Virus "Internet Security"

Bonjour à tous,

Il semblerait que mon PC soit touché par un virus. Quand je l'allume, il y a un message d'erreur et un antivirus ("internet security") se lance. Je soupçonne que c'est 'lui' le virus étant donné que je ne l'ai jamais installé et que, comme par hasrad, il me demande payer pour éliminer les virus détectés.

J'ai essayé de le cupprimer normalement - en mettant les applis "Internet Security" dans la Corbeil mais il ne s'agissait que de raccourcis et du coup, ça ne changeait rien.

Qu'est-ce que je peux faire ? :/

Merci d'avance !!
Configuration: Windows XP Internet Explorer 7.0

10 réponses

  1. Contributeur sécurité
    ok bonne suite!

    mettre un antivirus

    ANTIVIR ou AVG8 ou (AVAST ) ou Microsoft Security Essentials

    http://forum.telecharger.01net.com/forum/high-tech/PRODUITS/Questions-techniques/antivir-installation-configuration-sujet_201938_1.htm
    https://www.avira.com/fr/free-antivirus-windows
    -------------
    des anti-espions :
    MalwareByte's Anti-Malware + SPYBOT +/- si tea timer non active de spybot:
    WINDOWS DEFENDER ou SPYWARE TERMINATOR ou SPYWARE GUARD
    +
    SPYWAREBLASTER pour immuniser le système contre vundo notamment mais en anglais (mais facile d'utilisation : il suffit de faire "update" pour mettre à jour tous les mois et ensuite" enable all protection" pour immuniser)...

    Rq : spybot … sortent de nouvelles versions régulièrement, vérifiez que vous avez la dernière version
    --------
    un pare feu :
    celui de (Windows) ou mieux Online armor ou KERIO ou JETICO ou ZONE ALARM (mettre que le parefeu gratuit) ou COMODO

    https://www.commentcamarche.net/telecharger/securite/16545-online-armor-personal-firewall/
    https://www.01net.com/telecharger/windows/Securite/firewall/fiches/39911.html
    https://forum.pcastuces.com/sujet.asp?f=25&s=35606
    https://www.clubic.com/telecharger-fiche11071-sunbelt-personal-firewall-ex-kerio.html
    https://manuelsdaide.com/contact/
    http://www.open-files.com/forum/index.php?showtopic=29277
    https://www.01net.com/telecharger/windows/Securite/firewall/fiches/18128.html
    https://www.zonealarm.com/software/free-firewall

    -----------
    CCLEANER pour effacer les traces de surf
    ---------
    naviguer avec firefox ou safari ou opera et non internet explorer plus touché par les virus
    http://www.mozilla-europe.org/fr/products/firefox/
    0
    1. Contributeur sécurité
      Téléchargez Tools Cleaner 2 sur votre bureau ici: https://www.commentcamarche.net/telecharger/securite/22061-toolscleaner/

      * Double-cliquez sur Tools Cleaner2 pour l’exécuter. (Si vous êtes sous Vista, cliquez droit sur le fichier Tools Cleaner 2 et exécutez-le en tant qu'administrateur.)
      * Cliquez sur Recherche et laissez-la se dérouler
      * Cliquez sur Suppression pour finaliser.
      * Vous pouvez, si vous le souhaitez, vous servir des Options facultatives.
      * Cliquez sur Quitter pour obtenir le rapport.
      * Postez le rapport (TCleaner.txt) qui se trouve à la racine de votre disque dur (C:) dans le forum où cela vous a été demandé.

      ____________________

      désactive ta restauration puis redemarre ton pc puis réactive la

      https://docs.microsoft.com/en-us/

      _______________________________

      dis si encore des soucis et explique
      0
      1. Le rapport de TCleaner :

        [ Rapport ToolsCleaner version 2.3.11 (par A.Rothstein & dj QUIOU) ]

        --> Recherche:

        C:\_OTM: trouvé !
        C:\Rsit: trouvé !
        C:\Documents and Settings\HP_Administrateur\Bureau\OTM.exe: trouvé !
        C:\Documents and Settings\HP_Administrateur\Bureau\Rsit.exe: trouvé !
        C:\Program Files\Trend Micro\HijackThis.exe: trouvé !
        C:\Program Files\Trend Micro\hijackthis.log: trouvé !

        ---------------------------------
        --> Suppression:

        C:\Documents and Settings\HP_Administrateur\Bureau\OTM.exe: supprimé !
        C:\Program Files\Trend Micro\HijackThis.exe: supprimé !
        C:\Documents and Settings\HP_Administrateur\Bureau\Rsit.exe: supprimé !
        C:\Program Files\Trend Micro\hijackthis.log: supprimé !
        C:\_OTM: supprimé !
        C:\Rsit: supprimé !

        Et je m'occupe de la restauration système
        0
      2. Ca y est, j'ai fait le redémarrage comme tu me l'as dit et apparemment, tout a l'air de bien fonctionner !

        eh bien merci pour tout :)
        0
    2. Contributeur sécurité
      colle un rapport avec antivir
      0
      1. Il est en train de tourner, ça risque de prendre un petit bout de temps !

        en tout cas merci, pour ton aide !!

        Je poste le rapport dès que le scan est fini
        0
      2. Voici le rapport d'Antivir :

        Avira AntiVir Personal
        Date de création du fichier de rapport : mardi 12 janvier 2010 18:38

        La recherche porte sur 1525403 souches de virus.

        Détenteur de la licence : Avira AntiVir Personal - FREE Antivirus
        Numéro de série : 0000149996-ADJIE-0000001
        Plateforme : Windows XP
        Version de Windows : (Service Pack 3) [5.1.2600]
        Mode Boot : Démarré normalement
        Identifiant : SYSTEM
        Nom de l'ordinateur : NOM-FB9B15D2723

        Informations de version :
        BUILD.DAT : 9.0.0.74 21698 Bytes 04/12/2009 13:56:00
        AVSCAN.EXE : 9.0.3.10 466689 Bytes 20/11/2009 12:45:51
        AVSCAN.DLL : 9.0.3.0 49409 Bytes 03/03/2009 09:21:02
        LUKE.DLL : 9.0.3.2 209665 Bytes 20/02/2009 10:35:11
        LUKERES.DLL : 9.0.2.0 13569 Bytes 03/03/2009 09:21:31
        VBASE000.VDF : 7.10.0.0 19875328 Bytes 06/11/2009 12:45:51
        VBASE001.VDF : 7.10.1.0 1372672 Bytes 19/11/2009 12:45:51
        VBASE002.VDF : 7.10.1.1 2048 Bytes 19/11/2009 12:45:51
        VBASE003.VDF : 7.10.1.2 2048 Bytes 19/11/2009 12:45:51
        VBASE004.VDF : 7.10.1.3 2048 Bytes 19/11/2009 12:45:51
        VBASE005.VDF : 7.10.1.4 2048 Bytes 19/11/2009 12:45:51
        VBASE006.VDF : 7.10.1.5 2048 Bytes 19/11/2009 12:45:51
        VBASE007.VDF : 7.10.1.6 2048 Bytes 19/11/2009 12:45:51
        VBASE008.VDF : 7.10.1.7 2048 Bytes 19/11/2009 12:45:51
        VBASE009.VDF : 7.10.1.8 2048 Bytes 19/11/2009 12:45:51
        VBASE010.VDF : 7.10.1.9 2048 Bytes 19/11/2009 12:45:51
        VBASE011.VDF : 7.10.1.10 2048 Bytes 19/11/2009 12:45:51
        VBASE012.VDF : 7.10.1.11 2048 Bytes 19/11/2009 12:45:51
        VBASE013.VDF : 7.10.1.79 209920 Bytes 25/11/2009 17:03:34
        VBASE014.VDF : 7.10.1.128 197632 Bytes 30/11/2009 16:07:10
        VBASE015.VDF : 7.10.1.178 195584 Bytes 07/12/2009 17:11:04
        VBASE016.VDF : 7.10.1.224 183296 Bytes 14/12/2009 21:28:14
        VBASE017.VDF : 7.10.1.247 182272 Bytes 15/12/2009 11:52:16
        VBASE018.VDF : 7.10.2.30 198144 Bytes 21/12/2009 17:12:26
        VBASE019.VDF : 7.10.2.63 187392 Bytes 24/12/2009 17:26:28
        VBASE020.VDF : 7.10.2.93 195072 Bytes 29/12/2009 12:17:36
        VBASE021.VDF : 7.10.2.131 201216 Bytes 07/01/2010 16:34:10
        VBASE022.VDF : 7.10.2.158 192000 Bytes 11/01/2010 17:38:22
        VBASE023.VDF : 7.10.2.159 2048 Bytes 11/01/2010 17:38:23
        VBASE024.VDF : 7.10.2.160 2048 Bytes 11/01/2010 17:38:23
        VBASE025.VDF : 7.10.2.161 2048 Bytes 11/01/2010 17:38:23
        VBASE026.VDF : 7.10.2.162 2048 Bytes 11/01/2010 17:38:23
        VBASE027.VDF : 7.10.2.163 2048 Bytes 11/01/2010 17:38:23
        VBASE028.VDF : 7.10.2.164 2048 Bytes 11/01/2010 17:38:23
        VBASE029.VDF : 7.10.2.165 2048 Bytes 11/01/2010 17:38:23
        VBASE030.VDF : 7.10.2.166 2048 Bytes 11/01/2010 17:38:23
        VBASE031.VDF : 7.10.2.175 143872 Bytes 12/01/2010 17:38:23
        Version du moteur : 8.2.1.134
        AEVDF.DLL : 8.1.1.2 106867 Bytes 16/09/2009 15:41:20
        AESCRIPT.DLL : 8.1.3.7 594296 Bytes 05/01/2010 16:54:38
        AESCN.DLL : 8.1.3.0 127348 Bytes 10/12/2009 18:07:29
        AESBX.DLL : 8.1.1.1 246132 Bytes 20/11/2009 12:45:51
        AERDL.DLL : 8.1.3.4 479605 Bytes 01/12/2009 16:07:13
        AEPACK.DLL : 8.2.0.4 422263 Bytes 05/01/2010 16:54:33
        AEOFFICE.DLL : 8.1.0.38 196987 Bytes 18/06/2009 14:57:46
        AEHEUR.DLL : 8.1.0.194 2228599 Bytes 09/01/2010 17:03:56
        AEHELP.DLL : 8.1.9.0 237943 Bytes 17/12/2009 15:20:41
        AEGEN.DLL : 8.1.1.83 369014 Bytes 05/01/2010 16:40:42
        AEEMU.DLL : 8.1.1.0 393587 Bytes 05/10/2009 15:20:33
        AECORE.DLL : 8.1.9.1 180598 Bytes 10/12/2009 18:07:28
        AEBB.DLL : 8.1.0.3 53618 Bytes 09/10/2008 13:32:40
        AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 07:47:30
        AVPREF.DLL : 9.0.3.0 44289 Bytes 26/09/2009 16:54:45
        AVREP.DLL : 8.0.0.3 155905 Bytes 20/01/2009 13:34:28
        AVREG.DLL : 9.0.0.0 36609 Bytes 07/11/2008 14:24:42
        AVARKT.DLL : 9.0.0.3 292609 Bytes 24/03/2009 14:05:22
        AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 30/01/2009 09:36:37
        SQLITE3.DLL : 3.6.1.0 326401 Bytes 28/01/2009 14:03:49
        SMTPLIB.DLL : 9.2.0.25 28417 Bytes 02/02/2009 07:20:57
        NETNT.DLL : 9.0.0.0 11521 Bytes 07/11/2008 14:40:59
        RCIMAGE.DLL : 9.0.0.25 2438913 Bytes 15/07/2009 08:44:17
        RCTEXT.DLL : 9.0.73.0 88321 Bytes 20/11/2009 12:45:51

        Configuration pour la recherche actuelle :
        Nom de la tâche...............................: Contrôle intégral du système
        Fichier de configuration......................: c:\program files\avira\antivir desktop\sysscan.avp
        Documentation.................................: bas
        Action principale.............................: interactif
        Action secondaire.............................: ignorer
        Recherche sur les secteurs d'amorçage maître..: marche
        Recherche sur les secteurs d'amorçage.........: marche
        Secteurs d'amorçage...........................: C:, D:,
        Recherche dans les programmes actifs..........: marche
        Recherche en cours sur l'enregistrement.......: marche
        Recherche de Rootkits.........................: marche
        Contrôle d'intégrité de fichiers système......: arrêt
        Fichier mode de recherche.....................: Tous les fichiers
        Recherche sur les archives....................: marche
        Limiter la profondeur de récursivité..........: 20
        Archive Smart Extensions......................: marche
        Heuristique de macrovirus.....................: marche
        Heuristique fichier...........................: moyen

        Début de la recherche : mardi 12 janvier 2010 18:38

        La recherche d'objets cachés commence.
        '72745' objets ont été contrôlés, '0' objets cachés ont été trouvés.

        La recherche sur les processus démarrés commence :
        Processus de recherche 'iexplore.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'avscan.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'iexplore.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'iexplore.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'iexplore.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'wmiapsrv.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'jqs.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'hpsysdrv.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'kbd.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'alg.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'ehmsas.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'dllhost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'mcrdsvc.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'TomTomHOMEService.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'nvsvc32.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'MDM.EXE' - '1' module(s) sont contrôlés
        Processus de recherche 'LSSrvc.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'ezntsvc.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'ehSched.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'hpqtra08.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'ehrecvr.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'arservice.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'avguard.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'ctfmon.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'TomTomHOMERunner.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'msnmsgr.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'avgnt.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'realsched.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'RealOneMessageCenter.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'EEventManager.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'qttask.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'hpwuSchd2.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'DMAScheduler.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'ehtray.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'sched.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'explorer.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'spoolsv.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'lsass.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'services.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'winlogon.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'csrss.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'smss.exe' - '1' module(s) sont contrôlés
        '51' processus ont été contrôlés avec '51' modules

        La recherche sur les secteurs d'amorçage maître commence :
        Secteur d'amorçage maître HD0
        [INFO] Aucun virus trouvé !
        Secteur d'amorçage maître HD1
        [INFO] Aucun virus trouvé !
        Secteur d'amorçage maître HD2
        [INFO] Aucun virus trouvé !
        Secteur d'amorçage maître HD3
        [INFO] Aucun virus trouvé !
        Secteur d'amorçage maître HD4
        [INFO] Aucun virus trouvé !

        La recherche sur les secteurs d'amorçage commence :
        Secteur d'amorçage 'C:\'
        [INFO] Aucun virus trouvé !
        Secteur d'amorçage 'D:\'
        [INFO] Aucun virus trouvé !

        La recherche sur les renvois aux fichiers exécutables (registre) commence :
        Le registre a été contrôlé ( '74' fichiers).

        La recherche sur les fichiers sélectionnés commence :

        Recherche débutant dans 'C:\' <HP_PAVILION>
        C:\hiberfil.sys
        [AVERTISSEMENT] Impossible d'ouvrir le fichier !
        [REMARQUE] Ce fichier est un fichier système Windows.
        [REMARQUE] Il est correct que ce fichier ne puisse pas être ouvert pour la recherche.
        C:\pagefile.sys
        [AVERTISSEMENT] Impossible d'ouvrir le fichier !
        [REMARQUE] Ce fichier est un fichier système Windows.
        [REMARQUE] Il est correct que ce fichier ne puisse pas être ouvert pour la recherche.
        C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP168\A0042899.exe
        [RESULTAT] Contient le cheval de Troie TR/Dldr.FraudLoad.gje.8
        C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP169\A0042921.exe
        [RESULTAT] Contient le cheval de Troie TR/Dldr.FraudLoad.gje.8
        C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP169\A0042936.exe
        [RESULTAT] Contient le cheval de Troie TR/Dldr.FraudLoad.gje.8
        C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP170\A0042948.exe
        [RESULTAT] Contient le cheval de Troie TR/Fakealert.afey
        C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP170\A0042949.exe
        [RESULTAT] Contient le cheval de Troie TR/Trash.Gen
        C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP170\A0042950.exe
        [RESULTAT] Contient le cheval de Troie TR/Trash.Gen
        C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP170\A0042955.dll
        [RESULTAT] Contient le cheval de Troie TR/Trash.Gen
        Recherche débutant dans 'D:\' <HP_RECOVERY>

        Début de la désinfection :
        C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP168\A0042899.exe
        [RESULTAT] Contient le cheval de Troie TR/Dldr.FraudLoad.gje.8
        [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4b7cc4d5.qua' !
        C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP169\A0042921.exe
        [RESULTAT] Contient le cheval de Troie TR/Dldr.FraudLoad.gje.8
        [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4a01997e.qua' !
        C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP169\A0042936.exe
        [RESULTAT] Contient le cheval de Troie TR/Dldr.FraudLoad.gje.8
        [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '48b69186.qua' !
        C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP170\A0042948.exe
        [RESULTAT] Contient le cheval de Troie TR/Fakealert.afey
        [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4af850f6.qua' !
        C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP170\A0042949.exe
        [RESULTAT] Contient le cheval de Troie TR/Trash.Gen
        [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4a02a1a6.qua' !
        C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP170\A0042950.exe
        [RESULTAT] Contient le cheval de Troie TR/Trash.Gen
        [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4aff488e.qua' !
        C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP170\A0042955.dll
        [RESULTAT] Contient le cheval de Troie TR/Trash.Gen
        [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4b7cc4d6.qua' !

        Fin de la recherche : mardi 12 janvier 2010 19:51
        Temps nécessaire: 1:10:19 Heure(s)

        La recherche a été effectuée intégralement

        11250 Les répertoires ont été contrôlés
        544049 Des fichiers ont été contrôlés
        7 Des virus ou programmes indésirables ont été trouvés
        0 Des fichiers ont été classés comme suspects
        0 Des fichiers ont été supprimés
        0 Des virus ou programmes indésirables ont été réparés
        7 Les fichiers ont été déplacés dans la quarantaine
        0 Les fichiers ont été renommés
        2 Impossible de contrôler des fichiers
        544040 Fichiers non infectés
        16227 Les archives ont été contrôlées
        2 Avertissements
        9 Consignes
        72745 Des objets ont été contrôlés lors du Rootkitscan
        0 Des objets cachés ont été trouvés
        0
      3. Voici le rapport d'Antivir :

        Avira AntiVir Personal
        Date de création du fichier de rapport : mardi 12 janvier 2010 18:38

        La recherche porte sur 1525403 souches de virus.

        Détenteur de la licence : Avira AntiVir Personal - FREE Antivirus
        Numéro de série : 0000149996-ADJIE-0000001
        Plateforme : Windows XP
        Version de Windows : (Service Pack 3) [5.1.2600]
        Mode Boot : Démarré normalement
        Identifiant : SYSTEM
        Nom de l'ordinateur : NOM-FB9B15D2723

        Informations de version :
        BUILD.DAT : 9.0.0.74 21698 Bytes 04/12/2009 13:56:00
        AVSCAN.EXE : 9.0.3.10 466689 Bytes 20/11/2009 12:45:51
        AVSCAN.DLL : 9.0.3.0 49409 Bytes 03/03/2009 09:21:02
        LUKE.DLL : 9.0.3.2 209665 Bytes 20/02/2009 10:35:11
        LUKERES.DLL : 9.0.2.0 13569 Bytes 03/03/2009 09:21:31
        VBASE000.VDF : 7.10.0.0 19875328 Bytes 06/11/2009 12:45:51
        VBASE001.VDF : 7.10.1.0 1372672 Bytes 19/11/2009 12:45:51
        VBASE002.VDF : 7.10.1.1 2048 Bytes 19/11/2009 12:45:51
        VBASE003.VDF : 7.10.1.2 2048 Bytes 19/11/2009 12:45:51
        VBASE004.VDF : 7.10.1.3 2048 Bytes 19/11/2009 12:45:51
        VBASE005.VDF : 7.10.1.4 2048 Bytes 19/11/2009 12:45:51
        VBASE006.VDF : 7.10.1.5 2048 Bytes 19/11/2009 12:45:51
        VBASE007.VDF : 7.10.1.6 2048 Bytes 19/11/2009 12:45:51
        VBASE008.VDF : 7.10.1.7 2048 Bytes 19/11/2009 12:45:51
        VBASE009.VDF : 7.10.1.8 2048 Bytes 19/11/2009 12:45:51
        VBASE010.VDF : 7.10.1.9 2048 Bytes 19/11/2009 12:45:51
        VBASE011.VDF : 7.10.1.10 2048 Bytes 19/11/2009 12:45:51
        VBASE012.VDF : 7.10.1.11 2048 Bytes 19/11/2009 12:45:51
        VBASE013.VDF : 7.10.1.79 209920 Bytes 25/11/2009 17:03:34
        VBASE014.VDF : 7.10.1.128 197632 Bytes 30/11/2009 16:07:10
        VBASE015.VDF : 7.10.1.178 195584 Bytes 07/12/2009 17:11:04
        VBASE016.VDF : 7.10.1.224 183296 Bytes 14/12/2009 21:28:14
        VBASE017.VDF : 7.10.1.247 182272 Bytes 15/12/2009 11:52:16
        VBASE018.VDF : 7.10.2.30 198144 Bytes 21/12/2009 17:12:26
        VBASE019.VDF : 7.10.2.63 187392 Bytes 24/12/2009 17:26:28
        VBASE020.VDF : 7.10.2.93 195072 Bytes 29/12/2009 12:17:36
        VBASE021.VDF : 7.10.2.131 201216 Bytes 07/01/2010 16:34:10
        VBASE022.VDF : 7.10.2.158 192000 Bytes 11/01/2010 17:38:22
        VBASE023.VDF : 7.10.2.159 2048 Bytes 11/01/2010 17:38:23
        VBASE024.VDF : 7.10.2.160 2048 Bytes 11/01/2010 17:38:23
        VBASE025.VDF : 7.10.2.161 2048 Bytes 11/01/2010 17:38:23
        VBASE026.VDF : 7.10.2.162 2048 Bytes 11/01/2010 17:38:23
        VBASE027.VDF : 7.10.2.163 2048 Bytes 11/01/2010 17:38:23
        VBASE028.VDF : 7.10.2.164 2048 Bytes 11/01/2010 17:38:23
        VBASE029.VDF : 7.10.2.165 2048 Bytes 11/01/2010 17:38:23
        VBASE030.VDF : 7.10.2.166 2048 Bytes 11/01/2010 17:38:23
        VBASE031.VDF : 7.10.2.175 143872 Bytes 12/01/2010 17:38:23
        Version du moteur : 8.2.1.134
        AEVDF.DLL : 8.1.1.2 106867 Bytes 16/09/2009 15:41:20
        AESCRIPT.DLL : 8.1.3.7 594296 Bytes 05/01/2010 16:54:38
        AESCN.DLL : 8.1.3.0 127348 Bytes 10/12/2009 18:07:29
        AESBX.DLL : 8.1.1.1 246132 Bytes 20/11/2009 12:45:51
        AERDL.DLL : 8.1.3.4 479605 Bytes 01/12/2009 16:07:13
        AEPACK.DLL : 8.2.0.4 422263 Bytes 05/01/2010 16:54:33
        AEOFFICE.DLL : 8.1.0.38 196987 Bytes 18/06/2009 14:57:46
        AEHEUR.DLL : 8.1.0.194 2228599 Bytes 09/01/2010 17:03:56
        AEHELP.DLL : 8.1.9.0 237943 Bytes 17/12/2009 15:20:41
        AEGEN.DLL : 8.1.1.83 369014 Bytes 05/01/2010 16:40:42
        AEEMU.DLL : 8.1.1.0 393587 Bytes 05/10/2009 15:20:33
        AECORE.DLL : 8.1.9.1 180598 Bytes 10/12/2009 18:07:28
        AEBB.DLL : 8.1.0.3 53618 Bytes 09/10/2008 13:32:40
        AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 07:47:30
        AVPREF.DLL : 9.0.3.0 44289 Bytes 26/09/2009 16:54:45
        AVREP.DLL : 8.0.0.3 155905 Bytes 20/01/2009 13:34:28
        AVREG.DLL : 9.0.0.0 36609 Bytes 07/11/2008 14:24:42
        AVARKT.DLL : 9.0.0.3 292609 Bytes 24/03/2009 14:05:22
        AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 30/01/2009 09:36:37
        SQLITE3.DLL : 3.6.1.0 326401 Bytes 28/01/2009 14:03:49
        SMTPLIB.DLL : 9.2.0.25 28417 Bytes 02/02/2009 07:20:57
        NETNT.DLL : 9.0.0.0 11521 Bytes 07/11/2008 14:40:59
        RCIMAGE.DLL : 9.0.0.25 2438913 Bytes 15/07/2009 08:44:17
        RCTEXT.DLL : 9.0.73.0 88321 Bytes 20/11/2009 12:45:51

        Configuration pour la recherche actuelle :
        Nom de la tâche...............................: Contrôle intégral du système
        Fichier de configuration......................: c:\program files\avira\antivir desktop\sysscan.avp
        Documentation.................................: bas
        Action principale.............................: interactif
        Action secondaire.............................: ignorer
        Recherche sur les secteurs d'amorçage maître..: marche
        Recherche sur les secteurs d'amorçage.........: marche
        Secteurs d'amorçage...........................: C:, D:,
        Recherche dans les programmes actifs..........: marche
        Recherche en cours sur l'enregistrement.......: marche
        Recherche de Rootkits.........................: marche
        Contrôle d'intégrité de fichiers système......: arrêt
        Fichier mode de recherche.....................: Tous les fichiers
        Recherche sur les archives....................: marche
        Limiter la profondeur de récursivité..........: 20
        Archive Smart Extensions......................: marche
        Heuristique de macrovirus.....................: marche
        Heuristique fichier...........................: moyen

        Début de la recherche : mardi 12 janvier 2010 18:38

        La recherche d'objets cachés commence.
        '72745' objets ont été contrôlés, '0' objets cachés ont été trouvés.

        La recherche sur les processus démarrés commence :
        Processus de recherche 'iexplore.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'avscan.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'iexplore.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'iexplore.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'iexplore.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'wmiapsrv.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'jqs.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'hpsysdrv.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'kbd.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'alg.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'ehmsas.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'dllhost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'mcrdsvc.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'TomTomHOMEService.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'nvsvc32.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'MDM.EXE' - '1' module(s) sont contrôlés
        Processus de recherche 'LSSrvc.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'ezntsvc.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'ehSched.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'hpqtra08.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'ehrecvr.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'arservice.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'avguard.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'ctfmon.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'TomTomHOMERunner.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'msnmsgr.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'avgnt.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'realsched.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'RealOneMessageCenter.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'EEventManager.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'qttask.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'hpwuSchd2.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'DMAScheduler.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'ehtray.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'sched.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'explorer.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'spoolsv.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'lsass.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'services.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'winlogon.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'csrss.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'smss.exe' - '1' module(s) sont contrôlés
        '51' processus ont été contrôlés avec '51' modules

        La recherche sur les secteurs d'amorçage maître commence :
        Secteur d'amorçage maître HD0
        [INFO] Aucun virus trouvé !
        Secteur d'amorçage maître HD1
        [INFO] Aucun virus trouvé !
        Secteur d'amorçage maître HD2
        [INFO] Aucun virus trouvé !
        Secteur d'amorçage maître HD3
        [INFO] Aucun virus trouvé !
        Secteur d'amorçage maître HD4
        [INFO] Aucun virus trouvé !

        La recherche sur les secteurs d'amorçage commence :
        Secteur d'amorçage 'C:\'
        [INFO] Aucun virus trouvé !
        Secteur d'amorçage 'D:\'
        [INFO] Aucun virus trouvé !

        La recherche sur les renvois aux fichiers exécutables (registre) commence :
        Le registre a été contrôlé ( '74' fichiers).

        La recherche sur les fichiers sélectionnés commence :

        Recherche débutant dans 'C:\' <HP_PAVILION>
        C:\hiberfil.sys
        [AVERTISSEMENT] Impossible d'ouvrir le fichier !
        [REMARQUE] Ce fichier est un fichier système Windows.
        [REMARQUE] Il est correct que ce fichier ne puisse pas être ouvert pour la recherche.
        C:\pagefile.sys
        [AVERTISSEMENT] Impossible d'ouvrir le fichier !
        [REMARQUE] Ce fichier est un fichier système Windows.
        [REMARQUE] Il est correct que ce fichier ne puisse pas être ouvert pour la recherche.
        C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP168\A0042899.exe
        [RESULTAT] Contient le cheval de Troie TR/Dldr.FraudLoad.gje.8
        C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP169\A0042921.exe
        [RESULTAT] Contient le cheval de Troie TR/Dldr.FraudLoad.gje.8
        C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP169\A0042936.exe
        [RESULTAT] Contient le cheval de Troie TR/Dldr.FraudLoad.gje.8
        C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP170\A0042948.exe
        [RESULTAT] Contient le cheval de Troie TR/Fakealert.afey
        C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP170\A0042949.exe
        [RESULTAT] Contient le cheval de Troie TR/Trash.Gen
        C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP170\A0042950.exe
        [RESULTAT] Contient le cheval de Troie TR/Trash.Gen
        C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP170\A0042955.dll
        [RESULTAT] Contient le cheval de Troie TR/Trash.Gen
        Recherche débutant dans 'D:\' <HP_RECOVERY>

        Début de la désinfection :
        C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP168\A0042899.exe
        [RESULTAT] Contient le cheval de Troie TR/Dldr.FraudLoad.gje.8
        [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4b7cc4d5.qua' !
        C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP169\A0042921.exe
        [RESULTAT] Contient le cheval de Troie TR/Dldr.FraudLoad.gje.8
        [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4a01997e.qua' !
        C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP169\A0042936.exe
        [RESULTAT] Contient le cheval de Troie TR/Dldr.FraudLoad.gje.8
        [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '48b69186.qua' !
        C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP170\A0042948.exe
        [RESULTAT] Contient le cheval de Troie TR/Fakealert.afey
        [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4af850f6.qua' !
        C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP170\A0042949.exe
        [RESULTAT] Contient le cheval de Troie TR/Trash.Gen
        [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4a02a1a6.qua' !
        C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP170\A0042950.exe
        [RESULTAT] Contient le cheval de Troie TR/Trash.Gen
        [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4aff488e.qua' !
        C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP170\A0042955.dll
        [RESULTAT] Contient le cheval de Troie TR/Trash.Gen
        [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4b7cc4d6.qua' !

        Fin de la recherche : mardi 12 janvier 2010 19:51
        Temps nécessaire: 1:10:19 Heure(s)

        La recherche a été effectuée intégralement

        11250 Les répertoires ont été contrôlés
        544049 Des fichiers ont été contrôlés
        7 Des virus ou programmes indésirables ont été trouvés
        0 Des fichiers ont été classés comme suspects
        0 Des fichiers ont été supprimés
        0 Des virus ou programmes indésirables ont été réparés
        7 Les fichiers ont été déplacés dans la quarantaine
        0 Les fichiers ont été renommés
        2 Impossible de contrôler des fichiers
        544040 Fichiers non infectés
        16227 Les archives ont été contrôlées
        2 Avertissements
        9 Consignes
        72745 Des objets ont été contrôlés lors du Rootkitscan
        0 Des objets cachés ont été trouvés
        0
    3. Contributeur sécurité
      ok

      lien javara
      https://www.commentcamarche.net/faq/15645-supprimer-les-anciennes-versions-de-java-avec-javara

      http://www.libellules.ch/dotclear/index.php?post/2008/07/13/2689-javara
      0
      1. le rapport de javara :

        JavaRa 1.15 Removal Log.

        Report follows after line.

        ------------------------------------

        The JavaRa removal process was started on Tue Jan 12 17:06:49 2010

        Found and removed: C:\Program Files\Java\jre1.5.0_09

        Found and removed: C:\Program Files\Java\jre1.6.0_07

        Found and removed: Software\JavaSoft\Java2D\1.5.0

        Found and removed: Software\JavaSoft\Java2D\1.5.0_06

        Found and removed: Software\JavaSoft\Java2D\1.5.0_09

        Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}

        Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}

        Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D510009

        Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D510009

        Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D510009

        Found and removed: SOFTWARE\Classes\JavaPlugin.150_09

        Found and removed: SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0

        Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.5.0_09

        Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5

        Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5.0_09

        Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}

        Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D510009

        Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D510009

        Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0150090}

        Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.5.0_09

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

        Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

        Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

        Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

        Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

        Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

        Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

        Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_07

        Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_07

        Found and removed: SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}

        Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610007

        Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610007

        Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160070}

        Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.5.0_09\

        Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_07\bin\

        ------------------------------------

        Finished reporting.

        et par contre, le lien pour installer foxit reader n'a pas marché
        0
    4. Contributeur sécurité
      télécharge OTM
      http://www.geekstogo.com/forum/files/file/402-otm-oldtimers-move-it/ (de Old_Timer) sur ton Bureau.

      double-clique sur OTM.exe pour le lancer.
      copie la liste qui se trouve en citation ci-dessous,
      et colle-la dans le cadre de gauche de OTM :Paste instruction for items to be moved.

      :processes
      explorer.exe
      :files
      C:\WINDOWS\system32\5705.exe
      C:\WINDOWS\system32\24464.exe
      C:\WINDOWS\system32\26962.exe
      C:\WINDOWS\system32\29358.exe
      C:\WINDOWS\system32\11478.exe
      C:\WINDOWS\system32\15724.exe
      C:\WINDOWS\system32\19169.exe
      C:\WINDOWS\system32\26500.exe
      C:\WINDOWS\system32\6334.exe
      C:\WINDOWS\system32\18467.exe
      :commands
      [purity]
      [emptytemp]
      [start explorer]

      clique sur MoveIt! pour lancer la suppression.
      le résultat apparaitra dans le cadre "Results".
      clique sur Exit pour fermer.
      poste le rapport situé dans C:\_OTM\MovedFiles.

      il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

      _______________________

      mettre a jour internet explorer
      pour XP
      https://www.microsoft.com/en-us/download

      pour VISTA:
      https://www.microsoft.com/en-us/download

      _____________

      mettre à jour adobe reader puis supprimer les anciennes version via le panneau de configuration
      https://acrobat.adobe.com/fr/fr/acrobat/pdf-reader.html

      ou passer a un lecteur alternatif ce qui évitera les virus circulant via les PDF comme foxit reader (ne pas mettre les barres foxit, ask, ebay..)

      https://www.commentcamarche.net/telecharger/ 205 foxit reader

      _____________

      Mettre a jour java:
      https://javara.fr.malavida.com/­indows

      Télécharge JavaRa.zip de Paul 'Prm753' McLain et Fred de Vries.
      Décompresse le fichier sur ton bureau (clique droit > Extraire tout.)
      Double-clique sur le répertoire JavaRa obtenu.
      Puis double-clique sur le fichier JavaRa.exe (le .exe peut ne pas s'afficher)
      Clique sur Search For Updates.
      Sélectionne Update Using jucheck.exe puis clique sur Search.
      Autorise le processus à se connecter s'il te le demande, clique sur Install et suis les instructions d'installation. Cela prendra quelques minutes.
      Quand l'installation est terminée, revient à l'écran de JavaRa et clique sur Remove Older Versions.
      Clique sur Oui pour confirmer. L'outil va travailler, clique ensuite sur Ok, puis une deuxième fois sur Ok.
      Un rapport va s'ouvrir, copie-colle le dans ta prochaine réponse.
      Note : le rapport se trouve aussi à la racine de la partition système, en général C:\ sous le nom JavaRa.log
      (c:\JavaRa.log)
      Ferme l'application.

      si cela ne fonctionne pas

      https://www.java.com/fr/download/windows_manual.jsp?locale=fr&host=www.java.com:80

      tu peux désinstaller les vieilles versions.

      ________________________

      colle un rapport avec antivir
      0
      1. Voilà le rapport d'OTM :

        All processes killed
        ========== PROCESSES ==========
        No active process named explorer.exe was found!
        ========== FILES ==========
        C:\WINDOWS\system32\5705.exe moved successfully.
        C:\WINDOWS\system32\24464.exe moved successfully.
        C:\WINDOWS\system32\26962.exe moved successfully.
        C:\WINDOWS\system32\29358.exe moved successfully.
        C:\WINDOWS\system32\11478.exe moved successfully.
        C:\WINDOWS\system32\15724.exe moved successfully.
        C:\WINDOWS\system32\19169.exe moved successfully.
        C:\WINDOWS\system32\26500.exe moved successfully.
        C:\WINDOWS\system32\6334.exe moved successfully.
        C:\WINDOWS\system32\18467.exe moved successfully.
        ========== COMMANDS ==========

        [EMPTYTEMP]

        User: Administrateur
        ->Temp folder emptied: 0 bytes
        ->Temporary Internet Files folder emptied: 0 bytes

        User: All Users

        User: Default User
        ->Temp folder emptied: 0 bytes
        ->Temporary Internet Files folder emptied: 32902 bytes

        User: HP_Administrateur
        ->Temp folder emptied: 942829488 bytes
        ->Temporary Internet Files folder emptied: 1290357047 bytes
        ->Java cache emptied: 480 bytes
        ->FireFox cache emptied: 3119088 bytes

        User: Invité
        ->Temp folder emptied: 0 bytes
        ->Temporary Internet Files folder emptied: 78991 bytes
        ->Java cache emptied: 718123 bytes

        User: InvitÚ
        ->Temp folder emptied: 0 bytes

        User: LocalService
        ->Temp folder emptied: 65748 bytes
        ->Temporary Internet Files folder emptied: 481239 bytes

        User: NetworkService
        ->Temp folder emptied: 0 bytes
        ->Temporary Internet Files folder emptied: 33170 bytes

        %systemdrive% .tmp files removed: 14648 bytes
        %systemroot% .tmp files removed: 19569 bytes
        %systemroot%\System32 .tmp files removed: 4637696 bytes
        %systemroot%\System32\dllcache .tmp files removed: 0 bytes
        %systemroot%\System32\drivers .tmp files removed: 0 bytes
        Windows Temp folder emptied: 8396908 bytes
        %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 23967620 bytes
        %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
        RecycleBin emptied: 15450426 bytes

        Total Files Cleaned = 2 184,00 mb

        OTM by OldTimer - Version 3.1.5.0 log created on 01122010_160419

        Files moved on Reboot...

        Registry entries deleted on Reboot...

        Je m'occupe des mises à jour
        0
    5. Contributeur sécurité
      ok vire tout puis remets un nouveau rapport RSIT
      0
      1. c'est viré et voilà le rapport :

        Logfile of random's system information tool 1.06 (written by random/random)
        Run by HP_Administrateur at 2010-01-12 15:29:55
        Microsoft Windows XP Professionnel Service Pack 3
        System drive C: has 149 GB (81%) free of 184 GB
        Total RAM: 1982 MB (73% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 15:30:00, on 12/01/2010
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16945)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Avira\AntiVir Desktop\sched.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\ehome\ehtray.exe
        C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
        C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
        C:\Program Files\Fichiers communs\Real\Update_OB\RealOneMessageCenter.exe
        C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
        C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
        C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
        C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIEFE.EXE
        C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        C:\Program Files\Avira\AntiVir Desktop\avguard.exe
        C:\WINDOWS\arservice.exe
        C:\WINDOWS\eHome\ehRecvr.exe
        C:\WINDOWS\eHome\ehSched.exe
        C:\WINDOWS\system32\ezNTSvc.exe
        C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
        C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
        C:\WINDOWS\system32\nvsvc32.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\WINDOWS\system32\dllhost.exe
        C:\WINDOWS\eHome\ehmsas.exe
        C:\HP\KBD\KBD.EXE
        c:\windows\system\hpsysdrv.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\Documents and Settings\HP_Administrateur\Bureau\RSIT.exe
        C:\Program Files\trend micro\HP_Administrateur.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/...
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.wikipedia.org/wiki/Accueil
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/...
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/...
        R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxybiblio.hec.fr:8080
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
        O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
        O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
        O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
        O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
        O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
        O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
        O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
        O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
        O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
        O4 - HKLM\..\Run: [MsgCenterExe] "C:\Program Files\Fichiers communs\Real\Update_OB\RealOneMessageCenter.exe" -osboot
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
        O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [EPSON Stylus SX200 Series (Copie 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIEFE.EXE /FU "C:\WINDOWS\TEMP\E_S51C.tmp" /EF "HKCU"
        O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
        O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        O8 - Extra context menu item: Add to AMV Converter... - C:\Program Files\MP3 Player Utilities 4.05\AMVConverter\grab.html
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
        O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.05\MediaManager\grab.html
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
        O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/...
        O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.extrafilm.fr/ImageUploader5.cab
        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
        O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.can.com.sg/mwf/mgaxctrl.cab
        O16 - DPF: {B79A53C0-1DAC-4636-BACE-FD086A7A79BF} (AdSignerLCContrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP-2.0.cab
        O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
        O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
        O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
        O23 - Service: EasyBits Magic Desktop Services for Windows NT (ezntsvc) - EasyBits Software Corp. - C:\WINDOWS\system32\ezNTSvc.exe
        O23 - Service: Service Google Update (gupdate1ca09eac5303ab0) (gupdate1ca09eac5303ab0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
        O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
        0
    6. Contributeur sécurité
      ok

      scan avec malwarebyte , fais un scan rapide et colle le rapport obtenu et vire ce qui est trouvé:

      https://www.malekal.com/tutoriel-malwarebyte-anti-malware/­
      0
      1. voilà la rapport du scan rapide :

        Malwarebytes' Anti-Malware 1.44
        Version de la base de données: 3548
        Windows 5.1.2600 Service Pack 3
        Internet Explorer 7.0.5730.11

        12/01/2010 15:20:57
        mbam-log-2010-01-12 (15-20-55).txt

        Type de recherche: Examen rapide
        Eléments examinés: 147447
        Temps écoulé: 11 minute(s), 52 second(s)

        Processus mémoire infecté(s): 2
        Module(s) mémoire infecté(s): 1
        Clé(s) du Registre infectée(s): 1
        Valeur(s) du Registre infectée(s): 5
        Elément(s) de données du Registre infecté(s): 11
        Dossier(s) infecté(s): 1
        Fichier(s) infecté(s): 12

        Processus mémoire infecté(s):
        C:\Program Files\InternetSecurity2010\IS2010.exe (Rogue.Installer) -> No action taken.
        C:\WINDOWS\system32\smss32.exe (Trojan.FakeAlert) -> No action taken.

        Module(s) mémoire infecté(s):
        C:\WINDOWS\system32\helper32.dll (Trojan.FakeAlert) -> No action taken.

        Clé(s) du Registre infectée(s):
        HKEY_CURRENT_USER\SOFTWARE\IS2010 (Rogue.InternetSecurity2010) -> No action taken.

        Valeur(s) du Registre infectée(s):
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\internet security 2010 (Rogue.Installer) -> No action taken.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\smss32.exe (Trojan.FakeAlert) -> No action taken.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\General\wallpaper (Hijack.Wallpaper) -> No action taken.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\lsass service (Trojan.Agent) -> No action taken.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\defence (Trojan.Agent) -> No action taken.

        Elément(s) de données du Registre infecté(s):
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: c:\windows\system32\winlogon32.exe -> No action taken.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: system32\winlogon32.exe -> No action taken.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.UserInit) -> Bad: (C:\WINDOWS\system32\winlogon32.exe) Good: (userinit.exe) -> No action taken.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> No action taken.

        Dossier(s) infecté(s):
        C:\Program Files\InternetSecurity2010 (Rogue.InternetSecurity2010) -> No action taken.

        Fichier(s) infecté(s):
        C:\WINDOWS\system32\helper32.dll (Trojan.FakeAlert) -> No action taken.
        C:\Program Files\InternetSecurity2010\IS2010.exe (Rogue.Installer) -> No action taken.
        C:\Documents and Settings\HP_Administrateur\Local Settings\temp\a.exe (Trojan.Dropper) -> No action taken.
        C:\Documents and Settings\HP_Administrateur\Local Settings\Temporary Internet Files\Content.IE5\1I4TFXVE\dfghfghgfj[1].dll (Trojan.FakeAlert) -> No action taken.
        C:\Documents and Settings\HP_Administrateur\Local Settings\Temporary Internet Files\Content.IE5\IVQM528B\SetupIS2010[1].exe (Rogue.Installer) -> No action taken.
        C:\WINDOWS\system32\smss32.exe (Trojan.FakeAlert) -> No action taken.
        C:\WINDOWS\system32\Winlogon32.exe (Trojan.FakeAlert) -> No action taken.
        C:\Documents and Settings\HP_Administrateur\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Security 2010.lnk (Rogue.InternetSecurity2010) -> No action taken.
        C:\WINDOWS\system32\41.exe (Trojan.FakeAlert) -> No action taken.
        C:\Documents and Settings\HP_Administrateur\Local Settings\temp\0.09971990493751082.exe (Trojan.Dropper) -> No action taken.
        C:\Documents and Settings\HP_Administrateur\Local Settings\temp\0.7662111847528514.exe (Trojan.Dropper) -> No action taken.
        C:\WINDOWS\system32\warning.html (Trojan.FakeAlert) -> No action taken.
        0
    7. Contributeur sécurité
      ok
      0
      1. Voilà les 2 rapports demandés :

        Logfile of random's system information tool 1.06 (written by random/random)
        Run by HP_Administrateur at 2010-01-12 14:55:44
        Microsoft Windows XP Professionnel Service Pack 3
        System drive C: has 149 GB (81%) free of 184 GB
        Total RAM: 1982 MB (73% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 15:02:31, on 12/01/2010
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16945)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Avira\AntiVir Desktop\sched.exe
        C:\Program Files\Avira\AntiVir Desktop\avguard.exe
        C:\WINDOWS\arservice.exe
        C:\WINDOWS\eHome\ehRecvr.exe
        C:\WINDOWS\eHome\ehSched.exe
        C:\WINDOWS\system32\ezNTSvc.exe
        C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
        C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
        C:\WINDOWS\system32\nvsvc32.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
        C:\WINDOWS\system32\dllhost.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\ehome\ehtray.exe
        C:\WINDOWS\ARPWRMSG.EXE
        C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
        C:\WINDOWS\eHome\ehmsas.exe
        C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
        C:\Program Files\Fichiers communs\Real\Update_OB\RealOneMessageCenter.exe
        C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
        C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
        C:\WINDOWS\system32\smss32.exe
        C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIEFE.EXE
        C:\Program Files\InternetSecurity2010\IS2010.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\HP\KBD\KBD.EXE
        c:\windows\system\hpsysdrv.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Documents and Settings\HP_Administrateur\Bureau\RSIT.exe
        C:\Program Files\trend micro\HP_Administrateur.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://fr.search.yahoo.com/?fr=cb-hp06
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.wikipedia.org/wiki/Accueil
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://fr.search.yahoo.com/?fr=cb-hp06
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
        R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxybiblio.hec.fr:8080
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\winlogon32.exe
        O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
        O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
        O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
        O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
        O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
        O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
        O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
        O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
        O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
        O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
        O4 - HKLM\..\Run: [MsgCenterExe] "C:\Program Files\Fichiers communs\Real\Update_OB\RealOneMessageCenter.exe" -osboot
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
        O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
        O4 - HKLM\..\Run: [smss32.exe] C:\WINDOWS\system32\smss32.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [EPSON Stylus SX200 Series (Copie 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIEFE.EXE /FU "C:\WINDOWS\TEMP\E_S51C.tmp" /EF "HKCU"
        O4 - HKCU\..\Run: [Defence] "C:\Documents and Settings\All Users\Defence\smss.exe" -SystemDefence
        O4 - HKCU\..\Run: [Internet Security 2010] C:\Program Files\InternetSecurity2010\IS2010.exe
        O4 - HKLM\..\Policies\Explorer\Run: [Lsass Service] C:\Documents and Settings\HP_Administrateur\Application Data\Microsoft\Windows\lsass.exe
        O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
        O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        O8 - Extra context menu item: Add to AMV Converter... - C:\Program Files\MP3 Player Utilities 4.05\AMVConverter\grab.html
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
        O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.05\MediaManager\grab.html
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
        O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O10 - Unknown file in Winsock LSP: c:\windows\system32\helper32.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\helper32.dll
        O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20070501/qtinstall.info.apple.com/qtactivex/qtplugin.cab
        O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.extrafilm.fr/ImageUploader5.cab
        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
        O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.can.com.sg/mwf/mgaxctrl.cab
        O16 - DPF: {B79A53C0-1DAC-4636-BACE-FD086A7A79BF} (AdSignerLCContrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP-2.0.cab
        O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
        O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
        O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
        O23 - Service: EasyBits Magic Desktop Services for Windows NT (ezntsvc) - EasyBits Software Corp. - C:\WINDOWS\system32\ezNTSvc.exe
        O23 - Service: Service Google Update (gupdate1ca09eac5303ab0) (gupdate1ca09eac5303ab0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
        O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
        0
    8. Contributeur sécurité
      slt restaure le pc avant le souci comme ceci:
      http://www.infoprat.net/astuces/windows2k_xp/astuces/divers_004.php

      puis dis si cela persiste

      et

      Télécharge ici :

      http://images.malwareremoval.com/random/RSIT.exe

      random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

      Double-clique sur RSIT.exe afin de lancer RSIT.

      Clique Continue à l'écran Disclaimer.

      Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

      Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

      Poste le contenu de log.txt (<<qui sera affiché)
      ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

      NB : Les rapports sont sauvegardés dans le dossier C:\rsit
      0
      1. Je n'arrive pas à faire la restauration système, quand j'essaie de lancer le programme dans outils système, ça me met : "application cannot de executed. The file is infected. Please activate your antivirus software"

        Je vais faire la suite du message et poster les rapports !
        0