Virus ou pas ??

Logfile of random's system information tool 1.06 (written by random/random)
Run by Jules at 2010-03-21 12:24:42
Microsoft® Windows Vista(TM) Édition Familiale Premium Service Pack 1
System drive C: has 45 GB (10%) free of 469 GB
Total RAM: 2046 MB (51% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:26:44, on 21/03/2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18385)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Bywifi\bywifi.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\WinApplication\WinApplication.exe
C:\Users\Jules\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\conime.exe
C:\Users\Jules\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\UI0Detect.exe
C:\Users\Jules\Documents\Downloads\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Jules.exe
C:\Users\Jules\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jules\AppData\Local\Google\Chrome\Application\chrome.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.ask.com/?o=0&l=dir&ad=dirN
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://localhost:9000/proxy.pac
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - (no file)
O2 - BHO: SBCONVERT - {31B27F2D-6BC6-451B-B3D2-4EAB36B2FC3B} - C:\Program Files\SpeedBit Video Downloader\Toolbar\tbcore3.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: BywifiBHO - {C4743D3E-20D7-4B52-84F2-5E4E277B2D82} - C:\Program Files\Bywifi\bywifiie.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: GrabberObj Class - {FF7C3CF0-4B15-11D1-ABED-709549C10000} - C:\PROGRA~1\SPEEDB~1\Toolbar\grabber.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (file missing)
O3 - Toolbar: SpeedBit Video Downloader - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - C:\Program Files\SpeedBit Video Downloader\Toolbar\tbcore3.dll
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [bywifi] C:\Program Files\Bywifi\bywifi.exe "-silent"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Users\Jules\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [LosAlamos] rundll32.exe C:\Windows\system32\sshnas.dll,AddConsoleAliasAW
O4 - HKCU\..\Run: [PUT2VIDQLG] C:\Users\Jules\AppData\Local\Temp\d.exe
O4 - HKCU\..\Run: [bywifi] C:\Program Files\Bywifi\bywifi.exe "-silent"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [RGSC] C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
O4 - Global Startup: Application.lnk = C:\Program Files\WinApplication\WinApplication.exe
O9 - Extra button: Bywifi: Video Downloader - {09E90109-A9AA-4980-BCEF-76F8D924E902} - C:\Program Files\Bywifi\bywifici.exe
O9 - Extra 'Tools' menuitem: Bywifi: Video Downloader - {09E90109-A9AA-4980-BCEF-76F8D924E902} - C:\Program Files\Bywifi\bywifici.exe
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Bywifi: Video Downloader - {09E90109-A9AA-4980-BCEF-76F8D924E902} - C:\Program Files\Bywifi\bywifici.exe (HKCU)
O9 - Extra 'Tools' menuitem: Bywifi: Video Downloader - {09E90109-A9AA-4980-BCEF-76F8D924E902} - C:\Program Files\Bywifi\bywifici.exe (HKCU)
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Application Driver Auto Removal Service (01) (appdrvrem01) - Protection Technology - C:\Windows\System32\appdrvrem01.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - Unknown owner - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2009.SP4\RpcAgentSrv.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe

--
End of file - 9755 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Extension de garantie.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-829625975-2554254917-1831524914-1003Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-829625975-2554254917-1831524914-1003UA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-829625975-2554254917-1831524914-1004Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-829625975-2554254917-1831524914-1004UA.job
C:\Windows\tasks\Maintenance en 1 clic.job
C:\Windows\tasks\Recovery DVD Creator.job
C:\Windows\tasks\User_Feed_Synchronization-{208DB4DA-6CA6-45DC-BC70-11C378459701}.job
C:\Windows\tasks\User_Feed_Synchronization-{76461DD1-B6E6-4076-BBA9-EF584055E07F}.job
C:\Windows\tasks\User_Feed_Synchronization-{E9994E27-B913-4BBB-A62C-60E7B671623C}.job
C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
C:\Windows\tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1E8A6170-7264-4D0F-BEAE-D42A53123C75}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31B27F2D-6BC6-451B-B3D2-4EAB36B2FC3B}]
SBCONVERT Class - C:\Program Files\SpeedBit Video Downloader\Toolbar\tbcore3.dll [2010-01-02 2655736]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C4743D3E-20D7-4B52-84F2-5E4E277B2D82}]
BywifiBHO Class - C:\Program Files\Bywifi\bywifiie.dll [2009-12-31 720896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FF7C3CF0-4B15-11D1-ABED-709549C10000}]
GrabberObj Class - C:\PROGRA~1\SPEEDB~1\Toolbar\grabber.dll [2010-01-02 185944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll []
{0329E7D6-6F54-462D-93F6-F5C3118BADF2} - SpeedBit Video Downloader - C:\Program Files\SpeedBit Video Downloader\Toolbar\tbcore3.dll [2010-01-02 2655736]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-03-01 4390912]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
"AdobeCS4ServiceManager"=C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [2008-08-14 611712]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-11-10 417792]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-11-12 141600]
"bywifi"=C:\Program Files\Bywifi\bywifi.exe [2009-12-31 2199552]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]
"LifeCam"=C:\Program Files\Microsoft LifeCam\LifeExp.exe [2010-03-01 119152]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883856]
"Google Update"=C:\Users\Jules\AppData\Local\Google\Update\GoogleUpdate.exe [2009-03-20 133104]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-19 125952]
"uTorrent"=C:\Program Files\uTorrent\uTorrent.exe [2010-02-17 319280]
"LosAlamos"=C:\Windows\system32\sshnas.dll,AddConsoleAliasAW []
"PUT2VIDQLG"=C:\Users\Jules\AppData\Local\Temp\d.exe []
"bywifi"=C:\Program Files\Bywifi\bywifi.exe [2009-12-31 2199552]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-19 202240]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-12-29 687560]
"RGSC"=C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe [2008-11-14 305064]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Application.lnk - C:\Program Files\WinApplication\WinApplication.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=95000000
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\Orange\Connectivity\ConnectivityManager.exe"="C:\Program Files\Orange\Connectivity\ConnectivityManager.exe:*:enabled:CSS"
"C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\N]
shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RECYCLER\S-0-9-40-100000880-100004925-100011867-8555.com n:\
shell\Open\command - RECYCLER\S-0-9-40-100000880-100004925-100011867-8555.com n:\

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{02bee381-2f2c-11dd-a414-001c252f6b0c}]
shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RECYCLER\S-0-9-40-100000880-100004925-100011867-8555.com n:\
shell\Open\command - RECYCLER\S-0-9-40-100000880-100004925-100011867-8555.com n:\

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bbb503c0-f03e-11dc-8971-001c252f6b0c}]
shell\AutoRun\command - L:\autorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d8f2c9ec-773a-11dd-a897-001c252f6b0c}]
shell\AutoRun\command - I:\Autorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e32111ca-bc7d-11dc-bca7-001c252f6b0c}]
shell\AutoRun\command - I:\OblivionLauncher.exe

======List of files/folders created in the last 1 months======

2010-03-14 11:17:08 ----A---- C:\Windows\system32\browserchoice.exe
2010-03-12 14:25:26 ----A---- C:\Windows\system32\nshhttp.dll
2010-03-12 14:25:25 ----A---- C:\Windows\system32\httpapi.dll
2010-03-07 21:39:48 ----A---- C:\Windows\system32\OpenCL.dll
2010-03-07 21:39:47 ----A---- C:\Windows\system32\nvwgf2um.dll
2010-03-07 21:39:46 ----A---- C:\Windows\system32\nvoglv32.dll
2010-03-07 21:39:46 ----A---- C:\Windows\system32\nvcuvid.dll
2010-03-07 21:39:44 ----A---- C:\Windows\system32\nvcuvenc.dll
2010-03-07 21:39:44 ----A---- C:\Windows\system32\nvcuda.dll
2010-03-07 21:39:44 ----A---- C:\Windows\system32\nvcompiler.dll
2010-03-07 21:39:44 ----A---- C:\Windows\system32\nvcod189.dll
2010-03-07 21:39:44 ----A---- C:\Windows\system32\nvcod.dll
2010-03-07 12:48:00 ----D---- C:\Program Files\Microsoft LifeCam
2010-03-06 18:59:38 ----D---- C:\Program Files\NVIDIA Corporation
2010-03-06 18:07:08 ----D---- C:\Windows\1C4551A64743409391E41477CD655043.TMP
2010-03-05 19:30:01 ----D---- C:\Program Files\AIDA32 - Personal System Information
2010-03-05 19:26:21 ----D---- C:\Program Files\Lavalys
2010-03-05 19:08:36 ----D---- C:\Program Files\Belarc
2010-03-04 21:07:10 ----A---- C:\Windows\system32\pbsvc_bc2.exe
2010-03-02 22:26:01 ----D---- C:\Windows\system32\xlive
2010-03-02 22:26:00 ----D---- C:\Program Files\Microsoft Games for Windows - LIVE
2010-03-02 21:28:34 ----D---- C:\Program Files\Rockstar Games
2010-03-01 21:55:28 ----D---- C:\Program Files\Common Files\INCA Shared
2010-03-01 18:53:56 ----D---- C:\Program Files\RocketDock
2010-03-01 18:34:32 ----D---- C:\Program Files\gPotato.eu
2010-02-24 10:47:37 ----A---- C:\Windows\system32\tzres.dll
2010-02-24 10:46:58 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2010-02-24 10:46:58 ----A---- C:\Windows\system32\secproc_ssp.dll
2010-02-24 10:46:58 ----A---- C:\Windows\system32\secproc_isv.dll
2010-02-24 10:46:58 ----A---- C:\Windows\system32\secproc.dll
2010-02-24 10:46:58 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2010-02-24 10:46:58 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2010-02-24 10:46:58 ----A---- C:\Windows\system32\RMActivate_isv.exe
2010-02-24 10:46:58 ----A---- C:\Windows\system32\RMActivate.exe
2010-02-24 10:46:58 ----A---- C:\Windows\system32\msdrm.dll

======List of files/folders modified in the last 1 months======

2010-03-21 12:26:43 ----D---- C:\Users\Jules\AppData\Roaming\uTorrent
2010-03-21 12:26:07 ----D---- C:\Windows\temp
2010-03-21 12:25:32 ----D---- C:\BywifiShare
2010-03-21 12:24:53 ----D---- C:\Windows\Prefetch
2010-03-21 12:24:42 ----D---- C:\rsit
2010-03-21 12:21:46 ----D---- C:\Windows\tracing
2010-03-21 12:21:45 ----D---- C:\ProgramData\NVIDIA
2010-03-21 11:48:21 ----D---- C:\Program Files\Steam
2010-03-21 09:47:38 ----AD---- C:\Windows\System32
2010-03-21 09:47:38 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-03-21 09:47:37 ----D---- C:\Windows\inf
2010-03-19 21:01:23 ----A---- C:\Windows\system32\PnkBstrB.exe
2010-03-19 11:22:05 ----SHD---- C:\System Volume Information
2010-03-14 22:05:03 ----SHD---- C:\Windows\Installer
2010-03-14 22:05:02 ----HD---- C:\Config.Msi
2010-03-14 22:04:44 ----RSD---- C:\Windows\assembly
2010-03-14 11:18:01 ----D---- C:\Windows\winsxs
2010-03-14 11:17:57 ----D---- C:\Windows\system32\catroot
2010-03-14 11:17:56 ----D---- C:\Windows\system32\catroot2
2010-03-13 10:41:00 ----D---- C:\Windows\system32\drivers
2010-03-13 10:41:00 ----D---- C:\Program Files\Windows Mail
2010-03-13 10:41:00 ----D---- C:\Program Files\Movie Maker
2010-03-12 14:30:40 ----D---- C:\ProgramData\Microsoft Help
2010-03-12 14:27:37 ----D---- C:\Windows\Debug
2010-03-07 22:00:32 ----D---- C:\Windows
2010-03-07 21:40:34 ----D---- C:\Windows\system32\Tasks
2010-03-07 12:48:00 ----RD---- C:\Program Files
2010-03-06 19:22:38 ----D---- C:\ProgramData
2010-03-06 19:17:22 ----D---- C:\Windows\Help
2010-03-06 19:01:45 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-03-06 19:01:45 ----D---- C:\Program Files\AGEIA Technologies
2010-03-06 17:56:39 ----D---- C:\NVIDIA
2010-03-05 17:26:37 ----D---- C:\Program Files\Common Files\Steam
2010-03-04 22:12:04 ----A---- C:\Windows\system32\PnkBstrA.exe
2010-03-02 22:27:32 ----A---- C:\Windows\system32\CmdLineExt.dll
2010-03-02 21:41:32 ----HD---- C:\Program Files\InstallShield Installation Information
2010-03-02 06:30:12 ----A---- C:\Windows\system32\mrt.exe
2010-03-01 21:55:28 ----D---- C:\Program Files\Common Files
2010-02-26 10:15:24 ----D---- C:\Windows\rescache
2010-02-25 22:21:22 ----D---- C:\Windows\system32\fr-FR
2010-02-25 22:21:21 ----RSD---- C:\Windows\Fonts
2010-02-24 10:16:06 ----N---- C:\Windows\system32\MpSigStub.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 appdrv01;Application Driver (01); C:\Windows\System32\Drivers\appdrv01.sys [2009-07-20 3033712]
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys [2009-02-13 11608]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
R1 ssmdrv;ssmdrv; C:\Windows\system32\DRIVERS\ssmdrv.sys [2009-07-13 28520]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.3.0; C:\Windows\system32\DRIVERS\AegisP.sys [2008-01-16 20747]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2009-12-10 56816]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\System32\Drivers\GEARAspiWDM.sys [2009-05-18 26600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-03-01 1744928]
R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver; C:\Windows\System32\Drivers\nx6000.sys [2010-01-29 30576]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2010-01-12 11586280]
R3 RTL8023xp;Pilote Realtek 10/100 NIC Family NDIS x86; C:\Windows\system32\DRIVERS\Rtnicxp.sys [2006-11-02 47104]
R3 usbaudio;Pilote USB audio (WDM); C:\Windows\system32\drivers\usbaudio.sys [2008-01-19 73088]
R3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-19 134016]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]
S2 ADILOADER;General Purpose USB Driver (adildr.sys); C:\Windows\System32\Drivers\adildr.sys []
S3 ab99vxfy;ab99vxfy; C:\Windows\system32\drivers\ab99vxfy.sys []
S3 adiusbaw;USB ADSL WAN Adapter; C:\Windows\system32\DRIVERS\adiusbaw.sys []
S3 Dot4;Pilote MS IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-19 131584]
S3 Dot4Print;Pilote de classe Imprimante pour IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-19 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-19 36864]
S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
S3 Nokia USB Generic;Nokia USB Generic; C:\Windows\system32\drivers\nmwcdc.sys [2006-05-29 8704]
S3 Nokia USB Modem;Nokia USB Modem; C:\Windows\system32\drivers\nmwcdcm.sys [2006-05-29 13312]
S3 Nokia USB Phone Parent;Nokia USB Phone Parent; C:\Windows\system32\drivers\nmwcd.sys [2006-05-29 127488]
S3 PCAMp50;PCAMp50 NDIS Protocol Driver; C:\Windows\System32\Drivers\PCAMp50.sys [2006-11-28 28224]
S3 PCASp50;PCASp50 NDIS Protocol Driver; C:\Windows\System32\Drivers\PCASp50.sys [2006-11-28 27072]
S3 PnkBstrK;PnkBstrK; \??\C:\Windows\system32\drivers\PnkBstrK.sys [2010-03-19 139128]
S3 SANDRA;SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2009.SP4\WNt500x86\Sandra.sys []
S3 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys [2009-09-28 7168]
S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2009-08-28 40448]
S3 USBIO;USBIO Driver (usbio.sys); C:\Windows\System32\Drivers\usbio.sys [2001-05-07 19805]
S3 usbscan;Pilote de scanneur USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-19 35328]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-01-19 39936]
S3 xnacc;Contrôleur XBOX 360 pour le service de pilote Windows; C:\Windows\system32\DRIVERS\xnacc.sys [2008-01-19 521216]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirSchedulerService;Avira AntiVir Planificateur; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-07-13 108289]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-08-19 185089]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-08-28 144672]
R2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 FTRTSVC;France Telecom Routing Table Service; C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe [2007-09-25 65536]
R2 hpqddsvc;Service HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R2 MSCamSvc;MSCamSvc; C:\Program Files\Microsoft LifeCam\MSCamS32.exe [2010-03-01 139632]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-19 21504]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-01-11 129640]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-19 21504]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2010-03-04 75064]
R2 PnkBstrB;PnkBstrB; C:\Windows\system32\PnkBstrB.exe [2010-03-19 215128]
R2 RoxWatch9;Roxio Hard Drive Watcher 9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe [2007-01-11 166648]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-01-11 240232]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2008-01-19 21504]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R3 iPod Service;Service de l'iPod; C:\Program Files\iPod\bin\iPodService.exe [2009-11-12 545568]
S2 appdrvrem01;Application Driver Auto Removal Service (01); C:\Windows\System32\appdrvrem01.exe [2009-07-20 316816]
S2 CLTNetCnService;Symantec Lic NetConnect service; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe /h ccCommon []
S2 LiveUpdate Notice Ex;LiveUpdate Notice Service Ex; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe /h ccCommon []
S2 NMSAccessU;NMSAccessU; C:\Program Files\CDBurnerXP\NMSAccessU.exe []
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-10-07 655624]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 npggsvc;nProtect GameGuard Service; C:\Windows\system32\GameMon.des [2009-12-16 3453712]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 SandraAgentSrv;SiSoftware Deployment Agent Service; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2009.SP4\RpcAgentSrv.exe []
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2010-03-04 332720]
S3 TuneUp.Defrag;@%SystemRoot%\System32\TuneUpDefragService.exe,-1; C:\Windows\System32\TuneUpDefragService.exe [2008-02-14 306432]
S4 GoogleDesktopManager;GoogleDesktopManager; C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe [2007-09-13 81408]
S4 LiveUpdate Notice Service;LiveUpdate Notice Service; C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe /m C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll []
S4 RoxMediaDB9;RoxMediaDB9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe [2007-01-11 887544]
S4 ServiceLayer;ServiceLayer; C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe [2006-06-05 174080]
S4 stllssvr;stllssvr; C:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2006-09-14 73728]

-----------------EOF-----------------

34 réponses

Résumé de la discussion

Rapport HijackThis et journal système sous Windows Vista révèlent une compromission potentielle avec de nombreuses BHO (Browser Helper Objects), barres d'outils et paramètres de démarrage indésirables. Des éléments problématiques incluent SpeedBit Video Downloader, Bywifi et Ask Toolbar, des entrées de registre et des services non standards, ainsi que des DLL manquantes ou douteuses présentes dans System32 et les extensions du navigateur. Les listes d'éléments modifiés et les programmes au démarrage (GrooveMonitor, RTKVHD, iTunesHelper, uTorrent, GoogleUpdate) suggèrent une activité persistante nécessitant un nettoyage ciblé et une vérification des tâches planifiées.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Re,

    C'est beaucoup mieux :)

    ~~> Fixer les lignes :

    ▶ Lance Hijackthis ( ou ce fichier : )

    ▶ Choisis " Do a system scan only "

    ▶ Coche ces lignes sur leurs gauche : (et uniquement celles ci !!)

    O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - (no file)
    O2 - BHO: SBCONVERT - {31B27F2D-6BC6-451B-B3D2-4EAB36B2FC3B} - C:\Program Files\SpeedBit Video Downloader\Toolbar\tbcore3.dll (file missing)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: BywifiBHO - {C4743D3E-20D7-4B52-84F2-5E4E277B2D82} - C:\Program Files\Bywifi\bywifiie.dll (file missing)
    O3 - Toolbar: SpeedBit Video Downloader - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - C:\Program Files\SpeedBit Video Downloader\Toolbar\tbcore3.dll (file missing)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [bywifi] C:\Program Files\Bywifi\bywifi.exe "-silent"
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
    O9 - Extra button: Bywifi: Video Downloader - {09E90109-A9AA-4980-BCEF-76F8D924E902} - C:\Program Files\Bywifi\bywifici.exe (file missing)
    O9 - Extra 'Tools' menuitem: Bywifi: Video Downloader - {09E90109-A9AA-4980-BCEF-76F8D924E902} - C:\Program Files\Bywifi\bywifici.exe (file missing)
    O9 - Extra button: Bywifi: Video Downloader - {09E90109-A9AA-4980-BCEF-76F8D924E902} - C:\Program Files\Bywifi\bywifici.exe (file missing) (HKCU)
    O9 - Extra 'Tools' menuitem: Bywifi: Video Downloader - {09E90109-A9AA-4980-BCEF-76F8D924E902} - C:\Program Files\Bywifi\bywifici.exe (file missing) (HKCU)
    O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)

    ▶ Clique sur " FIX CHECKED " et valide au message d'avertissement.

    ▶ Redémarre ton PC .

    › Tutoriel , Fixer les lignes avec Hijackthis

    ====================================================

    ► Nettoyage :

    • Passe une fois tout les deux jours un coup de nettoyage avec ATF-Cleaner, puis CCleaner.

    • Passe une fois tous les 15 jours une défragmentation.

    ► Logiciels de protection :

    ⇒ Antivirus:

    • Tu peux garder antivir, c'est un bon AV. f

    ⇒ Anti-spyware:

    • Télécharge et Installe Spyware-blaster,qui est léger en ressources, met le a jour régulièrement,et active toutes les protections (« Enable all protection »).
    • Télécharge et installe Spyware Guard et garde le sur ton PC.
    • Garde Malwarebytes en complément.

    ⇒ Firewall:

    • Désactive le firewall de windows , car il ne vaut rien :
    Sous XP
    Sous Vista

    • Je te conseille si tu n'as pas , afin d'installer un pare-feu pour mieux sécuriser ton PC , voici quelque uns que je trouve très bien :

    › Online Armor Personal Firewall (gratuit)
    › Kerio
    › PC Tools Firewall Plus (<= N'INSTALLE PAS SPYWARE DOCTOR !!!!)

    › Tutoriel Online Armor
    › Tutoriel Kerio
    › Tutoriel PC Tools

    ⇒ Navigateur:

    • Pour naviguer sur internet plus en sécurité , je te conseille vivement d'installer et utiliser le navigateur Firefox (MAIS GARDE INTERNET EXPLORER POUR LES MISES A JOURS). Une fois que c'est fait, lance le et installe les trois extensions de sécurité suivantes :
    › WOT : pour se protéger des sites malveillants.
    Tuto

    › No Script
    Tutoriel et test No Script

    › Adblock Plus , Pour bloquer les pubs.
    Tutoriel d'utilisation

    ► Surveillance :

    • Fais un scan avec ton antivirus a chaque fin de semaine (mets le à jour avant de lancer le scan)

    • Mets a jour régulièrement Malwarebytes', fais un scan rapide a chaque semaine.

    • Mets a jour régulièrement Windows, vérifie que les mises a jours automatiques sont bien activés :
    › Démarrer > Panneau de configuration
    choisis l'icône Windows Update, coche la case Mise à jour automatique. Ainsi, Windows et les autres produits de Microsoft comme Internet Explorer, Windows Defender, Windows Media Player etc...

    • Mets a jour régulièrement Java, adobe reader, comme expliqué

    • Utilise régulièrement Update checker comme expliqué.

    • Fais régulièrement une sauvegarde de donnés sur un support externe; ça peut être utile au cas où le système plante.

    ► Prévention:
    Je t'invite à lire ces articles pour éviter une ré-infection au futur: [30 Minutes de lecture très instructive]

    Sécuriser son ordinateur et connaitre les menaces (Merci Malekal)

    Prévention & Protection sur internet (Grand merci aux auteurs de ce très bon PDF)

    Voila, bonne lecture et une fois tous ceci fait et lu tu peux mettre le topic comme résolu.

    Bon surf et soit plus vigilent(e) a l'avenir ! ;)

    Cordialement Fix.
    1. Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 11:43:18, on 24/03/2010
      Platform: Windows Vista SP2 (WinNT 6.00.1906)
      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\Dwm.exe
      C:\Windows\system32\taskeng.exe
      C:\Windows\Explorer.EXE
      C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
      C:\Windows\RtHDVCpl.exe
      C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Common Files\Java\Java Update\jusched.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Windows\ehome\ehtray.exe
      C:\Windows\ehome\ehmsas.exe
      C:\Program Files\uTorrent\uTorrent.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Program Files\DAEMON Tools Lite\daemon.exe
      C:\Program Files\WinApplication\WinApplication.exe
      C:\Users\Jules\AppData\Local\Google\Chrome\Application\chrome.exe
      C:\Users\Jules\AppData\Local\Google\Chrome\Application\chrome.exe
      C:\Windows\system32\wuauclt.exe
      C:\Windows\system32\SearchFilterHost.exe
      C:\Windows\system32\Taskmgr.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.01net.com/telecharger/
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.01net.com/telecharger/
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
      O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - (no file)
      O2 - BHO: SBCONVERT - {31B27F2D-6BC6-451B-B3D2-4EAB36B2FC3B} - C:\Program Files\SpeedBit Video Downloader\Toolbar\tbcore3.dll (file missing)
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
      O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
      O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: BywifiBHO - {C4743D3E-20D7-4B52-84F2-5E4E277B2D82} - C:\Program Files\Bywifi\bywifiie.dll (file missing)
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O2 - BHO: GrabberObj Class - {FF7C3CF0-4B15-11D1-ABED-709549C10000} - C:\PROGRA~1\SPEEDB~1\Toolbar\grabber.dll (file missing)
      O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O3 - Toolbar: SpeedBit Video Downloader - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - C:\Program Files\SpeedBit Video Downloader\Toolbar\tbcore3.dll (file missing)
      O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
      O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [bywifi] C:\Program Files\Bywifi\bywifi.exe "-silent"
      O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKCU\..\Run: [Google Update] "C:\Users\Jules\AppData\Local\Google\Update\GoogleUpdate.exe" /c
      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
      O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
      O4 - HKCU\..\Run: [bywifi] C:\Program Files\Bywifi\bywifi.exe "-silent"
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
      O4 - HKCU\..\Run: [RGSC] C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
      O4 - Global Startup: Application.lnk = C:\Program Files\WinApplication\WinApplication.exe
      O9 - Extra button: Bywifi: Video Downloader - {09E90109-A9AA-4980-BCEF-76F8D924E902} - C:\Program Files\Bywifi\bywifici.exe (file missing)
      O9 - Extra 'Tools' menuitem: Bywifi: Video Downloader - {09E90109-A9AA-4980-BCEF-76F8D924E902} - C:\Program Files\Bywifi\bywifici.exe (file missing)
      O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
      O9 - Extra button: Bywifi: Video Downloader - {09E90109-A9AA-4980-BCEF-76F8D924E902} - C:\Program Files\Bywifi\bywifici.exe (file missing) (HKCU)
      O9 - Extra 'Tools' menuitem: Bywifi: Video Downloader - {09E90109-A9AA-4980-BCEF-76F8D924E902} - C:\Program Files\Bywifi\bywifici.exe (file missing) (HKCU)
      O15 - Trusted Zone: https://www.orange.fr/portail
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/fr/scan8/oscan8.cab
      O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
      O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
      O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      O23 - Service: Application Driver Auto Removal Service (01) (appdrvrem01) - Protection Technology - C:\Windows\System32\appdrvrem01.exe
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe (file missing)
      O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
      O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
      O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
      O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
      O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe (file missing)
      O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - Unknown owner - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2009.SP4\RpcAgentSrv.exe (file missing)
      O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
      O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
      O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
      1. Contributeur sécurité
        ???????????????????????????????????????????????

        C'est quoi ce rapport ?!!

        --
        1. Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 20:53:24, on 23/03/2010
          Platform: Windows Vista SP2 (WinNT 6.00.1906)
          MSIE: Internet Explorer v8.00 (8.00.6001.18702)
          Boot mode: Normal

          Running processes:
          C:\Windows\system32\taskeng.exe
          C:\Windows\system32\Dwm.exe
          C:\Windows\Explorer.EXE
          C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
          C:\Windows\RtHDVCpl.exe
          C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\Program Files\Common Files\Java\Java Update\jusched.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Windows\ehome\ehtray.exe
          C:\Program Files\uTorrent\uTorrent.exe
          C:\Program Files\DAEMON Tools Lite\daemon.exe
          C:\Program Files\WinApplication\WinApplication.exe
          C:\Windows\ehome\ehmsas.exe
          C:\Program Files\Windows Media Player\wmpnscfg.exe
          C:\Windows\system32\wuauclt.exe
          C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
          C:\program files\avira\antivir desktop\avcenter.exe
          C:\Program Files\RocketDock\RocketDock.exe
          C:\Users\Jules\AppData\Local\Google\Chrome\Application\chrome.exe
          C:\Users\Jules\AppData\Local\Google\Chrome\Application\chrome.exe
          C:\Users\Jules\AppData\Local\Google\Chrome\Application\chrome.exe
          C:\Users\Jules\Documents\Downloads\HijackThis.exe
          C:\Windows\system32\SearchFilterHost.exe
          C:\Users\Jules\AppData\Local\Google\Chrome\Application\chrome.exe

          O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
          1. Contributeur sécurité
            Re,

            Tu suis une désinfection autrement ?

            ========

            --> à supprimer manuellement :
            C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis
            C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\Ad-remover
            C:\Users\Jules\Downloads\ComboFix.exe

            ========

            Fais les autres manips' et recolle un nouveau rapport de scan hijackthis

            --
            1. Rapport ToolsCleaner version 2.3.11 (par A.Rothstein & dj QUIOU) ]

              --> Recherche:

              C:\VundoFix.txt: trouvé !
              C:\Combofix.txt: trouvé !
              C:\fixnavi.txt: trouvé !
              C:\cleannavi.txt: trouvé !
              C:\TB.txt: trouvé !
              C:\UsbFix.txt: trouvé !
              C:\Combofix: trouvé !
              C:\Vundofix backups: trouvé !
              C:\Qoobox: trouvé !
              C:\_OTM: trouvé !
              C:\Toolbar SD: trouvé !
              C:\UsbFix: trouvé !
              C:\Rsit: trouvé !
              C:\WORT: trouvé !
              C:\Ad-remover: trouvé !
              C:\Program Files\Navilog1: trouvé !
              C:\Program Files\Ad-remover: trouvé !
              C:\Program Files\Trend Micro\HijackThis: trouvé !
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
              C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !
              C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: trouvé !
              C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\Ad-remover: trouvé !
              C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
              C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ad-remover: trouvé !
              C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
              C:\Qoobox\Quarantine\catchme.log: trouvé !
              C:\Users\Jules\AppData\Local\VirtualStore\Program Files\Trend Micro\HijackThis: trouvé !
              C:\Users\Jules\AppData\Local\VirtualStore\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !
              C:\Users\Jules\AppData\Roaming\Microsoft\Windows\Recent\HijackThis.lnk: trouvé !
              C:\Users\Jules\AppData\Roaming\Microsoft\Windows\Recent\UsbFix.lnk: trouvé !
              C:\Users\Jules\Desktop\WareOut Removal Tool.bat: trouvé !
              C:\Users\Jules\Desktop\WORT: trouvé !
              C:\Users\Jules\Desktop\Todos\logiciel sécurité\HijackThis.lnk: trouvé !
              C:\Users\Jules\Desktop\Wort\catchme.exe: trouvé !
              C:\Users\Jules\Documents\Downloads\OTM.exe: trouvé !
              C:\Users\Jules\Documents\Downloads\Ad-R.exe: trouvé !
              C:\Users\Jules\Documents\Downloads\UsbFix.exe: trouvé !
              C:\Users\Jules\Documents\Downloads\Rsit.exe: trouvé !
              C:\Users\Jules\Documents\Downloads\WORT.exe: trouvé !
              C:\Users\Jules\Downloads\OTM.exe: trouvé !
              C:\Users\Jules\Downloads\Navilog1.exe: trouvé !
              C:\Users\Jules\Downloads\ComboFix.exe: trouvé !
              C:\Users\Jules\Downloads\vundoFix.exe: trouvé !
              C:\Users\Jules\Downloads\Ad-R.exe: trouvé !
              C:\Users\Jules\Downloads\ToolBarSD.exe: trouvé !
              C:\Users\Jules\Downloads\Rsit.exe: trouvé !

              ---------------------------------
              --> Suppression:

              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
              C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: supprimé !
              C:\Users\Jules\AppData\Roaming\Microsoft\Windows\Recent\HijackThis.lnk: supprimé !
              C:\Users\Jules\Desktop\WareOut Removal Tool.bat: supprimé !
              C:\Users\Jules\Desktop\Todos\logiciel sécurité\HijackThis.lnk: supprimé !
              C:\Users\Jules\Desktop\Wort\catchme.exe: supprimé !
              C:\Users\Jules\Documents\Downloads\OTM.exe: supprimé !
              C:\Users\Jules\Documents\Downloads\Ad-R.exe: supprimé !
              C:\Users\Jules\Downloads\OTM.exe: supprimé !
              C:\Users\Jules\Downloads\Navilog1.exe: supprimé !
              C:\Users\Jules\Downloads\ComboFix.exe: ERREUR DE SUPPRESSION !!
              C:\Users\Jules\Downloads\vundoFix.exe: supprimé !
              C:\Users\Jules\Downloads\Ad-R.exe: supprimé !
              C:\Users\Jules\Downloads\ToolBarSD.exe: supprimé !
              C:\VundoFix.txt: supprimé !
              C:\Combofix.txt: supprimé !
              C:\fixnavi.txt: supprimé !
              C:\cleannavi.txt: supprimé !
              C:\TB.txt: supprimé !
              C:\UsbFix.txt: supprimé !
              C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
              C:\Qoobox\Quarantine\catchme.log: supprimé !
              C:\Users\Jules\AppData\Local\VirtualStore\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
              C:\Users\Jules\AppData\Roaming\Microsoft\Windows\Recent\UsbFix.lnk: supprimé !
              C:\Users\Jules\Documents\Downloads\UsbFix.exe: supprimé !
              C:\Users\Jules\Documents\Downloads\Rsit.exe: supprimé !
              C:\Users\Jules\Documents\Downloads\WORT.exe: supprimé !
              C:\Users\Jules\Downloads\Rsit.exe: supprimé !
              C:\Combofix: supprimé !
              C:\Vundofix backups: supprimé !
              C:\Qoobox: supprimé !
              C:\_OTM: supprimé !
              C:\Toolbar SD: supprimé !
              C:\UsbFix: supprimé !
              C:\Rsit: supprimé !
              C:\WORT: supprimé !
              C:\Ad-remover: supprimé !
              C:\Program Files\Navilog1: supprimé !
              C:\Program Files\Ad-remover: supprimé !
              C:\Program Files\Trend Micro\HijackThis: supprimé !
              C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: ERREUR DE SUPPRESSION !!
              C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\Ad-remover: ERREUR DE SUPPRESSION !!
              C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: supprimé !
              C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ad-remover: supprimé !
              C:\Users\Jules\AppData\Local\VirtualStore\Program Files\Trend Micro\HijackThis: supprimé !
              C:\Users\Jules\Desktop\WORT: supprimé !
              1. Javara ne trouve rien en metteant via juschehck
                Et tools cleaner plante pdt le recherhce
                1. Contributeur sécurité
                  Slaut,

                  Pourquoi tu fais pas les manips' dans l'ordre ?
                  Pourquoi tu lis pas correctement ?

                  MSIE: Internet Explorer v7.00 (7.00.6002.18005)

                  J'ai demandé de mettre à jour les logiciels ET NON les supprimer ........ ^^
                  J'ai demandé d'utiliser Toolscleaner aussi ;)

                  Tu as fait la totalité du post ?
                  Si oui, repasse Hijackthis et colle le rapport.

                  Merci

                  --
                  1. JavaRa 1.15 Removal Log.

                    Report follows after line.

                    ------------------------------------

                    The JavaRa removal process was started on Mon Mar 22 22:19:39 2010

                    Found and removed: C:\Users\Jules\AppData\LocalLow\Sun\Java\jre1.6.0_17

                    ------------------------------------

                    Finished reporting.
                    1. Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 22:21:30, on 22/03/2010
                      Platform: Windows Vista SP2 (WinNT 6.00.1906)
                      MSIE: Internet Explorer v7.00 (7.00.6002.18005)
                      Boot mode: Normal

                      Running processes:
                      C:\Windows\system32\taskeng.exe
                      C:\Windows\system32\Dwm.exe
                      C:\Windows\Explorer.EXE
                      C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
                      C:\Windows\RtHDVCpl.exe
                      C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                      C:\Program Files\iTunes\iTunesHelper.exe
                      C:\Program Files\Bywifi\bywifi.exe
                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                      C:\Users\Jules\AppData\Local\Google\Update\GoogleUpdate.exe
                      C:\Windows\ehome\ehtray.exe
                      C:\Program Files\uTorrent\uTorrent.exe
                      C:\Program Files\DAEMON Tools Lite\daemon.exe
                      C:\Program Files\WinApplication\WinApplication.exe
                      C:\Windows\system32\wuauclt.exe
                      C:\Windows\ehome\ehmsas.exe
                      C:\Program Files\Windows Media Player\wmpnscfg.exe
                      C:\Windows\system32\UI0Detect.exe
                      C:\Users\Jules\AppData\Local\Google\Chrome\Application\chrome.exe
                      C:\Windows\system32\conime.exe
                      C:\Users\Jules\AppData\Local\Google\Chrome\Application\chrome.exe
                      C:\Users\Jules\AppData\Local\Google\Chrome\Application\chrome.exe
                      C:\Users\Jules\AppData\Local\Google\Chrome\Application\chrome.exe
                      C:\Users\Jules\AppData\Local\Google\Chrome\Application\chrome.exe
                      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
                      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://localhost:9000/proxy.pac
                      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
                      O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - (no file)
                      O2 - BHO: SBCONVERT - {31B27F2D-6BC6-451B-B3D2-4EAB36B2FC3B} - C:\Program Files\SpeedBit Video Downloader\Toolbar\tbcore3.dll
                      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                      O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                      O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: BywifiBHO - {C4743D3E-20D7-4B52-84F2-5E4E277B2D82} - C:\Program Files\Bywifi\bywifiie.dll
                      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                      O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                      O2 - BHO: GrabberObj Class - {FF7C3CF0-4B15-11D1-ABED-709549C10000} - C:\PROGRA~1\SPEEDB~1\Toolbar\grabber.dll
                      O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                      O3 - Toolbar: SpeedBit Video Downloader - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - C:\Program Files\SpeedBit Video Downloader\Toolbar\tbcore3.dll
                      O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
                      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                      O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                      O4 - HKLM\..\Run: [bywifi] C:\Program Files\Bywifi\bywifi.exe "-silent"
                      O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
                      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                      O4 - HKCU\..\Run: [Google Update] "C:\Users\Jules\AppData\Local\Google\Update\GoogleUpdate.exe" /c
                      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                      O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
                      O4 - HKCU\..\Run: [bywifi] C:\Program Files\Bywifi\bywifi.exe "-silent"
                      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                      O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
                      O4 - HKCU\..\Run: [RGSC] C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
                      O4 - Global Startup: Application.lnk = C:\Program Files\WinApplication\WinApplication.exe
                      O9 - Extra button: Bywifi: Video Downloader - {09E90109-A9AA-4980-BCEF-76F8D924E902} - C:\Program Files\Bywifi\bywifici.exe
                      O9 - Extra 'Tools' menuitem: Bywifi: Video Downloader - {09E90109-A9AA-4980-BCEF-76F8D924E902} - C:\Program Files\Bywifi\bywifici.exe
                      O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                      O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                      O9 - Extra button: Bywifi: Video Downloader - {09E90109-A9AA-4980-BCEF-76F8D924E902} - C:\Program Files\Bywifi\bywifici.exe (HKCU)
                      O9 - Extra 'Tools' menuitem: Bywifi: Video Downloader - {09E90109-A9AA-4980-BCEF-76F8D924E902} - C:\Program Files\Bywifi\bywifici.exe (HKCU)
                      O15 - Trusted Zone: https://www.orange.fr/portail
                      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/fr/scan8/oscan8.cab
                      O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
                      O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                      O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                      O23 - Service: Application Driver Auto Removal Service (01) (appdrvrem01) - Protection Technology - C:\Windows\System32\appdrvrem01.exe
                      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                      O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                      O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe (file missing)
                      O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
                      O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
                      O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
                      O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                      O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - Unknown owner - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2009.SP4\RpcAgentSrv.exe (file missing)
                      O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
                      O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
                      O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
                      1. Contributeur sécurité
                        Salut,

                        Pas grave, le scan était juste pour s'assurer que tout est clean.

                        Mets à jour ton antivirus (antivir), fais un scan, vire ce qu'il trouve et colle le rapport.

                        _____________________________________________________

                        1: Pour supprimer les outils spécifiques utilisés lors la désinfection :

                        Télécharge ToolsCleaner2 (de A.Rothstein) sur ton Bureau

                        ▶ Sous XP : Double-clique sur ToolsCleaner2.exe
                        ▶ Sous Vista : Fais un clic droit sur ToolsCleaner2.exe et sélectionne "Exécuter en tant qu'administrateur"
                        ▶ Clique sur Recherche et laisse le scan se terminer.
                        ▶ Clique sur Suppression pour finaliser.
                        ▶ Tu peux, si tu le souhaites, te servir des Options facultatives.
                        ▶ Clique sur Quitter (et pas sur la croix rouge!) , pour que le rapport puisse se créer.
                        ▶ Le rapport (TCleaner.txt) se trouve à la racine de votre disque dur (C:\), colle le dans ta réponse.

                        ______________________________________________________

                        2: Nettoyage des fichiers temporaires :

                        Télécharge ATF Cleaner par Atribune

                        Sous XP : Double-clique ATF-Cleaner.exe afin de lancer le programme.
                        Sous Vista : Fais un clic droit sur ATF-Cleaner.exe et choisis " Exécuter en tant qu'admin..."
                        ▶ Dans l'onglet Main, coche simplement la case Select All (toutes les cases vont se cocher) puis sur le bouton Empty Selected.
                        ▶ Si tu possèdes : Firefox ou Opera comme navigateur, pense à choisir ton navigateur en haut a gauche avant de sélectionner Select All puis Empty Selected.
                        ▶ Puis réponds Non au message qui s'affiche, si tu ne souhaites pas perdre tes mots de passes .

                        Aide : Comment utiliser ATF-Cleaner.

                        Télécharge CCleaner sur ton bureau

                        ▶ Installe le programme.
                        ▶ Lance CCleaner puis Clique sur "Options" → "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures".
                        ▶ Dans le menu " Nettoyeur " → "Analyse" .
                        ▶ Ensuite clique sur le bouton "Lancer le nettoyage" et laisse le faire.
                        ▶ Maintenant dans l'onglet "Registre" → "Chercher des erreurs .
                        ▶ Réponds a Oui a la question qui te sera posée.
                        ▶ Enfin , répare les erreurs en cliquant sur " Réparer les erreurs sélectionnés "
                        .

                        * Note : Refais trois fois , une réparation du registre pour que cela soit efficace !

                        Aide : Comment utiliser CCleaner ?

                        ______________________________________________________

                        3 : Purge de la restauration du système :

                        ⇒ Sous XP :

                        * Désactivation :

                        ▶ Clic droit sur le Poste de travail → Propriétés → Onglet "Restauration du système" → coche la case "Désactiver la Restauration du système sur tous les lecteurs" → Appliquer.
                        ▶ Patiente jusqu'à que cela soit marqué "désactivée" puis OK.
                        ⇒ Redémarre le PC.

                        * Activation :

                        ▶ Suis le même chemin ; décoche la case "Désactiver la Restauration du système sur tous les lecteurs" > Appliquer.
                        ▶ Attends que cela soit a nouveau sur "Surveillance" puis OK.
                        ⇒ Redémarre le PC.

                        ⇒ Sous Vista :

                        * Désactivation:

                        ▶ Clique droit sur " Ordinateur " → Propriétés → Paramètres système avancés → onglet Protection du Système.
                        ▶ Décoche (une par une) tes partitions, un message de confirmation va apparaître, clique sur " Désactiver la protection du système " → Appliquer → OK.

                        ⇒ Redémarre ton PC.

                        * Activation :

                        ▶ Suis le même chemin , décoche " Désactiver la protection du système " → Appliquer → OK.
                        ⇒ Redémarre ton PC.

                        ______________________________________________________

                        4: Création d'un point de restauration sain :

                        ⇒ Sous XP

                        ⇒ Sous Vista

                        ______________________________________________________

                        5: Ménage & Optimisation :

                        * Nettoyage de disque:

                        ▶ Clic droit sur "Poste de travail" → "Ouvrir" > Clic droit sur le disque C → Propriétés → Onglet "Général"
                        ▶ Clique sur le bouton "Nettoyage de disque" → OK
                        ▶ Fais la même chose pour chacun de tes disques

                        * Défragmentation:

                        ● Menu "Démarrer" → "Tous les programmes" → Accessoires → Outils système → "Défragumenteur de disque"
                        ▶ Clique sur Analyser, s'il te demande de défragmenter , tu Défragmentes.
                        › › Fais le même chose pour chacun de tes disques.

                        Note : si tu as un utilitaire pour défragmenter , utilise le à la place

                        * Vérifications des erreurs :

                        ▶ Clic droit sur "Poste de travail" / "Ordinateur" → "ouvrir" → clic droit sur le disque C → Propriétés → Onglet "Outil" → "Vérifier maintenant", une boîte s'ouvre, coche les cases :

                        - Réparer automatiquement les erreurs...
                        - Rechercher et tenter une récupération...

                        ⇒ Démarrer, OK

                        Note : s'il te dis de redémarrer ton PC pour le faire , tu redémarres et tu laisses faire, cela prend un peu de temps c'est normal

                        ______________________________________________________

                        6: Remise en place des paramètres système par défaut :

                        ▶ Démarrer → Panneau de configuration → Options des dossiers → onglet 'Affichage'
                        - [Décoche] Afficher les fichiers et dossiers cachés
                        - [Coche] Masquer les fichiers protégés du système d'exploitation (recommandé)
                        - Clique sur Appliquer, puis OK.

                        ▶ Tu peux maintenant à réactiver toutes tes protections résidentes (Antivirus, Antispyware, Firewall).

                        ▶ Si tu as Vista : Tu peux réactiver l'UAC :

                        - Menu Démarrer > Panneaux de configuration .
                        - Clique sur l'icône " Comptes d'utilisateurs " puis sur " Activer ou désactiver le contrôle des comptes d'utilisateurs " .
                        - Coche la case : " Utiliser le contrôle des comptes d'utilisateurs pour vous aider à protéger votre ordinateur "
                        - Valide par OK , il sera demandé de redemarrer le PC , fais le ! .

                        ▶ Tu peux vider la quarantaine de ton antivirus , ton anti-spyware , et celle de MalwareBytes' .

                        7: Maintenir son système a jour contre les failles de sécurité :

                        ⇒ Windows :

                        • Installe ces quelque mises a jours critiques :

                        Windows Vista SP2
                        Internet Explorer 8

                        • Rends toi ICI (avec internet explorer !)

                        ! Ferme tes applications en cours (seulement le navigateur) !
                        • Installe TOUTES les mises a jours critiques (M.A.J's de sécurité, framwork etc...)

                        • Laisse toi guider ...

                        ⇒ Java :

                        • Désinstalle tes versions de Java et installe la nouvelle version :

                        • Télécharge JavaRa.zip

                        • Décompresse le fichier sur ton bureau (clique droit > Extraire tout.)

                        • Double-clique sur le répertoire JavaRa obtenu.

                        • Puis double-clique sur le fichier JavaRa.exe (le .exe peut ne pas s'afficher)

                        • Clique sur " Search For Updates ".

                        • Sélectionne " Update Using jucheck.exe " puis clique sur Search.

                        • Autorise le processus à se connecter s'il te le demande, clique sur Install et suis les instructions d'installation. Cela prendra quelques minutes.

                        • Quand l'installation est terminée, revient à l'écran de JavaRa et clique sur " Remove Older Versions ".

                        • Clique sur Oui pour confirmer. L'outil va travailler, clique ensuite sur Ok, puis une deuxième fois sur Ok.

                        • Un rapport va s'ouvrir, copie-colle le dans ta prochaine réponse.

                        Note : le rapport se trouve aussi là : ( C:\JavaRa.log )

                        **Aide** : Comment Utiliser JavaRa ?

                        ⇒ Adobe Reader :

                        • Désinstalle Adobe Reader depuis le menu Ajout/ suppression des programmes (programmes et fonctionnalités pour vista) .

                        • Installe cette version

                        ⇒ Autres Mises a jours a effectuer :

                        • Tu peux aussi mettre a jour tes logiciels grâce a Update Checker

                        • Tutoriel

                        ~~> Je t'invite a lire ça: Le danger des failles de sécurité

                        ______________________________________________________

                        Télécharge TrendMicro(TM) HijackThis(TM) sur ton bureau.

                        ▶ Fais un double-clic sur HJTInstall.exe afin de lancer l'installation

                        ▶ Clique sur Install ensuite sur I Accept

                        ▶ Lance un scan en cliquant sur " do a system scan and save a logfile " .

                        ▶ Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note

                        ▶ Copie-colle son contenu A ta prochaine réponse.


                        ⇒ Aide :
                        › Démonstration animée (Merci baltrap34)
                        › Tutoriel HijackThis

                        @+ ;)
                        --
                        1. Le security chechk
                          Results of screen317's Security Check version 0.99.1
                          Windows Vista Service Pack 1 [color=red][b](UAC is disabled!)[/b][/color]
                          [color=red][b]Out of date service pack!![/b][/color]
                          [b]''''''''''''''''''''''''''''''
                          [u]Antivirus/Firewall Check:[/u][/b]
                          Avira AntiVir Personal - Free Antivirus
                          Norton 360
                          WMIC entry does not exist for antivirus; attempting automatic update.
                          Avira updated!
                          [b]''''''''''''''''''''''''''''''
                          [u]Anti-malware/Other Utilities Check:[/u][/b]
                          HijackThis 2.0.2
                          TuneUp Utilities 2008
                          CCleaner (remove only)
                          Java(TM) 6 Update 17
                          Java(TM) 6 Update 3
                          [color=red][b]Out of date Java installed![/b][/color]
                          Adobe Flash Player 10
                          Adobe Reader 8
                          Adobe Reader 8.1.2 - Français
                          Adobe Reader 8.1.2 Security Update 1 (KB403742)
                          [color=red][b]Out of date Adobe Reader installed![/b][/color]
                          [b]''''''''''''''''''''''''''''''
                          Process Check:
                          [u]objlist.exe by Laurent[/u][/b]
                          Avira Antivir avgnt.exe
                          Avira Antivir avguard.exe
                          [b]''''''''''''''''''''''''''''''
                          [u]DNS Vulnerability Check:[/u][/b]
                          [color=red][b]Request Timed Out (Wireless Internet connection/Disconnected Internet/Proxy?)[/b][/color]

                          [b]'''''''''End of Log'''''''''''[/b]
                          1. Contributeur sécurité
                            Re,

                            Parfait! un dernier contrôle:

                            Fais un scan antivirus en ligne chez Bit-Defender (avec Internet Explorer) :

                            > Utilisation :
                            ▶ En bas, dans l'encadré "Analyse en ligne gratuite" , clique sur "Analyser" .
                            ▶ Dans la nouvelle fenêtre, clique sur "J'accepte" .
                            ▶ Il te sera proposer d'installer un module complémentaire (contrôle ActiveX) pour pouvoir faire le scan > accepte !
                            ▶ Patiente le temps du chargement ...
                            ▶ La fenêtre change encore, clique sur "Démarrer l'analyse" .
                            ▶ Les signatures se chargent, le scan démarre ... Laisse travailler et ne touche a rien !

                            → Poste le rapport obtenu, pour cela :
                            - Clique sur l'onglet "plus de détailles" . A la fin du scan, clique sur "problèmes détectés " .
                            - Au dessus à droite de la fenêtre des résultats , clique sur "Cliquer ici pour exporter le rapport" choisis d'enregistrer le rapport sur ton bureau .
                            - Ouvre le document html que tu viens de sauvegarder ( le rapport ),
                            > fais un copier/coller de tout son contenu et poste le dans ta prochaine réponse

                            Aide en images si besoin

                            ============

                            Télécharge Security Check de screen317 et sauvegarde-le sur ton Bureau.

                            - Double-clic sur Security Check.exe (l'extension peut ne pas apparaitre)
                            - Suis les instructions données à l'écran.
                            - Le rapport sera ouvert dans notepad : checkup.txt; Poste le dans ta prochaine réponse.

                            ============

                            Bonne nuit et à demain ;)

                            @+

                            --
                            1. ===== Rapport WareOut Removal Tool =====

                              version 3.6.2

                              analyse effectuée le 21/03/2010 à 16:46:50,26

                              Résultats de l'analyse :
                              ========================

                              ~~~~ Recherche d'infections dans C:\ ~~~~

                              C:\autorun.inf trouvé!
                              C:\autorun.inf suppression impossible

                              ~~~~ Recherche d'infections dans C:\Program Files\ ~~~~

                              ~~~~ Recherche d'infections dans C:\Windows\system\ ~~~~

                              ~~~~ Recherche d'infections dans C:\Windows\system32\ ~~~~

                              ~~~~ Recherche d'infections dans C:\Windows\system32\drivers\ ~~~~

                              ~~~~ Recherche d'infections dans C:\Users\Jules\AppData\Roaming\ ~~~~

                              ~~~~ Recherche d'infections dans C:\Users\Jules\Bureau\ ~~~~

                              ~~~~ Recherche de détournement de DNS ~~~~

                              ~~~~ Recherche de Rootkits ~~~~

                              _______________________________________________________________________

                              catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                              Rootkit scan 2010-03-21 16:46:53
                              Windows 6.0.6001 Service Pack 1 NTFS

                              scanning hidden files ...

                              scan completed successfully
                              hidden files: 0

                              _______________________________________________________________________

                              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
                              System REG_SZ

                              ~~~~ Recherche d'infections dans C:\Users\Jules\AppData\Local\Temp\ ~~~~

                              ~~~~ Recherche d'infections dans C:\Users\Jules\Start Menu\Programs\ ~~~~

                              ~~~~ Nettoyage du registre ~~~~

                              ~~~~ Tentative de réparation des entrées suivantes: ~~~~

                              [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] = "System"

                              [HKLM\SYSTEM\CurrentControlSet\Services\Windows Tribute Service]
                              [HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_Windows Tribute Service]

                              ~~~~ Vérification: ~~~~

                              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
                              System REG_SZ

                              _________________________________

                              développé par http://pc-system.fr
                              _________________________________
                              1. http://www.virustotal.com/fr/analisis/fd626a73e5bd0d0af1c9519ce9864fba1b5c86bfd4c2915bce0ca02032d66ab3-1269185930
                                • 1
                                • 2