Virus MSN

Bonjour,voila mon soucis, j'ai remarque que mon msn envoi des message instantané a mes contacts sans mon avis, quel est la Solution pour y remedier?
Merci d'avance.
Configuration: Windows Vista / Firefox 3.0.18

22 réponses

Résumé de la discussion

La problématique porte sur l'envoi de messages instantanés non autorisés via une application de messagerie, potentiellement dû à une infection ou à un piratage sur un poste Windows Vista et un navigateur obsolète. Des solutions proposées incluent l'utilisation d'HijackThis et RSIT pour diagnostiquer les traces de malware et partager les rapports pour analyse, puis Malwarebytes' Anti-Malware pour un examen approfondi. En cas de suspicion persistante, les journaux RSIT et le contenu du fichier hosts peuvent révéler des modifications système malveillantes, nécessitant un nettoyage des programmes indésirables et une restauration des paramètres.

Bobot (l’IA à votre service)
  1. tu n'a pas mis a jour malwarebyts met le a jour puis refais un scan complet
    0
    1. Re

      Merci de ton intervention;mais laisses moi faire;merci.

      @Bleach0723
      On continue:
      Je te propose de changer d'antivirus

      Télécharge : http://www.commentcamarche.net/telecharger/telechargement-55-antivir sur ton
      bureau.
      --> Installe Antivir et mets-le à jour.

      --> Double-clique sur l'icône d'AntiVir (Parapluie) dans la barre des tâches.

      --> Dans AntiVir, choisis Outils puis Configuration .

      --> Coche Mode Expert et coche Rech. Rootkit au dém. de la recherche à droite dans Autres réglages puis valide.

      --> Fais un scan complet, clique sur Tout réparer si AntiVir trouve quelque chose et poste le rapport.
      Tutoriel sur AntiVir.
      Pourquoi changer ? Avast-Antivir

      Comment installer et utiliser AntiVir :
      http://www.libellules.ch/tuto_antivir.php

      Configuration de Antivir (Merci Nico) :

      clic droit sur son icône dans la barre des taches et sélectionner Configurer Antivir.

      Cocher la case : Mode Expert.

      => Cliquer sur Scanner dans le volet de gauche :

      > Dans "Fichiers" sélectionner Tous les fichiers.

      > Dans procédure de recherche, cocher Autoriser l'arrêt, et dans "priorité scanner" sélectionner Elevé.

      > Dans "Autres réglages" cocher toutes les cases.

      NE SURTOUT PAS OUBLIER LA RECHERCHE DES ROOTKIT QUI EST TRES IMPORTANTE !

      => Cliquer sur "Recherche" dans le volet de gauche et appliquer les mêmes paramètres que précédemment.

      => Dérouler "Recherche" en cliquant sur le +. Cliquer sur "Heuristique" :

      > Cocher "Heuristique de Macro Virus" et "Heuristique fichier Win32" avec degré d'identification ELEVE !

      => Dans le volet de gauche, dérouler "Guard" puis dérouler "Recherche" :

      > Cocher "Heuristique de Macro Virus" et "Heuristique fichier Win32" avec degré d'identification ELEVE !

      Désinstalle Avast avant l'installation d'Antivir

      @+
      0
  2. Malwarebytes' Anti-Malware 1.44
    Version de la base de données: 3510
    Windows 6.0.6002 Service Pack 2
    Internet Explorer 8.0.6001.18882

    06/03/2010 13:41:08
    mbam-log-2010-03-06 (13-41-08).txt

    Type de recherche: Examen complet (C:\|D:\|)
    Eléments examinés: 293956
    Temps écoulé: 1 hour(s), 43 minute(s), 29 second(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 0
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 0

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Valeur(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    (Aucun élément nuisible détecté)
    0
    1. bon il me reste windows update a faire, et attendre la fin de malwarebytes
      0
      1. ok merci.j'ai lancé secunia....
        0
        1. concernant javara, je l'ai trouver mais impossible de faire la recherche via juchek, il ne cherche pas
          0
          1. Re

            J'ai lu trop vite ;tu disposes de Java.
            et avec mise à jour;donc pas de soucis de ce côté là.
            Passe à la suite.
            0
        2. le scan malwayre est en marche, je n'ai pas trouve unistall pour trojan dans le dossier, je l'ai supprimer, et pour javara, malgres les liens que tu m'as donné je ne le trouve pas a telecharger.( il y a bien un onglet telecharger, mais cela m'amene sur une page en anglais).
          0
          1. et pour le scan de malweyre, je fais un scan minutieux ou rapide?
            0
            1. Re

              Un scan complet;n'oublie pas la mise à jour avant.
              @+
              0
          2. a 1ere vu non
            j'en envoi plus.
            par contre je sais pas ou est trojan remover.
            0
            1. Re

              Ici:C:\Program Files\Trojan Remover\

              Tu désinstalles en cliquant sur ce fichier:unins000.exe

              @+
              0
          3. lol, faut faire tout ça pour voir si je n'est pas de virus!!lol
            0
            1. Re

              Non ;tout ceci pour mettre à jour ton PC.

              PS: envoies tu encore des messages?

              @+
              0
          4. oui j'ai fixé les lignes que tu m'as dis de fixer.
            0
            1. C bon j'ai fait ce que tu m'as dis.
              Bein pour mon msn il se trouve, que je vois qu'il envoi des message, car se sont mes amis qui me le disent."c'est quoi le fichier que tu m'as envoye..."
              alors que je n'ai rien envoye.
              A part ça, tu as vu si j'avais un virus?
              Mon probleme est il resolu?
              en tout cas merci par avance c'est gentil
              0
              1. Re

                Ton MSN envoie t'il encore des messages?

                Ensuite :

                1)Désinstalle Trojan Remover

                2)Lance un scan avec Malwaresbytes;met le à jour avant;et poste moi le rapport à l'issue.
                Supprime tout se qu'il trouve.

                3)Installe Internet Explorer 8

                4)Pour java utilises javaRa https://www.commentcamarche.net/faq/15645-supprimer-les-anciennes-versions-de-java-avec-javara

                et un autre tutoriel javaRa http://www.libellules.ch/dotclear/index.php?post/2008/07/13/2689-javara

                Décompresse le fichier sur le Bureau (Clic droit > Extraire tout).
                * Double-cliques sur le répertoire JavaRa.
                * Puis double-cliques sur le fichier JavaRa.exe (le exe peut ne pas s'afficher).
                * Choisis Français puis cliques sur Select.
                * Cliques sur Recherche de mises à jour.
                * Sélectionne Mettre à jour via jucheck.exe puis clique sur Rechercher.
                * Autorises le processus à se connecter s'il le demande, cliques sur Installer et suis les instructions d'installation qui prennent quelques minutes.
                * L'installation est terminée, reviens à l'écran de JavaRa et cliques sur Effacer les anciennes versions.
                * Cliques sur Oui pour confirmer. Laisses travailler et cliques ensuite sur OK, puis une deuxième fois sur OK.
                * Un rapport va s'ouvrir. Postes-le dans ta prochaine réponse.
                * Ferme l'application.

                Note : le rapport se trouve aussi dans C:\ sous le nom JavaRa.log.

                5)Pour vérifier les mises à jour logiciels à appliquer sur ton PC
                https://www.flexera.com/products/operations/software-vulnerability-management.html
                Divers liens te seront proposés pour les logiciels non à jour.

                Ce n'est pas fini...

                @+
                0
            2. Computer Name: LEROUX
              Event Code: 1015
              Message: L'ID événement 3013 du service Windows Search a été supprimé 10 fois depuis 10:01:47. Cet événement est utilisé pour supprimer les événements du service Windows Search qui se sont produits fréquemment dans une courte période. Voir l'ID événement 3013 pour plus de détails sur cet événement.
              Record Number: 12286
              Source Name: Microsoft-Windows-Search
              Time Written: 20090512083026.000000-000
              Event Type: Avertissement
              User:

              Computer Name: LEROUX
              Event Code: 1530
              Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

              DÉTAIL -
              1 user registry handles leaked from \Registry\User\S-1-5-21-648204624-3893815093-3798972402-1003:
              Process 976 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-648204624-3893815093-3798972402-1003

              Record Number: 12289
              Source Name: Microsoft-Windows-User Profiles Service
              Time Written: 20090512091043.000000-000
              Event Type: Avertissement
              User: AUTORITE NT\SYSTEM

              Computer Name: LEROUX
              Event Code: 1530
              Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

              DÉTAIL -
              1 user registry handles leaked from \Registry\User\S-1-5-21-648204624-3893815093-3798972402-1003_Classes:
              Process 976 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-648204624-3893815093-3798972402-1003_CLASSES

              Record Number: 12290
              Source Name: Microsoft-Windows-User Profiles Service
              Time Written: 20090512091043.000000-000
              Event Type: Avertissement
              User: AUTORITE NT\SYSTEM

              Computer Name: LEROUX
              Event Code: 3
              Message: La configuration du protocole AdminConnection\TCP n'est pas valide dans l'instance SQL MSSMLBIZ.
              Record Number: 12306
              Source Name: SQLBrowser
              Time Written: 20090512091146.000000-000
              Event Type: Avertissement
              User:

              Computer Name: LEROUX
              Event Code: 10
              Message: Le filtre d’événement avec la requête « SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99 » n’a pas pu être réactivé dans l’espace de noms « //./root/CIMV2 » à cause de l’erreur 0x80041003. Les événements ne peuvent pas être délivrés à travers ce filtre tant que le problème ne sera pas corrigé.
              Record Number: 12312
              Source Name: Microsoft-Windows-WMI
              Time Written: 20090512091148.000000-000
              Event Type: Erreur
              User:

              =====Security event log=====

              Computer Name: LEROUX
              Event Code: 5038
              Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

              Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
              Record Number: 15334
              Source Name: Microsoft-Windows-Security-Auditing
              Time Written: 20090512093004.253355-000
              Event Type: Échec de l'audit
              User:

              Computer Name: LEROUX
              Event Code: 5038
              Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

              Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
              Record Number: 15335
              Source Name: Microsoft-Windows-Security-Auditing
              Time Written: 20090512093004.393755-000
              Event Type: Échec de l'audit
              User:

              Computer Name: LEROUX
              Event Code: 5038
              Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

              Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
              Record Number: 15336
              Source Name: Microsoft-Windows-Security-Auditing
              Time Written: 20090512093004.471755-000
              Event Type: Échec de l'audit
              User:

              Computer Name: LEROUX
              Event Code: 5038
              Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

              Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
              Record Number: 15337
              Source Name: Microsoft-Windows-Security-Auditing
              Time Written: 20090512093004.549755-000
              Event Type: Échec de l'audit
              User:

              Computer Name: LEROUX
              Event Code: 5038
              Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

              Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
              Record Number: 15338
              Source Name: Microsoft-Windows-Security-Auditing
              Time Written: 20090512093004.627755-000
              Event Type: Échec de l'audit
              User:

              ======Environment variables======

              "ComSpec"=%SystemRoot%\system32\cmd.exe
              "FP_NO_HOST_CHECK"=NO
              "OS"=Windows_NT
              "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Microsoft SQL Server\90\Tools\binn\;C:\Program Files\QuickTime\QTSystem\
              "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
              "PROCESSOR_ARCHITECTURE"=x86
              "TEMP"=%SystemRoot%\TEMP
              "TMP"=%SystemRoot%\TEMP
              "USERNAME"=SYSTEM
              "windir"=%SystemRoot%
              "PROCESSOR_LEVEL"=6
              "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
              "PROCESSOR_REVISION"=0f0d
              "NUMBER_OF_PROCESSORS"=2
              "TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
              "DFSTRACINGON"=FALSE
              "CLASSPATH"=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
              "QTJAVA"=C:\Program Files\QuickTime\QTSystem\QTJava.zip

              -----------------EOF-----------------
              0
              1. Re

                As tu fixé les lignes ?
                @+
                0
            3. info.txt logfile of random's system information tool 1.06 2009-05-12 11:30:25

              ======Uninstall list======

              -->MsiExec /X{DD1865F0-AD73-40FB-B23E-1822E02396FF}
              2007 Microsoft Office system-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROHYBRIDR /dll OSETUP.DLL
              7 Sins-->C:\Program Files\Monte Cristo\7 Sins\uninst.exe
              Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
              Adobe Flash Player ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
              Adobe Reader 8.1.2 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81200000003}
              Agere Systems HDA Modem-->agrsmdel
              Apple Mobile Device Support-->MsiExec.exe /I{162B71B8-8464-4680-A086-601D555B331D}
              Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
              Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
              Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
              Atheros WLAN Client-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{04983D37-2202-4295-94A2-8B547C66133F}\setup.exe" -l0x9
              avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
              BankPerfect 6.23-->"C:\Program Files\BankPerfect\uninstall.exe"
              Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
              CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
              Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
              Crysis(R)-->MsiExec.exe /I{000E79B7-E725-4F01-870A-C12942B7F8E4}
              CyberLink DVD Suite-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\setup.exe" -uninstall
              CyberLink Power2Go-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\setup.exe" -uninstall
              Easy Battery Manager-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6F730513-8688-4C3C-90A3-6B9792CE2EF3}\setup.exe" -l0x9 Remove
              Easy Display Manager-->"C:\Program Files\InstallShield Installation Information\{17283B95-21A8-4996-97DA-547A48DB266F}\setup.exe" -runfromtemp -l0x0009 -removeonly
              Easy Network Manager-->MsiExec.exe /I{A7581D39-EA20-4883-A480-80C21047052B}
              Easy SpeedUp Manager-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EF367AA4-070B-493C-9575-85BE59D789C9}\setup.exe" -l0x9 Remove
              Fichiers de prise en charge de l'installation de Microsoft SQL Server (Français)-->MsiExec.exe /X{3380F354-C5F7-4E71-8F51-EEE6C3F06C62}
              Football Manager 2009-->"C:\Program Files\Sports Interactive\Football Manager 2009\Uninstall_Football Manager 2009\Uninstall Football Manager 2009.exe"
              Foto-Mosaik 4.1.0-->"C:\Program Files\Foto-Mosaik\unins000.exe"
              Freecorder Toolbar 3.02 Application-->"C:\Windows\Freecorder Toolbar\uninstall.exe" "/U:C:\Program Files\Freecorder Toolbar\Uninstall\uninstall.xml"
              Galerie de photos Windows Live-->MsiExec.exe /X{44E54A81-9D91-4AA1-9417-80AFF134F5FF}
              Gestionnaire de contacts professionnels pour Outlook 2007 SP2-->"C:\Program Files\Microsoft Small Business\Business Contact Manager\SetupBootstrap\Setup.exe" /remove {69ca8988-1c6c-4285-b8af-db780a6e42af}
              Gestionnaire de contacts professionnels pour Outlook 2007 SP2-->MsiExec.exe /X{69CA8988-1C6C-4285-B8AF-DB780A6E42AF}
              HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
              Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
              Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
              imagine digital freedom - Samsung-->MsiExec.exe /X{8E106A57-A17E-431D-B48F-175E42EB9F74}
              Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
              Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
              Intel PROSet Wireless-->Intel PROSet Wireless
              Intel® Matrix Storage Manager-->C:\Program Files\Intel\Intel Matrix Storage Manager\Uninstall\imsmudlg.exe -uninstall
              iTunes-->MsiExec.exe /I{C26B06A9-27BB-45B0-9873-9C623EC2BA38}
              Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
              LabelPrint-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\setup.exe" -uninstall
              LG PC Suite-->C:\Program Files\InstallShield Installation Information\{993960EE-CA4D-443F-8F88-E24260DD5FD2}\setup.exe -runfromtemp -l0x040c -removeonly
              LG USB Modem driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C3ABE126-2BB2-4246-BFE1-6797679B3579}\setup.exe" -l0x40c LG -removeonly
              LightScribe System Software 1.12.37.1-->MsiExec.exe /X{004C5DA2-2051-4D25-94BA-51CF810C91EB}
              Ma-Config.com-->MsiExec.exe /X{E780E536-16CE-4CD1-8FE0-2D5E52FAA65B}
              Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
              Marvell Miniport Driver-->C:\Program Files\Marvell\Miniport Driver\Uninst.exe
              Microsoft .NET Framework 1.1 Hotfix (KB929729)-->"C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\M929729\M929729Uninstall.msp"
              Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
              Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
              Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
              Microsoft .NET Framework 3.5 SP1-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
              Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
              Microsoft Office 2003 Web Components-->MsiExec.exe /I{90A4040C-6000-11D3-8CFE-0150048383C9}
              Microsoft Office 2007 Primary Interop Assemblies-->MsiExec.exe /X{50120000-1105-0000-0000-0000000FF1CE}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0015-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0015-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0019-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0019-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0044-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
              Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
              Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
              Microsoft Office InfoPath MUI (French) 2007-->MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}
              Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
              Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
              Microsoft Office Professional Hybrid 2007-->MsiExec.exe /X{91120000-0031-0000-0000-0000000FF1CE}
              Microsoft Office Professional Plus 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
              Microsoft Office Professional Plus 2007-->MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}
              Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
              Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
              Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
              Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
              Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
              Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
              Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
              Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
              Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
              Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
              Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
              Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
              Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
              Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
              Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
              Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
              Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
              Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
              Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
              Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
              Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
              Microsoft Office Small Business Connectivity Components-->MsiExec.exe /X{A939D341-5A04-4E0A-BB55-3E65B386432D}
              Microsoft Office Suite Activation Assistant-->MsiExec.exe /X{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}
              Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
              Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
              Microsoft SOAP Toolkit 2.0 SP2-->MsiExec.exe /I{36BEAD11-8577-49AD-9250-E06A50AE87B0}
              Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
              Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)-->MsiExec.exe /I{480DBB60-F0B6-45F2-B26F-1A2E11197791}
              Microsoft SQL Server 2005-->"C:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\ARPWrapper.exe" /Remove
              Microsoft SQL Server Native Client-->MsiExec.exe /I{1F24E48F-7692-4E89-8784-68DD4D2712A0}
              Microsoft SQL Server VSS Writer-->MsiExec.exe /I{A30179B7-997A-4D47-AA43-57AE59A9C78B}
              Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
              Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
              Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
              Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
              Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
              Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
              Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
              Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
              Mozilla Firefox (3.0.10)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
              MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
              NVIDIA Drivers-->C:\Windows\system32\nvuninst.exe UninstallGUI
              NVIDIA PhysX-->MsiExec.exe /X{DD1865F0-AD73-40FB-B23E-1822E02396FF}
              Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
              PhotoFiltre-->"C:\Program Files\PhotoFiltre\Uninst.exe"
              PlayCamera-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{804F1285-8CBF-408D-8CDC-D4D40003B2E4}\setup.exe" -l0x40c
              PowerDirector-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\setup.exe" -uninstall
              PowerDVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
              PowerProducer-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\setup.exe" -uninstall
              PunkBuster Services-->C:\Windows\system32\pbsvc.exe -u
              QuickTime-->MsiExec.exe /I{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}
              Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\setup.exe" -removeonly
              Samsung Magic Doctor-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{32D6A58F-9659-446C-BBFC-E6F2B41F24DC}\Setup.exe" -l0x9 Remove
              Samsung Mobility Panel-->MsiExec.exe /I{231F1242-35FB-4A1F-8E93-600BCE767941}
              Samsung Recovery Solution III-->"C:\Program Files\InstallShield Installation Information\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}\setup.exe" -runfromtemp -l0x040c -removeonly
              Samsung Update Plus-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\10\INTEL3~1\IDriver.exe /M{685707A4-911C-468D-BFC4-64A50E5E3A0C} /l1036
              Security Update for Windows Media Encoder (KB954156)-->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E} MSIPATCHREMOVE={E836F1B7-43FB-46B0-A0D9-E4D2A5951659} /qb
              Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
              Spyware Terminator-->"C:\Program Files\Spyware Terminator\unins000.exe"
              Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
              System Requirements Lab-->C:\Program Files\SystemRequirementsLab\Uninstall.exe
              Trojan Remover 6.7.8-->"C:\Program Files\Trojan Remover\unins000.exe"
              Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
              Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
              Update for Microsoft Office Outlook 2007 Help (KB957246)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {80E46078-C1C5-4AE8-8744-3EAFC812E118}
              Update for Microsoft Office Outlook 2007 Help (KB957246)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {80E46078-C1C5-4AE8-8744-3EAFC812E118}
              Update for Outlook 2007 Junk Email Filter (kb968503)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {5DD98950-4D10-4B79-8BF6-59726705207D}
              Update for Outlook 2007 Junk Email Filter (kb968503)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {5DD98950-4D10-4B79-8BF6-59726705207D}
              User Guide-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}\setup.exe" -l0x9 Remove
              Vimicro UVC Camera-->C:\Program Files\InstallShield Installation Information\{71A51B09-E7D3-11DB-A386-005056C00008}\setup.exe -runfromtemp -l0x0009 -removeonly
              VLC media player 0.9.8a-->C:\Program Files\VideoLAN\VLC\uninstall.exe
              WIDCOMM Bluetooth Software 6.0.1.6300-->MsiExec.exe /X{03D1988F-469F-4843-8E6E-E5FE9D17889D}
              Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
              Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
              Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
              Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
              Windows Live Movie Maker Bêta-->MsiExec.exe /X{F874DF52-A31F-44C1-A606-EF40F1549261}
              Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
              Windows Live Writer-->MsiExec.exe /X{2231CE39-B963-4B9D-823A-F412ECA637B1}
              Windows Media Encoder 9 Series-->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
              Windows Media Encoder 9 Series-->MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
              XLink Kai-->MsiExec.exe /X{87C24822-389C-45AA-9E75-0757B8F1A892}
              ZyDAS IEEE 802.11 b+g Wireless LAN - USB-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{581CE7EA-A30D-0000-1211-088635773309}\Setup.exe" -l0x9

              ======Hosts File======

              127.0.0.1 www.007guard.com
              127.0.0.1 007guard.com
              127.0.0.1 008i.com
              127.0.0.1 www.008k.com
              127.0.0.1 008k.com
              127.0.0.1 www.00hq.com
              127.0.0.1 00hq.com
              127.0.0.1 010402.com
              127.0.0.1 www.032439.com
              127.0.0.1 032439.com

              ======Security center information======

              AS: Spybot - Search and Destroy
              AS: Windows Defender
              AS: Spyware Terminator (disabled)

              ======System event log======

              Computer Name: LEROUX
              Event Code: 3004
              Message: L’agent de protection en temps réel Windows Defender a détecté des modifications. Microsoft vous recommande d’analyser les logiciels responsables de ces modifications, à la recherche de risques potentiels. Vous pouvez vous servir des informations relatives au fonctionnement de ces programmes pour autoriser ou non leur exécution, ou pour les supprimer de l’ordinateur. N’autorisez les modifications que si vous faites confiance au programme ou à l’éditeur de logiciel. Windows Defender ne peut pas annuler les modifications que vous autorisez.
              Pour plus d’informations, consultez les données suivantes :
              Non applicable
              ID d’analyse : {F30DEEBC-B377-457A-A6EC-CF58CF477DAA}
              Utilisateur : LEROUX\Virginie
              Nom : Unknown
              ID :
              ID de gravité :
              ID de catégorie :
              Chemin d’accès trouvé : clsid:HKLM\SOFTWARE\CLASSES\CLSID\{52B87208-9CCF-42C9-B88E-069281105805};regkey:HKLM\SOFTWARE\CLASSES\CLSID\{52B87208-9CCF-42C9-B88E-069281105805};regkey:HKLM\Software\Classes\*\shellex\ContextMenuHandlers\Trojan Remover;contextmenu:HKLM\Software\Classes\*\shellex\ContextMenuHandlers\Trojan Remover;file:C:\Program Files\Trojan Remover\Trshlex.dll
              Type d’alerte : Logiciel non classifié
              Type de détection :
              Record Number: 57610
              Source Name: Microsoft-Windows-Windows Defender
              Time Written: 20090512090935.000000-000
              Event Type: Avertissement
              User:

              Computer Name: LEROUX
              Event Code: 3004
              Message: L’agent de protection en temps réel Windows Defender a détecté des modifications. Microsoft vous recommande d’analyser les logiciels responsables de ces modifications, à la recherche de risques potentiels. Vous pouvez vous servir des informations relatives au fonctionnement de ces programmes pour autoriser ou non leur exécution, ou pour les supprimer de l’ordinateur. N’autorisez les modifications que si vous faites confiance au programme ou à l’éditeur de logiciel. Windows Defender ne peut pas annuler les modifications que vous autorisez.
              Pour plus d’informations, consultez les données suivantes :
              Non applicable
              ID d’analyse : {1FEE9A75-0CCB-41D6-ABB3-EEDDB50E50F7}
              Utilisateur : LEROUX\Virginie
              Nom : Unknown
              ID :
              ID de gravité :
              ID de catégorie :
              Chemin d’accès trouvé : regkey:HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\TrojanScanner;runkey:HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\TrojanScanner;file:C:\Program Files\Trojan Remover\Trjscan.exe
              Type d’alerte : Logiciel non classifié
              Type de détection :
              Record Number: 57613
              Source Name: Microsoft-Windows-Windows Defender
              Time Written: 20090512090938.000000-000
              Event Type: Avertissement
              User:

              Computer Name: LEROUX
              Event Code: 15016
              Message: Impossible d’initialiser le package de sécurité Kerberos pour l’authentification côté serveur. Le champ de données contient le numéro de l’erreur.
              Record Number: 57636
              Source Name: Microsoft-Windows-HttpEvent
              Time Written: 20090512091141.368555-000
              Event Type: Erreur
              User:

              Computer Name: LEROUX
              Event Code: 7000
              Message: Le service Parallel port driver n'a pas pu démarrer en raison de l'erreur :
              Le service ne peut pas être démarré parce qu'il est désactivé ou qu'aucun périphérique activé ne lui est associé.
              Record Number: 57674
              Source Name: Service Control Manager
              Time Written: 20090512091148.000000-000
              Event Type: Erreur
              User:

              Computer Name: LEROUX
              Event Code: 1001
              Message: L’initialisation de l’application a échoué. Dernière erreur : 0x80070032
              Record Number: 57725
              Source Name: Microsoft-Windows-LanguagePackSetup
              Time Written: 20090512091212.282355-000
              Event Type: Erreur
              User: AUTORITE NT\SYSTEM

              =====Application event log=====
              0
              1. par contre j'ai que le log
                pas l'autre
                0
                1. Re

                  Il est normalement ici:C:\rsit

                  Ensuite;Lance hijackthis ; ici : C:\Program Files\Trend Micro\HijackThis\Virginie.exe

                  mais cette fois clic sur "Do a system scan only"

                  ensuite coches les cases sur la gauche des ces lignes :
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ww12.cherche.us
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ww12.cherche.us
                  R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.cherche.us/keyword/%s
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://ww12.cherche.us
                  O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                  O4 - Global Startup: BTTray.lnk = ?
                  O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
                  ;ensuite tu cliques sur la fenêtre "Fix cheked".
                  HijackThis va te demander de confirmer que tu veux supprimer ces éléments. Cliques sur Yes (Oui) ) .

                  Tuto ici:https://www.bleepingcomputer.com/tutorials/comment-utiliser-hijackthis/#RDiag

                  Comment se comporte ton MSN? Envoies tu encore des messages?

                  @+
                  0
              2. [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

                [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

                ======List of files/folders created in the last 2 months======

                2010-03-06 09:54:27 ----RASHD---- C:\autorun.inf
                2010-03-06 09:50:11 ----A---- C:\UsbFix.txt
                2010-03-06 09:41:26 ----D---- C:\UsbFix
                2010-03-06 09:08:55 ----D---- C:\Users\Virginie\AppData\Roaming\QuickScan
                2010-03-04 20:41:08 ----SHD---- C:\Config.Msi
                2010-03-04 20:16:27 ----D---- C:\ProgramData\FLEXnet
                2010-02-04 20:41:55 ----D---- C:\ProgramData\Sun
                2010-02-04 20:41:53 ----D---- C:\Program Files\Common Files\Java
                2010-02-04 20:41:35 ----A---- C:\Windows\system32\javaws.exe
                2010-02-04 20:41:35 ----A---- C:\Windows\system32\javaw.exe
                2010-02-04 20:41:35 ----A---- C:\Windows\system32\java.exe
                2010-01-23 10:21:30 ----D---- C:\Program Files\Google
                2010-01-23 10:21:30 ----D---- C:\Program Files\DivX

                ======List of files/folders modified in the last 2 months======

                2010-03-06 10:03:48 ----D---- C:\Windows\Temp
                2010-03-06 10:00:56 ----D---- C:\Program Files\trend micro
                2010-03-06 09:56:55 ----D---- C:\Program Files\Mozilla Firefox
                2010-03-06 09:53:25 ----SHD---- C:\$Recycle.Bin
                2010-03-06 09:43:36 ----D---- C:\Windows\tracing
                2010-03-06 09:39:50 ----D---- C:\Users\Virginie\AppData\Roaming\Spyware Terminator
                2010-03-06 09:39:49 ----D---- C:\Program Files\Spyware Terminator
                2010-03-05 08:53:56 ----D---- C:\Windows\Prefetch
                2010-03-04 20:58:54 ----SHD---- C:\Windows\Installer
                2010-03-04 20:57:51 ----D---- C:\Program Files\Common Files\Adobe
                2010-03-04 20:57:50 ----D---- C:\Program Files\Common Files
                2010-03-04 20:55:56 ----D---- C:\Program Files\Adobe
                2010-03-04 20:55:31 ----D---- C:\Users\Virginie\AppData\Roaming\Adobe
                2010-03-04 20:55:31 ----D---- C:\ProgramData\Adobe
                2010-03-04 20:48:12 ----D---- C:\Windows\system32\drivers
                2010-03-04 20:42:49 ----D---- C:\Windows\System32
                2010-03-04 20:41:55 ----RD---- C:\Program Files
                2010-03-04 20:41:47 ----SHD---- C:\System Volume Information
                2010-03-04 20:16:27 ----D---- C:\ProgramData
                2010-03-04 19:57:40 ----RSD---- C:\Windows\Fonts
                2010-03-01 12:12:16 ----D---- C:\Program Files\Microsoft Silverlight
                2010-02-28 14:07:35 ----D---- C:\Windows\system32\catroot2
                2010-02-26 20:04:02 ----D---- C:\Windows\inf
                2010-02-26 20:04:02 ----A---- C:\Windows\system32\PerfStringBackup.INI
                2010-02-26 16:18:55 ----D---- C:\Windows
                2010-02-24 08:55:59 ----D---- C:\Windows\system32\catroot
                2010-02-24 08:55:53 ----D---- C:\Windows\winsxs
                2010-02-11 18:28:24 ----D---- C:\ProgramData\Spyware Terminator
                2010-02-09 17:16:45 ----D---- C:\ProgramData\Spybot - Search & Destroy
                2010-02-08 17:06:58 ----SD---- C:\Windows\Downloaded Program Files
                2010-02-08 14:47:36 ----D---- C:\Program Files\MyDefrag v4.2.5
                2010-02-04 20:41:29 ----D---- C:\Program Files\Java
                2010-02-01 15:41:49 ----SD---- C:\Users\Virginie\AppData\Roaming\Microsoft
                2010-01-23 11:34:10 ----D---- C:\Windows\Tasks
                2010-01-23 11:34:10 ----D---- C:\ProgramData\Google
                2010-01-23 10:29:59 ----D---- C:\Windows\system32\Tasks

                ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

                R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2009-11-25 23120]
                R1 aswSP;avast! Self Protection; C:\Windows\system32\drivers\aswSP.sys [2009-09-15 114768]
                R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2009-11-25 48560]
                R2 aswFsBlk;aswFsBlk; C:\Windows\system32\DRIVERS\aswFsBlk.sys [2009-09-15 20560]
                R2 aswMonFlt;aswMonFlt; C:\Windows\system32\DRIVERS\aswMonFlt.sys [2009-09-15 53328]
                R2 KMDFMEMIO;SAMSUNG Kernel Driver; C:\Windows\system32\DRIVERS\kmdfmemio.sys [2008-12-30 13312]
                R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2008-04-27 909824]
                R3 CmBatt;Pilote pour Batterie à méthode de contrôle ACPI Microsoft; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-21 14208]
                R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
                R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-09-23 26176]
                R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-07-07 2152088]
                R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda32v.sys [2009-01-22 52768]
                R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2008-07-27 7548000]
                R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\Windows\System32\Drivers\RootMdm.sys [2008-01-21 8192]
                R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2007-10-26 193456]
                R3 VMC302;Vimicro Camera Service VMC302; C:\Windows\System32\Drivers\VMC302.sys [2008-06-05 242048]
                R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2008-06-27 303616]
                R3 ZDPSp50;ZDPSp50 NDIS Protocol Driver; C:\Windows\System32\Drivers\ZDPSp50.sys [2004-10-25 17664]
                S2 adfs;adfs; C:\Windows\system32\drivers\adfs.sys []
                S3 ag52skom;ag52skom; C:\Windows\system32\drivers\ag52skom.sys []
                S3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2008-03-21 1203776]
                S3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller XP Driver; C:\Windows\system32\DRIVERS\bcm4sbxp.sys [2006-11-02 45056]
                S3 BthEnum;Pilote de bloc de demande Bluetooth; C:\Windows\system32\DRIVERS\BthEnum.sys [2008-01-21 19456]
                S3 BthPan;Périphérique Bluetooth (réseau personnel); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
                S3 BTHPORT;Pilote de port Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2008-04-29 220160]
                S3 BTHUSB;Pilote USB radio Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2008-04-29 29184]
                S3 btwaudio;Périphérique audio Bluetooth; C:\Windows\system32\drivers\btwaudio.sys [2008-02-14 80424]
                S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2007-07-15 80936]
                S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2007-07-15 16168]
                S3 driverhardwarev2;driverhardwarev2; \??\C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys [2009-05-29 14336]
                S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
                S3 HdAudAddService;Pilote de fonction UAA 1.1 Microsoft pour le service High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
                S3 ialm;ialm; C:\Windows\system32\DRIVERS\igdkmd32.sys [2006-10-19 1380864]
                S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
                S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
                S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
                S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
                S3 NETw3v32;Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw3v32.sys [2008-01-21 2225664]
                S3 PsSdk41;PsSdk41; \??\C:\Windows\system32\Drivers\pssdk41.sys [2009-05-04 36928]
                S3 RFCOMM;Périphérique Bluetooth (TDI protocole RFCOMM); C:\Windows\system32\DRIVERS\rfcomm.sys [2008-02-21 50688]
                S3 tosporte;Bluetooth COM Port; C:\Windows\system32\DRIVERS\tosporte.sys []
                S3 tosrfbd;Bluetooth RFBUS; C:\Windows\system32\DRIVERS\tosrfbd.sys []
                S3 tosrfbnp;Bluetooth RFBNEP; C:\Windows\System32\Drivers\tosrfbnp.sys []
                S3 Tosrfcom;Bluetooth RFCOMM; C:\Windows\System32\Drivers\tosrfcom.sys []
                S3 Tosrfhid;Bluetooth RFHID; C:\Windows\system32\DRIVERS\Tosrfhid.sys []
                S3 tosrfnds;Bluetooth Personal Area Network; C:\Windows\system32\DRIVERS\tosrfnds.sys []
                S3 TosRfSnd;Bluetooth Audio; C:\Windows\system32\drivers\tosrfsnd.sys []
                S3 Tosrfusb;Bluetooth USB Controller; C:\Windows\system32\DRIVERS\tosrfusb.sys []
                S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2009-08-28 40448]
                S3 usbbus;LGE Mobile Composite USB Device; C:\Windows\system32\DRIVERS\lgusbbus.sys [2007-07-11 12416]
                S3 UsbDiag;LGE Mobile USB Serial Port; C:\Windows\system32\DRIVERS\lgusbdiag.sys [2007-07-11 19840]
                S3 USBModem;LGE Mobile USB Modem; C:\Windows\system32\DRIVERS\lgusbmodem.sys [2007-07-11 21632]
                S3 usbvideo;Périphérique vidéo USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
                S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
                S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
                S3 xnacc;Contrôleur XBOX 360 pour le service de pilote Windows; C:\Windows\system32\DRIVERS\xnacc.sys [2008-01-21 521216]
                S3 ZD1211BU(ZyDAS);ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS); C:\Windows\system32\DRIVERS\zd1211Bu.sys [2005-10-28 402432]
                S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
                S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
                S4 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-21 88576]
                S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2008-01-21 11264]

                ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

                R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-08-28 144672]
                R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-11-25 18752]
                R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-11-25 138680]
                R2 BcmSqlStartupSvc;Service de démarrage SQL Server pour le Gestionnaire de contacts professionnels; C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [2008-01-16 30312]
                R2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
                R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
                R2 EvtEng;Intel® PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2008-07-10 819200]
                R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [2009-10-29 1074568]
                R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-03-17 73728]
                R2 NMSAccessU;NMSAccessU; C:\Program Files\CDBurnerXP\NMSAccessU.exe [2009-07-13 71096]
                R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2008-07-27 196608]
                R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2009-05-09 66872]
                R2 RegSrvc;Intel® PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2008-07-10 466944]
                R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2006-12-19 272024]
                R2 SBSDWSCService;SBSD Security Center Service; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
                R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
                R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2009-05-10 487424]
                R2 SQLBrowser;SQL Server Browser; C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2008-11-24 239968]
                R2 SQLWriter;Enregistreur VSS SQL Server; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-11-24 87904]
                R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-11-25 254040]
                R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-11-25 352920]
                R3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
                S2 Samsung Update Plus;Samsung Update Plus; C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe [2008-05-13 77480]
                S3 aspnet_state;Service d'état ASP.NET; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2009-03-30 31048]
                S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
                S3 iPod Service;Service de l’iPod; C:\Program Files\iPod\bin\iPodService.exe [2009-09-21 545568]
                S3 maconfservice;Ma-Config Service; C:\Program Files\ma-config.com\maconfservice.exe [2009-05-29 234864]
                S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ); C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2009-05-27 29262680]
                S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
                S4 MSSQLServerADHelper;SQL Server Active Directory Helper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2008-11-24 45408]

                -----------------EOF-----------------
                0
                1. Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
                  System drive C: has 53 GB (36%) free of 148 GB
                  Total RAM: 3066 MB (69% free)

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 10:04:29, on 06/03/2010
                  Platform: Windows Vista SP2 (WinNT 6.00.1906)
                  MSIE: Internet Explorer v7.00 (7.00.6002.18005)
                  Boot mode: Normal

                  Running processes:
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\system32\Dwm.exe
                  C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe
                  C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
                  C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe
                  C:\Windows\system32\conime.exe
                  C:\Windows\explorer.exe
                  C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
                  C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe
                  C:\Users\Virginie\Downloads\RSIT.exe
                  C:\Program Files\Trend Micro\HijackThis\Virginie.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.cherche.us
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.cherche.us
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                  R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.cherche.us/keyword/%s
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.cherche.us
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                  O1 - Hosts: ::1 localhost
                  O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                  O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                  O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                  O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                  O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                  O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                  O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
                  O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\system32\NeroCheck.exe
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                  O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
                  O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                  O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
                  O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                  O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
                  O4 - HKCU\..\Run: [Speech Recognition] "C:\Windows\Speech\Common\sapisvr.exe" -SpeechUX -Startup
                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                  O4 - Global Startup: BTTray.lnk = ?
                  O4 - Global Startup: ZDWLan Utility.lnk = C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                  O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                  O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                  O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
                  O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                  O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                  O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O13 - Gopher Prefix:
                  O15 - Trusted Zone: *.chat-land.org
                  O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                  O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
                  O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
                  O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                  O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
                  O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
                  O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
                  O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
                  O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
                  O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                  O23 - Service: Samsung Update Plus - Unknown owner - C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe
                  O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                  O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
                  0
                  1. Intel(R) Pentium(R) Dual CPU T3400 @ 2.16GHz
                    Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
                    Internet Explorer 7.0.6002.18005
                    Windows Firewall Status : Enabled

                    C:\ -> Disque fixe local # 144,09 Go (51,69 Go free) # NTFS
                    D:\ -> Disque fixe local # 144 Go (69,37 Go free) # NTFS
                    E:\ -> Disque CD-ROM
                    F:\ -> Disque CD-ROM
                    G:\ -> Disque CD-ROM

                    ################## | Elements infectieux |

                    Supprimé ! C:\Users\Virginie\Documents - Raccourci.lnk
                    Supprimé ! C:\$Recycle.Bin\S-1-5-21-3317431821-2754218308-1391888111-500
                    Supprimé ! C:\$Recycle.Bin\S-1-5-21-648204624-3893815093-3798972402-1003
                    Supprimé ! C:\$Recycle.Bin\S-1-5-21-648204624-3893815093-3798972402-1006
                    Supprimé ! C:\$Recycle.Bin\S-1-5-21-648204624-3893815093-3798972402-500
                    Supprimé ! C:\$Recycle.Bin\S-1-5-21-648204624-3893815093-3798972402-501
                    Supprimé ! D:\$Recycle.Bin\S-1-5-21-648204624-3893815093-3798972402-1003
                    Supprimé ! D:\$Recycle.Bin\S-1-5-21-648204624-3893815093-3798972402-1006
                    Supprimé ! D:\$Recycle.Bin\S-1-5-21-648204624-3893815093-3798972402-501

                    ################## | Registre |

                    ################## | Mountpoints2 |

                    Supprimé ! HKCU\...\Explorer\MountPoints2\{1845bb55-64ec-11de-a2a7-001377d5b71e}\Shell\AutoRun\Command
                    Supprimé ! HKCU\...\Explorer\MountPoints2\{1fced380-ab32-11de-ac91-001377d5b71e}\Shell\AutoRun\Command

                    ################## | Listing des fichiers présent |

                    [18/09/2006 22:43|--a------|24] C:\autoexec.bat
                    [11/04/2009 07:36|-rahs----|333257] C:\bootmgr
                    [08/02/2008 10:31|-ra-s----|8192] C:\BOOTSECT.BAK
                    [18/09/2006 22:43|--a------|10] C:\config.sys
                    [27/04/2009 12:34|--a------|148] C:\dxlog.txt
                    [07/01/2009 02:33|-rahs----|0] C:\IO.SYS
                    [07/01/2009 02:33|-rahs----|0] C:\MSDOS.SYS
                    [?|?|?] C:\pagefile.sys
                    [03/11/2009 17:47|--a------|417] C:\RHDSetup.log
                    [03/11/2009 18:04|--a------|173] C:\setup.log
                    [29/04/2009 13:43|--a------|0] C:\Tech_Vista.log
                    [06/03/2010 09:54|--a------|2241] C:\UsbFix.txt

                    ################## | Vaccination |

                    # C:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
                    # D:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).

                    ################## | Upload |

                    Veuillez envoyer le fichier : C:\UsbFix_Upload_Me_LEROUX.zip : https://www.ionos.fr/?affiliate_id=77097
                    Merci pour votre contribution .

                    ################## | ! Fin du rapport # UsbFix V6.098 ! |
                    0
                    1. pardon, jai pas fai l'option 2
                      0
                      1. Intel(R) Pentium(R) Dual CPU T3400 @ 2.16GHz
                        Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
                        Internet Explorer 7.0.6002.18005
                        Windows Firewall Status : Enabled

                        C:\ -> Disque fixe local # 144,09 Go (51,83 Go free) # NTFS
                        D:\ -> Disque fixe local # 144 Go (69,37 Go free) # NTFS
                        E:\ -> Disque CD-ROM
                        F:\ -> Disque CD-ROM # 2,32 Go (0 Mo free) [FM2010] # UDF
                        G:\ -> Disque CD-ROM

                        ################## | Elements infectieux |

                        C:\Users\Virginie\Documents - Raccourci.lnk
                        F:\autorun.inf

                        ################## | Registre |

                        ################## | Mountpoints2 |

                        HKCU\..\..\Explorer\MountPoints2\{1845bb55-64ec-11de-a2a7-001377d5b71e}
                        shell\AutoRun\command =F:\InstallTomTomHOME.exe

                        HKCU\..\..\Explorer\MountPoints2\{1fced380-ab32-11de-ac91-001377d5b71e}
                        shell\AutoRun\command =F:\autorun.exe

                        ################## | Vaccin |

                        ################## | ! Fin du rapport # UsbFix V6.098 ! |
                        0
                        1. Re

                          Pour de plus amples informations;fait ceci stp;merci

                          a) Télécharge et installe le logiciel HijackThis :

                          https://www.commentcamarche.net/telecharger/securite/11747-hijackthis/
                          ou ici http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe
                          ou ici https://www.clubic.com/telecharger-fiche17891-hijackthis.html

                          -->Clique sur le setup pour lancer l'installation : laisse toi guider et ne modifie pas les paramètres d'installation .
                          A la fin de l’installation, le programme se lance automatiquement : ferme le en cliquant sur la croix rouge.
                          Au final, tu dois avoir un raccourci sur ton bureau et aussi un cheminement comme :
                          "C:\ program files\Trend Micro\HijackThis\HijackThis.exe " .

                          (Ne lance pas ce prg pour l'instant et fais la suite ... )

                          b) Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

                          -> http://images.malwareremoval.com/random/RSIT.exe

                          ! Déconnecte toi et ferme toutes tes applications en cours !

                          Double-clique sur " RSIT.exe " pour le lancer.

                          Clic droit sous VISTA (exécuter en tant que…)

                          -> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

                          * Devant l'option "List files/folders created ..." , tu choisis : 2 months

                          * clique ensuite sur " Continue " pour lancer l'analyse ...

                          -> laisse faire le scan et ne touche pas au PC ...

                          Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-notes).

                          Poste le contenu de " log.txt " (c'est celui qui apparaît à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

                          Important : poste un rapport, puis l'autre dans la réponse suivante ...
                          Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum ...
                          ( Et si "log.txt" seul, ne passe pas non plus , fais le en 2 fois ... merci ... )

                          ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit

                          @+
                          0
                      • 1
                      • 2