Pc infecté?

Résolu
Bonjour,
je voudrais savoir commentje peut faire pour savoir si mon pc et infecté merci de votre aide
Configuration: Windows Vista Internet Explorer 7.0

11 réponses

  1. Pour norton c'est ok apparemment, plus de tracess,

    Pour optimiser le demarrage,

    Relances HIJACKTHIS mais cette fois clic sur
    DO A SYSTEM SCAN ONLY
    puis coches toutes ces lignes (et seulement ces lignes : tu pourrais altérer le fonctionnement de ton pc!)
    puis clic sur
    FIX CHEKEED

    O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-09.sun.com/

    ensuite

    Très bien, ton ordinateur n'est plus infecté !

    Avant de retourner sur le net, il y a quelques petites choses que tu dois faire pour finir le nettoyage et améliorer sensiblement la sécurité de ton ordinateur, ça t'évitera peut-être de devoir revenir ici avec une nouvelle infection dans le futur ;)

    Mais sache qu'aucun logiciel de sécurité ne te protègera à 100%, ce qui fait la différence, c'est ta vigilance lorsque tu télécharges ou installes quelque chose : pour en savoir plus, je t'invite à bien lire la page indiquée tout en bas de ce message.

    1) Les barres d'outils

    Souvent installées avec d'autres logiciels sans que l'utilisateur y fasse attention, les barres d'outils se multiplient sur les ordinateurs et ont deux résultats : ralentir les ordinateurs et provoquer des bugs des navigateurs.
    Je te conseille vivement de désinstaller les tiennes,je les ai inclus dans hijackthis au dessus.
    Pour ça, ferme ton navigateur, puis Menu démarrer --> Panneau de configuration --> ajout/suppression de programmes --> désinstalle la « Windows Live Toolbar et la google toolbar».

    2) Sécurise ton ordinateur

    Anti-virus :
    tres bien

    Anti-spyware :

    * Installe Spyware Blaster

    : il ne prend pas de mémoire, c'est juste un logiciel qui vaccine ton pc contre certaines infections. Il faut le mettre à jour manuellement (« Updates »), tous les 15 jours environ, et activer toutes les protections (« Enable all protection »)

    * En complément, garde MalwareBytes pour son scan de nettoyage performant. 1 fois par mois environ

    Pour naviguer sur internet plus en sécurité et à l’abri des publicités, je te conseille vivement d’installer et d'utiliser le navigateur Firefox 3 avec deux extensions :
    AdBlockPlus pour bloquer les publicités ;

    WOT, pour t'avertir des sites web dangereux.

    3) Télécharge ToolsCleaner sur ton Bureau pour nettoyer l'ordi de tous les outils qu'on a utilisé : ToolsCleaner

    Lance le, clique sur Recherche et laisse le scan se finir, puis clique sur Suppression pour nettoyer.
    Tu peux aussi supprimer les fichiers temporaires.
    Ensuite, supprime manuellement ToolsCleaner (mets le à la corbeille).
    S'il ne supprime pas tout, supprime manuellement ce qui reste.

    4) Télécharge et installe Ccleaner (si ce n’est déjà fait) :

    Lance CCleaner
    Option --> avancé --> décoche « effacer uniquement les fichiers plus vieux que 48h »
    Puis nettoyeur --> Analyse > Lancer le nettoyage, puis sur OK dans la fenêtre qui s' affiche.
    Enfin, registre --> corrige toutes les erreurs, et recommence jusqu'à ce qu'il ne trouve plus d'erreurs.

    (Tu peux garder ce logiciel et l'utiliser régulièrement).

    5) Pour finir le nettoyage, il faut purger la restauration du système (pour supprimer les points de restauration infectés).
    .RESTAURATION vista

    Pour finir le nettoyage, il faut purger la restauration du système (pour supprimer les points de restauration infectés).
    Menu démarrer : clique droit sur ordinateur : propriétés : protection du système
    Désactiver la restauration du système sur tous les lecteurs
    Clique sur OK.

    Puis refais la manipulation inverse pour réactiver la restauration système.

    6) Je t'invite enfin à visiter cette page qui t'apportera des informations de prévention et de protection contre les infections (environ 15 minutes de lecture très instructive et utile):
    Prévention et sécurité sur internet

    Bonne lecture, bon courage, et n'hésite pas à poser des questions en cas de besoin ;)

    Et penses a mettre ton sujet en « RESOLU » ;)

    1. as tu pensé a desinstaller Norton ? c'est important

      Java n'est pas à jour, c'est une faille de sécurité.
      Il faut d'abord désinstaller l'ancienne version : Ouvre le menu démarrer --> panneau de configuration --> ajout/suppression de programmes --> sélectionne toutes les versions de java présentes et désinstalle les.
      Ensuite, télécharge et installe la nouvelle version depuis le site officiel de java : https://java.com/fr/

      • Tu dois aussi mettre à jour tous tes autres programmes pour combler des failles de sécurité... Vérifie les mises disponibles à l'aide de ce petit programme (choisis la version sans installation) : Update Checker

      ensuite pour verifier et terminer,

      télécharges le fichier d'installation
      HIJACKTHIS

      Enregistre HJTInstall.exe sur ton bureau.

      Double-clique sur HJTInstall.exe pour lancer le programme

      Par défaut, il s'installera là :
      C:\Program Files\Trend Micro\HijackThis

      Accepte la licence en cliquant sur le bouton "I Accept"

      Choisis l'option "Do a system scan and save a log file"

      Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note

      Clique sur "Edition -> Sélectionner tout" (ou fais ctrl A), puis sur "Edition -> Copier" pour copier tout le contenu du rapport et poste le dans ton prochain message

      A LIRE : Tutoriaux

      (ne fixe rien pour le moment !! cela pourrait empêcher ton PC de fonctionner correctement)

      Si vous êtes sous VISTA, ne pas oublier de désactiver Le contrôle des comptes utilisateurs
      1. Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 19:47:50, on 05/06/2009
        Platform: Windows Vista SP1 (WinNT 6.00.1905)
        MSIE: Internet Explorer v7.00 (7.00.6001.18226)
        Boot mode: Normal

        Running processes:
        C:\Windows\system32\taskeng.exe
        C:\Windows\system32\Dwm.exe
        C:\Windows\Explorer.EXE
        C:\Program Files\Windows Defender\MSASCui.exe
        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
        C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
        C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
        C:\Windows\System32\rundll32.exe
        C:\Windows\System32\rundll32.exe
        C:\Program Files\Java\jre6\bin\jusched.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\Program Files\Windows Media Player\wmpnscfg.exe
        C:\Program Files\filehippo.com\UpdateChecker.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://format.packardbell.com/...
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
        O1 - Hosts: ::1 localhost
        O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
        O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
        O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
        O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
        O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
        O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
        O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
        O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
        O4 - HKCU\..\Run: [filehippo.com] "C:\Program Files\filehippo.com\UpdateChecker.exe" /background
        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
        O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
        O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
        O13 - Gopher Prefix:
        O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-09.sun.com/s/ESD7/JSCDL/jdk/6u13-b03/jinstall-6u13-windows-i586-jc.cab?e=1244223516590&h=62e7f109f2dc549f087a8bbffc056cfb/&filename=jinstall-6u13-windows-i586-jc.cab
        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
        O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
        O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL c:\progra~1\bandoo\bndhook.dll
        O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
        O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
        O23 - Service: Bandoo Coordinator - Discordia Limited - C:\PROGRA~1\Bandoo\Bandoo.exe
        O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
        O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
        O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
        O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
        O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
        O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
        O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
        O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe
        O23 - Service: @%SystemRoot%\System32\TUProgSt.exe,-1 (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\Windows\System32\TUProgSt.exe
      2. norton ne c est pas bien désintaller il me dit qu il y a une erreur numero 21
    2. voici le rapport Malwarebytes' Anti-Malware 1.37
      Version de la base de données: 2233
      Windows 6.0.6001 Service Pack 1

      05/06/2009 18:49:13
      mbam-log-2009-06-05 (18-49-13).txt

      Type de recherche: Examen complet (C:\|)
      Eléments examinés: 222135
      Temps écoulé: 56 minute(s), 23 second(s)

      Processus mémoire infecté(s): 0
      Module(s) mémoire infecté(s): 0
      Clé(s) du Registre infectée(s): 0
      Valeur(s) du Registre infectée(s): 0
      Elément(s) de données du Registre infecté(s): 0
      Dossier(s) infecté(s): 2
      Fichier(s) infecté(s): 5

      Processus mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Module(s) mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Clé(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Valeur(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Elément(s) de données du Registre infecté(s):
      (Aucun élément nuisible détecté)

      Dossier(s) infecté(s):
      C:\Users\All Users\Start Menu\Programs\PremierOpinion (Adware.PremierOpinion) -> Quarantined and deleted successfully.
      C:\Program Files\InternetProgram (Adware.PlayMp3z) -> Quarantined and deleted successfully.

      Fichier(s) infecté(s):
      c:\Users\all users\start menu\Programs\premieropinion\About PremierOpinion.lnk (Adware.PremierOpinion) -> Quarantined and deleted successfully.
      c:\Users\all users\start menu\Programs\premieropinion\Privacy Policy and User License Agreement.lnk (Adware.PremierOpinion) -> Quarantined and deleted successfully.
      c:\Users\all users\start menu\Programs\premieropinion\Support.lnk (Adware.PremierOpinion) -> Quarantined and deleted successfully.
      c:\program files\internetprogram\pcre3.dll (Adware.PlayMp3z) -> Quarantined and deleted successfully.
      c:\program files\internetprogram\uninstall.exe (Adware.PlayMp3z) -> Quarantined and deleted successfully.
      merci
      1. slt

        ok t'inquietes pas si c'est long c'est normal ;) et surtout penses a la mise a jour
        1. Télécharge Malwarebytes

          Tu auras un tutoriel à ta disposition sur mon site web pour l'installer et l'utiliser correctement.

          Fais la mise à jour du logiciel (elle se fait normalement à l'installation)

          Lance une analyse complète en cliquant sur "Exécuter un examen complet"

          Sélectionnes les disques que tu veux analyser et cliques sur "Lancer l'examen"

          L'analyse peut durer un bon moment.....

          Une fois l'analyse terminée, cliques sur "OK" puis sur "Afficher les résultats"

          Vérifies que tout est bien coché et cliques sur "Supprimer la sélection" => et ensuite sur "OK"

          Un rapport va s'ouvrir dans le bloc note... Fais un copié/collé du rapport dans ta prochaine réponse sur le forum
          Il se pourrait que certains fichiers devront être supprimés au redémarrage du PC... Faites le en cliquant sur "oui" à la question posée
          1. bonjour neophyte je commence l examen je t envois le rapport des que celui ci et terminer
        2. ok si je ne reponds pas ce soir pour la suite, je reviens demain :))

          * Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d avoir été infectés sans les ouvrir

          * Fais un clic droit sur le raccourci UsbFix présent sur ton bureau et choisi "Exécuter en tant qu'administrateur" .

          * choisi l'option 2 ( Suppression )

          * Ton bureau disparaîtra et le pc redémarrera .

          * Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.

          * Ensuite post le rapport UsbFix.txt qui apparaîtra avec le bureau .

          * Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

          ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
          1. voici le rapport
            ############################## [ UsbFix V3.028 | Cleaning ]

            # User : daniel (Administrateurs) # LINK
            # Update on 02/06/09 by Chiquitine29, C_XX & Chimay8
            # WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
            # Start at: 20:15:06 | 04/06/2009

            # Intel(R) Core(TM)2 Duo CPU T5450 @ 1.66GHz
            # Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6000 32-bit) #
            # Internet Explorer 7.0.6000.16830
            # Windows Firewall Status : Disabled
            # AV : AntiVir Desktop 9.0.1.26 [ Enabled | Updated ]

            # C:\ # Disque fixe local # 141,04 Go (51,6 Go free) [HDD] # NTFS
            # E:\ # Disque CD-ROM # 654,81 Mo (0 Mo free) [SC4DELUXE2] # CDFS

            ############################## [ Processus actifs ]

            C:\Windows\System32\smss.exe
            C:\Windows\system32\csrss.exe
            C:\Windows\system32\csrss.exe
            C:\Windows\system32\wininit.exe
            C:\Windows\system32\services.exe
            C:\Windows\system32\lsass.exe
            C:\Windows\system32\lsm.exe
            C:\Windows\system32\winlogon.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\LogonUI.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\SLsvc.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\spoolsv.exe
            C:\Program Files\Avira\AntiVir Desktop\sched.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\Dwm.exe
            C:\Windows\Explorer.EXE
            C:\Windows\system32\runonce.exe
            C:\Program Files\Avira\AntiVir Desktop\avguard.exe
            C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
            C:\Windows\system32\PnkBstrA.exe
            C:\Windows\system32\PnkBstrB.exe
            C:\Program Files\CyberLink\Shared Files\RichVideo.exe
            C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
            C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\TUProgSt.exe
            C:\Windows\System32\svchost.exe
            C:\PROGRA~1\Bandoo\Bandoo.exe
            C:\Windows\system32\taskeng.exe
            C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
            C:\Windows\system32\wbem\wmiprvse.exe
            C:\Windows\system32\taskeng.exe
            C:\Program Files\TuneUp Utilities 2009\OneClickStarter.exe

            ################## [ Fichiers # Dossiers infectieux ]

            (!) Not Deleted ! E:\autorun.inf

            ################## [ Registre # Clés Run infectieuses ]

            Deleted ! HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe

            ################## [ Registre # Mountpoints2 ]

            Deleted ! HKCU\...\Explorer\MountPoints2\{91a43783-194d-11de-aa25-806e6f6e6963}\Shell\AutoRun\Command

            ################## [ Listing des fichiers présent ]

            [01/01/2009 19:14|--a--c---|7394] - C:\AD-report-Clean-01.01.2009.log
            [18/09/2006 23:43|--a--c---|24] - C:\autoexec.bat
            [02/11/2006 11:53|-rahs----|438840] - C:\bootmgr
            [26/11/2007 18:41|-ra-sc---|8192] - C:\BOOTSECT.BAK
            [01/01/2009 00:35|--a--c---|5242] - C:\cleannavi.txt
            [18/09/2006 23:43|--a--c---|10] - C:\config.sys
            [01/01/2009 00:35|--a--c---|4710] - C:\fixnavi.txt
            [24/03/2008 22:56|-rahsc---|0] - C:\IO.SYS
            [10/02/2009 20:39|--a--c---|2688] - C:\LGSInst.Log
            [01/01/2009 13:12|--a--c---|14396] - C:\lopR.txt
            [24/03/2008 22:56|-rahsc---|0] - C:\MSDOS.SYS
            [29/11/2006 23:38|--a--c---|512] - C:\MSP.iss
            [?|?|?] - C:\pagefile.sys
            [26/11/2007 10:46|--a--c---|86] - C:\setup.log
            [04/06/2009 20:18|--a--c---|3418] - C:\UsbFix.txt
            [02/01/2009 19:55|--a--c---|562] - C:\Vaccin.txt
            [02/01/2009 16:02|--a--c---|162] - C:\YServer.txt
            [29/08/2003 00:16|-r-------|153718] - E:\00000000.016
            [29/08/2003 00:16|-r-------|308280] - E:\00000000.256
            [26/03/2008 17:17|-r-------|2048] - E:\00000001.TMP
            [26/03/2008 17:17|-r-------|317440] - E:\00000002.TMP
            [29/08/2003 00:16|-r-------|41472] - E:\DRVMGT.DLL
            [29/08/2003 00:27|-r-------|61030094] - E:\EP1.dat
            [25/08/2003 13:03|-r-------|19976] - E:\Graphics Rules.sgr
            [25/08/2003 13:04|-r-------|18242823] - E:\Intro.dat
            [29/08/2003 01:02|-r-------|147456] - E:\RunGame.exe
            [13/07/2003 02:31|-r-------|10134] - E:\SC4.ico
            [29/08/2003 00:16|-r-------|12400] - E:\SECDRV.SYS
            [29/08/2003 00:27|-r-------|144547650] - E:\SimCity_1.dat
            [29/08/2003 00:27|-r-------|169268568] - E:\SimCity_2.dat
            [29/08/2003 00:27|-r-------|115072687] - E:\SimCity_3.dat
            [29/08/2003 00:27|-r-------|122372241] - E:\Sound.dat
            [25/08/2003 13:10|-r-------|10420] - E:\Video Cards.sgr
            [29/08/2003 01:02|-r-------|59] - E:\autorun.inf

            ################## [ Vaccination ]

            # C:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.

            ################## [ ! Fin du rapport # UsbFix V3.028 ! ]

            merci de ton aide
        3. tu es bien infecté mais le plus urgent est que tu as 2 antivirus, tu n'es pas mieux protégé , meme moins, puisqu'ils se genent entre eux...

          je te conseille vivement de desinstaller norton avec ceci et de garder antivir qui est tres performant

          ensuite

          ==> Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):
          UAC

          * Va dans démarrer puis panneau de configuration
          * Double Clique sur l'icône "Comptes d'utilisateurs"
          * Clique ensuite sur désactiver et valide.

          puis

          * Telecharge et installe UsbFix de C_XX & Chiquitine29
          http://sd-1.archive-host.com/membres/up/127028005715545653/UsbFix.exe

          * Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

          * Fais un clic droit sur le raccourci UsbFix présent sur ton bureau et choisi "Exécuter en tant qu'administrateur" .

          * Choisi l'option 1 ( Recherche )

          * Laisse travailler l'outil.

          * Ensuite post le rapport UsbFix.txt qui apparaîtra.

          * Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

          ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

          * Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
          Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
          Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

          1. voici le rapport ,
            ############################## [ UsbFix V3.028 | Scan ]

            # User : daniel (Administrateurs) # LINK
            # Update on 02/06/09 by Chiquitine29, C_XX & Chimay8
            # WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
            # Start at: 19:43:55 | 04/06/2009

            # Intel(R) Core(TM)2 Duo CPU T5450 @ 1.66GHz
            # Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6000 32-bit) #
            # Internet Explorer 7.0.6000.16830
            # Windows Firewall Status : Disabled
            # AV : AntiVir Desktop 9.0.1.26 [ Enabled | Updated ]

            # C:\ # Disque fixe local # 141,04 Go (51,69 Go free) [HDD] # NTFS
            # E:\ # Disque CD-ROM # 654,81 Mo (0 Mo free) [SC4DELUXE2] # CDFS

            ############################## [ Processus actifs ]

            C:\Windows\System32\smss.exe
            C:\Windows\system32\csrss.exe
            C:\Windows\system32\csrss.exe
            C:\Windows\system32\wininit.exe
            C:\Windows\system32\services.exe
            C:\Windows\system32\lsass.exe
            C:\Windows\system32\lsm.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\winlogon.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\SLsvc.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\spoolsv.exe
            C:\Program Files\Avira\AntiVir Desktop\sched.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\Dwm.exe
            C:\Windows\Explorer.EXE
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            C:\Windows\System32\rundll32.exe
            C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
            C:\Windows\System32\rundll32.exe
            C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
            C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
            C:\Program Files\Windows Live\Messenger\msnmsgr.exe
            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            C:\Program Files\Windows Media Player\wmpnscfg.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Avira\AntiVir Desktop\avguard.exe
            C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
            C:\Windows\system32\PnkBstrA.exe
            C:\Windows\system32\PnkBstrB.exe
            C:\Program Files\CyberLink\Shared Files\RichVideo.exe
            C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
            C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\TUProgSt.exe
            C:\Windows\System32\svchost.exe
            C:\PROGRA~1\Bandoo\Bandoo.exe
            C:\Windows\system32\taskeng.exe
            C:\Windows\system32\wbem\wmiprvse.exe
            C:\Program Files\Windows Media Player\wmpnetwk.exe
            C:\Windows\system32\taskeng.exe
            C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
            C:\Windows\system32\conime.exe
            C:\Windows\system32\wbem\wmiprvse.exe

            ################## [ Registre Startup ]

            HKCU_Main: "Local Page"="C:\\Windows\\system32\\blank.htm"
            HKCU_Main: "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
            HKCU_Main: "Start Page"="https://www.google.fr/?gws_rd=ssl"
            HKLM_logon: "Userinit"="C:\\Windows\\system32\\userinit.exe,"
            HKLM_logon: "LegalNoticeCaption"=""
            HKLM_logon: "LegalNoticeText"=""
            HKLM_Run: Windows Defender=%ProgramFiles%\Windows Defender\MSASCui.exe -hide
            HKLM_Run: SynTPEnh=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            HKLM_Run: NvSvc=RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
            HKLM_Run: NvCplDaemon=RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
            HKLM_Run: NvMediaCenter=RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
            HKLM_Run: IAAnotif="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
            HKLM_Run: Google Quick Search Box="C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
            HKLM_Run: avgnt="C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
            HKCU_Run: msnmsgr="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
            HKCU_Run: swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            HKCU_Run: WMPNSCFG=C:\Program Files\Windows Media Player\WMPNSCFG.exe

            ################## [ Fichiers # Dossiers infectieux ]

            Found ! E:\autorun.inf

            ################## [ Registre # Clés Run infectieuses ]

            Found ! HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe

            ################## [ Registre # Mountpoints2 ]

            HKCU\...\Explorer\MountPoints2\{91a43783-194d-11de-aa25-806e6f6e6963}\Shell\AutoRun\Command

            ################## [ ! Fin du rapport # UsbFix V3.028 ! ]

            merci
        4. slt

          Pour analyser ton pc : télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.

          - Double-clique sur RSIT.exe afin de lancer le programme.

          - Clique sur Continue à l'écran Disclaimer.

          - Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

          - Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).

          Note : Les rapports sont sauvegardés dans le dossier C:\rsit.
          1. voici les rapport merci de ton aide Logfile of random's system information tool 1.06 (written by random/random)
            Run by daniel at 2009-06-04 18:57:49
            Microsoft® Windows Vista™ Édition Familiale Premium
            System drive C: has 53 GB (36%) free of 144 GB
            Total RAM: 2038 MB (45% free)

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 18:58:17, on 04/06/2009
            Platform: Windows Vista (WinNT 6.00.1904)
            MSIE: Internet Explorer v7.00 (7.00.6000.16830)
            Boot mode: Normal

            Running processes:
            C:\Windows\system32\Dwm.exe
            C:\Windows\system32\taskeng.exe
            C:\Windows\Explorer.EXE
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            C:\Windows\System32\rundll32.exe
            C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
            C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
            C:\Windows\System32\rundll32.exe
            C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
            C:\Program Files\Windows Live\Messenger\msnmsgr.exe
            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            C:\Program Files\Windows Media Player\wmpnscfg.exe
            C:\Windows\system32\wuauclt.exe
            C:\Program Files\Windows Live\Contacts\wlcomm.exe
            C:\PROGRA~1\Bandoo\BndCore.exe
            C:\Program Files\Internet Explorer\ieuser.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
            C:\Users\daniel\Desktop\RSIT.exe
            C:\Program Files\trend micro\daniel.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://format.packardbell.com/cgi-bin/redirect/?country=FR&range=AD&phase=8&key=IESTART
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
            O1 - Hosts: ::1 localhost
            O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
            O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
            O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
            O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll
            O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
            O3 - Toolbar: Afficher Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
            O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
            O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
            O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
            O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
            O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
            O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
            O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
            O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
            O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
            O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
            O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
            O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
            O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
            O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
            O13 - Gopher Prefix:
            O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
            O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
            O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL c:\progra~1\bandoo\bndhook.dll
            O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
            O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
            O23 - Service: Bandoo Coordinator - Discordia Limited - C:\PROGRA~1\Bandoo\Bandoo.exe
            O23 - Service: ccEvtMgr - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            O23 - Service: ccSetMgr - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
            O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
            O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
            O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
            O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
            O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
            O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
            O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
            O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
            O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
            O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
            O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe
            O23 - Service: @%SystemRoot%\System32\TUProgSt.exe,-1 (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\Windows\System32\TUProgSt.exe