Rapport hijackhis

Résolu
Bonjour, pouvais vous m aider a analysé le rapport svp merci
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:13:38, on 17/08/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\PersonalAV\pav.exe
C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\PixArt\Pac207\Monitor.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Windows\Twain_32\CA561A\SnapDetect.exe
C:\Users\loic\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
C:\Users\loic\AppData\Roaming\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Apoint\Apntex.exe
C:\Windows\system32\conime.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Program Files\Internet Explorer\IELowutil.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {A77D3539-581D-450C-9E44-A84C415A6172} - C:\Windows\System32\msxmlm.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Monitor] C:\Windows\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [FileHippo.com] "C:\Program Files\FileHippo.com\UpdateChecker.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Startup: Outil de notification Live Search.lnk = C:\Users\loic\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Icatch(VI) SnapDetect.lnk = ?
O8 - Extra context menu item: Ajouter un site de support RSS à VAIO Information FLOW - C:\Program Files\Sony\VAIO Information FLOW\aiesc.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = laura
O17 - HKLM\Software\..\Telephony: DomainName = laura
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = laura
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = laura
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AvLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AvLib\PACSPTISVR.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AvLib\SPTISRV.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 12279 bytes
Configuration: Windows Vista Internet Explorer 8.0

13 réponses

  1. Contributeur sécurité
    On va faire une petite vérif au cas ou :

    Fais un scan en ligne Kaspersky avec Internet Explorer.
    - Clique sur Démarrer Online-Scanner

    - Clique maintenant sur J'accepte.
    - Valide l'installation d'un ou de plusieurs ActiveX si c'est nécessaire.
    - Patiente pendant l'installation des Mises à jour.
    - Choisis par la suite l'analyse du Poste de travail.
    - Sauvegarde puis colle le rapport généré en fin d'analyse.

    AIDE : Configurer le contrôle des ActiveX

    NOTE : Si tu reçois le message "La licence de Kaspersky On-line Scanner est périmée", va dans Ajout/Suppression de programmes puis désinstalle On-Line Scanner, reconnecte toi sur le site de Kaspersky pour retenter le scan en ligne.
    0
    1. slt jfk oui c l ordi a ma copine aprés je n ai pas tro de soucis a part que des fois il rame
      0
      1. Contributeur sécurité
        As tu encore des soucis avec ton pc ?

        Le nom de domaine "laura" te parle ?
        0
        1. pas grave jfk voici le rapportLogfile of random's system information tool 1.06 (written by random/random)
          Run by loic at 2009-09-25 21:40:26
          Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
          System drive C: has 24 GB (23%) free of 105 GB
          Total RAM: 2045 MB (42% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 21:41:04, on 25/09/2009
          Platform: Windows Vista SP2 (WinNT 6.00.1906)
          MSIE: Internet Explorer v8.00 (8.00.6001.18813)
          Boot mode: Normal

          Running processes:
          C:\Windows\system32\Dwm.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\Explorer.EXE
          C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe
          C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
          C:\Program Files\Windows Defender\MSASCui.exe
          C:\Program Files\Apoint\Apoint.exe
          C:\Program Files\Sony\ISB Utility\ISBMgr.exe
          C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
          C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
          C:\Program Files\Alwil Software\Avast4\ashDisp.exe
          C:\Windows\PixArt\Pac207\Monitor.exe
          C:\Program Files\Java\jre6\bin\jusched.exe
          C:\Program Files\Windows Sidebar\sidebar.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Windows\ehome\ehtray.exe
          C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
          C:\Windows\Twain_32\CA561A\SnapDetect.exe
          C:\Users\loic\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
          C:\Windows\ehome\ehmsas.exe
          C:\Users\loic\AppData\Roaming\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
          C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
          C:\Program Files\Apoint\ApMsgFwd.exe
          C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
          C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
          C:\Program Files\Apoint\Apntex.exe
          C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
          C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
          C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
          C:\Windows\System32\mobsync.exe
          C:\Program Files\Skype\Phone\Skype.exe
          C:\Program Files\Skype\Plugin Manager\skypePM.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
          C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Users\loic\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SV93U216\RSIT[1].exe
          C:\Program Files\trend micro\loic.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.com
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          O1 - Hosts: ::1 localhost
          O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
          O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
          O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
          O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
          O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
          O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
          O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
          O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
          O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\Run: [Monitor] C:\Windows\PixArt\PAC207\Monitor.exe
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
          O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
          O4 - Startup: Outil de notification Live Search.lnk = C:\Users\loic\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
          O4 - Global Startup: Bluetooth Manager.lnk = ?
          O4 - Global Startup: Icatch(VI) SnapDetect.lnk = ?
          O8 - Extra context menu item: Ajouter un site de support RSS à VAIO Information FLOW - C:\Program Files\Sony\VAIO Information FLOW\aiesc.html
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
          O13 - Gopher Prefix:
          O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = laura
          O17 - HKLM\Software\..\Telephony: DomainName = laura
          O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = laura
          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
          O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
          O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
          O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe
          O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AvLib\MSCSPTISRV.exe
          O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AvLib\PACSPTISVR.exe
          O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
          O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AvLib\SPTISRV.exe
          O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
          O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
          O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
          O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
          O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
          O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
          O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
          O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
          O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
          O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
          O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
          O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
          O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
          O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
          0
          1. Contributeur sécurité
            Oupss...Je t'ai oublié ^^

            Peux tu me recoller un log RSIT ?
            0
            1. bonjour jfk voici le rapport
              ############################## | UsbFix V6.024 |

              User : loic (Administrateurs) # LAURA
              Update on 01/09/09 by Chiquitine29, C_XX & Chimay8
              Start at: 12:44:17 | 04/09/2009
              Website : http://pagesperso-orange.fr/NosTools/index.html

              Intel(R) Core(TM)2 CPU T5500 @ 1.66GHz
              Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
              Internet Explorer 8.0.6001.18813
              Windows Firewall Status : Enabled

              C:\ -> Disque fixe local # 102,48 Go (23,18 Go free) # NTFS
              D:\ -> Disque amovible
              E:\ -> Disque CD-ROM

              ############################## | Processus actifs |

              C:\Windows\System32\smss.exe
              C:\Windows\system32\csrss.exe
              C:\Windows\system32\wininit.exe
              C:\Windows\system32\csrss.exe
              C:\Windows\system32\services.exe
              C:\Windows\system32\lsass.exe
              C:\Windows\system32\lsm.exe
              C:\Windows\system32\winlogon.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\LogonUI.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\SLsvc.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\Windows\System32\spoolsv.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\Dwm.exe
              C:\Windows\Explorer.EXE
              C:\Windows\system32\taskeng.exe
              C:\Windows\system32\runonce.exe
              C:\Windows\system32\conime.exe
              C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe
              C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
              C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
              C:\Program Files\Bonjour\mDNSResponder.exe
              C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
              C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe
              C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
              C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
              C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
              C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\SearchIndexer.exe
              C:\Windows\system32\DRIVERS\xaudio.exe
              C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
              C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe
              C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
              C:\Windows\system32\WUDFHost.exe
              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              C:\Windows\system32\wbem\wmiprvse.exe

              ################## | Fichiers # Dossiers infectieux |

              ################## | Autres |

              ################## | Suspect ! ... | https://www.virustotal.com/gui/ |

              ################## | Registre # Clés Run infectieuses |

              ################## | Registre # Mountpoints2 |

              Supprimé ! HKCU\...\Explorer\MountPoints2\F\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{069b2515-33eb-11dd-9401-0013a9a72ff0}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{069b2518-33eb-11dd-9401-0013a9a72ff0}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{1c8be406-2cbf-11dd-8c41-0013a9a72ff0}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{288ae069-6009-11dd-9163-0013a9a72ff0}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{2ca998e5-da7a-11dd-8d9f-0019c1b3696b}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{3b996f18-4eaa-11dd-8454-0013a9a72ff0}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{41b1428e-683c-11dd-ab54-0013a9a72ff0}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{41b8ac2f-f2a9-11dc-8aea-935381213e4b}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{4aea49f6-0efd-11de-91c4-0019c1b3696b}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{516097b8-5a21-11dc-a462-0013a9a72ff0}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{516097ba-5a21-11dc-a462-0013a9a72ff0}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{57872fc1-e3d5-11dc-8b94-0019c1b3696b}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{60b9eac7-84c2-11dd-87f3-0019c1b3696b}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{73fc03a1-7e8f-11dd-8380-fce6ccafd6f2}\Shell\Auto\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{771f1b22-2995-11dc-b546-0019c1b3696b}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{7e96b73f-7ee8-11dd-873f-0019c1b3696b}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{831058e4-827b-11dd-b6c6-0019c1b3696b}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{86f4b182-6faa-11dd-9e84-0019c1b3696b}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{90f781dc-a29d-11dc-bc72-0013a9a72ff0}\Shell\Auto\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{9a400fb1-9fa0-11dd-a42c-ca9d34c26d74}\Shell\Auto\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{9a400fb7-9fa0-11dd-a42c-ca9d34c26d74}\Shell\Auto\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{b3451f2a-315f-11dd-af7b-0013a9a72ff0}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{bb0933ad-516f-11dd-80cc-0013a9a72ff0}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{c1e04666-cb7a-11dd-9558-a4a9433284ae}\Shell\Auto\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{c5814d84-87cd-11dd-9835-0013a9a72ff0}\Shell\Auto\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{dd21f8ca-78b8-11dd-a2a2-ba376d8ebdda}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{e0ff4bfa-78b3-11dd-add1-b7dd1cc5a01a}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{e43b52ff-b9e1-11dc-abbd-0013a9a72ff0}\Shell\Auto\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{ee71fd1c-59f2-11dc-8f27-0013a9a72ff0}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{ee71fd2e-59f2-11dc-8f27-0013a9a72ff0}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{f26687e8-5258-11dc-bbbe-0019c1b3696b}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{fbf288ce-6676-11dd-825c-0013a9a72ff0}\Shell\AutoRun\Command

              ################## | Listing des fichiers présent |

              [19/01/2008 09:45|-rahs----|333203] -> C:\bootmgr
              [04/12/2006 21:02|-ra-s----|8192] -> C:\BOOTSECT.BAK
              [05/06/2008 15:20|--a------|889] -> C:\Cucu_Video_log.txt
              [11/05/2009 22:23|--a------|230432] -> C:\PA207.DAT
              [?|?|?] -> C:\pagefile.sys
              [04/09/2009 12:50|--a------|6962] -> C:\UsbFix.txt

              ################## | Cracks / Keygens / Serials |

              ################## | ! Fin du rapport # UsbFix V6.024 ! |

              merci
              0
              1. Contributeur sécurité
                Tu as juste un disque externe ? pas de clés Usb ?

                (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d avoir été infectées sans les ouvrir

                • Fais un clic droit sur le raccourci UsbFix présent sur ton bureau et choisis "éxécuter en tant qu'administrateur" .

                • Au menu principal choisis l'option " F " pour français et tape sur [entrée] .

                • Au second menu Choisis l'option " 2 " ( Suppression ) et tape sur [entrée]

                • Ton bureau disparaitra et le pc redémarrera .

                • Au redémarrage , UsbFix scannera ton pc , laisse travailler l outil.

                • Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .

                • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

                ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
                0
                1. slt jfk cela fais un bout de temps que je n ai pas de nouvelle je voulais savoir si mon pc etais encore infecter ou non merci de ton aide
                  0
              2. salut jfk voici le rapport
                ############################## | UsbFix V6.024 |

                User : loic (Administrateurs) # LAURA
                Update on 01/09/09 by Chiquitine29, C_XX & Chimay8
                Start at: 20:04:59 | 01/09/2009
                Website : http://pagesperso-orange.fr/NosTools/index.html

                Intel(R) Core(TM)2 CPU T5500 @ 1.66GHz
                Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
                Internet Explorer 8.0.6001.18813
                Windows Firewall Status : Enabled

                C:\ -> Disque fixe local # 102,48 Go (21,27 Go free) # NTFS
                D:\ -> Disque amovible
                E:\ -> Disque CD-ROM

                ############################## | Processus actifs |

                C:\Windows\System32\smss.exe
                C:\Windows\system32\csrss.exe
                C:\Windows\system32\wininit.exe
                C:\Windows\system32\csrss.exe
                C:\Windows\system32\services.exe
                C:\Windows\system32\lsass.exe
                C:\Windows\system32\lsm.exe
                C:\Windows\system32\winlogon.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\SLsvc.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                C:\Windows\System32\spoolsv.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\Dwm.exe
                C:\Windows\system32\taskeng.exe
                C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
                C:\Program Files\Bonjour\mDNSResponder.exe
                C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
                C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe
                C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
                C:\Windows\system32\svchost.exe
                C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
                C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
                C:\Windows\Explorer.EXE
                C:\Windows\system32\svchost.exe
                C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
                C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
                C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\system32\SearchIndexer.exe
                C:\Windows\system32\DRIVERS\xaudio.exe
                C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe
                C:\Program Files\Windows Defender\MSASCui.exe
                C:\Program Files\Apoint\Apoint.exe
                C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe
                C:\Program Files\Sony\ISB Utility\ISBMgr.exe
                C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
                C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
                C:\Windows\system32\WUDFHost.exe
                C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
                C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                C:\Windows\PixArt\Pac207\Monitor.exe
                C:\Program Files\Java\jre6\bin\jusched.exe
                C:\Program Files\Windows Sidebar\sidebar.exe
                C:\Program Files\Skype\Phone\Skype.exe
                C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                C:\Windows\ehome\ehtray.exe
                C:\Program Files\Apoint\ApMsgFwd.exe
                C:\Program Files\FileHippo.com\UpdateChecker.exe
                C:\Windows\ehome\ehmsas.exe
                C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
                C:\Program Files\Apoint\Apntex.exe
                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
                C:\Windows\Twain_32\CA561A\SnapDetect.exe
                C:\Windows\System32\mobsync.exe
                C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
                C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
                C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
                C:\Users\loic\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
                C:\Users\loic\AppData\Roaming\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
                C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
                C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
                C:\Windows\system32\taskeng.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                C:\Windows\system32\SearchProtocolHost.exe
                C:\Windows\system32\SearchFilterHost.exe
                C:\Windows\system32\conime.exe
                C:\Windows\system32\wbem\wmiprvse.exe

                ################## | Fichiers # Dossiers infectieux |

                ################## | Suspect ! ... | https://www.virustotal.com/gui/ |

                ################## | Registre # Clés Run infectieuses |

                ################## | Registre # Mountpoints2 |

                HKCU\..\..\Explorer\MountPoints2\F
                shell\AutoRun\command =
                shell\explore\Command =
                shell\open\Command =

                HKCU\..\..\Explorer\MountPoints2\{069b2515-33eb-11dd-9401-0013a9a72ff0}
                shell\AutoRun\command =
                shell\explore\Command =
                shell\open\Command =

                HKCU\..\..\Explorer\MountPoints2\{069b2518-33eb-11dd-9401-0013a9a72ff0}
                shell\AutoRun\command =G:\LaunchU3.exe -a

                HKCU\..\..\Explorer\MountPoints2\{1c8be406-2cbf-11dd-8c41-0013a9a72ff0}
                shell\AutoRun\command =um.cmd
                shell\explore\Command =um.cmd
                shell\open\Command =um.cmd

                HKCU\..\..\Explorer\MountPoints2\{288ae069-6009-11dd-9163-0013a9a72ff0}
                shell\AutoRun\command =
                shell\explore\Command =
                shell\open\Command =

                HKCU\..\..\Explorer\MountPoints2\{2ca998e5-da7a-11dd-8d9f-0019c1b3696b}
                shell\AutoRun\command =G:\SETUP.EXE
                shell\configure\command =G:\SETUP.EXE
                shell\install\command =G:\SETUP.EXE

                HKCU\..\..\Explorer\MountPoints2\{3b996f18-4eaa-11dd-8454-0013a9a72ff0}
                shell\AutoRun\command =um.cmd
                shell\explore\Command =um.cmd
                shell\open\Command =um.cmd

                HKCU\..\..\Explorer\MountPoints2\{41b1428e-683c-11dd-ab54-0013a9a72ff0}
                shell\AutoRun\command =
                shell\explore\Command =
                shell\open\Command =

                HKCU\..\..\Explorer\MountPoints2\{41b8ac2f-f2a9-11dc-8aea-935381213e4b}
                shell\AutoRun\command =
                shell\explore\Command =
                shell\open\Command =

                HKCU\..\..\Explorer\MountPoints2\{4aea49f6-0efd-11de-91c4-0019c1b3696b}
                shell\AutoRun\command =C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe MSdF3E.vbs

                HKCU\..\..\Explorer\MountPoints2\{516097b8-5a21-11dc-a462-0013a9a72ff0}
                shell\AutoRun\command =

                HKCU\..\..\Explorer\MountPoints2\{516097ba-5a21-11dc-a462-0013a9a72ff0}
                shell\AutoRun\command =

                HKCU\..\..\Explorer\MountPoints2\{57872fc1-e3d5-11dc-8b94-0019c1b3696b}
                shell\AutoRun\command =
                shell\explore\Command =
                shell\open\Command =

                HKCU\..\..\Explorer\MountPoints2\{60b9eac7-84c2-11dd-87f3-0019c1b3696b}
                shell\AutoRun\command =q83iwmgf.bat
                shell\explore\Command =q83iwmgf.bat
                shell\open\Command =q83iwmgf.bat

                HKCU\..\..\Explorer\MountPoints2\{73fc03a1-7e8f-11dd-8380-fce6ccafd6f2}
                shell\Auto\command =
                shell\AutoRun\command =C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\Start.exe

                HKCU\..\..\Explorer\MountPoints2\{771f1b22-2995-11dc-b546-0019c1b3696b}
                shell\AutoRun\command =tmf3w3g0.com
                shell\explore\Command =tmf3w3g0.com
                shell\open\Command =tmf3w3g0.com

                HKCU\..\..\Explorer\MountPoints2\{7e96b73f-7ee8-11dd-873f-0019c1b3696b}
                shell\AutoRun\command =um.cmd
                shell\explore\Command =um.cmd
                shell\open\Command =um.cmd

                HKCU\..\..\Explorer\MountPoints2\{831058e4-827b-11dd-b6c6-0019c1b3696b}
                shell\AutoRun\command =
                shell\explore\Command =
                shell\open\Command =

                HKCU\..\..\Explorer\MountPoints2\{86f4b182-6faa-11dd-9e84-0019c1b3696b}
                shell\AutoRun\command =um.cmd
                shell\explore\Command =um.cmd
                shell\open\Command =um.cmd

                HKCU\..\..\Explorer\MountPoints2\{90f781dc-a29d-11dc-bc72-0013a9a72ff0}
                shell\Auto\command =AdobeR.exe e
                shell\AutoRun\command =C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\

                HKCU\..\..\Explorer\MountPoints2\{9a400fb1-9fa0-11dd-a42c-ca9d34c26d74}
                shell\Auto\command =Start.exe
                shell\AutoRun\command =C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe

                HKCU\..\..\Explorer\MountPoints2\{9a400fb7-9fa0-11dd-a42c-ca9d34c26d74}
                shell\Auto\command =
                shell\AutoRun\command =C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\AdobeR.exe e

                HKCU\..\..\Explorer\MountPoints2\{b3451f2a-315f-11dd-af7b-0013a9a72ff0}
                shell\AutoRun\command =
                shell\explore\Command =
                shell\open\Command =

                HKCU\..\..\Explorer\MountPoints2\{bb0933ad-516f-11dd-80cc-0013a9a72ff0}
                shell\AutoRun\command =
                shell\explore\Command =
                shell\open\Command =

                HKCU\..\..\Explorer\MountPoints2\{c1e04666-cb7a-11dd-9558-a4a9433284ae}
                shell\Auto\command =AdobeR.exe e
                shell\AutoRun\command =C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\

                HKCU\..\..\Explorer\MountPoints2\{c5814d84-87cd-11dd-9835-0013a9a72ff0}
                shell\Auto\command =AdobeR.exe e
                shell\AutoRun\command =C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e

                HKCU\..\..\Explorer\MountPoints2\{dd21f8ca-78b8-11dd-a2a2-ba376d8ebdda}
                shell\AutoRun\command =
                shell\explore\Command =
                shell\open\Command =

                HKCU\..\..\Explorer\MountPoints2\{e0ff4bfa-78b3-11dd-add1-b7dd1cc5a01a}
                shell\AutoRun\command =
                shell\explore\Command =
                shell\open\Command =

                HKCU\..\..\Explorer\MountPoints2\{e43b52ff-b9e1-11dc-abbd-0013a9a72ff0}
                shell\Auto\command =AdobeR.exe e
                shell\AutoRun\command =C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\

                HKCU\..\..\Explorer\MountPoints2\{ee71fd1c-59f2-11dc-8f27-0013a9a72ff0}
                shell\AutoRun\command =

                HKCU\..\..\Explorer\MountPoints2\{ee71fd2e-59f2-11dc-8f27-0013a9a72ff0}
                shell\AutoRun\command =G:\VMC_PBStarter.exe

                HKCU\..\..\Explorer\MountPoints2\{f26687e8-5258-11dc-bbbe-0019c1b3696b}
                shell\AutoRun\command =

                HKCU\..\..\Explorer\MountPoints2\{fbf288ce-6676-11dd-825c-0013a9a72ff0}
                shell\AutoRun\command =
                shell\explore\Command =
                shell\open\Command =

                ################## | Cracks / Keygens / Serials |

                ################## | ! Fin du rapport # UsbFix V6.024 ! |

                merci
                0
                1. Contributeur sécurité
                  Désactive l'UAC comme décrit ici : http://pagesperso-orange.fr/FindyKill.Ad.Remover/uac_vista.html

                  • Telecharge et install UsbFix par Chiquitine29

                  (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

                  • Fais un clic droit sur le raccourci UsbFix présent sur ton bureau et choisis "éxécuter en tant qu'administrateur" .

                  • Au menu principal choisis l'option " F " pour français et tape sur [entrée] .

                  • Au second menu Choisis l'option " 1 " (recherche) et tape sur [entrée]

                  • Laisse travailler l outil.

                  • Ensuite post le rapport UsbFix.txt qui apparaitra.

                  • Note : Le rapport UsbFix.txt est sauvegardé à la racine du disque. ( C:\UsbFix.txt )

                  ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                  • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                  Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                  Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

                  • Tuto : http://pagesperso-orange.fr/NosTools/usbfix.html
                  0
                  1. Logfile of random's system information tool 1.06 (written by random/random)
                    Run by loic at 2009-08-29 18:01:49
                    Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
                    System drive C: has 22 GB (21%) free of 105 GB
                    Total RAM: 2045 MB (49% free)

                    Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 18:02:23, on 29/08/2009
                    Platform: Windows Vista SP1 (WinNT 6.00.1905)
                    MSIE: Internet Explorer v8.00 (8.00.6001.18813)
                    Boot mode: Normal

                    Running processes:
                    C:\Windows\system32\taskeng.exe
                    C:\Windows\system32\Dwm.exe
                    C:\Windows\Explorer.EXE
                    C:\Windows\system32\taskeng.exe
                    C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
                    C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe
                    C:\Program Files\Windows Defender\MSASCui.exe
                    C:\Program Files\Apoint\Apoint.exe
                    C:\Program Files\Sony\ISB Utility\ISBMgr.exe
                    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
                    C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                    C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                    C:\Windows\PixArt\Pac207\Monitor.exe
                    C:\Program Files\Java\jre6\bin\jusched.exe
                    C:\Program Files\Windows Sidebar\sidebar.exe
                    C:\Program Files\Skype\Phone\Skype.exe
                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                    C:\Windows\ehome\ehtray.exe
                    C:\Program Files\Apoint\ApMsgFwd.exe
                    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
                    C:\Windows\Twain_32\CA561A\SnapDetect.exe
                    C:\Windows\ehome\ehmsas.exe
                    C:\Users\loic\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
                    C:\Program Files\Apoint\Apntex.exe
                    C:\Users\loic\AppData\Roaming\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
                    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
                    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
                    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
                    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
                    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
                    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
                    C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\Users\loic\Desktop\RSIT.exe
                    C:\Program Files\Trend Micro\HijackThis\loic.exe

                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.com
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                    O1 - Hosts: ::1 localhost
                    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
                    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
                    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
                    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
                    O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
                    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
                    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
                    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                    O4 - HKLM\..\Run: [Monitor] C:\Windows\PixArt\PAC207\Monitor.exe
                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
                    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                    O4 - HKCU\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
                    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                    O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
                    O4 - HKCU\..\Run: [FileHippo.com] "C:\Program Files\FileHippo.com\UpdateChecker.exe" /background
                    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                    O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
                    O4 - Startup: Outil de notification Live Search.lnk = C:\Users\loic\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
                    O4 - Global Startup: Bluetooth Manager.lnk = ?
                    O4 - Global Startup: Icatch(VI) SnapDetect.lnk = ?
                    O8 - Extra context menu item: Ajouter un site de support RSS à VAIO Information FLOW - C:\Program Files\Sony\VAIO Information FLOW\aiesc.html
                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                    O13 - Gopher Prefix:
                    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = laura
                    O17 - HKLM\Software\..\Telephony: DomainName = laura
                    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = laura
                    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = laura
                    O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
                    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                    O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
                    O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
                    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe
                    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AvLib\MSCSPTISRV.exe
                    O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AvLib\PACSPTISVR.exe
                    O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AvLib\SPTISRV.exe
                    O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
                    O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
                    O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                    O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
                    O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
                    O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
                    O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
                    O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
                    O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
                    O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
                    O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
                    O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
                    O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
                    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                    0
                    1. Contributeur sécurité
                      Lu'

                      ça fait un baille ........

                      On va vérifier tout ça :

                      Télécharge ici :

                      http://images.malwareremoval.com/random/RSIT.exe

                      random's system information tool (RSIT) par random/random et sauvegarde-le sur le Bureau.

                      Double-clique sur RSIT.exe afin de lancer RSIT.

                      Lis le contenu de l'écran Disclaimer puis clique sur Continue (si tu acceptes les conditions).

                      Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

                      Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

                      Poste le contenu de log.txt (<<qui sera affiché)
                      ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

                      NB : Les rapports sont sauvegardés dans le dossier C:\rsit

                      Aide en images si besoin
                      0
                      1. bonsoir jfkpresident voici le rapport du mbamMalwarebytes' Anti-Malware 1.40
                        Version de la base de données: 2708
                        Windows 6.0.6001 Service Pack 1

                        28/08/2009 22:38:41
                        mbam-log-2009-08-28 (22-38-41).txt

                        Type de recherche: Examen complet (C:\|D:\|E:\|)
                        Eléments examinés: 459187
                        Temps écoulé: 2 hour(s), 11 minute(s), 40 second(s)

                        Processus mémoire infecté(s): 0
                        Module(s) mémoire infecté(s): 0
                        Clé(s) du Registre infectée(s): 2
                        Valeur(s) du Registre infectée(s): 2
                        Elément(s) de données du Registre infecté(s): 0
                        Dossier(s) infecté(s): 3
                        Fichier(s) infecté(s): 4

                        Processus mémoire infecté(s):
                        (Aucun élément nuisible détecté)

                        Module(s) mémoire infecté(s):
                        (Aucun élément nuisible détecté)

                        Clé(s) du Registre infectée(s):
                        HKEY_CLASSES_ROOT\CLSID\{a77d3539-581d-450c-9e44-a84c415a6172} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a77d3539-581d-450c-9e44-a84c415a6172} (Trojan.FakeAlert) -> Quarantined and deleted successfully.

                        Valeur(s) du Registre infectée(s):
                        HKEY_CURRENT_USER\Environment\avapp (Rogue.PersonalAntiVirus) -> Quarantined and deleted successfully.
                        HKEY_CURRENT_USER\Environment\avuninst (Rogue.PersonalAntiVirus) -> Quarantined and deleted successfully.

                        Elément(s) de données du Registre infecté(s):
                        (Aucun élément nuisible détecté)

                        Dossier(s) infecté(s):
                        C:\Program Files\Common Files\Uninstall\PersonalAV (Rogue.PersonalAntiVirus) -> Quarantined and deleted successfully.
                        C:\Program Files\PersonalAV (Rogue.PersonalAntiVirus) -> Quarantined and deleted successfully.
                        C:\ProgramData\Microsoft\Windows\Start Menu\PersonalAV (Rogue.PersonalAntiVirus) -> Quarantined and deleted successfully.

                        Fichier(s) infecté(s):
                        C:\Program Files\Glary Utilities\encryptexe.exe (Virus.Induc) -> Quarantined and deleted successfully.
                        C:\Program Files\Common Files\Uninstall\PersonalAV\Uninstall.lnk (Rogue.PersonalAntiVirus) -> Quarantined and deleted successfully.
                        C:\ProgramData\Microsoft\Windows\Start Menu\PersonalAV\Personal Antivirus.lnk (Rogue.PersonalAntiVirus) -> Quarantined and deleted successfully.
                        C:\ProgramData\Microsoft\Windows\Start Menu\PersonalAV\Uninstall.lnk (Rogue.PersonalAntiVirus) -> Quarantined and deleted successfully.
                        0
                        1. Contributeur sécurité
                          Bonsoir ;

                          Ton pc est infecté par un rogue .

                          1) Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

                          2) Télécharge Malwarebytes' Anti-Malware (MBAM) et enregistre le sur ton Bureau à partir de ce lien :

                          https://www.malwarebytes.com/

                          3) A la fin du téléchargement, ferme toutes les fenêtres et programmes, y compris celui-ci.

                          4) Double-clique sur l'icône Download_mbam-setup.exe sur ton bureau pour démarrer le programme d'installation.

                          5) Pendant l'installation, suis les indications (en particulier le choix de la langue et l'autorisation d'accession à Internet). N'apporte aucune modification aux réglages par défaut et, en fin d'installation, vérifie que les options Update Malwarebytes' Anti-Malware et Launch Malwarebytes' Anti-Malware sont cochées.

                          6) MBAM démarrera automatiquement et enverra un message demandant à mettre à jour le programme avant de lancer une analyse. Comme MBAM se met automatiquement à jour en fin d'installation, clique sur OK pour fermer la boîte de dialogue. La fenêtre principale de MBAM s'affiche :

                          7) Dans l'onglet analyse, vérifie que "Exécuter un examen complet" est coché et clique sur le bouton Rechercher pour démarrer l'analyse.

                          8) MBAM analyse ton ordinateur. L'analyse peut prendre un certain temps. Il suffit de vérifier de temps en temps son avancement.

                          9) A la fin de l'analyse, un message s'affiche indiquant la fin de l'analyse. Clique sur OK pour poursuivre.

                          10) Si des malwares ont été détectés, leur liste s'affiche.
                          En cliquant sur Suppression (?) , MBAM va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.

                          11) MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Ferme le Bloc-notes. (Le rapport peut être retrouvé sous l'onglet Rapports/logs)

                          12) Ferme MBAM en cliquant sur Quitter.

                          13) Poste le rapport dans ta réponse
                          0