Publicité intempestive

Bonjour,

Mon PC a un léger souci : il est envahi par de la publicité intempestive. Mais, ce ne sont pas des "pop-up classiques". En effet, toutes les fenêtes sont intitulées "CiD : [nom du site]" (à noter : ce ne sont que des sites que l'on utilise qui arrivent en pub, comme ça... laredoute, surcouf, orange... et c'est pour ça que j'hésite à les bloquer) et j'ai remarqué que depuis que j'ai ça, mon navigateur met un moment avant de s'ouvrir pour la première fois (comme si il se préparait à me lancer des pubs jusqu'à ce que j'arrête le PC).

Enfin, tant que je ne lance pas Internet, il n'y a pas de problème ; mais une fois que c'est fait, ça n'arrête plus.

Grand merci d'avance pour votre aide !
Configuration: Windows XP
Internet Explorer 7.0

42 réponses

Résumé de la discussion

Des utilisateurs rencontrent une infestation publicitaire sur Windows XP et Internet Explorer 7, avec des fenêtres affichant CiD : [nom du site] et un ralentissement du navigateur après connexion. Plusieurs solutions techniques sont proposées, notamment nettoyer le système avec HijackThis et CCleaner, désactiver le service LiveUpdate et lancer en mode sans échec avec Ad-fix puis générer des rapports pour analyse. D'autres retours décrivent l'utilisation de GenProc, des scans plus approfondis et la purge des entrées Run, des tâches planifiées et des cookies suspects, avec des résultats variables et un rappel à partager les rapports.

Bobot (l’IA à votre service)
  1. par contre je n'arrive pas à changer le statut du topic pour le mettre en "problème résolu"... parce que je n'ai pas la petite case à cocher ! enfin, si un modérateur passe par là, il le fera !
    0
    1. Contributeur sécurité
      ;-)
      -1
  2. je n'ai pas tout lu... je le ferai dès que possible mais en tout cas merci pour tout :)
    0
    1. Contributeur sécurité
      De rien ... =)

      A+
      -1
  3. Contributeur sécurité
    Salut,

    impec ...

    Prb résolu donc :
    http://www.commentcamarche.net/faq/sujet 11365 mettre son poste en probleme resolu

    Content d'avoir pu te rendre service ... ^^

    potasses ceci :

    Des informations intéressantes pour toi et ton PC :

    => Comportement à adopter avec son PC : http://assiste.com.free.fr/p/abc/a/safe_cex.html
    et pourquoi ( exemple ) : http://assiste.com.free.fr/p/abc/a/zombies_et_botnets.html

    => Surveillance :
    Effectue des scan réguliers de surveillance (une fois tous les 15 jours, par exemple) avec ton antivirus puis avec ton anti-spyware (après les avoir mis à jour bien sur !) et supprime ce qu'ils peuvent trouver (où mets en quarantaine, en pensant à la vider ultérieurement).

    Pourquoi ? Pour éviter de se retrouver dans ce genre de situation par exemple ( peu commune mais ...) :
    -> http://secubox.aldria.com/topic-2373.html

    =============================================================

    => Il faut mettre a jour la console Java régulièrement aussi :

    Rends toi sur https://www.java.com/fr/download/manual.jsp et télécharge la dernière version (si ta version actuelle n'est pas à jour) ou ici https://filehippo.com/download_jre_32/?ex=CORE-116.0
    Après avoir installé la dernière version, désinstalle les anciennes versions (de Java) afin d’éliminer les failles de sécurité présentes dans ces anciennes versions.
    via Démarrer / Paramètres / Panneau de config / et dans Ajout/Suppression de programmes navigue jusqu'aux anciennes versions de la console Java qui s'y trouvent, puis clique sur « Supprimer », suis les invites de commandes dans la boite de dialogue qui va s'ouvrir afin d'amener la désinstallation à son terme.
    Fais cela pour chacune d'elles, une à une, fais redémarrer ton PC quand cela te sera demandé .
    Retourne ensuite chez Java ci-dessus et clique sur le bouton "Vérifier l'installation" pour t'assurer que tout est en ordre.

    =============================================================

    => Afin d’éviter les autres failles de sécurité des différents programmes présents sur ton PC :

    Vérifie tes mises à jours des différents softs régulièrement ici et mets à jour ce qui ne l’est pas. https://www.flexera.com/products/operations/software-vulnerability-management.html
    -Tuto https://www.malekal.com/tester-la-vulnerabilite-de-son-systeme-2/
    -Autre possibilité, t'abonner gratuitement a "la lettre hebdomadaire de secuser.com" ici http://www.secuser.com/ a gauche en bas de page.

    ===========================================================
    * le pare- feu de Xp vaut rien , je te conseille fortement dans installer un :
    Armor ou Comodo sont très bien ( en anglais mais gratuit )...Tu trouveras tout ce qu'il faut ici :
    http://www.commentcamarche.net/telecharger/logiciel 38 firewall

    tutos :
    https://www.malekal.com/tutorial-online-armor-free/
    https://www.malekal.com/tutorial-comodo-firewall/

    En deuxieme choix ( gratuit aussi ) :
    ->Comodo ancienne version 2.4 ( en francais ) :
    http://download.comodo.com/cpf/download/setups/release/languages/CFP_Setup_English_French_2.4.16.174.exe
    tuto: https://infomars.fr/forum/index.php?s=908072e48ff7cf0359366440cb26c93f&showtopic=389

    ->PC Tools Firewall Plus (en français) :
    https://fr.norton.com/
    Tuto : http://www.6ma.fr/tuto/utilisation-pc-tools-firewall-plus/

    (Note: pensez bien à désactiver le pare-feu de Windows avant de lancer l'installe de tout autre pare-feu !)

    * tests firewall: http://www.matousec.com/index.html

    => Un complément au pare-feu pour fermer les ports risqués (dangereux, s’ils restent ouverts) :

    ZebProtect (application ne nécessitant pas d’installation à lancer et paramétrer une unique fois) http://telechargement.zebulon.fr/123.html

    -Tuto https://www.zebulon.fr/dossiers/autres/40-zebprotect.html

    ================================================================

    --> Tutorial pour sécuriser Firefox ( si tu utilises ce navigateur ) :
    https://forum.zebulon.fr/topic/69628-s%C3%A9curiser-un-peu-plus-firefox/

    =================================================================
    => Rappel sur les principales causes d'infection :

    * L'utilisation de cracks ou keygens est à proscrire, de même que le surf sur les sites de téléchargement de ceux-ci :

    Les dangers des cracks : http://forum.malekal.com/ftopic893.php

    ->Le crack dans toute sa splendeur, journal d'une infection attendue :
    https://forum.zebulon.fr/topic/93281-pr%C3%A9vention-le-crack-dans-toute-sa-splendeur/

    ->autre exemple en image , où comment s'infiltre une infection par un pseudo crack :
    http://secuboxlabs.fr/archives/computertoday.html

    * Le P2P ( l'utilisation de logiciels comme eMule, Sharazaa, LimeWire, Bit torrent):

    Les conséquences du P2P : https://forum.zebulon.fr/topic/85544-pr%C3%A9vention-le-p2p-et-ses-cons%C3%A9quences/

    Pourquoi éviter le P2P :
    > http://www.libellules.ch/...
    > http://www.speedweb1.org/forum-tesgaz/viewtopic.php?t=1793
    > https://lexpansion.lexpress.fr/actualite-economique/

    * Faire attention avec les ActiveX :
    http://assiste.com.free.fr/p/abc/a/activex_dangers.html
    et comment :
    http://assiste.com.free.fr/p/abc/c/anti_activex.html

    * Prévention sur deux autres types d'infection d'actualité :

    MSN prévention :
    https://forum.zebulon.fr/topic/130590-infection-par-msn-ou-wlm/
    -> autre danger grandissant , le " phishing " (= hameçonnage ) :
    http://msnfix.changelog.fr/index.php/2008/05/18/32-alerte

    Infection par supports amovibles (clefs usb, flash, DD externes ..) :
    https://forum.zebulon.fr/topic/131959-infections-par-supports-amovibles/
    https://forum.malekal.com/viewtopic.php?f=45&t=5544

    =================================================================
    ( merci le sioux )

    Voili,voilou ...

    Bonne continuation à toi ... =)

    A+

    -1
    1. alors j'ai tout fait : je pense que c'est bon :))
      0
      1. Contributeur sécurité
        pas mal de bugs sur le cite ce soir ... :-/

        Penses a supprimer les versions antérieur de Java ( toute celle que tu as hors mis la jre1.6.0_07 bien sûr ) via panneau de config / "ajout et suppression de prg" ...

        Dans l'ordre :

        1- Vas dans "Démarrer" > "accessoire" > "executer" > tu tapes : services.msc

        Cliques droit sur le service cité -> Planificateur LiveUpdate automatique
        ->vas sur propriétés .
        ->et dans "type de démarrage" : mets le sur « désactivé ».
        ->Ensuite si le "Status du service" est sur "Démarré", faire : « arrêté »
        ->valides la modif ...

        Tutorial : https://www.zebulon.fr/dossiers/windows/31-services.html

        2- Fermes toutes tes applications et déconnectes toi .

        Relances Hijackthis mais click sur " Do a scan only "
        Tu vois donc apparaitre le résultat du scan : une multitudes de lignes ,chacunes précédées d'un carré vide .
        Tu vas cliquer sur les carrés des lignes suivantes :

        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        
        O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot 
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime 
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" 
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" 
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe 
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL') 
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        
        O16 - DPF: STS Secure Viewer - http://83.206.149.125:8080/pmasweb//tools/pviewersetup.cab  
        O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game09.zylom.com/activex/zylomgamesplayer.cab
        
        O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)


        Tu cliques en bas sur le bouton FIX CHECKED et valides .

        Si et seulement si tu n'as plus de soucis avec le PC , fais la suite :

        3-Déconnectes toi et fermes bien toutes tes applications en cours .

        Lances Toolscleaner2 .
        *Cliques sur Recherche et laisses le scan se terminer (cela peut être long).
        *Cliques sur Suppression pour finaliser.
        *Tu peux, si tu le souhaites, te servir des Options facultatives
        *Cliques sur "quitter" pour générer un rapport ( et pas sur la croix rouge !) :
        ---> Postes ce rapport : il se trouve à la racine de ton disque dur -> C:\TCleaner.txt .

        Note : Ce petit soft va te nettoyer tout les trucs dont on c'est servi pour la désinfection ( tu n'en as plus besion ! ) .
        Supprimes tout les outils , dossiers ou rapports consernant la désinfection que Toolscleaner2 n'a pas supprimé .

        Puis enfin supprimes Toolscleaner2 ...

        4- Refais un coup de CCleaner ( registre compris )

        5- Purge de la restauration système
        *Désactives ta restauration :
        Cliques droit sur poste de travail/propriétés/Restauration système/coche la case désactiver la restauration, appliquer, OK
        --->Redémarres ton PC
        *Réactives ta restauration :
        Cliques droit sur poste de travail/propriétés/Restauration système/décoche la case désactiver la restauration, appliquer, OK
        --->Redémarres ton PC
        ( Note : tu peux aussi y accéder via panneau de configuration->" système "->" restauration système " ).

        --> une fois terminé, dis moi ce que cela a donné ... =)
        0
        1. Si je l'avais fait, mais contrairement à aujourd'hui, hier quand je cliquais sur "mettre à jour maintenant" il n'y a rien qui se passait... pourtant j'ai cliqué plusieurs fois !

          en tout cas, maintenant c'est fait :)

          et le rapport hijackthis :

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 20:53:16, on 16/09/2008
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16705)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\ehome\ehtray.exe
          C:\WINDOWS\RTHDCPL.EXE
          C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
          C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
          C:\Program Files\QuickTime\qttask.exe
          C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
          C:\Program Files\Fichiers communs\Real\Update_OB\RealOneMessageCenter.exe
          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
          C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
          C:\Program Files\TomTom HOME 2\HOMERunner.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
          C:\WINDOWS\arservice.exe
          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
          C:\WINDOWS\eHome\ehRecvr.exe
          C:\WINDOWS\eHome\ehSched.exe
          C:\WINDOWS\system32\ezNTSvc.exe
          C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
          C:\WINDOWS\system32\nvsvc32.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\dllhost.exe
          C:\WINDOWS\eHome\ehmsas.exe
          C:\HP\KBD\KBD.EXE
          c:\windows\system\hpsysdrv.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\Program Files\internet explorer\iexplore.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
          C:\WINDOWS\SoftwareDistribution\Download\24af2a69c06a4de03e35dc89d706475f\update\update.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\WINDOWS\system32\msiexec.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://fr.search.yahoo.com/?fr=cb-hp06
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.wikipedia.org/wiki/Accueil
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://fr.search.yahoo.com/?fr=cb-hp06
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
          R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxybiblio.hec.fr:8080
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
          O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
          O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
          O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
          O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
          O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
          O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
          O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
          O4 - HKLM\..\Run: [MsgCenterExe] "C:\Program Files\Fichiers communs\Real\Update_OB\RealOneMessageCenter.exe" -osboot
          O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
          O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          O8 - Extra context menu item: Add to AMV Converter... - C:\Program Files\MP3 Player Utilities 4.05\AMVConverter\grab.html
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
          O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.05\MediaManager\grab.html
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
          O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
          O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
          O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: STS Secure Viewer - http://83.206.149.125:8080/pmasweb//tools/pviewersetup.cab
          O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20070501/qtinstall.info.apple.com/qtactivex/qtplugin.cab
          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
          O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.can.com.sg/mwf/mgaxctrl.cab
          O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game09.zylom.com/activex/zylomgamesplayer.cab
          O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
          O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
          O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
          O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
          O23 - Service: EasyBits Magic Desktop Services for Windows NT (ezntsvc) - EasyBits Software Corp. - C:\WINDOWS\system32\ezNTSvc.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
          O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
          0
          1. Contributeur sécurité
            Re,

            tu n'as pas mis à jours la Console Java ... Il faut absolument le faire ! ...

            ->Mets à jours ce qui suit, c'est important ( des versions pas à jours = failles de sécurité ) :
            * pour la console Java :
            aller sur : Démarrer > Panneau de configuration > Icône Java > onglet Mise à jour > "Mettre à jour maintenant" > cocher la case "Automatiser la détection des mises à jour".
            ( puis désinstalles les versions antérieurs via "paneau de configuration" et "ajout/suppression de prg" ...)
            -> si tu ne trouves pas l' icône Java :
            Désinstalles les version antérieurs, puis télécharges et installes la dernière version ici :
            http://www.commentcamarche.net/telecharger/telecharger 34055318 java runtime environment

            --> Une fois fait, repostes moi un dernier hijackthis de contrôle et attends la suite ....
            0
            1. le rapport hijackthis :

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 19:41:57, on 16/09/2008
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16705)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\ehome\ehtray.exe
              C:\WINDOWS\RTHDCPL.EXE
              C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
              C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
              C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
              C:\Program Files\QuickTime\qttask.exe
              C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
              C:\Program Files\Fichiers communs\Real\Update_OB\RealOneMessageCenter.exe
              C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
              C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
              C:\Program Files\TomTom HOME 2\HOMERunner.exe
              C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
              C:\WINDOWS\arservice.exe
              C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
              C:\WINDOWS\eHome\ehRecvr.exe
              C:\WINDOWS\eHome\ehSched.exe
              C:\WINDOWS\system32\ezNTSvc.exe
              C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
              C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
              C:\WINDOWS\system32\nvsvc32.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\dllhost.exe
              C:\WINDOWS\eHome\ehmsas.exe
              C:\HP\KBD\KBD.EXE
              c:\windows\system\hpsysdrv.exe
              C:\Program Files\internet explorer\iexplore.exe
              C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://fr.search.yahoo.com/?fr=cb-hp06
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.wikipedia.org/wiki/Accueil
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://fr.search.yahoo.com/?fr=cb-hp06
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
              R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxybiblio.hec.fr:8080
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
              O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
              O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
              O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
              O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
              O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
              O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
              O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
              O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
              O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
              O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
              O4 - HKLM\..\Run: [MsgCenterExe] "C:\Program Files\Fichiers communs\Real\Update_OB\RealOneMessageCenter.exe" -osboot
              O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
              O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
              O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
              O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
              O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
              O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
              O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
              O8 - Extra context menu item: Add to AMV Converter... - C:\Program Files\MP3 Player Utilities 4.05\AMVConverter\grab.html
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
              O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.05\MediaManager\grab.html
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
              O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
              O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
              O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
              O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
              O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O16 - DPF: STS Secure Viewer - http://83.206.149.125:8080/pmasweb//tools/pviewersetup.cab
              O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20070501/qtinstall.info.apple.com/qtactivex/qtplugin.cab
              O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
              O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.can.com.sg/mwf/mgaxctrl.cab
              O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game09.zylom.com/activex/zylomgamesplayer.cab
              O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
              O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
              O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
              O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
              O23 - Service: EasyBits Magic Desktop Services for Windows NT (ezntsvc) - EasyBits Software Corp. - C:\WINDOWS\system32\ezNTSvc.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
              O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
              O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
              0
              1. Euh... pour combofix il me met "windows ne trouve pas combofix. veuillez vérifier que vous avez bien rentré le nom et recommencez"
                0
                1. Contributeur sécurité
                  Supprimes le manuellement ( directe à la poubelle ) .

                  et passes à la suite ....
                  0
              2. Contributeur sécurité
                bien ... Rapport vierge ^^

                1-Vas sur "démarrer" / cliques sur la commande "Exécuter" :

                Là tu tapes ou copies/colles exactement ce qui est en gras :

                sc stop Planificateur LiveUpdate automatique ---> puis tapes sur [Entrée]

                Ensuite recommences avec ceci :
                sc delete Planificateur LiveUpdate automatique ---> puis tapes sur [Entrée]

                Puis avec ceci :
                ComboFix /u ---> puis tapes sur [Entrée]

                2- Mets à jours ce qui suit, c'est important ( des versions pas à jours = failles de sécurité ) :
                * pour la console Java :
                aller sur : Démarrer > Panneau de configuration > Icône Java > onglet Mise à jour > "Mettre à jour maintenant" > cocher la case "Automatiser la détection des mises à jour".
                ( puis désinstalles les versions antérieurs via "paneau de configuration" et "ajout/suppression de prg" ...)
                -> si tu ne trouves pas l' icône Java :
                Désinstalles les version antérieurs, puis télécharges et installes la dernière version ici :
                http://www.commentcamarche.net/telecharger/telecharger 34055318 java runtime environment

                * Adobe Reader :
                télécharges et installes la dernière version ici (désinstalles avant l'ancienne version via son propre prg de désinstallation):
                http://www.commentcamarche.net/telecharger/telecharger 27 acrobat reader

                3- Refais un dernier scan Hijackthis , postes le nouveau rapport et attends la suite ...
                0
                1. Et voilà le rapport de bitdefender :

                  BitDefender Online Scanner

                  Rapport d'analyse généré à: Mon, Sep 15, 2008 - 20:18:16

                  Voie d'analyse: C:\;D:\;E:\;F:\;G:\;H:\;I:\;

                  Statistiques

                  Temps
                  00:28:19

                  Fichiers
                  134303

                  Directoires
                  10346

                  Secteurs de boot
                  0

                  Archives
                  2388

                  Paquets programmes
                  14317

                  Résultats

                  Virus identifiés
                  0

                  Fichiers infectés
                  0

                  Fichiers suspects
                  0

                  Avertissements
                  0

                  Désinfectés
                  0

                  Fichiers effacés
                  0

                  Info sur les moteurs

                  Définition virus
                  1758662

                  Version des moteurs
                  AVCORE v1.7 (build 8314.19) (i386) (Sep 10 2008 19:37:42)

                  Analyse des plugins
                  16

                  Archive des plugins
                  43

                  Unpack des plugins
                  7

                  E-mail plugins
                  6

                  Système plugins
                  4

                  Paramètres d'analyse

                  Première action
                  Désinfecté

                  Seconde Action
                  Supprimé

                  Heuristique
                  Oui

                  Acceptez les avertissements
                  Oui

                  Extensions analysées
                  exe;com;dll;ocx;scr;bin;dat;386;vxd;sys;wdm;cla;class;ovl;ole;hlp;doc;dot;xls;ppt;wbk;wiz;pot;ppa;xla;xlt;vbs;vbe;mdb;rtf;htm;hta;html;xml;xtp;php;asp;js;shs;chm;lnk;pif;prc;url;smm;pfd;msi;ini;csc;cmd;bas;

                  Excludez les extensions

                  Analyse d'emails
                  Oui

                  Analyse des Archives
                  Oui

                  Analyser paquets programmes
                  Oui

                  Analyse des fichiers
                  Oui

                  Analyse de boot
                  Oui

                  Fichier analysé
                  Statut

                  Aucun virus trouvé.
                  0
                  1. Contributeur sécurité
                    Salut,

                    à tout' avec le rapport de Bitdefender ... ;)
                    0
                    1. Excuse-moi pour le retard : j'ai pas trop eu accès à mon pc ce week-end !

                      Voilà le rapport ToolsCleaner :
                      [ Rapport ToolsCleaner version 2.2.3 (par A.Rothstein & dj QUIOU) ]

                      -->- Recherche:

                      C:\Combofix.txt: trouvé !
                      C:\lopR.txt: trouvé !
                      C:\TB.txt: trouvé !
                      C:\Ad-Fix.txt: trouvé !
                      C:\Lop SD: trouvé !
                      C:\Qoobox: trouvé !
                      C:\_OtMoveIt: trouvé !
                      C:\Toolbar SD: trouvé !
                      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
                      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
                      C:\Documents and Settings\HP_Administrateur\Bureau\GenProc.zip: trouvé !
                      C:\Documents and Settings\HP_Administrateur\Bureau\OtMoveIt2.exe: trouvé !
                      C:\Documents and Settings\HP_Administrateur\Bureau\GenProc: trouvé !
                      C:\Documents and Settings\HP_Administrateur\Bureau\Ad-Fix: trouvé !
                      C:\Program Files\Trend Micro\HijackThis: trouvé !
                      C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !

                      ---------------------------------
                      -->- Suppression:

                      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
                      C:\Documents and Settings\HP_Administrateur\Bureau\GenProc.zip: supprimé !
                      C:\Documents and Settings\HP_Administrateur\Bureau\OtMoveIt2.exe: supprimé !
                      C:\Combofix.txt: supprimé !
                      C:\lopR.txt: supprimé !
                      C:\TB.txt: supprimé !
                      C:\Ad-Fix.txt: supprimé !
                      C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
                      C:\Lop SD: supprimé !
                      C:\Qoobox: supprimé !
                      C:\_OtMoveIt: supprimé !
                      C:\Toolbar SD: supprimé !
                      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
                      C:\Documents and Settings\HP_Administrateur\Bureau\GenProc: supprimé !
                      C:\Documents and Settings\HP_Administrateur\Bureau\Ad-Fix: supprimé !
                      C:\Program Files\Trend Micro\HijackThis: supprimé !

                      Et BitDefender est en train de tourner...
                      0
                      1. Contributeur sécurité
                        Bien ... c'est plutot bon signe ... ^^

                        Dans l'ordre :

                        1-Télécharges ToolsCleaner (de A.Rothstein) sur ton Bureau.
                        http://pc-system.fr/

                        Déconnectes toi et fermes bien toutes tes applications en cours .

                        Lances le .
                        *Cliques sur Recherche et laisses le scan se terminer (cela peut être long).
                        *Cliques sur Suppression pour finaliser.
                        *Tu peux, si tu le souhaites, te servir des Options facultatives
                        *Click sur "quitter" pour générer un rapport :
                        ---> Postes le (TCleaner.txt), il se trouve à la racine de ton disque dur (C:\).

                        Note : Ce petit soft va te nettoyer tout les trucs dont on c'est servi pour la désinfection .
                        Supprimes tout les outils , dossiers ou rapports consernant la désinfection que Toolscleaner2 n'a pas supprimé .

                        ( gardes CCleaner et Malwarebytes : très utiles ! )

                        2- Refais un coup de CCleaner ( registre compris ) .

                        3- Retélécharges et réinstalles hijackthis ( car supprimé par Toolscleaner2 ) ,

                        Télécharges et installes le logiciel HijackThis :

                        ici ftp://ftp.commentcamarche.com/download/HJTInstall.exe
                        ou ici http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe
                        ou ici https://www.clubic.com/telecharger-fiche17891-hijackthis.html

                        -> Cliques sur le setup pour lancer l'installe : laisses toi guider et ne modifies pas les paramètres d'installation .
                        A la fin de l'installe , le prg ce lance automatiquement : fermes le en cliquant sur la croix rouge .
                        Au final, tu dois avoir un raccourci sur ton bureau et aussi un cheminement comme :
                        "C:\ program files\Trend Micro\HijackThis\HijackThis.exe " .

                        ( ne fais pas de scan pour le momment )

                        4- Purge de la restauration système
                        *Désactives ta restauration :
                        Cliques droit sur poste de travail/propriétés/Restauration système/coche la case désactiver la restauration, appliquer, OK
                        --->Redémarres ton PC
                        *Réactives ta restauration :
                        Cliques droit sur poste de travail/propriétés/Restauration système/décoche la case désactiver la restauration, appliquer, OK
                        --->Redémarres ton PC

                        5- Fais ce scan en ligne pour vérifier :

                        Fais un scan antivirus en ligne, avec Internet Explorer et accepter l'ActiveX :

                        https://www.bitdefender.fr/

                        * Aide : En bas, à gauche de la fenêtre, clique sur BitDefender SCAN ONLINE
                        Dans la nouvelle fenêtre, clique sur j’accepte .
                        La fenêtre change encore, clique sur scanner .
                        Les signatures se chargent, etc ...

                        * pour le rapport : cliques sur l'onglet "plus de détailles" . A la fin du scan, cliques sur " problème détectés " .
                        -> juste au dessus à droite de la fenêtre des résultats , tu as " cliquer ici pour exporter le rapport " .
                        ->Cliques dessus et choisis d'enregistrer le rapport sur ton bureau .

                        --> Ouvres le document html que tu viens de sauvegarder ( le rapport ),
                        fais un copier/coller de tout son contenu et postes le dans ta prochaine réponse ...

                        Rappel : le scan en ligne ne fonctionne que sous Internet Exploreur ! ( et pas sur FireFox ou autres navigateurs )

                        Tutoriel en images ici :
                        http://perso.orange.fr/rginformatique/section%20virus/defender.htm (merci à Balltrap34 pour cette réalisation)
                        Et ici : http://www.commentcamarche.net/faq/sujet 8872 scanner en ligne avec bitdefender
                        0
                        1. le rapport de genproc :

                          GenProc 2.025 [1] 11/09/2008 - Windows [XP] : Aucune infection caractéristique trouvée
                          0
                          1. Contributeur sécurité
                            bien ...

                            1- refais un coup de ccleaner (registre compris ) .

                            2- Télécharges GenProc (de Jean-Chretien1 et Narco4) sur ton bureau (et pas ailleur !) :
                            http://www.alt-shift-return.org/Info/Fichiers/GenProc.zip

                            !!Déconnectes toi et fermes tes application en cours !!

                            Dézippes (=extraire tout) le contenu de ce que tu viens de télécharger sur ton bureau .

                            Ouvres le dossier Genproc :
                            double-cliques sur GenProc.bat et laisses faire ...

                            Une fois terminé, postes le contenu du rapport qui s'ouvre ...

                            Aide en images ici : http://www.alt-shift-return.org/Info/GenProc-HowTo.html
                            IMPORTANT : postes le rapport et ne fait rien d'autre pour l'instant ( souvant il faut ajouter des consignes à la manipe indiquée pour que cela fonctionne parfaitement ) .

                            0
                            1. le rapport moveit :

                              C:\windows\System32\restart.exe moved successfully.
                              C:\Documents and Settings\Invité\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML moved successfully.

                              OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 09102008_214147
                              0
                              1. le mode sans échec ne marche toujours pas...

                                voici le rapport de safeboot repair au cas où ça puisse t'éclairer :

                                Reg export of SafeBoot key after repair:
                                ========================

                                Windows Registry Editor Version 5.00

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot]
                                "AlternateShell"="cmd.exe"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal]

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\AppMgmt]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\AVG Anti-Spyware Driver]
                                @="Driver"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\AVG Anti-Spyware Guard]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Base]
                                @="Driver Group"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Boot Bus Extender]
                                @="Driver Group"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Boot file system]
                                @="Driver Group"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\CryptSvc]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\DcomLaunch]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmadmin]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmboot.sys]
                                @="Driver"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmio.sys]
                                @="Driver"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmload.sys]
                                @="Driver"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmserver]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\EventLog]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\File system]
                                @="Driver Group"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Filter]
                                @="Driver Group"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\HelpSvc]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Netlogon]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\PCI Configuration]
                                @="Driver Group"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\PlugPlay]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\PNP Filter]
                                @="Driver Group"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Primary disk]
                                @="Driver Group"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\PSEXESVC]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\RpcSs]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\SCSI Class]
                                @="Driver Group"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\sermouse.sys]
                                @="Driver"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\sr.sys]
                                @="FSFilter System Recovery"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\SRService]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\System Bus Extender]
                                @="Driver Group"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\vga.sys]
                                @="Driver"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\vgasave.sys]
                                @="Driver"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\WinMgmt]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}]
                                @="Universal Serial Bus controllers"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}]
                                @="CD-ROM Drive"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
                                @="DiskDrive"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}]
                                @="Standard floppy disk controller"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
                                @="Hdc"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
                                @="Keyboard"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
                                @="Mouse"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}]
                                @="PCMCIA Adapters"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
                                @="SCSIAdapter"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
                                @="System"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}]
                                @="Floppy disk drive"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
                                @="Volume"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
                                @="Human Interface Devices"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network]

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\AFD]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\AppMgmt]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\AVG Anti-Spyware Driver]
                                @="Driver"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\AVG Anti-Spyware Guard]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Base]
                                @="Driver Group"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Boot Bus Extender]
                                @="Driver Group"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Boot file system]
                                @="Driver Group"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Browser]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\CryptSvc]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\DcomLaunch]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Dhcp]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmadmin]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmboot.sys]
                                @="Driver"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmio.sys]
                                @="Driver"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmload.sys]
                                @="Driver"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmserver]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\DnsCache]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\EventLog]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\File system]
                                @="Driver Group"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Filter]
                                @="Driver Group"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\HelpSvc]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\ip6fw.sys]
                                @="Driver"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\ipnat.sys]
                                @="Driver"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\LanmanServer]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\LanmanWorkstation]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\LmHosts]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Messenger]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NDIS]
                                @="Driver Group"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NDIS Wrapper]
                                @="Driver Group"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Ndisuio]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetBIOS]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetBIOSGroup]
                                @="Driver Group"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetBT]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetDDEGroup]
                                @="Driver Group"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Netlogon]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetMan]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Network]
                                @="Driver Group"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetworkProvider]
                                @="Driver Group"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NtLmSsp]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PCI Configuration]
                                @="Driver Group"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PlugPlay]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PNP Filter]
                                @="Driver Group"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PNP_TDI]
                                @="Driver Group"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Primary disk]
                                @="Driver Group"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PSEXESVC]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdpcdd.sys]
                                @="Driver"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdpdd.sys]
                                @="Driver"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdpwd.sys]
                                @="Driver"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdsessmgr]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\RpcSs]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\SCSI Class]
                                @="Driver Group"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\sermouse.sys]
                                @="Driver"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\SharedAccess]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\sr.sys]
                                @="FSFilter System Recovery"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\SRService]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Streams Drivers]
                                @="Driver Group"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\System Bus Extender]
                                @="Driver Group"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Tcpip]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\TDI]
                                @="Driver Group"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\tdpipe.sys]
                                @="Driver"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\tdtcp.sys]
                                @="Driver"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\termservice]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\vga.sys]
                                @="Driver"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\vgasave.sys]
                                @="Driver"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\WinMgmt]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\WZCSVC]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{36FC9E60-C465-11CF-8056-444553540000}]
                                @="Universal Serial Bus controllers"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E965-E325-11CE-BFC1-08002BE10318}]
                                @="CD-ROM Drive"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}]
                                @="DiskDrive"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E969-E325-11CE-BFC1-08002BE10318}]
                                @="Standard floppy disk controller"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
                                @="Hdc"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
                                @="Keyboard"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
                                @="Mouse"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}]
                                @="Net"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E973-E325-11CE-BFC1-08002BE10318}]
                                @="NetClient"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E974-E325-11CE-BFC1-08002BE10318}]
                                @="NetService"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}]
                                @="NetTrans"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E977-E325-11CE-BFC1-08002BE10318}]
                                @="PCMCIA Adapters"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
                                @="SCSIAdapter"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
                                @="System"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E980-E325-11CE-BFC1-08002BE10318}]
                                @="Floppy disk drive"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
                                @="Volume"

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
                                @="Human Interface Devices"

                                ========================

                                HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver
                                HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard
                                HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\PSEXESVC
                                0
                                • 1
                                • 2
                                • 3