Virus

Résolu
Bonjour,

je suis infectée par 2 virus: virtumonde et privacyremover.

Comment faire pour m'en débarasser?

merci d'avance
Configuration: Windows Vista
Internet Explorer 7.0

28 réponses

Résumé de la discussion

Plusieurs utilisateurs ont rencontré une infection associant Virtumonde et PrivacyRemover sur Windows Vista avec Internet Explorer 7, et ont cherché des méthodes efficaces pour s'en débarrasser. Des solutions proposées impliquent l'exécution d'outils de nettoyage en mode administrateur tels que HijackThis, ToolsCleaner, Easy Cleaner et Malwarebytes, puis l'analyse des rapports pour supprimer registres, processus et fichiers compromis. Les retours indiquent des suppressions réussies de composants malveillants, des registres et fichiers supprimés ou quarantainés, et un PC qui retrouve son fonctionnement après le nettoyage et les vérifications. En parallèle, des conseils prévoient l'usage régulier d'anti-malware et d'anti-virus, la mise à jour des logiciels et des navigations plus prudentes, ainsi que la vérification des périphériques comme l'imprimante.

Bobot (l’IA à votre service)
  1. alors, j'ai essayé un autre cable et ça na pas fonctionné. J'ai réinstallé et maintenant elle marche.

    Merci bcp pour tous tes conseils.
    0
    1. Bonsoir,
      Tant mieux pour ton PC.

      Pour ton imprimante, si tu as la possibilité de la tester sur un autre PC ce serait bien. C'est un cable USB ? Tu en as un autre pour faire un test : changer le câble ?
      Sinon tu peux aussi la désinstaller et la réinstaller. Mais si elle n'est pas détectée...Ca ressemble plus à un problème matériel.

      Tiens moi au courant.

      A+
      0
      1. J'ai éxcuter les programmes en mode administrateur et ça a marché. voici les résultats:

        rapport tool cleaner:
        -->- Recherche:

        C:\Program Files\Trend Micro\HijackThis: trouvé !
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
        C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: trouvé !
        C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
        C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
        C:\Users\All Users\Microsoft\Windows\Start Menu\Programmes\HijackThis: trouvé !
        C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
        C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !

        ---------------------------------
        -->- Suppression:

        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
        C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: supprimé !
        C:\Program Files\Trend Micro\HijackThis: supprimé !
        C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: Erreur de suppression !
        C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: supprimé !

        Quant à mon PC, il va très bien. La virus me lançait des warning sans arrêt mais ne m'a jamais bloqué un programme, donc mon pc est redevenu comme avant.
        Merci beaucoup de ton aide, je n'aurais jamais pu faire ça toute seule!

        Par contre j'ai un autre souci, je sais pas si tu pourras m'aider: j'ai changé ma cartouche d'encre il y a quelques jours (avant de déinfecter le pc). L'imprimante a réussi à me sortir une page de test (qui était normale). Mais depuis, je ne peux plus imprimer car l'ordinateur la reconnait "hors connexion" et quand je lance l'impression, elle me met "erreur-imprssion". Je n'ai pourtant touché à aucun cable, et j'ai vérifié plusieurs fois que tout soit bien branché.
        C'est une HP photosmart C3180. Dois-je désinstaller et réinstaller l'imprimante?
        0
        1. Bonjour,
          parfait.

          Peux tu refaire un toolscleaner mais pour l'executer :
          Fais un Clic-droit sur le programme et choisis "Exécuter en tant qu'administrateur"
          De cette façon, il devrait fonctionner.
          Poste son rapport stp.

          Idem pour Easycleaner.

          Comment va le PC ?

          A+
          0
          1. pour désactiver et réactiver la restauration du systeme, je ne peux pas car ils me mettent: création du point de restauration désactivée par la stratégie de groupe
            0
            1. j'ai effectué l'opération tool cleaner. Voici le rapport:

              -->- Recherche:

              C:\Program Files\Trend Micro\HijackThis: trouvé !
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
              C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: trouvé !
              C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
              C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
              C:\Users\alain\AppData\Local\VirtualStore\Program Files\Trend Micro\HijackThis: trouvé !
              C:\Users\alain\AppData\Roaming\Microsoft\Windows\Recent\HijackThis.lnk: trouvé !
              C:\Users\alain\Desktop\HijackThis.lnk: trouvé !
              C:\Users\All Users\Microsoft\Windows\Start Menu\Programmes\HijackThis: trouvé !
              C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
              C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !

              ---------------------------------
              -->- Suppression:

              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: Erreur de suppression !
              C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: Erreur de suppression !
              C:\Users\alain\AppData\Roaming\Microsoft\Windows\Recent\HijackThis.lnk: supprimé !
              C:\Users\alain\Desktop\HijackThis.lnk: supprimé !
              C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: Erreur de suppression !
              C:\Program Files\Trend Micro\HijackThis: Erreur de suppression !
              C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: Erreur de suppression !
              C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: Erreur de suppression !
              C:\Users\alain\AppData\Local\VirtualStore\Program Files\Trend Micro\HijackThis: supprimé !
              C:\Users\All Users\Microsoft\Windows\Start Menu\Programmes\HijackThis: Erreur de suppression !
              C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis: Erreur de suppression !

              j'ai effectué easy cleaner:

              mais ils me mettent que la suppression est impossible
              0
              1. maintenant je viens de mettre à jour java et acrobate.
                J'ai aussi vider ma poubelle.
                0
                1. alors déja, j'ai réaliser l'étape 1. voici le dernier hijackthislog:

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 12:19:22, on 01/09/2008
                  Platform: Windows Vista SP1 (WinNT 6.00.1905)
                  MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                  Boot mode: Normal

                  Running processes:
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\Explorer.EXE
                  C:\Windows\RtHDVCpl.exe
                  C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
                  C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
                  C:\Users\alain\AppData\Local\Temp\RtkBtMnt.exe
                  C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                  C:\Program Files\Apoint2K\Apoint.exe
                  C:\Acer\Empowering Technology\eAudio\eAudio.exe
                  C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                  C:\Windows\WindowsMobile\wmdSync.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                  C:\Windows\System32\igfxtray.exe
                  C:\Windows\System32\hkcmd.exe
                  C:\Windows\System32\igfxpers.exe
                  C:\Program Files\Windows Sidebar\sidebar.exe
                  C:\Windows\system32\igfxsrvc.exe
                  C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  C:\Program Files\Apoint2K\Apntex.exe
                  C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
                  C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
                  C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
                  C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
                  C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                  C:\Windows\system32\DllHost.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                  R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                  O1 - Hosts: ::1 localhost
                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                  O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                  O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                  O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                  O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\Run: [PLFSetL] C:\Windows\PLFSetL.exe
                  O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
                  O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
                  O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
                  O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
                  O4 - HKLM\..\Run: [eAudio] "C:\Acer\Empowering Technology\eAudio\eAudio.exe"
                  O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                  O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
                  O4 - HKLM\..\Run: [Skytel] Skytel.exe
                  O4 - HKLM\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALuNotify.exe
                  O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
                  O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                  O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                  O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                  O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                  O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                  O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                  O4 - HKUS\S-1-5-18\..\RunOnce: [] (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\RunOnce: [] (User 'Default user')
                  O4 - Global Startup: Empowering Technology Launcher.lnk = ?
                  O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                  O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                  O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                  O13 - Gopher Prefix:
                  O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL eNetHook.dll
                  O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
                  O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                  O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                  O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
                  O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
                  O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
                  O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                  O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
                  O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                  O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
                  O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
                  O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                  0
                  1. alors déja, j'ai réaliser l'étape 1. voici le dernier hijackthislog:

                    Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 12:19:22, on 01/09/2008
                    Platform: Windows Vista SP1 (WinNT 6.00.1905)
                    MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                    Boot mode: Normal

                    Running processes:
                    C:\Windows\system32\taskeng.exe
                    C:\Windows\system32\Dwm.exe
                    C:\Windows\Explorer.EXE
                    C:\Windows\RtHDVCpl.exe
                    C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
                    C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
                    C:\Users\alain\AppData\Local\Temp\RtkBtMnt.exe
                    C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                    C:\Program Files\Apoint2K\Apoint.exe
                    C:\Acer\Empowering Technology\eAudio\eAudio.exe
                    C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                    C:\Windows\WindowsMobile\wmdSync.exe
                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                    C:\Windows\System32\igfxtray.exe
                    C:\Windows\System32\hkcmd.exe
                    C:\Windows\System32\igfxpers.exe
                    C:\Program Files\Windows Sidebar\sidebar.exe
                    C:\Windows\system32\igfxsrvc.exe
                    C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                    C:\Program Files\Apoint2K\Apntex.exe
                    C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
                    C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
                    C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
                    C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
                    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                    C:\Windows\system32\DllHost.exe

                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                    O1 - Hosts: ::1 localhost
                    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                    O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                    O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                    O4 - HKLM\..\Run: [PLFSetL] C:\Windows\PLFSetL.exe
                    O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
                    O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
                    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
                    O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
                    O4 - HKLM\..\Run: [eAudio] "C:\Acer\Empowering Technology\eAudio\eAudio.exe"
                    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                    O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
                    O4 - HKLM\..\Run: [Skytel] Skytel.exe
                    O4 - HKLM\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALuNotify.exe
                    O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
                    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                    O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                    O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                    O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                    O4 - HKUS\S-1-5-18\..\RunOnce: [] (User 'SYSTEM')
                    O4 - HKUS\.DEFAULT\..\RunOnce: [] (User 'Default user')
                    O4 - Global Startup: Empowering Technology Launcher.lnk = ?
                    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                    O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                    O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                    O13 - Gopher Prefix:
                    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL eNetHook.dll
                    O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
                    O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                    O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                    O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
                    O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
                    O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
                    O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                    O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
                    O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                    O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
                    O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
                    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                    0
                    1. Parfait.
                      Alors on termine.

                      > Lance Hijackthis :
                      - Puis sélectionne < Do a system scan only >
                      - Coche les cases des lignes suivantes :

                      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                      
                      O4 - HKUS\S-1-5-18\..\RunOnce: [] (User 'SYSTEM')
                      Inconnu
                      O4 - HKUS\.DEFAULT\..\RunOnce: [] (User 'Default user')
                      O4 - Global Startup: Empowering Technology Launcher.lnk = ?

                      Ensuite,
                      - Ferme toutes les autres fenêtres et applications (même internet)
                      - Clic sur < fixe checked >

                      > Relance ton PC en mode normal puis Hijackthis :
                      Puis sélectionne < do a system scan and save a logfile >,

                      Et envoie, par collier/coller, ton log Hijackthis,

                      Ensuite,
                      > Peux-tu vérifier ta console JAVA ici : https://www.java.com/fr/download/uninstalltool.jsp, et installer la nouvelle version si besoin est (dans ce cas désinstalle avant l'ancienne version). Dis moi ce qu'il en est stp.
                      Pour info. ou en cas de problème : http://assiste.com.free.fr/p/abc/c/anti_java.html

                      > Mets à jour Acrobat si ce n'est pas le cas (désinstalle avant la version antérieure) : https://get2.adobe.com/reader/otherversions/

                      > Télécharge ToolsCleaner : https://www.commentcamarche.net/telecharger/securite/22061-toolscleaner/ sur ton bureau pour supprimer les boîtes de Pandore.
                      - Clique sur Recherche et laisse le scan agir ...
                      - Clique sur Suppression pour finaliser (tu peux, si tu le souhaites, te servir des Options facultatives)
                      - Clique sur Quitter pour obtenir le rapport et poste le dans ta réponse (TCleaner.txt se trouve à la racine de ton disque dur (C:\)).
                      - Supprime ToolsCleaner ensuite (il n'est pas installé dans Ajout/suppression de programmes. C'est un fichier directement exécutable : pas d'installation).

                      > Télécharge et installe Easy Cleaner stp : https://www.01net.com/telecharger/windows/Utilitaire/registre/fiches/8351.html
                      (lien miroir : https://www.clubic.com/telecharger-fiche11170-easycleaner.html )
                      - Lance le programme puis clique sur <Registre> puis sur <Trouver>.
                      - A la fin du scan clique sur <Supprime tout> puis confirme par <Oui> puis quitte le programme.
                      Si besoin tuto ici : https://www.pcparadise.fr
                      et http://www.6ma.fr/tuto/easycleaner-nettoyer-windows-des-elements-obsoletes/

                      > Tu peux aussi vider ta corbeille.

                      > Désactive et réactive la restauration de système, pour cela : suis les instructions de ce lien : http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/fr_docid/20020830101856924
                      PS : Si tu est sous Vista c'est ce lien : http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/4f60eedf1156c8068525695b005ca288/c066b2e9a50cc948802572870032b170?OpenDocument

                      ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

                      Quelques conseils et recommandations pour l'avenir :

                      > Passe un coup d'AGV et/ou de MalwareByte's Anti-Malware et de Ccleaner de temps en temps (1 fois par semaine à 1 fois par mois, suivant l'utilisation que tu fais de ton PC. Tu peux aussi décocher la casse dans l’onglet "Options" puis clique sur "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier temp de Windows, plus vieux que 48 heures").
                      - Utilise aussi tes autres logiciels de protection (scannes antivirus, antispywares...). N'oublie pas de faire les mises à jour avant de les utiliser.
                      - Pense aussi à faire une défragmentation de tes disques durs de temps en temps (garde suffisamment d'espace sur C:\ (1/3 de libre pour être à l'aise))

                      > Pour bien protéger ton PC :
                      [1 seul Antivirus] + [1 seul Pare feu] + [Quelques Antispywares] + [Mises à Jour récentes Windows et Logiciels de Protection] + [Utilisation de Firefox -ou autres- (Internet Explorer présente des failles de sécurité qui mettent longtemps avant d'être corrigées mais il faut absolument le conserver pour les mises à jour Windows)] + [Utilisation du PC en mode Invité (= limité). Lors d'une infection en mode administrateur le PC est beaucoup plus vulnérable. Voir ICI]
                      PS : En fait la meilleure des protections c'est toi même : ce que tu fais avec ton PC : où tu surfes, télécharges...ect....
                      Les virus utilisent les failles de ton PC pour infecter un système. Info : http://assiste.com.free.fr/p/abc/a/zombies_et_botnets.html

                      > Quelques liens utiles :
                      - http://www.commentcamarche.net/faq/sujet 2432 securite proteger un ordinateur contre les malwares d internet
                      - https://sebsauvage.net/safehex.html
                      - https://www.zebulon.fr/telechargements/securite/protection-donnees-personnelles/spywareblaster.html (= petit logiciel qui bloque l'installation d'activ-X nuisibles au PC. Fonctionne en arrière plan)

                      Voila,
                      Bonne lecture....

                      A+
                      0
                      1. alors, après avoir suivi tes conseils, voici:

                        -le rapport antivir:

                        Avira AntiVir Personal
                        Report file date: dimanche 31 août 2008 18:26

                        Scanning for 1585012 virus strains and unwanted programs.

                        Licensed to: Avira AntiVir PersonalEdition Classic
                        Serial number: 0000149996-ADJIE-0001
                        Platform: Windows Vista
                        Windows version: (Service Pack 1) [6.0.6001]
                        Boot mode: Normally booted
                        Username: SYSTEM
                        Computer name: PC-DE-ALAIN

                        Version information:
                        BUILD.DAT : 8.1.0.331 16934 Bytes 12/08/2008 11:46:00
                        AVSCAN.EXE : 8.1.4.7 315649 Bytes 26/06/2008 08:57:53
                        AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 07:56:40
                        LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 12:44:19
                        LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 07:58:52
                        ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 10:33:34
                        ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 24/06/2008 13:54:15
                        ANTIVIR2.VDF : 7.0.6.94 2998784 Bytes 31/08/2008 16:24:58
                        ANTIVIR3.VDF : 7.0.6.95 2048 Bytes 31/08/2008 16:24:59
                        Engineversion : 8.1.1.23
                        AEVDF.DLL : 8.1.0.5 102772 Bytes 25/02/2008 09:58:21
                        AESCRIPT.DLL : 8.1.0.68 315770 Bytes 31/08/2008 16:25:13
                        AESCN.DLL : 8.1.0.23 119156 Bytes 10/07/2008 12:44:49
                        AERDL.DLL : 8.1.0.20 418165 Bytes 24/04/2008 12:37:48
                        AEPACK.DLL : 8.1.2.1 364917 Bytes 15/07/2008 12:58:35
                        AEOFFICE.DLL : 8.1.0.22 192890 Bytes 31/08/2008 16:25:11
                        AEHEUR.DLL : 8.1.0.50 1388918 Bytes 31/08/2008 16:25:09
                        AEHELP.DLL : 8.1.0.15 115063 Bytes 10/07/2008 12:44:48
                        AEGEN.DLL : 8.1.0.36 315764 Bytes 31/08/2008 16:25:01
                        AEEMU.DLL : 8.1.0.7 430452 Bytes 31/07/2008 08:33:21
                        AECORE.DLL : 8.1.1.8 172406 Bytes 31/07/2008 08:33:21
                        AEBB.DLL : 8.1.0.1 53617 Bytes 10/07/2008 12:44:48
                        AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 08:40:05
                        AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 09:28:01
                        AVREP.DLL : 8.0.0.2 98344 Bytes 31/08/2008 16:24:59
                        AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 11:26:40
                        AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
                        AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 12:27:49
                        SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
                        SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 12:49:40
                        NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
                        RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 13:48:07
                        RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 13:34:37

                        Configuration settings for the scan:
                        Jobname..........................: Complete system scan
                        Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
                        Logging..........................: low
                        Primary action...................: interactive
                        Secondary action.................: ignore
                        Scan master boot sector..........: on
                        Scan boot sector.................: on
                        Boot sectors.....................: C:, D:, F:, G:,
                        Process scan.....................: on
                        Scan registry....................: on
                        Search for rootkits..............: off
                        Scan all files...................: Intelligent file selection
                        Scan archives....................: on
                        Recursion depth..................: 20
                        Smart extensions.................: on
                        Macro heuristic..................: on
                        File heuristic...................: medium

                        Start of the scan: dimanche 31 août 2008 18:26

                        The scan of running processes will be started
                        Scan process 'avscan.exe' - '1' Module(s) have been scanned
                        Scan process 'mobsync.exe' - '1' Module(s) have been scanned
                        Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                        Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                        Scan process 'avguard.exe' - '1' Module(s) have been scanned
                        Scan process 'sched.exe' - '1' Module(s) have been scanned
                        Scan process 'svchost.exe' - '1' Module(s) have been scanned
                        Scan process 'VSSVC.exe' - '1' Module(s) have been scanned
                        Scan process 'hpqste08.exe' - '1' Module(s) have been scanned
                        Scan process 'eRAgent.exe' - '1' Module(s) have been scanned
                        Scan process 'Acer.Empowering.Framework.Supervisor.ex' - '1' Module(s) have been scanned
                        Scan process 'ePower_DMC.exe' - '1' Module(s) have been scanned
                        Scan process 'infocard.exe' - '1' Module(s) have been scanned
                        Scan process 'eNMTray.exe' - '1' Module(s) have been scanned
                        Scan process 'hpqtra08.exe' - '1' Module(s) have been scanned
                        Scan process 'sidebar.exe' - '1' Module(s) have been scanned
                        Scan process 'igfxsrvc.exe' - '1' Module(s) have been scanned
                        Scan process 'igfxext.exe' - '1' Module(s) have been scanned
                        Scan process 'ApntEx.exe' - '1' Module(s) have been scanned
                        Scan process 'svchost.exe' - '1' Module(s) have been scanned
                        Scan process 'ApMsgFwd.exe' - '1' Module(s) have been scanned
                        Scan process 'wmdSync.exe' - '1' Module(s) have been scanned
                        Scan process 'hpwuSchd2.exe' - '1' Module(s) have been scanned
                        Scan process 'eAudio.exe' - '1' Module(s) have been scanned
                        Scan process 'Apoint.exe' - '1' Module(s) have been scanned
                        Scan process 'IAAnotif.exe' - '1' Module(s) have been scanned
                        Scan process 'LManager.exe' - '1' Module(s) have been scanned
                        Scan process 'unsecapp.exe' - '1' Module(s) have been scanned
                        Scan process 'WmiPrvSE.exe' - '1' Module(s) have been scanned
                        Scan process 'WmiPrvSE.exe' - '1' Module(s) have been scanned
                        Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned
                        Scan process 'WLLoginProxy.exe' - '1' Module(s) have been scanned
                        Scan process 'iexplore.exe' - '1' Module(s) have been scanned
                        Scan process 'ieuser.exe' - '1' Module(s) have been scanned
                        Scan process 'ePowerSvc.exe' - '1' Module(s) have been scanned
                        Scan process 'capuserv.exe' - '1' Module(s) have been scanned
                        Scan process 'eRecoveryService.exe' - '1' Module(s) have been scanned
                        Scan process 'XAudio.exe' - '1' Module(s) have been scanned
                        Scan process 'RtkBtMnt.exe' - '1' Module(s) have been scanned
                        Scan process 'igfxsrvc.exe' - '1' Module(s) have been scanned
                        Scan process 'SearchIndexer.exe' - '1' Module(s) have been scanned
                        Scan process 'svchost.exe' - '1' Module(s) have been scanned
                        Scan process 'svchost.exe' - '1' Module(s) have been scanned
                        Scan process 'svchost.exe' - '1' Module(s) have been scanned
                        Scan process 'svchost.exe' - '1' Module(s) have been scanned
                        Scan process 'svchost.exe' - '1' Module(s) have been scanned
                        Scan process 'taskeng.exe' - '1' Module(s) have been scanned
                        Scan process 'igfxpers.exe' - '1' Module(s) have been scanned
                        Scan process 'hkcmd.exe' - '1' Module(s) have been scanned
                        Scan process 'igfxtray.exe' - '1' Module(s) have been scanned
                        Scan process 'MobilityService.exe' - '1' Module(s) have been scanned
                        Scan process 'eDSLoader.exe' - '1' Module(s) have been scanned
                        Scan process 'LSSrvc.exe' - '1' Module(s) have been scanned
                        Scan process 'RtHDVCpl.exe' - '1' Module(s) have been scanned
                        Scan process 'IAANTmon.exe' - '1' Module(s) have been scanned
                        Scan process 'svchost.exe' - '1' Module(s) have been scanned
                        Scan process 'eNet Service.exe' - '1' Module(s) have been scanned
                        Scan process 'eLockServ.exe' - '1' Module(s) have been scanned
                        Scan process 'explorer.exe' - '1' Module(s) have been scanned
                        Scan process 'eDSService.exe' - '1' Module(s) have been scanned
                        Scan process 'dwm.exe' - '1' Module(s) have been scanned
                        Scan process 'taskeng.exe' - '1' Module(s) have been scanned
                        Scan process 'ALaunchSvc.exe' - '1' Module(s) have been scanned
                        Scan process 'svchost.exe' - '1' Module(s) have been scanned
                        Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                        Scan process 'svchost.exe' - '1' Module(s) have been scanned
                        Scan process 'svchost.exe' - '1' Module(s) have been scanned
                        Scan process 'SLsvc.exe' - '1' Module(s) have been scanned
                        Scan process 'audiodg.exe' - '0' Module(s) have been scanned
                        Scan process 'svchost.exe' - '1' Module(s) have been scanned
                        Scan process 'svchost.exe' - '1' Module(s) have been scanned
                        Scan process 'svchost.exe' - '1' Module(s) have been scanned
                        Scan process 'svchost.exe' - '1' Module(s) have been scanned
                        Scan process 'svchost.exe' - '1' Module(s) have been scanned
                        Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                        Scan process 'lsm.exe' - '1' Module(s) have been scanned
                        Scan process 'lsass.exe' - '1' Module(s) have been scanned
                        Scan process 'services.exe' - '1' Module(s) have been scanned
                        Scan process 'csrss.exe' - '1' Module(s) have been scanned
                        Scan process 'wininit.exe' - '1' Module(s) have been scanned
                        Scan process 'csrss.exe' - '1' Module(s) have been scanned
                        Scan process 'smss.exe' - '1' Module(s) have been scanned
                        81 processes with 81 modules were scanned

                        Starting master boot sector scan:
                        Master boot sector HD0
                        [INFO] No virus was found!
                        Master boot sector HD1
                        [INFO] No virus was found!
                        Master boot sector HD2
                        [INFO] No virus was found!

                        Start scanning boot sectors:
                        Boot sector 'C:\'
                        [INFO] No virus was found!
                        Boot sector 'D:\'
                        [INFO] No virus was found!
                        Boot sector 'F:\'
                        [INFO] No virus was found!
                        Boot sector 'G:\'
                        [INFO] No virus was found!

                        Starting to scan the registry.
                        The registry was scanned ( '51' files ).

                        Starting the file scan:

                        Begin scan in 'C:\' <ACER>
                        C:\hiberfil.sys
                        [WARNING] The file could not be opened!
                        C:\pagefile.sys
                        [WARNING] The file could not be opened!
                        C:\Users\alain\AppData\Local\VirtualStore\Windows\System32\phc9rjj0etfv.bmp
                        [DETECTION] Is the TR/Fakealert.AAF Trojan
                        [NOTE] The file was moved to '491dc9fa.qua'!
                        Begin scan in 'D:\' <DATA>
                        Begin scan in 'F:\' <EXTERNE>
                        F:\sauvegarde portable toshiba\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\5EFT9YSE\f4d28682d186cc6beb75f106d133f489[1].zip
                        [0] Archive type: ZIP
                        --> b128.exe
                        [DETECTION] Is the TR/Dldr.Agent.ezc.1 Trojan
                        [NOTE] The file was moved to '491ecfe9.qua'!
                        F:\sauvegarde portable toshiba\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\6YJ9T3TF\b433b5a80d2cb00f8f1c54387f9aa332[1].zip
                        [0] Archive type: ZIP
                        --> b157.exe
                        [DETECTION] Is the TR/Dldr.Agent.jih.1 Trojan
                        [NOTE] The file was moved to '48edcff7.qua'!
                        F:\sauvegarde portable toshiba\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\6YJ9T3TF\mrofinu[1].zip
                        [0] Archive type: ZIP
                        --> mrofinu.exe
                        [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
                        [NOTE] The file was moved to '4929d03a.qua'!
                        F:\sauvegarde portable toshiba\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\6YJ9T3TF\mrofinu[2].zip
                        [0] Archive type: ZIP
                        --> mrofinu.exe
                        [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
                        [NOTE] The file was moved to '4929d03d.qua'!
                        F:\sauvegarde portable toshiba\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\8W6LRE2L\17PHolmes[1].cmt
                        [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
                        [NOTE] The file was moved to '490ad007.qua'!
                        F:\sauvegarde portable toshiba\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\8W6LRE2L\wv[1].exe
                        [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
                        [NOTE] The file was moved to '4915d04c.qua'!
                        F:\sauvegarde portable toshiba\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\A8X9VRFJ\sruninstaller.prod.v12000.11jan2008.exe[1].1ac39aea6b22cdb4e6ed0c75f1d83467
                        [DETECTION] Is the TR/Agent.52736.K Trojan
                        [NOTE] The file was moved to '492fd04f.qua'!
                        F:\sauvegarde portable toshiba\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\BGDPV84O\dummy[1].exe
                        [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
                        [NOTE] The file was moved to '4927d05a.qua'!
                        F:\sauvegarde portable toshiba\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\BGDPV84O\mrofinu[1].zip
                        [0] Archive type: ZIP
                        --> mrofinu.exe
                        [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
                        [NOTE] The file was moved to '4929d05c.qua'!
                        F:\sauvegarde portable toshiba\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\FX08GRRN\8154ff2675af1b6e0677560871425153[1].zip
                        [0] Archive type: ZIP
                        --> b138.exe
                        [DETECTION] Is the TR/Agent.11264.K Trojan
                        [NOTE] The file was moved to '48efd028.qua'!
                        F:\sauvegarde portable toshiba\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\LBRVX1OE\wv[1].exe
                        [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
                        [NOTE] The file was moved to '4915d07d.qua'!
                        F:\sauvegarde portable toshiba\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\NQKVR10T\488aede55160e40e3d5988951bfacaca[1].zip
                        [0] Archive type: ZIP
                        --> b999.exe
                        [DETECTION] Is the TR/Agent.CZF Trojan
                        [NOTE] The file was moved to '48f2d043.qua'!
                        F:\sauvegarde portable toshiba\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\XTKMGVTV\93e4c2046fcb4ac4bdc3dbbcc28127fb[1].zip
                        [0] Archive type: ZIP
                        --> b155.exe
                        [DETECTION] Is the TR/BHO.bhg Trojan
                        [NOTE] The file was moved to '491fd050.qua'!
                        F:\sauvegarde portable toshiba\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\ZRRYUJOE\mrofinu[1].zip
                        [0] Archive type: ZIP
                        --> mrofinu.exe
                        [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
                        [NOTE] The file was moved to '4929d097.qua'!
                        F:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP223\A0081345.exe
                        [DETECTION] Contains recognition pattern of the WORM/RJUMP.D worm
                        [NOTE] The file was moved to '48ead05e.qua'!
                        F:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP224\A0081368.exe
                        [DETECTION] Contains recognition pattern of the WORM/RJUMP.D worm
                        [NOTE] The file was moved to '48ead062.qua'!
                        F:\System Volume Information\_restore{A13C7A4E-F5F7-4C03-A681-969D661F2F13}\RP244\A0013528.exe
                        [DETECTION] Contains recognition pattern of the WORM/RJUMP.D worm
                        [NOTE] The file was moved to '48ead066.qua'!
                        F:\System Volume Information\_restore{A13C7A4E-F5F7-4C03-A681-969D661F2F13}\RP244\A0013536.exe
                        [DETECTION] Contains recognition pattern of the WORM/RJUMP.D worm
                        [NOTE] The file was moved to '48ead069.qua'!
                        F:\System Volume Information\_restore{A13C7A4E-F5F7-4C03-A681-969D661F2F13}\RP306\A0015349.exe
                        [DETECTION] Contains recognition pattern of the WORM/RJUMP.D worm
                        [NOTE] The file was moved to '48ead06c.qua'!
                        F:\System Volume Information\_restore{A13C7A4E-F5F7-4C03-A681-969D661F2F13}\RP306\A0015354.exe
                        [DETECTION] Contains recognition pattern of the WORM/RJUMP.D worm
                        [NOTE] The file was moved to '48ead06f.qua'!
                        F:\System Volume Information\_restore{A13C7A4E-F5F7-4C03-A681-969D661F2F13}\RP306\A0015363.exe
                        [DETECTION] Contains recognition pattern of the WORM/RJUMP.D worm
                        [NOTE] The file was moved to '48ead073.qua'!
                        Begin scan in 'G:\' <My Passport>
                        G:\$RECYCLE.BIN\$RNTE3LQ\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\ZRRYUJOE\mrofinu[1].zip
                        [0] Archive type: ZIP
                        --> mrofinu.exe
                        [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
                        [NOTE] The file was moved to '4929d0cb.qua'!
                        G:\$RECYCLE.BIN\$RNTE3LQ\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\XTKMGVTV\93e4c2046fcb4ac4bdc3dbbcc28127fb[1].zip
                        [0] Archive type: ZIP
                        --> b155.exe
                        [DETECTION] Is the TR/BHO.bhg Trojan
                        [NOTE] The file was moved to '491fd093.qua'!
                        G:\$RECYCLE.BIN\$RNTE3LQ\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\NQKVR10T\488aede55160e40e3d5988951bfacaca[1].zip
                        [0] Archive type: ZIP
                        --> b999.exe
                        [DETECTION] Is the TR/Agent.CZF Trojan
                        [NOTE] The file was moved to '48f2d0b1.qua'!
                        G:\$RECYCLE.BIN\$RNTE3LQ\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\LBRVX1OE\wv[1].exe
                        [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
                        [NOTE] The file was moved to '4915d0fa.qua'!
                        G:\$RECYCLE.BIN\$RNTE3LQ\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\FX08GRRN\8154ff2675af1b6e0677560871425153[1].zip
                        [0] Archive type: ZIP
                        --> b138.exe
                        [DETECTION] Is the TR/Agent.11264.K Trojan
                        [NOTE] The file was moved to '48efd0c9.qua'!
                        G:\$RECYCLE.BIN\$RNTE3LQ\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\BGDPV84O\dummy[1].exe
                        [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
                        [NOTE] The file was moved to '4927d124.qua'!
                        G:\$RECYCLE.BIN\$RNTE3LQ\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\BGDPV84O\mrofinu[1].zip
                        [0] Archive type: ZIP
                        --> mrofinu.exe
                        [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
                        [NOTE] The file was moved to '4929d128.qua'!
                        G:\$RECYCLE.BIN\$RNTE3LQ\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\A8X9VRFJ\sruninstaller.prod.v12000.11jan2008.exe[1].1ac39aea6b22cdb4e6ed0c75f1d83467
                        [DETECTION] Is the TR/Agent.52736.K Trojan
                        [NOTE] The file was moved to '492fd135.qua'!
                        G:\$RECYCLE.BIN\$RNTE3LQ\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\8W6LRE2L\17PHolmes[1].cmt
                        [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
                        [NOTE] The file was moved to '490ad0fd.qua'!
                        G:\$RECYCLE.BIN\$RNTE3LQ\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\8W6LRE2L\wv[1].exe
                        [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
                        [NOTE] The file was moved to '4915d143.qua'!
                        G:\$RECYCLE.BIN\$RNTE3LQ\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\6YJ9T3TF\b433b5a80d2cb00f8f1c54387f9aa332[1].zip
                        [0] Archive type: ZIP
                        --> b157.exe
                        [DETECTION] Is the TR/Dldr.Agent.jih.1 Trojan
                        [NOTE] The file was moved to '48edd106.qua'!
                        G:\$RECYCLE.BIN\$RNTE3LQ\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\6YJ9T3TF\mrofinu[1].zip
                        [0] Archive type: ZIP
                        --> mrofinu.exe
                        [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
                        [NOTE] The file was moved to '4929d148.qua'!
                        G:\$RECYCLE.BIN\$RNTE3LQ\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\6YJ9T3TF\mrofinu[2].zip
                        [0] Archive type: ZIP
                        --> mrofinu.exe
                        [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
                        [NOTE] The file was moved to '4929d14b.qua'!
                        G:\$RECYCLE.BIN\$RNTE3LQ\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\5EFT9YSE\f4d28682d186cc6beb75f106d133f489[1].zip
                        [0] Archive type: ZIP
                        --> b128.exe
                        [DETECTION] Is the TR/Dldr.Agent.ezc.1 Trojan
                        [NOTE] The file was moved to '491ed11b.qua'!

                        End of the scan: dimanche 31 août 2008 19:13
                        Used time: 46:26 Minute(s)

                        The scan has been done completely.

                        15320 Scanning directories
                        235275 Files were scanned
                        36 viruses and/or unwanted programs were found
                        0 Files were classified as suspicious:
                        0 files were deleted
                        0 files were repaired
                        36 files were moved to quarantine
                        0 files were renamed
                        2 Files cannot be scanned
                        235237 Files not concerned
                        1984 Archives were scanned
                        2 Warnings
                        36 Notes

                        -le dernier hijackthis:

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 19:14:31, on 31/08/2008
                        Platform: Windows Vista SP1 (WinNT 6.00.1905)
                        MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                        Boot mode: Normal

                        Running processes:
                        C:\Windows\system32\taskeng.exe
                        C:\Windows\system32\Dwm.exe
                        C:\Windows\Explorer.EXE
                        C:\Windows\RtHDVCpl.exe
                        C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
                        C:\Windows\System32\igfxtray.exe
                        C:\Windows\System32\hkcmd.exe
                        C:\Windows\System32\igfxpers.exe
                        C:\Windows\system32\igfxsrvc.exe
                        C:\Users\alain\AppData\Local\Temp\RtkBtMnt.exe
                        C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                        C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                        C:\Program Files\Apoint2K\Apoint.exe
                        C:\Acer\Empowering Technology\eAudio\eAudio.exe
                        C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                        C:\Windows\WindowsMobile\wmdSync.exe
                        C:\Program Files\Apoint2K\Apntex.exe
                        C:\Program Files\Windows Sidebar\sidebar.exe
                        C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                        C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
                        C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
                        C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
                        C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
                        C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                        C:\Program Files\Internet Explorer\ieuser.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                        C:\Windows\system32\DllHost.exe

                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                        R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                        O1 - Hosts: ::1 localhost
                        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                        O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
                        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                        O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                        O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
                        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                        O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                        O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                        O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                        O4 - HKLM\..\Run: [PLFSetL] C:\Windows\PLFSetL.exe
                        O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
                        O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
                        O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
                        O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
                        O4 - HKLM\..\Run: [eAudio] "C:\Acer\Empowering Technology\eAudio\eAudio.exe"
                        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                        O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
                        O4 - HKLM\..\Run: [Skytel] Skytel.exe
                        O4 - HKLM\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALuNotify.exe
                        O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
                        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                        O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                        O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                        O4 - HKUS\S-1-5-18\..\RunOnce: [] (User 'SYSTEM')
                        O4 - HKUS\.DEFAULT\..\RunOnce: [] (User 'Default user')
                        O4 - Global Startup: Empowering Technology Launcher.lnk = ?
                        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                        O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                        O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                        O13 - Gopher Prefix:
                        O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL eNetHook.dll
                        O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
                        O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                        O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                        O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
                        O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
                        O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
                        O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                        O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
                        O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                        O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
                        O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
                        O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                        0
                        1. alors, après avoir suivi tes conseils, voici:

                          -le rapport antivir:

                          Avira AntiVir Personal
                          Report file date: dimanche 31 août 2008 18:26

                          Scanning for 1585012 virus strains and unwanted programs.

                          Licensed to: Avira AntiVir PersonalEdition Classic
                          Serial number: 0000149996-ADJIE-0001
                          Platform: Windows Vista
                          Windows version: (Service Pack 1) [6.0.6001]
                          Boot mode: Normally booted
                          Username: SYSTEM
                          Computer name: PC-DE-ALAIN

                          Version information:
                          BUILD.DAT : 8.1.0.331 16934 Bytes 12/08/2008 11:46:00
                          AVSCAN.EXE : 8.1.4.7 315649 Bytes 26/06/2008 08:57:53
                          AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 07:56:40
                          LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 12:44:19
                          LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 07:58:52
                          ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 10:33:34
                          ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 24/06/2008 13:54:15
                          ANTIVIR2.VDF : 7.0.6.94 2998784 Bytes 31/08/2008 16:24:58
                          ANTIVIR3.VDF : 7.0.6.95 2048 Bytes 31/08/2008 16:24:59
                          Engineversion : 8.1.1.23
                          AEVDF.DLL : 8.1.0.5 102772 Bytes 25/02/2008 09:58:21
                          AESCRIPT.DLL : 8.1.0.68 315770 Bytes 31/08/2008 16:25:13
                          AESCN.DLL : 8.1.0.23 119156 Bytes 10/07/2008 12:44:49
                          AERDL.DLL : 8.1.0.20 418165 Bytes 24/04/2008 12:37:48
                          AEPACK.DLL : 8.1.2.1 364917 Bytes 15/07/2008 12:58:35
                          AEOFFICE.DLL : 8.1.0.22 192890 Bytes 31/08/2008 16:25:11
                          AEHEUR.DLL : 8.1.0.50 1388918 Bytes 31/08/2008 16:25:09
                          AEHELP.DLL : 8.1.0.15 115063 Bytes 10/07/2008 12:44:48
                          AEGEN.DLL : 8.1.0.36 315764 Bytes 31/08/2008 16:25:01
                          AEEMU.DLL : 8.1.0.7 430452 Bytes 31/07/2008 08:33:21
                          AECORE.DLL : 8.1.1.8 172406 Bytes 31/07/2008 08:33:21
                          AEBB.DLL : 8.1.0.1 53617 Bytes 10/07/2008 12:44:48
                          AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 08:40:05
                          AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 09:28:01
                          AVREP.DLL : 8.0.0.2 98344 Bytes 31/08/2008 16:24:59
                          AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 11:26:40
                          AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
                          AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 12:27:49
                          SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
                          SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 12:49:40
                          NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
                          RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 13:48:07
                          RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 13:34:37

                          Configuration settings for the scan:
                          Jobname..........................: Complete system scan
                          Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
                          Logging..........................: low
                          Primary action...................: interactive
                          Secondary action.................: ignore
                          Scan master boot sector..........: on
                          Scan boot sector.................: on
                          Boot sectors.....................: C:, D:, F:, G:,
                          Process scan.....................: on
                          Scan registry....................: on
                          Search for rootkits..............: off
                          Scan all files...................: Intelligent file selection
                          Scan archives....................: on
                          Recursion depth..................: 20
                          Smart extensions.................: on
                          Macro heuristic..................: on
                          File heuristic...................: medium

                          Start of the scan: dimanche 31 août 2008 18:26

                          The scan of running processes will be started
                          Scan process 'avscan.exe' - '1' Module(s) have been scanned
                          Scan process 'mobsync.exe' - '1' Module(s) have been scanned
                          Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                          Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                          Scan process 'avguard.exe' - '1' Module(s) have been scanned
                          Scan process 'sched.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'VSSVC.exe' - '1' Module(s) have been scanned
                          Scan process 'hpqste08.exe' - '1' Module(s) have been scanned
                          Scan process 'eRAgent.exe' - '1' Module(s) have been scanned
                          Scan process 'Acer.Empowering.Framework.Supervisor.ex' - '1' Module(s) have been scanned
                          Scan process 'ePower_DMC.exe' - '1' Module(s) have been scanned
                          Scan process 'infocard.exe' - '1' Module(s) have been scanned
                          Scan process 'eNMTray.exe' - '1' Module(s) have been scanned
                          Scan process 'hpqtra08.exe' - '1' Module(s) have been scanned
                          Scan process 'sidebar.exe' - '1' Module(s) have been scanned
                          Scan process 'igfxsrvc.exe' - '1' Module(s) have been scanned
                          Scan process 'igfxext.exe' - '1' Module(s) have been scanned
                          Scan process 'ApntEx.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'ApMsgFwd.exe' - '1' Module(s) have been scanned
                          Scan process 'wmdSync.exe' - '1' Module(s) have been scanned
                          Scan process 'hpwuSchd2.exe' - '1' Module(s) have been scanned
                          Scan process 'eAudio.exe' - '1' Module(s) have been scanned
                          Scan process 'Apoint.exe' - '1' Module(s) have been scanned
                          Scan process 'IAAnotif.exe' - '1' Module(s) have been scanned
                          Scan process 'LManager.exe' - '1' Module(s) have been scanned
                          Scan process 'unsecapp.exe' - '1' Module(s) have been scanned
                          Scan process 'WmiPrvSE.exe' - '1' Module(s) have been scanned
                          Scan process 'WmiPrvSE.exe' - '1' Module(s) have been scanned
                          Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned
                          Scan process 'WLLoginProxy.exe' - '1' Module(s) have been scanned
                          Scan process 'iexplore.exe' - '1' Module(s) have been scanned
                          Scan process 'ieuser.exe' - '1' Module(s) have been scanned
                          Scan process 'ePowerSvc.exe' - '1' Module(s) have been scanned
                          Scan process 'capuserv.exe' - '1' Module(s) have been scanned
                          Scan process 'eRecoveryService.exe' - '1' Module(s) have been scanned
                          Scan process 'XAudio.exe' - '1' Module(s) have been scanned
                          Scan process 'RtkBtMnt.exe' - '1' Module(s) have been scanned
                          Scan process 'igfxsrvc.exe' - '1' Module(s) have been scanned
                          Scan process 'SearchIndexer.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'taskeng.exe' - '1' Module(s) have been scanned
                          Scan process 'igfxpers.exe' - '1' Module(s) have been scanned
                          Scan process 'hkcmd.exe' - '1' Module(s) have been scanned
                          Scan process 'igfxtray.exe' - '1' Module(s) have been scanned
                          Scan process 'MobilityService.exe' - '1' Module(s) have been scanned
                          Scan process 'eDSLoader.exe' - '1' Module(s) have been scanned
                          Scan process 'LSSrvc.exe' - '1' Module(s) have been scanned
                          Scan process 'RtHDVCpl.exe' - '1' Module(s) have been scanned
                          Scan process 'IAANTmon.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'eNet Service.exe' - '1' Module(s) have been scanned
                          Scan process 'eLockServ.exe' - '1' Module(s) have been scanned
                          Scan process 'explorer.exe' - '1' Module(s) have been scanned
                          Scan process 'eDSService.exe' - '1' Module(s) have been scanned
                          Scan process 'dwm.exe' - '1' Module(s) have been scanned
                          Scan process 'taskeng.exe' - '1' Module(s) have been scanned
                          Scan process 'ALaunchSvc.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'SLsvc.exe' - '1' Module(s) have been scanned
                          Scan process 'audiodg.exe' - '0' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                          Scan process 'lsm.exe' - '1' Module(s) have been scanned
                          Scan process 'lsass.exe' - '1' Module(s) have been scanned
                          Scan process 'services.exe' - '1' Module(s) have been scanned
                          Scan process 'csrss.exe' - '1' Module(s) have been scanned
                          Scan process 'wininit.exe' - '1' Module(s) have been scanned
                          Scan process 'csrss.exe' - '1' Module(s) have been scanned
                          Scan process 'smss.exe' - '1' Module(s) have been scanned
                          81 processes with 81 modules were scanned

                          Starting master boot sector scan:
                          Master boot sector HD0
                          [INFO] No virus was found!
                          Master boot sector HD1
                          [INFO] No virus was found!
                          Master boot sector HD2
                          [INFO] No virus was found!

                          Start scanning boot sectors:
                          Boot sector 'C:\'
                          [INFO] No virus was found!
                          Boot sector 'D:\'
                          [INFO] No virus was found!
                          Boot sector 'F:\'
                          [INFO] No virus was found!
                          Boot sector 'G:\'
                          [INFO] No virus was found!

                          Starting to scan the registry.
                          The registry was scanned ( '51' files ).

                          Starting the file scan:

                          Begin scan in 'C:\' <ACER>
                          C:\hiberfil.sys
                          [WARNING] The file could not be opened!
                          C:\pagefile.sys
                          [WARNING] The file could not be opened!
                          C:\Users\alain\AppData\Local\VirtualStore\Windows\System32\phc9rjj0etfv.bmp
                          [DETECTION] Is the TR/Fakealert.AAF Trojan
                          [NOTE] The file was moved to '491dc9fa.qua'!
                          Begin scan in 'D:\' <DATA>
                          Begin scan in 'F:\' <EXTERNE>
                          F:\sauvegarde portable toshiba\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\5EFT9YSE\f4d28682d186cc6beb75f106d133f489[1].zip
                          [0] Archive type: ZIP
                          --> b128.exe
                          [DETECTION] Is the TR/Dldr.Agent.ezc.1 Trojan
                          [NOTE] The file was moved to '491ecfe9.qua'!
                          F:\sauvegarde portable toshiba\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\6YJ9T3TF\b433b5a80d2cb00f8f1c54387f9aa332[1].zip
                          [0] Archive type: ZIP
                          --> b157.exe
                          [DETECTION] Is the TR/Dldr.Agent.jih.1 Trojan
                          [NOTE] The file was moved to '48edcff7.qua'!
                          F:\sauvegarde portable toshiba\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\6YJ9T3TF\mrofinu[1].zip
                          [0] Archive type: ZIP
                          --> mrofinu.exe
                          [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
                          [NOTE] The file was moved to '4929d03a.qua'!
                          F:\sauvegarde portable toshiba\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\6YJ9T3TF\mrofinu[2].zip
                          [0] Archive type: ZIP
                          --> mrofinu.exe
                          [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
                          [NOTE] The file was moved to '4929d03d.qua'!
                          F:\sauvegarde portable toshiba\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\8W6LRE2L\17PHolmes[1].cmt
                          [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
                          [NOTE] The file was moved to '490ad007.qua'!
                          F:\sauvegarde portable toshiba\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\8W6LRE2L\wv[1].exe
                          [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
                          [NOTE] The file was moved to '4915d04c.qua'!
                          F:\sauvegarde portable toshiba\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\A8X9VRFJ\sruninstaller.prod.v12000.11jan2008.exe[1].1ac39aea6b22cdb4e6ed0c75f1d83467
                          [DETECTION] Is the TR/Agent.52736.K Trojan
                          [NOTE] The file was moved to '492fd04f.qua'!
                          F:\sauvegarde portable toshiba\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\BGDPV84O\dummy[1].exe
                          [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
                          [NOTE] The file was moved to '4927d05a.qua'!
                          F:\sauvegarde portable toshiba\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\BGDPV84O\mrofinu[1].zip
                          [0] Archive type: ZIP
                          --> mrofinu.exe
                          [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
                          [NOTE] The file was moved to '4929d05c.qua'!
                          F:\sauvegarde portable toshiba\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\FX08GRRN\8154ff2675af1b6e0677560871425153[1].zip
                          [0] Archive type: ZIP
                          --> b138.exe
                          [DETECTION] Is the TR/Agent.11264.K Trojan
                          [NOTE] The file was moved to '48efd028.qua'!
                          F:\sauvegarde portable toshiba\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\LBRVX1OE\wv[1].exe
                          [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
                          [NOTE] The file was moved to '4915d07d.qua'!
                          F:\sauvegarde portable toshiba\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\NQKVR10T\488aede55160e40e3d5988951bfacaca[1].zip
                          [0] Archive type: ZIP
                          --> b999.exe
                          [DETECTION] Is the TR/Agent.CZF Trojan
                          [NOTE] The file was moved to '48f2d043.qua'!
                          F:\sauvegarde portable toshiba\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\XTKMGVTV\93e4c2046fcb4ac4bdc3dbbcc28127fb[1].zip
                          [0] Archive type: ZIP
                          --> b155.exe
                          [DETECTION] Is the TR/BHO.bhg Trojan
                          [NOTE] The file was moved to '491fd050.qua'!
                          F:\sauvegarde portable toshiba\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\ZRRYUJOE\mrofinu[1].zip
                          [0] Archive type: ZIP
                          --> mrofinu.exe
                          [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
                          [NOTE] The file was moved to '4929d097.qua'!
                          F:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP223\A0081345.exe
                          [DETECTION] Contains recognition pattern of the WORM/RJUMP.D worm
                          [NOTE] The file was moved to '48ead05e.qua'!
                          F:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP224\A0081368.exe
                          [DETECTION] Contains recognition pattern of the WORM/RJUMP.D worm
                          [NOTE] The file was moved to '48ead062.qua'!
                          F:\System Volume Information\_restore{A13C7A4E-F5F7-4C03-A681-969D661F2F13}\RP244\A0013528.exe
                          [DETECTION] Contains recognition pattern of the WORM/RJUMP.D worm
                          [NOTE] The file was moved to '48ead066.qua'!
                          F:\System Volume Information\_restore{A13C7A4E-F5F7-4C03-A681-969D661F2F13}\RP244\A0013536.exe
                          [DETECTION] Contains recognition pattern of the WORM/RJUMP.D worm
                          [NOTE] The file was moved to '48ead069.qua'!
                          F:\System Volume Information\_restore{A13C7A4E-F5F7-4C03-A681-969D661F2F13}\RP306\A0015349.exe
                          [DETECTION] Contains recognition pattern of the WORM/RJUMP.D worm
                          [NOTE] The file was moved to '48ead06c.qua'!
                          F:\System Volume Information\_restore{A13C7A4E-F5F7-4C03-A681-969D661F2F13}\RP306\A0015354.exe
                          [DETECTION] Contains recognition pattern of the WORM/RJUMP.D worm
                          [NOTE] The file was moved to '48ead06f.qua'!
                          F:\System Volume Information\_restore{A13C7A4E-F5F7-4C03-A681-969D661F2F13}\RP306\A0015363.exe
                          [DETECTION] Contains recognition pattern of the WORM/RJUMP.D worm
                          [NOTE] The file was moved to '48ead073.qua'!
                          Begin scan in 'G:\' <My Passport>
                          G:\$RECYCLE.BIN\$RNTE3LQ\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\ZRRYUJOE\mrofinu[1].zip
                          [0] Archive type: ZIP
                          --> mrofinu.exe
                          [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
                          [NOTE] The file was moved to '4929d0cb.qua'!
                          G:\$RECYCLE.BIN\$RNTE3LQ\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\XTKMGVTV\93e4c2046fcb4ac4bdc3dbbcc28127fb[1].zip
                          [0] Archive type: ZIP
                          --> b155.exe
                          [DETECTION] Is the TR/BHO.bhg Trojan
                          [NOTE] The file was moved to '491fd093.qua'!
                          G:\$RECYCLE.BIN\$RNTE3LQ\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\NQKVR10T\488aede55160e40e3d5988951bfacaca[1].zip
                          [0] Archive type: ZIP
                          --> b999.exe
                          [DETECTION] Is the TR/Agent.CZF Trojan
                          [NOTE] The file was moved to '48f2d0b1.qua'!
                          G:\$RECYCLE.BIN\$RNTE3LQ\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\LBRVX1OE\wv[1].exe
                          [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
                          [NOTE] The file was moved to '4915d0fa.qua'!
                          G:\$RECYCLE.BIN\$RNTE3LQ\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\FX08GRRN\8154ff2675af1b6e0677560871425153[1].zip
                          [0] Archive type: ZIP
                          --> b138.exe
                          [DETECTION] Is the TR/Agent.11264.K Trojan
                          [NOTE] The file was moved to '48efd0c9.qua'!
                          G:\$RECYCLE.BIN\$RNTE3LQ\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\BGDPV84O\dummy[1].exe
                          [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
                          [NOTE] The file was moved to '4927d124.qua'!
                          G:\$RECYCLE.BIN\$RNTE3LQ\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\BGDPV84O\mrofinu[1].zip
                          [0] Archive type: ZIP
                          --> mrofinu.exe
                          [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
                          [NOTE] The file was moved to '4929d128.qua'!
                          G:\$RECYCLE.BIN\$RNTE3LQ\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\A8X9VRFJ\sruninstaller.prod.v12000.11jan2008.exe[1].1ac39aea6b22cdb4e6ed0c75f1d83467
                          [DETECTION] Is the TR/Agent.52736.K Trojan
                          [NOTE] The file was moved to '492fd135.qua'!
                          G:\$RECYCLE.BIN\$RNTE3LQ\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\8W6LRE2L\17PHolmes[1].cmt
                          [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
                          [NOTE] The file was moved to '490ad0fd.qua'!
                          G:\$RECYCLE.BIN\$RNTE3LQ\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\8W6LRE2L\wv[1].exe
                          [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
                          [NOTE] The file was moved to '4915d143.qua'!
                          G:\$RECYCLE.BIN\$RNTE3LQ\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\6YJ9T3TF\b433b5a80d2cb00f8f1c54387f9aa332[1].zip
                          [0] Archive type: ZIP
                          --> b157.exe
                          [DETECTION] Is the TR/Dldr.Agent.jih.1 Trojan
                          [NOTE] The file was moved to '48edd106.qua'!
                          G:\$RECYCLE.BIN\$RNTE3LQ\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\6YJ9T3TF\mrofinu[1].zip
                          [0] Archive type: ZIP
                          --> mrofinu.exe
                          [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
                          [NOTE] The file was moved to '4929d148.qua'!
                          G:\$RECYCLE.BIN\$RNTE3LQ\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\6YJ9T3TF\mrofinu[2].zip
                          [0] Archive type: ZIP
                          --> mrofinu.exe
                          [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
                          [NOTE] The file was moved to '4929d14b.qua'!
                          G:\$RECYCLE.BIN\$RNTE3LQ\alain suissa\Local Settings\Temporary Internet Files\Content.IE5\5EFT9YSE\f4d28682d186cc6beb75f106d133f489[1].zip
                          [0] Archive type: ZIP
                          --> b128.exe
                          [DETECTION] Is the TR/Dldr.Agent.ezc.1 Trojan
                          [NOTE] The file was moved to '491ed11b.qua'!

                          End of the scan: dimanche 31 août 2008 19:13
                          Used time: 46:26 Minute(s)

                          The scan has been done completely.

                          15320 Scanning directories
                          235275 Files were scanned
                          36 viruses and/or unwanted programs were found
                          0 Files were classified as suspicious:
                          0 files were deleted
                          0 files were repaired
                          36 files were moved to quarantine
                          0 files were renamed
                          2 Files cannot be scanned
                          235237 Files not concerned
                          1984 Archives were scanned
                          2 Warnings
                          36 Notes

                          -le dernier hijackthis:

                          Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 19:14:31, on 31/08/2008
                          Platform: Windows Vista SP1 (WinNT 6.00.1905)
                          MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                          Boot mode: Normal

                          Running processes:
                          C:\Windows\system32\taskeng.exe
                          C:\Windows\system32\Dwm.exe
                          C:\Windows\Explorer.EXE
                          C:\Windows\RtHDVCpl.exe
                          C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
                          C:\Windows\System32\igfxtray.exe
                          C:\Windows\System32\hkcmd.exe
                          C:\Windows\System32\igfxpers.exe
                          C:\Windows\system32\igfxsrvc.exe
                          C:\Users\alain\AppData\Local\Temp\RtkBtMnt.exe
                          C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                          C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                          C:\Program Files\Apoint2K\Apoint.exe
                          C:\Acer\Empowering Technology\eAudio\eAudio.exe
                          C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                          C:\Windows\WindowsMobile\wmdSync.exe
                          C:\Program Files\Apoint2K\Apntex.exe
                          C:\Program Files\Windows Sidebar\sidebar.exe
                          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                          C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
                          C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
                          C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
                          C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
                          C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                          C:\Program Files\Internet Explorer\ieuser.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                          C:\Windows\system32\DllHost.exe

                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                          R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                          O1 - Hosts: ::1 localhost
                          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                          O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
                          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                          O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
                          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                          O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                          O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                          O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                          O4 - HKLM\..\Run: [PLFSetL] C:\Windows\PLFSetL.exe
                          O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
                          O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
                          O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
                          O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
                          O4 - HKLM\..\Run: [eAudio] "C:\Acer\Empowering Technology\eAudio\eAudio.exe"
                          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                          O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
                          O4 - HKLM\..\Run: [Skytel] Skytel.exe
                          O4 - HKLM\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALuNotify.exe
                          O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
                          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                          O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                          O4 - HKUS\S-1-5-18\..\RunOnce: [] (User 'SYSTEM')
                          O4 - HKUS\.DEFAULT\..\RunOnce: [] (User 'Default user')
                          O4 - Global Startup: Empowering Technology Launcher.lnk = ?
                          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                          O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                          O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                          O13 - Gopher Prefix:
                          O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL eNetHook.dll
                          O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
                          O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                          O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                          O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
                          O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
                          O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
                          O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                          O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
                          O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                          O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
                          O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
                          O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                          0
                          1. Ok,
                            alors :
                            (Antivir est en anglais, mais très simple d'utilisation, tu vas voir).

                            Pour chacun des deux produits utilise les liens ci-dessous :
                            Avast : https://www.avast.com/fr-fr/uninstall-utility
                            Norton : http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/fr_docid/20050414110429924

                            Ensuite,
                            > Essaye d'installer Antivir : : ouvre ce lien, lis le tuto, télécharge Antivir et installe le
                            - Tu peux aussi télécharger Antivir ICI.
                            - Lance Antivir, fais les mises à jours, branche tous ton matériel de stockage sur le PC, puis lance un scan (si des virus sont découverts, mets les en quarantaine. Si tu ne peux pas alors supprime les).
                            - A la fin du scan clique sur 'report', enregistre ce rapport sur le bureau (fichier => enregistrer sous), puis fait un copier/coller de ce rapport dans ton prochain message.

                            > Relance ton PC

                            > Dis-moi les résultats....et si ton PC vas mieux...

                            Poste aussi un dernier rapport HiJackT stp.

                            A+
                            0
                            1. je te fais confiance: moi j'y connais rien. Norton c'est une version que j'ai eu gratuitement, d'emblée, avec l'ordinateur.

                              Comment faire pour virer les 2 et prendre antivir?
                              0
                              1. Pourras tu me dire ce qu'il est utile que je garde dans tous les logiciels que tu m'as fait télécharger. Et ce que je peux désinstaller? merci bcp
                                0
                                1. Ok,
                                  alors tu as toujours deux antivirus qui tournent sur ta machine : Norton et Avast.

                                  Lequel souhaites-tu garder ? (Norton tu le payes ?)

                                  Perso, je te conseille de changer pour Antivir qui est gratuit et plus performant que ces deux là.

                                  dis-moi car pour la désinstallation il y a une manip. spéciale.

                                  A+
                                  0
                                  1. J'ai trouvé:

                                    Logfile of Trend Micro HijackThis v2.0.2
                                    Scan saved at 17:36:30, on 31/08/2008
                                    Platform: Windows Vista SP1 (WinNT 6.00.1905)
                                    MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                                    Boot mode: Normal

                                    Running processes:
                                    C:\Windows\system32\Dwm.exe
                                    C:\Windows\Explorer.EXE
                                    C:\Windows\system32\taskeng.exe
                                    C:\Windows\RtHDVCpl.exe
                                    C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
                                    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                                    C:\Windows\System32\igfxtray.exe
                                    C:\Windows\system32\igfxsrvc.exe
                                    C:\Windows\System32\hkcmd.exe
                                    C:\Windows\System32\igfxpers.exe
                                    C:\Users\alain\AppData\Local\Temp\RtkBtMnt.exe
                                    C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                                    C:\Program Files\Apoint2K\Apoint.exe
                                    C:\Acer\Empowering Technology\eAudio\eAudio.exe
                                    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                    C:\Program Files\Picasa2\PicasaMediaDetector.exe
                                    C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                                    C:\Windows\WindowsMobile\wmdSync.exe
                                    C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                                    C:\Program Files\Windows Sidebar\sidebar.exe
                                    C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                    C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
                                    C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
                                    C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
                                    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                    C:\Program Files\Apoint2K\Apntex.exe
                                    C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
                                    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                                    C:\Program Files\Internet Explorer\ieuser.exe
                                    C:\Program Files\Internet Explorer\iexplore.exe
                                    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                                    C:\Windows\system32\Macromed\Flash\FlashUtil9b.exe
                                    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                                    C:\Windows\system32\DllHost.exe

                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                    O1 - Hosts: ::1 localhost
                                    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                    O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
                                    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                                    O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
                                    O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
                                    O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                                    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                                    O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
                                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                                    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
                                    O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                                    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                                    O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                                    O4 - HKLM\..\Run: [PLFSetL] C:\Windows\PLFSetL.exe
                                    O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
                                    O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
                                    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
                                    O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
                                    O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
                                    O4 - HKLM\..\Run: [eAudio] "C:\Acer\Empowering Technology\eAudio\eAudio.exe"
                                    O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                                    O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
                                    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                    O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
                                    O4 - HKLM\..\Run: [Skytel] Skytel.exe
                                    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                                    O4 - HKLM\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALuNotify.exe
                                    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                    O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
                                    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                                    O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                                    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                                    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                                    O4 - HKUS\S-1-5-18\..\RunOnce: [] (User 'SYSTEM')
                                    O4 - HKUS\.DEFAULT\..\RunOnce: [] (User 'Default user')
                                    O4 - Global Startup: Empowering Technology Launcher.lnk = ?
                                    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                                    O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                                    O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                                    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                                    O13 - Gopher Prefix:
                                    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL eNetHook.dll
                                    O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
                                    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
                                    O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
                                    O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
                                    O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
                                    O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                                    O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
                                    O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                                    O23 - Service: Validation de mot de passe Symantec IS (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
                                    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                                    O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                                    O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
                                    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                                    O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
                                    O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
                                    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                                    0
                                    1. Bon,
                                      alors :
                                      > Télécharge Zeb-Restore : http://telechargement.zebulon.fr/zeb-restore.html
                                      - Mets le dans un dossier, sur ton bureau par exemple.
                                      - Lance Zebrestore et coche la/les case(s) suivante(s) :

                                      Sites de confiance et sensibles
                                      Préfixes et Protocoles Internet
                                      Réinitialiser Fichier Hosts


                                      - Ne coche que la/les case(s) indiquée(s).
                                      - Clique sur le bouton Restaurer.
                                      - Quitte le programme.

                                      Puis réessaye HiJackT stp.

                                      A+
                                      0
                                      1. le probleme c'est que quand je fais "do a scan and save a logfile" ils me mettent: "for some reasons, your system denied right acces ti the host files. if any hijacked domains are in this file, hijackthis may not be able to fix it.
                                        0
                                        • 1
                                        • 2