Des troyens, help ! zlob.dnschanger.rtk ...

Bonjour,
D'avance un énorme merci à quiconque m'aidera à me débarrasser de ces horreurs !
Spybot a détecté zlob.DNSchanger.rtk ainsi que zlob.downloader.bit
Configuration: Windows Vista
Firefox 3.0.3

43 réponses

Résumé de la discussion

Des alertes liées à zlob.DNSchanger.rtk et zlob.downloader.bitConfiguration apparaissent, et les rapports de Spybot et HijackThis indiquent une présence étendue d'éléments malveillants et de modifications dans les paramètres du navigateur et du système. Plusieurs éléments d'exécution automatique et de composants potentiellement indésirables apparaissent dans la liste Run, BHO et les services, notamment Google Updater, Google Desktop, Google Toolbar, Dell Support Center et Apple Mobile Device. Des changements de configuration réseau et des entrées de registre suggèrent une altération des pages d'accueil et des moteurs de recherche, avec des valeurs ProxyOverride et des URL remplaçant des paramètres par défaut. Enfin, des éléments nouveaux notés incluent des fichiers récemment créés tels que WS2Fix.exe, VACFix.exe et o4Patch.exe, ainsi que des entrées AppInit_DLLs associant Google à des modules chargés au démarrage.

Bobot (l’IA à votre service)
  1. Modérateur
    Salut,
    - Télécharge HijackThis Version 2.02 :
    http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe

    - Enregistre HJTInstall.exe sur ton bureau.
    - Fais un double-clic sur HJTInstall.exe afin de lancer l'installation
    - Clique sur Install ensuite sur I Accept
    - Clique sur Do a scan system and save log file
    - Le bloc-notes s'ouvrira, fais un copier-coller de tout son contenu ici dans ta prochaine réponse.
    Petit tuto si besoin : http://pageperso.aol.fr/balltrap34/demohijack.htm
    0
    1. Salut Crapoulou ! Merci pour le coup de main.
      Voici le log.

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 21:49:25, on 22/10/2008
      Platform: Windows Vista (WinNT 6.00.1904)
      MSIE: Internet Explorer v7.00 (7.00.6000.16757)
      Boot mode: Normal

      Running processes:
      C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
      C:\Windows\system32\taskeng.exe
      C:\Windows\SYSTEM32\WISPTIS.EXE
      C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Program Files\DellTPad\Apoint.exe
      C:\Windows\OEM02Mon.exe
      C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
      C:\Windows\System32\igfxtray.exe
      C:\Windows\System32\hkcmd.exe
      C:\Windows\System32\igfxpers.exe
      C:\Windows\system32\igfxsrvc.exe
      C:\Program Files\Java\jre1.6.0\bin\jusched.exe
      C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe
      C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
      C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      C:\Program Files\Dell\MediaDirect\PCMService.exe
      C:\Program Files\Canon\SolutionMenu\CNSLMAIN.EXE
      C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
      C:\Program Files\DellTPad\ApMsgFwd.exe
      C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
      C:\Program Files\DellTPad\HidFind.exe
      C:\Program Files\DellTPad\Apntex.exe
      C:\Program Files\Dell Support Center\bin\sprtcmd.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
      C:\Program Files\Common Files\Real\Update_OB\realsched.exe
      C:\Program Files\Activ Software\Activdriver\ActivControl2.exe
      C:\Windows\ehome\ehtray.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
      C:\Program Files\Digital Line Detect\DLG.exe
      C:\Program Files\Dell\QuickSet\quickset.exe
      C:\Windows\ehome\ehmsas.exe
      C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      c:\PROGRA~1\mcafee\msc\mcuimgr.exe
      C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
      C:\Windows\system32\wuauclt.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.free.fr/freebox/index.html
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer fourni par Dell
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      O1 - Hosts: ::1 localhost
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
      O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - C:\Program Files\McAfee\MSK\mcapbho.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
      O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
      O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
      O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
      O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
      O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
      O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
      O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "c:\Program Files\Java\jre1.6.0\bin\jusched.exe"
      O4 - HKLM\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s
      O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
      O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
      O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
      O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
      O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
      O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
      O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
      O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
      O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [ActivControl] C:\Program Files\Activ Software\Activdriver\ActivControl2.exe
      O4 - HKLM\..\Run: [695.tmp] C:\Windows\temp\695.tmp
      O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
      O4 - Global Startup: BTTray.lnk = ?
      O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
      O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
      O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
      O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
      O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O13 - Gopher Prefix:
      O16 - DPF: {04CB5B64-5915-4629-B869-8945CEBADD21} (Module de délivrance de certificat MINEFI) - https://static.impots.gouv.fr/abos/static/securite/certdgi1.cab
      O17 - HKLM\System\CCS\Services\Tcpip\..\{1CD96B66-F18A-4056-8227-D221416AAE8F}: NameServer = 85.255.112.159;85.255.112.23
      O17 - HKLM\System\CCS\Services\Tcpip\..\{94C0E11D-255E-49E4-A052-FBB06AD48B2A}: NameServer = 85.255.112.159;85.255.112.23
      O17 - HKLM\System\CS1\Services\Tcpip\..\{1CD96B66-F18A-4056-8227-D221416AAE8F}: NameServer = 85.255.112.159;85.255.112.23
      O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
      O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
      O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
      O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
      O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
      O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
      O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
      O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
      O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
      O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
      O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
      O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
      O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
      O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
      O23 - Service: Windows Tribute Service - Unknown owner - C:\Windows\system32\kdnaw.exe
      O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
      0
      1. Modérateur
        Télécharge Malwarebytes' Anti-Malware:
        http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.htm

        - Sur la page cliques sur Télécharger Malwarebyte's Anti-Malware
        - Enregistres le sur le bureau
        - Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
        - Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
        - Si le pare-feu demande l'autorisation de se connecter pour malwarebytes, acceptes
        - Une fois la mise à jour terminée, fermes Malwarebytes
        - Redémarres en mode sans échec pour savoir comment au cas ou tu ne saurais pas regarde plus bas
        - Une fois en mode sans échec tu double-cliques sur l'icône de malwarebytes
        - Une fois ouvert rend-toi dans l'onglet, Recherche
        - Sélectionnes Exécuter un examen complet
        - Cliques sur Rechercher
        - Le scan démarre.
        - A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
        - Cliques sur Ok pour poursuivre.
        - Si des malwares ont été détectés, cliques sur Afficher les résultats
        - Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
        - Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
        - Redémarre le PC
        - Une fois redémarré en mode normal double-cliques sur malwarebytes
        - Rends toi dans l'onglet rapport/log
        - Tu cliques dessus pour l'afficher une fois affiché
        - Tu cliques sur édition en haut du boc notes, et puis sur sélectionner tous
        - Tu recliques sur édition et puis sur copier et tu reviens sur le forum et dans ta réponse
        - Tu cliques droit dans le cadre de la réponse et coller

        Si tu as besoin d'aide regarde ce tutorial :
        https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

        (attention : pas de connexion possible en mode sans échec, donc copies ou imprimes bien la manipe pour éviter les erreurs ...)
        Pour redémarrer en mode sans échec :

        Cliques sur Démarrer
        . Cliques sur Arrêter
        . Sélectionnes Redémarrer et au redémarrage
        . Appuis sur la touche F8 sans discontinuer "1 appuis seconde" dès qu'un écran de texte apparaît puis disparaît
        . Utilise les touches de direction pour sélectionner mode sans échec
        . Puis appuis sur ENTRÉE
        . Il faudra choisir ta session habituelle, pas le compte "Administrateur" ou une autre
        une fois démarré ne t'inquiète pas si les couleurs et les icônes ne sont pas comme d'habitude.
        0
        1. Salut Crapoulou. Voici le travail....

          Malwarebytes' Anti-Malware 1.30
          Version de la base de données: 1310
          Windows 6.0.6000

          23/10/2008 19:50:58
          mbam-log-2008-10-23 (19-50-58).txt

          Type de recherche: Examen complet (C:\|D:\|)
          Eléments examinés: 161246
          Temps écoulé: 29 minute(s), 14 second(s)

          Processus mémoire infecté(s): 0
          Module(s) mémoire infecté(s): 0
          Clé(s) du Registre infectée(s): 1
          Valeur(s) du Registre infectée(s): 0
          Elément(s) de données du Registre infecté(s): 9
          Dossier(s) infecté(s): 1
          Fichier(s) infecté(s): 2

          Processus mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Module(s) mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Clé(s) du Registre infectée(s):
          HKEY_CLASSES_ROOT\Pornovid (Trojan.DNSChanger) -> Quarantined and deleted successfully.

          Valeur(s) du Registre infectée(s):
          (Aucun élément nuisible détecté)

          Elément(s) de données du Registre infecté(s):
          HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{1cd96b66-f18a-4056-8227-d221416aae8f}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.159;85.255.112.23 -> Quarantined and deleted successfully.
          HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{94c0e11d-255e-49e4-a052-fbb06ad48b2a}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.159;85.255.112.23 -> Quarantined and deleted successfully.
          HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{94c0e11d-255e-49e4-a052-fbb06ad48b2a}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.159;85.255.112.23 -> Quarantined and deleted successfully.
          HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{1cd96b66-f18a-4056-8227-d221416aae8f}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.159;85.255.112.23 -> Quarantined and deleted successfully.
          HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{94c0e11d-255e-49e4-a052-fbb06ad48b2a}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.159;85.255.112.23 -> Quarantined and deleted successfully.
          HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{94c0e11d-255e-49e4-a052-fbb06ad48b2a}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.159;85.255.112.23 -> Quarantined and deleted successfully.
          HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{1cd96b66-f18a-4056-8227-d221416aae8f}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.159;85.255.112.23 -> Quarantined and deleted successfully.
          HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{94c0e11d-255e-49e4-a052-fbb06ad48b2a}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.159;85.255.112.23 -> Quarantined and deleted successfully.
          HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{94c0e11d-255e-49e4-a052-fbb06ad48b2a}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.159;85.255.112.23 -> Quarantined and deleted successfully.

          Dossier(s) infecté(s):
          C:\resycled (Trojan.DNSChanger) -> Quarantined and deleted successfully.

          Fichier(s) infecté(s):
          C:\Users\Isabelle\Downloads\keygen.Newsleecher.3.9.Final.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
          C:\resycled\boot.com (Trojan.DNSChanger) -> Quarantined and deleted successfully.
          0
          1. Modérateur
            Très bien !
            Poste un nouveau rapport hijackthis stp.
            0
            1. Et voilà.

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 21:49:25, on 22/10/2008
              Platform: Windows Vista (WinNT 6.00.1904)
              MSIE: Internet Explorer v7.00 (7.00.6000.16757)
              Boot mode: Normal

              Running processes:
              C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
              C:\Windows\system32\taskeng.exe
              C:\Windows\SYSTEM32\WISPTIS.EXE
              C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
              C:\Windows\system32\Dwm.exe
              C:\Windows\Explorer.EXE
              C:\Program Files\DellTPad\Apoint.exe
              C:\Windows\OEM02Mon.exe
              C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
              C:\Windows\System32\igfxtray.exe
              C:\Windows\System32\hkcmd.exe
              C:\Windows\System32\igfxpers.exe
              C:\Windows\system32\igfxsrvc.exe
              C:\Program Files\Java\jre1.6.0\bin\jusched.exe
              C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe
              C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
              C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
              C:\Program Files\Dell\MediaDirect\PCMService.exe
              C:\Program Files\Canon\SolutionMenu\CNSLMAIN.EXE
              C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
              C:\Program Files\DellTPad\ApMsgFwd.exe
              C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
              C:\Program Files\DellTPad\HidFind.exe
              C:\Program Files\DellTPad\Apntex.exe
              C:\Program Files\Dell Support Center\bin\sprtcmd.exe
              C:\Program Files\iTunes\iTunesHelper.exe
              C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
              C:\Program Files\Common Files\Real\Update_OB\realsched.exe
              C:\Program Files\Activ Software\Activdriver\ActivControl2.exe
              C:\Windows\ehome\ehtray.exe
              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              C:\Program Files\Windows Media Player\wmpnscfg.exe
              C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
              C:\Program Files\Digital Line Detect\DLG.exe
              C:\Program Files\Dell\QuickSet\quickset.exe
              C:\Windows\ehome\ehmsas.exe
              C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
              c:\PROGRA~1\mcafee\msc\mcuimgr.exe
              C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
              C:\Windows\system32\wuauclt.exe
              C:\Program Files\Mozilla Firefox\firefox.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.free.fr/freebox/index.html
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer fourni par Dell
              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
              O1 - Hosts: ::1 localhost
              O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
              O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
              O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - C:\Program Files\McAfee\MSK\mcapbho.dll
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
              O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
              O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
              O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
              O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
              O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
              O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
              O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
              O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
              O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
              O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "c:\Program Files\Java\jre1.6.0\bin\jusched.exe"
              O4 - HKLM\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s
              O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
              O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
              O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
              O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
              O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
              O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
              O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
              O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
              O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
              O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
              O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
              O4 - HKLM\..\Run: [ActivControl] C:\Program Files\Activ Software\Activdriver\ActivControl2.exe
              O4 - HKLM\..\Run: [695.tmp] C:\Windows\temp\695.tmp
              O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
              O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
              O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
              O4 - Global Startup: BTTray.lnk = ?
              O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
              O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
              O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
              O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
              O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
              O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
              O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
              O13 - Gopher Prefix:
              O16 - DPF: {04CB5B64-5915-4629-B869-8945CEBADD21} (Module de délivrance de certificat MINEFI) - https://static.impots.gouv.fr/abos/static/securite/certdgi1.cab
              O17 - HKLM\System\CCS\Services\Tcpip\..\{1CD96B66-F18A-4056-8227-D221416AAE8F}: NameServer = 85.255.112.159;85.255.112.23
              O17 - HKLM\System\CCS\Services\Tcpip\..\{94C0E11D-255E-49E4-A052-FBB06AD48B2A}: NameServer = 85.255.112.159;85.255.112.23
              O17 - HKLM\System\CS1\Services\Tcpip\..\{1CD96B66-F18A-4056-8227-D221416AAE8F}: NameServer = 85.255.112.159;85.255.112.23
              O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
              O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
              O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
              O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
              O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
              O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
              O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
              O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
              O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
              O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
              O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
              O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
              O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
              O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
              O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
              O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
              O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
              O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
              O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
              O23 - Service: Windows Tribute Service - Unknown owner - C:\Windows\system32\kdnaw.exe
              O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
              0
              1. Modérateur
                Un nouveau : c'est à dire que tu relances le programme.
                Celui là date d'hier soir.
                0
                1. Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 21:53:54, on 23/10/2008
                  Platform: Windows Vista (WinNT 6.00.1904)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16757)
                  Boot mode: Normal

                  Running processes:
                  C:\Windows\system32\csrss.exe
                  C:\Windows\system32\wininit.exe
                  C:\Windows\system32\csrss.exe
                  C:\Windows\system32\services.exe
                  C:\Windows\system32\lsass.exe
                  C:\Windows\system32\lsm.exe
                  C:\Windows\system32\winlogon.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\SLsvc.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\SYSTEM32\WISPTIS.EXE
                  C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
                  C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                  C:\Windows\system32\WLANExt.exe
                  C:\Windows\System32\spoolsv.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\SYSTEM32\WISPTIS.EXE
                  C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
                  C:\Windows\Explorer.EXE
                  C:\Windows\system32\aestsrv.exe
                  C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  C:\Program Files\Bonjour\mDNSResponder.exe
                  C:\Windows\system32\svchost.exe
                  C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                  C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                  C:\Windows\system32\svchost.exe
                  C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                  C:\Program Files\Dell Support Center\bin\sprtsvc.exe
                  C:\Windows\system32\STacSV.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\system32\SearchIndexer.exe
                  C:\Windows\system32\DRIVERS\xaudio.exe
                  C:\Windows\system32\WUDFHost.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Program Files\Windows Defender\MSASCui.exe
                  C:\Program Files\DellTPad\Apoint.exe
                  C:\Windows\OEM02Mon.exe
                  C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
                  C:\Windows\System32\igfxtray.exe
                  C:\Windows\System32\hkcmd.exe
                  C:\Windows\System32\igfxpers.exe
                  C:\Windows\system32\igfxsrvc.exe
                  C:\Program Files\Java\jre1.6.0\bin\jusched.exe
                  C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe
                  C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                  C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                  C:\Program Files\DellTPad\ApMsgFwd.exe
                  C:\Program Files\Dell\MediaDirect\PCMService.exe
                  C:\Program Files\DellTPad\HidFind.exe
                  C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
                  C:\Program Files\DellTPad\Apntex.exe
                  C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
                  C:\Program Files\Dell Support Center\bin\sprtcmd.exe
                  C:\Program Files\iTunes\iTunesHelper.exe
                  C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
                  C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                  C:\Program Files\Activ Software\Activdriver\ActivControl2.exe
                  C:\Windows\ehome\ehtray.exe
                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  C:\Program Files\Windows Media Player\wmpnscfg.exe
                  C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                  C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
                  C:\Program Files\Digital Line Detect\DLG.exe
                  C:\Program Files\Dell\QuickSet\quickset.exe
                  C:\Windows\ehome\ehmsas.exe
                  C:\Program Files\Windows Media Player\wmpnetwk.exe
                  C:\Windows\system32\wbem\wmiprvse.exe
                  C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                  C:\Program Files\iPod\bin\iPodService.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\Windows\system32\svchost.exe
                  C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
                  C:\Windows\system32\wuauclt.exe
                  C:\Windows\system32\wbem\wmiprvse.exe
                  C:\Windows\system32\DllHost.exe
                  C:\Windows\system32\DllHost.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.free.fr/freebox/index.html
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer fourni par Dell
                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                  O1 - Hosts: ::1 localhost
                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
                  O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                  O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                  O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
                  O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
                  O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
                  O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
                  O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                  O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                  O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "c:\Program Files\Java\jre1.6.0\bin\jusched.exe"
                  O4 - HKLM\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s
                  O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
                  O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                  O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
                  O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
                  O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
                  O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
                  O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
                  O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                  O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                  O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                  O4 - HKLM\..\Run: [ActivControl] C:\Program Files\Activ Software\Activdriver\ActivControl2.exe
                  O4 - HKLM\..\Run: [695.tmp] C:\Windows\temp\695.tmp
                  O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
                  O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                  O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                  O4 - Global Startup: BTTray.lnk = ?
                  O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
                  O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                  O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                  O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                  O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                  O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                  O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                  O13 - Gopher Prefix:
                  O16 - DPF: {04CB5B64-5915-4629-B869-8945CEBADD21} (Module de délivrance de certificat MINEFI) - https://static.impots.gouv.fr/abos/static/securite/certdgi1.cab
                  O17 - HKLM\System\CCS\Services\Tcpip\..\{1CD96B66-F18A-4056-8227-D221416AAE8F}: NameServer = 85.255.112.159;85.255.112.23
                  O17 - HKLM\System\CCS\Services\Tcpip\..\{94C0E11D-255E-49E4-A052-FBB06AD48B2A}: NameServer = 85.255.112.159;85.255.112.23
                  O17 - HKLM\System\CS1\Services\Tcpip\..\{1CD96B66-F18A-4056-8227-D221416AAE8F}: NameServer = 85.255.112.159;85.255.112.23
                  O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
                  O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                  O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
                  O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                  O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                  O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                  O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                  O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                  O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
                  O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
                  O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                  O23 - Service: Windows Tribute Service - Unknown owner - C:\Windows\system32\kdnaw.exe
                  O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                  0
                  1. Modérateur
                    Appuie simultanément sur la touche Vista + r > La boite "Exécuter" s'ouvre...
                    Tape "cmd" (sans les "") et valide par ok
                    Dans la fenetre noir tape ceci : "ipconfig /flushdns" (sans les "") et valide par Entrée
                    Relance HijackThis > Do a system scan only
                    Coche ces lignes (si présentes) :

                    O17 - HKLM\System\CCS\Services\Tcpip\..\{1CD96B66-F18A-4056-8227-D221416AAE8F}: NameServer = 85.255.112.159;85.255.112.23
                    O17 - HKLM\System\CCS\Services\Tcpip\..\{94C0E11D-255E-49E4-A052-FBB06AD48B2A}: NameServer = 85.255.112.159;85.255.112.23
                    O17 - HKLM\System\CS1\Services\Tcpip\..\{1CD96B66-F18A-4056-8227-D221416AAE8F}: NameServer = 85.255.112.159;85.255.112.23

                    Clique sur Fix Checked
                    Redémarre le PC et teste la connexion .
                    0
                    1. Je l'ai fait. Rien ne semble avoir changé. Toujours des fenêtres hot qui s'ouvrent.....
                      0
                      1. Modérateur
                        - Télécharge SmitfraudFix (de S!Ri, balltrap34 et moe31) :
                        http://siri.urz.free.fr/Fix/SmitfraudFix.exe ou http://www.geekstogo.com/forum/files/file/6-smitfraudfix/

                        - Enregistre-le sur le bureau
                        - Double-clique sur SmitfraudFix.exe et choisis l'option 5 puis Entrée
                        - Un rapport sera généré, poste-le dans ta prochaine réponse.

                        [*] process.exe est détecté par certains antivirus comme étant un risktool. Il ne s'agit pas d'un virus mais d'un utilitaire destiné à mettre fin à des processus. [*]
                        0
                        1. Visiblement ça ne fonctionne pas. Lorsque je lance smitfraud, option 5, il m'indique accès refusé. Puis une fenêtre s'affiche " your computer may be victim of a DNS hijack...". Pas de génération de rapport.
                          0
                          1. Modérateur
                            Désactives l’UAC (User Account Control) le temps de la désinfection.
                            Démarrer, Panneau de configuration, Comptes d’utilisateurs, Désactiver le contrôle des comptes d’utilisateur.
                            (Manipulation inverse pour le remettre en fin de désinfection).
                            (Cela va permettre aux outils de désinfection de travailler correctement).

                            Relance ensuite l'option 5 de smitfraudfix.
                            0
                            1. C'est fait..

                              SmitFraudFix v2.366

                              Scan done at 0:01:36,41, 24/10/2008
                              Run from C:\Users\Isabelle\Desktop\SmitfraudFix
                              OS: Microsoft Windows [version 6.0.6000] - Windows_NT
                              The filesystem type is NTFS
                              Fix run in normal mode

                              »»»»»»»»»»»»»»»»»»»»»»»» DNS Before Fix

                              Your computer may be victim of a DNS Hijack: 85.255.x.x detected !

                              Description: Marvell Yukon 88E8040 PCI-E Fast Ethernet Controller
                              DNS Server Search Order: 85.255.112.159;85.255.112.23

                              HKLM\SYSTEM\CCS\Services\Tcpip\..\{1CD96B66-F18A-4056-8227-D221416AAE8F}: DhcpNameServer=212.27.40.241 212.27.40.240
                              HKLM\SYSTEM\CCS\Services\Tcpip\..\{1CD96B66-F18A-4056-8227-D221416AAE8F}: NameServer=85.255.112.159;85.255.112.23
                              HKLM\SYSTEM\CCS\Services\Tcpip\..\{94C0E11D-255E-49E4-A052-FBB06AD48B2A}: DhcpNameServer=85.255.112.159;85.255.112.23
                              HKLM\SYSTEM\CCS\Services\Tcpip\..\{94C0E11D-255E-49E4-A052-FBB06AD48B2A}: NameServer=85.255.112.159;85.255.112.23
                              HKLM\SYSTEM\CS1\Services\Tcpip\..\{1CD96B66-F18A-4056-8227-D221416AAE8F}: DhcpNameServer=212.27.40.241 212.27.40.240
                              HKLM\SYSTEM\CS1\Services\Tcpip\..\{1CD96B66-F18A-4056-8227-D221416AAE8F}: NameServer=85.255.112.159;85.255.112.23
                              HKLM\SYSTEM\CS1\Services\Tcpip\..\{94C0E11D-255E-49E4-A052-FBB06AD48B2A}: DhcpNameServer=85.255.112.159;85.255.112.23
                              HKLM\SYSTEM\CS1\Services\Tcpip\..\{94C0E11D-255E-49E4-A052-FBB06AD48B2A}: NameServer=85.255.112.159;85.255.112.23
                              HKLM\SYSTEM\CS3\Services\Tcpip\..\{1CD96B66-F18A-4056-8227-D221416AAE8F}: DhcpNameServer=212.27.40.241 212.27.40.240
                              HKLM\SYSTEM\CS3\Services\Tcpip\..\{1CD96B66-F18A-4056-8227-D221416AAE8F}: NameServer=85.255.112.159;85.255.112.23
                              HKLM\SYSTEM\CS3\Services\Tcpip\..\{94C0E11D-255E-49E4-A052-FBB06AD48B2A}: DhcpNameServer=85.255.112.159;85.255.112.23
                              HKLM\SYSTEM\CS3\Services\Tcpip\..\{94C0E11D-255E-49E4-A052-FBB06AD48B2A}: NameServer=85.255.112.159;85.255.112.23
                              HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.241 212.27.40.240
                              HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.241 212.27.40.240
                              HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.241 212.27.40.240

                              »»»»»»»»»»»»»»»»»»»»»»»» DNS After Fix

                              Description: Marvell Yukon 88E8040 PCI-E Fast Ethernet Controller
                              DNS Server Search Order: 212.27.40.241
                              DNS Server Search Order: 212.27.40.240

                              HKLM\SYSTEM\CCS\Services\Tcpip\..\{1CD96B66-F18A-4056-8227-D221416AAE8F}: DhcpNameServer=212.27.40.241 212.27.40.240
                              0
                              1. Modérateur
                                Parfait, poste un nouveau rapport hijackthis stp.
                                0
                                1. Bonjour, voici le log.

                                  Logfile of Trend Micro HijackThis v2.0.2
                                  Scan saved at 17:23:01, on 24/10/2008
                                  Platform: Windows Vista (WinNT 6.00.1904)
                                  MSIE: Internet Explorer v7.00 (7.00.6000.16757)
                                  Boot mode: Normal

                                  Running processes:
                                  C:\Windows\system32\csrss.exe
                                  C:\Windows\system32\wininit.exe
                                  C:\Windows\system32\csrss.exe
                                  C:\Windows\system32\services.exe
                                  C:\Windows\system32\lsass.exe
                                  C:\Windows\system32\lsm.exe
                                  C:\Windows\system32\winlogon.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Windows\System32\svchost.exe
                                  C:\Windows\System32\svchost.exe
                                  C:\Windows\System32\svchost.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Windows\system32\SLsvc.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Windows\SYSTEM32\WISPTIS.EXE
                                  C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                                  C:\Windows\system32\WLANExt.exe
                                  C:\Windows\System32\spoolsv.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Windows\system32\taskeng.exe
                                  C:\Windows\system32\Dwm.exe
                                  C:\Windows\SYSTEM32\WISPTIS.EXE
                                  C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
                                  C:\Windows\Explorer.EXE
                                  C:\Program Files\Windows Defender\MSASCui.exe
                                  C:\Program Files\DellTPad\Apoint.exe
                                  C:\Windows\OEM02Mon.exe
                                  C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
                                  C:\Windows\System32\igfxtray.exe
                                  C:\Windows\System32\hkcmd.exe
                                  C:\Windows\System32\igfxpers.exe
                                  C:\Program Files\Java\jre1.6.0\bin\jusched.exe
                                  C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe
                                  C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                                  C:\Windows\system32\aestsrv.exe
                                  C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                  C:\Program Files\Bonjour\mDNSResponder.exe
                                  C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                  C:\Program Files\Dell\MediaDirect\PCMService.exe
                                  C:\Program Files\Canon\SolutionMenu\CNSLMAIN.EXE
                                  C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
                                  C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
                                  C:\Program Files\Dell Support Center\bin\sprtcmd.exe
                                  C:\Program Files\iTunes\iTunesHelper.exe
                                  C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
                                  C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                                  C:\Program Files\Activ Software\Activdriver\ActivControl2.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                                  C:\Windows\ehome\ehtray.exe
                                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                  C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                  C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                                  C:\Program Files\Dell Support Center\bin\sprtsvc.exe
                                  C:\Windows\system32\STacSV.exe
                                  C:\Program Files\Windows Media Player\wmpnscfg.exe
                                  C:\Windows\system32\igfxsrvc.exe
                                  C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                  C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
                                  C:\Program Files\Digital Line Detect\DLG.exe
                                  C:\Program Files\Dell\QuickSet\quickset.exe
                                  C:\Windows\ehome\ehmsas.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Windows\System32\svchost.exe
                                  C:\Windows\system32\SearchIndexer.exe
                                  C:\Windows\system32\DRIVERS\xaudio.exe
                                  C:\Program Files\Windows Media Player\wmpnetwk.exe
                                  C:\Windows\system32\taskeng.exe
                                  C:\Windows\system32\wbem\wmiprvse.exe
                                  C:\Program Files\DellTPad\ApMsgFwd.exe
                                  C:\Program Files\DellTPad\Apntex.exe
                                  C:\Program Files\DellTPad\HidFind.exe
                                  C:\Program Files\iPod\bin\iPodService.exe
                                  C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                  C:\Program Files\Mozilla Firefox\firefox.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
                                  C:\Windows\system32\wuauclt.exe
                                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                                  C:\Windows\system32\wbem\wmiprvse.exe

                                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.free.fr/freebox/index.html
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer fourni par Dell
                                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                  O1 - Hosts: ::1 localhost
                                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                  O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
                                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
                                  O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
                                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                                  O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                  O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
                                  O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
                                  O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
                                  O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
                                  O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                                  O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                                  O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "c:\Program Files\Java\jre1.6.0\bin\jusched.exe"
                                  O4 - HKLM\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s
                                  O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
                                  O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                                  O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
                                  O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
                                  O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
                                  O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
                                  O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
                                  O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
                                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                                  O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
                                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                  O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
                                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                                  O4 - HKLM\..\Run: [ActivControl] C:\Program Files\Activ Software\Activdriver\ActivControl2.exe
                                  O4 - HKLM\..\Run: [695.tmp] C:\Windows\temp\695.tmp
                                  O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
                                  O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                  O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                  O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                  O4 - Global Startup: BTTray.lnk = ?
                                  O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
                                  O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
                                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                                  O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                                  O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
                                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
                                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
                                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                                  O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                                  O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                                  O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                                  O13 - Gopher Prefix:
                                  O16 - DPF: {04CB5B64-5915-4629-B869-8945CEBADD21} (Module de délivrance de certificat MINEFI) - https://static.impots.gouv.fr/abos/static/securite/certdgi1.cab
                                  O17 - HKLM\System\CCS\Services\Tcpip\..\{1CD96B66-F18A-4056-8227-D221416AAE8F}: NameServer = 85.255.112.159;85.255.112.23
                                  O17 - HKLM\System\CCS\Services\Tcpip\..\{94C0E11D-255E-49E4-A052-FBB06AD48B2A}: NameServer = 85.255.112.159;85.255.112.23
                                  O17 - HKLM\System\CS1\Services\Tcpip\..\{1CD96B66-F18A-4056-8227-D221416AAE8F}: NameServer = 85.255.112.159;85.255.112.23
                                  O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
                                  O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                                  O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
                                  O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                  O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                  O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                                  O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                  O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                                  O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                  O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                                  O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
                                  O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
                                  O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                                  O23 - Service: Windows Tribute Service - Unknown owner - C:\Windows\system32\kdnaw.exe
                                  O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                                  0
                                  1. Modérateur
                                    Edit :

                                    Désactives l’UAC (User Account Control) le temps de la désinfection.
                                    Démarrer, Panneau de configuration, Comptes d’utilisateurs, Désactiver le contrôle des comptes d’utilisateur.
                                    (Manipulation inverse pour le remettre en fin de désinfection).
                                    (Cela va permettre aux outils de désinfection de travailler correctement).

                                    Ensuite :

                                    Telecharge UsbFix sur ton bureau :
                                    http://sd-1.archive-host.com/membres/up/116615172019703188/UsbFix.exe

                                    --> Lance l installation avec les paramètres par defaut

                                    Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été mis sur l'ordinateur.

                                    --> Double clic sur le raccourci UsbFix sur ton bureau

                                    --> Le pc va redémarrer

                                    -->Après redémarrage poste le rapport UsbFix.txt

                                    Note : le rapport UsbFix.txt est sauvegardé a la racine du disque
                                    Note : Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides
                                    0
                                    1. Voici le rapport.

                                      -------------- UsbFix V2.395 ---------------

                                      * User : Isabelle - PC-DE-ISABELLE
                                      * Outils mis a jours le 20/10/2008 par Chiquitine29 et Chimay8
                                      * Recherche effectuée à 20:05:06 le 24/10/2008
                                      * Windows Vista - Internet Explorer 7.0.6000.16757

                                      --------------- [ Processus actifs ] ----------------

                                      C:\Windows\system32\csrss.exe
                                      C:\Windows\system32\wininit.exe
                                      C:\Windows\system32\csrss.exe
                                      C:\Windows\system32\services.exe
                                      C:\Windows\system32\lsass.exe
                                      C:\Windows\system32\lsm.exe
                                      C:\Windows\system32\winlogon.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Windows\System32\svchost.exe
                                      C:\Windows\System32\svchost.exe
                                      C:\Windows\System32\svchost.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Windows\system32\SLsvc.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Windows\SYSTEM32\WISPTIS.EXE
                                      C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
                                      C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                                      C:\Windows\system32\WLANExt.exe
                                      C:\Windows\System32\spoolsv.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Windows\system32\aestsrv.exe
                                      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                      C:\Program Files\Bonjour\mDNSResponder.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                                      C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                      C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                                      C:\Program Files\Dell Support Center\bin\sprtsvc.exe
                                      C:\Windows\system32\STacSV.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Windows\System32\svchost.exe
                                      C:\Windows\system32\SearchIndexer.exe
                                      C:\Windows\system32\DRIVERS\xaudio.exe
                                      C:\Windows\system32\WUDFHost.exe
                                      C:\Windows\system32\taskeng.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Windows\system32\wbem\wmiprvse.exe
                                      C:\Windows\system32\taskeng.exe
                                      C:\Windows\system32\userinit.exe
                                      C:\Windows\SYSTEM32\WISPTIS.EXE
                                      C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
                                      C:\Windows\system32\Dwm.exe
                                      C:\Windows\system32\SearchProtocolHost.exe
                                      C:\Windows\system32\SearchFilterHost.exe
                                      C:\Users\Isabelle\AppData\Local\Temp\7925.tmp\b2e.exe
                                      C:\Program Files\Windows Defender\MSASCui.exe
                                      C:\DELL\E-Center\EULALauncher.exe
                                      C:\Program Files\DellTPad\Apoint.exe
                                      C:\Windows\system32\conime.exe
                                      C:\Windows\OEM02Mon.exe
                                      C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
                                      C:\Windows\System32\igfxtray.exe
                                      C:\Windows\System32\igfxpers.exe
                                      C:\Program Files\Java\jre1.6.0\bin\jusched.exe
                                      C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                                      C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                      C:\Windows\system32\igfxsrvc.exe
                                      C:\Program Files\Dell\MediaDirect\PCMService.exe
                                      C:\Program Files\Canon\SolutionMenu\CNSLMAIN.EXE
                                      C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
                                      C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
                                      C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
                                      C:\Program Files\iTunes\iTunesHelper.exe
                                      C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
                                      C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                                      C:\Program Files\Activ Software\Activdriver\ActivControl2.exe
                                      C:\Windows\ehome\ehtray.exe
                                      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                      C:\Program Files\Windows Media Player\wmpnscfg.exe
                                      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                      C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
                                      C:\Program Files\Digital Line Detect\DLG.exe
                                      C:\Program Files\Dell\QuickSet\quickset.exe
                                      C:\Program Files\Windows Media Player\wmpnetwk.exe
                                      C:\Windows\ehome\ehmsas.exe
                                      C:\Program Files\DellTPad\ApMsgFwd.exe
                                      C:\Windows\system32\wbem\wmiprvse.exe
                                      C:\Program Files\DellTPad\HidFind.exe
                                      C:\Program Files\DellTPad\Apntex.exe

                                      --------------- [ Informations lecteurs ] ----------------

                                      C: - Lecteur fixe
                                      D: - Lecteur fixe
                                      G: - Lecteur de CD-ROM
                                      H: - Lecteur amovible

                                      +- Contenu de l'autorun : C:\autorun.inf

                                      [autorun]
                                      shellexecute="resycled\boot.com c:"
                                      shell\Open\command="resycled\boot.com c:"
                                      shell=Open

                                      +- Contenu de l'autorun : D:\autorun.inf

                                      [autorun]
                                      shellexecute="resycled\boot.com d:"
                                      shell\Open\command="resycled\boot.com d:"
                                      shell=Open

                                      +- Contenu de l'autorun : G:\autorun.inf

                                      [AutoRun]
                                      open=LaunchU3.exe -a
                                      icon=LaunchU3.exe,0

                                      [Definitions]
                                      Launchpad=LaunchPad.exe
                                      Vtype=2

                                      [CopyFiles]
                                      FileNumber=1
                                      File1=LaunchPad.zip

                                      [Update]
                                      URL=http://u3.sandisk.com/download/lp_installer.asp?custom=1.6.1.1&brand=CruzerBFG

                                      [Comment]
                                      brand=CruzerBFG
                                      --------------- [ Registre / Startup ] ----------------

                                      HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
                                      Windows Defender REG_EXPAND_SZ %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                      ECenter REG_SZ C:\Dell\E-Center\EULALauncher.exe
                                      Apoint REG_SZ C:\Program Files\DellTPad\Apoint.exe
                                      OEM02Mon.exe REG_SZ C:\Windows\OEM02Mon.exe
                                      SigmatelSysTrayApp REG_EXPAND_SZ %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
                                      IgfxTray REG_SZ C:\Windows\system32\igfxtray.exe
                                      HotKeysCmds REG_SZ C:\Windows\system32\hkcmd.exe
                                      Persistence REG_SZ C:\Windows\system32\igfxpers.exe
                                      SunJavaUpdateSched REG_SZ "c:\Program Files\Java\jre1.6.0\bin\jusched.exe"
                                      DELL Webcam Manager REG_SZ "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s
                                      IAAnotif REG_SZ "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
                                      Google Desktop Search REG_SZ "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                                      dscactivate REG_SZ "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
                                      PCMService REG_SZ "C:\Program Files\Dell\MediaDirect\PCMService.exe"
                                      CanonSolutionMenu REG_SZ C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
                                      CanonMyPrinter REG_SZ C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
                                      SSBkgdUpdate REG_SZ "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
                                      OpwareSE4 REG_SZ "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
                                      Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                      QuickTime Task REG_SZ "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                                      DellSupportCenter REG_SZ "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
                                      iTunesHelper REG_SZ "C:\Program Files\iTunes\iTunesHelper.exe"
                                      SMSTray REG_SZ C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
                                      TkBellExe REG_SZ "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                                      ActivControl REG_SZ C:\Program Files\Activ Software\Activdriver\ActivControl2.exe
                                      695.tmp REG_SZ C:\Windows\temp\695.tmp

                                      HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents

                                      HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
                                      DellSupportCenter REG_SZ "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
                                      ehTray.exe REG_SZ C:\Windows\ehome\ehTray.exe
                                      swg REG_SZ C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                      WMPNSCFG REG_SZ C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                      SpybotSD TeaTimer REG_SZ C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

                                      --------------- [ Registre / Mountpoint2 ] ----------------

                                      Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G\Shell\AutoRun\command
                                      Supprimé ! - HKEY_USERS\S-1-5-21-898479912-569789823-1289803555-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G\Shell\AutoRun\command
                                      Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6446b63c-4e0a-11dd-b391-001d094eaa4e}\Shell\AutoRun\command
                                      Supprimé ! - HKEY_USERS\S-1-5-21-898479912-569789823-1289803555-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6446b63c-4e0a-11dd-b391-001d094eaa4e}\Shell\AutoRun\command
                                      Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{dedd0491-0ff7-11dd-a960-806e6f6e6963}\Shell\AutoRun\command
                                      Supprimé ! - HKEY_USERS\S-1-5-21-898479912-569789823-1289803555-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{dedd0491-0ff7-11dd-a960-806e6f6e6963}\Shell\AutoRun\command

                                      --------------- [ Nettoyage des disques ] ----------------

                                      Supprimé ! - C:\autorun.inf
                                      Supprimé ! - D:\autorun.inf
                                      Supprimé ! - D:\resycled\boot.com
                                      Supprimé ! - D:\resycled
                                      Echec de la supression !! - G:\autorun.inf
                                      Echec de la supression !! - G:\autorun.inf

                                      --------------- ! Fin du rapport ! ----------------
                                      0
                                  2. Contributeur sécurité
                                    lut'
                                    pour suivre
                                    merci
                                    0
                                    1. Modérateur
                                      Sur le lecteur G, il y a un autorun à supprimer.
                                      Pour ce faire :
                                      Affiche les fichiers et dossiers cachés :
                                      Dans Mes documents, Outils, Options des dossiers, Onglet Affichage, coche Afficher les fichiers et dossiers cachés.

                                      Va dans ton lecteur G et supprime manuellement "autorun.inf".
                                      0
                                      1. Contributeur sécurité
                                        pas nécessaire

                                        G: - Lecteur de CD-ROM

                                        donc normal
                                        @+
                                        0
                                        • 1
                                        • 2
                                        • 3