-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7AC15160-A49B-4A89-B181-D4619C025FFF}\setup.exe" -l0x40c -removeonly
      Search Guard Plus (My Web Tattoo)-->C:\Program Files\Search Guard Plus\uninstalSGP.exe
      Search Guard Plus Updater (My Web Tattoo)-->C:\Program Files\Search Guard PlusU\uninstalSGPU.exe
      Security Update for 2007 Microsoft Office System (KB951550)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {B243E9A5-ED77-4F1B-B338-2486FD82DC85}
      Security Update for Microsoft Office OneNote 2007 (KB950130)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {F1B2401C-B610-4BF2-AA1C-52C55827A8F4}
      Security Update for Microsoft Office PowerPoint 2007 (KB951338)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {558B709B-821B-4FC5-90FC-9A8890641E77}
      Security Update for Microsoft Office system 2007 (KB956828)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {885E081B-72BD-4E76-8E98-30B4BE468FAC}
      Setup My PC-->"C:\Program Files\InstallShield Installation Information\{28518520-F25C-48C3-A224-861F331602F4}\setup.exe" -runfromtemp -l0x040c -removeonly
      Shareaza 2.4.0.0-->"C:\Program Files\Shareaza\Uninstall\unins000.exe"
      Spelling Dictionaries Support For Adobe Reader 9-->MsiExec.exe /I{AC76BA86-7AD7-5464-3428-900000000004}
      SpotAuditor 3.9.4-->"C:\Program Files\Nsasoft\SpotAuditor\unins000.exe"
      SpotMSN 1.9-->"C:\Program Files\Nsasoft\SpotMSN\unins000.exe"
      Studio-Scrap 2-->"C:\Program Files\StudioScrap2-Decouverte\unins000.exe"
      Update 1.2-->"C:\Users\Ophélie\AppData\Roaming\Agence Exclusive\Update\unins000.exe"
      Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
      Update for Office 2007 (KB946691)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278}
      VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
      VLC media player 0.9.8a-->C:\Program Files\VideoLAN\VLC\uninstall.exe
      Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
      Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
      Word Reader 5.4-->C:\PROGRA~1\Abdio\WORDRE~1\UNWISE.EXE C:\PROGRA~1\Abdio\WORDRE~1\INSTALL.LOG

      ======Security center information======

      AS: Windows Defender

      ======System event log======

      Computer Name: PC-de-Ophélie
      Event Code: 3004
      Message: L’agent de protection en temps réel Windows Defender a détecté des modifications. Microsoft vous recommande d’analyser les logiciels responsables de ces modifications, à la recherche de risques potentiels. Vous pouvez vous servir des informations relatives au fonctionnement de ces programmes pour autoriser ou non leur exécution, ou pour les supprimer de l’ordinateur. N’autorisez les modifications que si vous faites confiance au programme ou à l’éditeur de logiciel. Windows Defender ne peut pas annuler les modifications que vous autorisez.
      Pour plus d’informations, consultez les données suivantes :
      Non applicable
      ID d’analyse : {373476DA-84BF-4D3E-9D43-D9A2AA96222D}
      Utilisateur : PC-de-Ophélie\Ophélie
      Nom : Unknown
      ID :
      ID de gravité :
      ID de catégorie :
      Chemin d’accès trouvé : iemain:HKCU@S-1-5-21-1317888482-1263933886-2889319296-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page
      Type d’alerte : Logiciel non classifié
      Type de détection :
      Record Number: 83898
      Source Name: Microsoft-Windows-Windows Defender
      Time Written: 20100221101435.000000-000
      Event Type: Avertissement
      User:

      Computer Name: PC-de-Ophélie
      Event Code: 4001
      Message: Le Service d’autoconfiguration WLAN s’est arrêté correctement.

      Record Number: 83922
      Source Name: Microsoft-Windows-WLAN-AutoConfig
      Time Written: 20100221214834.833000-000
      Event Type: Avertissement
      User: AUTORITE NT\SYSTEM

      Computer Name: PC-de-Ophélie
      Event Code: 15016
      Message: Impossible d’initialiser le package de sécurité Kerberos pour l’authentification côté serveur. Le champ de données contient le numéro de l’erreur.
      Record Number: 83935
      Source Name: Microsoft-Windows-HttpEvent
      Time Written: 20100222172701.902327-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-Ophélie
      Event Code: 4001
      Message: Le Service d’autoconfiguration WLAN s’est arrêté correctement.

      Record Number: 84065
      Source Name: Microsoft-Windows-WLAN-AutoConfig
      Time Written: 20100222202049.220200-000
      Event Type: Avertissement
      User: AUTORITE NT\SYSTEM

      Computer Name: PC-de-Ophélie
      Event Code: 15016
      Message: Impossible d’initialiser le package de sécurité Kerberos pour l’authentification côté serveur. Le champ de données contient le numéro de l’erreur.
      Record Number: 84078
      Source Name: Microsoft-Windows-HttpEvent
      Time Written: 20100222202143.069929-000
      Event Type: Erreur
      User:

      =====Application event log=====

      Computer Name: PC-de-Ophélie
      Event Code: 10
      Message: Le filtre d’événement avec la requête « SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99 » n’a pas pu être réactivé dans l’espace de noms « //./root/CIMV2 » à cause de l’erreur 0x80041003. Les événements ne peuvent pas être délivrés à travers ce filtre tant que le problème ne sera pas corrigé.
      Record Number: 18818
      Source Name: Microsoft-Windows-WMI
      Time Written: 20100221101402.000000-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-Ophélie
      Event Code: 10
      Message: Le filtre d’événement avec la requête « SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99 » n’a pas pu être réactivé dans l’espace de noms « //./root/CIMV2 » à cause de l’erreur 0x80041003. Les événements ne peuvent pas être délivrés à travers ce filtre tant que le problème ne sera pas corrigé.
      Record Number: 18862
      Source Name: Microsoft-Windows-WMI
      Time Written: 20100222172837.000000-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-Ophélie
      Event Code: 1000
      Message: Application défaillante iexplore.exe, version 7.0.6001.18000, horodatage 0x47918f11, module défaillant unknown, version 0.0.0.0, horodatage 0x00000000, code d’exception 0xc0000005, décalage d’erreur 0x04e20994, ID du processus 0x1278, heure de début de l’application 0x01cab3e5e96d5b58.
      Record Number: 18874
      Source Name: Application Error
      Time Written: 20100222182732.000000-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-Ophélie
      Event Code: 1000
      Message: Application défaillante iexplore.exe, version 7.0.6001.18000, horodatage 0x47918f11, module défaillant FBStoolbar.dll, version 4.1.0.41, horodatage 0x4a82ccea, code d’exception 0xc0000005, décalage d’erreur 0x001738f7, ID du processus 0x199c, heure de début de l’application 0x01cab3ecb5420638.
      Record Number: 18877
      Source Name: Application Error
      Time Written: 20100222194758.000000-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-Ophélie
      Event Code: 10
      Message: Le filtre d’événement avec la requête « SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99 » n’a pas pu être réactivé dans l’espace de noms « //./root/CIMV2 » à cause de l’erreur 0x80041003. Les événements ne peuvent pas être délivrés à travers ce filtre tant que le problème ne sera pas corrigé.
      Record Number: 18902
      Source Name: Microsoft-Windows-WMI
      Time Written: 20100222202318.000000-000
      Event Type: Erreur
      User:

      =====Security event log=====

      Computer Name: PC-de-Ophélie
      Event Code: 4672
      Message: Privilèges spéciaux attribués à la nouvelle ouverture de session.

      Sujet :
      ID de sécurité : S-1-5-21-1317888482-1263933886-2889319296-1000
      Nom du compte : Ophélie
      Domaine du compte : PC-de-Ophélie
      ID d’ouverture de session : 0x353fc

      Privilèges : SeSecurityPrivilege
      SeTakeOwnershipPrivilege
      SeLoadDriverPrivilege
      SeBackupPrivilege
      SeRestorePrivilege
      SeDebugPrivilege
      SeSystemEnvironmentPrivilege
      SeImpersonatePrivilege
      Record Number: 23857
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20091204193718.089732-000
      Event Type: Succès de l'audit
      User:

      Computer Name: PC-de-Ophélie
      Event Code: 5032
      Message: Le Pare-feu Windows n’a pas pu notifier l’utilisateur qu’il a empêché une application d’accepter des connexions entrantes sur le réseau.

      Code d’erreur : 2
      Record Number: 23858
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20091204193728.814332-000
      Event Type: Échec de l'audit
      User:

      Computer Name: PC-de-Ophélie
      Event Code: 5032
      Message: Le Pare-feu Windows n’a pas pu notifier l’utilisateur qu’il a empêché une application d’accepter des connexions entrantes sur le réseau.

      Code d’erreur : 2
      Record Number: 23859
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20091204193728.814332-000
      Event Type: Échec de l'audit
      User:

      Computer Name: PC-de-Ophélie
      Event Code: 5032
      Message: Le Pare-feu Windows n’a pas pu notifier l’utilisateur qu’il a empêché une application d’accepter des connexions entrantes sur le réseau.

      Code d’erreur : 2
      Record Number: 23860
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20091204193728.814332-000
      Event Type: Échec de l'audit
      User:

      Computer Name: PC-de-Ophélie
      Event Code: 4648
      Message: Tentative d’ouverture de session en utilisant des informations d’identification explicites.

      Sujet :
      ID de sécurité : S-1-5-18
      Nom du compte : PC-DE-OPHÉLIE$
      Domaine du compte : WORKGROUP
      ID d’ouverture de session : 0x3e7
      GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

      Compte dont les informations d’identification ont été utilisées :
      Nom du compte : SYSTEM
      Domaine du compte : AUTORITE NT
      GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

      Serveur cible :
      Nom du serveur cible : localhost
      Informations supplémentaires : localhost

      Informations sur le processus :
      ID du processus : 0x270
      Nom du processus : C:\Windows\System32\services.exe

      Informations sur le réseau :
      Adresse du réseau : -
      Port : -

      Cet événement est généré lorsqu’un processus tente d’ouvrir une session pour un compte en spécifiant explicitement les informations d’identification de ce compte. Ceci se produit le plus souvent dans les configurations par lot comme les tâches planifiées, ou avec l’utilisation de la commande RUNAS.
      Record Number: 23861
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20091204194022.122932-000
      Event Type: Succès de l'audit
      User:

      ======Environment variables======

      "ComSpec"=%SystemRoot%\system32\cmd.exe
      "FP_NO_HOST_CHECK"=NO
      "OS"=Windows_NT
      "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Common Files\DivX Shared\;C:\Program Files\Samsung\Samsung PC Studio 3\;C:\Program Files\QuickTime\QTSystem\
      "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
      "PROCESSOR_ARCHITECTURE"=x86
      "TEMP"=%SystemRoot%\TEMP
      "TMP"=%SystemRoot%\TEMP
      "USERNAME"=SYSTEM
      "windir"=%SystemRoot%
      "PROCESSOR_LEVEL"=6
      "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
      "PROCESSOR_REVISION"=0f0d
      "NUMBER_OF_PROCESSORS"=2
      "TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
      "DFSTRACINGON"=FALSE
      "CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
      "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

      -----------------EOF-----------------
  2. Modérateur
    Très bien.
    De nombreux fichiers infectés sur le PC :

    Recherche avec Ad-Remover :
    Télécharge Ad-Remover ( de Cyrildu17 / C_XX ) sur ton bureau :
    = = = =>>> En cliquant ici <<<= = = =

    /!\ Déconnectes toi et fermes toutes applications en cours, désactive ton antivirus le temps de la manipulation/!\

    * Double clique sur le programme d’installation, et installe le dans son emplacement par défaut. (C:\Program files)
    * Clique droit sur l’icône Ad-remover située sur ton bureau puis sélectionne "Exécuter en tant qu’administrateur".
    * Réponds ‘Oui‘ au message d’alerte automatique.
    * Au menu principal choisi l’option ‘S‘ et tape ensuite [Entrée]
    * Poste le rapport qui apparaît à la fin.

    (Le rapport est sauvegardé aussi sous C:\Ad-report(date).log)
    (CTRL+A Pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)

    Note :

    "Process.exe", une composante de l’outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
    Il ne s’agit pas d’un virus, mais d’un utilitaire destiné à mettre fin à des processus.
    1. Modérateur
      1. re,

        .
        ======= RAPPORT D'AD-REMOVER 1.1.4.6_J | UNIQUEMENT XP/VISTA/7 =======
        .
        Mis à jour par C_XX le 05.02.2010 à 17:34
        Contact: AdRemover.contact@gmail.com
        Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
        .
        Lancé à: 22:01:48, 22/02/2010 | Mode Normal | Option: SCAN
        Exécuté de: C:\Ad-Remover\
        Système d'exploitation: Microsoft® Windows Vista™ HomePremium Service Pack 2 v6.0.6001
        Nom du PC: PC-DE-OPHLIE | Utilisateur actuel: Oph‚lie
        .
        ============== ÉLÉMENT(S) TROUVÉ(S) ==============
        .

        C:\Program Files\Mozilla FireFox\Components\AskSearch.js
        C:\Users\Public\MyWebTattoo.exe
        C:\Program Files\Agence Exclusive
        C:\Program Files\Fast Browser Search
        C:\Program Files\Search Guard Plus
        C:\Program Files\Search Guard PlusU
        C:\Program Files\SGPSA
        C:\Users\OPHLIE~1\AppData\Roaming\Agence Exclusive
        C:\Users\Oph‚lie\AppData\Local\Agence Exclusive
        .
        HKCU\software\AgenceExclusive
        HKCU\software\EoRezo
        HKCU\software\FBSearch
        HKCU\software\FunkyEmoticons
        HKCU\software\microsoft\internet explorer\searchscopes\{19F2B849-4ADE-4d4b-85F9-C31C643DBDE9}
        HKCU\software\microsoft\internet explorer\searchscopes\{CF739809-1C6C-47C0-85B9-569DBB141420}
        HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{1BB22D38-A411-4B13-A746-C2A4F4EC7344}
        HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{91C18ED5-5E1C-4AE5-A148-A861DE8C8E16}
        HKCU\software\SGPUpdater
        HKLM\software\AgenceExclusive
        HKLM\software\classes\AgenceBHO.AEBHO
        HKLM\software\classes\AgenceBHO.AEBHO.1
        HKLM\Software\Classes\AppID\{9B70CBA7-E01C-4e1f-B046-D13CD051A84B}
        HKLM\software\classes\appid\AgenceBHO.DLL
        HKLM\Software\Classes\CLSID\{0495F4D7-9FE3-4456-AA9D-1D57E78DF5F0}
        HKLM\Software\Classes\CLSID\{1BB22D38-A411-4B13-A746-C2A4F4EC7344}
        HKLM\Software\Classes\CLSID\{57CADC46-58FF-4105-B733-5A9F3FC9783C}
        HKLM\Software\Classes\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}
        HKLM\Software\Classes\CLSID\{F0626A63-410B-45E2-99A1-3F2475B2D695}
        HKLM\Software\Classes\CLSID\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
        HKLM\software\classes\ComObject.DeskbarEnabler
        HKLM\software\classes\ComObject.DeskbarEnabler.1
        HKLM\Software\Classes\Interface\{492D9495-CC24-4460-8856-CF52179A3C3D}
        HKLM\Software\Classes\TypeLib\{4509D3CC-B642-4745-B030-645B79522C6D}
        HKLM\Software\Classes\TypeLib\{77AA25E8-6083-4949-A831-9CB11861DC10}
        HKLM\Software\Classes\TypeLib\{D105A2C4-36DA-49AD-BDB1-34215B3A9ED9}
        HKLM\software\classes\URLSearchHook.ToolbarURLSearchHook
        HKLM\software\classes\URLSearchHook.ToolbarURLSearchHook.1
        HKLM\software\FunkyEmoticons
        HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E00ED7E4-C602-47b1-A8B0-A53B2685B4EC}
        HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{1BB22D38-A411-4B13-A746-C2A4F4EC7344}
        HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0495F4D7-9FE3-4456-AA9D-1D57E78DF5F0}
        HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
        HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Agence
        HKLM\software\microsoft\windows\currentversion\uninstall\Agence_is1
        HKLM\software\microsoft\windows\currentversion\uninstall\Search Guard Plus
        HKLM\software\microsoft\windows\currentversion\uninstall\Search Guard Plus Updater
        HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Update_is1
        HKU\s-1-5-21-1317888482-1263933886-2889319296-1000\software\AgenceExclusive
        HKU\s-1-5-21-1317888482-1263933886-2889319296-1000\software\EoRezo
        HKU\s-1-5-21-1317888482-1263933886-2889319296-1000\software\FBSearch
        HKU\s-1-5-21-1317888482-1263933886-2889319296-1000\software\FunkyEmoticons
        HKU\s-1-5-21-1317888482-1263933886-2889319296-1000\software\SGPUpdater
        .
        ============== Scan additionnel ==============
        .
        .
        * Internet Explorer Version 7.0.6001.18000 *
        .
        [HKEY_CURRENT_USER\..\Internet Explorer\Main]
        .
        Start Page: hxxp://y.lo.st
        Default_Page_URL: hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=040c&s=1&o=vp32&d=1208&m=imedia_d3610_fr
        Do404Search: 01000000
        Local Page: C:\Windows\system32\blank.htm
        Show_ToolBar: yes
        Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
        .
        [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
        .
        Start Page: hxxp://www.yoower.com/
        Default_Page_URL: hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=040c&s=1&o=vp32&d=1208&m=imedia_d3610_fr
        Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
        Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
        Delete_Temp_Files_On_Exit: yes
        Local Page: %SystemRoot%\system32\blank.htm
        .
        [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
        .
        Tabs: hxxp://www.fastbrowsersearch.com/new-tab/?v=18&tid={9834306E-EAC8-4ea3-ADFE-9FC11CE67BA0}
        .
        ============== Suspect (Cracks, Serials, ...) ==============
        .
        C:\Users\Oph‚lie\Favorites\Patch Anti mise … jour pour WLM 8.5.url
        .
        ===================================
        .
        5252 Octet(s) - C:\Ad-Report-SCAN[1].log
        4950 Octet(s) - C:\Ad-Report-SCAN[2].log
        .
        43624 Fichier(s) - C:\Users\OPHLIE~1\AppData\Local\Temp
        145 Fichier(s) - C:\Windows\Temp
        121 Fichier(s) - C:\Windows\Prefetch
        .
        1 Fichier(s) - C:\Ad-Remover\BACKUP
        0 Fichier(s) - C:\Ad-Remover\QUARANTINE
        .
        Fin à: 22:06:54 | 22/02/2010 - SCAN[2]
        .
        ============== E.O.F ==============
        .
      2. re,

        que dois-je faire maintenat que j fait une recherche avec Ad-Remover?
    2. Modérateur
      Une belle collection de virus !

      MyWebTattoo
      Agence Exclusive
      Fast Browser Search
      Search Guard Plus

      *******

      Suppression avec Ad-Remover :
      /!\ Déconnectes toi et fermes toutes applications en cours, désactive ton antivirus le temps de la manipulation/!\

      * Clique droit sur l’icône Ad-Remover située sur ton bureau puis sélectionne "Exécuter en tant qu’administrateur".
      * Au menu principal choisi l’option "L" et tape ensuite [Entrée]
      * Poste le rapport qui apparaît à la fin.

      (Le rapport est sauvegardé aussi sous C:\Ad-report(date).log)
      (CTRL+A Pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)

      Note :

      "Process.exe", une composante de l’outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
      Il ne s’agit pas d’un virus, mais d’un utilitaire destiné à mettre fin à des processus.
      1. Bonjour crapoulou, désolé du retard.

        j fait ad remover en tappant le L

        voici le rapport:

        ======= RAPPORT D'AD-REMOVER 1.1.4.6_J | UNIQUEMENT XP/VISTA/7 =======
        .
        Mis à jour par C_XX le 05.02.2010 à 17:34
        Contact: AdRemover.contact@gmail.com
        Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
        .
        Lancé à: 15:27:54, 23/02/2010 | Mode Normal | Option: CLEAN
        Exécuté de: C:\Ad-Remover\
        Système d'exploitation: Microsoft® Windows Vista™ HomePremium Service Pack 2 v6.0.6001
        Nom du PC: PC-DE-OPHLIE | Utilisateur actuel: Oph‚lie
        .
        ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
        .

        C:\Users\Public\MyWebTattoo.exe
        C:\Program Files\Agence Exclusive
        C:\Program Files\Fast Browser Search
        C:\Program Files\Search Guard Plus - ... [b]ERREUR SUPPRESSION !!/b
        C:\Program Files\Search Guard PlusU - ... [b]ERREUR SUPPRESSION !!/b
        C:\Program Files\SGPSA
        C:\Users\OPHLIE~1\AppData\Roaming\Agence Exclusive
        C:\Users\Oph‚lie\AppData\Local\Agence Exclusive

        (!) -- Fichiers temporaires supprimés.

        .
        HKCU\software\AgenceExclusive
        HKCU\software\FBSearch
        HKCU\software\FunkyEmoticons
        HKCU\software\microsoft\internet explorer\searchscopes\{19F2B849-4ADE-4d4b-85F9-C31C643DBDE9}
        HKCU\software\microsoft\internet explorer\searchscopes\{CF739809-1C6C-47C0-85B9-569DBB141420}
        HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{1BB22D38-A411-4B13-A746-C2A4F4EC7344}
        HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{91C18ED5-5E1C-4AE5-A148-A861DE8C8E16}
        HKCU\software\SGPUpdater
        HKLM\software\AgenceExclusive
        HKLM\software\classes\AgenceBHO.AEBHO
        HKLM\software\classes\AgenceBHO.AEBHO.1
        HKLM\Software\Classes\AppID\{9B70CBA7-E01C-4e1f-B046-D13CD051A84B}
        HKLM\software\classes\appid\AgenceBHO.DLL
        HKLM\Software\Classes\CLSID\{0495F4D7-9FE3-4456-AA9D-1D57E78DF5F0}
        HKLM\Software\Classes\CLSID\{1BB22D38-A411-4B13-A746-C2A4F4EC7344}
        HKLM\Software\Classes\CLSID\{57CADC46-58FF-4105-B733-5A9F3FC9783C}
        HKLM\Software\Classes\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}
        HKLM\Software\Classes\CLSID\{F0626A63-410B-45E2-99A1-3F2475B2D695}
        HKLM\Software\Classes\CLSID\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
        HKLM\software\classes\ComObject.DeskbarEnabler
        HKLM\software\classes\ComObject.DeskbarEnabler.1
        HKLM\Software\Classes\Interface\{492D9495-CC24-4460-8856-CF52179A3C3D}
        HKLM\Software\Classes\TypeLib\{4509D3CC-B642-4745-B030-645B79522C6D}
        HKLM\Software\Classes\TypeLib\{77AA25E8-6083-4949-A831-9CB11861DC10}
        HKLM\Software\Classes\TypeLib\{D105A2C4-36DA-49AD-BDB1-34215B3A9ED9}
        HKLM\software\classes\URLSearchHook.ToolbarURLSearchHook
        HKLM\software\classes\URLSearchHook.ToolbarURLSearchHook.1
        HKLM\software\FunkyEmoticons
        HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E00ED7E4-C602-47b1-A8B0-A53B2685B4EC}
        HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{1BB22D38-A411-4B13-A746-C2A4F4EC7344}
        HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0495F4D7-9FE3-4456-AA9D-1D57E78DF5F0}
        HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
        HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Agence
        HKLM\software\microsoft\windows\currentversion\uninstall\Agence_is1
        HKLM\software\microsoft\windows\currentversion\uninstall\Search Guard Plus
        HKLM\software\microsoft\windows\currentversion\uninstall\Search Guard Plus Updater
        HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Update_is1
        .
        ============== Scan additionnel ==============
        .
        .
        * Internet Explorer Version 7.0.6001.18000 *
        .
        [HKEY_CURRENT_USER\..\Internet Explorer\Main]
        .
        Start Page: hxxp://fr.msn.com/
        Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
        Do404Search: 01000000
        Local Page: C:\Windows\system32\blank.htm
        Show_ToolBar: yes
        Default_search_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
        Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
        .
        [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
        .
        Start Page: hxxp://fr.msn.com/
        Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
        Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
        Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
        Delete_Temp_Files_On_Exit: yes
        Local Page: %SystemRoot%\system32\blank.htm
        Search bar: hxxp://search.msn.com/spbasic.htm
        .
        [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
        .
        Tabs: res://ieframe.dll/tabswelcome.htm
        .
        ============== Suspect (Cracks, Serials, ...) ==============
        .
        C:\Users\Oph‚lie\Favorites\Patch Anti mise … jour pour WLM 8.5.url
        .
        ===================================
        .
        4638 Octet(s) - C:\Ad-Report-CLEAN[1].log
        5252 Octet(s) - C:\Ad-Report-SCAN[1].log
        5295 Octet(s) - C:\Ad-Report-SCAN[2].log
        .
        43387 Fichier(s) - C:\Users\OPHLIE~1\AppData\Local\Temp
        123 Fichier(s) - C:\Windows\Temp
        13 Fichier(s) - C:\Windows\Prefetch
        .
        20 Fichier(s) - C:\Ad-Remover\BACKUP
        84 Fichier(s) - C:\Ad-Remover\QUARANTINE
        .
        Fin à: 15:31:12 | 23/02/2010 - CLEAN[1]
        .
        ============== E.O.F ==============
        .
    3. Modérateur
      désolé du retard. => Personne ne pointe, ne t'en fais pas : ni toi, ni moi ;-).

      Supprime manuellement ces dossiers :
      C:\Program Files\Search Guard Plus
      C:\Program Files\Search Guard PlusU


      ********

      Tu es infecté par un ver qui se propage dans ton ordinateur par support amovibles (clé USB, disquettes, appareils photos numériques, disques durs externes, …)

      Télécharge et installe UsbFix de C_XX & El desaparecido :
      = = = = >>> En cliquant ici <<< = = = =

      Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptibles d’avoir été infectés sans les ouvrir !

      * Clique droit sur le raccourci UsbFix présent sur ton bureau et sélectionne "Exécuter en tant qu’administrateur".
      * Choisis ensuite l’option 1 (Recherche)
      * Laisse travailler l’outil.
      * Ensuite poste le rapport UsbFix.txt qui apparaîtra.

      Notes :
      - Le rapport UsbFix.txt est sauvegardé a la racine du disque. (C:\UsbFix.txt)
      (CTRL+A Pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller sur le forum).
      - "Process.exe", une composante de l’outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s’agit pas d’un virus, mais d’un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d’où l’alerte émise par ces antivirus.
      1. rebonsoir,

        Voici le rapport :

        ############################## | UsbFix V6.097 |

        User : Ophélie (Administrateurs) # PC-DE-OPHÉLIE
        Update on 20/02/2010 by El Desaparecido , C_XX & Chimay8
        Start at: 20:56:57 | 23/02/2010
        Website : http://pagesperso-orange.fr/NosTools/index.html
        Contact : FindyKill.Contact@gmail.com

        Intel(R) Pentium(R) Dual CPU E2220 @ 2.40GHz
        Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
        Internet Explorer 7.0.6001.18000
        Windows Firewall Status : Enabled

        C:\ -> Disque fixe local # 583,17 Go (430,38 Go free) [OS] # NTFS
        D:\ -> Disque CD-ROM

        ############################## | Processus actifs |

        C:\Windows\System32\smss.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\wininit.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\services.exe
        C:\Windows\system32\lsass.exe
        C:\Windows\system32\lsm.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\winlogon.exe
        C:\Windows\system32\nvvsvc.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\SLsvc.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\rundll32.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\Windows\system32\WUDFHost.exe
        C:\Windows\System32\spoolsv.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\Program Files\PACKARDBELL\Packard Bell Recovery Management\Service\ETService.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\WinService.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\SearchIndexer.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\Windows\system32\taskeng.exe
        C:\Windows\system32\taskeng.exe
        C:\Windows\system32\Dwm.exe
        C:\Windows\Explorer.EXE
        C:\Program Files\Windows Defender\MSASCui.exe
        C:\Windows\RtHDVCpl.exe
        C:\Program Files\PACKARD BELL\SetUpMyPC\SmpSys.exe
        C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
        C:\Program Files\Alwil Software\Avast4\ashDisp.exe
        C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
        C:\Program Files\Java\jre6\bin\jusched.exe
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\Windows\ehome\ehtray.exe
        C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
        C:\Philips\GoGear SA018 Device Manager\GoGear_SA018_DeviceManager.exe
        C:\Program Files\OpenOffice.org 3\program\soffice.exe
        C:\Program Files\OpenOffice.org 3\program\soffice.bin
        C:\Windows\ehome\ehmsas.exe
        C:\Program Files\iPod\bin\iPodService.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Windows Live\Messenger\usnsvc.exe
        C:\Windows\system32\conime.exe
        C:\Windows\system32\wbem\wmiprvse.exe

        ################## | Elements infectieux |

        C:\Windows\msnimport.exe

        ################## | Registre |

        ################## | Mountpoints2 |

        HKCU\..\..\Explorer\MountPoints2\{b10d0f84-069c-11df-916e-002197a45a20}
        shell\AutoRun\command =C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL E:\NoLimit.exe

        HKCU\..\..\Explorer\MountPoints2\{b347922b-a1fc-11de-b4b1-002197a45a20}
        shell\AutoRun\command =C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL copy.exe

        HKCU\..\..\Explorer\MountPoints2\{b99b1388-ea62-11de-b09e-002197a45a20}
        shell\verb\command =explorer https://www.p4c.philips.com/files/s/sa018102k_02/sa018102k_02_pal_eng.exe

        HKCU\..\..\Explorer\MountPoints2\{edd46403-13d3-11de-8771-002197a45a20}
        shell\Auto\command =RavMonE.exe e
        shell\AutoRun\command =C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RavMonE.exe e

        ################## | Vaccin |

        (!) Cet ordinateur n'est pas vacciné !

        ################## | ! Fin du rapport # UsbFix V6.097 ! |
    4. Modérateur
      Nettoyage avec UsbFix :

      Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptibles d’avoir été infectés sans les ouvrir !

      * Relance UsbFix par un clic droit sur le raccourci UsbFix présent sur ton bureau et en sélectionnant "Exécuter en tant qu’administrateur".
      * Choisis l’option 2 (Suppression)
      * Ton bureau disparaîtra et le PC redémarrera.
      * Au redémarrage, UsbFix scannera ton PC. Laisse travailler l’outil.
      * Ensuite poste l’intégralité du rapport UsbFix.txt qui apparaîtra avec le bureau.

      Note :
      Le rapport UsbFix.txt est sauvegardé a la racine du disque. (C:\UsbFix.txt)

      ********

      Télécharge Malwarebytes’ Anti-Malware
      = = = = >>> En cliquant ici <<< = = = =

      - Enregistre le sur le bureau
      - Double-clique sur le fichier téléchargé pour lancer le processus d’installation
      - Lorsqu’il te le sera demandé, mets à jour Malwarebytes anti malware
      - Si le pare-feu demande l’autorisation de se connecter pour malwarebytes, acceptes
      - Une fois la mise à jour terminée, ferme Malwarebytes
      - Double-clique sur l’icône de malwarebytes pour le relancer
      - Dans l’onglet, Recherche, probablement ouvert par défaut,
      - Sélectionne Exécuter un examen complet
      - Clique sur Rechercher
      - Le scan démarre
      - A la fin de l’analyse, un message s’affiche : L’examen s’est terminé normalement. Cliquez sur ‘Afficher les résultats’ pour afficher tous les objets trouvés.
      - Clique sur Ok pour poursuivre.
      - Si des malwares ont été détectés, cliques sur Afficher les résultats
      - Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
      - Malwarebytes va ouvrir le bloc-notes et y copier le rapport d’analyse.
      - Rends toi dans l’onglet rapport/log
      - Tu clique dessus pour l’afficher une fois affiché
      - Tu clique sur édition en haut du bloc notes, et puis sur sélectionner tout
      - Tu reclique sur édition et puis sur copier et tu reviens sur le forum et dans ta réponse
      - Tu clique droit dans le cadre de la réponse et coller

      Si tu as besoin d’aide regarde ce tutorial ICI
      1. re, Voici le rapport, maintenat je m'attaque a MALWEREBYTES

        ############################## | UsbFix V6.097 |

        User : Ophélie (Administrateurs) # PC-DE-OPHÉLIE
        Update on 20/02/2010 by El Desaparecido , C_XX & Chimay8
        Start at: 21:08:52 | 23/02/2010
        Website : http://pagesperso-orange.fr/NosTools/index.html
        Contact : FindyKill.Contact@gmail.com

        Intel(R) Pentium(R) Dual CPU E2220 @ 2.40GHz
        Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
        Internet Explorer 7.0.6001.18000
        Windows Firewall Status : Enabled

        C:\ -> Disque fixe local # 583,17 Go (430,3 Go free) [OS] # NTFS
        D:\ -> Disque CD-ROM

        ############################## | Processus actifs |

        C:\Windows\System32\smss.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\wininit.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\services.exe
        C:\Windows\system32\lsass.exe
        C:\Windows\system32\lsm.exe
        C:\Windows\system32\winlogon.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\nvvsvc.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\LogonUI.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\SLsvc.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\rundll32.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\Windows\system32\WUDFHost.exe
        C:\Windows\System32\spoolsv.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\Program Files\PACKARDBELL\Packard Bell Recovery Management\Service\ETService.exe
        C:\Program Files\Google\Update\GoogleUpdate.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\WinService.exe
        C:\Program Files\Google\Update\GoogleUpdate.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\SearchIndexer.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\Windows\system32\wbem\wmiprvse.exe
        C:\Windows\system32\DllHost.exe
        C:\Windows\system32\userinit.exe
        C:\Windows\system32\taskeng.exe
        C:\Windows\system32\Dwm.exe
        C:\Windows\system32\taskeng.exe
        C:\Program Files\Google\Update\GoogleUpdate.exe
        C:\Windows\Explorer.EXE
        C:\Windows\system32\runonce.exe
        C:\Windows\system32\conime.exe
        C:\Windows\system32\DllHost.exe
        C:\Windows\system32\DllHost.exe

        ################## | Elements infectieux |

        Supprimé ! C:\Windows\msnimport.exe
        Supprimé ! C:\$Recycle.Bin\S-1-5-21-1317888482-1263933886-2889319296-1000
        Supprimé ! C:\$Recycle.Bin\S-1-5-21-1317888482-1263933886-2889319296-500
        Supprimé ! C:\$Recycle.Bin\S-1-5-21-1519845611-2888426927-2721905098-500

        ################## | Registre |

        ################## | Mountpoints2 |

        Supprimé ! HKCU\...\Explorer\MountPoints2\{b10d0f84-069c-11df-916e-002197a45a20}\Shell\AutoRun\Command
        Supprimé ! HKCU\...\Explorer\MountPoints2\{b347922b-a1fc-11de-b4b1-002197a45a20}\Shell\AutoRun\Command
        Supprimé ! HKCU\...\Explorer\MountPoints2\{b99b1388-ea62-11de-b09e-002197a45a20}\Shell\verb\Command
        Supprimé ! HKCU\...\Explorer\MountPoints2\{edd46403-13d3-11de-8771-002197a45a20}\Shell\Auto\Command

        ################## | Listing des fichiers présent |

        [23/02/2010 15:31|--a------|5072] C:\Ad-Report-CLEAN[1].log
        [22/02/2010 21:29|--a------|5252] C:\Ad-Report-SCAN[1].log
        [22/02/2010 22:06|--a------|5295] C:\Ad-Report-SCAN[2].log
        [18/09/2006 22:43|--a------|24] C:\autoexec.bat
        [21/01/2008 03:24|-rahs----|333203] C:\bootmgr
        [13/11/2008 14:33|-ra-s----|8192] C:\BOOTSECT.BAK
        [18/09/2006 22:43|--a------|10] C:\config.sys
        [27/01/2009 17:46|--a------|2382] C:\ExtractLog.txt
        [11/02/2009 15:24|-rahs----|0] C:\IO.SYS
        [11/02/2009 15:24|-rahs----|0] C:\MSDOS.SYS
        [29/02/2004 16:44|--a------|52576] C:\orange.bmp
        [?|?|?] C:\pagefile.sys
        [13/11/2008 06:30|--a------|426] C:\RHDSetup.log
        [12/03/2009 16:32|--a------|159] C:\Setup.log
        [17/06/2009 20:09|--a------|5392808] C:\Tom Frager & Gwayav - Lady Melody(1).mp3
        [23/02/2010 21:11|--a------|4231] C:\UsbFix.txt

        ################## | Vaccination |

        # C:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).

        ################## | Upload |

        Veuillez envoyer le fichier : C:\UsbFix_Upload_Me_PC-de-Oph‚lie.zip : https://www.ionos.fr/?affiliate_id=77097
        Merci pour votre contribution .

        ################## | ! Fin du rapport # UsbFix V6.097 ! |
      2. je n'arrive pas a retrouvé le rapport :

        pour que je puisse l'envoyé a upload?
        comment faire??
    5. Modérateur
      Il est ici :
      C:\UsbFix_Upload_Me_PC-de-Oph‚lie.zip
      Tu vas sur le site, sélectionne ce fichier et l'envoie.
      1. Bonjour,

        Ca va?

        C bon j'ai retrouvé le fichier, je les renomé pour etre sur de le retrouvé.
        Es ce qu'il doivent me répondre?
        la je suis entrain de faire anti malwayre car hier soir trop naze.
        voila je tenvoie le résumé tout a leur.
        Encore merci de ton aide.
    6. Modérateur
      Non, ils ne te répondront pas.
      Si tu l'as envoyé, tu peux le supprimer.
      1. j fait le test malwary

        voici le rapport :

        Malwarebytes' Anti-Malware 1.44
        Version de la base de données: 3781
        Windows 6.0.6001 Service Pack 1
        Internet Explorer 7.0.6001.18000

        24/02/2010 19:20:17
        mbam-log-2010-02-24 (19-20-17).txt

        Type de recherche: Examen complet (C:\|)
        Eléments examinés: 283375
        Temps écoulé: 39 minute(s), 10 second(s)

        Processus mémoire infecté(s): 0
        Module(s) mémoire infecté(s): 0
        Clé(s) du Registre infectée(s): 0
        Valeur(s) du Registre infectée(s): 0
        Elément(s) de données du Registre infecté(s): 0
        Dossier(s) infecté(s): 0
        Fichier(s) infecté(s): 0

        Processus mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Module(s) mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Clé(s) du Registre infectée(s):
        (Aucun élément nuisible détecté)

        Valeur(s) du Registre infectée(s):
        (Aucun élément nuisible détecté)

        Elément(s) de données du Registre infecté(s):
        (Aucun élément nuisible détecté)

        Dossier(s) infecté(s):
        (Aucun élément nuisible détecté)

        Fichier(s) infecté(s):
        (Aucun élément nuisible détecté)

        j un de mes contact msn ki a du recevoir un trucs bizarre de ma part style clike sur le lien pour voir ta foto ou un trucs dans le genre, elle la recu ojourdui a 15h45 alors ke jété en hors ligne?
        es ce kil y a possibilité que j'ai encore un virus??
    7. Modérateur
      On va regarder.
      Poste un nouveau rapport RSIT stp.
      1. bonsoir,

        Voici le rapport RSIT:

        Logfile of random's system information tool 1.06 (written by random/random)
        Run by Ophélie at 2010-02-25 18:43:08
        Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
        System drive C: has 441 GB (74%) free of 597 GB
        Total RAM: 3071 MB (61% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 18:43:26, on 25/02/2010
        Platform: Windows Vista SP1 (WinNT 6.00.1905)
        MSIE: Internet Explorer v7.00 (7.00.6001.18000)
        Boot mode: Normal

        Running processes:
        C:\Windows\system32\taskeng.exe
        C:\Windows\system32\Dwm.exe
        C:\Windows\Explorer.EXE
        C:\Program Files\Windows Defender\MSASCui.exe
        C:\Windows\RtHDVCpl.exe
        C:\Program Files\PACKARD BELL\SetUpMyPC\SmpSys.exe
        C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
        C:\Program Files\Alwil Software\Avast4\ashDisp.exe
        C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
        C:\Program Files\Java\jre6\bin\jusched.exe
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\Windows\ehome\ehtray.exe
        C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
        C:\Philips\GoGear SA018 Device Manager\GoGear_SA018_DeviceManager.exe
        C:\Program Files\OpenOffice.org 3\program\soffice.exe
        C:\Windows\ehome\ehmsas.exe
        C:\Program Files\OpenOffice.org 3\program\soffice.bin
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Users\Ophélie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VUOUVISH\RSIT[1].exe
        C:\Program Files\trend micro\Ophélie.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.fr/
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
        R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll (file missing)
        O1 - Hosts: ::1 localhost
        O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
        O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
        O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
        O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
        O4 - HKLM\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetupMyPC\SmpSys.exe
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
        O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\OrangeHSS\Systray\SystrayApp.exe"
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKLM\..\Run: [ContentTransferWMDetector.exe] C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
        O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
        O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /F "C:\Windows\TEMP\E_S7658.tmp" /EF "HKLM"
        O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\PACKARD BELL\SetUpMyPC\SmpSys.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
        O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
        O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
        O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
        O4 - Global Startup: NETGEAR WG111v2 Smart Wizard.lnk = ?
        O4 - Global Startup: Philips GoGear SA018 Device Manager.lnk = ?
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
        O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
        O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
        O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
        O13 - Gopher Prefix:
        O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
        O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
        O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
        O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\PACKARDBELL\Packard Bell Recovery Management\Service\ETService.exe
        O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
        O23 - Service: Google Desktop Manager 5.9.911.3589 (GoogleDesktopManager-110309-193829) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
        O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
        O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
        O23 - Service: SCM_Service - Unknown owner - C:\Windows\System32\WinService.exe
    8. Modérateur
      Pour supprimer un service sous Vista :
      Clique sur Démarrer puis tape cmd dans la barre de recherche.
      Valide par [Ctrl]+[Shift]+[Entrée]
      sc stop SCM_Service
      Puis [Entrée].
      sc delete SCM_Service
      Tape [Entrée].
      Ferme ensuite la fenêtre noire.

      *******

      Vérifie que ce fichier soit absent :
      C:\Windows\System32\WinService.exe

      ******

      Désinstalle Avast 4.8 pour installer la dernière version : 5.0.
      Mets le à jour et fais une analyse complète du système.
      1. je te remercie de ta pacience.

        je n'ai pas retrouvé winservice.

        je vais désinstallé avast 4.8 et installé le 5 faire une analyse et après c bon je repars sur de bonne base??

        si j tjr se virus sur msn es ce que je peu le désinstallé et le réinstallé ca enléveré peu etre le virus??

        je voulais savoir ossi une otre petite question si tu ne sais pas c pas grave.

        j essyé de téléchargé sur liberty land il y a kelke jours, jarive a téléchargé que la moitié des film ou alors que qeulque minutes?
    9. Modérateur
      Évite le langage SMS stp.

      si j tjr se virus sur msn es ce que je peu le désinstallé et le réinstallé ca enléveré peu etre le virus?? 

      Malheureusement non.
      Le souci, c'est que je nois rien donc si le problème persiste, on fera des analyses complémentaires.

      Aucune idée pour l'autre souci.

      Poste le rapport d'Avast quand d c'est terminé.
      1. Bonsoir Crapoulou !

        Ca va?

        Désolé pour le retard mais pas mal prise par mon travail.

        Alors j'ai désinstallé avast 4.8 ou autre, et j installé la 5.0 c une icone orange.

        J'ai fait un scan, voici le résultat du scan :

        C:\ACER\Preload\Autorun\APP\Nero 8 Essentials\Installation\Data\E4060BF5.cab]rootFEAA0a71.img]root.img

        Ereur: le fichier et une bombe de décompression(Décompression bombe).(42110)
    10. Modérateur
      Euh... n'ouvre surtout pas ce fichier concerné.
      Supprime le si ce n'est pas déjà fait.

      ******

      Tu l'avais mis en jour et fais une analyse complète du système ?
      Rien d'autre de détecté ?
      1. Bonjour crapoulou,

        Je te remercie beaucoup pour tes conseil, plus aucun virus appriorie.
        Encore 1000 mille.
        Bonne fin de journée.
        Bon courage
    11. Modérateur
      C'est gentil mais on n'a pas tout à fait terminé.
      Poste un dernier rapport RSIT pour vérification stp.
      1. Bonsoir, désolé du retard mais je ne suis pas beaucoup sur l'ordi en ce moment.
        Beaucoup de travail.
        Voici le rapport rsi

        Logfile of random's system information tool 1.06 (written by random/random)
        Run by Ophélie at 2010-03-08 18:50:26
        Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
        System drive C: has 441 GB (74%) free of 597 GB
        Total RAM: 3071 MB (61% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 18:50:39, on 08/03/2010
        Platform: Windows Vista SP1 (WinNT 6.00.1905)
        MSIE: Internet Explorer v7.00 (7.00.6001.18000)
        Boot mode: Normal

        Running processes:
        C:\Windows\system32\Dwm.exe
        C:\Windows\Explorer.EXE
        C:\Windows\system32\taskeng.exe
        C:\Program Files\Windows Defender\MSASCui.exe
        C:\Windows\RtHDVCpl.exe
        C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
        C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
        C:\Program Files\Alwil Software\Avast5\AvastUI.exe
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\Program Files\PACKARD BELL\SetUpMyPC\SmpSys.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\Windows\ehome\ehtray.exe
        C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
        C:\Program Files\OpenOffice.org 3\program\soffice.exe
        C:\Windows\ehome\ehmsas.exe
        C:\Program Files\OpenOffice.org 3\program\soffice.bin
        C:\Program Files\Internet Explorer\IEUser.exe
        C:\Windows\system32\Macromed\Flash\FlashUtil10e.exe
        C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Users\Ophélie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VUOUVISH\RSIT[1].exe
        C:\Program Files\trend micro\Ophélie.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
        R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll (file missing)
        O1 - Hosts: ::1 localhost
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
        O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
        O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
        O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
        O4 - HKLM\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetupMyPC\SmpSys.exe
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
        O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\OrangeHSS\Systray\SystrayApp.exe"
        O4 - HKLM\..\Run: [ContentTransferWMDetector.exe] C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
        O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
        O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /F "C:\Windows\TEMP\E_S7658.tmp" /EF "HKLM"
        O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
        O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\PACKARD BELL\SetUpMyPC\SmpSys.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
        O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
        O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
        O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
        O4 - Global Startup: NETGEAR WG111v2 Smart Wizard.lnk = ?
        O4 - Global Startup: Philips GoGear SA018 Device Manager.lnk = ?
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
        O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
        O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
        O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
        O13 - Gopher Prefix:
        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
        O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
        O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
        O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
        O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
        O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
        O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\PACKARDBELL\Packard Bell Recovery Management\Service\ETService.exe
        O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
        O23 - Service: Google Desktop Manager 5.9.911.3589 (GoogleDesktopManager-110309-193829) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
        O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
        O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
    12. Désolé je n'est pas du le posté entier le rapport

      Logfile of random's system information tool 1.06 (written by random/random)
      Run by Ophélie at 2010-03-08 18:50:26
      Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
      System drive C: has 441 GB (74%) free of 597 GB
      Total RAM: 3071 MB (61% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 18:50:39, on 08/03/2010
      Platform: Windows Vista SP1 (WinNT 6.00.1905)
      MSIE: Internet Explorer v7.00 (7.00.6001.18000)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Windows\system32\taskeng.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Windows\RtHDVCpl.exe
      C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
      C:\Program Files\Alwil Software\Avast5\AvastUI.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\PACKARD BELL\SetUpMyPC\SmpSys.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Windows\ehome\ehtray.exe
      C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
      C:\Program Files\OpenOffice.org 3\program\soffice.exe
      C:\Windows\ehome\ehmsas.exe
      C:\Program Files\OpenOffice.org 3\program\soffice.bin
      C:\Program Files\Internet Explorer\IEUser.exe
      C:\Windows\system32\Macromed\Flash\FlashUtil10e.exe
      C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Users\Ophélie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VUOUVISH\RSIT[1].exe
      C:\Program Files\trend micro\Ophélie.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.fr/
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll (file missing)
      O1 - Hosts: ::1 localhost
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
      O4 - HKLM\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetupMyPC\SmpSys.exe
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
      O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\OrangeHSS\Systray\SystrayApp.exe"
      O4 - HKLM\..\Run: [ContentTransferWMDetector.exe] C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
      O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /F "C:\Windows\TEMP\E_S7658.tmp" /EF "HKLM"
      O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\PACKARD BELL\SetUpMyPC\SmpSys.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
      O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
      O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
      O4 - Global Startup: NETGEAR WG111v2 Smart Wizard.lnk = ?
      O4 - Global Startup: Philips GoGear SA018 Device Manager.lnk = ?
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
      O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
      O13 - Gopher Prefix:
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
      O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
      O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\PACKARDBELL\Packard Bell Recovery Management\Service\ETService.exe
      O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      O23 - Service: Google Desktop Manager 5.9.911.3589 (GoogleDesktopManager-110309-193829) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
      1. Modérateur
        Qui t'a fait utilisé STFix le 22/02/2010 ?

        Analyse ce fichier :
        C:\Windows\System32\WinService.exe
        Ici :
        https://www.virustotal.com/gui/
        Si le fichier a déjà été analysé, réanalyse-le.
        Poste le rapport qui s'affichera à l'écran en fin d'analyse (liste des antivirus)...
        1. a-squared 4.5.0.50 2010.03.08 -
          AhnLab-V3 5.0.0.2 2010.03.07 -
          AntiVir 8.2.1.180 2010.03.08 -
          Antiy-AVL 2.0.3.7 2010.03.08 -
          Authentium 5.2.0.5 2010.03.08 -
          Avast 4.8.1351.0 2010.03.07 -
          Avast5 5.0.332.0 2010.03.07 -
          AVG 9.0.0.787 2010.03.08 -
          BitDefender 7.2 2010.03.08 -
          CAT-QuickHeal 10.00 2010.03.06 -
          ClamAV 0.96.0.0-git 2010.03.08 -
          Comodo 4091 2010.02.28 -
          DrWeb 5.0.1.12222 2010.03.08 -
          eSafe 7.0.17.0 2010.03.08 -
          eTrust-Vet 35.2.7345 2010.03.08 -
          F-Prot 4.5.1.85 2010.03.08 -
          F-Secure 9.0.15370.0 2010.03.08 -
          Fortinet 4.0.14.0 2010.03.07 -
          GData 19 2010.03.08 -
          Ikarus T3.1.1.80.0 2010.03.07 -
          Jiangmin 13.0.900 2010.03.08 -
          K7AntiVirus 7.10.992 2010.03.08 -
          Kaspersky 7.0.0.125 2010.03.08 -
          McAfee 5914 2010.03.08 -
          McAfee+Artemis 5914 2010.03.08 -
          McAfee-GW-Edition 6.8.5 2010.03.08 -
          Microsoft 1.5502 2010.03.08 -
          NOD32 4925 2010.03.08 -
          Norman 6.04.08 2010.03.08 -
          nProtect 2009.1.8.0 2010.03.07 -
          Panda 10.0.2.2 2010.03.07 -
          PCTools 7.0.3.5 2010.03.04 -
          Prevx 3.0 2010.03.08 -
          Rising 22.37.06.04 2010.03.07 -
          Sophos 4.51.0 2010.03.07 -
          Sunbelt 5780 2010.03.07 -
          Symantec 20091.2.0.41 2010.03.07 -
          TheHacker 6.5.1.9.223 2010.03.07 -
          TrendMicro 9.120.0.1004 2010.03.07 -
          VBA32 3.12.12.2 2010.03.05 -
          ViRobot 2010.3.5.2214 2010.03.05 -
          VirusBuster 5.0.27.0 2010.03.06 -
          Information additionnelle
          File size: 305 bytes
          MD5...: ce6090d23ab2eb844671222730eb3379
          SHA1..: 01306354cbcc99aa862fb45ee502b33010a78697
          SHA256: 24703a9c55f87d1e2ed4719298579ec2af0cd132ef1874e96fb91f408f5961cd
          ssdeep: 6:+ZPUrOBzjF/Ma5yzvdPC4OfpK14OfpKG/ULRuXi5X:+ZPD1j4JPCxaxXUNsi5X

          PEiD..: -
          PEInfo: -
          RDS...: NSRL Reference Data Set
          -
          pdfid.: -
          trid..: Unknown!
          sigcheck:
          publisher....: n/a
          copyright....: n/a
          product......: n/a
          description..: n/a
          original name: n/a
          internal name: n/a
          file version.: n/a
          comments.....: n/a
          signers......: -
          signing date.: -
          verified.....: Unsigned
        2. je ne sais pas qui ma fait utilisé.

          car personne ma dit de me servir de ca.

          car c quoi ce truc système 32...

          tu sais j'y connais rien peut etre que c 'est moi qui es touché a quelque chose.

          car j'essaie d'activé javascript mais je n'y arrive pas.
        3. Modérateur
          @ophelieJavascript, c'est un bug du site.
          Supprime le dossier ST_Fix à la racine du disque : C:\
        4. @crapoulouBonsoir,

          Ca y es j'ai supprimé st fix.

          Je te remercie encore beaucoup.

          Très bonne soirée.
      2. Modérateur
        On n'a pas tout à fait terminé.

        a pars javascript qui beug depuis 2 mois je peu rien faire du tout.
        Qu'entends-tu par là ?
        1. Voila quand je veut regardé une vidéo sur you tube ca me mets ca :

          Bonjour, vous avez désactivé JavaScript ou bien vous avez une ancienne version d'Adobe Flash Player. Télécharger la dernière version de Flash Player .

          j tout regardé et cherché je trouve rien qui bloque.

          alors je me demande si c 'est pas vista tout simplement?
      3. Modérateur
        Je ne pense pas que ce soit Vista mais plutôt un souci avec ton navigateur Internet.

        Tu as Internet Explorer, essaye avec Firefox.

        *******

        Lance Hijackthis par clic droit, `Exécuter en tant qu'administrateur`.
        Il se situe ici :
        C:\Program Files\trend micro\Ophélie.exe

        Clique sur "Do a system scan only".
        Coche ces lignes :
        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
        O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
        O4 - Global Startup: NETGEAR WG111v2 Smart Wizard.lnk = ?
        O4 - Global Startup: Philips GoGear SA018 Device Manager.lnk = ?
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
        O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

        Clique ensuite sur "Fix checked".
        Ferme Hijackthis.

        ***********

        Pour supprimer toutes les traces des logiciels qui ont servi à traiter les infections spécifiques :

        Télécharge Toolscleaner sur ton Bureau
        = = = =>>> En cliquant ici <<<= = = =
        * Clique droit sur ToolsCleaner2.exe et clique sur "Exécuter en tant qu'administrateur" pour le lancer. Laisse le travailler (même s'il est écrit "Ne répond plus").
        * Clique sur Recherche et laisse le scan se terminer.
        * Clique sur Suppression pour finaliser.
        * Tu peux, si tu le souhaites, te servir des Options facultatives.
        * Clique sur Quitter, pour que le rapport puisse se créer.
        * Le rapport (TCleaner.txt) se trouve à la racine de votre disque dur (C:\)...colle le dans ta réponse.

        *********************

        Tu peux garder Malwarebytes anti malware en tant qu'anti malware, il est très efficace. (Même s'il ne résout pas tous les problèmes, bien entendu ... !)
        Par contre, il n'a pas de scan résident en mode gratuit ! Il faut donc pour l'utiliser le lancer, faire les mises à jour et faire un scan complet après.

        *********************

        Mets à jour Windows en installant le Service Pack 2 de Vista :
        http://www.microsoft.com/downloads/details.aspx?FamilyID=a4dd31d5-f907-4406-9012-a5c3199ea2b3&DisplayLang=fr

        *********************

        * Télécharge Ccleaner Slim :
        = = = = >>> En cliquant ici <<< = = = =

        * Installe le.
        * Choisis l'onglet Nettoyeur

        Quitte ton navigateur Internet avant de le lancer, décoche la dernière case (Avancé si elle est cochée) puis clique sur "lancer le nettoyage" quand il aura terminé le scan cliques en bas à droite sur "lancer le nettoyage" et accepte par oui.
        Attention, il risque de vider ta corbeille : si tu veux récupérer des fichiers effacés par erreur, mieux vaut le faire maintenant.

        * Choisis l'onglet Registre

        - Clique sur Chercher des erreurs
        - Une fois la recherche terminée, clic sur Réparer les erreurs sélectionnées (par défaut, tout est sélectionné, laisse comme ça)
        - Au message Voulez-vous sauvegarder les changements faits dans le registre, réponds Oui et enregistre le fichier au format « .reg » en le nommant par la date par exemple en le mettant sur le bureau. Puis continue.
        - A la fenêtre qui s'ouvre ensuite, clique sur Corriger toutes les erreurs sélectionnées puis OK
        - Recommence jusqu'à ce qu'aucune erreur n'apparaisse (ou une seule récurrente).
        - Ferme Ccleaner.

        * Tutoriel en images ICI si besoin.

        Note : La sauvegarde utilisée permet de remettre tel que la base était avant la manipulation au cas où il y aurait des soucis mais cela ne m'est jamais arrivé ! Il vaut mieux prendre des précautions, c'est tout. ;-)

        ********

        Réactive l'UAC.
        1. Voici le rapport :

          [ Rapport ToolsCleaner version 2.3.11 (par A.Rothstein & dj QUIOU) ]

          --> Recherche:

          C:\UsbFix: trouvé !
          C:\Rsit: trouvé !
          C:\Ad-remover: trouvé !
          C:\Program Files\trend micro\HijackThis.exe: trouvé !
          C:\Program Files\trend micro\hijackthis.log: trouvé !
          C:\Users\Ophélie\AppData\Roaming\Microsoft\Windows\Recent\UsbFix.lnk: trouvé !
          C:\Users\Ophélie\Downloads\Ad-R.exe: trouvé !
          C:\Users\Ophélie\Downloads\UsbFix.exe: trouvé !
          C:\Users\Ophélie\Downloads\Rsit.exe: trouvé !

          ---------------------------------
          --> Suppression:

          C:\Program Files\trend micro\HijackThis.exe: supprimé !
          C:\Users\Ophélie\Downloads\Ad-R.exe: supprimé !
          C:\Program Files\trend micro\hijackthis.log: supprimé !
          C:\Users\Ophélie\AppData\Roaming\Microsoft\Windows\Recent\UsbFix.lnk: supprimé !
          C:\Users\Ophélie\Downloads\UsbFix.exe: supprimé !
          C:\Users\Ophélie\Downloads\Rsit.exe: supprimé !
          C:\UsbFix: supprimé !
          C:\Rsit: supprimé !
          C:\Ad-remover: supprimé !
      4. Modérateur
        Supprime Toolscleaner et C:/TCleaner.txt.
        As-tu fait la suite ?
        1. Non je n'est pas fait la suite.

          Je suis entrain de le faire.
        2. Modérateur
          Ok, quand c'est terminé, tiens moi au courant.
          Après, ce sera tout bon, plus de virus :D
      5. Modérateur
        Parfait alors :-)...

        Désactive et réactive ta restauration système en suivant cette procédure :
        https://www.commentcamarche.net/faq/13214-vista-desactiver-reactiver-la-restauration-systeme-de-vista

        On a terminé si tu n'as pas de question ...
        1. Je n'arrive pas a téléchargé le service pack 2

          ca me mets ca a chaque fois :

          vous devez installer windows vista service pack 1 avant de continué.

          après avoir installé windows viste veuillez redémarré l'installation
        2. Je suis entrain de l'installé.

          Merci je te tient au courant pour la suit car je n'est pas fait c cleaner encore
        3. Rebonsoir,

          Quand je télécharge le service pack 2 ca me mets donné non valide??
        4. Non je ne l'est pas redémarré c'est bizarre je vien de réessayé ca me fait pareil.

          Tant pis j'ai installé firefox.

          es ce que je peu supprimé internet explorer?
        5. Modérateur
          Non, tu peux laisser Internet Explorer d'installé même si tu ne l'utilise pas.
          Il faut le laisser même ! (Utile pour les mises à jours, analyses antivirus en ligne, ...)
      6. Modérateur
        Ah ok, alors installe d'abord le service pack 1 :
        http://www.microsoft.com/downloads/details.aspx?FamilyID=b0c7136d-5ebb-413b-89c9-cb3d06d12674&DisplayLang=fr
        • 1
        • 2