Problème spam/pub

Résolu
Salut salut,

Alors je vous explique la situation, pendant un moment j'ai pas activé mon antivirus (AVG) et depuis, je reçois pas mal de spam et de pub quand je suis sur internet. En parcourant ce forum, j'ai vu qu'on pouvait régler ça en copiant le rapport de hijack donc le voici:

C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\samsung\SAMSUN~2\SUPNOT~1.EXE
C:\Users\Alexis\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http:\\www.samsungcomputer.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll (file missing)
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [CAPON] C:\Windows\system32\Spool\Drivers\w32x86\3\CAPONN.EXE
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [pdfw] C:\Program Files\Amic Utilities\PDF Writer Pro\pdfwload.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [VeohPlugin] "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
O4 - HKCU\..\Run: [SansaDispatch] C:\Users\Alexis\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
O4 - HKCU\..\Run: [regrufk] "c:\users\alexis\appdata\local\regrufk.exe" regrufk
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Fenêtre d'état Canon LBP-810.LNK = C:\Windows\System32\spool\drivers\w32x86\3\CAPPSWK.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Samsung Update Plus - Unknown owner - C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe
O23 - Service: Syntek AVStream USB2.0 WebCam Service (StkSSrv) - Syntek America Inc. - C:\Windows\System32\StkCSrv.exe

--
End of file - 9451 bytes

Voila, j'espère que vous pourrez m'aider, Ciao !
Configuration: Windows Vista / Firefox 3.5.8

16 réponses

  1. Contributeur sécurité
    Bonjour,

    Télécharge Navilog d'il mafioso sur ton bureau.
    http://il.mafioso.pagesperso-orange.fr/Navifix/Navilog1.exe

    · Double-clique sur le raccourci de navilog ( sur le bureau ).
    Si sous Vista , clique droit sur le fichier et choisis exécuter en tant qu’administrateur
    · Sélectionne la langue puis valide.
    · Choisis l'option 1 ( ne choisit pas une autre option )

    Le PC va redémarrer pour nettoyer l'infection.

    Une fois l’analyse terminée, un rapport va s’ouvrir dans le bloc-notes.
    Tu copies et colles le texte de ce rapport dans ton prochain message.

    Note : Si tu ne le trouves pas, il est en C:\Cleannavi.txt.


    Je serais de retour sur le forum vers 14 h.

    A+
    1. Edit :

      bonjour Verni29 :-)

      à toi l'honneur et bonne chasse ;)

      un petit coucou à MDG ;)
      1. wow ! ça a été rapide ! Bah voila j'ai fait comme tu m'as dit,

        Fix Navipromo version 4.0.6 commencé le 21/02/2010 16:59:39,69

        !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
        !!! Postez ce rapport sur le forum pour le faire analyser !!!

        Outil exécuté depuis C:\Program Files\navilog1

        Mise à jour le 03.01.2010 à 11h00 par IL-MAFIOSO

        Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
        X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU P7350 @ 2.00GHz )
        BIOS : Phoenix SecureCore(tm) NB Version 06SU.MP01.20081021.HCW
        USER : Alexis ( Administrator )
        BOOT : Normal boot

        Antivirus : AVG Anti-Virus Free 8.0 (Activated)

        C:\ (Local Disk) - NTFS - Total:111 Go (Free:16 Go)
        D:\ (Local Disk) - NTFS - Total:110 Go (Free:86 Go)
        E:\ (CD or DVD)

        Recherche executée en mode normal

        Nettoyage exécuté au redémarrage de l'ordinateur

        C:\Windows\prefetch\GAME.EXE-D4F0C478.pf supprimé !
        C:\Users\Alexis\AppData\Local\regrufk.exe supprimé !
        C:\Users\Alexis\AppData\Local\regrufk.dat supprimé !
        C:\Users\Alexis\AppData\Local\regrufk_nav.dat supprimé !
        C:\Users\Alexis\AppData\Local\regrufk_navps.dat supprimé !

        Nettoyage contenu C:\Windows\Temp effectué !
        Nettoyage contenu C:\Users\Alexis\AppData\Local\Temp effectué !

        *** Sauvegarde du Registre vers dossier Safebackup ***

        sauvegarde du Registre réalisée avec succès !

        *** Nettoyage Registre ***

        Nettoyage Registre Ok

        *** Scan terminé 21/02/2010 17:06:33,03 ***
        1. Contributeur sécurité
          Re,

          Le problème de publicités doit être réglé.
          Tu me diras si il y a des améliorations.

          On va vérifier si le PC est propre.

          Commence par ceci.

          Télécharge Random's System Information Tool (RSIT) de random/random et enregistre le sur ton Bureau.
          http://images.malwareremoval.com/random/RSIT.exe

          # Double-clique sur " RSIT.exe " pour le lancer .
          ( Si sous Vista : Click droit sur le fichier et choisir exécuter en tant qu'administrateur )
          # dans la fenêtre qui va s’ouvrir choisis 1 month pour l'option "List files/folders created ...".
          # clique ensuite sur " Continue " pour lancer l'analyse ...

          Si la dernière version de HijackThis n'est pas trouvée sur ton PC, RSIT la téléchargera et te demandera d'accepter la licence.

          Attends jusqu’à la fin de l’analyse. deux rapports vont être crées.

          # Poste en deux messages le contenu de " log.txt ", et de " info.txt " ( dans la barre des tâches).

          Note : Si tu ne les trouves pas,les rapports sont sauvegardés dans le dossier C:\rsit.

          A+
          1. alors déjà voila pour le log.txt:
            Logfile of random's system information tool 1.06 (written by random/random)
            Run by Alexis at 2010-02-21 18:00:40
            Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
            System drive C: has 17 GB (15%) free of 115 GB
            Total RAM: 2008 MB (46% free)

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 18:01:18, on 21/02/2010
            Platform: Windows Vista SP1 (WinNT 6.00.1905)
            MSIE: Internet Explorer v8.00 (8.00.6001.18882)
            Boot mode: Normal

            Running processes:
            C:\Windows\system32\Dwm.exe
            C:\Windows\Explorer.EXE
            C:\Windows\system32\taskeng.exe
            C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
            C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe
            C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
            C:\Windows\system32\conime.exe
            C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe
            C:\Windows\system32\igfxext.exe
            C:\Windows\system32\igfxsrvc.exe
            C:\Windows\System32\rundll32.exe
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\Windows\System32\igfxtray.exe
            C:\Windows\System32\hkcmd.exe
            C:\Windows\System32\igfxpers.exe
            C:\Windows\RtHDVCpl.exe
            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
            C:\Program Files\AVG\AVG8\avgtray.exe
            C:\Program Files\Winamp\winampa.exe
            C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
            C:\Program Files\Java\jre6\bin\jusched.exe
            C:\Program Files\Windows Sidebar\sidebar.exe
            C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
            C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
            C:\Users\Alexis\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
            C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
            C:\Windows\System32\spool\drivers\w32x86\3\CAPPSWK.EXE
            C:\Windows\System32\spool\drivers\w32x86\3\CAPPSWK.EXE
            C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
            C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
            C:\Windows\system32\wuauclt.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\Users\Alexis\Downloads\RSIT.exe
            C:\Windows\system32\SearchFilterHost.exe
            C:\Users\Alexis\Downloads\Alexis.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http:\\www.samsungcomputer.com
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
            R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
            R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
            O1 - Hosts: ::1 localhost
            O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
            O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
            O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
            O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
            O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll (file missing)
            O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
            O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
            O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
            O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
            O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
            O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
            O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
            O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
            O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
            O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
            O4 - HKLM\..\Run: [CAPON] C:\Windows\system32\Spool\Drivers\w32x86\3\CAPONN.EXE
            O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
            O4 - HKLM\..\Run: [pdfw] C:\Program Files\Amic Utilities\PDF Writer Pro\pdfwload.exe
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
            O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
            O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
            O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
            O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
            O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
            O4 - HKCU\..\Run: [VeohPlugin] "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
            O4 - HKCU\..\Run: [SansaDispatch] C:\Users\Alexis\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
            O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
            O4 - Global Startup: BTTray.lnk = ?
            O4 - Global Startup: Fenêtre d'état Canon LBP-810.LNK = C:\Windows\System32\spool\drivers\w32x86\3\CAPPSWK.EXE
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
            O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
            O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
            O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
            O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
            O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
            O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
            O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
            O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
            O13 - Gopher Prefix:
            O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
            O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
            O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
            O20 - AppInit_DLLs: avgrsstx.dll
            O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
            O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
            O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
            O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
            O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
            O23 - Service: Samsung Update Plus - Unknown owner - C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe
            O23 - Service: Syntek AVStream USB2.0 WebCam Service (StkSSrv) - Syntek America Inc. - C:\Windows\System32\StkCSrv.exe
            1. info.txt logfile of random's system information tool 1.06 2010-02-21 18:01:20

              ======Uninstall list======

              Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
              Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
              Adobe Reader 8.1.6 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81300000003}
              dBpowerAMP Music Converter-->"C:\Windows\system32\SpoonUninstall.exe" <uninstall>C:\Windows\system32\SpoonUninstall-dBpowerAMP Music Converter.dat
              DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
              eMule-->"C:\Program Files\eMule\Uninstall.exe"
              GDR 4053 for SQL Server Database Services 2005 ENU (KB970892)-->C:\Windows\SQL9_KB970892_ENU\Hotfix.exe /Uninstall
              Gestionnaire de contacts professionnels pour Outlook 2007 SP2-->"C:\Program Files\Microsoft Small Business\Business Contact Manager\SetupBootstrap\Setup.exe" /remove {69ca8988-1c6c-4285-b8af-db780a6e42af}
              Gestionnaire de contacts professionnels pour Outlook 2007 SP2-->MsiExec.exe /X{69CA8988-1C6C-4285-B8AF-DB780A6E42AF}
              HijackThis 2.0.2-->"C:\Users\Alexis\Downloads\HijackThis.exe" /uninstall
              Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
              Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
              Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
              Microsoft .NET Framework 3.5 SP1-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
              Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
              Microsoft Office 2003 Web Components-->MsiExec.exe /I{90A4040C-6000-11D3-8CFE-0150048383C9}
              Microsoft Office 2007 Primary Interop Assemblies-->MsiExec.exe /X{50120000-1105-0000-0000-0000000FF1CE}
              Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)-->MsiExec.exe /I{480DBB60-F0B6-45F2-B26F-1A2E11197791}
              Microsoft SQL Server 2005-->"C:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\ARPWrapper.exe" /Remove
              Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
              Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
              Mozilla Firefox (3.5.8)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
              NDSROM Player-->C:\Users\Alexis\Downloads\rom\Uninstal.exe
              StepMania (remove only)-->"C:\Program Files\StepMania\uninstall.exe"
              Stream Torrent 1.0-->"C:\Program Files\StreamTorrent 1.0\uninstall.exe"
              SUPER © Version 2009.bld.36 (June 10, 2009)-->C:\PROGRA~1\ERIGHT~1\SUPER\Setup.exe /remove /q0
              Tag&Rename 3.5.2-->"C:\Program Files\TagRename\unins000.exe"
              TVUPlayer 2.4.9.1-->C:\Program Files\TVUPlayer\uninst.exe
              Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
              VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
              VLC media player 1.0.5-->C:\Program Files\VideoLAN\VLC\uninstall.exe
              Winamp-->"C:\Program Files\Winamp\UninstWA.exe"
              WinDS PRO-->"C:\ProgramData\WinDS PRO\windsprox.exe" "/U:C:\ProgramData\WinDS PRO\windsprox.xml"

              ======Hosts File======

              127.0.0.1 www.007guard.com
              127.0.0.1 007guard.com
              127.0.0.1 008i.com
              127.0.0.1 www.008k.com
              127.0.0.1 008k.com
              127.0.0.1 www.00hq.com
              127.0.0.1 00hq.com
              127.0.0.1 010402.com
              127.0.0.1 www.032439.com
              127.0.0.1 032439.com

              ======Security center information======

              AV: AVG Anti-Virus Free
              AS: AVG Anti-Virus Free (disabled)
              AS: Windows Defender

              ======System event log======

              Computer Name: PC-de-Alexis
              Event Code: 15300
              Message: Échec du démarrage de MTP WPD Driver, erreur : 0x80070005
              Record Number: 136123
              Source Name: Microsoft-Windows-WPD-MTPClassDriver
              Time Written: 20100221160524.000000-000
              Event Type: Erreur
              User:

              Computer Name: PC-de-Alexis
              Event Code: 7000
              Message: Le service Parallel port driver n'a pas pu démarrer en raison de l'erreur :
              Le service ne peut pas être démarré parce qu'il est désactivé ou qu'aucun périphérique activé ne lui est associé.
              Record Number: 136167
              Source Name: Service Control Manager
              Time Written: 20100221160622.000000-000
              Event Type: Erreur
              User:

              Computer Name: PC-de-Alexis
              Event Code: 1001
              Message: L’initialisation de l’application a échoué. Dernière erreur : 0x80070032
              Record Number: 136205
              Source Name: Microsoft-Windows-LanguagePackSetup
              Time Written: 20100221160659.581246-000
              Event Type: Erreur
              User: AUTORITE NT\SYSTEM

              Computer Name: PC-de-Alexis
              Event Code: 4
              Message: Le spouleur d’impression n’a pas pu rouvrir une connexion d’imprimante existante car il n’a pas pu lire les informations de configuration dans la clé de Registre S-1-5-18\Printers\Connections. Le spouleur d’impression n’a pas pu ouvrir la clé de Registre. Ceci peut se produire si la clé de Registre est endommagée ou absente, ou si le Registre est momentanément indisponible.
              Record Number: 136206
              Source Name: Microsoft-Windows-SpoolerWin32SPL
              Time Written: 20100221160703.000000-000
              Event Type: Avertissement
              User:

              Computer Name: PC-de-Alexis
              Event Code: 4
              Message: Le spouleur d’impression n’a pas pu rouvrir une connexion d’imprimante existante car il n’a pas pu lire les informations de configuration dans la clé de Registre S-1-5-18\Printers\Connections. Le spouleur d’impression n’a pas pu ouvrir la clé de Registre. Ceci peut se produire si la clé de Registre est endommagée ou absente, ou si le Registre est momentanément indisponible.
              Record Number: 136207
              Source Name: Microsoft-Windows-SpoolerWin32SPL
              Time Written: 20100221160703.000000-000
              Event Type: Avertissement
              User:

              =====Application event log=====

              Computer Name: PC-de-Alexis
              Event Code: 1024
              Message: Produit : Microsoft Office Enterprise 2007 - La mise à jour ‘Security Update for 2007 Microsoft Office System (KB973704)’ n’a pas pu être installée. Code d’erreur 1603. Windows Installer peut créer des journaux pour faciliter la résolution des éventuelles erreurs d’installation des packages logiciels. Utilisez le lien suivant pour afficher des instructions concernant l’activation des journaux : https://docs.microsoft.com/en-us/troubleshoot/windows-client/application-management/enable-windows-installer-logging
              Record Number: 35991
              Source Name: MsiInstaller
              Time Written: 20100221110241.000000-000
              Event Type: Erreur
              User: PC-de-Alexis\Alexis

              Computer Name: PC-de-Alexis
              Event Code: 1024
              Message: Produit : Microsoft Office Enterprise 2007 - La mise à jour ‘Security Update for Microsoft Office Publisher 2007 (KB969693)’ n’a pas pu être installée. Code d’erreur 1603. Windows Installer peut créer des journaux pour faciliter la résolution des éventuelles erreurs d’installation des packages logiciels. Utilisez le lien suivant pour afficher des instructions concernant l’activation des journaux : https://docs.microsoft.com/en-us/troubleshoot/windows-client/application-management/enable-windows-installer-logging
              Record Number: 35995
              Source Name: MsiInstaller
              Time Written: 20100221110334.000000-000
              Event Type: Erreur
              User: PC-de-Alexis\Alexis

              Computer Name: PC-de-Alexis
              Event Code: 1024
              Message: Produit : Microsoft Office Enterprise 2007 - La mise à jour ‘Update for Microsoft Office Word 2007 (KB974561)’ n’a pas pu être installée. Code d’erreur 1603. Windows Installer peut créer des journaux pour faciliter la résolution des éventuelles erreurs d’installation des packages logiciels. Utilisez le lien suivant pour afficher des instructions concernant l’activation des journaux : https://docs.microsoft.com/en-us/troubleshoot/windows-client/application-management/enable-windows-installer-logging
              Record Number: 35999
              Source Name: MsiInstaller
              Time Written: 20100221110435.000000-000
              Event Type: Erreur
              User: PC-de-Alexis\Alexis

              Computer Name: PC-de-Alexis
              Event Code: 3
              Message: La configuration du protocole AdminConnection\TCP n'est pas valide dans l'instance SQL MSSMLBIZ.
              Record Number: 36032
              Source Name: SQLBrowser
              Time Written: 20100221160504.000000-000
              Event Type: Avertissement
              User:

              Computer Name: PC-de-Alexis
              Event Code: 10
              Message: Le filtre d’événement avec la requête « SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99 » n’a pas pu être réactivé dans l’espace de noms « //./root/CIMV2 » à cause de l’erreur 0x80041003. Les événements ne peuvent pas être délivrés à travers ce filtre tant que le problème ne sera pas corrigé.
              Record Number: 36046
              Source Name: Microsoft-Windows-WMI
              Time Written: 20100221160621.000000-000
              Event Type: Erreur
              User:

              =====Security event log=====

              Computer Name: PC-de-Alexis
              Event Code: 4907
              Message: Les paramètres d’audit sur l’objet ont changé.

              Sujet :
              ID de sécurité : S-1-5-18
              Nom du compte : PC-DE-ALEXIS$
              Domaine du compte : WORKGROUP
              ID d’ouverture de session : 0x3e7

              Objet :
              Serveur de l’objet : Security
              Type d’objet : File
              Nom de l’objet : C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll
              ID du handle : 0x14

              Informations sur le processus :
              ID du processus : 0x2f0
              Nom du processus : C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\poqexec.exe

              Paramètres d’audit :
              Descripteur de sécurité d’origine :
              Nouveau descripteur de sécurité : S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
              Record Number: 18637
              Source Name: Microsoft-Windows-Security-Auditing
              Time Written: 20090713080538.035318-000
              Event Type: Succès de l'audit
              User:

              Computer Name: PC-de-Alexis
              Event Code: 4907
              Message: Les paramètres d’audit sur l’objet ont changé.

              Sujet :
              ID de sécurité : S-1-5-18
              Nom du compte : PC-DE-ALEXIS$
              Domaine du compte : WORKGROUP
              ID d’ouverture de session : 0x3e7

              Objet :
              Serveur de l’objet : Security
              Type d’objet : File
              Nom de l’objet : C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.Data.dll
              ID du handle : 0x14

              Informations sur le processus :
              ID du processus : 0x2f0
              Nom du processus : C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\poqexec.exe

              Paramètres d’audit :
              Descripteur de sécurité d’origine :
              Nouveau descripteur de sécurité : S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
              Record Number: 18638
              Source Name: Microsoft-Windows-Security-Auditing
              Time Written: 20090713080538.253718-000
              Event Type: Succès de l'audit
              User:

              Computer Name: PC-de-Alexis
              Event Code: 4907
              Message: Les paramètres d’audit sur l’objet ont changé.

              Sujet :
              ID de sécurité : S-1-5-18
              Nom du compte : PC-DE-ALEXIS$
              Domaine du compte : WORKGROUP
              ID d’ouverture de session : 0x3e7

              Objet :
              Serveur de l’objet : Security
              Type d’objet : File
              Nom de l’objet : C:\Windows\Microsoft.NET\Framework\v2.0.50727\InstallSqlState.sql
              ID du handle : 0x14

              Informations sur le processus :
              ID du processus : 0x2f0
              Nom du processus : C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\poqexec.exe

              Paramètres d’audit :
              Descripteur de sécurité d’origine : S:AI
              Nouveau descripteur de sécurité :
              Record Number: 18639
              Source Name: Microsoft-Windows-Security-Auditing
              Time Written: 20090713080538.253718-000
              Event Type: Succès de l'audit
              User:

              Computer Name: PC-de-Alexis
              Event Code: 4907
              Message: Les paramètres d’audit sur l’objet ont changé.

              Sujet :
              ID de sécurité : S-1-5-18
              Nom du compte : PC-DE-ALEXIS$
              Domaine du compte : WORKGROUP
              ID d’ouverture de session : 0x3e7

              Objet :
              Serveur de l’objet : Security
              Type d’objet : File
              Nom de l’objet : C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.dll
              ID du handle : 0x14

              Informations sur le processus :
              ID du processus : 0x2f0
              Nom du processus : C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\poqexec.exe

              Paramètres d’audit :
              Descripteur de sécurité d’origine :
              Nouveau descripteur de sécurité : S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
              Record Number: 18640
              Source Name: Microsoft-Windows-Security-Auditing
              Time Written: 20090713080538.394118-000
              Event Type: Succès de l'audit
              User:

              Computer Name: PC-de-Alexis
              Event Code: 4907
              Message: Les paramètres d’audit sur l’objet ont changé.

              Sujet :
              ID de sécurité : S-1-5-18
              Nom du compte : PC-DE-ALEXIS$
              Domaine du compte : WORKGROUP
              ID d’ouverture de session : 0x3e7

              Objet :
              Serveur de l’objet : Security
              Type d’objet : File
              Nom de l’objet : C:\Windows\Microsoft.NET\Framework\v2.0.50727\peverify.dll
              ID du handle : 0x14

              Informations sur le processus :
              ID du processus : 0x2f0
              Nom du processus : C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\poqexec.exe

              Paramètres d’audit :
              Descripteur de sécurité d’origine :
              Nouveau descripteur de sécurité : S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
              Record Number: 18641
              Source Name: Microsoft-Windows-Security-Auditing
              Time Written: 20090713080538.487718-000
              Event Type: Succès de l'audit
              User:

              ======Environment variables======

              "ComSpec"=%SystemRoot%\system32\cmd.exe
              "FP_NO_HOST_CHECK"=NO
              "OS"=Windows_NT
              "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Microsoft SQL Server\90\Tools\binn\;C:\Program Files\QuickTime\QTSystem\
              "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
              "PROCESSOR_ARCHITECTURE"=x86
              "TEMP"=%SystemRoot%\TEMP
              "TMP"=%SystemRoot%\TEMP
              "USERNAME"=SYSTEM
              "windir"=%SystemRoot%
              "PROCESSOR_LEVEL"=6
              "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 23 Stepping 6, GenuineIntel
              "PROCESSOR_REVISION"=1706
              "NUMBER_OF_PROCESSORS"=2
              "TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
              "DFSTRACINGON"=FALSE
              "CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
              "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

              -----------------EOF-----------------

              Merci d'avance !
          2. Contributeur sécurité
            Le rapport est propre.
            Il faudra tout de même vérifier pour les supports amovibles et les vacciner de toute façon.

            1/ Je remarque également que tu as l'émulateur DaemonTools sur le PC.
            Ce logiciel est accompagné d'une barre d'outil ask qu'on peut parfois installé.

            Télécharge AD-Remover de C_XX sur ton bureau :
            http://pagesperso-orange.fr/NosTools/C_XX/AD-R.exe

            Tu te déconnectes du net et ferme toutes les applications en cours.

            Sous Vista, il faut nécessairement désactiver l'UAC ou contrôle de compte utilisateur.

            Tuto : https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

            * Double-clique sur AD-R.exe .
            Si sous Vista --> click droit sur le fichier et choisir exécuter en tant qu'administrateur.
            * Au menu principal, choisis l'option "S" pour effectuer le nettoyage .

            un rapport va apparaitre. Poste le contenu dans ton prochain message.

            Note : Il se trouve en C:\AD-Report-SCAN.log

            2/ Télécharge USBFix ( par Chiquitine29 ) sur ton bureau.

            (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptibles d'avoir été infectées sans les ouvrir
            • Double clic sur UsbFix.exe présent sur ton bureau .
            • Au menu principal choisis l'option " F " pour français et tape sur [entrée] .
            • Au second menu Choisis l'option " 1 " (recherche) et tape sur [entrée]
            • Laisse travailler l'outil.
            • Ensuite post le rapport UsbFix.txt qui apparaitra.

            Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )


            tuto

            A+
            1. merci beaucoup ! mon problème a été plus que réglé et rapidement en plus !

              ça fait plaisir !
              1. alors voila pour le premier:

                * Internet Explorer Version 8.0.6001.18882 *
                .
                [HKEY_CURRENT_USER\..\Internet Explorer\Main]
                .
                Do404Search: 01000000
                Local Page: C:\Windows\system32\blank.htm
                Show_ToolBar: yes
                Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
                Enable Browser Extensions: yes
                Start Page: http:\\www.samsungcomputer.com
                Default_Page_URL: http:\\www.samsungcomputer.com
                .
                [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
                .
                Start Page: hxxp://go.microsoft.com/fwlink/?LinkId=69157
                Default_Page_URL: http:\\www.samsungcomputer.com
                Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
                Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
                Delete_Temp_Files_On_Exit: yes
                Local Page: C:\Windows\System32\blank.htm
                .
                [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
                .
                Tabs: res://ieframe.dll/tabswelcome.htm
                .
                ============== Suspect (Cracks, Serials, ...) ==============
                .
                C:\Users\Alexis\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
                C:\Users\Alexis\AppData\Roaming\uTorrent\Tag & Rename 3.5.2 & Patch.torrent
                .
                ===================================
                .
                2792 Octet(s) - C:\Ad-Report-SCAN[1].log
                .
                45 Fichier(s) - C:\Users\Alexis\AppData\Local\Temp
                2 Fichier(s) - C:\Windows\Temp
                96 Fichier(s) - C:\Windows\Prefetch
                .
                2 Fichier(s) - C:\Ad-Remover\BACKUP
                0 Fichier(s) - C:\Ad-Remover\QUARANTINE
                .
                Fin à: 22:21:38 | 21/02/2010 - SCAN[1]
                .
                ============== E.O.F ==============
                .
                1. et usbfix:

                  ############################## | UsbFix V6.097 |

                  User : Alexis (Administrateurs) # PC-DE-ALEXIS
                  Update on 20/02/2010 by El Desaparecido , C_XX & Chimay8
                  Start at: 22:40:08 | 21/02/2010
                  Website : http://pagesperso-orange.fr/NosTools/index.html
                  Contact : FindyKill.Contact@gmail.com

                  Intel(R) Core(TM)2 Duo CPU P7350 @ 2.00GHz
                  Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
                  Internet Explorer 8.0.6001.18882
                  Windows Firewall Status : Enabled
                  AV : AVG Anti-Virus Free 8.0 [ Enabled | Updated ]

                  C:\ -> Disque fixe local # 111,88 Go (16,18 Go free) # NTFS
                  D:\ -> Disque fixe local # 111 Go (86,24 Go free) # NTFS
                  E:\ -> Disque CD-ROM

                  ############################## | Processus actifs |

                  C:\Windows\System32\smss.exe
                  C:\Windows\system32\csrss.exe
                  C:\Windows\system32\wininit.exe
                  C:\Windows\system32\csrss.exe
                  C:\Windows\system32\services.exe
                  C:\Windows\system32\lsass.exe
                  C:\Windows\system32\lsm.exe
                  C:\Windows\system32\winlogon.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\SLsvc.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\Explorer.EXE
                  C:\Windows\System32\spoolsv.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
                  C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe
                  C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
                  C:\Windows\system32\conime.exe
                  C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe
                  C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                  C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
                  C:\Program Files\Bonjour\mDNSResponder.exe
                  C:\Windows\system32\svchost.exe
                  C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                  C:\Windows\system32\svchost.exe
                  C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                  C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
                  C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                  C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\System32\StkCSrv.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\system32\SearchIndexer.exe
                  C:\Windows\system32\igfxext.exe
                  C:\Windows\system32\igfxsrvc.exe
                  C:\Windows\System32\rundll32.exe
                  C:\Windows\system32\CAPRPCSK.EXE
                  C:\Windows\system32\spool\drivers\w32x86\3\CAPPSWK.EXE
                  C:\Program Files\Windows Defender\MSASCui.exe
                  C:\Windows\System32\igfxtray.exe
                  C:\Windows\System32\igfxpers.exe
                  C:\Windows\RtHDVCpl.exe
                  C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
                  C:\Program Files\AVG\AVG8\avgtray.exe
                  C:\Program Files\Winamp\winampa.exe
                  C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
                  C:\Program Files\Java\jre6\bin\jusched.exe
                  C:\Program Files\Windows Sidebar\sidebar.exe
                  C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
                  C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                  C:\Users\Alexis\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
                  C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
                  C:\Windows\System32\spool\drivers\w32x86\3\CAPPSWK.EXE
                  C:\Windows\System32\spool\drivers\w32x86\3\CAPPSWK.EXE
                  C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
                  C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
                  C:\Windows\system32\wuauclt.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\Windows\system32\WUDFHost.exe
                  C:\Windows\System32\mobsync.exe
                  C:\Windows\system32\wbem\wmiprvse.exe

                  ################## | Elements infectieux |

                  ################## | Registre |

                  ################## | Mountpoints2 |

                  HKCU\..\..\Explorer\MountPoints2\{d8ad3619-f0f1-11de-bbfb-002269d1fff9}
                  shell\AutoRun\command =F:\WDSetup.exe

                  HKCU\..\..\Explorer\MountPoints2\{f24ed604-bff9-11de-8b40-002269d1fff9}
                  shell\AutoRun\command =F:\aoesetup.exe /autorun
                  shell\directx\command =F:\DirectX\dxsetup.exe
                  shell\dplay\command =F:\DirectX\dplay61a.exe
                  shell\dxdiag\command =F:\goodies\ar40eng.exe
                  shell\dxinfo\command =F:\goodies\DirectX\dxinfo.exe
                  shell\dxtest\command =F:\DirectX\dxdiag.exe
                  shell\dxtool\command =F:\goodies\DirectX\dxtool.exe
                  shell\log\command =F:\goodies\machine\machine.exe -l
                  shell\machine\command =F:\goodies\machine\machine.exe
                  shell\setup\command =F:\aoesetup.exe /autorun
                  shell\zone\command =F:\goodies\mszone\zoneA600.exe

                  HKCU\..\..\Explorer\MountPoints2\{f24ed605-bff9-11de-8b40-002269d1fff9}
                  shell\AutoRun\command =G:\Autorun.exe

                  HKCU\..\..\Explorer\MountPoints2\{f24ed60e-bff9-11de-8b40-002269d1fff9}
                  shell\AutoRun\command =J:\setupSNK.exe

                  HKCU\..\..\Explorer\MountPoints2\{f8797b1b-c784-11dd-b5e5-002269d1fff9}
                  shell\AutoRun\command =F:\Autorun.exe

                  ################## | Vaccin |

                  (!) Cet ordinateur n'est pas vacciné !

                  ################## | ! Fin du rapport # UsbFix V6.097 ! |
                  1. Contributeur sécurité
                    OK,

                    Pas de trace d'infections sur les supports.
                    ON va les vacciner. Il y a de plus en plus d'infections de ce type.
                    Et il suffit de se connecter à un PC infecté pour que la clé utilisée soit également infecté.

                    1/ (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptiblse d avoir été infectées sans les ouvrir

                    • Double clic sur usbfix.exe présent sur ton bureau
                    • Au menu principal choisis l'option " F " pour français et tape sur [entrée] .
                    • Au second menu Choisis l'option " 3 " ( Vaccination ) et tape sur [entrée]
                    • Ton bureau disparaitra et le pc redémarrera .
                    • Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.
                    • Ensuite poste le rapport UsbFix.txt qui apparaitra avec le bureau .

                    Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

                    2/ Fais également deux analyses pour vérifier qu'il n'y a aucun virus sur le PC.

                    Tu télécharges MalwareBytes.
                    http://www.malwarebytes.org/mbam/program/mbam-setup.exe

                    Tu l'installes. Choisis les options par défaut.
                    # A la fin de l’installation, il te sera demandé de mettre à jour MalwareBytes et de l’éxecuter .
                    # Accepte. Après la, mise à jour, le logiciel va s’ouvrir.

                    # Dans l’onglet Recherche, sélectionne Exécuter un examen complet.
                    # Clique sur recherche. Tu ne sélectionnes que les disques durs de l’ordinateur.
                    # Clique sur lancer l’examen.

                    # A la fin de la recherche, comme il est demandé, clique sur afficher les résultats.
                    # Si des infections sont trouvées, clique sur Supprimer la sélection.
                    Tu postes le rapport dans ton prochain message.

                    Si tu ne retrouves pas le rapport, ouvre MalwareBytes et regarde dans l’onglet Rapport/logs. Il y est. Clique dessus et choisir ouvrir.

                    3/ Puis un scan en ligne .
                    Suis le tuto : https://forum.pcastuces.com/default.asp
                    Poste le rapport.

                    A+
                    1. Ca c'est pour usbfix:

                      ############################## | UsbFix V6.097 |

                      User : Alexis (Administrateurs) # PC-DE-ALEXIS
                      Update on 20/02/2010 by El Desaparecido , C_XX & Chimay8
                      Start at: 00:36:23 | 22/02/2010
                      Website : http://pagesperso-orange.fr/NosTools/index.html
                      Contact : FindyKill.Contact@gmail.com

                      Intel(R) Core(TM)2 Duo CPU P7350 @ 2.00GHz
                      Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
                      Internet Explorer 8.0.6001.18882
                      Windows Firewall Status : Enabled
                      AV : AVG Anti-Virus Free 8.0 [ Enabled | Updated ]

                      C:\ -> Disque fixe local # 111,88 Go (16,01 Go free) # NTFS
                      D:\ -> Disque fixe local # 111 Go (86,24 Go free) # NTFS
                      E:\ -> Disque CD-ROM

                      ################## | Vaccination |

                      # C:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
                      # D:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).

                      ################## | ! Fin du rapport # UsbFix V6.097 ! |
                      1. et voila pour malwarebytes:

                        Malwarebytes' Anti-Malware 1.44
                        Version de la base de données: 3772
                        Windows 6.0.6001 Service Pack 1
                        Internet Explorer 8.0.6001.18882

                        22/02/2010 08:48:40
                        mbam-log-2010-02-22 (08-48-40).txt

                        Type de recherche: Examen complet (C:\|D:\|)
                        Eléments examinés: 260864
                        Temps écoulé: 1 hour(s), 32 minute(s), 2 second(s)

                        Processus mémoire infecté(s): 0
                        Module(s) mémoire infecté(s): 0
                        Clé(s) du Registre infectée(s): 0
                        Valeur(s) du Registre infectée(s): 0
                        Elément(s) de données du Registre infecté(s): 0
                        Dossier(s) infecté(s): 0
                        Fichier(s) infecté(s): 0

                        Processus mémoire infecté(s):
                        (Aucun élément nuisible détecté)

                        Module(s) mémoire infecté(s):
                        (Aucun élément nuisible détecté)

                        Clé(s) du Registre infectée(s):
                        (Aucun élément nuisible détecté)

                        Valeur(s) du Registre infectée(s):
                        (Aucun élément nuisible détecté)

                        Elément(s) de données du Registre infecté(s):
                        (Aucun élément nuisible détecté)

                        Dossier(s) infecté(s):
                        (Aucun élément nuisible détecté)

                        Fichier(s) infecté(s):
                        (Aucun élément nuisible détecté)
                        1. Contributeur sécurité
                          Ok,

                          Fais le scan en ligne.
                          On termine ensuite.

                          A+
                          1. BitDefender Online Scanner - Rapport virus en temps r�el

                            G�n�r� �: Tue, Feb 23, 2010 - 10:54:54

                            Info d'analyse

                            Fichiers scann�s

                            102108

                            Infect�s Fichiers

                            0

                            Virus D�tect�s

                            Aucun virus trouvé.

                            Ce sommaire du processus d'analyse sera utilis� par les laboratoires Antivirus BitDefender pour cr�er des statistiques agr�gu�es sur l'activit� des virus dans le monde.

                            Bon bah je crois que c'est clair, mon pc est propre ! en tout cas merci pour tout !
                            1. Contributeur sécurité
                              maxilevrai,

                              Oui, le PC doit être propre. Tu n'avais qu'une infection très précise.

                              Une information sur comment tu as attrapé cette infection :

                              L’adware MagicControl/Navipromo est installé par les programmes : go-astro, GoRecord, HotTVPlayer / HotTVPlayer & Paris Hilton , Live-Player, MailSkinner, Messenger Skinner, Instant Access, InternetGameBox, Officiale Emule (Version d'Emule modifiée), Sudoplanet, Webmediaplayer, Sur le site w*w.games-desktop.com.

                              ----------------------------------------------------------------------------------------------

                              On termine.

                              1) On va enlever les logiciels qui ont été utilisés..
                              Télécharge ToolsCleaner .sur le bureau
                              http://pc-system.fr/

                              Double-clique sur ToolsCleaner2.exe --> Recherche --> Suppression.
                              Il est possible que ton bureau disparaisse.

                              Fais un copier/coller du rapport qui se trouve dans C:\TCleaner.txt.

                              2/ Tu vas utiliser CCleaner.
                              http://www.commentcamarche.net/telecharger/telecharger 168 ccleaner

                              utilise les fonctions nettoyeur et registre.

                              3) Il est préférable maintenant que ton PC est de créer un point propre pour une utilisation ultérieure.

                              Pour recréer un point de restauration :
                              Démarrer --> Programmes --> Accessoires --> Outils système --> Restauration système
                              Choisis "Créer un point de restauration". Suis les invites.

                              --------------------------------------------------------------------------------------------------------

                              Ton PC est propre.
                              Sois prudent dans ton surf.

                              Un peu de lecture : projet antimalwares

                              ---------------------------------------------------------------------------------------------------------

                              /!\ Tu peux aussi dénoncer ton infection /!\
                              http://www.malwarecomplaints.info/phpBB3/viewforum.php?f=10

                              Lis l'article suivant pour t'aider dans la démarche : http://www.malekal.com/malwarecomplaints.html
                              Pour ton cas, choisis l'infection Navipromo/Egaccess.

                              -----------------------------------------------------------------------------------------------------------

                              Peux-tu mettre le sujet en résolu ? Merci.

                              En te souhaitant bonne lecture et bon surf.

                              Salut.