Problème Trojan Generic ! Urgent !

Bonjour,
Depuis aujourd'hui, après avoir fait une analyse avec Spyware Doctor, j'ai découvert une surprise : mon ordinateur est infecté par un Trojan Generic...
Ca faisait quelques jours que mon ordinateur ramait, que mon processus firefox ne se fermait pas etc...

J'aimerai votre aide pour pouvoir supprimer cette chose et qu'elle ne revienne jamais :) ^^.
Merci et bonne journée.
Configuration: Windows Vista
Firefox

12 réponses

  1. Modérateur
    Supprime manuellement ceci :
    C:\Program Files\Search Settings


    ********

    Tu n’as pas d’antivirus ! C’est risqué de naviguer sur Internet sans antivirus !
    Installe Antivir d’Avira, préférable à Avast.
    Tout est expliqué sur ce lien, du téléchargement à la configuration.
    Autres liens utiles : ICI
    ET ICI

    *********

    Mets à jour Adobe Acrobat Reader en téléchargeant la version 9 = = = =>>> En cliquant ici <<<= = = = Il faut le faire car c’est une faille de sécurité de ne pas le tenir à jour.
    0
    1. Modérateur
      Pour vérification, poste un nouveau rapport RSIT stp.
      0
      1. Logfile of random's system information tool 1.06 (written by random/random)
        Run by Lili at 2010-02-17 21:14:47
        Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
        System drive C: has 20 GB (18%) free of 115 GB
        Total RAM: 3066 MB (49% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 21:14:58, on 17/02/2010
        Platform: Windows Vista SP2 (WinNT 6.00.1906)
        MSIE: Internet Explorer v8.00 (8.00.6001.18882)
        Boot mode: Normal

        Running processes:
        C:\Windows\System32\smss.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\wininit.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\services.exe
        C:\Windows\system32\lsass.exe
        C:\Windows\system32\lsm.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\nvvsvc.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\winlogon.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\SLsvc.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
        C:\Windows\system32\WLANExt.exe
        C:\Windows\System32\spoolsv.exe
        C:\Windows\system32\taskeng.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\Dwm.exe
        C:\Windows\system32\taskeng.exe
        C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe
        C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe
        C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
        C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
        C:\Windows\system32\conime.exe
        C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
        C:\Windows\system32\agrsmsvc.exe
        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\Intel\WiFi\bin\EvtEng.exe
        C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
        C:\Windows\system32\lxdicoms.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
        C:\Program Files\Spyware Doctor\pctsAuxs.exe
        C:\Program Files\Spyware Doctor\pctsSvc.exe
        C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
        C:\Program Files\Spyware Doctor\pctsTray.exe
        C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\SearchIndexer.exe
        C:\Windows\system32\wbem\unsecapp.exe
        C:\Windows\system32\wbem\wmiprvse.exe
        C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
        C:\Program Files\Windows Media Player\wmpnetwk.exe
        C:\Windows\explorer.exe
        C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
        C:\Program Files\OpenOffice.org 3\program\soffice.exe
        C:\Program Files\OpenOffice.org 3\program\soffice.bin
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\BitTorrent\bittorrent.exe
        C:\Program Files\Windows Live\Contacts\wlcomm.exe
        C:\Windows\explorer.exe
        C:\Users\Lili\AppData\Local\Google\Chrome\Application\chrome.exe
        C:\Windows\system32\SearchProtocolHost.exe
        C:\Users\Lili\AppData\Local\Google\Chrome\Application\chrome.exe
        C:\Windows\system32\SearchFilterHost.exe
        C:\Users\Lili\AppData\Local\Google\Chrome\Application\chrome.exe
        C:\Users\Lili\AppData\Local\Google\Chrome\Application\chrome.exe
        C:\Users\Lili\Documents\Downloads\RSIT (1).exe
        C:\Windows\system32\wbem\wmiprvse.exe
        C:\Program Files\trend micro\Lili.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
        O1 - Hosts: ::1 localhost
        O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [lxdimon.exe] "C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe"
        O4 - HKLM\..\Run: [lxdiamon] "C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe"
        O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
        O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe"
        O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
        O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
        O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
        O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
        O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
        O4 - HKCU\..\Run: [Google Update] "C:\Users\Lili\AppData\Local\Google\Update\GoogleUpdate.exe" /c
        O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
        O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
        O4 - Global Startup: BTTray.lnk = ?
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
        O8 - Extra context menu item: Télécharger avec IDM - C:\Program Files\Internet Download Manager\IEExt.htm
        O8 - Extra context menu item: Télécharger le contenu de video FLV avec IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
        O8 - Extra context menu item: Télécharger tous les liens avec IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
        O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
        O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
        O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
        O13 - Gopher Prefix:
        O15 - Trusted Zone: http://*.secuser.com
        O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
        O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
        O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
        O23 - Service: Browser Defender Update Service - Threat Expert Ltd. - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
        O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
        O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
        O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
        O23 - Service: lxdiCATSCustConnectService - Lexmark International, Inc. - C:\Windows\system32\spool\DRIVERS\W32X86\3\\lxdiserv.exe
        O23 - Service: lxdi_device - - C:\Windows\system32\lxdicoms.exe
        O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
        O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
        O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
        O23 - Service: Samsung Update Plus - Unknown owner - C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe
        O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
        O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
        O23 - Service: TeamViewer 4 (TeamViewer4) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
        0
    2. Modérateur
      J'aimerais bien voir le rapport MBAM stp.
      0
      1. Le voilà :

        Malwarebytes' Anti-Malware 1.44
        Version de la base de données: 3751
        Windows 6.0.6002 Service Pack 2
        Internet Explorer 8.0.6001.18882

        17/02/2010 19:58:47
        mbam-log-2010-02-17 (19-58-47).txt

        Type de recherche: Examen complet (C:\|D:\|E:\|F:\|I:\|)
        Eléments examinés: 343239
        Temps écoulé: 2 hour(s), 52 minute(s), 50 second(s)

        Processus mémoire infecté(s): 0
        Module(s) mémoire infecté(s): 0
        Clé(s) du Registre infectée(s): 0
        Valeur(s) du Registre infectée(s): 0
        Elément(s) de données du Registre infecté(s): 0
        Dossier(s) infecté(s): 0
        Fichier(s) infecté(s): 0

        Processus mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Module(s) mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Clé(s) du Registre infectée(s):
        (Aucun élément nuisible détecté)

        Valeur(s) du Registre infectée(s):
        (Aucun élément nuisible détecté)

        Elément(s) de données du Registre infecté(s):
        (Aucun élément nuisible détecté)

        Dossier(s) infecté(s):
        (Aucun élément nuisible détecté)

        Fichier(s) infecté(s):
        (Aucun élément nuisible détecté)
        0
    3. Modérateur
      Nettoyage avec UsbFix :

      Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptibles d’avoir été infectés sans les ouvrir !

      * Relance UsbFix par un clic droit sur le raccourci UsbFix présent sur ton bureau et en sélectionnant "Exécuter en tant qu’administrateur".
      * Choisis l’option 2 (Suppression)
      * Ton bureau disparaîtra et le PC redémarrera.
      * Au redémarrage, UsbFix scannera ton PC. Laisse travailler l’outil.
      * Ensuite poste l’intégralité du rapport UsbFix.txt qui apparaîtra avec le bureau.

      Note :
      Le rapport UsbFix.txt est sauvegardé a la racine du disque. (C:\UsbFix.txt)

      ********

      Télécharge Malwarebytes’ Anti-Malware
      = = = = >>> En cliquant ici <<< = = = =

      - Enregistre le sur le bureau
      - Double-clique sur le fichier téléchargé pour lancer le processus d’installation
      - Lorsqu’il te le sera demandé, mets à jour Malwarebytes anti malware
      - Si le pare-feu demande l’autorisation de se connecter pour malwarebytes, acceptes
      - Une fois la mise à jour terminée, ferme Malwarebytes
      - Double-clique sur l’icône de malwarebytes pour le relancer
      - Dans l’onglet, Recherche, probablement ouvert par défaut,
      - Sélectionne Exécuter un examen complet
      - Clique sur Rechercher
      - Le scan démarre
      - A la fin de l’analyse, un message s’affiche : L’examen s’est terminé normalement. Cliquez sur ‘Afficher les résultats’ pour afficher tous les objets trouvés.
      - Clique sur Ok pour poursuivre.
      - Si des malwares ont été détectés, cliques sur Afficher les résultats
      - Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
      - Malwarebytes va ouvrir le bloc-notes et y copier le rapport d’analyse.
      - Rends toi dans l’onglet rapport/log
      - Tu clique dessus pour l’afficher une fois affiché
      - Tu clique sur édition en haut du bloc notes, et puis sur sélectionner tout
      - Tu reclique sur édition et puis sur copier et tu reviens sur le forum et dans ta réponse
      - Tu clique droit dans le cadre de la réponse et coller

      Si tu as besoin d’aide regarde ce tutorial ICI
      0
      1. Malwarebyte n'a détecté aucun élément suspect, et Spyware Doctor ne donne plus rien :).

        Je suppose donc que c'est bon ^^ as tu quand même besoin des rapports ?
        0
    4. Modérateur
      Suppression avec Ad-Remover :
      /!\ Déconnectes toi et fermes toutes applications en cours, désactive ton antivirus le temps de la manipulation/!\

      * Clique droit sur l’icône Ad-Remover située sur ton bureau puis sélectionne "Exécuter en tant qu’administrateur".
      * Au menu principal choisi l’option "L" et tape ensuite [Entrée]
      * Poste le rapport qui apparaît à la fin.

      (Le rapport est sauvegardé aussi sous C:\Ad-report(date).log)
      (CTRL+A Pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)

      Note :

      "Process.exe", une composante de l’outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
      Il ne s’agit pas d’un virus, mais d’un utilitaire destiné à mettre fin à des processus.

      ***********

      Tu es infecté par un ver qui se propage dans ton ordinateur par support amovibles (clé USB, disquettes, appareils photos numériques, disques durs externes, …)

      Télécharge et installe UsbFix de C_XX & El desaparecido :
      = = = = >>> En cliquant ici <<< = = = =

      Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptibles d’avoir été infectés sans les ouvrir !

      * Clique droit sur le raccourci UsbFix présent sur ton bureau et sélectionne "Exécuter en tant qu’administrateur".
      * Choisis ensuite l’option 1 (Recherche)
      * Laisse travailler l’outil.
      * Ensuite poste le rapport UsbFix.txt qui apparaîtra.

      Notes :
      - Le rapport UsbFix.txt est sauvegardé a la racine du disque. (C:\UsbFix.txt)
      (CTRL+A Pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller sur le forum).
      - "Process.exe", une composante de l’outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s’agit pas d’un virus, mais d’un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d’où l’alerte émise par ces antivirus.
      0
      1. Le rapport d'Ad-Remover :

        .
        ======= RAPPORT D'AD-REMOVER 1.1.4.6_J | UNIQUEMENT XP/VISTA/7 =======
        .
        Mis à jour par C_XX le 05.02.2010 à 17:34
        Contact: AdRemover.contact@gmail.com
        Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
        .
        Lancé à: 16:07:45, 17/02/2010 | Mode Normal | Option: CLEAN
        Exécuté de: C:\Ad-Remover\
        Système d'exploitation: Microsoft® Windows Vista™ HomePremium Service Pack 2 v6.0.6002
        Nom du PC: PC-DE-LILI | Utilisateur actuel: Lili
        .
        ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
        .

        C:\Program Files\Dealio
        C:\Program Files\Search Settings - ... [b]ERREUR SUPPRESSION !![/b]
        C:\Users\Lili\AppData\LocalLow\Search Settings
        C:\Windows\Installer\9944cc.msi

        (!) -- Fichiers temporaires supprimés.

        .
        HKCU\Software\Microsoft\Internet Explorer\LowRegistry\Search Settings
        HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F}
        HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
        HKLM\Software\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
        HKLM\software\classes\installer\Products\79CAA1B036589D14EA74856E2A220F1E
        HKLM\Software\Classes\Interface\{D5A1EF9A-7948-435D-8B87-D6A598317288}
        HKLM\software\classes\SearchSettings.BHO
        HKLM\software\classes\SearchSettings.BHO.1
        HKLM\Software\Classes\TypeLib\{CD082CCA-086F-4FD8-8FD7-247A0DBBD1CC}
        HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\0292226F570267D459357AF78015E534
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\03285961954D5824C85975D955031EE8
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\6AC3985F4D64C2245A96D31569D1BF40
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\855847FA0E25FBA46B8516389DFDD4B3
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\94E65EF7E080DDA4AA2F1DEDCE74AC5B
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\9DC2844D0E3E8924C8973C3B3BAE1F58
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\AFEB575AA30ACB243B748619F62F0782
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\F461B8DD96FF5AA41A52D14E1D7B69C7
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Products\79CAA1B036589D14EA74856E2A220F1E
        HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SearchSettings
        HKLM\software\microsoft\windows\currentversion\uninstall\{0B1AAC97-8563-41D9-AE47-58E6A222F0E1}
        HKLM\software\Search Settings
        .
        ============== Scan additionnel ==============
        .
        .
        * Mozilla FireFox Version 3.6 [fr] *
        .
        Nom du profil: kb9jjnte.default (Lili)
        .
        (Lili, prefs.js) Browser.download.dir, C:\Users\Lili\Downloads
        (Lili, prefs.js) Browser.download.lastDir, C:\Users\Lili\Desktop
        (Lili, prefs.js) Browser.startup.homepage, hxxp://google.fr
        (Lili, prefs.js) Extensions.enabledItems, {d5bc46d8-67c7-11dc-8c1d-0097498c2b7a}:1.0.0.1,{b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.7,mozilla_cc@internetdownloadmanager.com:6.7,{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11,{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07,{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13,{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15,{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17,{20a82645-c095-46ed-80e3-08825760534b}:1.1,{635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.5.200812101546,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6
        .
        .
        .
        * Internet Explorer Version 8.0.6001.18882 *
        .
        [HKEY_CURRENT_USER\..\Internet Explorer\Main]
        .
        Do404Search: 01000000
        Local Page: C:\Windows\system32\blank.htm
        Show_ToolBar: yes
        Enable Browser Extensions: yes
        Start Page: hxxp://fr.msn.com/
        Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
        Default_search_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
        Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
        .
        [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
        .
        Start Page: hxxp://fr.msn.com/
        Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
        Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
        Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
        Delete_Temp_Files_On_Exit: yes
        Local Page: C:\Windows\System32\blank.htm
        Search bar: hxxp://search.msn.com/spbasic.htm
        .
        [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
        .
        Tabs: res://ieframe.dll/tabswelcome.htm
        .
        ============== Suspect (Cracks, Serials, ...) ==============
        .
        C:\Users\Lili\Documents\Downloads\Spyware_Doctor_2010_7.0.0.508__Serials.5125968.TPB (1).torrent
        C:\Users\Lili\Documents\Downloads\Spyware_Doctor_2010_7.0.0.508__Serials.5125968.TPB.torrent
        .
        ===================================
        .
        5001 Octet(s) - C:\Ad-Report-CLEAN[1].log
        512 Octet(s) - C:\Ad-Report-SCAN[1].log
        5073 Octet(s) - C:\Ad-Report-SCAN[2].log
        .
        48 Fichier(s) - C:\Users\Lili\AppData\Local\Temp
        24 Fichier(s) - C:\Windows\Temp
        0 Fichier(s) - C:\Windows\Prefetch
        .
        23 Fichier(s) - C:\Ad-Remover\BACKUP
        8 Fichier(s) - C:\Ad-Remover\QUARANTINE
        .
        Fin à: 16:27:27 | 17/02/2010 - CLEAN[1]
        .
        ============== E.O.F ==============
        .

        Et le rapport de USBfix (j'ai branché uniquement mon disque dur externe, sur lequel je copie tout mes fichiers) :

        ############################## | UsbFix V6.095 |

        User : Lili (Administrateurs) # PC-DE-LILI
        Update on 15/02/2010 by El Desaparecido , C_XX & Chimay8
        Start at: 16:31:35 | 17/02/2010
        Website : http://pagesperso-orange.fr/NosTools/index.html
        Contact : FindyKill.Contact@gmail.com

        Intel(R) Core(TM)2 Duo CPU T5800 @ 2.00GHz
        Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
        Internet Explorer 8.0.6001.18882
        Windows Firewall Status : Enabled

        C:\ -> Disque fixe local # 111,88 Go (19,73 Go free) # NTFS
        D:\ -> Disque fixe local # 111 Go (44,53 Go free) # NTFS
        E:\ -> Disque CD-ROM # 7,08 Go (0 Mo free) [ROMEO_AND_JULIET] # UDF
        F:\ -> Disque CD-ROM
        G:\ -> Disque CD-ROM
        H:\ -> Disque CD-ROM
        I:\ -> Disque fixe local # 232,83 Go (68,83 Go free) [IOMEGA_HDD] # FAT32

        ############################## | Processus actifs |

        C:\Windows\System32\smss.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\wininit.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\services.exe
        C:\Windows\system32\lsass.exe
        C:\Windows\system32\lsm.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\nvvsvc.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\winlogon.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\SLsvc.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\rundll32.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
        C:\Windows\system32\WLANExt.exe
        C:\Windows\System32\spoolsv.exe
        C:\Windows\system32\taskeng.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\Dwm.exe
        C:\Windows\Explorer.EXE
        C:\Windows\system32\taskeng.exe
        C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe
        C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe
        C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
        C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
        C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
        C:\Windows\system32\agrsmsvc.exe
        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
        C:\Windows\system32\conime.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\Intel\WiFi\bin\EvtEng.exe
        C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
        C:\Windows\system32\lxdicoms.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
        C:\Program Files\Spyware Doctor\pctsAuxs.exe
        C:\Program Files\Spyware Doctor\pctsSvc.exe
        C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
        C:\Program Files\Spyware Doctor\pctsTray.exe
        C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\SearchIndexer.exe
        C:\Windows\system32\wbem\wmiprvse.exe
        C:\Windows\system32\wbem\unsecapp.exe
        C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
        C:\Program Files\Windows Media Player\wmpnetwk.exe
        C:\Windows\System32\rundll32.exe
        C:\Windows\RtHDVCpl.exe
        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
        C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe
        C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe
        C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe
        C:\Program Files\PowerISO\PWRISOVM.EXE
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\Program Files\Java\jre6\bin\jusched.exe
        C:\Program Files\DAEMON Tools Lite\daemon.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
        C:\Program Files\OpenOffice.org 3\program\soffice.exe
        C:\Program Files\OpenOffice.org 3\program\soffice.bin
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Program Files\iPod\bin\iPodService.exe
        C:\Program Files\DNA\btdna.exe
        C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
        C:\Windows\system32\wbem\wmiprvse.exe

        ################## | Elements infectieux |

        ################## | Registre |

        ################## | Mountpoints2 |

        HKCU\..\..\Explorer\MountPoints2\G
        shell\AutoRun\command =G:\Autorun.exe

        HKCU\..\..\Explorer\MountPoints2\H
        shell\AutoRun\command =H:\Autorun.exe

        HKCU\..\..\Explorer\MountPoints2\{487dfef6-5a8b-11de-b372-001377ae2249}
        shell\AutoRun\command =H:\LaunchU3.exe -a

        HKCU\..\..\Explorer\MountPoints2\{ef9dc7cc-11a9-11df-8f42-001377ae2249}
        shell\AutoRun\command =J:\
        shell\explore\Command =RECYCLED\INFO.exe
        shell\open\Command =RECYCLED\INFO.exe

        ################## | Vaccin |

        (!) Cet ordinateur n'est pas vacciné !

        ################## | ! Fin du rapport # UsbFix V6.095 ! |
        0
    5. Modérateur
      Adware / Spyware Doctor : desux adwares : un qui ne sert à rien.
      PAS d'ANTIVIRUS
      Infection SearchSettings
      Infection USB

      *********

      Recherche avec Ad-Remover :
      Télécharge Ad-Remover ( de Cyrildu17 / C_XX ) sur ton bureau :
      = = = =>>> En cliquant ici <<<= = = =

      /!\ Déconnectes toi et fermes toutes applications en cours, désactive ton antivirus le temps de la manipulation/!\

      * Double clique sur le programme d’installation, et installe le dans son emplacement par défaut. (C:\Program files)
      * Clique droit sur l’icône Ad-remover située sur ton bureau puis sélectionne "Exécuter en tant qu’administrateur".
      * Réponds ‘Oui‘ au message d’alerte automatique.
      * Au menu principal choisi l’option ‘S‘ et tape ensuite [Entrée]
      * Poste le rapport qui apparaît à la fin.

      (Le rapport est sauvegardé aussi sous C:\Ad-report(date).log)
      (CTRL+A Pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)

      Note :

      "Process.exe", une composante de l’outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
      Il ne s’agit pas d’un virus, mais d’un utilitaire destiné à mettre fin à des processus.
      0
      1. Voici le rapport :

        .
        ======= RAPPORT D'AD-REMOVER 1.1.4.6_J | UNIQUEMENT XP/VISTA/7 =======
        .
        Mis à jour par C_XX le 05.02.2010 à 17:34
        Contact: AdRemover.contact@gmail.com
        Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
        .
        Lancé à: 15:21:35, 17/02/2010 | Mode Normal | Option: SCAN
        Exécuté de: C:\Ad-Remover\
        Système d'exploitation: Microsoft® Windows Vista™ HomePremium Service Pack 2 v6.0.6002
        Nom du PC: PC-DE-LILI | Utilisateur actuel: Lili
        .
        ============== ÉLÉMENT(S) TROUVÉ(S) ==============
        .

        C:\Program Files\Dealio
        C:\Program Files\Search Settings
        C:\Users\Lili\AppData\LocalLow\Search Settings
        C:\Windows\Installer\9944cc.msi
        .
        HKCU\Software\Microsoft\Internet Explorer\LowRegistry\Search Settings
        HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F}
        HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
        HKLM\Software\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
        HKLM\software\classes\installer\Products\79CAA1B036589D14EA74856E2A220F1E
        HKLM\Software\Classes\Interface\{D5A1EF9A-7948-435D-8B87-D6A598317288}
        HKLM\software\classes\SearchSettings.BHO
        HKLM\software\classes\SearchSettings.BHO.1
        HKLM\Software\Classes\TypeLib\{CD082CCA-086F-4FD8-8FD7-247A0DBBD1CC}
        HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\0292226F570267D459357AF78015E534
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\03285961954D5824C85975D955031EE8
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\6AC3985F4D64C2245A96D31569D1BF40
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\855847FA0E25FBA46B8516389DFDD4B3
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\94E65EF7E080DDA4AA2F1DEDCE74AC5B
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\9DC2844D0E3E8924C8973C3B3BAE1F58
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\AFEB575AA30ACB243B748619F62F0782
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\F461B8DD96FF5AA41A52D14E1D7B69C7
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Products\79CAA1B036589D14EA74856E2A220F1E
        HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SearchSettings
        HKLM\software\microsoft\windows\currentversion\uninstall\{0B1AAC97-8563-41D9-AE47-58E6A222F0E1}
        HKLM\software\Search Settings
        .
        ============== Scan additionnel ==============
        .
        .
        * Mozilla FireFox Version 3.6 [fr] *
        .
        Nom du profil: kb9jjnte.default (Lili)
        .
        (Lili, prefs.js) Browser.download.dir, C:\Users\Lili\Downloads
        (Lili, prefs.js) Browser.download.lastDir, C:\Users\Lili\Desktop
        (Lili, prefs.js) Browser.startup.homepage, hxxp://google.fr
        (Lili, prefs.js) Extensions.enabledItems, {d5bc46d8-67c7-11dc-8c1d-0097498c2b7a}:1.0.0.1,{b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.7,mozilla_cc@internetdownloadmanager.com:6.7,{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11,{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07,{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13,{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15,{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17,{20a82645-c095-46ed-80e3-08825760534b}:1.1,{635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.5.200812101546,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6
        .
        .
        .
        * Internet Explorer Version 8.0.6001.18882 *
        .
        [HKEY_CURRENT_USER\..\Internet Explorer\Main]
        .
        Do404Search: 01000000
        Local Page: C:\Windows\system32\blank.htm
        Show_ToolBar: yes
        Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
        Enable Browser Extensions: yes
        Start Page:
        Default_Page_URL: http:\\www.samsungcomputer.com
        .
        [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
        .
        Start Page: hxxp://go.microsoft.com/fwlink/?LinkId=69157
        Default_Page_URL: http:\\www.samsungcomputer.com
        Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
        Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
        Delete_Temp_Files_On_Exit: yes
        Local Page: C:\Windows\System32\blank.htm
        .
        [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
        .
        Tabs: res://ieframe.dll/tabswelcome.htm
        .
        ============== Suspect (Cracks, Serials, ...) ==============
        .
        C:\Users\Lili\Documents\Downloads\Spyware_Doctor_2010_7.0.0.508__Serials.5125968.TPB (1).torrent
        C:\Users\Lili\Documents\Downloads\Spyware_Doctor_2010_7.0.0.508__Serials.5125968.TPB.torrent
        .
        ===================================
        .
        512 Octet(s) - C:\Ad-Report-SCAN[1].log
        4736 Octet(s) - C:\Ad-Report-SCAN[2].log
        .
        49 Fichier(s) - C:\Users\Lili\AppData\Local\Temp
        21 Fichier(s) - C:\Windows\Temp
        129 Fichier(s) - C:\Windows\Prefetch
        .
        4 Fichier(s) - C:\Ad-Remover\BACKUP
        0 Fichier(s) - C:\Ad-Remover\QUARANTINE
        .
        Fin à: 15:53:21 | 17/02/2010 - SCAN[2]
        .
        ============== E.O.F ==============
        .
        0
    6. Modérateur
      Non.
      On va vérifier s'il y a des infections sur le PC :

      Désactive l’UAC (User Account Control) le temps de la désinfection.
      Démarrer > Panneau de configuration > Comptes d’utilisateurs > Désactiver le contrôle des comptes d’utilisateur.
      (Manipulation inverse pour le remettre en fin de désinfection).
      (Cela va permettre aux outils de désinfection de travailler correctement).

      *********

      Pour établir un diagnostic plus en profondeur de ton PC :
      Télécharge Random’s System Information Tool (RSIT) de random/random et enregistre l’exécutable sur le Bureau.
      = = = = >>> En cliquant ici <<< = = = =

      * Clique droit sur RSIT.exe puis sélectionne ‘Exécuter en tant qu’administrateur‘ pour le lancer.
      * Une première fenêtre s’ouvre, clique alors sur Continue (Disclaimer).
      * Si la dernière version de HijackThis n’est pas détectée sur ton PC, RSIT le téléchargera et te demandera d’accepter la licence.
      * Lorsque l’analyse sera terminée, deux fichiers texte s’ouvriront (probablement avec le bloc-notes).
      * Poste le contenu de log.txt et de info.txt.
      0
      1. Je n'ai eu que le rapport log.txt :

        Logfile of random's system information tool 1.06 (written by random/random)
        Run by Lili at 2010-02-17 15:09:15
        Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
        System drive C: has 21 GB (18%) free of 115 GB
        Total RAM: 3066 MB (53% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 15:09:21, on 17/02/2010
        Platform: Windows Vista SP2 (WinNT 6.00.1906)
        MSIE: Internet Explorer v8.00 (8.00.6001.18882)
        Boot mode: Normal

        Running processes:
        C:\Windows\System32\smss.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\wininit.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\services.exe
        C:\Windows\system32\lsass.exe
        C:\Windows\system32\lsm.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\nvvsvc.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\winlogon.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\SLsvc.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\rundll32.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
        C:\Windows\system32\WLANExt.exe
        C:\Windows\system32\taskeng.exe
        C:\Windows\System32\spoolsv.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\Dwm.exe
        C:\Windows\Explorer.EXE
        C:\Windows\system32\taskeng.exe
        C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
        C:\Windows\system32\taskeng.exe
        C:\Windows\system32\agrsmsvc.exe
        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe
        C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe
        C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
        C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
        C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter3.exe
        C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\Intel\WiFi\bin\EvtEng.exe
        C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
        C:\Windows\system32\lxdicoms.exe
        C:\Windows\System32\rundll32.exe
        C:\Windows\RtHDVCpl.exe
        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
        C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe
        C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe
        C:\Program Files\Search Settings\SearchSettings.exe
        C:\Program Files\Spyware Doctor\pctsAuxs.exe
        C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
        C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe
        C:\Program Files\Spyware Doctor\pctsSvc.exe
        C:\Program Files\PowerISO\PWRISOVM.EXE
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\Program Files\Java\jre6\bin\jusched.exe
        C:\Program Files\DAEMON Tools Lite\daemon.exe
        C:\Users\Lili\Program Files\DNA\btdna.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\Spyware Doctor\pctsTray.exe
        C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
        C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\SearchIndexer.exe
        C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
        C:\Program Files\OpenOffice.org 3\program\soffice.exe
        C:\Program Files\OpenOffice.org 3\program\soffice.bin
        C:\Windows\system32\wbem\unsecapp.exe
        C:\Windows\system32\wbem\wmiprvse.exe
        C:\Program Files\iPod\bin\iPodService.exe
        C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
        C:\Windows\system32\SearchProtocolHost.exe
        C:\Program Files\Windows Media Player\wmpnetwk.exe
        C:\Windows\system32\wbem\wmiprvse.exe
        C:\Windows\system32\taskeng.exe
        C:\Windows\system32\SearchFilterHost.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Users\Lili\Desktop\RSIT.exe
        C:\Program Files\trend micro\Lili.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
        R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
        O1 - Hosts: ::1 localhost
        O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
        O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
        O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [lxdimon.exe] "C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe"
        O4 - HKLM\..\Run: [lxdiamon] "C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe"
        O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
        O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
        O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe"
        O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
        O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
        O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
        O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\Lili\Program Files\DNA\btdna.exe"
        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
        O4 - HKCU\..\Run: [Google Update] "C:\Users\Lili\AppData\Local\Google\Update\GoogleUpdate.exe" /c
        O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
        O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
        O4 - Global Startup: BTTray.lnk = ?
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
        O8 - Extra context menu item: Télécharger avec IDM - C:\Program Files\Internet Download Manager\IEExt.htm
        O8 - Extra context menu item: Télécharger le contenu de video FLV avec IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
        O8 - Extra context menu item: Télécharger tous les liens avec IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
        O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
        O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
        O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
        O13 - Gopher Prefix:
        O15 - Trusted Zone: http://*.secuser.com
        O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
        O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
        O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
        O23 - Service: Browser Defender Update Service - Threat Expert Ltd. - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
        O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
        O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
        O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
        O23 - Service: lxdiCATSCustConnectService - Lexmark International, Inc. - C:\Windows\system32\spool\DRIVERS\W32X86\3\\lxdiserv.exe
        O23 - Service: lxdi_device - - C:\Windows\system32\lxdicoms.exe
        O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
        O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
        O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
        O23 - Service: Samsung Update Plus - Unknown owner - C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe
        O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
        O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
        O23 - Service: TeamViewer 4 (TeamViewer4) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
        0
    7. Modérateur
      Je ne peux pas t'obliger mais ton crack est infecté ! (la preuve)...
      Fais ce que tu veux maintenant.

      **********

      Tu as un logiciel édité par DVDVideoSoft.
      Supprime tout ce qui a été détecté...
      Pour ton jeu, c'est toi qui voit si tu supprime le fichier.
      0
      1. J'ai désinstallé le jeu, et effectivement il ne restait qu'un truc dans le dossier du jeu c'était le virus.
        Je viens de le supprimer, mais n'ayant que la version non enregistrée de Spyware Doctor je l'ai supprimé "à la main".
        Y a t'il des chances qu'il revienne ?
        0
    8. Modérateur
      Euh, tu l'as cracké le jeu ?
      Je veut bien voir aussi un petit aperçu des 58 infections Adware stp (pas tout) et les 2 spywares.
      0
      1. Oui j'ai craqué le jeu, c'était pour jouer en réseau avec mon petit ami ^^". C'est lui qui s'est occupé de le craquer.
        Je ne suis pas très douée en ordinateur, donc je le laisse faire ce qu'il veut un peu avec mon PC. Donc si il y a des trucs un peu... bizarre, je ne sais rien x).

        Voilà un extrait des Adware :
        https://imageshack.com/

        Et les Spywares :
        https://imageshack.com/
        0
    9. Modérateur
      Je n'utilise pas Spyware Doctor mais y aurait-il un rapport texte ?
      (Car il me faut le nom du fichier détecté comme infectieux).
      Sur cette capture d'écran, je ne vois pas les noms des fichiers.

      En cliquant sur les petits '+' sur le côté, ça devrait s'afficher...
      0
      1. Désolée, je ne suis pas très douée ^^"".

        Voilà ce qui s'affiche, en cliquant sur le +.
        J'avoue avoir un petit peu rit en voyant d'où il venait ^^".

        https://imageshack.com/
        0