Skintrim

Bonjour,
depuis qq tps avast détecte skintream et je n'arrive pas à m'en débarasser. Est ce que qqun peut m'aider. Merci
Configuration: Windows Vista Internet Explorer 7.0

19 réponses

  1. Contributeur sécurité
    Ok

    tu va télécharger Ccleaner https://www.ccleaner.com/ccleaner/download

    ouvre "Ccleaner" vas dans l'onglet "Option" puis "Avancé" puis décoches "Effacer uniquement les fichiers, du dossier temp de Windows, plus vieux que 48 heures."

    . Puis vas dans l'onglet "Nettoyeur" fais "Analyse" puis "Lancer le nettoyage".
    Puis vas dans l'onglet "Registre" puis fait "Chercher des erreurs" puis "Réparer les erreurs sélectionnée"
    . Tu refais tous ca 4-5 fois (le nettoyage et le registre).

    Puis reste dans "Ccleaner" puis va dans "Option" puis "Propriété" puis coches "Nettoyer automatiquement l'ordinateur au démarrage".

    içi mode d'emploi pour ccleaner

    https://www.malekal.com/tutoriel-ccleaner/
    1. -> Suppression:

      C:\Program Files\Navilog1\Navilog1.bat: supprimé !
      C:\Program Files\Navilog1\catchme.exe: supprimé !
      C:\Program Files\trend micro\HijackThis.exe: supprimé !
      C:\cleannavi.txt: supprimé !
      C:\UsbFix.txt: supprimé !
      C:\Program Files\trend micro\hijackthis.log: supprimé !
      C:\Program Files\Navilog1: supprimé !

      Je crois que j'ai enfin compris : je ne le lançais pas en tant qu'administrateur.
      Merci pour ton aide
      1. Contributeur sécurité
        bonjour

        tu redémarre et tu relance toolscleaner avec un clic droit et exécute le en tant qu'administrateur

        Par Manque De Curiosité On Risque De Mourir Ignorant;Tu es libre de penser que tu es C..,
        Mais C.. de penser que ­tu es libre...Merci a australe13
        1. rapport obtenu après avoir fait 2 fois la procédure
          [ Rapport ToolsCleaner version 2.3.10 (par A.Rothstein & dj QUIOU) ]

          --> Recherche:

          C:\cleannavi.txt: trouvé !
          C:\UsbFix.txt: trouvé !
          C:\Program Files\Navilog1: trouvé !
          C:\Program Files\Navilog1\Navilog1.bat: trouvé !
          C:\Program Files\Navilog1\catchme.exe: trouvé !
          C:\Program Files\trend micro\HijackThis.exe: trouvé !
          C:\Program Files\trend micro\hijackthis.log: trouvé !

          ---------------------------------
          --> Suppression:

          C:\Program Files\Navilog1\Navilog1.bat: ERREUR DE SUPPRESSION !!
          C:\Program Files\Navilog1\catchme.exe: ERREUR DE SUPPRESSION !!
          C:\Program Files\trend micro\HijackThis.exe: ERREUR DE SUPPRESSION !!
          C:\cleannavi.txt: ERREUR DE SUPPRESSION !!
          C:\UsbFix.txt: ERREUR DE SUPPRESSION !!
          C:\Program Files\trend micro\hijackthis.log: ERREUR DE SUPPRESSION !!
          C:\Program Files\Navilog1: ERREUR DE SUPPRESSION !!
          1. Contributeur sécurité
            pour nettoyer les fix qui ont servit

            Ferme toutes les applications en cours, puis télécharge ToolsCleaner2 sur ton Bureau.
            https://www.commentcamarche.net/telecharger/securite/22061-toolscleaner/

            Double clique sur ToolsCleaner2.exe >
            puis Recherche
            et sur Suppression
            Note : ton bureau va disparaître, c'est normal. S'il n'apparaît pas à la fin du scan, fais la manip suivante :

            CTRL+ALT+SUPP pour ouvrir le Gestionnaire des tâches.
            Puis rends toi à l'onglet "Processus". Clique en haut à gauche sur Fichiers et choisis "Exécuter"

            Tape explorer.exe et valide. Cela fera re-apparaître le Bureau

            tu poste le rapport générer après suppression
            1. Fix Navipromo version 4.0.2 commencé le 17/09/2009 22:27:42,22

              !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
              !!! Postez ce rapport sur le forum pour le faire analyser !!!

              Outil exécuté depuis C:\Program Files\navilog1

              Mise à jour le 27.08.2009 à 11h00 par IL-MAFIOSO

              Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
              X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) D CPU 3.00GHz )
              BIOS : Phoenix - AwardBIOS v6.00PG
              USER : André ( Administrator )
              BOOT : Normal boot

              Antivirus : avast! antivirus 4.8.1229 [VPS 081201-0] 4.8.1229 (Activated)

              C:\ (Local Disk) - NTFS - Total:143 Go (Free:69 Go)
              D:\ (Local Disk) - NTFS - Total:5 Go (Free:0 Go)
              E:\ (CD or DVD) - UDF - Total:0 Go (Free:0 Go)
              F:\ (USB)
              G:\ (USB)
              H:\ (USB)
              I:\ (USB)

              Recherche executée en mode normal

              Nettoyage exécuté au redémarrage de l'ordinateur

              C:\Users\Andr‚\AppData\Local\eamkcio.dat supprimé !

              Nettoyage contenu C:\Windows\Temp effectué !
              Nettoyage contenu C:\Users\ANDR~1\AppData\Local\Temp effectué !

              *** Sauvegarde du Registre vers dossier Safebackup ***

              sauvegarde du Registre réalisée avec succès !

              *** Nettoyage Registre ***

              Nettoyage Registre Ok

              Certificat Egroup supprimé !
              Certificat Electronic-Group supprimé !
              Certificat OOO-Favorit supprimé !

              *** Scan terminé 17/09/2009 22:51:30,34 ***
              1. Contributeur sécurité
                télécharge navilog1 sur le bureau :
                http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

                1° clique droit sur navilog1.exe présent sur ton bureau et excute le en tant qu'administrateur
                2° Sélectionnez la langue désirée dans le menu puis valide le choix par la touche « entrer »
                3° Petit message d’avertissement, appuie sur une touche pour passe à la suite
                4° un nouveau avertissement, appuie sur une touche pour suivre
                5° Vérification de l’installation de Navilog1 : si tout est bon, appuie sur une touche pour continuer
                6° Choisir option 1 : recherche/désinfection automatique
                7° La recherche va se lancer automatiquement et peut durée quelques minutes, patiente
                8° Une fois l’analyse terminé, fermez et enregistre ton travail en cours, puis appuie sur une touche pour que le pc puisse démarrer
                9° Au redémarrage du pc, Navilog va supprimer ce qu’il a trouvé, patiente quelques instants.

                Un rapport est génère par l'outil. Il se trouve à cette emplacement :

                démarrer »/ordinateur/c:/ cleannavi.txt
                1. Désolé de ne pas avoir répondu plus vite mais j'étais au travail.

                  Malwarebytes' Anti-Malware 1.41
                  Version de la base de données: 2812
                  Windows 6.0.6001 Service Pack 1

                  16/09/2009 20:40:10
                  mbam-log-2009-09-16 (20-40-10).txt

                  Type de recherche: Examen complet (C:\|D:\|)
                  Eléments examinés: 271358
                  Temps écoulé: 1 hour(s), 12 minute(s), 32 second(s)

                  Processus mémoire infecté(s): 0
                  Module(s) mémoire infecté(s): 0
                  Clé(s) du Registre infectée(s): 2
                  Valeur(s) du Registre infectée(s): 1
                  Elément(s) de données du Registre infecté(s): 0
                  Dossier(s) infecté(s): 0
                  Fichier(s) infecté(s): 3

                  Processus mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Module(s) mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Clé(s) du Registre infectée(s):
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\fcn (Rogue.Residue) -> Quarantined and deleted successfully.

                  Valeur(s) du Registre infectée(s):
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\eamkcio (Trojan.Agent.H) -> Quarantined and deleted successfully.

                  Elément(s) de données du Registre infecté(s):
                  (Aucun élément nuisible détecté)

                  Dossier(s) infecté(s):
                  (Aucun élément nuisible détecté)

                  Fichier(s) infecté(s):
                  c:\Users\André\AppData\Local\eamkcio.exe (Trojan.Agent.H) -> Delete on reboot.
                  C:\Users\André\Local Settings\Application Data\eamkcio_nav.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
                  C:\Users\André\Local Settings\Application Data\eamkcio_navps.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.

                  Logfile of random's system information tool 1.06 (written by random/random)
                  Run by André at 2009-09-17 21:01:07
                  Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
                  System drive C: has 71 GB (48%) free of 147 GB
                  Total RAM: 1014 MB (26% free)

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 21:01:50, on 17/09/2009
                  Platform: Windows Vista SP1 (WinNT 6.00.1905)
                  MSIE: Internet Explorer v8.00 (8.00.6001.18813)
                  Boot mode: Normal

                  Running processes:
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\Explorer.EXE
                  C:\Windows\System32\mobsync.exe
                  C:\Program Files\Windows Defender\MSASCui.exe
                  C:\hp\support\hpsysdrv.exe
                  C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
                  C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                  C:\Windows\RtHDVCpl.exe
                  C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                  C:\Program Files\QuickTime\qttask.exe
                  C:\Program Files\iTunes\iTunesHelper.exe
                  C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                  C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
                  C:\Windows\System32\hkcmd.exe
                  C:\Windows\System32\igfxpers.exe
                  C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                  C:\Program Files\Java\jre6\bin\jusched.exe
                  C:\Windows\system32\igfxsrvc.exe
                  C:\Program Files\Windows Sidebar\sidebar.exe
                  C:\Windows\ehome\ehtray.exe
                  C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  C:\Program Files\Windows Mail\WinMail.exe
                  C:\Windows\ehome\ehmsas.exe
                  C:\Program Files\Windows Live\Contacts\wlcomm.exe
                  C:\hp\kbd\kbd.exe
                  C:\Windows\system32\wuauclt.exe
                  C:\Program Files\Google\Chrome\Application\chrome.exe
                  C:\Program Files\Google\Chrome\Application\chrome.exe
                  C:\Program Files\Google\Chrome\Application\chrome.exe
                  C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
                  C:\Windows\system32\NOTEPAD.EXE
                  C:\Program Files\Google\Chrome\Application\chrome.exe
                  C:\Users\André\Documents\Downloads\RSIT (1).exe
                  C:\Program Files\trend micro\André.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                  R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                  O1 - Hosts: ::1 localhost
                  O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                  O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                  O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                  O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                  O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: BHO Barre de Confiance - {988B07F5-7392-455A-8A1F-64935CB8B6ED} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                  O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                  O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                  O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                  O3 - Toolbar: Barre de confiance - {55BDF3B0-C0A8-481A-B8A6-01CD2BE0F3FD} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
                  O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                  O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                  O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                  O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
                  O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
                  O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
                  O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
                  O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                  O4 - HKLM\..\Run: [CCUTRAYICON] FactoryMode
                  O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
                  O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                  O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                  O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                  O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
                  O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
                  O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                  O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                  O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
                  O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
                  O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                  O13 - Gopher Prefix:
                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                  O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
                  O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                  O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
                  O23 - Service: Service Google Update (gupdate1c9ae565ffe3ec0) (gupdate1c9ae565ffe3ec0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                  O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                  O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe
                  O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                  O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                  O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
                  O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
                  O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                  O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
                  O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                  O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
                  1. Contributeur sécurité
                    SALUT

                    tu peut m'envoyer le rapport malwarbyte et un nouveau rapport rsit
                    1. Contributeur sécurité
                      envoie le fichier comme demander a la fin du rapport

                      télécharge malwarbyte http://www.malwarebytes.org/mbam/program/mbam-setup.exe

                      a l'installation vérifie que mise a jour et lancer programme et scan complet sont bien cocher


                      Une fois a jour, le programme va se lancer; clic sur l´onglet paramètre, et coche la case : "Arrêter internet explorer pendant la suppression".

                      A la fin du scan clique sur Afficher les résultats

                      Suppression des éléments détectés >>>> clique sur Supprimer la sélection ou supprimer tout
                      S'il t'es demandé de redémarrer >>> clique sur "Yes"


                      Et tu poste le rapport générer

                      Par Manque De Curiosité On Risque De Mourir Ignorant;Tu es libre de penser que tu es C..,
                      Mais C.. de penser que ­tu es libre...Merci a australe13
                      1. Et voila ...

                        ############################## | UsbFix V6.033 |

                        User : André (Administrateurs) # PC-DE-BUREAU
                        Update on 14/09/2009 by Chiquitine29, C_XX & Chimay8
                        Start at: 19:00:05 | 16/09/2009
                        Website : http://pagesperso-orange.fr/NosTools/index.html

                        Intel(R) Pentium(R) D CPU 3.00GHz
                        Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
                        Internet Explorer 8.0.6001.18813
                        Windows Firewall Status : Enabled
                        AV : avast! antivirus 4.8.1229 [VPS 081201-0] 4.8.1229 [ Enabled | Updated ]

                        C:\ -> Disque fixe local # 143,88 Go (70,43 Go free) [HP] # NTFS
                        D:\ -> Disque fixe local # 5,17 Go (899,61 Mo free) [Recovery] # NTFS
                        E:\ -> Disque CD-ROM # 621,05 Mo (0 Mo free) [BOMPARD] # UDF
                        F:\ -> Disque amovible
                        G:\ -> Disque amovible
                        H:\ -> Disque amovible
                        I:\ -> Disque amovible
                        J:\ -> Disque amovible # 976,12 Mo (914,78 Mo free) # FAT

                        ############################## | Processus actifs |

                        C:\Windows\System32\smss.exe
                        C:\Windows\system32\csrss.exe
                        C:\Windows\system32\wininit.exe
                        C:\Windows\system32\csrss.exe
                        C:\Windows\system32\services.exe
                        C:\Windows\system32\lsass.exe
                        C:\Windows\system32\lsm.exe
                        C:\Windows\system32\winlogon.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\system32\LogonUI.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\SLsvc.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        C:\Windows\System32\spoolsv.exe
                        C:\Windows\system32\svchost.exe
                        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                        C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
                        C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                        c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                        C:\Windows\system32\svchost.exe
                        C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                        C:\Windows\system32\svchost.exe
                        C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\system32\SearchIndexer.exe
                        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        C:\Windows\system32\WUDFHost.exe
                        C:\Windows\system32\taskeng.exe
                        C:\Windows\system32\taskeng.exe
                        C:\Windows\system32\userinit.exe
                        C:\Windows\system32\Dwm.exe
                        C:\Windows\Explorer.EXE
                        C:\Windows\system32\runonce.exe
                        C:\Windows\system32\conime.exe
                        C:\Windows\system32\wbem\wmiprvse.exe

                        ################## | Fichiers # Dossiers infectieux |

                        Supprimé ! D:\desktop.ini

                        ################## | Registre # Clés Run infectieuses |

                        ################## | Registre # Mountpoints2 |

                        Supprimé ! HKCU\...\Explorer\MountPoints2\{12a7651c-ba35-11dd-9f1f-001a925d23a3}\Shell\Auto\Command
                        Supprimé ! HKCU\...\Explorer\MountPoints2\{7e9c44f4-bc8e-11dc-b309-001a925d23a3}\Shell\AutoRun\Command
                        Supprimé ! HKCU\...\Explorer\MountPoints2\{e623e40c-8344-11de-9048-001a925d23a3}\Shell\Auto\Command

                        ################## | Listing des fichiers présent |

                        [18/09/2006 23:43|--a------|24] C:\autoexec.bat
                        [19/01/2008 09:45|-rahs----|333203] C:\bootmgr
                        [31/10/2008 01:57|-ra-s----|8192] C:\BOOTSECT.BAK
                        [18/09/2006 23:43|--a------|10] C:\config.sys
                        [16/05/2007 17:49|---hs----|5381] C:\ffastun.ffa
                        [16/05/2007 17:49|---hs----|188416] C:\ffastun.ffl
                        [16/05/2007 17:49|--ah-----|86016] C:\ffastun.ffo
                        [16/05/2007 17:49|---hs----|4608000] C:\ffastun0.ffx
                        [?|?|?] C:\hiberfil.sys
                        [16/05/2007 17:40|-rahs----|0] C:\IO.SYS
                        [16/05/2007 17:40|-rahs----|0] C:\MSDOS.SYS
                        [?|?|?] C:\pagefile.sys
                        [30/10/2008 17:14|--a------|402] C:\RHDSetup.log
                        [16/09/2009 19:03|--a------|3837] C:\UsbFix.txt
                        [04/10/2006 01:02|--ahs----|438328] D:\boo.mgr
                        [02/11/2006 02:53|--ahs----|438840] D:\bootmgr
                        [16/05/2007 17:47|--ah-----|4109] D:\ffastun.ffa
                        [16/05/2007 17:47|--ah-----|8192] D:\ffastun.ffl
                        [16/05/2007 17:47|--ah-----|4096] D:\ffastun.ffo
                        [16/05/2007 17:47|--ah-----|4096] D:\ffastun0.ffx
                        [31/10/2008 03:08|--ahs----|106] D:\MASTER.LOG
                        [15/05/2007 21:17|--ah-----|487] D:\pcdr.ini
                        [10/09/2002 14:58|--ahs----|181616] D:\Protect.ed
                        [31/10/2008 03:08|--ahs----|44] D:\RESTORE.INI
                        [18/10/2006 12:09|--ahs----|34] D:\SystemRecovery.txt

                        ################## | Upload |

                        Veuillez envoyer le fichier : C:\Users\ANDR~1\Desktop\UsbFix_Upload_Me_PC-de-bureau.zip : https://www.androidworld.fr/
                        Merci pour votre contribution .
                        1. Contributeur sécurité
                          relance usbfix

                          Choisie l'option 2(Suppression)toujours avec un clique droit et exécute le en tant qu'administrateur

                          Le bureau disparait et le pc redémarre
                          Patiente le temps du scan.
                          le rapport UsbFix.txt est sauvegardé à la racine du disque
                          Faites en un copier/coller dans le bloc notes pour le poster.
                          1. VOILA LE RAPPORT USBFIX.TXT
                            Merci
                            ############################## | UsbFix V6.033 |

                            User : André (Administrateurs) # PC-DE-BUREAU
                            Update on 14/09/2009 by Chiquitine29, C_XX & Chimay8
                            Start at: 18:05:54 | 16/09/2009
                            Website : http://pagesperso-orange.fr/NosTools/index.html

                            Intel(R) Pentium(R) D CPU 3.00GHz
                            Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
                            Internet Explorer 8.0.6001.18813
                            Windows Firewall Status : Enabled
                            AV : avast! antivirus 4.8.1229 [VPS 081201-0] 4.8.1229 [ Enabled | Updated ]

                            C:\ -> Disque fixe local # 143,88 Go (70,5 Go free) [HP] # NTFS
                            D:\ -> Disque fixe local # 5,17 Go (899,61 Mo free) [Recovery] # NTFS
                            E:\ -> Disque CD-ROM # 621,05 Mo (0 Mo free) [BOMPARD] # UDF
                            F:\ -> Disque amovible
                            G:\ -> Disque amovible
                            H:\ -> Disque amovible
                            I:\ -> Disque amovible
                            J:\ -> Disque amovible # 976,12 Mo (914,78 Mo free) # FAT

                            ############################## | Processus actifs |

                            C:\Windows\System32\smss.exe
                            C:\Windows\system32\csrss.exe
                            C:\Windows\system32\csrss.exe
                            C:\Windows\system32\wininit.exe
                            C:\Windows\system32\services.exe
                            C:\Windows\system32\lsass.exe
                            C:\Windows\system32\lsm.exe
                            C:\Windows\system32\winlogon.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\System32\svchost.exe
                            C:\Windows\System32\svchost.exe
                            C:\Windows\System32\svchost.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\system32\SLsvc.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\system32\svchost.exe
                            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                            C:\Program Files\Alwil Software\Avast4\ashServ.exe
                            C:\Windows\System32\spoolsv.exe
                            C:\Windows\system32\svchost.exe
                            C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                            C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
                            C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                            c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                            C:\Windows\system32\svchost.exe
                            C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                            C:\Windows\system32\svchost.exe
                            C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
                            C:\Windows\System32\svchost.exe
                            C:\Windows\system32\SearchIndexer.exe
                            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                            C:\Windows\system32\WUDFHost.exe
                            C:\Windows\system32\taskeng.exe
                            C:\Windows\system32\Dwm.exe
                            C:\Windows\system32\taskeng.exe
                            C:\Windows\Explorer.EXE
                            C:\Program Files\Windows Defender\MSASCui.exe
                            C:\hp\support\hpsysdrv.exe
                            C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
                            C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                            C:\Windows\RtHDVCpl.exe
                            C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                            C:\Program Files\QuickTime\qttask.exe
                            C:\Program Files\iTunes\iTunesHelper.exe
                            C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                            C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
                            C:\Windows\System32\igfxpers.exe
                            C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                            C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
                            C:\Program Files\Java\jre6\bin\jusched.exe
                            C:\Program Files\Windows Sidebar\sidebar.exe
                            C:\Windows\ehome\ehtray.exe
                            C:\Windows\system32\igfxsrvc.exe
                            C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
                            C:\Users\André\AppData\Local\eamkcio.exe
                            C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                            C:\Program Files\iPod\bin\iPodService.exe
                            C:\Windows\ehome\ehmsas.exe
                            C:\Program Files\vghd\VirtuaGirl_downloader.exe
                            C:\Windows\system32\wbem\wmiprvse.exe
                            C:\Program Files\Windows Mail\WinMail.exe
                            C:\Program Files\Windows Live\Contacts\wlcomm.exe
                            C:\Windows\system32\wbem\wmiprvse.exe
                            C:\hp\kbd\kbd.exe
                            C:\Program Files\Google\Chrome\Application\chrome.exe
                            C:\Program Files\Google\Chrome\Application\chrome.exe
                            C:\Windows\system32\wuauclt.exe
                            C:\Windows\system32\conime.exe

                            ################## | Fichiers # Dossiers infectieux |

                            D:\desktop.ini

                            ################## | Registre # Clés Run infectieuses |

                            ################## | Registre # Mountpoints2 |

                            HKCU\..\..\Explorer\MountPoints2\{12a7651c-ba35-11dd-9f1f-001a925d23a3}
                            shell\Auto\command =cmd /C launch.bat
                            shell\AutoRun\command =C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL cmd /C launch.bat

                            HKCU\..\..\Explorer\MountPoints2\{7e9c44f4-bc8e-11dc-b309-001a925d23a3}
                            shell\AutoRun\command =J:\InstallTomTomHOME.exe

                            HKCU\..\..\Explorer\MountPoints2\{e623e40c-8344-11de-9048-001a925d23a3}
                            shell\Auto\command =J:\launcher.exe
                            shell\AutoRun\command =C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL J:\launcher.exe

                            ################## | ! Fin du rapport # UsbFix V6.033 ! |
                            1. Contributeur sécurité
                              Télécharge et installe UsbFix de C_XX & Chiquitine29 :

                              Tu utilises vista, tu dois donc désactiver l'UAC avant d'utiliser ces logiciels.

                              # Désactiver le contrôle des comptes utilisateurs (le réactiver à la fin de la désinfection) :
                              # Aller dans démarrer puis Panneau de configuration.
                              # Double-cliquer sur l'icône "Comptes d'utilisateurs".
                              # Cliquer ensuite sur désactiver et valider.

                              ici un tuto

                              https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

                              lien de téléchargement


                              http://sd-1.archive-host.com/membres/up/127028005715545653/UsbFix.exe

                              Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...)sans les ouvrir !

                              *fait un clique droit sur UsbFix.exe présent sur le bureau.et exécute le en tant qu'administrateur

                              Tape F pour français , et pressez enter pour valider

                              Dans le second menu qui apparait

                              * Choisis l’option 1 (Recherche)

                              * Laisse travailler l’outil.cela peut prendre plusieurs minutes, soit patient
                              * Ensuite poste l’intégralité du rapport UsbFix.txt qui apparaîtra.

                              Notes :
                              - Le rapport UsbFix.txt est sauvegardé a la racine du disque. (C:\UsbFix.txt)

                              (CTRL+A Pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller sur le forum).

                              - "Process.exe", une composante de l’outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s’agit pas d’un virus, mais d’un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d’où l’alerte émise par ces antivirus.
                              1. Logfile of random's system information tool 1.06 (written by random/random)
                                Run by André at 2009-09-16 17:00:14
                                Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
                                System drive C: has 73 GB (49%) free of 147 GB
                                Total RAM: 1014 MB (18% free)

                                Logfile of Trend Micro HijackThis v2.0.2
                                Scan saved at 17:01:36, on 16/09/2009
                                Platform: Windows Vista SP1 (WinNT 6.00.1905)
                                MSIE: Internet Explorer v8.00 (8.00.6001.18813)
                                Boot mode: Normal

                                Running processes:
                                C:\Windows\system32\Dwm.exe
                                C:\Windows\system32\taskeng.exe
                                C:\Windows\Explorer.EXE
                                C:\Program Files\Windows Defender\MSASCui.exe
                                C:\hp\support\hpsysdrv.exe
                                C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
                                C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                                C:\Windows\RtHDVCpl.exe
                                C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                                C:\Program Files\QuickTime\qttask.exe
                                C:\Program Files\iTunes\iTunesHelper.exe
                                C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                                C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
                                C:\Windows\System32\hkcmd.exe
                                C:\Windows\System32\igfxpers.exe
                                C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                                C:\Program Files\Windows Sidebar\sidebar.exe
                                C:\Windows\ehome\ehtray.exe
                                C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
                                C:\Users\André\AppData\Local\eamkcio.exe
                                C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                C:\Windows\system32\igfxsrvc.exe
                                C:\Windows\ehome\ehmsas.exe
                                C:\Program Files\vghd\VirtuaGirl_downloader.exe
                                C:\Program Files\Windows Live\Contacts\wlcomm.exe
                                C:\hp\kbd\kbd.exe
                                C:\Program Files\Windows Mail\WinMail.exe
                                C:\Windows\system32\wuauclt.exe
                                C:\Program Files\Google\Chrome\Application\chrome.exe
                                C:\Program Files\Google\Chrome\Application\chrome.exe
                                C:\Program Files\Google\Chrome\Application\chrome.exe
                                C:\Program Files\Google\Chrome\Application\chrome.exe
                                C:\Users\André\Documents\Downloads\RSIT.exe
                                C:\Windows\system32\SearchFilterHost.exe
                                C:\Program Files\trend micro\André.exe
                                C:\Windows\System32\wsqmcons.exe

                                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/webhp?gws_rd=ssl#max4
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                O1 - Hosts: ::1 localhost
                                O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                                O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                                O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                                O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                O2 - BHO: BHO Barre de Confiance - {988B07F5-7392-455A-8A1F-64935CB8B6ED} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
                                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                                O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                                O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                                O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                                O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                                O3 - Toolbar: Barre de confiance - {55BDF3B0-C0A8-481A-B8A6-01CD2BE0F3FD} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
                                O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                                O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
                                O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
                                O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
                                O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
                                O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                                O4 - HKLM\..\Run: [CCUTRAYICON] FactoryMode
                                O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                O4 - HKLM\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALuNotify.exe
                                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
                                O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                                O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                                O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                                O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                                O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
                                O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                                O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
                                O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
                                O4 - HKCU\..\Run: [eamkcio] "c:\users\andré\appdata\local\eamkcio.exe" eamkcio
                                O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                                O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                O4 - Startup: DesktopVideoPlayer.LNK = C:\Program Files\vghd\vghd.exe
                                O13 - Gopher Prefix:
                                O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://ushousecall02.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
                                O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                                O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
                                O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                                O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
                                O23 - Service: Service Google Update (gupdate1c9ae565ffe3ec0) (gupdate1c9ae565ffe3ec0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                                O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                                O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe
                                O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
                                O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
                                O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
                                O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                                O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
                                O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                                O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
                                1. Contributeur sécurité
                                  salut

                                  Télécharge ici :

                                  http://images.malwareremoval.com/random/RSIT.exe

                                  random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

                                  Double-clique sur RSIT.exe afin de lancer RSIT.

                                  Clique Continue à l'écran Disclaimer.

                                  Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

                                  Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

                                  Poste le contenu de log.txt (<<qui sera affiché)
                                  ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

                                  NB : Les rapports sont sauvegardés dans le dossier C:\rsit