Infection bien cachée :s : HELP ME PLEASE!!!

Résolu
Bonjours a tous,

Alors voila, depuis quelque jours, le gestionnaire des taches , Firefox et Internet explorer ne veulent pas toujours s'ouvrir même si je supprimes la tache de Firefox et Internet explorer dans le gestionnaire des Taches ( quand il veux s'ouvrir), j'ai scanné mon pc avec Antivir, Mbam & le logiciel mrt.exe de Windows, cela n'y change rien ( tous ne détectent rien).

Pourriez-vous m'aidez svp à ce qui est à l'origine de tout ceci?

Merci à vous.

--
L'asse c'est ma passion, ma religion. Tu peux pas test la puissance x3. Asse for ever <3<3<3<3<3<3<3<3<3<3<3
Configuration: Windows XP pro mais peut etre linux plus tard.....

112 réponses

Résumé de la discussion

Blocage des applications et, plus largement, des tâches système est rapporté lorsque Firefox et Internet Explorer refusent de s’ouvrir, malgré la suppression des processus et des scans antivirus répétés. Des éléments évoquent une possible infection et des outils spécifiques donnent des résultats partiels: un rapport Bitdefender signale Trojan.Wimad.Gen.1 et Spyware, et Findykill peut bloquer l’accès aux répertoires sensibles. D’autres interventions évoquent le mode sans échec, l’analyse Ad-Remover et des rapports modifiant les paramètres IE et Firefox, avec des résultats variables et des blocs persistants dans Program Files. En cas de besoin, des rapports complémentaires tels que les logs Ad-Remover et les scan successifs précisent des artefacts détectés dans Fichiers Communs, offrant des pistes pour la suite des investigations.

Bobot (l’IA à votre service)
  1. Lu cher gen-Hackman, le problème est réglé maintenant, merci de ton aide, @+ et merci encore :))
    0
    1. hello tu as le resultat de mon post 119 ?
      0
      1. Alors mon pc refonctionne depuis 4/5 jours je crois mais si tu veux un log rsit pour etre sur?
        0
        1. salut :

          ---> Désactive ton antivirus le temps de la manipulation car OTM est détecté comme une infection à tort.

          ---> Télécharge OTM (OldTimer) sur ton Bureau :

          ---> Double-clique sur OTM.exe afin de le lancer.

          ---> Copie (Ctrl+C) le texte suivant ci-dessous :



          :processes
          explorer.exe
          TeaTimer.exe
          msnmsgr.exe
          iexplore.exe
          firefox.exe

          :services
          mbr

          :files
          C:\WINDOWS\isRS-000.tmp
          C:\WINDOWS\system32\CF17051.exe
          C:\WINDOWS\system32\uxt66.tmp
          C:\WINDOWS\system32\RtkCoInstXP(6).dll
          C:\WINDOWS\system32\RtkCoInstXP(5).dll
          C:\WINDOWS\system32\RtkCoInstXP(4).dll
          C:\WINDOWS\system32\RtkCoInstXP(3).dll
          C:\WINDOWS\system32\RtkCoInstXP(2).dll
          C:\WINDOWS\IsUn0407.exe
          C:\Documents and Settings\All Users.WINDOWS\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
          C:\Documents and Settings\All Users.WINDOWS\Application Data\{92E7A367-8E12-4830-AA70-29C32E331A81}

          :reg

          :commands
          [purity]
          [emptytemp]
          [start explorer]
          [reboot]



          ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

          ---> Clique maintenant sur le bouton MoveIt! puis ferme OTM

          Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
          Accepte en cliquant sur YES.

          ---> Poste le rapport situé dans ce dossier : C:\_OTM\MovedFiles\
          Le nom du rapport correspond au moment de sa création : date_heure.log
          0
          1. ok , merci de ton aide ^^
            0
            1. je dois m absenter jusqu'a dimanche apres midi
              0
              1. Et la :

                info.txt logfile of random's system information tool 1.06 2009-07-10 18:44:24

                ======Uninstall list======

                -->C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
                -->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
                -->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
                -->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
                -->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
                -->C:\WINDOWS\UNRecode.exe /UNINSTALL
                -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
                ABBYY FineReader 4.0 Sprint-->C:\WINDOWS\bitdeins.exe C:\PROGRA~1\ABBYYF~1.0SP\bitdeins.ini
                Adobe Acrobat 4.0, 5.0-->C:\WINDOWS\ISUN040C.EXE -f"C:\Program Files\Fichiers communs\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Fichiers communs\Adobe\Acrobat 5.0\NT\Uninst.dll"
                Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
                Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
                Adobe Reader 9.1.2 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A91000000001}
                Adobe Shockwave Player 11.5-->"C:\WINDOWS\system32\Adobe\Shockwave 11\uninstaller.exe"
                AirXonix version 1.36-->"C:\Program Files\AirXonix\unins000.exe"
                Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
                Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
                ArcSoft PhotoImpression 3.0-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\ArcSoft\PhotoImpression\Uninst.isu"
                asquarred-->"C:\Program Files\a-squared Free\unins000.exe"
                Assistant de connexion Windows Live-->MsiExec.exe /I{D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
                Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE
                Barre d'outils Outlook de Windows Live (Windows Live Toolbar)-->MsiExec.exe /X{4002F73D-EBB3-4EA1-A2FF-DBCB4529759E}
                Bloqueur de fenêtres pop-up (Windows Live Toolbar)-->MsiExec.exe /X{51F366F4-C2E4-429A-866A-59C885ED42FD}
                Bluesoleil2.6.0.8 Release 070517-->MsiExec.exe /X{438BB9B4-65FE-4626-91D9-A8F57B18001D}
                CamStudio-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{EB371786-9449-4ED8-B47A-032467A58CAD} anything\anything
                CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
                Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
                CleanUp!-->C:\Program Files\CleanUp!\uninstall.exe
                Coffret de pilotes Logitech QuickCam-->"C:\Program Files\Fichiers communs\LogiShrd\LogiDriverStore\lvdrivers\11.90.1262\LgDrvInst.exe" -remove -instdir"C:\Program Files\Fichiers communs\LogiShrd\LogiDriverStore\lvdrivers\" -enumdelay=200 -enabledifx -forcedelete -usbhubsfirst -forceremove -cumulativeremove -promptuninstall -arpregkey"lvdrivers_11.90" /clone_wait /hide_progress
                Détecteur de flux Windows Live Toolbar (Windows Live Toolbar)-->MsiExec.exe /X{175B7C4A-CAF8-437A-B597-73E0D2D970FE}
                Disc2Phone-->MsiExec.exe /X{1C75E8E0-29D5-4298-AE16-B8604FD9DDE4}
                eMule-->"C:\Program Files\eMule\Uninstall.exe"
                EPSON Scan Tool-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9F57DB08-26D6-11D6-8AA5-0000E22DA3A0}\setup.exe" -l0x40c
                ESET Online Scanner-->C:\WINDOWS\system32\OnlineScannerUninstaller.exe
                Extension de Windows Live Toolbar (Windows Live Toolbar)-->MsiExec.exe /X{D518AD32-C710-4616-BA0D-D4B1FA5F82E8}
                FindyKill-->C:\FindyKill\Uninstal.exe
                Free Music Zilla-->"C:\Program Files\Free Music Zilla\unins000.exe"
                Freeplayer-->C:\Program Files\Freeplayer\Uninstall.exe
                GIMP 2.6.4-->"C:\Program Files\GIMP-2.0\setup\unins000.exe"
                Google Chrome-->"C:\Program Files\Google\Chrome\Application\2.0.172.33\Installer\setup.exe" --uninstall --system-level
                Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
                Google Earth-->MsiExec.exe /X{CC016F21-3970-11DE-B878-005056806466}
                HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
                Imprimantes Canon CAPT-->C:\WINDOWS\system32\Spool\Drivers\w32x86\3\CAP1UNIK.EXE
                Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
                Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
                Intel(R) Graphics Media Accelerator Driver-->C:\WINDOWS\system32\igxpun.exe -uninstall
                Java 2 Runtime Environment, SE v1.4.2_05-->MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142050}
                Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216013FF}
                Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
                Logitech QuickCam-->MsiExec.exe /I{937B232D-9776-471E-92BD-D424E514EF14}
                Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins001.exe"
                Menus intelligents (Windows Live Toolbar)-->MsiExec.exe /X{3585ED1C-74C5-43B0-A232-831B96A12A2B}
                Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
                Microsoft Search Enhancement Pack-->MsiExec.exe /X{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
                Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
                Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
                Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
                Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022-->MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
                Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
                Mise à jour de sécurité pour Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
                Mozilla Firefox (3.0.11)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
                MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                Navigation par onglets (Windows Live Toolbar)-->MsiExec.exe /X{E74559C2-BB47-45AD-83DD-0D66B67E7811}
                Nero 7 Essentials-->MsiExec.exe /X{3BDEE284-1516-40E8-B784-00FEBE1B1036}
                OneCare Advisor (Windows Live Toolbar)-->MsiExec.exe /X{F242B06B-517F-4D62-B654-16B11564A912}
                OpenOffice.org 3.0-->MsiExec.exe /I{1572F66F-F9AD-4D45-B0D2-0F45A0D5A0F6}
                Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
                Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
                PhotoFiltre-->"C:\Program Files\PhotoFiltre\Uninst.exe"
                RarZilla Free Unrar 2.53-->C:\Program Files\RarZilla Free Unrar\uninstall.exe
                REALTEK GbE & FE Ethernet PCI-E NIC Driver-->C:\Program Files\InstallShield Installation Information\{C9BED750-1211-4480-B1A5-718A3BE15525}\Setup.exe -runfromtemp -l0x040c -removeonly
                Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x40c -removeonly
                Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
                ServerMania 0.98-->"C:\Program Files\ServerMania\unins000.exe"
                Sony Ericsson Device Data-->MsiExec.exe /I{C92E7DF1-624A-4D95-A4C4-18CB491B44A4}
                Sony Ericsson Drivers-->MsiExec.exe /I{5CC68528-24FF-4DF8-91C9-AF540F98505A}
                Sony Ericsson PC Suite-->C:\WINDOWS\Installer\{D6BF6477-8369-489F-8DE6-3731F4B88560}\setup.exe /uninstall
                Sony Ericsson PC Suite-->MsiExec.exe /I{B192E1BB-98A4-4369-9271-96117A57F546}
                Spelling Dictionaries Support For Adobe Reader 9-->MsiExec.exe /I{AC76BA86-7AD7-5464-3428-900000000004}
                Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
                SpywareBlaster 4.2-->"C:\Program Files\SpywareBlaster\unins000.exe"
                TeamSpeak 2 RC2-->"C:\Program Files\Teamspeak2_RC2\unins000.exe"
                TeamViewer 4-->C:\Program Files\TeamViewer\Version4\uninstall.exe
                TmUnitedForever-->"C:\Program Files\TmUnitedForever\unins000.exe"
                TrackMania United 0.2.0.0-->"C:\Program Files\TrackMania United\unins000.exe"
                Urban Terror 4.1-->"C:\Program Files\UrbanTerror\unins000.exe"
                VLC media player 0.9.8a-->C:\Program Files\VideoLAN\VLC\uninstall.exe
                Winamp (remove only)-->"C:\Program Files\Winamp\UninstWA.exe"
                Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
                Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
                Windows Live Favorites pour Windows Live Toolbar-->MsiExec.exe /X{DCE65B11-710D-4C54-9DE5-1A6A0BD2186B}
                Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
                Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
                Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
                Windows Live Writer-->MsiExec.exe /X{2231CE39-B963-4B9D-823A-F412ECA637B1}
                Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
                Yu-Gi-Oh Virtual Battle 5.18-->C:\Program Files\Yu-Gi-Oh Virtual Battle 5\Uninstal.exe

                ======Security center information======

                AV: AntiVir Desktop

                ======System event log======

                Computer Name: TITANIUM
                Event Code: 7035
                Message: Un contrôle Arrêter a correctement été envoyé au service TuneUp Drive Defrag Service.

                Record Number: 774
                Source Name: Service Control Manager
                Time Written: 20090703042802.000000+120
                Event Type: Informations
                User: TITANIUM\Administrateur

                Computer Name: TITANIUM
                Event Code: 7036
                Message: Le service TuneUp Drive Defrag Service est entré dans l'état : arrêté.

                Record Number: 773
                Source Name: Service Control Manager
                Time Written: 20090703042802.000000+120
                Event Type: Informations
                User:

                Computer Name: TITANIUM
                Event Code: 7036
                Message: Le service TuneUp Drive Defrag Service est entré dans l'état : en cours d'exécution.

                Record Number: 772
                Source Name: Service Control Manager
                Time Written: 20090703030804.000000+120
                Event Type: Informations
                User:

                Computer Name: TITANIUM
                Event Code: 7035
                Message: Un contrôle Démarrer a correctement été envoyé au service TuneUp Drive Defrag Service.

                Record Number: 771
                Source Name: Service Control Manager
                Time Written: 20090703030804.000000+120
                Event Type: Informations
                User: TITANIUM\Administrateur

                Computer Name: TITANIUM
                Event Code: 7036
                Message: Le service Service COM de gravage de CD IMAPI est entré dans l'état : arrêté.

                Record Number: 770
                Source Name: Service Control Manager
                Time Written: 20090703014734.000000+120
                Event Type: Informations
                User:

                =====Application event log=====

                Computer Name: TITANIUM
                Event Code: 4096
                Message: Le service AntiVir a bien démarré!

                Record Number: 3573
                Source Name: Avira AntiVir
                Time Written: 20090527232802.000000+120
                Event Type: Informations
                User: AUTORITE NT\SYSTEM

                Computer Name: TITANIUM
                Event Code: 4097
                Message: Le service AntiVir a été arrêté!

                Record Number: 3572
                Source Name: Avira AntiVir
                Time Written: 20090527232741.000000+120
                Event Type: Informations
                User: AUTORITE NT\SYSTEM

                Computer Name: TITANIUM
                Event Code: 1005
                Message: Windows Installer a initié un redémarrage système afin de terminer ou de continuer la configuration de 'Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17'.

                Record Number: 3571
                Source Name: MsiInstaller
                Time Written: 20090527232706.000000+120
                Event Type: Informations
                User: TITANIUM\Administrateur

                Computer Name: TITANIUM
                Event Code: 11728
                Message: Product: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 -- Configuration completed successfully.

                Record Number: 3570
                Source Name: MsiInstaller
                Time Written: 20090527232706.000000+120
                Event Type: Informations
                User: TITANIUM\Administrateur

                Computer Name: TITANIUM
                Event Code: 1025
                Message: Produit : Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17. Le fichier C:\WINDOWS\winsxs\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcr90.dll est actuellement utilisé par le processus de nom 'msnmsgr' et d'identificateur '2448'.

                Record Number: 3569
                Source Name: MsiInstaller
                Time Written: 20090527232705.000000+120
                Event Type: Informations
                User: TITANIUM\Administrateur

                ======Environment variables======

                "ComSpec"=%SystemRoot%\system32\cmd.exe
                "Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\Fichiers communs\Teleca Shared;C:\Program Files\QuickTime\QTSystem
                "windir"=%SystemRoot%
                "FP_NO_HOST_CHECK"=NO
                "OS"=Windows_NT
                "PROCESSOR_ARCHITECTURE"=x86
                "PROCESSOR_LEVEL"=6
                "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 22 Stepping 1, GenuineIntel
                "PROCESSOR_REVISION"=1601
                "NUMBER_OF_PROCESSORS"=1
                "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
                "TEMP"=%SystemRoot%\TEMP
                "TMP"=%SystemRoot%\TEMP
                "DEVMGR_SHOW_DETAILS"=1
                "CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
                "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

                -----------------EOF-----------------
                0
                1. Voila:

                  Logfile of random's system information tool 1.06 (written by random/random)
                  Run by Administrateur at 2009-07-10 18:44:18
                  Microsoft Windows XP Professionnel Service Pack 3
                  System drive C: has 18 GB (35%) free of 50 GB
                  Total RAM: 1015 MB (55% free)

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 18:44:22, on 10/07/2009
                  Platform: Windows XP SP3 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Avira\AntiVir Desktop\sched.exe
                  C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\WINDOWS\explorer.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\Documents and Settings\Administrateur.TITANIUM.000\Bureau\FFM.exe
                  C:\WINDOWS\system32\msiexec.exe
                  C:\Documents and Settings\Administrateur.TITANIUM.000\Bureau\RSIT.exe
                  C:\Program Files\trend micro\Administrateur.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://coramail.net/r3.php
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Program Files\Windows Live\Messenger\wlchtc.dll
                  O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                  O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                  O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                  O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                  O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                  O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                  O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                  O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKUS\S-1-5-18\..\RunOnce: [WUAppSetup] C:\Program Files\Fichiers communs\logishrd\WUApp32.exe -v 0x046d -p 0x08da -f video -m logitech -d 11.90.1262.0 (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\RunOnce: [WUAppSetup] C:\Program Files\Fichiers communs\logishrd\WUApp32.exe -v 0x046d -p 0x08da -f video -m logitech -d 11.90.1262.0 (User 'Default user')
                  O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                  O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                  O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                  O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                  O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - https://www.eset.com/
                  O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                  O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                  O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
                  O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://fichiers.touslesdrivers.com/maconfig/MaConfig_3_1_2_1.cab
                  O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
                  O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
                  O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                  O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
                  O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
                  O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                  O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                  O23 - Service: Service Google Update (gupdate1c98fb4bd28432c) (gupdate1c98fb4bd28432c) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                  O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                  O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
                  O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
                  O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
                  O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
                  0
                  1. Fichiers supprimés, un log RSIT maintenant?^^
                    0
                    1. je n'ai jamais vu ca dans auncun pc ca doit pas etre très catholique quand meme
                      0
                      1. C'est quoi exactement ces 2 fichiers? des virus?
                        0
                        1. Oui, dans les 2 MFT, il n'y a qu'un fichier "explorer.exe", c'est tout
                          0
                          1. Dedans, ya un fichier nommé '"explorer.exe"
                            0
                            • 1
                            • 2
                            • 3
                            • 4
                            • 5
                            • 6