Je suis FULL infected, a l'aide

Bonjour,

je suis infectée. Vous m'avez déjà aidée par le passée. J'ai encore besoin d'aide. Voici mon hijack :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:52:41, on 2008-11-06
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16757)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\jureg.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\system32\schtasks.exe
C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
C:\Windows\System32\LVCOMSX.EXE
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
c:\users\tony stewart 20\appdata\local\qiqok.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\jusched.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avcenter.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.fr.msn.ca/0SEFRCA/SAOS01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.rds.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://compaq-consumer.my.aol.qc.ca/?icid=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://compaq-consumer.my.aol.qc.ca/?icid=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O1 - Hosts: ::1 localhost
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\msgr.fr.fr-ca\msntb.dll
O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=0
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\Windows\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [CamWizard] C:\Program Files\Common Files\Logitech\QCDRV\BIN\CamWizard.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [yrtb5246] C:\Windows\yrtb5246.exe
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [qiqok] "c:\users\tony stewart 20\appdata\local\qiqok.exe" qiqok
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\Windows\system32\Macromed\Flash\FlashUtil9c.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O4 - Startup: ppcbooster.lnk = C:\Program Files\ppcbooster\ppcbooster.exe
O4 - Startup: ppcb_32.lnk = ?
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZRxdm690MXCA
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O13 - Gopher Prefix:
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-3/PopularScreenSaversFWBInitialSetup1.0.1.0.cab
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 9085 bytes

Merci beaucoup
Configuration: Windows Vista
Internet Explorer 7.0

22 réponses

Résumé de la discussion

Infection informatique détectée, le journal HijackThis signale de nombreux processus et extensions indésirables ainsi que des redirections et des méthodes d'installation potentiellement malveillantes sur le système. Plusieurs interventions proposées visent à nettoyer le système en profondeur, en priorité la suppression du dossier RSIT et l'exécution du scanner RSIT en mode Administrateur pour générer deux rapports. D'autres contributions suggèrent des alternatives comme désactiver temporairement l'UAC et utiliser Navilog1 pour diagnostiquer et extraire un rapport, puis partager le contenu pour continuer le nettoyage. Certains participants évoquent également des questions sur des composants comme PPCBooster ou des barres d'outils tierces et la nécessité d'évaluer les risques avant de supprimer des éléments légitimes.

Bobot (l’IA à votre service)
  1. Modérateur
    Salut,

    Wahoo, c'est la fête dans ton PC.

    ---> Désactive l'UAC le temps de la désinfection :
    http://www.commentcamarche.net/faq/sujet 8343 vista desactiver l uac

    - Télécharge Navilog1 (de IL-MAFIOSO) et enregistre-le sur le bureau :
    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

    - Double-clique sur Navilog1.exe afin de lancer l'installation

    - Si le fix ne se lance pas automatiquement après son installation, double-clique sur Navilog1 présent sur le bureau

    - Appuie sur F ou f puis valide par Entrée

    - Appuie sur une touche de ton clavier à chaque fois que cela est demandé, tu arriveras au menu des options

    - Choisis l'option 1 et appuie sur la touche Entrée pour valider ton choix

    - Patiente jusqu'au message : *** Analyse terminée le ..... ***

    - Le scan fini, le bloc-notes contenant le rapport sera affiché, poste le contenu de ce rapport dans ta prochaine réponse

    - Si le résultat du scan ne s'affiche pas, tu le trouveras dans C:\fixnavi.txt

    N'utilise pas l'option 2, 3 et 4 sans notre accord, des fichiers légitimes peuvent être inclus dans ce scan.
    0
    1. Bonjour,

      j'ai suivi vos instructions. Voici mon post :

      Search Navipromo version 3.6.9 commencé le 2008-11-06 à 23:18:22,85

      !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
      !!! Postez ce rapport sur le forum pour le faire analyser !!!
      !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

      Outil exécuté depuis C:\Program Files\navilog1
      Session actuelle : "Tony Stewart 20"

      Mise à jour le 05.11.2008 à 21h00 par IL-MAFIOSO

      Microsoft Windows Vista 6.0.6000
      Internet Explorer : 7.0.6000.16757
      Système de fichiers : NTFS

      Recherche executé en mode normal

      *** Recherche Programmes installés ***

      *** Recherche dossiers dans "C:\Windows" ***

      *** Recherche dossiers dans "C:\Program Files" ***

      *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

      *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1" ***

      *** Recherche dossiers dans "C:\ProgramData" ***

      *** Recherche dossiers dans "c:\users\tonyst~1\appdata\roaming\micros~1\windows\startm~1\programs" ***

      *** Recherche dossiers dans "C:\Users\Tony Stewart 20\AppData\Local\virtualstore\Program Files" ***

      *** Recherche dossiers dans "C:\Users\Tony Stewart 20\AppData\Roaming" ***

      *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
      pour + d'infos : http://www.gmer.net

      *** Recherche avec GenericNaviSearch ***
      !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
      !!! A vérifier impérativement avant toute suppression manuelle !!!

      * Recherche dans "C:\Windows\system32" *

      * Recherche dans "C:\Users\Tony Stewart 20\AppData\Local\Microsoft" *

      * Recherche dans "C:\Users\Tony Stewart 20\AppData\Local" *

      *** Recherche fichiers ***

      *** Recherche clés spécifiques dans le Registre ***

      HKEY_CURRENT_USER\Software\Lanconfig trouvé !

      *** Module de Recherche complémentaire ***
      (Recherche fichiers spécifiques)

      1)Recherche nouveaux fichiers Instant Access :

      2)Recherche Heuristique :

      * Dans "C:\Windows\system32" :

      * Dans "C:\Users\Tony Stewart 20\AppData\Local\Microsoft" :

      * Dans "C:\Users\Tony Stewart 20\AppData\Local" :

      qiqok.exe trouvé !
      qiqok.dat trouvé !
      qiqok_nav.dat trouvé !
      qiqok_navps.dat trouvé !

      3)Recherche Certificats :

      Certificat Egroup trouvé !
      Certificat Electronic-Group trouvé !
      Certificat Montorgueil absent !
      Certificat OOO-Favorit trouvé !
      Certificat Sunny-Day-Design-Ltd absent !

      4)Recherche fichiers connus :

      *** Analyse terminée le 2008-11-06 à 23:25:46,37 ***

      merci
      0
  2. Modérateur
    ---> Relance Navilog1, fais l'option 2 et poste le rapport.
    0
    1. rebonjour,

      dernier message de la soirée, je vais aller me coucher. Voici mon raport, j'attend de tes nouvelles pour demain, je continuerai. Merci beaucoup e ton aide.

      mon post :

      Clean Navipromo version 3.6.9 commencé le 2008-11-06 à 23:54:56,44

      Outil exécuté depuis C:\Program Files\navilog1
      Session actuelle : "Tony Stewart 20"

      Mise à jour le 05.11.2008 à 21h00 par IL-MAFIOSO

      Microsoft Windows Vista 6.0.6000
      Internet Explorer : 7.0.6000.16757
      Système de fichiers : NTFS

      Mode suppression automatique
      avec prise en charge résultats Catchme et GNS

      Nettoyage exécuté au redémarrage de l'ordinateur

      *** fsbl1.txt non trouvé ***
      (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)

      *** Suppression avec sauvegardes résultats GenericNaviSearch ***

      * Suppression dans "C:\Windows\System32" *

      * Suppression dans "C:\Users\Tony Stewart 20\AppData\Local\Microsoft" *

      * Suppression dans "C:\Users\Tony Stewart 20\AppData\Local" *

      *** Suppression dossiers dans "C:\Windows" ***

      *** Suppression dossiers dans "C:\Program Files" ***

      *** Suppression dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

      *** Suppression dossiers dans "c:\progra~2\micros~1\windows\startm~1" ***

      *** Suppression dossiers dans "C:\ProgramData" ***

      *** Suppression dossiers dans c:\users\tonyst~1\appdata\roaming\micros~1\windows\startm~1\programs ***

      *** Suppression dossiers dans "C:\Users\Tony Stewart 20\AppData\Local\virtualstore\Program Files" ***

      *** Suppression dossiers dans "C:\Users\Tony Stewart 20\AppData\Roaming" ***

      *** Suppression fichiers ***

      *** Suppression fichiers temporaires ***

      Nettoyage contenu C:\Windows\Temp effectué !
      Nettoyage contenu C:\Users\TONYST~1\AppData\Local\Temp effectué !

      *** Traitement Recherche complémentaire ***
      (Recherche fichiers spécifiques)

      1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

      2)Recherche, création sauvegardes et suppression Heuristique :

      * Dans "C:\Windows\system32" *

      * Dans "C:\Users\Tony Stewart 20\AppData\Local\Microsoft" *

      * Dans "C:\Users\Tony Stewart 20\AppData\Local" *

      qiqok.exe trouvé !
      Copie qiqok.exe réalisée avec succès !
      qiqok.exe supprimé !

      qiqok.dat trouvé !
      Copie qiqok.dat réalisée avec succès !
      qiqok.dat supprimé !

      qiqok_nav.dat trouvé !
      Copie qiqok_nav.dat réalisée avec succès !
      qiqok_nav.dat supprimé !

      qiqok_navps.dat trouvé !
      Copie qiqok_navps.dat réalisée avec succès !
      qiqok_navps.dat supprimé !

      C:\Windows\prefetch\qiqok*.pf trouvé !
      Copie C:\Windows\prefetch\qiqok*.pf réalisée avec succès !
      C:\Windows\prefetch\qiqok*.pf supprimé !

      *** Sauvegarde du Registre vers dossier Safebackup ***

      sauvegarde du Registre réalisée avec succès !

      *** Nettoyage Registre ***

      Nettoyage Registre Ok

      *** Certificats ***

      Certificat Egroup supprimé !
      Certificat Electronic-Group supprimé !
      Certificat Montorgueil absent !
      Certificat OOO-Favorit supprimé !
      Certificat Sunny-Day-Design-Ltdt absent !

      *** Nettoyage terminé le 2008-11-06 à 23:59:13,61 ***

      Bonne nuit
      xx
      0
      1. Modérateur
        ---> Télécharge Toolbar S&D (Team IDN) sur ton Bureau.
        * Lance l'installation du programme en exécutant le fichier téléchargé.
        * Double-clique maintenant sur le raccourci de Toolbar S&D.
        * Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
        * Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
        * Poste le rapport généré. (C:\TB.txt)
        0
        1. me revoici :

          -----------\\ ToolBar S&D 1.2.4 XP/Vista

          Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6000 )
          X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) Dual CPU E2140 @ 1.60GHz )
          BIOS : BIOS Date: 10/01/07 17:10:01 Ver: 5.16
          USER : Tony Stewart 20 ( Administrator )
          BOOT : Normal boot
          Antivirus : Avira AntiVir PersonalEdition 8.0.1.30 (Activated)
          C:\ (Local Disk) - NTFS - Total:291 Go (Free:227 Go)
          D:\ (Local Disk) - NTFS - Total:6 Go (Free:0 Go)
          E:\ (CD or DVD)
          F:\ (USB)
          G:\ (USB)
          H:\ (USB)
          I:\ (USB)

          "C:\ToolBar SD" ( MAJ : 27-10-2008|09:25 )
          Option : [1] ( 2008-11-07|18:11 )

          [ UAC => 0 ]

          -----------\\ Recherche de Fichiers / Dossiers ...

          [Service] MyWebSearchService
          C:\Program Files\FunWebProducts
          C:\Program Files\FunWebProducts\ScreenSaver
          C:\Users\TONYST~1\AppData\Roaming\MICROS~1\Windows\Cookies\tony_stewart_20@mywebsearch[1].txt
          C:\Program Files\MyWebSearch
          C:\Program Files\MyWebSearch\bar
          C:\Program Files\MyWebSearch\SrchAstt
          C:\Windows\System32\f3PSSavr.scr
          C:\Program Files\Internet Explorer\msimg32.dll
          C:\Program Files\MSN Messenger\riched20.dll

          -----------\\ [..\Internet Explorer\Main]

          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
          "Start Page"="https://www.rds.ca/"
          "Local Page"="C:\\Windows\\system32\\blank.htm"
          "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
          "Search Bar"="http://g.fr.msn.ca/0SEFRCA/SAOS01"
          "Url"="https://www.msn.com/fr-fr/actualite/"

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
          "Start Page"="http://compaq-consumer.my.aol.qc.ca/?icid=desktop"
          "Default_Page_URL"="http://compaq-consumer.my.aol.qc.ca/?icid=desktop"
          "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
          "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"

          --------------------\\ Recherche d'autres infections

          --------------------\\ Cracks & Keygens ..

          C:\Users\TONYST~1\AppData\Roaming\Microsoft\Windows\Recent\dvd fab 5.0.8.5 platinum+crack [ita].lnk
          C:\Users\TONYST~1\AppData\Roaming\Microsoft\Windows\Recent\VSO Software ConvertXtoDVD 3.2.0.50 Full Multilanguage + Crack.lnk
          C:\Users\TONYST~1\Desktop\musique\dvd fab 5.0.8.5 platinum+crack [ita]
          C:\Users\TONYST~1\Desktop\musique\VSO Software ConvertXtoDVD 3.2.0.50 Full Multilanguage + Crack
          C:\Users\TONYST~1\Desktop\musique\VSO Software ConvertXtoDVD 3.2.0.50 Full Multilanguage + Crack.zip
          C:\Users\TONYST~1\Desktop\musique\VSO Software ConvertXtoDVD 3.2.0.50 Full Multilanguage + Crack\Data1.cab
          C:\Users\TONYST~1\Desktop\musique\VSO Software ConvertXtoDVD 3.2.0.50 Full Multilanguage + Crack\Data2.cab
          C:\Users\TONYST~1\Desktop\musique\VSO Software ConvertXtoDVD 3.2.0.50 Full Multilanguage + Crack\Data3.cab
          C:\Users\TONYST~1\Desktop\musique\VSO Software ConvertXtoDVD 3.2.0.50 Full Multilanguage + Crack\keymaker.exe
          C:\Users\TONYST~1\Desktop\musique\VSO Software ConvertXtoDVD 3.2.0.50 Full Multilanguage + Crack\Setup.exe
          C:\Users\TONYST~1\Desktop\musique\VSO Software ConvertXtoDVD 3.2.0.50 Full Multilanguage + Crack\VSO Software ConvertXtoDVD 3.2.0.50 Full Multilanguage + Crack.nfo

          [ UAC => 1 ]

          1 - "C:\ToolBar SD\TB_1.txt" - 2008-11-07|18:11 - Option : [1]

          -----------\\ Fin du rapport a 18:11:40,40
          0
      2. Modérateur
        ---> Relance ToolBar S&D, fais l'option 2 et poste le rapport.
        0
        1. voici mon post :

          -----------\\ ToolBar S&D 1.2.4 XP/Vista

          Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6000 )
          X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) Dual CPU E2140 @ 1.60GHz )
          BIOS : BIOS Date: 10/01/07 17:10:01 Ver: 5.16
          USER : Tony Stewart 20 ( Administrator )
          BOOT : Normal boot
          Antivirus : Avira AntiVir PersonalEdition 8.0.1.30 (Activated)
          C:\ (Local Disk) - NTFS - Total:291 Go (Free:227 Go)
          D:\ (Local Disk) - NTFS - Total:6 Go (Free:0 Go)
          E:\ (CD or DVD)
          F:\ (USB)
          G:\ (USB)
          H:\ (USB)
          I:\ (USB)

          "C:\ToolBar SD" ( MAJ : 27-10-2008|09:25 )
          Option : [2] ( 2008-11-07|18:31 )

          [ UAC => 1 ]

          -----------\\ SUPPRESSION

          Supprime! - [Service] MyWebSearchService
          Supprime! - C:\Program Files\FunWebProducts\ScreenSaver
          Supprime! - C:\Users\TONYST~1\AppData\Roaming\MICROS~1\Windows\Cookies\tony_stewart_20@mywebsearch[1].txt
          Echec ! - C:\Program Files\MyWebSearch\bar
          Supprime! - C:\Program Files\MyWebSearch\SrchAstt
          Supprime! - C:\Windows\System32\f3PSSavr.scr
          Supprime! - C:\Program Files\Internet Explorer\msimg32.dll
          Supprime! - C:\Program Files\MSN Messenger\riched20.dll
          Supprime! - C:\Program Files\FunWebProducts
          Echec ! - C:\Program Files\MyWebSearch

          -----------\\ DEUXIEME PASSAGE

          Echec ! - C:\Program Files\MyWebSearch\bar
          Echec ! - C:\Program Files\MyWebSearch

          -----------\\ Recherche de Fichiers / Dossiers ...

          C:\Program Files\MyWebSearch
          C:\Program Files\MyWebSearch\bar

          -----------\\ [..\Internet Explorer\Main]

          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
          "Start Page"="https://www.rds.ca/"
          "Local Page"="C:\\Windows\\system32\\blank.htm"
          "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
          "Search Bar"="http://g.fr.msn.ca/0SEFRCA/SAOS01"
          "Url"="https://www.msn.com/fr-fr/actualite/"

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
          "Start Page"="https://www.msn.com/fr-fr/"
          "Default_Page_URL"="http://compaq-consumer.my.aol.qc.ca/?icid=desktop"
          "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
          "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"

          --------------------\\ Recherche d'autres infections

          --------------------\\ Cracks & Keygens ..

          C:\Users\TONYST~1\AppData\Roaming\Microsoft\Windows\Recent\dvd fab 5.0.8.5 platinum+crack [ita].lnk
          C:\Users\TONYST~1\AppData\Roaming\Microsoft\Windows\Recent\VSO Software ConvertXtoDVD 3.2.0.50 Full Multilanguage + Crack.lnk
          C:\Users\TONYST~1\Desktop\musique\dvd fab 5.0.8.5 platinum+crack [ita]
          C:\Users\TONYST~1\Desktop\musique\VSO Software ConvertXtoDVD 3.2.0.50 Full Multilanguage + Crack
          C:\Users\TONYST~1\Desktop\musique\VSO Software ConvertXtoDVD 3.2.0.50 Full Multilanguage + Crack.zip
          C:\Users\TONYST~1\Desktop\musique\VSO Software ConvertXtoDVD 3.2.0.50 Full Multilanguage + Crack\Data1.cab
          C:\Users\TONYST~1\Desktop\musique\VSO Software ConvertXtoDVD 3.2.0.50 Full Multilanguage + Crack\Data2.cab
          C:\Users\TONYST~1\Desktop\musique\VSO Software ConvertXtoDVD 3.2.0.50 Full Multilanguage + Crack\Data3.cab
          C:\Users\TONYST~1\Desktop\musique\VSO Software ConvertXtoDVD 3.2.0.50 Full Multilanguage + Crack\keymaker.exe
          C:\Users\TONYST~1\Desktop\musique\VSO Software ConvertXtoDVD 3.2.0.50 Full Multilanguage + Crack\Setup.exe
          C:\Users\TONYST~1\Desktop\musique\VSO Software ConvertXtoDVD 3.2.0.50 Full Multilanguage + Crack\VSO Software ConvertXtoDVD 3.2.0.50 Full Multilanguage + Crack.nfo

          [ UAC => 1 ]

          1 - "C:\ToolBar SD\TB_1.txt" - 2008-11-07|18:11 - Option : [1]
          2 - "C:\ToolBar SD\TB_2.txt" - 2008-11-07|18:32 - Option : [2]

          -----------\\ Fin du rapport a 18:32:19,07
          0
          1. Modérateur
            - Télécharge AD-Remover (de Cyrildu17 / C_XX) sur ton Bureau.

            /!\ Déconnecte-toi et ferme toutes applications en cours /!\

            - Double-clique sur le programme d'installation, installe-le dans son emplacement par défaut (C:\Program files).
            - Clique droit sur l'icône Ad-remover située sur ton Bureau et choisis Exécuter en tant qu'administrateur.
            - Au menu principal, choisis l'option "A".
            - Poste le rapport qui apparaît à la fin.

            (Le rapport est sauvegardé aussi sous C:\Ad-report(date).log)

            (CTRL+A pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)

            Note :

            "Process.exe", une composante de l'outil, est détectée par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
            Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
            Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
            0
            1. F --------- Logfile of AD-Remover 1.0.2.9 by C_XX ---------

              START at: 18:41:24 | 2008-11-07
              ON: Microsoft Windows [version 6.0.6000] ( Windows Vista )
              OPTION: Scan
              EXECUTED FROM: C:\Program Files\Ad-remover\AD-Remover.bat
              USER: Tony Stewart 20 | PC: PC-DE-TONYSTEWA
              BOOT MODE: Normal
              /!\ UAC is enable
              DRIVE(S): C:\ D:\ E:\ F:\ G:\ H:\ I:\ (Systemdrive= C:\)

              --------- [ PROCESSES ] ---------

              C:\Windows\system32\csrss.exe
              C:\Windows\system32\wininit.exe
              C:\Windows\system32\csrss.exe
              C:\Windows\system32\services.exe
              C:\Windows\system32\lsass.exe
              C:\Windows\system32\lsm.exe
              C:\Windows\system32\winlogon.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\System32\svchost.exe
              c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\SLsvc.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\spoolsv.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
              C:\Windows\system32\Dwm.exe
              C:\Windows\system32\taskeng.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\Explorer.EXE
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
              c:\Program Files\Common Files\LightScribe\LSSrvc.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\SearchIndexer.exe
              C:\Windows\system32\DRIVERS\xaudio.exe
              C:\Windows\system32\WUDFHost.exe
              C:\Windows\system32\taskeng.exe
              C:\Program Files\Windows Defender\MSASCui.exe
              C:\hp\support\hpsysdrv.exe
              C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
              C:\Windows\RtHDVCpl.exe
              C:\Windows\System32\jureg.exe
              C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
              C:\Windows\system32\schtasks.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
              C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
              C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
              C:\Windows\System32\LVCOMSX.EXE
              C:\Windows\System32\hkcmd.exe
              C:\Windows\System32\igfxpers.exe
              C:\Windows\system32\igfxsrvc.exe
              C:\Program Files\Winamp\winampa.exe
              C:\Program Files\Windows Sidebar\sidebar.exe
              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
              C:\Windows\ehome\ehtray.exe
              C:\Program Files\Windows Media Player\wmpnscfg.exe
              C:\Program Files\Windows Media Player\wmpnetwk.exe
              C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
              C:\Windows\ehome\ehmsas.exe
              C:\Windows\System32\mobsync.exe
              c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
              C:\Program Files\Windows Live\Messenger\usnsvc.exe
              C:\Windows\system32\wuauclt.exe
              C:\Windows\system32\conime.exe
              C:\Windows\system32\SearchProtocolHost.exe
              C:\Windows\system32\SearchFilterHost.exe
              C:\Windows\System32\cmd.exe
              C:\Windows\System32\WScript.exe
              C:\Windows\system32\wbem\wmiprvse.exe

              ---------------------------- [ 64 ]

              +---------------------------------------------------------------------------+
              +------------------------------- SERVICES FOUND
              +---------------------------------------------------------------------------+

              +---------------------------------------------------------------------------+
              +------------------------------- REGISTRY ELEMENTS FOUND
              +---------------------------------------------------------------------------+

              "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481}"
              "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EoWiki_is1"
              "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612}"
              "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\428C9AFC877ABE7409DCBBD48BC23F84"
              "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /v "{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}"
              "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MyWayToolBar.NetscapeStartup"
              "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{06ADA938-0FB0-4BC0-B19B-0A38AB17F182}"
              "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}"
              "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\MyWebSearchService"
              "HKEY_CURRENT_USER\SOFTWARE\FunWebProducts"
              "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser" /v "{07b18ea9-a523-4961-b6bb-170de4475cca}"
              "HKEY_CLASSES_ROOT\Toolbar3.SWEETIE"
              "HKEY_CLASSES_ROOT\MyWebSearch.HTMLPanel"
              "HKEY_CLASSES_ROOT\CLSID\{37b85a21-692b-4205-9cad-2626e4993404}"

              +---------------------------------------------------------------------------+
              +------------------------------- FILES\FOLDERS FOUND
              +---------------------------------------------------------------------------+

              [2008-10-24 02:07|--a------] C:\Windows\PFRO.log
              [2008-11-07 18:31|d--------] C:\Program Files\MyWebSearch
              [2007-04-24 12:11|--a------] C:\Windows\Downloaded Program Files\f3initialsetup1.0.1.0.inf
              [2008-02-06 17:48|d--------] C:\Users\Tony Stewart 20\AppData\LocalLow\MyWebSearch
              [2008-02-06 17:48|d--------] C:\Users\Tony Stewart 20\AppData\LocalLow\FunWebProducts

              +---------- Temp files found.. ( Elements found aren't necessarily harmful )

              [2008-11-07 00:00|d--------] C:\Users\TONYST~1\AppData\Local\Temp\sv95c.tmp
              [2008-11-06 23:59|--a------] C:\Users\TONYST~1\AppData\Local\Temp\Tony Stewart 20.bmp
              [2008-11-06 23:59|d--------] C:\Users\TONYST~1\AppData\Local\Temp\WPDNSE
              [2008-11-06 23:59|--a------] C:\Windows\temp\coinlog.log
              [2008-11-07 00:13|--a------] C:\Windows\temp\lpksetup-20081107-001249-0.log
              [2008-11-07 00:13|--a------] C:\Windows\temp\lpksetup-20081107-001306-0.log
              [2008-11-07 17:18|--a------] C:\Windows\temp\MpSigStub.log

              +---------- Added scan ...

              +-----[HKLM\...\Run]

              Windows Defender REG_EXPAND_SZ %ProgramFiles%\Windows Defender\MSASCui.exe -hide
              hpsysdrv REG_SZ c:\hp\support\hpsysdrv.exe
              OsdMaestro REG_SZ "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
              RtHDVCpl REG_SZ RtHDVCpl.exe
              HP Health Check Scheduler REG_SZ c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
              Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
              HP Software Update REG_SZ c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
              (par d‚faut) REG_SZ
              avgnt REG_SZ "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
              LVCOMSX REG_SZ C:\Windows\system32\LVCOMSX.EXE
              IgfxTray REG_SZ C:\Windows\system32\igfxtray.exe
              HotKeysCmds REG_SZ C:\Windows\system32\hkcmd.exe
              Persistence REG_SZ C:\Windows\system32\igfxpers.exe
              WinampAgent REG_SZ "C:\Program Files\Winamp\winampa.exe"
              yrtb5246 REG_SZ C:\Windows\yrtb5246.exe

              +-----[HKCU\...\Run]

              Sidebar REG_SZ C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
              MsnMsgr REG_SZ "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
              ehTray.exe REG_SZ C:\Windows\ehome\ehTray.exe
              WMPNSCFG REG_SZ C:\Program Files\Windows Media Player\WMPNSCFG.exe
              AdobeUpdater REG_SZ C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe

              +-----[HKLM\...\Internet Explorer\MAIN]

              Start Page : hxxp://www.msn.com/

              +-----[HKCU\...\Internet Explorer\MAIN]

              Start Page : hxxp://www.rds.ca/

              +---------------------------------------------------------------------------+
              +------------------------------- [ EOF - 143 lines ]
              +---------------------------------------------------------------------------+

              [ END at: 18:41:39 | 2008-11-07 ] - [ Time elapsed: 15.2 seconds ]
              0
          2. Modérateur
            /!\ Déconnecte-toi et ferme toutes applications en cours /!\

            - Clique droit sur AD-Remover et choisis Exécuter en tant qu'administrateur : au menu principal choisi l'option "B".

            --> Le programme va travailler...

            - Poste le rapport qui apparaît à la fin.

            (Le rapport est sauvegardé aussi sous C:\Ad-report.log)

            /!\ Si le Bureau ne réapparaît pas, presse Ctrl + Alt + Suppr, Onglet "Fichier", "Nouvelle tâche", tape explorer.exe et valide) /!\
            0
            1. Je dois te quitter pour l'instant, je reviens plus tard. Merci beaucoup encore une fois.

              F --------- Logfile of AD-Remover 1.0.2.9 by C_XX ---------

              START at: 18:58:48 | 2008-11-07
              ON: Microsoft Windows [version 6.0.6000] ( Windows Vista )
              OPTION: Clean
              EXECUTED FROM: C:\Program Files\Ad-remover\AD-Remover.bat
              USER: Tony Stewart 20 | PC: PC-DE-TONYSTEWA
              BOOT MODE: Normal
              /!\ UAC is enable
              DRIVE(S): C:\ D:\ E:\ F:\ G:\ H:\ I:\ (Systemdrive= C:\)

              --------- [ PROCESSES ] ---------

              C:\Windows\system32\csrss.exe
              C:\Windows\system32\wininit.exe
              C:\Windows\system32\csrss.exe
              C:\Windows\system32\services.exe
              C:\Windows\system32\lsass.exe
              C:\Windows\system32\lsm.exe
              C:\Windows\system32\winlogon.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\System32\svchost.exe
              c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\SLsvc.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\spoolsv.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
              C:\Windows\system32\Dwm.exe
              C:\Windows\system32\taskeng.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
              c:\Program Files\Common Files\LightScribe\LSSrvc.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\SearchIndexer.exe
              C:\Windows\system32\DRIVERS\xaudio.exe
              C:\Windows\system32\WUDFHost.exe
              C:\Windows\system32\taskeng.exe
              C:\Program Files\Windows Defender\MSASCui.exe
              C:\hp\support\hpsysdrv.exe
              C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
              C:\Windows\RtHDVCpl.exe
              C:\Windows\System32\jureg.exe
              C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
              C:\Windows\system32\schtasks.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
              C:\Windows\System32\LVCOMSX.EXE
              C:\Windows\System32\hkcmd.exe
              C:\Windows\System32\igfxpers.exe
              C:\Windows\system32\igfxsrvc.exe
              C:\Program Files\Winamp\winampa.exe
              C:\Program Files\Windows Sidebar\sidebar.exe
              C:\Windows\ehome\ehtray.exe
              C:\Program Files\Windows Media Player\wmpnscfg.exe
              C:\Program Files\Windows Media Player\wmpnetwk.exe
              C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
              C:\Windows\ehome\ehmsas.exe
              C:\Windows\System32\mobsync.exe
              c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
              C:\Program Files\Windows Live\Messenger\usnsvc.exe
              C:\Windows\system32\wuauclt.exe
              C:\Windows\system32\conime.exe
              C:\Windows\system32\SearchProtocolHost.exe
              C:\Windows\system32\SearchFilterHost.exe
              C:\Windows\System32\cmd.exe
              C:\Windows\System32\WScript.exe
              C:\Windows\system32\wbem\wmiprvse.exe

              ---------------------------- [ 60 ]

              +---------------------------------------------------------------------------+
              +------------------------------- SERVICES DELETED
              +---------------------------------------------------------------------------+

              +---------------------------------------------------------------------------+
              +------------------------------- REGISTRY ELEMENTS DELETED
              +---------------------------------------------------------------------------+

              "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss"
              /!\ -"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612}"
              /!\ -"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /v "{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}"
              /!\ -"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\MyWebSearchService"
              /!\ -"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612}"
              "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA}"
              /!\ -"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612}"
              "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F327D0C73C0973644A21E8CC852267A0"
              /!\ -"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /v "{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}"
              "HKEY_LOCAL_MACHINE\Software\Classes\boontybox"
              "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A}"
              /!\ -"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\MyWebSearchService"
              "HKEY_CURRENT_USER\SOFTWARE\FunWebProducts"
              "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser" /v "{07b18ea9-a523-4961-b6bb-170de4475cca}"
              "HKEY_CLASSES_ROOT\CLSID\{06ADA938-0FBO-4BCO-B19B-0A38AB17F182}"

              +---------------------------------------------------------------------------+
              +------------------------------- FILES\FOLDERS DELETED
              +---------------------------------------------------------------------------+

              [2008-10-24 02:07|--a------] C:\Windows\PFRO.log
              [2008-11-07 18:31|d--------] C:\Program Files\MyWebSearch
              [2007-04-24 12:11|--a------] C:\Windows\Downloaded Program Files\f3initialsetup1.0.1.0.inf
              [2008-02-06 17:48|d--------] C:\Users\Tony Stewart 20\AppData\LocalLow\MyWebSearch
              [2008-02-06 17:48|d--------] C:\Users\Tony Stewart 20\AppData\LocalLow\FunWebProducts

              +---------- Temp files deleted.. ( Elements deleted was not necessarily harmful )

              (!) ---- Recycle bin emptyed in all drives.

              [2008-11-07 00:00|d--------] C:\Users\TONYST~1\AppData\Local\Temp\sv95c.tmp
              [2008-11-07 18:55|--a------] C:\Users\TONYST~1\AppData\Local\Temp\Tony Stewart 20.bmp
              [2008-11-07 18:55|d--------] C:\Users\TONYST~1\AppData\Local\Temp\WPDNSE
              [2008-11-06 23:59|--a------] C:\Windows\temp\coinlog.log
              [2008-11-07 00:13|--a------] C:\Windows\temp\lpksetup-20081107-001249-0.log
              [2008-11-07 00:13|--a------] C:\Windows\temp\lpksetup-20081107-001306-0.log
              [2008-11-07 17:18|--a------] C:\Windows\temp\MpSigStub.log

              +---------- Added scan ...

              +-----[HKLM\...\Run]

              Windows Defender REG_EXPAND_SZ %ProgramFiles%\Windows Defender\MSASCui.exe -hide
              hpsysdrv REG_SZ c:\hp\support\hpsysdrv.exe
              OsdMaestro REG_SZ "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
              RtHDVCpl REG_SZ RtHDVCpl.exe
              HP Health Check Scheduler REG_SZ c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
              Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
              HP Software Update REG_SZ c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
              (par d‚faut) REG_SZ
              avgnt REG_SZ "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
              LVCOMSX REG_SZ C:\Windows\system32\LVCOMSX.EXE
              IgfxTray REG_SZ C:\Windows\system32\igfxtray.exe
              HotKeysCmds REG_SZ C:\Windows\system32\hkcmd.exe
              Persistence REG_SZ C:\Windows\system32\igfxpers.exe
              WinampAgent REG_SZ "C:\Program Files\Winamp\winampa.exe"
              yrtb5246 REG_SZ C:\Windows\yrtb5246.exe

              +-----[HKCU\...\Run]

              Sidebar REG_SZ C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
              MsnMsgr REG_SZ "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
              ehTray.exe REG_SZ C:\Windows\ehome\ehTray.exe
              WMPNSCFG REG_SZ C:\Program Files\Windows Media Player\WMPNSCFG.exe
              AdobeUpdater REG_SZ C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe

              +-----[HKLM\...\Internet Explorer\MAIN]

              Start Page : hxxp://fr.msn.com/

              +-----[HKCU\...\Internet Explorer\MAIN]

              Start Page : hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

              +---------------------------------------------------------------------------+
              +------------------------------- [ EOF - 143 lines ]
              +---------------------------------------------------------------------------+

              [ END at: 19:06:04 | 2008-11-07 ] - [ Time elapsed: 7 minutes, 16 seconds ]
              0
          3. Modérateur
            ---> Télécharge Malwarebytes' Anti-Malware (MBAM) sur ton Bureau.
            ---> Double-clique sur le fichier téléchargé pour lancer le processus d'installation.
            ---> Dans l'onglet Mise à jour, clique sur le bouton Recherche de mise à jour : si le pare-feu demande l'autorisation à MBAM de se connecter à Internet, accepte.
            ---> Une fois la mise à jour terminée, rends-toi dans l'onglet Recherche.
            ---> Sélectionne Exécuter un examen rapide.
            ---> Clique sur Rechercher. L'analyse démarre.

            A la fin de l'analyse, un message s'affiche :

            L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.

            ---> Clique sur OK pour poursuivre. Si MBAM n'a rien trouvé, il te le dira aussi.
            ---> Ferme tes navigateurs.
            Si des malwares ont été détectés, clique sur Afficher les résultats.
            ---> Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection, MBAM va détruire les fichiers et clés de registre infectés et en mettre une copie dans la quarantaine.
            ---> MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Copie-colle ce rapport dans ta prochaine réponse.
            0
            1. Malwarebytes' Anti-Malware 1.30
              Version de la base de données: 1375
              Windows 6.0.6000

              2008-11-08 16:46:08
              mbam-log-2008-11-08 (16-46-08).txt

              Type de recherche: Examen rapide
              Eléments examinés: 43415
              Temps écoulé: 3 minute(s), 45 second(s)

              Processus mémoire infecté(s): 0
              Module(s) mémoire infecté(s): 0
              Clé(s) du Registre infectée(s): 8
              Valeur(s) du Registre infectée(s): 0
              Elément(s) de données du Registre infecté(s): 0
              Dossier(s) infecté(s): 0
              Fichier(s) infecté(s): 0

              Processus mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Module(s) mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Clé(s) du Registre infectée(s):
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

              Valeur(s) du Registre infectée(s):
              (Aucun élément nuisible détecté)

              Elément(s) de données du Registre infecté(s):
              (Aucun élément nuisible détecté)

              Dossier(s) infecté(s):
              (Aucun élément nuisible détecté)

              Fichier(s) infecté(s):
              (Aucun élément nuisible détecté)
              0
          4. Modérateur
            ---> Relance MBAM, va dans Quarantaine et supprime tout.

            ---> Désinstalle Navilog1.

            ---> Poste un nouveau rapport HijackThis.
            0
            1. Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 17:09:16, on 2008-11-08
              Platform: Windows Vista (WinNT 6.00.1904)
              MSIE: Internet Explorer v7.00 (7.00.6000.16757)
              Boot mode: Normal

              Running processes:
              C:\Windows\system32\Dwm.exe
              C:\Windows\system32\taskeng.exe
              C:\Program Files\Windows Defender\MSASCui.exe
              C:\hp\support\hpsysdrv.exe
              C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
              C:\Windows\RtHDVCpl.exe
              C:\Windows\System32\jureg.exe
              C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
              C:\Windows\system32\schtasks.exe
              C:\Windows\System32\LVCOMSX.EXE
              C:\Windows\System32\hkcmd.exe
              C:\Windows\System32\igfxpers.exe
              C:\Windows\system32\igfxsrvc.exe
              C:\Program Files\Winamp\winampa.exe
              C:\Program Files\Windows Sidebar\sidebar.exe
              C:\Windows\ehome\ehtray.exe
              C:\Program Files\Windows Media Player\wmpnscfg.exe
              C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
              C:\Windows\ehome\ehmsas.exe
              C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
              C:\Windows\System32\mobsync.exe
              C:\Windows\system32\wuauclt.exe
              C:\Windows\system32\conime.exe
              C:\Windows\System32\rundll32.exe
              C:\Windows\explorer.exe
              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
              C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.fr.msn.ca/0SEFRCA/SAOS01
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://compaq-consumer.my.aol.qc.ca/?icid=desktop
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
              O1 - Hosts: ::1 localhost
              O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
              O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
              O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\msgr.fr.fr-ca\msntb.dll
              O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
              O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
              O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
              O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
              O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
              O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
              O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
              O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
              O4 - HKLM\..\Run: [LVCOMSX] C:\Windows\system32\LVCOMSX.EXE
              O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
              O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
              O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
              O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
              O4 - HKLM\..\Run: [yrtb5246] C:\Windows\yrtb5246.exe
              O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
              O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
              O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
              O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
              O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
              O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
              O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
              O4 - Startup: ppcbooster.lnk = C:\Program Files\ppcbooster\ppcbooster.exe
              O4 - Startup: ppcb_32.lnk = ?
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
              O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
              O13 - Gopher Prefix:
              O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
              O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
              O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
              O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
              O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
              O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
              O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
              O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
              0
            2. @GodgirlLogfile of Trend Micro HijackThis v2.0.2
              Scan saved at 15:56:55, on 2008-11-09
              Platform: Windows Vista (WinNT 6.00.1904)
              MSIE: Internet Explorer v7.00 (7.00.6000.16757)
              Boot mode: Normal

              Running processes:
              C:\Windows\system32\Dwm.exe
              C:\Windows\system32\taskeng.exe
              C:\Program Files\Windows Defender\MSASCui.exe
              C:\hp\support\hpsysdrv.exe
              C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
              C:\Windows\RtHDVCpl.exe
              C:\Windows\System32\jureg.exe
              C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
              C:\Windows\system32\schtasks.exe
              C:\Windows\System32\LVCOMSX.EXE
              C:\Windows\System32\hkcmd.exe
              C:\Windows\System32\igfxpers.exe
              C:\Windows\system32\igfxsrvc.exe
              C:\Program Files\Winamp\winampa.exe
              C:\Program Files\Windows Sidebar\sidebar.exe
              C:\Windows\ehome\ehtray.exe
              C:\Program Files\Windows Media Player\wmpnscfg.exe
              C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
              C:\Windows\ehome\ehmsas.exe
              C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
              C:\Windows\System32\mobsync.exe
              C:\Windows\system32\wuauclt.exe
              C:\Windows\system32\conime.exe
              C:\Windows\System32\rundll32.exe
              C:\Windows\explorer.exe
              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
              C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.fr.msn.ca/0SEFRCA/SAOS01
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/...
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
              O1 - Hosts: ::1 localhost
              O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
              O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
              O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\msgr.fr.fr-ca\msntb.dll
              O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
              O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
              O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
              O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
              O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
              O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
              O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
              O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
              O4 - HKLM\..\Run: [LVCOMSX] C:\Windows\system32\LVCOMSX.EXE
              O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
              O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
              O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
              O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
              O4 - HKLM\..\Run: [yrtb5246] C:\Windows\yrtb5246.exe
              O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
              O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
              O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
              O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
              O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
              O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
              O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
              O4 - Startup: ppcbooster.lnk = C:\Program Files\ppcbooster\ppcbooster.exe
              O4 - Startup: ppcb_32.lnk = ?
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
              O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
              O13 - Gopher Prefix:
              O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
              O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
              O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
              O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
              O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
              O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
              O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
              O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
              0
          5. Modérateur
            Pour utiliser HijackThis sous Vista, il faut l'exécuter en tant qu'administrateur (Clic droit sur le raccourci puis choisis Exécuter en tant qu'administrateur).

            Puis poste un nouveau rapport HijackThis.
            0
            1. Modérateur
              - Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.

              - Double-clique sur RSIT.exe afin de lancer le programme.

              - Clique sur Continue à l'écran Disclaimer.

              - Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

              - Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).

              Note : Les rapports sont sauvegardés dans le dossier C:\rsit.
              0
              1. Logfile of random's system information tool 1.04 (written by random/random)
                Run by Tony Stewart 20 at 2008-11-10 18:27:07
                Microsoft® Windows Vista™ Édition Familiale Premium
                System drive C: has 233 GB (78%) free of 298 GB
                Total RAM: 1015 MB (39% free)

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 18:27:14, on 2008-11-10
                Platform: Windows Vista (WinNT 6.00.1904)
                MSIE: Internet Explorer v7.00 (7.00.6000.16757)
                Boot mode: Normal

                Running processes:
                C:\Windows\system32\Dwm.exe
                C:\Windows\system32\taskeng.exe
                C:\Program Files\Windows Defender\MSASCui.exe
                C:\hp\support\hpsysdrv.exe
                C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
                C:\Windows\RtHDVCpl.exe
                C:\Windows\System32\jureg.exe
                C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                C:\Windows\system32\schtasks.exe
                C:\Windows\System32\LVCOMSX.EXE
                C:\Windows\System32\hkcmd.exe
                C:\Windows\System32\igfxpers.exe
                C:\Windows\system32\igfxsrvc.exe
                C:\Program Files\Winamp\winampa.exe
                C:\Program Files\Windows Sidebar\sidebar.exe
                C:\Windows\ehome\ehtray.exe
                C:\Program Files\Windows Media Player\wmpnscfg.exe
                C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
                C:\Windows\ehome\ehmsas.exe
                C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
                C:\Windows\System32\mobsync.exe
                C:\Windows\system32\wuauclt.exe
                C:\Windows\system32\conime.exe
                C:\Windows\System32\rundll32.exe
                C:\Windows\explorer.exe
                C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                C:\Windows\system32\jusched.exe
                C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                C:\Windows\system32\SearchFilterHost.exe
                C:\Users\Tony Stewart 20\Desktop\RSIT.exe
                C:\Program Files\Trend Micro\HijackThis\Tony Stewart 20.exe

                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.fr.msn.ca/0SEFRCA/SAOS01
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://compaq-consumer.my.aol.qc.ca/?icid=desktop
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                O1 - Hosts: ::1 localhost
                O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
                O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\msgr.fr.fr-ca\msntb.dll
                O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
                O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
                O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
                O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                O4 - HKLM\..\Run: [LVCOMSX] C:\Windows\system32\LVCOMSX.EXE
                O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                O4 - HKLM\..\Run: [yrtb5246] C:\Windows\yrtb5246.exe
                O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
                O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
                O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
                O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
                O4 - Startup: ppcbooster.lnk = C:\Program Files\ppcbooster\ppcbooster.exe
                O4 - Startup: ppcb_32.lnk = ?
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
                O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
                O13 - Gopher Prefix:
                O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
                O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
                O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                0
              2. ensuite?
                0
            2. Modérateur
              C'est quoi ppcbooster ?
              0
              1. Modérateur
                1/

                ---> Mets à jour Adobe Reader :
                https://get2.adobe.com/reader/otherversions/

                ---> Mets à jour Java :
                https://www.java.com/fr/download/manual.jsp

                ---> Désinstalle via Ajout/Suppression de Programmes (si présents) :
                - Ad-remover
                - Java 6 Update 4
                - Java SE Runtime Environment 6 Update 1
                - PPC Booster

                2/

                ---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :
                http://oldtimer.geekstogo.com/OTMoveIt3.exe

                ---> Double-clique sur OTMoveIt3.exe afin de le lancer.

                ---> Copie (Ctrl+C) le texte suivant ci-dessous :

                :processes
                explorer.exe

                :files
                C:\Windows\yrtb5246.exe
                C:\Windows\h288.exe
                C:\Windows\pptb1948.exe
                C:\Windows\system32\lohxvlxyfcpmkhi.exe
                C:\Windows\bdtb3452.exe

                :reg
                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                "yrtb5246"=-

                :commands
                [emptytemp]
                [start explorer]
                [reboot]

                ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

                ---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

                Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
                Accepte en cliquant sur YES.

                ---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
                Le nom du rapport correspond au moment de sa création : date_heure.log
                0
                1. ========== PROCESSES ==========
                  Process explorer.exe killed successfully.
                  ========== FILES ==========
                  File/Folder C:\Windows\yrtb5246.exe not found.
                  C:\Windows\h288.exe moved successfully.
                  C:\Windows\pptb1948.exe moved successfully.
                  C:\Windows\system32\lohxvlxyfcpmkhi.exe moved successfully.
                  C:\Windows\bdtb3452.exe moved successfully.
                  ========== REGISTRY ==========
                  Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\yrtb5246 deleted successfully.
                  ========== COMMANDS ==========
                  File delete failed. C:\Users\TONYST~1\AppData\Local\Temp\~DF3776.tmp scheduled to be deleted on reboot.
                  File delete failed. C:\Users\TONYST~1\AppData\Local\Temp\~DF377D.tmp scheduled to be deleted on reboot.
                  File delete failed. C:\Users\TONYST~1\AppData\Local\Temp\~DF5DC3.tmp scheduled to be deleted on reboot.
                  File delete failed. C:\Users\TONYST~1\AppData\Local\Temp\~DF8A63.tmp scheduled to be deleted on reboot.
                  File delete failed. C:\Users\TONYST~1\AppData\Local\Temp\~DF8A6A.tmp scheduled to be deleted on reboot.
                  User's Temp folder emptied.
                  User's Temporary Internet Files folder emptied.
                  User's Internet Explorer cache folder emptied.
                  Local Service Temp folder emptied.
                  Local Service Temporary Internet Files folder emptied.
                  Windows Temp folder emptied.
                  Temp folders emptied.
                  Explorer started successfully

                  OTMoveIt3 by OldTimer - Version 1.0.7.0 log created on 11102008_210905

                  Files moved on Reboot...
                  File C:\Users\TONYST~1\AppData\Local\Temp\~DF3776.tmp not found!
                  File C:\Users\TONYST~1\AppData\Local\Temp\~DF377D.tmp not found!
                  C:\Users\TONYST~1\AppData\Local\Temp\~DF5DC3.tmp moved successfully.
                  File C:\Users\TONYST~1\AppData\Local\Temp\~DF8A63.tmp not found!
                  File C:\Users\TONYST~1\AppData\Local\Temp\~DF8A6A.tmp not found!
                  0
              2. Modérateur
                Bien.

                ---> Fais un nouveau scan avec RSIT et poste les deux rapports.
                0
                1. Logfile of random's system information tool 1.04 (written by random/random)
                  Run by Tony Stewart 20 at 2008-11-11 18:27:29
                  Microsoft® Windows Vista™ Édition Familiale Premium
                  System drive C: has 234 GB (79%) free of 298 GB
                  Total RAM: 1015 MB (42% free)

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 18:27:38, on 2008-11-11
                  Platform: Windows Vista (WinNT 6.00.1904)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16757)
                  Boot mode: Normal

                  Running processes:
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\Explorer.EXE
                  C:\Program Files\Windows Defender\MSASCui.exe
                  C:\hp\support\hpsysdrv.exe
                  C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
                  C:\Windows\RtHDVCpl.exe
                  C:\Windows\System32\jureg.exe
                  C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                  C:\Windows\system32\schtasks.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                  C:\Windows\System32\LVCOMSX.EXE
                  C:\Windows\System32\hkcmd.exe
                  C:\Windows\System32\igfxpers.exe
                  C:\Program Files\Winamp\winampa.exe
                  C:\Program Files\Windows Sidebar\sidebar.exe
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  C:\Windows\ehome\ehtray.exe
                  C:\Program Files\Windows Media Player\wmpnscfg.exe
                  C:\Windows\system32\igfxsrvc.exe
                  C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
                  C:\Windows\ehome\ehmsas.exe
                  C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
                  C:\Windows\system32\wuauclt.exe
                  C:\Program Files\Internet Explorer\IEUser.exe
                  C:\Program Files\Winamp\winamp.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                  C:\Windows\system32\SearchFilterHost.exe
                  C:\Users\Tony Stewart 20\Desktop\RSIT.exe
                  C:\Program Files\Trend Micro\HijackThis\Tony Stewart 20.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.fr.msn.ca/0SEFRCA/SAOS01
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://compaq-consumer.my.aol.qc.ca/?icid=desktop
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                  O1 - Hosts: ::1 localhost
                  O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                  O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                  O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\msgr.fr.fr-ca\msntb.dll
                  O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                  O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
                  O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
                  O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                  O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                  O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
                  O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                  O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                  O4 - HKLM\..\Run: [LVCOMSX] C:\Windows\system32\LVCOMSX.EXE
                  O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                  O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                  O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                  O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
                  O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                  O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                  O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                  O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
                  O4 - Startup: ppcbooster.lnk = C:\Program Files\ppcbooster\ppcbooster.exe
                  O13 - Gopher Prefix:
                  O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
                  O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                  O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                  O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                  O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
                  O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                  O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                  O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                  0
                  1. Modérateur
                    Refais un scan RSIT en l'exécutant en tant qu'administrateur (Clic droit sur RSIT puis Exécuter en tant qu'administrateur).
                    0
                    1. Logfile of random's system information tool 1.04 (written by random/random)
                      Run by Tony Stewart 20 at 2008-11-13 19:46:35
                      Microsoft® Windows Vista™ Édition Familiale Premium
                      System drive C: has 234 GB (78%) free of 298 GB
                      Total RAM: 1015 MB (45% free)

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 19:46:46, on 2008-11-13
                      Platform: Windows Vista (WinNT 6.00.1904)
                      MSIE: Internet Explorer v7.00 (7.00.6000.16757)
                      Boot mode: Normal

                      Running processes:
                      C:\Windows\system32\taskeng.exe
                      C:\Windows\system32\Dwm.exe
                      C:\Windows\Explorer.EXE
                      C:\Program Files\Windows Defender\MSASCui.exe
                      C:\hp\support\hpsysdrv.exe
                      C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
                      C:\Windows\RtHDVCpl.exe
                      C:\Windows\System32\jureg.exe
                      C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                      C:\Windows\system32\schtasks.exe
                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                      C:\Windows\System32\LVCOMSX.EXE
                      C:\Windows\System32\hkcmd.exe
                      C:\Windows\System32\igfxpers.exe
                      C:\Program Files\Winamp\winampa.exe
                      C:\Windows\system32\igfxsrvc.exe
                      C:\Program Files\Windows Sidebar\sidebar.exe
                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                      C:\Windows\ehome\ehtray.exe
                      C:\Program Files\Windows Media Player\wmpnscfg.exe
                      C:\Windows\ehome\ehmsas.exe
                      C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
                      C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
                      C:\Windows\system32\wuauclt.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Program Files\Internet Explorer\IEUser.exe
                      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                      C:\Users\Tony Stewart 20\Desktop\RSIT.exe
                      C:\Program Files\Trend Micro\HijackThis\Tony Stewart 20.exe

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.fr.msn.ca/0SEFRCA/SAOS01
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://compaq-consumer.my.aol.qc.ca/?icid=desktop
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                      O1 - Hosts: ::1 localhost
                      O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                      O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\msgr.fr.fr-ca\msntb.dll
                      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                      O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
                      O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
                      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                      O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                      O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
                      O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                      O4 - HKLM\..\Run: [LVCOMSX] C:\Windows\system32\LVCOMSX.EXE
                      O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                      O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                      O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                      O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                      O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
                      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                      O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
                      O4 - Startup: ppcbooster.lnk = C:\Program Files\ppcbooster\ppcbooster.exe
                      O13 - Gopher Prefix:
                      O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
                      O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                      O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                      O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                      O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
                      O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                      O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                      O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                      0
                  2. Modérateur
                    Ça ne va pas.

                    ---> Supprime le dossier RSIT situé dans C:\

                    ---> Lance RSIT en administrateur et poste les deux rapports.
                    0
                    1. Logfile of random's system information tool 1.04 (written by random/random)
                      Run by Tony Stewart 20 at 2008-11-15 14:27:27
                      Microsoft® Windows Vista™ Édition Familiale Premium
                      System drive C: has 233 GB (78%) free of 298 GB
                      Total RAM: 1015 MB (42% free)

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 14:27:36, on 2008-11-15
                      Platform: Windows Vista (WinNT 6.00.1904)
                      MSIE: Internet Explorer v7.00 (7.00.6000.16757)
                      Boot mode: Normal

                      Running processes:
                      C:\Windows\system32\taskeng.exe
                      C:\Windows\system32\Dwm.exe
                      C:\Windows\Explorer.EXE
                      C:\Program Files\Windows Defender\MSASCui.exe
                      C:\hp\support\hpsysdrv.exe
                      C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
                      C:\Windows\RtHDVCpl.exe
                      C:\Windows\System32\jureg.exe
                      C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                      C:\Windows\system32\schtasks.exe
                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                      C:\Windows\System32\LVCOMSX.EXE
                      C:\Windows\System32\hkcmd.exe
                      C:\Windows\System32\igfxpers.exe
                      C:\Program Files\Winamp\winampa.exe
                      C:\Windows\system32\igfxsrvc.exe
                      C:\Program Files\Windows Sidebar\sidebar.exe
                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                      C:\Windows\ehome\ehtray.exe
                      C:\Program Files\Windows Media Player\wmpnscfg.exe
                      C:\Windows\ehome\ehmsas.exe
                      C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
                      C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
                      C:\Windows\system32\wuauclt.exe
                      C:\Windows\System32\mobsync.exe
                      C:\Windows\system32\taskeng.exe
                      C:\Program Files\Internet Explorer\IEUser.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                      C:\Users\Tony Stewart 20\Desktop\RSIT.exe
                      C:\Program Files\Trend Micro\HijackThis\Tony Stewart 20.exe

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.fr.msn.ca/0SEFRCA/SAOS01
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://compaq-consumer.my.aol.qc.ca/?icid=desktop
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                      O1 - Hosts: ::1 localhost
                      O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                      O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\msgr.fr.fr-ca\msntb.dll
                      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                      O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
                      O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
                      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                      O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                      O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
                      O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                      O4 - HKLM\..\Run: [LVCOMSX] C:\Windows\system32\LVCOMSX.EXE
                      O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                      O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                      O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                      O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                      O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
                      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                      O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
                      O4 - Startup: ppcbooster.lnk = C:\Program Files\ppcbooster\ppcbooster.exe
                      O13 - Gopher Prefix:
                      O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
                      O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                      O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                      O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                      O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
                      O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                      O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                      O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                      0
                    2. Logfile of random's system information tool 1.04 (written by random/random)
                      Run by Tony Stewart 20 at 2008-11-19 18:35:57
                      Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
                      System drive C: has 268 GB (90%) free of 298 GB
                      Total RAM: 1015 MB (38% free)

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 18:36:06, on 2008-11-19
                      Platform: Windows Vista SP1 (WinNT 6.00.1905)
                      MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                      Boot mode: Normal

                      Running processes:
                      C:\Windows\system32\taskeng.exe
                      C:\Windows\system32\Dwm.exe
                      C:\Windows\Explorer.EXE
                      C:\hp\support\hpsysdrv.exe
                      C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
                      C:\Windows\RtHDVCpl.exe
                      C:\Windows\System32\jureg.exe
                      C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                      C:\Windows\system32\schtasks.exe
                      C:\Windows\System32\LVCOMSX.EXE
                      C:\Windows\System32\hkcmd.exe
                      C:\Windows\system32\igfxsrvc.exe
                      C:\Windows\System32\igfxpers.exe
                      C:\Program Files\Winamp\winampa.exe
                      C:\Windows\ehome\ehtray.exe
                      C:\Program Files\Windows Defender\MSASCui.exe
                      C:\Program Files\Windows Media Player\wmpnscfg.exe
                      C:\Program Files\Windows Sidebar\sidebar.exe
                      C:\Windows\ehome\ehmsas.exe
                      C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
                      C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
                      C:\Windows\System32\wsqmcons.exe
                      C:\Windows\system32\jusched.exe
                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                      C:\Windows\system32\wuauclt.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Program Files\Internet Explorer\IEUser.exe
                      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                      C:\Users\Tony Stewart 20\Desktop\RSIT.exe
                      C:\Program Files\Trend Micro\HijackThis\Tony Stewart 20.exe

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.fr.msn.ca/0SEFRCA/SAOS01
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://compaq-consumer.my.aol.qc.ca/?icid=desktop
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                      O1 - Hosts: ::1 localhost
                      O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                      O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\msgr.fr.fr-ca\msntb.dll
                      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                      O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
                      O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
                      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                      O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                      O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
                      O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                      O4 - HKLM\..\Run: [LVCOMSX] C:\Windows\system32\LVCOMSX.EXE
                      O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                      O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                      O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                      O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                      O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
                      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                      O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
                      O4 - Startup: ppcbooster.lnk = C:\Program Files\ppcbooster\ppcbooster.exe
                      O13 - Gopher Prefix:
                      O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
                      O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                      O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                      O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                      O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
                      O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                      O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                      O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                      0
                    3. @godgirl-------------------------------------------------------------------------------
                      KASPERSKY ON-LINE SCANNER REPORT
                      Friday, November 28, 2008 5:15:16 PM
                      Système d'exploitation : Home Edition, Service Pack 1 (Build 6001)
                      Kaspersky On-line Scanner version : 5.0.84.2
                      Dernière mise à jour de la base antivirus Kaspersky : 27/11/2008
                      Enregistrements dans la base antivirus Kaspersky : 1274923
                      -------------------------------------------------------------------------------

                      Paramètres d'analyse:
                      Analyser avec la base antivirus suivante: standard
                      Analyser les archives: vrai
                      Analyser les bases de messagerie: vrai

                      Cible de l'analyse - Poste de travail:
                      C:\
                      D:\
                      E:\
                      F:\
                      G:\
                      H:\
                      I:\

                      Statistiques de l'analyse:
                      Total d'objets analysés: 106584
                      Nombre de virus trouvés: 1
                      Nombre d'objets infectés: 3 / 0
                      Nombre d'objets suspects: 0
                      Durée de l'analyse: 02:21:29

                      Nom de l'objet infecté / Nom du virus / Dernière action
                      C:\Boot\BCD L'objet est verrouillé ignoré
                      C:\Boot\BCD.LOG L'objet est verrouillé ignoré
                      C:\Program Files\PC-Doctor 5 for Windows\Configuration\config.xml L'objet est verrouillé ignoré
                      C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a986b13b5edd27cdfb7c5a7ac87cc9fb_32f359ce-51be-4388-9665-1af5e5408317 L'objet est verrouillé ignoré
                      C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\a986b13b5edd27cdfb7c5a7ac87cc9fb_32f359ce-51be-4388-9665-1af5e5408317 L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\AppData\Local\Microsoft\Messenger\ma_kiki_@hotmail.com\SharingMetadata\Logs\Dfsr00005.log L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\AppData\Local\Microsoft\Messenger\ma_kiki_@hotmail.com\SharingMetadata\pending.dat L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\AppData\Local\Microsoft\Messenger\ma_kiki_@hotmail.com\SharingMetadata\Working\database_468E_7774_8E77_5AFF\dfsr.db L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\AppData\Local\Microsoft\Messenger\ma_kiki_@hotmail.com\SharingMetadata\Working\database_468E_7774_8E77_5AFF\fsr.log L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\AppData\Local\Microsoft\Messenger\ma_kiki_@hotmail.com\SharingMetadata\Working\database_468E_7774_8E77_5AFF\fsrtmp.log L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\AppData\Local\Microsoft\Messenger\ma_kiki_@hotmail.com\SharingMetadata\Working\database_468E_7774_8E77_5AFF\tmp.edb L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B83JZFDD\11409811-1[1].on2 L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\AppData\Local\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\AppData\Local\Microsoft\Windows\UsrClass.dat{a136f1d2-c654-11dc-9ca2-001d60c17422}.TM.blf L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\AppData\Local\Microsoft\Windows\UsrClass.dat{a136f1d2-c654-11dc-9ca2-001d60c17422}.TMContainer00000000000000000001.regtrans-ms L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\AppData\Local\Microsoft\Windows\UsrClass.dat{a136f1d2-c654-11dc-9ca2-001d60c17422}.TMContainer00000000000000000002.regtrans-ms L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\AppData\Local\Microsoft\Windows\WindowsUpdate.log L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\AppData\Local\Microsoft\Windows Defender\FileTracker\{FC530C74-0E6D-4EFD-ACC3-4FE6FD172B0D} L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\AppData\Local\Microsoft\Windows Live Contacts\ma_kiki_@hotmail.com\real\members.stg L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\AppData\Local\Microsoft\Windows Sidebar\Settings.ini L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\AppData\Local\Temp\fla9E67.tmp L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\AppData\Local\Temp\hsperfdata_Tony Stewart 20\38116 L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\AppData\Local\Temp\~DF7227.tmp L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\AppData\Local\Temp\~DF744B.tmp L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\AppData\Local\Temp\~DFEDDC.tmp L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\AppData\Roaming\Microsoft\Windows\Cookies\index.dat L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\AppData\Roaming\OpenOffice.org2\user\uno_packages\cache\log.txt L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\AppData\Roaming\OpenOffice.org2\user\uno_packages\cache\registry\com.sun.star.comp.deployment.component.PackageRegistryBackend\common.rdb L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\AppData\Roaming\OpenOffice.org2\user\uno_packages\cache\registry\com.sun.star.comp.deployment.component.PackageRegistryBackend\Windows_x86.rdb L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\AppData\Roaming\OpenOffice.org2\user\uno_packages\cache\registry\com.sun.star.comp.deployment.configuration.PackageRegistryBackend\registered_packages.db L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\AppData\Roaming\OpenOffice.org2\user\uno_packages\cache\uno_packages.db L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\Desktop\musique\VSO Software ConvertXtoDVD 3.2.0.50 Full Multilanguage + Crack.zip/keymaker.exe Infecté : Trojan-Dropper.Win32.VB.grk ignoré
                      C:\Users\Tony Stewart 20\Desktop\musique\VSO Software ConvertXtoDVD 3.2.0.50 Full Multilanguage + Crack.zip/Setup.exe Infecté : Trojan-Dropper.Win32.VB.grk ignoré
                      C:\Users\Tony Stewart 20\Desktop\musique\VSO Software ConvertXtoDVD 3.2.0.50 Full Multilanguage + Crack.zip ZIP: infecté - 2 ignoré
                      C:\Users\Tony Stewart 20\NTUSER.DAT L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\ntuser.dat.LOG1 L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\ntuser.dat.LOG2 L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms L'objet est verrouillé ignoré
                      C:\Users\Tony Stewart 20\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms L'objet est verrouillé ignoré
                      C:\Windows\Debug\PASSWD.LOG L'objet est verrouillé ignoré
                      C:\Windows\Debug\WIA\wiatrace.log L'objet est verrouillé ignoré
                      C:\Windows\Logs\CBS\CBS.log L'objet est verrouillé ignoré
                      C:\Windows\Logs\CBS\CBS.persist.log L'objet est verrouillé ignoré
                      C:\Windows\Logs\DPX\setupact.log L'objet est verrouillé ignoré
                      C:\Windows\Logs\DPX\setuperr.log L'objet est verrouillé ignoré
                      C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe.config L'objet est verrouillé ignoré
                      C:\Windows\Panther\UnattendGC\diagerr.xml L'objet est verrouillé ignoré
                      C:\Windows\Panther\UnattendGC\diagwrn.xml L'objet est verrouillé ignoré
                      C:\Windows\Panther\UnattendGC\setupact.log L'objet est verrouillé ignoré
                      C:\Windows\Panther\UnattendGC\setuperr.log L'objet est verrouillé ignoré
                      C:\Windows\security\database\secedit.sdb L'objet est verrouillé ignoré
                      C:\Windows\SoftwareDistribution\ReportingEvents.log L'objet est verrouillé ignoré
                      C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 L'objet est verrouillé ignoré
                      C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 L'objet est verrouillé ignoré
                      C:\Windows\System32\catroot2\edb.log L'objet est verrouillé ignoré
                      C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb L'objet est verrouillé ignoré
                      C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb L'objet est verrouillé ignoré
                      C:\Windows\System32\LogFiles\Scm\SCM.EVM L'objet est verrouillé ignoré
                      C:\Windows\System32\LogFiles\WUDF\WUDFTrace.etl L'objet est verrouillé ignoré
                      C:\Windows\System32\restore\MachineGuid.txt L'objet est verrouillé ignoré
                      C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT L'objet est verrouillé ignoré
                      C:\Windows\System32\SMI\Store\Machine\schema.dat.LOG1 L'objet est verrouillé ignoré
                      C:\Windows\System32\SMI\Store\Machine\schema.dat.LOG2 L'objet est verrouillé ignoré
                      C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT{3a53986c-6a70-11db-887c-d362bd253390}.TxR.0.regtrans-ms L'objet est verrouillé ignoré
                      C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT{3a53986c-6a70-11db-887c-d362bd253390}.TxR.1.regtrans-ms L'objet est verrouillé ignoré
                      C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT{3a53986c-6a70-11db-887c-d362bd253390}.TxR.2.regtrans-ms L'objet est verrouillé ignoré
                      C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT{3a53986c-6a70-11db-887c-d362bd253390}.TxR.blf L'objet est verrouillé ignoré
                      C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT{3a53986d-6a70-11db-887c-d362bd253390}.TM.blf L'objet est verrouillé ignoré
                      C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT{3a53986d-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms L'objet est verrouillé ignoré
                      C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT{3a53986d-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms L'objet est verrouillé ignoré
                      C:\Windows\System32\spool\SpoolerETW.etl L'objet est verrouillé ignoré
                      C:\Windows\System32\sysprep\Panther\diagerr.xml L'objet est verrouillé ignoré
                      C:\Windows\System32\sysprep\Panther\diagwrn.xml L'objet est verrouillé ignoré
                      C:\Windows\System32\sysprep\Panther\setupact.log L'objet est verrouillé ignoré
                      C:\Windows\System32\sysprep\Panther\setuperr.log L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\0296C47314AB746EC35476488248FCD9.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\040270F850D5C3C91057DDDA2DA294D8.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\0A9DBC92D554324656F61F9862679F27.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\0DF617D6737A7561E732F853792261C3.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\1641F982282E8CA70B0D93F1F2BB145B.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\2131A60D40501A974386B9E42E4FC201.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\26C097A9392F8C541AD42E89B7909073.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\2A811E5CCC22CC9D7AE2B04EF0402688.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\2AA23BB86A5EBD8BC2D820944E55B233.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\2D57A7682ACD19214C258D31A06D008F.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\3460B7617E0429A960E481B197F238A3.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\39C2F82384C755EF218F0F19FE619F80.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\3DC0BABDCA20E5E319117C21BD4BD795.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\494C62FAA08CD5217399BAA555FF491B.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\4A01E0F376B5833EBA98F0D1D5F60CD1.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\4B471F64BAF831EC7945C820FD5A16E5.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\4BE9D6CB921FE137B78AE9960CDD98B0.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\5679DFE988DE44D70C43B0E87A5D96E6.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\5774C77265BE4C55B5C6C9718979E015.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\5966D45C7B25EACA46E87DD8E5703964.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\5F037A89915D44B8819F9FCFDE0B489E.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\6364E8D3F688917ECAE1050954B63674.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\66B28EEE188E29399051A60BAF92D333.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\69554D930FCA40B0304B9A43A8036F2D.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\6DADEFFF2FCEDD93F8CEF59036FEF4B9.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\72F867EF62976CE9F70993FF3E68A4EB.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\75054C3771DF289038069A9BB1C1FB6E.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\7851AF96EA828F912853F32DB0D96138.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\7F417E1A6D819A9B2FEB55DA6858EA0A.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\7FAC187A43CA71A854CA4653D8E075B5.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\818B866A009B1338C5AC103B2D8E2372.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\903E49C444C46FEF5F2C3A189C9CEF71.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\9A72EE7775E8021F75961342B8AFD1B4.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\9AD3182A2F39A3E091E15109132EC6CC.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\9E06E4FE97F0CBB8D659894823F805D7.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\A80FF2DC09487ECD60AFB147B262BDD7.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\AA6E0E396C238977CA909EFD82299737.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\BBF206490BAA431B592F9A13534F43F6.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\BD818313E410FD46A9F63786A32AEE23.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\BE81B2C0741907C1FC1C42B6223E59AD.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\D566F9B651B60AE7D0B5DEBF57A90E35.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\DE391013DA56ABA39FFF40A9ABDF052F.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\DF80FD3849FFF74B4BF43E2EA8ADEC8A.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\DFB9AD54AC2D3B8122567AAD3BF3EB7F.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\E04DE4CDFEC284A342159BB920976701.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\E737DE61441445E1FDFCA45EF5E7D987.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\E9D8A460B2C986DD5FF19F299F4A27EC.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\EC45C70F2A3D9DED718E71631C38E2FE.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\F01326692CC5736EBAC31B9FC2381CF2.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\AutoRecover\F81E6BEBC3067C406E6C491608474198.mof L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\Logs\WMITracing.log L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\Repository\INDEX.BTR L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\Repository\MAPPING1.MAP L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\Repository\MAPPING2.MAP L'objet est verrouillé ignoré
                      C:\Windows\System32\wbem\Repository\OBJECTS.DATA L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Application.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\DFS Replication.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\HardwareEvents.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Internet Explorer.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Key Management Service.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Media Center.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-CorruptedFileRecovery-Client%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-CorruptedFileRecovery-Server%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-DateTimeControlPanel%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-PLA%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Networking%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-DiskDiagnostic%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-DiskDiagnosticDataCollector%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-DiskDiagnosticResolver%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-DriverFrameworks-UserMode%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-Forwarding%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-Help%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-International%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WDI%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-LanguagePackSetup%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-MUI%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-ParentalControls%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Metrics.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-RemoteAssistance%4Admin.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-RemoteAssistance%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Resolver%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Leak-Diagnostic%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-RestartManager%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-TaskScheduler%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-TerminalServices-RDPClient%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-UAC%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-UAC-FileVirtualization%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-WindowsUpdateClient%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-Winlogon%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-Wired-AutoConfig%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Microsoft-Windows-WLAN-AutoConfig%4Operational.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Security.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\Setup.evtx L'objet est verrouillé ignoré
                      C:\Windows\System32\winevt\Logs\System.evtx L'objet est verrouillé ignoré
                      C:\Windows\Tasks\SCHEDLGU.TXT L'objet est verrouillé ignoré
                      C:\Windows\Temp\fwtsqmfile00.sqm L'objet est verrouillé ignoré
                      C:\Windows\Temp\fwtsqmfile01.sqm L'objet est verrouillé ignoré
                      C:\Windows\Temp\fwtsqmfile02.sqm L'objet est verrouillé ignoré
                      C:\Windows\Temp\fwtsqmfile03.sqm L'objet est verrouillé ignoré
                      C:\Windows\Temp\fwtsqmfile04.sqm L'objet est verrouillé ignoré
                      C:\Windows\Temp\fwtsqmfile05.sqm L'objet est verrouillé ignoré
                      C:\Windows\Temp\fwtsqmfile06.sqm L'objet est verrouillé ignoré
                      C:\Windows\Temp\fwtsqmfile07.sqm L'objet est verrouillé ignoré
                      C:\Windows\Temp\fwtsqmfile08.sqm L'objet est verrouillé ignoré
                      C:\Windows\Temp\fwtsqmfile09.sqm L'objet est verrouillé ignoré
                      C:\Windows\Temp\fwtsqmfile10.sqm L'objet est verrouillé ignoré
                      C:\Windows\Temp\fwtsqmfile11.sqm L'objet est verrouillé ignoré
                      C:\Windows\Temp\fwtsqmfile12.sqm L'objet est verrouillé ignoré
                      C:\Windows\Temp\fwtsqmfile13.sqm L'objet est verrouillé ignoré
                      C:\Windows\Temp\fwtsqmfile14.sqm L'objet est verrouillé ignoré
                      C:\Windows\Temp\fwtsqmfile15.sqm L'objet est verrouillé ignoré
                      C:\Windows\Temp\fwtsqmfile16.sqm L'objet est verrouillé ignoré
                      C:\Windows\Temp\fwtsqmfile17.sqm L'objet est verrouillé ignoré
                      C:\Windows\Temp\fwtsqmfile18.sqm L'objet est verrouillé ignoré
                      C:\Windows\Temp\fwtsqmfile19.sqm L'objet est verrouillé ignoré
                      C:\Windows\Temp\VistaSP1_InstallPerf_142855.sqm L'objet est verrouillé ignoré
                      C:\Windows\WindowsUpdate.log L'objet est verrouillé ignoré
                      C:\Windows\winsxs\x86_microsoft-windows-n..n_service_datastore_31bf3856ad364e35_6.0.6000.16386_none_cef7ceb03914a67f\dnary.xsd L'objet est verrouillé ignoré
                      C:\Windows\winsxs\x86_microsoft-windows-n..n_service_datastore_31bf3856ad364e35_6.0.6001.18000_none_d12e90ac35ffb753\dnary.xsd L'objet est verrouillé ignoré

                      Analyse terminée.
                      0
                  3. Modérateur
                    ---> Supprime ToolBar S&D et le dossier ToolBar SD situé dans C:\

                    ---> Supprime OTMoveIt3 et le dossier _OTMoveIt situé dans C:\

                    ---> Désinstalle AD-Remover.

                    ---> Mets à jour Adobe Reader :
                    https://get2.adobe.com/reader/otherversions/

                    ---> Installe le SP1 de Vista :
                    http://www.microsoft.com/downloads/details.aspx?FamilyID=b0c7136d-5ebb-413b-89c9-cb3d06d12674&displaylang=fr

                    ---> Télécharge et installe CCleaner (N'installe pas la Yahoo Toolbar) :
                    * Lance-le. Va dans Outils puis Programmes de désinstallations.
                    * Cherche RON Tool Bannerstyles15 dans la liste et sélectionne-le. Clique ensuite sur Effacer l'Entrée.

                    ---> Supprime RSIT et le dossier RSIT situé dans C:\

                    ---> Refais un scan RSIT (en tant qu'administrateur) et poste les deux rapports.

                    Ton PC va bien ?
                    0
                    • 1
                    • 2