PC INFECTE AIDEZ MOI SVP

Résolu
Bonjour,
je viens d acheter un pc et j ai fais un scan guidez svp merci d avance

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:55:44, on 14/02/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18882)
Boot mode: Normal

Running processes:
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
c:\Program Files\Hewlett-Packard\IAM\Bin\AsGHost.exe
C:\windows\system32\taskeng.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\windows\system32\igfxsrvc.exe
C:\windows\system32\wbem\unsecapp.exe
C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
C:\Users\DINSS\Downloads\hijackthis-2.0.2.75917.exe
C:\Users\DINSS\AppData\Local\Temp\hijackthis-2.0.2.75917.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-comm.msn.com&ocid=HPDHP&pc=CMDTDF
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-comm.msn.com&ocid=HPDHP&pc=CMDTDF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-comm.msn.com&ocid=HPDHP&pc=CMDTDF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb128\SearchSettings.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\DealioToolbarIE.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: BHO_Startup - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files\Hewlett-Packard\File Sanitizer\IEBHO.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Credential Manager for HP ProtectTools - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - c:\Program Files\Hewlett-Packard\IAM\Bin\ItIEAddIn.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb128\SearchSettings.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\DealioToolbarIE.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe c:\PROGRA~1\HEWLET~1\IAM\Bin\ASTSVCC.dll,RegisterModule
O4 - HKLM\..\Run: [IgfxTray] C:\windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} (CamfrogWEB Advanced Unicode Control) - http://activex.camfrogweb.com/advanced/2.0.2.20/cfweb_activex.camfrogweb.com-advanced-2.0.2.20_instmodule.exe
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O20 - AppInit_DLLs: APSHook.dll
O23 - Service: ActivClient Middleware Service (accoca) - ActivIdentity - c:\Program Files\ActivIdentity\ActivClient\accoca.exe
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\windows\system32\AEADISRV.EXE
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BrowserQuest Service - Unknown owner - C:\ProgramData\BrowserQuest\browserquest119.exe (file missing)
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP ProtectTools Service - Hewlett-Packard Development Company, L.P - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe
O23 - Service: Drive Encryption Service (HpFkCryptService) - SafeBoot International - c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
O23 - Service: File Sanitizer for HP ProtectTools (HPFSService) - Hewlett-Packard - C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Hewlett-Packard Corporation - C:\windows\system32\Hpservice.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe
O23 - Service: RoxMediaDB10 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe

--
End of file - 10775 bytes
Configuration: Windows Vista
Firefox 3.6

17 réponses

  1. Contributeur sécurité
    bonjour

    fais ceci stp

    1)

    Désactiver le TeaTimer de Spybot (Merci à Nico et nathandre):
    Pour désactiver le TeaTimer :
    => Ouvrir Spybot S&D
    => Dans le menu "Mode", séléctionner le mode avancé.
    => Une fenêtre demande confirmation cliquer sur "oui".
    => Une fois le mode avancé actif, ouvrir l'onglet "Outils".
    => Cliquer sur Résident.
    => La partie Résident comporte deux lignes qui sont normalement cochées :
    *Résident "SDHelper" (bloqueur de téléchargements nuisibles pour Internet Explorer) actif.
    * Résident "TeaTimer" (Protection des réglages système fondamentaux) actif
    => Décocher la ligne TeaTimer.
    => Redémarrer Spybot (le fermer et le réouvrir)
    => Retourner dans le menu Résident et vérifier qu'il soit bien désactivé

    Spybot va géner les outils

    ...................

    2)

    Téléchargez et enregistrez le fichier d installation sur le bureau
    http://pagesperso-orange.fr/NosTools/C_XX/AD-R.exe

    Double cliquez sur le fichier d'installation de AD-Remover, le programme s'installera automatiquement.
    Sous Vista : clic droit sur AD-Remover et sélectionner "Exécuter en tant qu'administrateur"
    Au menu principal choisir
    Option L Lancer le nettoyage
    et tapez sur [entrée] .
    Laissez travailler l'outil et ne touchez à rien ...
    Postez le rapport qui apparait à la fin.

    ( le rapport est sauvegardé aussi sous C:\Ad-report.log )

    (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

    Note :Process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
    Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
    Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

    ...........................

    3)
    • Télécharge Random's System Information Tool (RSIT) de Random/Random.

    (outil de diagnostic)

    http://images.malwareremoval.com/random/RSIT.exe

    • Enregistre le sur ton Bureau.

    • Double clique sur RSIT.exe pour lancer l'outil.

    • Clique sur "Continue" à l'écran Disclaimer.

    • Si l'outil HijackThis n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu s'il te le demande)

    et tu devras accepter la licence.

    • Une fois le scan terminé, deux rapports vont apparaître : poste les dans deux messages séparés stp

    Les rapports se trouvent à cet endroit:
    C:\rsit\info.txt
    C:\rsit\log.txt

    0
    1. Contributeur sécurité
      en complement du post précedent

      la désactivation du Contrôle des comptes utilisateurs est obligatoire
      sous peine de ne pas pouvoir faire fonctionner correctement l'outil.
      Tuto : https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac
      0
      1. merci voila c est fait
        0
    2. Contributeur sécurité
      tu as fait l'ensemble du post 1 ?

      je ne vois aucun rapports postés...
      0
      1. bonjour grace dsl pour le retard voici le rapport

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 14:38:41, on 15/02/2010
        Platform: Windows Vista SP2 (WinNT 6.00.1906)
        MSIE: Internet Explorer v8.00 (8.00.6001.18882)
        Boot mode: Normal

        Running processes:
        C:\windows\system32\taskeng.exe
        C:\windows\system32\Dwm.exe
        C:\windows\Explorer.EXE
        c:\Program Files\Hewlett-Packard\IAM\Bin\AsGHost.exe
        C:\Windows\System32\hkcmd.exe
        C:\Windows\System32\igfxpers.exe
        C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
        C:\Program Files\Windows Media Player\wmpnscfg.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\windows\system32\igfxsrvc.exe
        C:\windows\system32\wbem\unsecapp.exe
        C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
        c:\Users\DINSS\Downloads\hijackthis-2.0.2.75917(2).exe
        C:\Users\DINSS\AppData\Local\Temp\hijackthis-2.0.2.75917.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fr_fr&c=83&bd=all&pf=cmnb
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fr_fr&c=83&bd=all&pf=cmnb
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fr_fr&c=83&bd=all&pf=cmnb
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
        R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb128\SearchSettings.dll
        O1 - Hosts: ::1 localhost
        O2 - BHO: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\DealioToolbarIE.dll
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
        O2 - BHO: BHO_Startup - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files\Hewlett-Packard\File Sanitizer\IEBHO.dll
        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
        O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: Credential Manager for HP ProtectTools - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - c:\Program Files\Hewlett-Packard\IAM\Bin\ItIEAddIn.dll
        O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
        O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb128\SearchSettings.dll
        O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
        O3 - Toolbar: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\DealioToolbarIE.dll
        O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
        O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
        O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe c:\PROGRA~1\HEWLET~1\IAM\Bin\ASTSVCC.dll,RegisterModule
        O4 - HKLM\..\Run: [IgfxTray] C:\windows\system32\igfxtray.exe
        O4 - HKLM\..\Run: [HotKeysCmds] C:\windows\system32\hkcmd.exe
        O4 - HKLM\..\Run: [Persistence] C:\windows\system32\igfxpers.exe
        O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
        O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
        O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
        O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O13 - Gopher Prefix:
        O16 - DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} (CamfrogWEB Advanced Unicode Control) - http://activex.camfrogweb.com/advanced/2.0.2.20/cfweb_activex.camfrogweb.com-advanced-2.0.2.20_instmodule.exe
        O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
        O20 - AppInit_DLLs: APSHook.dll
        O23 - Service: ActivClient Middleware Service (accoca) - ActivIdentity - c:\Program Files\ActivIdentity\ActivClient\accoca.exe
        O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\windows\system32\AEADISRV.EXE
        O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
        O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
        O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
        O23 - Service: BrowserQuest Service - Unknown owner - C:\ProgramData\BrowserQuest\browserquest119.exe (file missing)
        O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
        O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
        O23 - Service: HP ProtectTools Service - Hewlett-Packard Development Company, L.P - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe
        O23 - Service: Drive Encryption Service (HpFkCryptService) - SafeBoot International - c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
        O23 - Service: File Sanitizer for HP ProtectTools (HPFSService) - Hewlett-Packard - C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe
        O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
        O23 - Service: HP Service (hpsrv) - Hewlett-Packard Corporation - C:\windows\system32\Hpservice.exe
        O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
        O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
        O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
        O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
        O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
        O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe
        O23 - Service: RoxMediaDB10 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
        O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
        O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
        O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
        O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
        0
        1. voici le rapport merci d avance

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 19:37:30, on 15/02/2010
          Platform: Windows Vista SP2 (WinNT 6.00.1906)
          MSIE: Internet Explorer v8.00 (8.00.6001.18882)
          Boot mode: Normal

          Running processes:
          C:\windows\system32\Dwm.exe
          C:\windows\Explorer.EXE
          C:\windows\system32\taskeng.exe
          c:\Program Files\Hewlett-Packard\IAM\Bin\AsGHost.exe
          C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
          C:\Program Files\Windows Media Player\wmpnscfg.exe
          C:\windows\System32\mobsync.exe
          C:\windows\system32\wbem\unsecapp.exe
          C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
          c:\Users\DINSS\Downloads\hijackthis-2.0.2.75917(2).exe
          C:\Users\DINSS\AppData\Local\Temp\hijackthis-2.0.2.75917.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          O1 - Hosts: ::1 localhost
          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
          O2 - BHO: BHO_Startup - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files\Hewlett-Packard\File Sanitizer\IEBHO.dll
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
          O2 - BHO: Credential Manager for HP ProtectTools - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - c:\Program Files\Hewlett-Packard\IAM\Bin\ItIEAddIn.dll
          O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
          O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
          O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
          O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
          O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
          O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
          O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
          O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
          O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O13 - Gopher Prefix:
          O16 - DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} (CamfrogWEB Advanced Unicode Control) - http://activex.camfrogweb.com/advanced/2.0.2.20/cfweb_activex.camfrogweb.com-advanced-2.0.2.20_instmodule.exe
          O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
          O20 - AppInit_DLLs: APSHook.dll
          O23 - Service: ActivClient Middleware Service (accoca) - ActivIdentity - c:\Program Files\ActivIdentity\ActivClient\accoca.exe
          O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\windows\system32\AEADISRV.EXE
          O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
          O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
          O23 - Service: HP ProtectTools Service - Hewlett-Packard Development Company, L.P - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe
          O23 - Service: Drive Encryption Service (HpFkCryptService) - SafeBoot International - c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
          O23 - Service: File Sanitizer for HP ProtectTools (HPFSService) - Hewlett-Packard - C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe
          O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
          O23 - Service: HP Service (hpsrv) - Hewlett-Packard Corporation - C:\windows\system32\Hpservice.exe
          O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
          O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
          O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
          O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
          O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
          O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe
          O23 - Service: RoxMediaDB10 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
          O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
          O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
          O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
          O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
          0
          1. Contributeur sécurité
            tu n'es pas attentif !

            je te reposte ce qu'il faut faire

            fais ceci stp

            1)

            Désactiver le TeaTimer de Spybot (Merci à Nico et nathandre):
            Pour désactiver le TeaTimer :
            => Ouvrir Spybot S&D
            => Dans le menu "Mode", séléctionner le mode avancé.
            => Une fenêtre demande confirmation cliquer sur "oui".
            => Une fois le mode avancé actif, ouvrir l'onglet "Outils".
            => Cliquer sur Résident.
            => La partie Résident comporte deux lignes qui sont normalement cochées :
            *Résident "SDHelper" (bloqueur de téléchargements nuisibles pour Internet Explorer) actif.
            * Résident "TeaTimer" (Protection des réglages système fondamentaux) actif
            => Décocher la ligne TeaTimer.
            => Redémarrer Spybot (le fermer et le réouvrir)
            => Retourner dans le menu Résident et vérifier qu'il soit bien désactivé

            Spybot va géner les outils

            ...................

            2)

            Téléchargez et enregistrez le fichier d installation sur le bureau
            http://pagesperso-orange.fr/NosTools/C_XX/AD-R.exe

            Double cliquez sur le fichier d'installation de AD-Remover, le programme s'installera automatiquement.
            Sous Vista : clic droit sur AD-Remover et sélectionner "Exécuter en tant qu'administrateur"
            Au menu principal choisir
            Option L Lancer le nettoyage
            et tapez sur [entrée] .
            Laissez travailler l'outil et ne touchez à rien ...
            Postez le rapport qui apparait à la fin.

            ( le rapport est sauvegardé aussi sous C:\Ad-report.log )

            (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

            Note :Process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
            Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
            Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

            ...........................

            3)
            • Télécharge Random's System Information Tool (RSIT) de Random/Random.

            (outil de diagnostic)

            http://images.malwareremoval.com/random/RSIT.exe

            • Enregistre le sur ton Bureau.

            • Double clique sur RSIT.exe pour lancer l'outil.

            • Clique sur "Continue" à l'écran Disclaimer.

            • Si l'outil HijackThis n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu s'il te le demande)

            et tu devras accepter la licence.

            • Une fois le scan terminé, deux rapports vont apparaître : poste les dans deux messages séparés stp

            Les rapports se trouvent à cet endroit:
            C:\rsit\info.txt
            C:\rsit\log.txt
            0
            1. je te confirme que je suis attentif car je l ai deja desactiver je viens de reverifier la case n est plus cocher
              0
              1. Contributeur sécurité
                oui ca je te fais confiance

                il fait faire maintenant l'étape 2 ==> Ad remover

                puis la 3 ==> RSIT
                0
                1. bonjour grace ad remover c est fait j ai fais etape 1 et 2 et ensuite voici le rapport rsit

                  Logfile of random's system information tool 1.06 (written by random/random)
                  Run by DINSS at 2010-02-16 10:01:12
                  Microsoft® Windows Vista™ Professionnel Service Pack 2
                  System drive C: has 164 GB (72%) free of 228 GB
                  Total RAM: 1976 MB (48% free)

                  HijackThis download failed

                  ======Scheduled tasks folder======

                  C:\windows\tasks\GlaryInitialize.job
                  C:\windows\tasks\Google Software Updater.job
                  C:\windows\tasks\HPCeeScheduleForDINSS.job

                  ======Registry dump======

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
                  Adobe PDF Reader Link Helper - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-01-12 63128]

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3134413B-49B4-425C-98A5-893C1F195601}]
                  BHO_Startup Class - C:\Program Files\Hewlett-Packard\File Sanitizer\IEBHO.dll [2008-05-02 110592]

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
                  Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
                  Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
                  Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
                  Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll [2009-04-28 668656]

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
                  Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-11-15 41760]

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DF21F1DB-80C6-11D3-9483-B03D0EC10000}]
                  Credential Manager for HP ProtectTools - c:\Program Files\Hewlett-Packard\IAM\Bin\ItIEAddIn.dll [2008-05-21 58128]

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
                  Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
                  {0BF43445-2F28-4351-9252-17FE6E806AA0}
                  {21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
                  {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - BitDefender Toolbar - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll [2010-02-14 95536]

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                  "BDAgent"=C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe [2010-02-14 782336]
                  "BitDefender Antiphishing Helper"=C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe [2010-02-14 69632]

                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
                  "WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240]
                  "msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883856]

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\accrdsub]
                  c:\Program Files\ActivIdentity\ActivClient\accrdsub.exe [2007-05-16 293168]

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CognizanceTS]
                  c:\PROGRA~1\HEWLET~1\IAM\Bin\ASTSVCC.dll [2008-05-21 24848]

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
                  C:\windows\system32\hkcmd.exe [2008-06-10 170520]

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
                  c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-04-15 70912]

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
                  c:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2007-05-09 54840]

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
                  C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2008-04-15 488752]

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
                  C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2008-04-18 178712]

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
                  C:\windows\system32\igfxtray.exe [2008-06-10 150040]

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
                  C:\Program Files\iTunes\iTunesHelper.exe [2010-01-22 141608]

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
                  C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2008-03-18 2289664]

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
                  C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2010-01-07 1394000]

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883856]

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
                  C:\windows\system32\igfxpers.exe [2008-06-10 145944]

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PTHOSTTR]
                  c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE [2008-05-08 238984]

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
                  C:\Program Files\Analog Devices\SoundMAX\soundmax.exe [2008-03-19 3842048]

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
                  C:\Program Files\Synaptics\SynTP\SynTPEnh.exe []

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                  "AppInit_DLLS"="APSHook.dll"

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
                  C:\windows\system32\igfxdev.dll [2008-05-21 208896]

                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
                  "notification packages"=scecli
                  ASWLNPkg

                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                  "dontdisplaylastusername"=0
                  "legalnoticecaption"=
                  "legalnoticetext"=
                  "shutdownwithoutlogon"=1
                  "undockwithoutlogon"=1
                  "EnableUIADesktopToggle"=0

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                  "BindDirectlyToPropertySetStorage"=

                  [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

                  [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

                  [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{06e880e2-10ca-11de-9809-002186d187b7}]
                  shell\AutoRun\command - 0k.bat
                  shell\open\command - 0k.bat

                  [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3c945354-7074-11de-9f21-002186d187b7}]
                  shell\AutoRun\command - H:\g8k.exe
                  shell\open\command - H:\g8k.exe

                  [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5bd62e63-2bb4-11de-aee0-002186d187b7}]
                  shell\AutoRun\command - H:\WD_Windows_Tools\Setup.exe

                  ======File associations======

                  .js - edit - C:\windows\System32\Notepad.exe %1
                  .js - open - C:\windows\System32\WScript.exe "%1" %*

                  ======List of files/folders created in the last 1 months======

                  2010-02-16 10:01:12 ----D---- C:\rsit
                  2010-02-16 10:01:12 ----D---- C:\Program Files\trend micro
                  2010-02-15 17:50:48 ----D---- C:\Ad-Remover
                  2010-02-14 21:59:23 ----A---- C:\bdlog.txt
                  2010-02-14 14:51:59 ----D---- C:\Users\DINSS\AppData\Roaming\Malwarebytes
                  2010-02-14 14:51:51 ----D---- C:\ProgramData\Malwarebytes
                  2010-02-14 14:51:50 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
                  2010-02-14 12:40:57 ----D---- C:\Users\DINSS\AppData\Roaming\BitDefender
                  2010-02-14 12:40:18 ----D---- C:\ProgramData\BitDefender
                  2010-02-14 12:40:18 ----D---- C:\Program Files\BitDefender
                  2010-02-14 12:40:09 ----SHD---- C:\Config.Msi
                  2010-02-14 12:38:33 ----D---- C:\Program Files\Common Files\BitDefender
                  2010-02-10 21:56:21 ----D---- C:\Users\DINSS\AppData\Roaming\CamfrogWEB
                  2010-02-10 17:18:29 ----A---- C:\windows\wininit.ini
                  2010-02-10 16:38:37 ----D---- C:\ProgramData\Spybot - Search & Destroy
                  2010-02-10 16:38:37 ----D---- C:\Program Files\Spybot - Search & Destroy
                  2010-02-10 16:00:37 ----D---- C:\Program Files\Mozilla Firefox
                  2010-02-10 15:58:16 ----D---- C:\ProgramData\BrowserQuest
                  2010-02-10 15:58:16 ----D---- C:\Program Files\BrowserQuest
                  2010-02-10 15:54:50 ----D---- C:\Program Files\WinRAR
                  2010-02-10 15:51:27 ----D---- C:\Program Files\WinSCP
                  2010-02-10 15:37:25 ----A---- C:\windows\system32\GEARAspi.dll
                  2010-02-10 15:36:39 ----D---- C:\Program Files\iPod
                  2010-02-10 15:36:29 ----D---- C:\ProgramData\{755AC846-7372-4AC8-8550-C52491DAA8BD}
                  2010-02-10 15:36:29 ----D---- C:\Program Files\iTunes
                  2010-02-10 15:35:58 ----D---- C:\Program Files\Bonjour
                  2010-02-10 15:35:06 ----D---- C:\Program Files\QuickTime
                  2010-02-10 15:35:05 ----D---- C:\ProgramData\Apple Computer
                  2010-02-10 15:34:26 ----D---- C:\Program Files\Apple Software Update
                  2010-02-10 15:31:43 ----D---- C:\ProgramData\Apple
                  2010-02-10 15:31:43 ----D---- C:\Program Files\Common Files\Apple
                  2010-02-10 12:41:31 ----D---- C:\Users\DINSS\AppData\Roaming\GlarySoft
                  2010-02-10 12:35:33 ----D---- C:\Program Files\Glary Utilities
                  2010-02-10 01:34:01 ----D---- C:\Program Files\Hercules
                  2010-02-10 00:47:51 ----D---- C:\Program Files\CFWebAdvancedU
                  2010-02-10 00:46:32 ----A---- C:\windows\system32\ntoskrnl.exe
                  2010-02-10 00:46:32 ----A---- C:\windows\system32\ntkrnlpa.exe
                  2010-02-10 00:44:54 ----A---- C:\windows\system32\quartz.dll
                  2010-02-10 00:44:53 ----A---- C:\windows\system32\tsbyuv.dll
                  2010-02-10 00:44:53 ----A---- C:\windows\system32\msyuv.dll
                  2010-02-10 00:44:53 ----A---- C:\windows\system32\msvidc32.dll
                  2010-02-10 00:44:53 ----A---- C:\windows\system32\msrle32.dll
                  2010-02-10 00:44:53 ----A---- C:\windows\system32\mciavi32.dll
                  2010-02-10 00:44:53 ----A---- C:\windows\system32\iyuv_32.dll
                  2010-02-10 00:44:52 ----A---- C:\windows\system32\msvfw32.dll
                  2010-02-10 00:44:52 ----A---- C:\windows\system32\avifil32.dll
                  2010-01-27 21:23:26 ----HDC---- C:\ProgramData\{4890FF13-BFC8-467A-AD6A-71025F041ADD}
                  2010-01-27 21:12:55 ----D---- C:\ProgramData\EBP
                  2010-01-27 21:11:01 ----D---- C:\Program Files\EBP
                  2010-01-27 21:10:46 ----D---- C:\Program Files\Microsoft Synchronization Services
                  2010-01-27 21:10:32 ----HDC---- C:\ProgramData\{A8E6E53F-6DF1-44CD-A142-88E5DD20F5F7}
                  2010-01-22 18:50:00 ----A---- C:\windows\system32\mshtml.dll
                  2010-01-22 18:50:00 ----A---- C:\windows\system32\ieframe.dll
                  2010-01-22 18:49:58 ----A---- C:\windows\system32\wininet.dll
                  2010-01-22 18:49:58 ----A---- C:\windows\system32\urlmon.dll
                  2010-01-22 18:49:58 ----A---- C:\windows\system32\iertutil.dll
                  2010-01-22 18:49:57 ----A---- C:\windows\system32\occache.dll
                  2010-01-22 18:49:57 ----A---- C:\windows\system32\msfeedssync.exe
                  2010-01-22 18:49:57 ----A---- C:\windows\system32\msfeedsbs.dll
                  2010-01-22 18:49:57 ----A---- C:\windows\system32\msfeeds.dll
                  2010-01-22 18:49:57 ----A---- C:\windows\system32\jsproxy.dll
                  2010-01-22 18:49:57 ----A---- C:\windows\system32\ieUnatt.exe
                  2010-01-22 18:49:57 ----A---- C:\windows\system32\ieui.dll
                  2010-01-22 18:49:57 ----A---- C:\windows\system32\iesysprep.dll
                  2010-01-22 18:49:57 ----A---- C:\windows\system32\iesetup.dll
                  2010-01-22 18:49:57 ----A---- C:\windows\system32\iernonce.dll
                  2010-01-22 18:49:57 ----A---- C:\windows\system32\iepeers.dll
                  2010-01-22 18:49:57 ----A---- C:\windows\system32\iedkcs32.dll
                  2010-01-22 18:49:57 ----A---- C:\windows\system32\ie4uinit.exe

                  ======List of files/folders modified in the last 1 months======

                  2010-02-16 10:01:34 ----D---- C:\windows\Temp
                  2010-02-16 10:01:34 ----D---- C:\windows\System32
                  2010-02-16 10:01:13 ----D---- C:\windows\Prefetch
                  2010-02-16 10:01:12 ----RD---- C:\Program Files
                  2010-02-16 09:58:14 ----D---- C:\windows\Tasks
                  2010-02-16 09:55:58 ----D---- C:\ProgramData\hpqLog
                  2010-02-16 09:51:30 ----D---- C:\windows\inf
                  2010-02-16 09:51:30 ----A---- C:\windows\system32\PerfStringBackup.INI
                  2010-02-15 21:02:08 ----D---- C:\windows\system32\catroot
                  2010-02-15 21:02:03 ----D---- C:\windows\system32\drivers
                  2010-02-15 21:01:58 ----D---- C:\Windows
                  2010-02-15 19:22:18 ----HD---- C:\ProgramData
                  2010-02-15 19:06:54 ----SHD---- C:\windows\Installer
                  2010-02-15 14:17:15 ----D---- C:\windows\system32\zh-TW
                  2010-02-15 14:17:15 ----D---- C:\windows\system32\zh-CN
                  2010-02-15 14:17:15 ----D---- C:\windows\system32\sv-SE
                  2010-02-15 14:17:15 ----D---- C:\windows\system32\ru-RU
                  2010-02-15 14:17:15 ----D---- C:\windows\system32\pt-BR
                  2010-02-15 14:17:15 ----D---- C:\windows\system32\pl-PL
                  2010-02-15 14:17:15 ----D---- C:\windows\system32\nb-NO
                  2010-02-15 14:17:15 ----D---- C:\windows\system32\ko-KR
                  2010-02-15 14:17:15 ----D---- C:\windows\system32\ja-JP
                  2010-02-15 14:17:15 ----AD---- C:\windows\system32\nl-NL
                  2010-02-15 14:17:15 ----AD---- C:\windows\system32\it-IT
                  2010-02-15 14:17:14 ----D---- C:\windows\system32\fi-FI
                  2010-02-15 14:17:14 ----D---- C:\windows\system32\es-ES
                  2010-02-15 14:17:14 ----D---- C:\windows\system32\en-US
                  2010-02-15 14:17:14 ----D---- C:\windows\system32\da-DK
                  2010-02-15 14:17:14 ----AD---- C:\windows\system32\fr-FR
                  2010-02-15 14:17:14 ----AD---- C:\windows\system32\de-DE
                  2010-02-15 14:14:02 ----SHD---- C:\System Volume Information
                  2010-02-15 14:11:47 ----D---- C:\ProgramData\Google Updater
                  2010-02-14 22:01:18 ----HD---- C:\windows\system32\GroupPolicy
                  2010-02-14 21:12:12 ----D---- C:\windows\system32\catroot2
                  2010-02-14 16:02:18 ----D---- C:\windows\tapi
                  2010-02-14 15:15:26 ----A---- C:\windows\system32\txmlutil.dll
                  2010-02-14 14:44:58 ----D---- C:\ProgramData\Messenger Plus!
                  2010-02-14 13:07:20 ----D---- C:\windows\Debug
                  2010-02-14 13:00:47 ----D---- C:\Program Files\Messenger Plus! Live
                  2010-02-14 12:42:42 ----D---- C:\windows\winsxs
                  2010-02-14 12:38:33 ----D---- C:\Program Files\Common Files
                  2010-02-14 12:28:03 ----D---- C:\windows\system32\config
                  2010-02-14 12:27:59 ----D---- C:\windows\system32\Tasks
                  2010-02-14 12:27:59 ----D---- C:\windows\system32\spool
                  2010-02-14 12:27:59 ----D---- C:\windows\system32\Msdtc
                  2010-02-14 12:27:59 ----D---- C:\Users\DINSS\AppData\Roaming\vlc
                  2010-02-14 12:27:59 ----D---- C:\Users\DINSS\AppData\Roaming\dvdcss
                  2010-02-14 12:27:57 ----D---- C:\windows\system32\wbem
                  2010-02-14 12:27:57 ----D---- C:\windows\registration
                  2010-02-10 16:00:51 ----D---- C:\Users\DINSS\AppData\Roaming\Mozilla
                  2010-02-10 15:44:13 ----D---- C:\Users\DINSS\AppData\Roaming\Apple Computer
                  2010-02-10 15:37:25 ----DC---- C:\windows\system32\DRVSTORE
                  2010-02-10 14:09:40 ----D---- C:\Users\DINSS\AppData\Roaming\Macromedia
                  2010-02-10 13:47:51 ----D---- C:\windows\Minidump
                  2010-02-10 12:26:25 ----HD---- C:\Program Files\InstallShield Installation Information
                  2010-02-10 12:22:55 ----SD---- C:\Users\DINSS\AppData\Roaming\Microsoft
                  2010-02-10 01:11:22 ----D---- C:\Program Files\Windows Mail
                  2010-02-10 01:00:08 ----D---- C:\ProgramData\Microsoft Help
                  2010-02-10 00:47:54 ----SD---- C:\windows\Downloaded Program Files
                  2010-02-01 20:26:20 ----A---- C:\windows\system32\mrt.exe
                  2010-01-28 01:01:07 ----D---- C:\windows\ModemLogs
                  2010-01-27 22:08:06 ----D---- C:\Users\DINSS\AppData\Roaming\OFFICEOne7
                  2010-01-27 21:15:27 ----RSD---- C:\windows\assembly
                  2010-01-27 21:15:27 ----D---- C:\windows\Microsoft.NET
                  2010-01-27 21:10:44 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
                  2010-01-27 17:34:24 ----D---- C:\Program Files\Internet Explorer
                  2010-01-25 23:53:17 ----D---- C:\Program Files\Common Files\Steam
                  2010-01-23 13:28:20 ----D---- C:\windows\system32\migration
                  2010-01-20 16:38:11 ----D---- C:\Program Files\Microsoft Silverlight

                  ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

                  R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\windows\system32\drivers\Aavmker4.sys [2006-09-25 24560]
                  R1 bdftdif;bdftdif; \??\C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdftdif.sys [2010-02-14 137224]
                  R1 CSC;Offline Files Driver; C:\windows\system32\drivers\csc.sys [2009-04-11 351744]
                  R1 RsvLock;RsvLock; C:\windows\system32\drivers\RsvLock.sys [2008-05-14 12496]
                  R2 aswMon2;avast! Standard Shield Support; C:\windows\system32\drivers\aswMon2.sys [2006-09-25 87424]
                  R2 BDVEDISK;BDVEDISK; \??\C:\Program Files\BitDefender\BitDefender 2009\BDVEDISK.sys [2010-02-14 82696]
                  R3 Accelerometer;HP Accelerometer; C:\windows\system32\DRIVERS\Accelerometer.sys [2008-04-07 34664]
                  R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\windows\system32\drivers\ADIHdAud.sys [2008-04-11 382464]
                  R3 AgereSoftModem;Agere Systems Soft Modem; C:\windows\system32\DRIVERS\AGRSM.sys [2008-02-29 1202560]
                  R3 BCM43XX;Pilote pour carte réseau Broadcom 802.11; C:\windows\system32\DRIVERS\bcmwl6.sys [2008-03-21 1207288]
                  R3 bdfm;BDFM; C:\windows\system32\drivers\bdfm.sys [2010-02-14 111112]
                  R3 Bdfndisf;BitDefender Firewall NDIS Filter Service; C:\windows\system32\DRIVERS\bdfndisf.sys [2010-02-14 104456]
                  R3 bdfsfltr;bdfsfltr; C:\windows\system32\DRIVERS\bdfsfltr.sys [2010-02-14 242184]
                  R3 BDSelfPr;BDSelfPr; \??\C:\Program Files\BitDefender\BitDefender 2009\bdselfpr.sys [2010-02-14 8832]
                  R3 BthEnum;Service d'énumérateur Bluetooth; C:\windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
                  R3 BthPan;Périphérique Bluetooth (réseau personnel); C:\windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
                  R3 BTHUSB;Pilote USB radio Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys [2009-04-11 29696]
                  R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\windows\system32\DRIVERS\CmBatt.sys [2008-01-21 14208]
                  R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
                  R3 HBtnKey;HBtnKey; C:\windows\system32\DRIVERS\cpqbttn.sys [2008-04-14 9344]
                  R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\DRIVERS\HpqKbFiltr.sys [2007-06-19 16768]
                  R3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd32.sys [2008-05-21 2369536]
                  R3 RFCOMM;Périphérique Bluetooth (TDI protocole RFCOMM); C:\windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
                  R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\windows\system32\DRIVERS\snp2uvc.sys [2008-04-10 1804160]
                  R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264]
                  R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\windows\system32\DRIVERS\yk60x86.sys [2008-01-17 298496]
                  S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\windows\system32\DRIVERS\b57nd60x.sys [2008-01-21 179712]
                  S3 BTHPORT;Pilote de port Bluetooth; C:\windows\System32\Drivers\BTHport.sys [2009-04-11 507904]
                  S3 btwaudio;Périphérique audio Bluetooth; C:\windows\system32\drivers\btwaudio.sys []
                  S3 btwavdt;Bluetooth AVDT; C:\windows\system32\drivers\btwavdt.sys []
                  S3 btwrchid;btwrchid; C:\windows\system32\DRIVERS\btwrchid.sys []
                  S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
                  S3 ErrDev;Microsoft Hardware Error Device Driver; C:\windows\system32\drivers\errdev.sys [2008-01-21 6656]
                  S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
                  S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
                  S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
                  S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
                  S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
                  S3 Profos;Profos; \??\C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\profos.sys [2010-02-14 13056]
                  S3 USBAAPL;Apple Mobile USB Driver; C:\windows\System32\Drivers\usbaapl.sys [2009-08-28 40448]
                  S3 usbscan;Pilote de scanneur USB; C:\windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
                  S3 usbvideo;Périphérique vidéo USB (WDM); C:\windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
                  S3 WpdUsb;WpdUsb; C:\windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
                  S3 WUDFRd;WUDFRd; C:\windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]

                  ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

                  R2 accoca;ActivClient Middleware Service; c:\Program Files\ActivIdentity\ActivClient\accoca.exe [2007-05-16 182576]
                  R2 AEADIFilters;Andrea ADI Filters Service; C:\windows\system32\AEADISRV.EXE [2007-10-19 86016]
                  R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Windows\system32\agrsmsvc.exe [2007-12-11 12800]
                  R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-08-28 144672]
                  R2 ASBroker;Logon Session Broker; C:\windows\System32\svchost.exe [2008-01-21 21504]
                  R2 ASChannel;Local Communication Channel; C:\windows\System32\svchost.exe [2008-01-21 21504]
                  R2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
                  R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\windows\system32\svchost.exe [2008-01-21 21504]
                  R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\windows\System32\svchost.exe [2008-01-21 21504]
                  R2 HP Health Check Service;HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2008-04-15 94208]
                  R2 HP ProtectTools Service;HP ProtectTools Service; c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe [2008-05-14 34184]
                  R2 HpFkCryptService;Drive Encryption Service; c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [2008-05-14 256512]
                  R2 HPFSService;File Sanitizer for HP ProtectTools; C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe [2008-05-02 77824]
                  R2 hpsrv;HP Service; C:\windows\system32\Hpservice.exe [2008-04-07 24936]
                  R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2008-04-18 354840]
                  R2 IviRegMgr;IviRegMgr; C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2007-01-05 112152]
                  R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-03-18 73728]
                  R2 LIVESRV;BitDefender Desktop Update Service; C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe [2010-02-14 413696]
                  R2 Net Driver HPZ12;Net Driver HPZ12; C:\windows\System32\svchost.exe [2008-01-21 21504]
                  R2 pdfcDispatcher;PDF Document Manager; C:\Program Files\PDF Complete\pdfsvc.exe [2008-05-12 576024]
                  R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\windows\System32\svchost.exe [2008-01-21 21504]
                  R2 SBSDWSCService;SBSD Security Center Service; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
                  R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
                  R2 VSSERV;BitDefender Virus Shield; C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe [2010-02-14 1638240]
                  R3 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2008-04-16 165192]
                  S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-03 183280]
                  S3 AppMgmt;@appmgmts.dll,-3250; C:\windows\system32\svchost.exe [2008-01-21 21504]
                  S3 Arrakis3;BitDefender Arrakis Server; C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe [2008-07-17 118784]
                  S3 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2009-03-30 31048]
                  S3 Com4QLBEx;Com4QLBEx; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
                  S3 Fax;@%systemroot%\system32\fxsresm.dll,-118; C:\windows\system32\fxssvc.exe [2008-01-21 523776]
                  S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\windows\system32\svchost.exe [2008-01-21 21504]
                  S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
                  S3 iPod Service;Service de l’iPod; C:\Program Files\iPod\bin\iPodService.exe [2010-01-22 545576]
                  S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-04-13 792112]
                  S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-01 271920]
                  S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
                  S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
                  S3 RoxMediaDB10;RoxMediaDB10; c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2008-04-08 1112560]
                  S3 scan;BitDefender Threat Scanner; C:\windows\System32\svchost.exe [2008-01-21 21504]
                  S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2010-01-24 326792]
                  S3 stllssvr;stllssvr; c:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2008-03-24 74384]
                  S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\windows\System32\svchost.exe [2008-01-21 21504]
                  S3 wbengine;@%systemroot%\system32\wbengine.exe,-104; C:\windows\system32\wbengine.exe [2009-04-11 918528]

                  -----------------EOF-----------------
                  0
                  1. Contributeur sécurité
                    ok

                    deux choses à faire et copier les rapports ici

                    1)

                    Téléchargez USBFIX de El Desaparecido, C_xx

                    http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe
                    ou
                    https://www.ionos.fr/?affiliate_id=77097

                    /!\ Utilisateur de vista et windows 7 :
                    ne pas oublier de désactiver Le contrôle des comptes utilisateurs
                    https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

                    /!\ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

                    • Double clic sur le raccourci UsbFix présent sur le bureau .

                    • Choisir l'option2 suppression
                    (d’autres options disponibles, voir le tutoriel).
                    • Laissez travailler l'outil.
                    Le menu démarrer et les icônes vont disparaître.. c'est normal.

                    Si un message te demande de redémarrer l'ordinateur fais le ...

                    ● Au redémarrage, le fix se relance... laisses l'opération s'effectuer.

                    ● Le bloc note s'ouvre avec un rapport, envoies le dans la prochaine réponse

                    • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

                    ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

                    • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                    Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                    Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

                    • Tuto : http://pagesperso-orange.fr/NosTools/usbfix.html

                    UsbFix peut te demander d'uploader un dossier compressé à cette adresse : https://www.ionos.fr/?affiliate_id=77097

                    Il est enregistré sur ton bureau.

                    Merci de l'envoyer à l'adresse indiquée afin d'aider l'auteur de UsbFix dans ses recherches.

                    ............................

                    2)

                    Téléchargez MalwareByte's Anti-Malware

                    http://www.malwarebytes.org/mbam/program/mbam-setup.exe

                    . Enregistres le sur le bureau
                    . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
                    . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
                    . Si le pare-feu demande l'autorisation de se connecter pour malwarebytes, accepte
                    . Une fois la mise à jour terminé
                    . Rend-toi dans l'onglet, Recherche
                    . Sélectionnes Exécuter un examen complet (examen assez long)
                    . Cliques sur Rechercher
                    . Le scan démarre.
                    . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
                    . Cliques sur Ok pour poursuivre.
                    . Si des malwares ont été détectés, clique sur Afficher les résultats
                    . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
                    . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
                    . Rends toi dans l'onglet rapport/log
                    . Tu cliques dessus pour l'afficher, une fois affiché
                    . Tu cliques sur edition en haut du boc notes, et puis sur sélectionner tous
                    . Tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
                    . tu cliques droit dans le cadre de la reponse et coller

                    Si tu as besoin d'aide regarde ces tutoriels :
                    Aide: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
                    http://www.infos-du-net.com/forum/278396-11-tuto-malwarebytes-anti-malware-mbam

                    0
                    1. premier rapport

                      ############################## | UsbFix V6.095 |

                      User : DINSS (Administrateurs) # PC-DE-DINSS
                      Update on 15/02/2010 by El Desaparecido , C_XX & Chimay8
                      Start at: 11:54:49 | 16/02/2010
                      Website : http://pagesperso-orange.fr/NosTools/index.html
                      Contact : FindyKill.Contact@gmail.com

                      Genuine Intel(R) CPU 575 @ 2.00GHz
                      Microsoft® Windows Vista™ Professionnel (6.0.6002 32-bit) # Service Pack 2
                      Internet Explorer 8.0.6001.18882
                      Windows Firewall Status : Disabled
                      AV : BitDefender Antivirus 12.0 [ (!) Disabled | Updated ]
                      FW : BitDefender Firewall[ (!) Disabled ]12.0

                      C:\ -> Disque fixe local # 222,88 Go (159,69 Go free) # NTFS
                      D:\ -> Disque fixe local # 9 Go (1,65 Go free) [HP_RECOVERY] # NTFS
                      E:\ -> Disque CD-ROM
                      F:\ -> Disque fixe local # 1021 Mo (1020,76 Mo free) [HP_TOOLS] # FAT32

                      ############################## | Processus actifs |

                      C:\windows\System32\smss.exe
                      C:\windows\system32\csrss.exe
                      C:\windows\system32\wininit.exe
                      C:\windows\system32\csrss.exe
                      C:\windows\system32\winlogon.exe
                      C:\windows\system32\services.exe
                      C:\windows\system32\lsass.exe
                      C:\windows\system32\lsm.exe
                      C:\windows\system32\svchost.exe
                      C:\windows\System32\svchost.exe
                      C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe
                      c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
                      C:\windows\system32\svchost.exe
                      C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
                      C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
                      C:\windows\System32\svchost.exe
                      C:\windows\System32\svchost.exe
                      C:\windows\system32\svchost.exe
                      C:\windows\system32\svchost.exe
                      C:\windows\system32\SLsvc.exe
                      C:\windows\system32\svchost.exe
                      C:\windows\system32\Hpservice.exe
                      C:\windows\system32\svchost.exe
                      C:\windows\system32\WLANExt.exe
                      C:\windows\System32\spoolsv.exe
                      C:\windows\system32\taskeng.exe
                      C:\windows\system32\svchost.exe
                      c:\Program Files\ActivIdentity\ActivClient\accoca.exe
                      C:\windows\system32\AEADISRV.EXE
                      C:\Windows\system32\agrsmsvc.exe
                      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      C:\Program Files\Bonjour\mDNSResponder.exe
                      c:\Program Files\ActivIdentity\ActivClient\acevents.exe
                      C:\windows\system32\svchost.exe
                      c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe
                      C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
                      C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
                      C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                      C:\windows\System32\svchost.exe
                      C:\Program Files\PDF Complete\pdfsvc.exe
                      C:\windows\System32\svchost.exe
                      C:\windows\system32\svchost.exe
                      C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                      C:\windows\system32\svchost.exe
                      C:\windows\System32\svchost.exe
                      C:\windows\system32\SearchIndexer.exe
                      C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                      C:\windows\System32\lpksetup.exe
                      C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                      C:\windows\system32\wbem\wmiprvse.exe
                      C:\windows\system32\wbem\wmiprvse.exe
                      C:\windows\servicing\TrustedInstaller.exe
                      C:\windows\system32\taskeng.exe
                      C:\windows\system32\Dwm.exe
                      C:\windows\Explorer.EXE
                      C:\windows\system32\runonce.exe
                      c:\Program Files\Hewlett-Packard\IAM\Bin\AsGHost.exe
                      C:\windows\system32\conime.exe
                      C:\windows\system32\PresentationSettings.exe

                      ################## | Elements infectieux |

                      Supprimé ! C:\$Recycle.Bin\S-1-5-21-2102018463-656916202-3680383204-500
                      Supprimé ! C:\$Recycle.Bin\S-1-5-21-391857896-3459148900-2116546876-1004
                      Supprimé ! D:\$Recycle.Bin\S-1-5-21-2102018463-656916202-3680383204-500
                      Supprimé ! D:\$Recycle.Bin\S-1-5-21-391857896-3459148900-2116546876-1004

                      ################## | Registre |

                      ################## | Mountpoints2 |

                      Supprimé ! HKCU\...\Explorer\MountPoints2\G\Shell\AutoRun\Command
                      Supprimé ! HKCU\...\Explorer\MountPoints2\{06e880e2-10ca-11de-9809-002186d187b7}\Shell\AutoRun\Command
                      Supprimé ! HKCU\...\Explorer\MountPoints2\{3c945354-7074-11de-9f21-002186d187b7}\Shell\AutoRun\Command
                      Supprimé ! HKCU\...\Explorer\MountPoints2\{5bd62e63-2bb4-11de-aee0-002186d187b7}\Shell\AutoRun\Command

                      ################## | Listing des fichiers présent |

                      [15/02/2010 19:08|--a------|7321] C:\Ad-Report-CLEAN[1].log
                      [15/02/2010 17:51|--a------|511] C:\Ad-Report-SCAN[1].log
                      [15/02/2010 17:56|--a------|511] C:\Ad-Report-SCAN[2].log
                      [15/02/2010 18:00|--a------|511] C:\Ad-Report-SCAN[3].log
                      [15/02/2010 18:46|--a------|7512] C:\Ad-Report-SCAN[4].log
                      [14/02/2010 21:59|--a------|2200] C:\bdlog.txt
                      [11/04/2009 07:36|-rahs----|333257] C:\bootmgr
                      [?|?|?] C:\hiberfil.sys
                      [10/02/2010 17:23|-rahs----|0] C:\IO.SYS
                      [10/02/2010 17:23|-rahs----|0] C:\MSDOS.SYS
                      [29/02/2004 16:44|--a------|52576] C:\orange.bmp
                      [?|?|?] C:\pagefile.sys
                      [16/12/2009 00:01|--a------|90] C:\Setup.log
                      [16/02/2010 12:03|--a------|4860] C:\UsbFix.txt
                      [21/01/2008 03:25|-rahs----|333203] D:\bootmgr
                      [14/03/2009 17:19|--a------|50] D:\HP_WINRE
                      [18/06/2008 18:28|--ahs----|536870912] D:\pagefile.sys

                      ################## | Vaccination |

                      # C:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
                      # D:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
                      # F:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).

                      ################## | Upload |

                      Veuillez envoyer le fichier : C:\UsbFix_Upload_Me_PC-de-DINSS.zip : https://www.ionos.fr/?affiliate_id=77097
                      Merci pour votre contribution .

                      ################## | ! Fin du rapport # UsbFix V6.095 ! |
                      0
                      1. Contributeur sécurité
                        vu

                        ==> MalwareByte's Anti-Malware
                        0
                        1. Malwarebytes' Anti-Malware 1.44
                          Version de la base de données: 3738
                          Windows 6.0.6002 Service Pack 2
                          Internet Explorer 8.0.6001.18882

                          16/02/2010 13:28:04
                          mbam-log-2010-02-16 (13-28-04).txt

                          Type de recherche: Examen complet (C:\|D:\|E:\|F:\|)
                          Eléments examinés: 278895
                          Temps écoulé: 1 hour(s), 13 minute(s), 48 second(s)

                          Processus mémoire infecté(s): 0
                          Module(s) mémoire infecté(s): 0
                          Clé(s) du Registre infectée(s): 0
                          Valeur(s) du Registre infectée(s): 0
                          Elément(s) de données du Registre infecté(s): 0
                          Dossier(s) infecté(s): 0
                          Fichier(s) infecté(s): 0

                          Processus mémoire infecté(s):
                          (Aucun élément nuisible détecté)

                          Module(s) mémoire infecté(s):
                          (Aucun élément nuisible détecté)

                          Clé(s) du Registre infectée(s):
                          (Aucun élément nuisible détecté)

                          Valeur(s) du Registre infectée(s):
                          (Aucun élément nuisible détecté)

                          Elément(s) de données du Registre infecté(s):
                          (Aucun élément nuisible détecté)

                          Dossier(s) infecté(s):
                          (Aucun élément nuisible détecté)

                          Fichier(s) infecté(s):
                          (Aucun élément nuisible détecté)
                          0
                          1. Contributeur sécurité
                            bien

                            comment va le pc ?

                            relances RSIT et postes le rapport log stp
                            0
                            1. il va bcp mieux merci par contre tu aurais une astuce pour que le pc s eteigne plus vite et s allume plus vit je l a i fais via registre mais c pas terrible merci d avance

                              Logfile of random's system information tool 1.06 (written by random/random)
                              Run by DINSS at 2010-02-16 14:09:15
                              Microsoft® Windows Vista™ Professionnel Service Pack 2
                              System drive C: has 164 GB (72%) free of 228 GB
                              Total RAM: 1976 MB (56% free)

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 14:10:01, on 16/02/2010
                              Platform: Windows Vista SP2 (WinNT 6.00.1906)
                              MSIE: Internet Explorer v8.00 (8.00.6001.18882)
                              Boot mode: Normal

                              Running processes:
                              C:\windows\system32\taskeng.exe
                              C:\windows\system32\Dwm.exe
                              c:\Program Files\Hewlett-Packard\IAM\Bin\AsGHost.exe
                              C:\windows\Explorer.EXE
                              C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
                              C:\Program Files\Windows Media Player\wmpnscfg.exe
                              C:\windows\system32\wbem\unsecapp.exe
                              C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
                              c:\Users\DINSS\Downloads\RSIT.exe
                              C:\Program Files\trend micro\DINSS.exe

                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
                              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                              O1 - Hosts: ::1 localhost
                              O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                              O2 - BHO: BHO_Startup - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files\Hewlett-Packard\File Sanitizer\IEBHO.dll
                              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                              O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
                              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                              O2 - BHO: Credential Manager for HP ProtectTools - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - c:\Program Files\Hewlett-Packard\IAM\Bin\ItIEAddIn.dll
                              O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                              O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
                              O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                              O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
                              O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
                              O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
                              O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                              O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
                              O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                              O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
                              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                              O13 - Gopher Prefix:
                              O16 - DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} (CamfrogWEB Advanced Unicode Control) - http://activex.camfrogweb.com/...
                              O20 - AppInit_DLLs: APSHook.dll
                              O23 - Service: ActivClient Middleware Service (accoca) - ActivIdentity - c:\Program Files\ActivIdentity\ActivClient\accoca.exe
                              O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\windows\system32\AEADISRV.EXE
                              O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
                              O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
                              O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                              O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
                              O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                              O23 - Service: HP ProtectTools Service - Hewlett-Packard Development Company, L.P - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe
                              O23 - Service: Drive Encryption Service (HpFkCryptService) - SafeBoot International - c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
                              O23 - Service: File Sanitizer for HP ProtectTools (HPFSService) - Hewlett-Packard - C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe
                              O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                              O23 - Service: HP Service (hpsrv) - Hewlett-Packard Corporation - C:\windows\system32\Hpservice.exe
                              O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
                              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                              O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                              O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
                              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                              O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
                              O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
                              O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
                              O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe
                              O23 - Service: RoxMediaDB10 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
                              O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                              O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
                              O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                              O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
                              0
                              1. Contributeur sécurité
                                le rapport est bon

                                pour voir si on peut nettoyer des choses encore fais ceci

                                Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent(car il est detecté a tort comme infection)

                                ▶ Télécharge et installe List&Kill'em et enregistre le sur ton bureau
                                http://sd-1.archive-host.com/membres/up/829108531491024/List_Killem_Install.exe

                                double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

                                coche la case "creer une icone sur le bureau"

                                une fois terminée , clic sur "terminer" et le programme se lancer seul

                                choisis la langue puis choisis l'option 1 = Mode Recherche

                                ▶ laisse travailler l'outil

                                à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

                                un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , mais ne le supprime pas pour l instant, le scan n'est pas fini.

                                ▶ Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"

                                tu peux supprimer le rapport catchme.log de ton bureau maintenant.
                                0