Pubs intempestives sur Internet

Résolu
Bonjour,

je reposte mon sujet ici en espérant avoir plus de succès de réponse...

je suis victime de pubs intempestives sur Internet ( Mozilla et IE) ! Il s'agit de petites fenêtres en bas à gauche et à droites qui s'ouvrent à chaque navigations. C'est assez gênant car à chaque fois je dois cliquer sur elles pour m'en débarrasser.

On m'a recommandé d'utiliser Malwarebytes, Junkware removal tool et adwcleaner, mais ça n'a rien donné.

Quelqu'un aurait il d'autres idées?
merci

23 réponses

Résumé de la discussion

Des publicités intempestives apparaissent sur Internet sous forme de petites fenêtres en bas à gauche et à droite, gênant la navigation sous Windows 7 avec Mozilla Firefox. Malgré des scans avec Malwarebytes, Junkware Removal Tool et adwcleaner, la problématique persiste, et certains conseillent HijackThis ou OTL pour diagnostiquer les programmes indésirables. Des conseils incluent la désinstallation de McAfee Security Scan, la réinstallation des navigateurs et l’utilisation d’OTL pour générer des rapports, puis partager les liens vers ces rapports sur pjjoint malekal. En cas d’infection récalcitrante, les échanges évoquent l’analyse des fichiers hosts et des entrées système, et proposent des rapports OTL ou HijackThis comme base pour une aide technique.

Bobot (l’IA à votre service)
  1. ah super !!!

    Je viens de le désinstaller

    pour le moment aucune pub à l'horizon

    merci grandement pour votre aide !!
    0
    1. Modérateur
      ouaip là c'est bon :)

      Si McAfee Security Scan est encore installé.
      Tu peux le désinstaller.

      Like the angel you are, you laugh creating a lightness in my chest,
      Your eyes they penetrate me,
      (Your answer's always 'maybe')
      That's when I got up and left
      0
      1. J' ai fais comme suit, j'ai du recommencer car la première fois mon anti-virus était activé. Par contre aucun rapport n'a été affiché Est-ce normal?
        0
        1. Modérateur
          Refais un scan OTL et donne le rapport pour voir si cela a fonctionné.
          0
      2. je pense que le cadre que je dois copier coller est incomplet non ? (je ne vois pas :OTL)
        dois je cocher "tous les utilisateurs", ou bien je laisse tel quel ?

        l'autre fois en faisant cette manipulation, mon pc avait rédémarré, puis il m'avait demandé d'exécuter je ne sais quoi, j'avais refusé, j'avais des anciens fichiers en transparence qui étaient également apparus sur mon bureau...
        0
        1. Modérateur
          non c'est bon.
          Tu lances, tu copies/colles et fais correction, le PC va redémarrer.
          0
      3. Modérateur
        Ton fichier HOSTS est encore pourri.
        Donc je pense que tu as mal fait RstHosts ou ça n'a pas fonctionné

        Relance OTL.
        o sous Personnalisation (Custom Scan), copie_colle le contenu du cadre ci dessous (bien prendre :OTL en début).
        Clic Correction (Fix), un rapport apparraitra, copie/colle le contenu ici:

        :Commands
        [resethosts]
        [reboot]

        * poste le rapport ici

        0
        1. Modérateur
          Tu utilises quel navigateur pour surfer ?

          Si Firefox et/ou Chrome sont installés :

          Sur Firefox : Menu Outils / Modules complémentaires
          Onglet Extension.
          Donne la liste.

          Sur Google Chrome : Menu en haut à droite puis Outils / Extensions
          Donne la liste

          ~~

          Refais un scan OTL et donne le rapport par pjjoint.
          0
          1. hélas ils y en a toujours :(elles sont coriaces celles là...
            0
            1. Modérateur
              As-tu encore des pubs?
              0
              1. All processes killed
                ========== OTL ==========
                Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{GZMWBNT1-I39Q-XCTB-P9MV-4R17EKOU1BIP}\ not found.
                Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{GZMWBNT1-I39Q-XCTB-P9MV-4R17EKOU1BIP}\ not found.
                Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Active Setup\Installed Components\{GZMWBNT1-I39Q-XCTB-P9MV-4R17EKOU1BIP}\ not found.
                Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{GZMWBNT1-I39Q-XCTB-P9MV-4R17EKOU1BIP}\ not found.
                File C:\ProgramData\-RY7owIKcTeAukur not found.
                File C:\ProgramData\-RY7owIKcTeAuku not found.
                File C:\ProgramData\RY7owIKcTeAuku not found.
                Folder C:\Users\Sérine\AppData\Roaming\Imtyvy\ not found.
                Folder C:\Users\Sérine\AppData\Roaming\Irsudu\ not found.
                ========== COMMANDS ==========

                [EMPTYTEMP]

                User: Administrator

                User: All Users

                User: AppData

                User: Default
                ->Temp folder emptied: 0 bytes
                ->Temporary Internet Files folder emptied: 0 bytes
                ->Flash cache emptied: 0 bytes

                User: Default User
                ->Temp folder emptied: 0 bytes
                ->Temporary Internet Files folder emptied: 0 bytes
                ->Flash cache emptied: 0 bytes

                User: Invite
                ->Temp folder emptied: 0 bytes
                ->Temporary Internet Files folder emptied: 0 bytes
                ->FireFox cache emptied: 0 bytes
                ->Google Chrome cache emptied: 0 bytes
                ->Flash cache emptied: 0 bytes

                User: Invité
                ->Temp folder emptied: 0 bytes
                ->Temporary Internet Files folder emptied: 0 bytes
                ->Flash cache emptied: 0 bytes

                User: Public

                User: Sérine
                ->Temp folder emptied: 169472 bytes
                ->Temporary Internet Files folder emptied: 97579339 bytes
                ->Java cache emptied: 0 bytes
                ->FireFox cache emptied: 38817986 bytes
                ->Google Chrome cache emptied: 0 bytes
                ->Flash cache emptied: 3213262 bytes

                %systemdrive% .tmp files removed: 0 bytes
                %systemroot% .tmp files removed: 0 bytes
                %systemroot%\System32 .tmp files removed: 0 bytes
                %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
                %systemroot%\System32\drivers .tmp files removed: 0 bytes
                Windows Temp folder emptied: 35101856 bytes
                %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 36072667 bytes
                RecycleBin emptied: 2156299 bytes

                Total Files Cleaned = 203,00 mb

                [EMPTYFLASH]

                User: Administrator

                User: All Users

                User: AppData

                User: Default
                ->Flash cache emptied: 0 bytes

                User: Default User
                ->Flash cache emptied: 0 bytes

                User: Invite
                ->Flash cache emptied: 0 bytes

                User: Invité
                ->Flash cache emptied: 0 bytes

                User: Public

                User: Sérine
                ->Flash cache emptied: 0 bytes

                Total Flash Files Cleaned = 0,00 mb

                File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
                Error: Unble to create default HOSTS file!

                OTL by OldTimer - Version 3.2.69.0 log created on 12202013_220010

                Files\Folders moved on Reboot...
                File move failed. C:\Users\Sérine\AppData\Local\Temp\FXSAPIDebugLogFile.txt scheduled to be moved on reboot.
                File\Folder C:\Users\Sérine\AppData\Local\Temp\~DF0D943A2AF7BDC5CE.TMP not found!
                File\Folder C:\Users\Sérine\AppData\Local\Temp\~DF32845111D92C1286.TMP not found!
                File\Folder C:\Users\Sérine\AppData\Local\Temp\~DF8F6C118DBDA15436.TMP not found!
                File\Folder C:\Users\Sérine\AppData\Local\Temp\~DFA1EDB06F3AF7CD6D.TMP not found!
                File\Folder C:\Users\Sérine\AppData\Local\Temp\~DFB908CE63B9080D31.TMP not found!
                File\Folder C:\Users\Sérine\AppData\Local\Temp\~DFC65234119BA16C16.TMP not found!
                C:\Users\Sérine\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\4A72F430-B40C-4D36-A068-CE33ADA5ADF9.dat moved successfully.
                C:\Users\Sérine\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T857RZDX\ba[1].htm moved successfully.
                C:\Users\Sérine\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T857RZDX\color[1].htm moved successfully.
                C:\Users\Sérine\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T857RZDX\likebox[1].htm moved successfully.
                C:\Users\Sérine\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T857RZDX\odIeERVR1c5[1].dat moved successfully.
                C:\Users\Sérine\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T0M3C7US\view[1].htm moved successfully.
                C:\Users\Sérine\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SX6G1NJD\ads[2].htm moved successfully.
                C:\Users\Sérine\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SX6G1NJD\ai[1].htm moved successfully.
                C:\Users\Sérine\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SX6G1NJD\display[1].htm moved successfully.
                C:\Users\Sérine\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LUNYA8TA\afr[1].htm moved successfully.
                C:\Users\Sérine\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LUNYA8TA\esp_invocation[1].htm moved successfully.
                C:\Users\Sérine\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J85UROTC\0928S1MA.htm moved successfully.
                C:\Users\Sérine\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H8XJ52RZ\16908-amel-bent-ou-je-vais[1].htm moved successfully.
                C:\Users\Sérine\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H8XJ52RZ\pixel[1].htm moved successfully.
                C:\Users\Sérine\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GBU0S000\LRLFV3M5.htm moved successfully.
                C:\Users\Sérine\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4G251EQ8\ads[1].htm moved successfully.
                C:\Users\Sérine\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4G251EQ8\ai[1].htm moved successfully.
                C:\Users\Sérine\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2K94R2Y4\watch[1].htm moved successfully.
                C:\Users\Sérine\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.
                File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.

                PendingFileRenameOperations files...

                Registry entries deleted on Reboot...
                0
                1. Modérateur
                  Relance OTL.
                  o sous Personnalisation (Custom Scan), copie_colle le contenu du cadre ci dessous (bien prendre :OTL en début).
                  Clic Correction (Fix), un rapport apparraitra, copie/colle le contenu ici:

                  :OTL
                  ActiveX: {GZMWBNT1-I39Q-XCTB-P9MV-4R17EKOU1BIP} - C:\Program Files (x86)\hackhound.exe
                  [2012/08/23 12:50:37 | 000,000,160 | -H-- | C] () -- C:\ProgramData\-RY7owIKcTeAukur
                  [2012/08/23 12:50:37 | 000,000,144 | -H-- | C] () -- C:\ProgramData\-RY7owIKcTeAuku
                  [2012/08/23 12:50:33 | 000,000,368 | -H-- | C] () -- C:\ProgramData\RY7owIKcTeAuku
                  [2013/06/28 12:36:18 | 000,000,000 | ---D | M] -- C:\Users\Sérine\AppData\Roaming\Imtyvy
                  [2013/06/23 11:18:13 | 000,000,000 | ---D | M] -- C:\Users\Sérine\AppData\Roaming\Irsudu
                  :Commands
                  [emptytemp]
                  [emptyflash]
                  [resethosts]
                  [reboot]

                  * poste le rapport ici

                  0
                  1. Modérateur
                    Faire un scan OTL pour diagnostiquer les programmes qui tournent et déceler des infections - Le programme va générer deux rapports OTL.txt et Extras.txt
                    Fournir les deux rapports :

                    Tu peux suivre les indications de cette page pour t'aider : https://www.malekal.com/tutorial-otl/

                    * Télécharge http://www.geekstogo.com/forum/files/file/398-otl-oldtimers-list-it/ sur ton bureau.
                    (Sous Vista/Win7, il faut cliquer droit sur OTL et choisir Exécuter en tant qu'administrateur)

                    Dans le cas d'Avast!, ne pas lancer le programme dans la Sandbox (voir lien d'aide ci-dessus).

                    * Lance OTL
                    * En haut à droite de Analyse rapide, coche "tous les utilisateurs"
                    * Sur OTL, sous Personnalisation, copie-colle le script ci-dessous :

                    netsvcs
                    msconfig
                    safebootminimal
                    safebootnetwork
                    activex
                    drivers32
                    %ALLUSERSPROFILE%\Application Data\*.
                    %ALLUSERSPROFILE%\Application Data\*.exe /s
                    %APPDATA%\*.
                    %APPDATA%\*.exe /s
                    %temp%\*.exe /s
                    %SYSTEMDRIVE%\*.exe
                    %systemroot%\*. /mp /s
                    %systemroot%\system32\consrv.dll
                    %systemroot%\system32\*.dll /lockedfiles
                    %windir%\Tasks\*.job /lockedfiles
                    %systemroot%\system32\drivers\*.sys /lockedfiles
                    %systemroot%\System32\config\*.sav
                    /md5start
                    explorer.exe
                    winlogon.exe
                    services.exe
                    wininit.exe
                    /md5stop
                    HKEY_CLASSES_ROOT\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InprocServer32 /s
                    HKEY_LOCAL_MACHINE\SYSTEM\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters /s
                    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems /s
                    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls /s
                    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList /s
                    HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor /s
                    HKEY_CURRENT_USER\Software\Microsoft\Command Processor /s
                    CREATERESTOREPOINT
                    nslookup https://www.google.fr/?gws_rd=ssl /c
                    SAVEMBR:0
                    hklm\software\clients\startmenuinternet|command /rs
                    hklm\software\clients\startmenuinternet|command /64 /rs

                    * Clique sur le bouton Analyse.

                    * Quand le scan est fini, utilise le site http://pjjoint.malekal.com/ pour envoyer le rapport OTL.txt (et Extra.txt si présent).
                    Donne le ou les liens pjjoint qui pointent vers ces rapports ici dans une réponse.
                    Je répète : donne le lien du rapport pjjoint ici en réponse.

                    NE PAS COPIER/COLLER LE RAPPORT ICI - DONNER LE LIEN PJJOINT DANS UN NOUVEAU MESSAGE

                    0
                    1. voilà c'est fait. mais toujours les petites fenêtres de pub en bas à gauche....
                      0
                      1. Modérateur
                        Désinstalle et réinstalle le navigateur où tu as ces pubs.
                        0
                      2. ben c'est déjà fait, j'ai désinstallé Internet explorer et Mozilla, puis réinstaller, c'est toujours là
                        0
                    2. voilà c'est fait, mais par contre mon antivirus Avira me signale qu'il a bloqué pour des raisons de sécurité un fichier hôte...
                      0
                      1. Modérateur
                        Désactive antivir pour faire la restauration.
                        0
                    3. Modérateur
                      utilise cela : http://general-changelog-team.fr/fr/downloads/viewdownload/20-outils-de-xplode/10-rsthosts
                      fais un restaure.
                      0
                      1. bonjour,
                        merci pour vos indications, j'ai fais comme vous me l'avez indiqué
                        voici le scan

                        Logfile of Trend Micro HijackThis v2.0.5
                        Scan saved at 00:27:57, on 14/12/2013
                        Platform: Windows 7 SP1 (WinNT 6.00.3505)
                        MSIE: Internet Explorer v11.0 (11.00.9600.16428)

                        FIREFOX: 26.0 (fr)
                        Boot mode: Normal

                        Running processes:
                        C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe
                        C:\Program Files (x86)\TOSHIBA\Toshiba Online Product Information\TOPI.exe
                        C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
                        C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe
                        C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe
                        C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
                        C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
                        C:\Users\Sérine\Desktop\HijackThis.exe

                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.fr/
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                        O1 - Hosts: ::1 localhost
                        O1 - Hosts: 149.5.18.172 www.google-analytics.com.
                        O1 - Hosts: 149.5.18.172 ad-emea.doubleclick.net.
                        O1 - Hosts: 149.5.18.172 www.statcounter.com.
                        O1 - Hosts: 108.163.215.51 www.google-analytics.com.
                        O1 - Hosts: 108.163.215.51 ad-emea.doubleclick.net.
                        O1 - Hosts: 108.163.215.51 www.statcounter.com.
                        O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
                        O4 - HKLM\..\Run: [HWSetup] "C:\Program Files\TOSHIBA\Utilities\HWSetup.exe" hwSetUP
                        O4 - HKLM\..\Run: [KeNotify] C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe
                        O4 - HKLM\..\Run: [TWebCamera] "%ProgramFiles%\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
                        O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
                        O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
                        O4 - HKCU\..\Run: [TOSHIBA Online Product Information] C:\Program Files (x86)\TOSHIBA\Toshiba Online Product Information\topi.exe
                        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVICE RÉSEAU')
                        O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVICE RÉSEAU')
                        O4 - HKUS\S-1-5-18\..\Run: [TOSHIBA Online Product Information] C:\Program Files (x86)\TOSHIBA\Toshiba Online Product Information\topi.exe (User 'Système')
                        O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Système')
                        O4 - HKUS\.DEFAULT\..\Run: [TOSHIBA Online Product Information] C:\Program Files (x86)\TOSHIBA\Toshiba Online Product Information\topi.exe (User 'Default user')
                        O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
                        O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (User 'Default user')
                        O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe
                        O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
                        O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
                        O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
                        O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
                        O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
                        O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
                        O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
                        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
                        O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
                        O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
                        O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
                        O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/fr/uno1/GAME_UNO1.cab
                        O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                        O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
                        O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
                        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
                        O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
                        O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
                        O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
                        O23 - Service: @%SystemRoot%\system32\aelupsvc.dll,-1 (AeLookupSvc) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
                        O23 - Service: Avira Planificateur (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
                        O23 - Service: Avira Protection temps réel (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
                        O23 - Service: @%systemroot%\system32\appidsvc.dll,-100 (AppIDSvc) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%systemroot%\system32\appinfo.dll,-100 (Appinfo) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
                        O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-204 (AudioEndpointBuilder) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-200 (AudioSrv) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\AxInstSV.dll,-103 (AxInstSV) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\bdesvc.dll,-100 (BDESVC) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\bfe.dll,-1001 (BFE) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\qmgr.dll,-1000 (BITS) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                        O23 - Service: @%systemroot%\system32\browser.dll,-100 (Browser) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%SystemRoot%\System32\bthserv.dll,-101 (bthserv) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%SystemRoot%\System32\certprop.dll,-11 (CertPropSvc) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: ConfigFree WiMAX Service (cfWiMAXService) - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
                        O23 - Service: ConfigFree Gadget Service - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe
                        O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
                        O23 - Service: @%SystemRoot%\system32\cryptsvc.dll,-1001 (CryptSvc) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @oleres.dll,-5012 (DcomLaunch) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\defragsvc.dll,-101 (defragsvc) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\dhcpcore.dll,-100 (Dhcp) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%SystemRoot%\System32\dnsapi.dll,-101 (Dnscache) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%systemroot%\system32\dot3svc.dll,-1102 (dot3svc) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%systemroot%\system32\dps.dll,-500 (DPS) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%systemroot%\system32\eapsvc.dll,-1 (EapHost) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
                        O23 - Service: @%SystemRoot%\ehome\ehrecvr.exe,-101 (ehRecvr) - Unknown owner - C:\Windows\ehome\ehRecvr.exe
                        O23 - Service: @%SystemRoot%\ehome\ehsched.exe,-101 (ehSched) - Unknown owner - C:\Windows\ehome\ehsched.exe
                        O23 - Service: EPSON V5 Service4(01) (EPSON_EB_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE
                        O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
                        O23 - Service: @%SystemRoot%\system32\wevtsvc.dll,-200 (eventlog) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @comres.dll,-2450 (EventSystem) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
                        O23 - Service: @%systemroot%\system32\fdPHost.dll,-100 (fdPHost) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%systemroot%\system32\fdrespub.dll,-100 (FDResPub) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%systemroot%\system32\FntCache.dll,-100 (FontCache) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: Service Google Update (gupdate) (gupdate) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
                        O23 - Service: Service Google Update (gupdatem) (gupdatem) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
                        O23 - Service: @%SystemRoot%\System32\hidserv.dll,-101 (hidserv) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\kmsvc.dll,-6 (hkmsvc) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%SystemRoot%\System32\ListSvc.dll,-100 (HomeGroupListener) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%SystemRoot%\System32\provsvc.dll,-100 (HomeGroupProvider) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: HTCMonitorService - Nero AG - C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe
                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                        O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
                        O23 - Service: @%SystemRoot%\system32\ikeext.dll,-501 (IKEEXT) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: InternetEverywhere_Service - Unknown owner - C:\Program Files (x86)\InternetEverywhere\InternetEverywhere_Service.exe
                        O23 - Service: @%systemroot%\system32\IPBusEnum.dll,-102 (IPBusEnum) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\iphlpsvc.dll,-500 (iphlpsvc) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                        O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
                        O23 - Service: @comres.dll,-2946 (KtmRm) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%systemroot%\system32\srvsvc.dll,-100 (LanmanServer) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%systemroot%\system32\wkssvc.dll,-100 (LanmanWorkstation) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\lltdres.dll,-1 (lltdsvc) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\lmhsvc.dll,-101 (lmhosts) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe
                        O23 - Service: @%systemroot%\system32\mmcss.dll,-100 (MMCSS) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
                        O23 - Service: @%SystemRoot%\system32\FirewallAPI.dll,-23090 (MpsSvc) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
                        O23 - Service: @%SystemRoot%\system32\iscsidsc.dll,-5000 (MSiSCSI) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\msimsg.dll,-27 (msiserver) - Unknown owner - C:\Windows\system32\msiexec.exe
                        O23 - Service: @%SystemRoot%\system32\qagentrt.dll,-6 (napagent) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
                        O23 - Service: @%SystemRoot%\system32\netman.dll,-109 (Netman) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\netprofm.dll,-202 (netprofm) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%SystemRoot%\System32\nlasvc.dll,-1 (NlaSvc) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\nsisvc.dll,-200 (nsi) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\pnrpsvc.dll,-8004 (p2pimsvc) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\p2psvc.dll,-8006 (p2psvc) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
                        O23 - Service: @%SystemRoot%\system32\pcasvc.dll,-1 (PcaSvc) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%systemroot%\sysWow64\perfhost.exe,-2 (PerfHost) - Unknown owner - C:\Windows\SysWow64\perfhost.exe
                        O23 - Service: @%systemroot%\system32\pla.dll,-500 (pla) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\umpnpmgr.dll,-100 (PlugPlay) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
                        O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
                        O23 - Service: @%SystemRoot%\system32\pnrpauto.dll,-8002 (PNRPAutoReg) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\pnrpsvc.dll,-8000 (PNRPsvc) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%SystemRoot%\System32\polstore.dll,-5010 (PolicyAgent) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\umpo.dll,-100 (Power) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%systemroot%\system32\profsvc.dll,-300 (ProfSvc) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
                        O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%windir%\WindowsMobile\rapimgr.dll,-104 (RapiMgr) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%Systemroot%\system32\rasauto.dll,-200 (RasAuto) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%Systemroot%\system32\rasmans.dll,-200 (RasMan) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @regsvc.dll,-1 (RemoteRegistry) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%windir%\system32\RpcEpMap.dll,-1001 (RpcEptMapper) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
                        O23 - Service: @oleres.dll,-5010 (RpcSs) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
                        O23 - Service: @%SystemRoot%\System32\SCardSvr.dll,-1 (SCardSvr) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\schedsvc.dll,-100 (Schedule) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%SystemRoot%\System32\certprop.dll,-13 (SCPolicySvc) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\sdrsvc.dll,-107 (SDRSVC) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\Sens.dll,-200 (SENS) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%SystemRoot%\System32\sensrsvc.dll,-1000 (SensrSvc) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%SystemRoot%\System32\SessEnv.dll,-1026 (SessionEnv) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\ipnathlp.dll,-106 (SharedAccess) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%SystemRoot%\System32\shsvcs.dll,-12288 (ShellHWDetection) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
                        O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
                        O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
                        O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
                        O23 - Service: @%SystemRoot%\system32\sppuinotify.dll,-103 (sppuinotify) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%systemroot%\system32\ssdpsrv.dll,-100 (SSDPSRV) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\sstpsvc.dll,-200 (SstpSvc) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\wiaservc.dll,-9 (stisvc) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%SystemRoot%\System32\swprv.dll,-103 (swprv) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\sysmain.dll,-1000 (SysMain) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\TabSvc.dll,-100 (TabletInputService) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\tapisrv.dll,-10100 (TapiSrv) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\tbssvc.dll,-100 (TBS) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: Notebook Performance Tuning Service (TEMPRO) (TemproMonitoringService) - Toshiba Europe GmbH - C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
                        O23 - Service: @%SystemRoot%\System32\termsrv.dll,-268 (TermService) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%SystemRoot%\System32\themeservice.dll,-8192 (Themes) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%systemroot%\system32\mmcss.dll,-102 (THREADORDER) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
                        O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - Unknown owner - C:\Windows\system32\TODDSrv.exe (file missing)
                        O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
                        O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TECO\TecoService.exe
                        O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
                        O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
                        O23 - Service: @%SystemRoot%\system32\trkwks.dll,-1 (TrkWks) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%SystemRoot%\servicing\TrustedInstaller.exe,-100 (TrustedInstaller) - Unknown owner - C:\Windows\servicing\TrustedInstaller.exe
                        O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
                        O23 - Service: @%systemroot%\system32\upnphost.dll,-213 (upnphost) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\dwm.exe,-2000 (UxSms) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
                        O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
                        O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
                        O23 - Service: @%SystemRoot%\system32\w32time.dll,-200 (W32Time) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
                        O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
                        O23 - Service: @%systemroot%\system32\wbiosrvc.dll,-100 (WbioSrvc) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%windir%\WindowsMobile\wcescomm.dll,-40079 (WcesComm) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\wcncsvc.dll,-3 (wcncsvc) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\WcsPlugInService.dll,-200 (WcsPlugInService) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%systemroot%\system32\wdi.dll,-502 (WdiServiceHost) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%systemroot%\system32\wdi.dll,-500 (WdiSystemHost) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%systemroot%\system32\webclnt.dll,-100 (WebClient) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\wecsvc.dll,-200 (Wecsvc) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%SystemRoot%\System32\wercplsupport.dll,-101 (wercplsupport) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%SystemRoot%\System32\wersvc.dll,-100 (WerSvc) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%ProgramFiles%\Windows Defender\MsMpRes.dll,-103 (WinDefend) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\winhttp.dll,-100 (WinHttpAutoProxySvc) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%Systemroot%\system32\wbem\wmisvc.dll,-205 (Winmgmt) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%Systemroot%\system32\wsmsvc.dll,-101 (WinRM) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%SystemRoot%\System32\wlansvc.dll,-257 (Wlansvc) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
                        O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
                        O23 - Service: @%SystemRoot%\system32\wpcsvc.dll,-100 (WPCSvc) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\wpdbusenum.dll,-100 (WPDBusEnum) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%SystemRoot%\System32\wscsvc.dll,-200 (wscsvc) - Unknown owner - C:\Windows\System32\svchost.exe
                        O23 - Service: @%systemroot%\system32\SearchIndexer.exe,-103 (WSearch) - Unknown owner - C:\Windows\system32\SearchIndexer.exe
                        O23 - Service: @%systemroot%\system32\wuaueng.dll,-105 (wuauserv) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%SystemRoot%\system32\wudfsvc.dll,-1000 (wudfsvc) - Unknown owner - C:\Windows\system32\svchost.exe
                        O23 - Service: @%SystemRoot%\System32\wwansvc.dll,-257 (WwanSvc) - Unknown owner - C:\Windows\system32\svchost.exe
                        0
                        1. Modérateur
                          Télécharge et lance ça : https://toolslib.net
                          Clic sur restaurer.

                          Relance HijackThis (si tu es sur Vista/Seven - faire un clic droit et executer en tant qu'administrateur) et coche ces lignes :

                          R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.cherche.us/keyword/%s
                          O4 - HKLM\..\Run: [] C:\Program Files (x86)\hackhound.exe
                          O4 - HKLM\..\RunServices: [] C:\Program Files (x86)\hackhound.exe

                          ==> clic sur fix checked

                          Redémarre l'ordinateur

                          Refais un scan HijackThis et donne le rapport.

                          Like the angel you are, you laugh creating a lightness in my chest,
                          Your eyes they penetrate me,
                          (Your answer's always 'maybe')
                          That's when I got up and left
                          0
                          • 1
                          • 2