Virus artemis et 25 autres....

Résolu
Bonjour,

plein de soucis sur l'ordi de mes parents, difficile de se connecter à internet, Avast se fait oublier, c'est vista antivirus qui me dit qu'il y a 25 virus tous plus dangereux les uns que les autres...
si on pouvait jeter un coup d'oeil ce serait sympa...

d'avance merci...
Configuration: Windows Vista / Firefox 3.0.18

34 réponses

Résumé de la discussion

Le fil porte sur des soucis rencontrés sur un PC sous Windows Vista, avec des avertissements antiviraux et des messages concernant virus, ainsi que des difficultés de connexion à Internet après alertes Avast. Plusieurs réponses suggèrent de désactiver le pare-feu Windows si un autre antivirus ou pare-feu est en place, et recommandent de désinstaller Avast via utilitaire dédié pour éviter les conflits. D'autres interventions évoquent l'utilisation d'outils comme USBFix, l'analyse des rapports générés (par exemple VirusTotal), et la sauvegarde de logs pour suivre les éléments suspects avant d'éliminer les éléments indésirables. En parallèle, les échanges soulignent l'importance de rétablir une protection fiable, de privilégier des solutions antivirus éprouvées et de vérifier les résultats des outils de détection avant toute réinstallation.

Bobot (l’IA à votre service)
  1. Salut Benjhy,
    Demandes à Avast de faire un scan au démarrage ,peut-être que tu pourras les éliminer de cette façon.
    A+
    0
    1. oui m'enfin, c'est pas trop tard quand il y a des trojans, des bat, des spy etc...?
      bon en tout cas je viens de le lancer mais je vais juste constater, je ne suis pas un as dans ces trucs là!!!
      0
      1. bonjour bonjour!! (j'espère que je ne parle pas qu'à moi...)
        avast n'a rien trouvé mais antivirus vista m'en trouve 25, les deux peuvent ils fonctionner ensemble? ou, ils n'ont rien à voir?
        bref il y a toujours des messages d'alertes d'attaque...
        0
        1. Contributeur sécurité
          bonjour

          antivirus vista est un rogue (faux antiviris et fausses alertes)

          redemarres en mode sans echec avec réseau

          https://www.micro-astuce.com/depannage/demarrer-mode-sans-echec.php

          ensuite

          Téléchargez MalwareByte's Anti-Malware

          http://www.malwarebytes.org/mbam/program/mbam-setup.exe

          . Enregistres le sur le bureau
          . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
          . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
          . Si le pare-feu demande l'autorisation de se connecter pour malwarebytes, accepte
          . Une fois la mise à jour terminé
          . Rend-toi dans l'onglet, Recherche
          . Sélectionnes Exécuter un examen complet (examen assez long)
          . Cliques sur Rechercher
          . Le scan démarre.
          . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
          . Cliques sur Ok pour poursuivre.
          . Si des malwares ont été détectés, clique sur Afficher les résultats
          . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
          . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
          . Rends toi dans l'onglet rapport/log
          . Tu cliques dessus pour l'afficher, une fois affiché
          . Tu cliques sur edition en haut du boc notes, et puis sur sélectionner tous
          . Tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
          . tu cliques droit dans le cadre de la reponse et coller

          Si tu as besoin d'aide regarde ces tutoriels :
          Aide: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
          http://www.infos-du-net.com/forum/278396-11-tuto-malwarebytes-anti-malware-mbam

          0
          1. bonjour, tout d'abord merci de me prendre en charge,

            j'ai donc fait tout ce que tu m'as dit par contre: au moment d'afficher le rapport il affichait que l'ordi devait redémarrer et m'a demandé si je voulais continuer j'ai donc "répondu" oui et il a effectivement redémarrer...

            si je dis ça c'est parceque lorsque je suis allé rechercher le rapport il précise qu'il n'y a aucun élément infecté alors qu'après le scan il en avait détecté 21...

            bref voici le rapport:

            Malwarebytes' Anti-Malware 1.44
            Version de la base de données: 3785
            Windows 6.0.6001 Service Pack 1 (Safe Mode)
            Internet Explorer 7.0.6001.18000

            24/02/2010 21:08:10
            mbam-log-2010-02-24 (21-08-10).txt

            Type de recherche: Examen complet (C:\|D:\|E:\|)
            Eléments examinés: 315963
            Temps écoulé: 49 minute(s), 32 second(s)

            Processus mémoire infecté(s): 1
            Module(s) mémoire infecté(s): 0
            Clé(s) du Registre infectée(s): 6
            Valeur(s) du Registre infectée(s): 1
            Elément(s) de données du Registre infecté(s): 2
            Dossier(s) infecté(s): 0
            Fichier(s) infecté(s): 11

            Processus mémoire infecté(s):
            C:\Users\BAILLIE Hubert\AppData\Local\av.exe (Rogue.MultipleAV) -> Unloaded process successfully.

            Module(s) mémoire infecté(s):
            (Aucun élément nuisible détecté)

            Clé(s) du Registre infectée(s):
            HKEY_CLASSES_ROOT\TypeLib\{b6acb3f1-6a83-432c-b854-3e1056f87f4e} (Rogue.Eorezo) -> Quarantined and deleted successfully.
            HKEY_CLASSES_ROOT\Interface\{819db72d-1c28-4387-9778-e2ff3dc86f74} (Rogue.Eorezo) -> Quarantined and deleted successfully.
            HKEY_CLASSES_ROOT\CLSID\{64f56fc1-1272-44cd-ba6e-39723696e350} (Rogue.Eorezo) -> Quarantined and deleted successfully.
            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{64f56fc1-1272-44cd-ba6e-39723696e350} (Rogue.Eorezo) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64f56fc1-1272-44cd-ba6e-39723696e350} (Rogue.Eorezo) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\EoRezo (Rogue.Eorezo) -> Quarantined and deleted successfully.

            Valeur(s) du Registre infectée(s):
            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winusr (Adware.Gibmedia) -> Quarantined and deleted successfully.

            Elément(s) de données du Registre infecté(s):
            HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> Quarantined and deleted successfully.
            HKEY_CLASSES_ROOT\.exe\(default) (Hijacked.exeFile) -> Bad: (secfile) Good: (exefile) -> Quarantined and deleted successfully.

            Dossier(s) infecté(s):
            (Aucun élément nuisible détecté)

            Fichier(s) infecté(s):
            C:\Program Files\EoRezo\EoEngine.exe (Rogue.Eorezo) -> Quarantined and deleted successfully.
            C:\Program Files\EoRezo\EoAdv\EoAdv.dll (Rogue.Eorezo) -> Quarantined and deleted successfully.
            C:\Program Files\EoRezo\EoAdv\EoRezoBHO.dll (Rogue.Eorezo) -> Quarantined and deleted successfully.
            C:\Users\BAILLIE Hubert\Downloads\Moovida_setup.exe (Adware.NaviPromo) -> Quarantined and deleted successfully.
            C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JDIN951S\gibupt[1].exe (Adware.Gibmedia) -> Quarantined and deleted successfully.
            C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JDIN951S\gibusr[1].exe (Adware.Gibmedia) -> Quarantined and deleted successfully.
            C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SK9NP05Y\gibcom[1].dll (Adware.Gibmedia) -> Quarantined and deleted successfully.
            C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SK9NP05Y\gibidl[1].dll (Adware.Gibmedia) -> Quarantined and deleted successfully.
            C:\Windows\Temp\75AB.tmp (Adware.Gibmedia) -> Quarantined and deleted successfully.
            C:\Users\BAILLIE Hubert\AppData\Local\av.exe (Rogue.MultipleAV) -> Quarantined and deleted successfully.
            C:\Users\BAILLIE Hubert\Local Settings\Application Data\av.exe (ROGUE.Win7Antispyware2010) -> Quarantined and deleted successfully.
            0
            1. Contributeur sécurité
              ok

              tu peux vider la quarantaine

              regardons maintenant le reste du pc

              • Télécharge Random's System Information Tool (RSIT) de Random/Random.

              (outil de diagnostic)

              http://images.malwareremoval.com/random/RSIT.exe

              • Enregistre le sur ton Bureau.

              • Double clique sur RSIT.exe pour lancer l'outil.

              • Clique sur "Continue" à l'écran Disclaimer.

              • Si l'outil HijackThis n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu s'il te le demande)

              et tu devras accepter la licence.

              • Une fois le scan terminé, deux rapports vont apparaître : poste les dans deux messages séparés stp

              Les rapports se trouvent à cet endroit:
              C:\rsit\info.txt
              C:\rsit\log.txt
              0
              1. quarantaine supprimée;

                voici le rapport INFO (bon courage!)

                info.txt logfile of random's system information tool 1.06 2010-02-24 21:56:28

                ======Uninstall list======

                -->MsiExec.exe /I{403EF592-953B-4794-BCEF-ECAB835C2095}
                Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
                Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
                Adobe Reader 9.3 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A93000000001}
                Apple Mobile Device Support-->MsiExec.exe /I{C337BDAF-CB4E-47E2-BE1A-CB31BB7DD0E3}
                Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
                avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
                Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
                Browser Address Error Redirector-->MsiExec.exe /I{62230596-37E5-4618-A329-0D21F529A86F}
                Call of Duty(R) 4 - Modern Warfare(TM)-->C:\Program Files\InstallShield Installation Information\{E48469CC-635E-4FD5-A122-1497C286D217}\setup.exe -runfromtemp -l0x040c
                Collab-->D:\programme\FL STUDIO 3\Collab\uninstall.exe
                Dell Photo AIO Printer 924-->C:\Windows\system32\spool\DRIVERS\W32X86\3\dlccUNST.EXE -NOLICENSE
                Dell Support Center (Support Software)-->MsiExec.exe /X{E3BFEE55-39E2-4BE0-B966-89FE583822C1}
                DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
                eoEngine 7.3-->"C:\Program Files\EoRezo\unins000.exe"
                EoWiki 2.0-->"C:\Program Files\EoRezo\EoWiki\unins000.exe"
                FL Studio 6-->D:\programme\FL STUDIO 1\uninstall.exe
                Fruity Loops Studio Producer Edition XXL v6.04 Patcher-->D:\PROGRA~1\FLSTUD~2\UNWISE.EXE D:\PROGRA~1\FLSTUD~2\INSTALL.LOG
                Google Chrome-->"C:\Program Files\Google\Chrome\Application\4.0.249.89\Installer\setup.exe" --uninstall --system-level
                Google Desktop-->C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
                Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
                Google Toolbar for Firefox-->MsiExec.exe /X{2CCBABCB-6427-4A55-B091-49864623C43F}
                Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_E85CDE7661A53A6A.exe" /uninstall
                Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
                Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
                Guide de l'utilisateur-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}\setup.exe"
                Guide de mise en route Dell-->MsiExec.exe /I{9954484F-6EE4-4040-94E3-4B380646F867}
                Heroes of Might and Magic V-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{20071984-5EB1-4881-8EDB-082532ACEC6D}\setup.exe" -l0x40c
                HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
                Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
                Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
                Image Transfer-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{564A8DD3-70BC-4018-A5C3-7CEB10BBB6E9}\Setup.exe" UNINSTALL
                ImageMixer for Sony-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1B4AA674-F5CA-4BB5-831A-CD37B4021959}\setup.exe"
                Intel(R) Graphics Media Accelerator Driver-->C:\Windows\system32\igxpun.exe -uninstall
                Intel(R) PRO Network Connections 12.1.11.0-->MsiExec.exe /i{777CA40C-0206-4EF6-A0FC-618BF06BF8D0} ARPREMOVE=1
                Intel(R) PRO Network Connections 12.1.11.0-->MsiExec.exe /i{777CA40C-0206-4EF6-A0FC-618BF06BF8D0} ARPREMOVE=1
                iTunes-->MsiExec.exe /I{99ECF41F-5CCA-42BD-B8B8-A8333E2E2944}
                Java(TM) 6 Update 14-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216014FF}
                Java(TM) SE Runtime Environment 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160000}
                Logitech Print Service-->C:\PROGRA~1\Logitech\PRINTS~1\UNWISE.EXE C:\PROGRA~1\Logitech\PRINTS~1\INSTALL.LOG
                Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
                McAfee Security Scan Plus-->"C:\Program Files\McAfee Security Scan\uninstall.exe"
                Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
                Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
                Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
                Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
                Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {91120000-0013-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
                Microsoft Office Basic 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall BASICR /dll OSETUP.DLL
                Microsoft Office Basic 2007-->MsiExec.exe /X{91120000-0013-0000-0000-0000000FF1CE}
                Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
                Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
                Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
                Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
                Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
                Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
                Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
                Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
                Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
                Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
                Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
                Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
                Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
                Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
                Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
                Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
                Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
                Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
                Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
                MicroStaff WINASPI-->C:\MWASPI\uninst.exe
                Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
                Mise à jour Microsoft Office Outlook 2007 Help (KB963677)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {51EFB347-1F3D-4BAC-8B79-F056B904FE21}
                Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
                Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
                Moovida-->C:\Program Files\Moovida\uninstall-1.0.6.exe
                Mouse Suite for Desktop Computers-->C:\Program Files\InstallShield Installation Information\{448E2D77-E504-4221-B2C2-93646B344729}\setup.exe -runfromtemp -l0x040c -removeonly
                Mozilla Firefox (3.0.18)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
                MSXML 4.0 SP2 (KB941833)-->MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
                MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
                NVIDIA Drivers-->C:\Windows\system32\NVUNINST.EXE UninstallGUI
                ooVoo Toolbar (Remove Toolbar Only)-->C:\Program Files\oovootb\uninstall.exe
                ooVoo-->"C:\Program Files\InstallShield Installation Information\{FAA7F8FF-3C05-4A61-8F14-D8A6E9ED6623}\setup.exe" -runfromtemp -l0x040c -removeonly
                Package de pilotes Windows - Nokia pccsmcfd (10/12/2007 6.85.4.0)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\Windows\system32\DRVSTORE\pccsmcfd_4A1E30386F4D0DEC8F5DF262CFBD8845EEBAB175\pccsmcfd.inf
                PC Connectivity Solution-->MsiExec.exe /I{AC599724-5755-48C1-ABE7-ABB857652930}
                PDFCreator-->C:\Program Files\PDFCreator\unins000.exe
                pdfforge Toolbar v1.1.2-->MsiExec.exe /X{5791B7D3-8B34-4218-9750-6A8E45D0AD32}
                QuickTime-->MsiExec.exe /I{C78EAC6F-7A73-452E-8134-DBB2165C5A68}
                RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|12.0
                Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
                Roxio Creator Audio-->MsiExec.exe /I{83FFCFC7-88C6-41c6-8752-958A45325C82}
                Roxio Creator BDAV Plugin-->MsiExec.exe /I{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}
                Roxio Creator Copy-->MsiExec.exe /I{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}
                Roxio Creator Data-->MsiExec.exe /I{0D397393-9B50-4c52-84D5-77E344289F87}
                Roxio Creator DE-->MsiExec.exe /I{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}
                Roxio Creator Tools-->MsiExec.exe /I{0394CDC8-FABD-4ed8-B104-03393876DFDF}
                Roxio Express Labeler-->MsiExec.exe /I{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
                Roxio MyDVD DE-->MsiExec.exe /I{D639085F-4B6E-4105-9F37-A0DBB023E2FB}
                Roxio Update Manager-->MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
                SAMSUNG Mobile Composite Device Software-->C:\Windows\system32\Samsung_USB_Drivers\6_old\SSBCUninstall.exe
                Samsung Mobile Modem Device Software-->C:\Windows\system32\Samsung_USB_Drivers\7\SSECUninstall.exe
                SAMSUNG Mobile Modem Driver Set-->C:\Windows\system32\Samsung_USB_Drivers\3\SSCDUninstall.exe
                Samsung Mobile phone USB driver Software-->C:\Windows\system32\Samsung_USB_Drivers\5\SSSDUninstall.exe
                SAMSUNG Mobile USB Modem 1.0 Software-->C:\Windows\system32\Samsung_USB_Drivers\1\SS_Uninstall.exe
                SAMSUNG Mobile USB Modem Software-->C:\Windows\system32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
                Samsung New PC Studio-->"C:\Program Files\InstallShield Installation Information\{F193FC0E-9E18-40FC-A974-509A1BDD240A}\setup.exe" -runfromtemp -l0x040c -removeonly
                Samsung New PC Studio-->MsiExec.exe /X{F193FC0E-9E18-40FC-A974-509A1BDD240A}
                SAMSUNG USB Mobile Device Software-->C:\Windows\system32\Samsung_USB_Drivers\6\SS_BUninstall.exe
                SamsungConnectivityCableDriver-->MsiExec.exe /X{7E84FAC8-C518-40F9-9807-7455301D6D25}
                Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {91120000-0013-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
                Security Update for 2007 Microsoft Office System (KB973704)-->msiexec /package {91120000-0013-0000-0000-0000000FF1CE} /uninstall {E626DC89-A787-4553-9BB3-DC2EC7E1593F}
                Security Update for Microsoft Office Excel 2007 (KB973593)-->msiexec /package {91120000-0013-0000-0000-0000000FF1CE} /uninstall {7D6255E3-3423-4D8B-A328-F6F8D28DD5FE}
                Security Update for Microsoft Office Outlook 2007 (KB972363)-->msiexec /package {91120000-0013-0000-0000-0000000FF1CE} /uninstall {120BE9A0-9B09-4855-9E0C-7DEE45CB03C0}
                Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {91120000-0013-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
                Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {91120000-0013-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
                Security Update for Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {91120000-0013-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
                Sonic Activation Module-->MsiExec.exe /I{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}
                TomTom HOME-->C:\Program Files\TomTom HOME 2\Uninstall TomTom HOME.exe
                TorrentMan Toolbar-->C:\PROGRA~1\TORREN~1\UNWISE.EXE C:\PROGRA~1\TORREN~1\INSTALL.LOG
                Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-0013-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
                Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
                Update for Microsoft Office InfoPath 2007 (KB976416)-->msiexec /package {91120000-0013-0000-0000-0000000FF1CE} /uninstall {432C5EE4-8096-4FF1-95E1-65219365DFF7}
                Update for Microsoft Office Word 2007 (KB974561)-->msiexec /package {91120000-0013-0000-0000-0000000FF1CE} /uninstall {0CDDBAA2-2111-4A0E-A1B0-76C40C635331}
                Update for Outlook 2007 Junk Email Filter (kb977719)-->msiexec /package {91120000-0013-0000-0000-0000000FF1CE} /uninstall {C0C92202-5215-4EFA-B0B9-B3A0DEABCDF1}
                VC_MergeModuleToMSI-->MsiExec.exe /I{900A92BA-19EF-4A34-86CF-7B6C85BDD971}
                VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
                VideoLAN VLC media player 0.8.6e-->C:\Program Files\VideoLAN\VLC\uninstall.exe
                VirtualCloneDrive-->"C:\Program Files\Elaborate Bytes\VirtualCloneDrive\vcd-uninst.exe" /D="C:\Program Files\Elaborate Bytes\VirtualCloneDrive"
                Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
                Windows Live Mail-->MsiExec.exe /I{C514C594-23AA-4F13-A070-DB8BDB27594F}
                Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}

                ======Security center information======

                AS: Windows Defender

                ======System event log======

                Computer Name: PC-de-BAILLIEHu
                Event Code: 10005
                Message: DCOM a reçu l'erreur "1084" lors de la mise en route du service ShellHWDetection avec les arguments "" pour démarrer le serveur :
                {DD522ACC-F821-461A-A407-50B198B896DC}
                Record Number: 200612
                Source Name: Microsoft-Windows-DistributedCOM
                Time Written: 20100224201006.000000-000
                Event Type: Erreur
                User:

                Computer Name: PC-de-BAILLIEHu
                Event Code: 10005
                Message: DCOM a reçu l'erreur "1084" lors de la mise en route du service EventSystem avec les arguments "" pour démarrer le serveur :
                {1BE1F766-5536-11D1-B726-00C04FB926AF}
                Record Number: 200613
                Source Name: Microsoft-Windows-DistributedCOM
                Time Written: 20100224201014.000000-000
                Event Type: Erreur
                User:

                Computer Name: PC-de-BAILLIEHu
                Event Code: 10005
                Message: DCOM a reçu l'erreur "1084" lors de la mise en route du service WSearch avec les arguments "" pour démarrer le serveur :
                {9E175B6D-F52A-11D8-B9A5-505054503030}
                Record Number: 200615
                Source Name: Microsoft-Windows-DistributedCOM
                Time Written: 20100224201020.000000-000
                Event Type: Erreur
                User:

                Computer Name: PC-de-BAILLIEHu
                Event Code: 7001
                Message: Le service Explorateur d'ordinateurs dépend du service Serveur qui n'a pas pu démarrer en raison de l'erreur :
                Le service ou le groupe de dépendance n'a pas pu démarrer.
                Record Number: 200629
                Source Name: Service Control Manager
                Time Written: 20100224201107.000000-000
                Event Type: Erreur
                User:

                Computer Name: PC-de-BAILLIEHu
                Event Code: 7026
                Message: Le pilote de démarrage système ou d'amorçage suivant n'a pas pu se charger :
                aswSP
                spldr
                Wanarpv6
                Record Number: 200638
                Source Name: Service Control Manager
                Time Written: 20100224201107.000000-000
                Event Type: Erreur
                User:

                =====Application event log=====

                Computer Name: PC-de-BAILLIEHu
                Event Code: 4609
                Message: Le système d'événements de COM+ a détecté un code de renvoi erroné lors de son traitement interne. Le HRESULT est 8007043c à partir de la ligne 45 de d:\vistasp1_gdr\com\complus\src\events\tier1\eventsystemobj.cpp. Contactez les services de support technique Microsoft pour signaler cette erreur.
                Record Number: 37617
                Source Name: Microsoft-Windows-EventSystem
                Time Written: 20100224184301.000000-000
                Event Type: Erreur
                User:

                Computer Name: PC-de-BAILLIEHu
                Event Code: 6000
                Message: L’abonné aux notifications Winlogon <GPClient> n’était pas disponible pour traiter un événement de notification.
                Record Number: 37620
                Source Name: Microsoft-Windows-Winlogon
                Time Written: 20100224200825.000000-000
                Event Type: Avertissement
                User:

                Computer Name: PC-de-BAILLIEHu
                Event Code: 6000
                Message: L’abonné aux notifications Winlogon <GPClient> n’était pas disponible pour traiter un événement de notification.
                Record Number: 37623
                Source Name: Microsoft-Windows-Winlogon
                Time Written: 20100224200826.000000-000
                Event Type: Avertissement
                User:

                Computer Name: PC-de-BAILLIEHu
                Event Code: 6000
                Message: L’abonné aux notifications Winlogon <GPClient> n’était pas disponible pour traiter un événement de notification.
                Record Number: 37629
                Source Name: Microsoft-Windows-Winlogon
                Time Written: 20100224201006.000000-000
                Event Type: Avertissement
                User:

                Computer Name: PC-de-BAILLIEHu
                Event Code: 4609
                Message: Le système d'événements de COM+ a détecté un code de renvoi erroné lors de son traitement interne. Le HRESULT est 8007043c à partir de la ligne 45 de d:\vistasp1_gdr\com\complus\src\events\tier1\eventsystemobj.cpp. Contactez les services de support technique Microsoft pour signaler cette erreur.
                Record Number: 37631
                Source Name: Microsoft-Windows-EventSystem
                Time Written: 20100224201014.000000-000
                Event Type: Erreur
                User:

                =====Security event log=====

                Computer Name: PC-de-BAILLIEHu
                Event Code: 4907
                Message: Les paramètres d’audit sur l’objet ont changé.

                Sujet :
                ID de sécurité : S-1-5-18
                Nom du compte : PC-DE-BAILLIEHU$
                Domaine du compte : WORKGROUP
                ID d’ouverture de session : 0x3e7

                Objet :
                Serveur de l’objet : Security
                Type d’objet : File
                Nom de l’objet : C:\Windows\Boot\PCAT\tr-TR\bootmgr.exe.mui
                ID du handle : 0x18

                Informations sur le processus :
                ID du processus : 0x12e8
                Nom du processus : C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\poqexec.exe

                Paramètres d’audit :
                Descripteur de sécurité d’origine :
                Nouveau descripteur de sécurité : S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
                Record Number: 54949
                Source Name: Microsoft-Windows-Security-Auditing
                Time Written: 20090828131140.982700-000
                Event Type: Succès de l'audit
                User:

                Computer Name: PC-de-BAILLIEHu
                Event Code: 4907
                Message: Les paramètres d’audit sur l’objet ont changé.

                Sujet :
                ID de sécurité : S-1-5-18
                Nom du compte : PC-DE-BAILLIEHU$
                Domaine du compte : WORKGROUP
                ID d’ouverture de session : 0x3e7

                Objet :
                Serveur de l’objet : Security
                Type d’objet : File
                Nom de l’objet : C:\Windows\Boot\PCAT\ja-JP\bootmgr.exe.mui
                ID du handle : 0x18

                Informations sur le processus :
                ID du processus : 0x12e8
                Nom du processus : C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\poqexec.exe

                Paramètres d’audit :
                Descripteur de sécurité d’origine :
                Nouveau descripteur de sécurité : S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
                Record Number: 54950
                Source Name: Microsoft-Windows-Security-Auditing
                Time Written: 20090828131140.982700-000
                Event Type: Succès de l'audit
                User:

                Computer Name: PC-de-BAILLIEHu
                Event Code: 4907
                Message: Les paramètres d’audit sur l’objet ont changé.

                Sujet :
                ID de sécurité : S-1-5-18
                Nom du compte : PC-DE-BAILLIEHU$
                Domaine du compte : WORKGROUP
                ID d’ouverture de session : 0x3e7

                Objet :
                Serveur de l’objet : Security
                Type d’objet : File
                Nom de l’objet : C:\Windows\Boot\PCAT\pt-PT\bootmgr.exe.mui
                ID du handle : 0x18

                Informations sur le processus :
                ID du processus : 0x12e8
                Nom du processus : C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\poqexec.exe

                Paramètres d’audit :
                Descripteur de sécurité d’origine :
                Nouveau descripteur de sécurité : S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
                Record Number: 54951
                Source Name: Microsoft-Windows-Security-Auditing
                Time Written: 20090828131140.982700-000
                Event Type: Succès de l'audit
                User:

                Computer Name: PC-de-BAILLIEHu
                Event Code: 4907
                Message: Les paramètres d’audit sur l’objet ont changé.

                Sujet :
                ID de sécurité : S-1-5-18
                Nom du compte : PC-DE-BAILLIEHU$
                Domaine du compte : WORKGROUP
                ID d’ouverture de session : 0x3e7

                Objet :
                Serveur de l’objet : Security
                Type d’objet : File
                Nom de l’objet : C:\Windows\Boot\PCAT\fr-FR\bootmgr.exe.mui
                ID du handle : 0x18

                Informations sur le processus :
                ID du processus : 0x12e8
                Nom du processus : C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\poqexec.exe

                Paramètres d’audit :
                Descripteur de sécurité d’origine :
                Nouveau descripteur de sécurité : S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
                Record Number: 54952
                Source Name: Microsoft-Windows-Security-Auditing
                Time Written: 20090828131140.982700-000
                Event Type: Succès de l'audit
                User:

                Computer Name: PC-de-BAILLIEHu
                Event Code: 4907
                Message: Les paramètres d’audit sur l’objet ont changé.

                Sujet :
                ID de sécurité : S-1-5-18
                Nom du compte : PC-DE-BAILLIEHU$
                Domaine du compte : WORKGROUP
                ID d’ouverture de session : 0x3e7

                Objet :
                Serveur de l’objet : Security
                Type d’objet : File
                Nom de l’objet : C:\Windows\Boot\DVD\PCAT\boot.sdi
                ID du handle : 0x18

                Informations sur le processus :
                ID du processus : 0x12e8
                Nom du processus : C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\poqexec.exe

                Paramètres d’audit :
                Descripteur de sécurité d’origine :
                Nouveau descripteur de sécurité : S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
                Record Number: 54953
                Source Name: Microsoft-Windows-Security-Auditing
                Time Written: 20090828131140.998300-000
                Event Type: Succès de l'audit
                User:

                ======Environment variables======

                "ComSpec"=%SystemRoot%\system32\cmd.exe
                "FP_NO_HOST_CHECK"=NO
                "OS"=Windows_NT
                "Path"=C:\Program Files\PC Connectivity Solution\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Intel\DMIX;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\;C:\Program Files\QuickTime\QTSystem\
                "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
                "PROCESSOR_ARCHITECTURE"=x86
                "TEMP"=%SystemRoot%\TEMP
                "TMP"=%SystemRoot%\TEMP
                "USERNAME"=SYSTEM
                "windir"=%SystemRoot%
                "PROCESSOR_LEVEL"=6
                "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 11, GenuineIntel
                "PROCESSOR_REVISION"=0f0b
                "NUMBER_OF_PROCESSORS"=4
                "RoxioCentral"=C:\Program Files\Common Files\Roxio Shared\9.0\Roxio Central33\
                "CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
                "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip
                "SAFEBOOT_OPTION"=NETWORK

                -----------------EOF-----------------
                0
                1. et voici le LOG

                  Logfile of random's system information tool 1.06 (written by random/random)
                  Run by BAILLIE Hubert at 2010-02-24 22:00:47
                  Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
                  System drive C: has 419 GB (90%) free of 467 GB
                  Total RAM: 3069 MB (74% free)

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 22:00:48, on 24/02/2010
                  Platform: Windows Vista SP1 (WinNT 6.00.1905)
                  MSIE: Internet Explorer v7.00 (7.00.6001.18385)
                  Boot mode: Safe mode with network support

                  Running processes:
                  C:\Windows\Explorer.EXE
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\Users\BAILLIE Hubert\Downloads\RSIT.exe
                  C:\Users\BAILLIE Hubert\Downloads\RSIT.exe
                  C:\Program Files\trend micro\BAILLIE Hubert.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://partnerpage.google.com/...
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mystart.com?pr=oovoo2_0
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://partnerpage.google.com/...
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lo.st
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer fourni par Dell
                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                  R3 - URLSearchHook: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTorr.dll
                  R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll
                  O1 - Hosts: ::1 localhost
                  O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                  O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
                  O2 - BHO: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTorr.dll
                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                  O2 - BHO: ooVoo Toolbar - {A1FB2F9A-D35E-11DD-8935-E46A56D89593} - C:\Program Files\oovootb\oovoodx.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
                  O2 - BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll
                  O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                  O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll
                  O3 - Toolbar: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTorr.dll
                  O3 - Toolbar: (no name) - {66886C4D-B307-4ECA-A228-52CA9B9851A4} - (no file)
                  O3 - Toolbar: ooVoo Toolbar - {A1FB2F9A-D35E-11DD-8935-E46A56D89593} - C:\Program Files\oovootb\oovoodx.dll
                  O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                  O3 - Toolbar: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll
                  O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
                  O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                  O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                  O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
                  O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                  O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                  O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\pdfforge Toolbar\SearchSettings.exe
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
                  O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
                  O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
                  O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
                  O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                  O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                  O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
                  O4 - HKCU\..\Run: [oovoo.exe] C:\Program Files\ooVoo\oovoo.exe /minimized
                  O4 - HKCU\..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                  O4 - Global Startup: Image Transfer.lnk = ?
                  O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                  O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                  O13 - Gopher Prefix:
                  O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
                  O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
                  O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files\Application Updater\ApplicationUpdater.exe
                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                  O23 - Service: dlcc_device - Unknown owner - C:\Windows\system32\dlcccoms.exe
                  O23 - Service: FsUsbExService - Teruten - C:\Windows\system32\FsUsbExService.Exe
                  O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                  O23 - Service: Service Google Update (gupdate1ca219645c69670) (gupdate1ca219645c69670) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                  O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                  O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                  O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
                  O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                  O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                  O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                  O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
                  O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                  0
                  1. Contributeur sécurité
                    ok

                    des choses encore

                    1)

                    supprimes cette toolbar qui est néfaste

                    TorrentMan Toolbar (C:\Program Files\TorrentMan\tbTorr.dll)

                    ................

                    2)
                    Téléchargez USBFIX de El Desaparecido, C_xx

                    http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe
                    ou
                    https://www.ionos.fr/?affiliate_id=77097

                    /!\ Utilisateur de vista et windows 7 :
                    ne pas oublier de désactiver Le contrôle des comptes utilisateurs
                    https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

                    /!\ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

                    • Double clic sur le raccourci UsbFix présent sur le bureau .

                    • Choisir l'option2 suppression
                    (d’autres options disponibles, voir le tutoriel).
                    • Laissez travailler l'outil.
                    Le menu démarrer et les icônes vont disparaître.. c'est normal.

                    Si un message te demande de redémarrer l'ordinateur fais le ...

                    ● Au redémarrage, le fix se relance... laisses l'opération s'effectuer.

                    ● Le bloc note s'ouvre avec un rapport, envoies le dans la prochaine réponse

                    • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

                    ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

                    • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                    Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                    Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

                    • Tuto : http://pagesperso-orange.fr/NosTools/usbfix.html

                    UsbFix peut te demander d'uploader un dossier compressé à cette adresse : https://www.ionos.fr/?affiliate_id=77097

                    Il est enregistré sur ton bureau.

                    Merci de l'envoyer à l'adresse indiquée afin d'aider l'auteur de UsbFix dans ses recherches.

                    ............................

                    3)

                    Note importante :
                    Pour les ordinateurs équipés de Windows Vista et Windows 7, la désactivation du Contrôle des comptes utilisateurs est obligatoire
                    sous peine de ne pas pouvoir faire fonctionner correctement l'outil.
                    Tuto : https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

                    Téléchargez et enregistrez le fichier d installation sur le bureau
                    http://pagesperso-orange.fr/NosTools/C_XX/AD-R.exe

                    Double cliquez sur le fichier d'installation de AD-Remover, le programme s'installera automatiquement.
                    Sous Vista : clic droit sur AD-Remover et sélectionner "Exécuter en tant qu'administrateur"
                    Au menu principal choisir
                    Option L Lancer le nettoyage
                    et tapez sur [entrée] .
                    Laissez travailler l'outil et ne touchez à rien ...
                    Postez le rapport qui apparait à la fin.

                    ( le rapport est sauvegardé aussi sous C:\Ad-report.log )

                    (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                    Note :Process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                    Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                    Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

                    0
                    1. Bouh des mountpoints2 , faut a tout pris passer usbfix ..

                      Quel drame ... nous ne savons pas encore si les mountpoints2 sont infectieuses ou pas ...

                      Hay que roderse ........................................

                      +
                      0
                      1. Contributeur sécurité
                        il en est un qui ne semble pas sûr...et l'auteur de l'outil a pensé justement à vacciner les supports quoiqu'il arrive avec son option 2
                        dommage il a de tres bonnes idées et il vient ici si mal les commenter (sauf si je n'ai pas compris)

                        benjhy,

                        tu peux suivre le post 9
                        0
                        1. au redémarrage le fix ne s'est pas relancé donc pas de bloc note ni de rapport Usbfix.text
                          note: à chaque fois je redémarre en mode sans échec avec réseau (je continue?)

                          et dois je quand même continuerla suite du post 9 avec AD-remover??
                          0
                          1. bon, j'ai relancé usbfix puis j'ai redémarré en mode normal et là le fix s'est lancé j'attend la fin....
                            0
                            1. Contributeur sécurité
                              Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

                              sinon tu passes les outils en mode normal

                              continues avec Ad Remover
                              0
                              1. et voici pour usbfix:

                                ############################## | UsbFix V6.097 |

                                User : BAILLIE Hubert (Administrateurs) # PC-DE-BAILLIEHU
                                Update on 20/02/2010 by El Desaparecido , C_XX & Chimay8
                                Start at: 22:50:23 | 24/02/2010
                                Website : http://pagesperso-orange.fr/NosTools/index.html
                                Contact : FindyKill.Contact@gmail.com

                                Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
                                Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
                                Internet Explorer 7.0.6001.18000
                                Windows Firewall Status : Enabled

                                C:\ -> Disque fixe local # 455,7 Go (406,85 Go free) [OS] # NTFS
                                D:\ -> Disque fixe local # 465,76 Go (291,74 Go free) [DATAPART1] # NTFS
                                E:\ -> Disque fixe local # 10 Go (5,5 Go free) [RECOVERY] # NTFS
                                F:\ -> Disque CD-ROM
                                G:\ -> Disque CD-ROM
                                H:\ -> Disque amovible
                                I:\ -> Disque amovible
                                J:\ -> Disque amovible
                                K:\ -> Disque amovible
                                M:\ -> Disque CD-ROM

                                ############################## | Processus actifs |

                                C:\Windows\System32\smss.exe
                                C:\Windows\system32\csrss.exe
                                C:\Windows\system32\csrss.exe
                                C:\Windows\system32\wininit.exe
                                C:\Windows\system32\services.exe
                                C:\Windows\system32\lsass.exe
                                C:\Windows\system32\lsm.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\winlogon.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\SLsvc.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\LogonUI.exe
                                C:\Windows\system32\svchost.exe
                                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                C:\Windows\System32\spoolsv.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\userinit.exe
                                C:\Windows\system32\Dwm.exe
                                C:\Windows\system32\taskeng.exe
                                C:\Windows\system32\taskeng.exe
                                C:\Windows\Explorer.EXE
                                C:\Windows\system32\runonce.exe
                                C:\Windows\system32\conime.exe
                                C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                C:\Program Files\Application Updater\ApplicationUpdater.exe
                                C:\Program Files\Bonjour\mDNSResponder.exe
                                C:\Windows\system32\FsUsbExService.Exe
                                C:\Program Files\Google\Update\GoogleUpdate.exe
                                C:\Windows\system32\svchost.exe
                                C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                                C:\Program Files\Dell Support Center\bin\sprtsvc.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\system32\SearchIndexer.exe
                                C:\Windows\system32\WUDFHost.exe
                                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                C:\Windows\system32\wbem\wmiprvse.exe

                                ################## | Elements infectieux |

                                Supprimé ! C:\$Recycle.Bin\S-1-5-18
                                Supprimé ! C:\$Recycle.Bin\S-1-5-21-1156096930-2836191889-3919688664-500
                                Supprimé ! C:\$Recycle.Bin\S-1-5-21-2152478756-3922319563-605102323-500
                                Supprimé ! C:\$Recycle.Bin\S-1-5-21-813763711-602068853-2054077353-1000
                                Supprimé ! C:\$Recycle.Bin\S-1-5-21-813763711-602068853-2054077353-500
                                Supprimé ! D:\$Recycle.Bin\S-1-5-18
                                Supprimé ! D:\$Recycle.Bin\S-1-5-21-813763711-602068853-2054077353-1000
                                Supprimé ! D:\$Recycle.Bin\S-1-5-21-813763711-602068853-2054077353-500
                                Supprimé ! E:\$Recycle.Bin\S-1-5-18
                                Supprimé ! E:\$Recycle.Bin\S-1-5-21-813763711-602068853-2054077353-1000
                                Supprimé ! E:\$Recycle.Bin\S-1-5-21-813763711-602068853-2054077353-500

                                ################## | Registre |

                                ################## | Mountpoints2 |

                                Supprimé ! HKCU\...\Explorer\MountPoints2\{1b9c354f-8cbd-11dd-999e-001d0984ca7c}\Shell\AutoRun\Command
                                Supprimé ! HKCU\...\Explorer\MountPoints2\{a7a6e3a5-094b-11dd-9954-001d0984ca7c}\Shell\AutoRun\Command

                                ################## | Listing des fichiers présent |

                                [18/09/2006 22:43|--a------|24] C:\autoexec.bat
                                [19/01/2008 08:45|-rahs----|333203] C:\bootmgr
                                [18/09/2006 22:43|--a------|10] C:\config.sys
                                [29/02/2008 23:23|-rah-----|4492] C:\dell.sdr
                                [?|?|?] C:\hiberfil.sys
                                [18/04/2008 14:54|-rahs----|0] C:\IO.SYS
                                [13/09/2009 10:46|--a------|91] C:\LogiSetup.log
                                [18/04/2008 14:54|-rahs----|0] C:\MSDOS.SYS
                                [?|?|?] C:\pagefile.sys
                                [24/02/2010 22:53|--a------|4118] C:\UsbFix.txt

                                ################## | Vaccination |

                                # C:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
                                # D:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
                                # E:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).

                                ################## | Upload |

                                Veuillez envoyer le fichier : C:\UsbFix_Upload_Me_PC-de-BAILLIEHu.zip : https://www.ionos.fr/?affiliate_id=77097
                                Merci pour votre contribution .

                                ################## | ! Fin du rapport # UsbFix V6.097 ! |
                                0
                                1. et maintenant pour AD remover!:

                                  .
                                  ======= RAPPORT D'AD-REMOVER 1.1.4.6_J | UNIQUEMENT XP/VISTA/7 =======
                                  .
                                  Mis à jour par C_XX le 05.02.2010 à 17:34
                                  Contact: AdRemover.contact@gmail.com
                                  Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
                                  .
                                  Lancé à: 23:03:13, 24/02/2010 | Mode Normal | Option: CLEAN
                                  Exécuté de: C:\Ad-Remover\
                                  Système d'exploitation: Microsoft® Windows Vista™ HomePremium Service Pack 2 v6.0.6001
                                  Nom du PC: PC-DE-BAILLIEHU | Utilisateur actuel: BAILLIE Hubert
                                  .
                                  ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
                                  .
                                  Service: *Application Updater*

                                  C:\Program Files\Mozilla Firefox\extensions\searchsettings@spigot.com
                                  C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\EoRezo
                                  C:\Program Files\Application Updater
                                  C:\Program Files\EoRezo
                                  C:\Program Files\pdfforge Toolbar
                                  C:\Program Files\Winletmin
                                  C:\Users\BAILLI~1\AppData\Roaming\EoRezo
                                  C:\Users\BAILLI~1\AppData\Roaming\ItsLabel
                                  C:\Users\BAILLIE Hubert\AppData\LocalLow\pdfforge
                                  C:\Users\BAILLIE Hubert\AppData\LocalLow\Search Settings
                                  C:\Windows\Installer\6d60be.msi
                                  C:\Windows\system32\config\systemprofile\AppData\LocalLow\Application Updater
                                  C:\Users\BAILLI~1\AppData\Local\Temp\is-JL8V3.tmp\EoWiki by EoRezo

                                  (!) -- Fichiers temporaires supprimés.

                                  .
                                  HKCU\software\appdatalow\software\pdfforge
                                  HKCU\software\EoRezo
                                  HKCU\software\ItsLabel
                                  HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8FBF6418-1FAD-4890-B1EF-96717193AA55}
                                  HKCU\Software\Microsoft\Internet Explorer\LowRegistry\Search Settings
                                  HKCU\software\microsoft\internet explorer\searchscopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
                                  HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
                                  HKCU\software\Search Settings
                                  HKLM\software\Application Updater
                                  HKLM\Software\Classes\AppID\{362A53B2-2913-4F8A-82F5-7E0A23FDC6F9}
                                  HKLM\software\classes\appid\EoRezoBHO.DLL
                                  HKLM\Software\Classes\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402}
                                  HKLM\Software\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
                                  HKLM\software\classes\EoRezoBHO.EoBHO
                                  HKLM\software\classes\EoRezoBHO.EoBHO.1
                                  HKLM\software\ItsLabel
                                  HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B922D405-6D13-4A2B-AE89-08A030DA4402}
                                  HKLM\software\microsoft\internet explorer\searchscopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
                                  HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{66886C4D-B307-4ECA-A228-52CA9B9851A4}
                                  HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{B922D405-6D13-4A2B-AE89-08A030DA4402}
                                  HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}
                                  HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
                                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\36BD92009DFD87846B2333BBBEA6DD1C
                                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\377026901A2D8744A8423A983B50E0D1
                                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\76DA9915C36F3D742951F63351CF5C97
                                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\8A01D85165E7CD5448C71263ADB6A2E2
                                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\9B0B0584E80456A4FB98DA3973B1EB3F
                                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\A89F1E0FE544529429C8BF82FE74CE39
                                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\B278DBFACA5AB424DA79915F3A109F9A
                                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\B3B348F18694F1949B4D6BD9507F2886
                                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\C9667115F6A9CE340B31B63B680FF26F
                                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\E48E3A6D380B2EC4ABCEB3BA048D767F
                                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\EFB70E89C3D6D354596520DE424F89D6
                                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\F49A213B5069AC348994D03F81B56C19
                                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\F715D253BF28D554C9C0F60ABA8585CF
                                  HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SearchSettings
                                  HKLM\software\microsoft\windows\currentversion\uninstall\eoEngine_is1
                                  HKLM\software\microsoft\windows\currentversion\uninstall\EoWiki_is1
                                  HKLM\software\pdfforge
                                  HKLM\software\Search Settings
                                  .
                                  ============== Scan additionnel ==============
                                  .
                                  .
                                  * Mozilla FireFox Version 3.0.18 [fr] *
                                  .
                                  Nom du profil: hhiggjyu.default (BAILLIE Hubert)
                                  .
                                  (BAILLI~1, prefs.js) Browser.download.dir, C:\Users\BAILLIE Hubert\Downloads
                                  (BAILLI~1, prefs.js) Browser.download.lastDir, C:\Users\BAILLIE Hubert\Pictures
                                  (BAILLI~1, prefs.js) Browser.search.defaultenginename, Yahoo
                                  (BAILLI~1, prefs.js) Browser.search.defaulturl, hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1640187&SearchSource=3&q=
                                  (BAILLI~1, prefs.js) Browser.search.selectedEngine, Yahoo
                                  (BAILLI~1, prefs.js) Browser.startup.homepage, hxxp://www.mystart.com?pr=oovoo2_0
                                  (BAILLI~1, prefs.js) Extensions.enabledItems, {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14,{20a82645-c095-46ed-80e3-08825760534b}:1.1,{99E00A4C-D35E-11DD-BA95-9B6A56D89593}:2.0,pdfforge@mybrowserbar.com:1.1.2,{ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0,searchsettings@spigot.com:1.2.3,{7c5c0f58-e061-457d-9033-77307f5ed00c}:1.5.39.0,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.18
                                  (BAILLI~1, prefs.js) Keyword.URL, hxxp://fr.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=302398&p=
                                  .
                                  .
                                  * Internet Explorer Version 7.0.6001.18000 *
                                  .
                                  [HKEY_CURRENT_USER\..\Internet Explorer\Main]
                                  .
                                  Do404Search: 01000000
                                  Local Page: C:\Windows\system32\blank.htm
                                  Show_ToolBar: yes
                                  Enable Browser Extensions: yes
                                  Start Page: hxxp://fr.msn.com/
                                  Use Search Asst: no
                                  Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                                  Default_search_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                                  Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                                  .
                                  [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
                                  .
                                  Start Page: hxxp://fr.msn.com/
                                  Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                                  Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                                  Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                                  Delete_Temp_Files_On_Exit: yes
                                  Local Page: %SystemRoot%\system32\blank.htm
                                  Enable Browser Extensions: yes
                                  Use Search Asst: no
                                  Search bar: hxxp://search.msn.com/spbasic.htm
                                  .
                                  [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
                                  .
                                  Tabs: res://ieframe.dll/tabswelcome.htm
                                  .
                                  ============== Suspect (Cracks, Serials, ...) ==============
                                  .
                                  C:\Users\All Users\SupportSoft\DellSupportCenter\SYSTEM\exec\DSCPatch_2_1_08044.exe
                                  C:\Users\All Users\SupportSoft\DellSupportCenter\SYSTEM\exec\DSCPatch_2_1_08060_20.exe
                                  C:\Users\All Users\SupportSoft\DellSupportCenter\SYSTEM\exec\DSCPatch_2_2_08100_2.0.exe
                                  C:\Users\All Users\SupportSoft\DellSupportCenter\SYSTEM\exec\DSCPatch_2_2_08267_2.0.exe
                                  C:\Users\All Users\SupportSoft\DellSupportCenter\SYSTEM\exec\DSCPatch_2_2_08298_2.0.exe
                                  C:\Users\All Users\SupportSoft\DellSupportCenter\SYSTEM\exec\DSCPatch_2_2_08335_2.0.exe
                                  C:\Users\All Users\SupportSoft\DellSupportCenter\SYSTEM\exec\DSCPatch_2_2_09085_2.0.exe
                                  C:\Users\BAILLIE Hubert\Desktop\Fruity Loops Studio Producer Edition XXL v6.04\PATCHER.EXE
                                  .
                                  ===================================
                                  .
                                  7642 Octet(s) - C:\Ad-Report-CLEAN[1].log
                                  .
                                  919 Fichier(s) - C:\Users\BAILLI~1\AppData\Local\Temp
                                  1604 Fichier(s) - C:\Windows\Temp
                                  0 Fichier(s) - C:\Windows\Prefetch
                                  .
                                  19 Fichier(s) - C:\Ad-Remover\BACKUP
                                  151 Fichier(s) - C:\Ad-Remover\QUARANTINE
                                  .
                                  Fin à: 23:06:47 | 24/02/2010 - CLEAN[1]
                                  .
                                  ============== E.O.F ==============
                                  .
                                  0
                                  1. Contributeur sécurité
                                    ok

                                    comment va le pc ?

                                    pour demain

                                    relances RSIT et postes le rapport log stp
                                    0
                                    1. il va bien mieux, merci! il ne s'affole plus à m'afficher toutes ces alertes dans tous les sens, c'est cool.
                                      et pas de problème, je vais faire mes devoirs pour demain ;) je vais même le faire maintenant...
                                      Bonne soirée et encore merci...
                                      0
                                      1. voilà, parcontre il n'y a que le "LOG" car le "INFO" c'est celui de tout à l'heure à 22h...

                                        Logfile of random's system information tool 1.06 (written by random/random)
                                        Run by BAILLIE Hubert at 2010-02-24 23:22:42
                                        Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
                                        System drive C: has 416 GB (89%) free of 467 GB
                                        Total RAM: 3069 MB (69% free)

                                        Logfile of Trend Micro HijackThis v2.0.2
                                        Scan saved at 23:22:44, on 24/02/2010
                                        Platform: Windows Vista SP1 (WinNT 6.00.1905)
                                        MSIE: Internet Explorer v7.00 (7.00.6001.18385)
                                        Boot mode: Normal

                                        Running processes:
                                        C:\Windows\system32\Dwm.exe
                                        C:\Windows\system32\taskeng.exe
                                        C:\Windows\Explorer.EXE
                                        C:\Windows\system32\conime.exe
                                        C:\Program Files\Dell Support Center\bin\sprtcmd.exe
                                        C:\Program Files\iTunes\iTunesHelper.exe
                                        C:\Windows\system32\wuauclt.exe
                                        C:\Windows\RtHDVCpl.exe
                                        C:\Windows\WindowsMobile\wmdSync.exe
                                        C:\Windows\System32\rundll32.exe
                                        C:\Windows\System32\rundll32.exe
                                        C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                                        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                                        C:\Windows\ehome\ehtray.exe
                                        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                        C:\Program Files\TomTom HOME 2\HOMERunner.exe
                                        C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
                                        C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
                                        C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
                                        C:\Windows\ehome\ehmsas.exe
                                        C:\Program Files\Mozilla Firefox\firefox.exe
                                        C:\Windows\system32\NOTEPAD.EXE
                                        C:\Users\BAILLIE Hubert\Downloads\RSIT.exe
                                        C:\Program Files\trend micro\BAILLIE Hubert.exe

                                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
                                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
                                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
                                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                        R3 - URLSearchHook: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTorr.dll (file missing)
                                        O1 - Hosts: ::1 localhost
                                        O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                                        O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
                                        O2 - BHO: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTorr.dll (file missing)
                                        O2 - BHO: ooVoo Toolbar - {A1FB2F9A-D35E-11DD-8935-E46A56D89593} - C:\Program Files\oovootb\oovoodx.dll
                                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                                        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
                                        O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
                                        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                                        O3 - Toolbar: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTorr.dll (file missing)
                                        O3 - Toolbar: ooVoo Toolbar - {A1FB2F9A-D35E-11DD-8935-E46A56D89593} - C:\Program Files\oovootb\oovoodx.dll
                                        O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                                        O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
                                        O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
                                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                                        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                        O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                                        O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
                                        O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                                        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                                        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                        O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
                                        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                                        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                                        O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
                                        O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
                                        O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                        O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                                        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                                        O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
                                        O4 - HKCU\..\Run: [oovoo.exe] C:\Program Files\ooVoo\oovoo.exe /minimized
                                        O4 - HKCU\..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
                                        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                                        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                        O4 - Global Startup: Image Transfer.lnk = ?
                                        O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
                                        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                                        O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
                                        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                                        O13 - Gopher Prefix:
                                        O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
                                        O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
                                        O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                        O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                        O23 - Service: dlcc_device - Unknown owner - C:\Windows\system32\dlcccoms.exe
                                        O23 - Service: FsUsbExService - Teruten - C:\Windows\system32\FsUsbExService.Exe
                                        O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                        O23 - Service: Service Google Update (gupdate1ca219645c69670) (gupdate1ca219645c69670) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                                        O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                        O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                        O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
                                        O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                                        O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                                        O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                                        O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
                                        O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                                        0
                                        1. Contributeur sécurité
                                          une dernière verif

                                          Rends toi sur ce site :

                                          https://www.virustotal.com/gui/

                                          Clique sur parcourir et cherche ce fichier : C:\Program Files\Dl_cats

                                          Clique sur Send File.

                                          Un rapport va s'élaborer ligne à ligne.

                                          Attends la fin. Il doit comprendre la taille du fichier envoyé.

                                          Sauvegarde le rapport avec le bloc-note.

                                          Copie le dans ta réponse.

                                          Si tu ne trouves pas le fichier alors

                                          Affiche tous les fichiers et dossiers :

                                          Pour cela :
                                          Clique sur démarrer/panneau de configuration/option des dossiers/affichage

                                          Cocher afficher les dossiers cachés

                                          Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

                                          Décocher masquer les extensions dont le type est connu

                                          Puis fais «appliquer» pour valider les changements.

                                          Et OK

                                          0
                                          • 1
                                          • 2