Virus spyware insupprimable !!

Bonjour,
je voulais voir une série en streaming je suis tombé sur un site hasardeux, et j'ai cliqué sur éxécuter les plug in... j'ai donc choppé un virus et maintenant j'ai des pop up qui m'envoi sur des sites d'antivirus j'ai une alerte dans la barre des taches en bas, un triangle qui clignote, parfois il me dis pb mémoire 49% disc 37% ou un truc du genre et des fois trojan il me semble, alors j'ai lancé ad aware, et depuis j'ai toujours ce souci, j'ai télécharger hijackthis, et j'aurai besoin d'aide pour comprendre le rapport et m'aider a supprimer ce virus... Merci beaucoup
Configuration: Windows Vista
Internet Explorer 7.0

66 réponses

Résumé de la discussion

Une visite d'un site de streaming non sécurisé a entraîné l'infection par un malware, avec des pop-ups redirigeant vers des antivirus, des alertes dans la barre des tâches et des messages évoquant trojan ou mémoire. Pour remédier à la situation, il est recommandé d'exécuter Malwarebytes' Anti-Malware (MBAM) et d'effectuer un examen complet, puis de supprimer ou mettre en quarantaine les éléments détectés et de partager le rapport. En cas de détection, suivre les instructions proposées par MBAM et fermer les navigateurs; puis relancer les outils RSIT et HijackThis et communiquer les rapports pour analyse complémentaire. Certains éléments résiduels peuvent persister dans les clés de registre ou les mécanismes de démarrage et nécessiter une vérification manuelle des autoruns après le nettoyage.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Salut, tu ignores l'alerte tout simplement ou mieux, tu désactive AntiVir le temps de la manipe ... ^^

    c'est normal :
    "process.exe", un composant de l'outil, est détecté par certains antivirus comme étant un "RiskTool". Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité.

    donc fais la manipe que je t'ai donné ... destrio5 attends les résultats ^^
    0
    1. j'ai un souci, en fait j'ai voulu faire ce que tu m'avais dis mais la j'ai un gros doute, en fait j'ai antivir qui me dit que smitfraudfix est un virus... donc je suis un peu réticent en ce qui concerne sont utilisation en nettoyage... que dois je faire
      0
      1. Contributeur sécurité
        Salut,

        pour avancer Destrio5 ...

        1- Suite de la manipe ( nettoyage ), fais exactement ce qui suit :

        Impératif : Démarrer en mode sans echec .

        /!\ Ne jamais démarrer en mode sans échec via MSCONFIG /!\

        Comment aller en Mode sans échec :
        1) Redémarres ton ordi .
        2) Tapotes la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip" .
        3) Tu tapotes jusqu' à l'apparition de l'écran avec les options de démarrage .
        4) Choisis la première option : Sans Échec , et valides en tapant sur [Entrée] .
        5) Choisis ton compte habituel ( et pas Administrateur ).
        attention : pas de connexion possible en mode sans échec , donc copies ou imprimes bien la manipe pour éviter les erreurs ...

        * Double-cliques sur SmitfraudFix.exe

        * Sélectionnes 2 et presses "Entrée" dans le menu pour supprimer les fichiers responsables de l'infection.

        --> Si besion :

        * A la question: Voulez-vous nettoyer le registre ? répondre O (oui) et presser Entrée afin de débloquer le fond d'écran et supprimer les clés de registre de l'infection.

        ( Le correctif déterminera si le fichier wininet.dll est infecté.)

        * A la question: "Corriger le fichier infecté ?" répondre O (oui) et presser Entrée
        pour remplacer le fichier corrompu.

        * Un redémarrage sera demandé pour terminer la procédure de nettoyage .
        Si le redémarrage ne se fais pas , fais le manuellement ( c'est important ) .

        Le rapport se trouve à la racine de disque dur C .
        ( dans le fichier C:\rapport.txt )

        Postes ce dernier rapport pour analyse ....

        2- refais un scan RSIT, postes le nouveau rapport "log.txt" et attends la suite ... ( avec Desrio5 ;) ).

        0
        1. j'attend tes conseils pour la suite...
          0
          1. SmitFraudFix v2.376

            Scan done at 19:29:08,43, 20/11/2008
            Run from C:\Users\thomas\Desktop\SmitfraudFix
            OS: Microsoft Windows [version 6.0.6001] - Windows_NT
            The filesystem type is NTFS
            Fix run in normal mode

            »»»»»»»»»»»»»»»»»»»»»»»» Process

            C:\Windows\system32\csrss.exe
            C:\Windows\SYSTEM32\wininit.exe
            C:\Windows\system32\csrss.exe
            C:\Windows\system32\services.exe
            C:\Windows\system32\lsass.exe
            C:\Windows\system32\lsm.exe
            C:\Windows\SYSTEM32\winlogon.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\Ati2evxx.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\Ati2evxx.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\SLsvc.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
            C:\Windows\system32\WLANExt.exe
            C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
            C:\Program Files\ATK Hotkey\ASLDRSrv.exe
            C:\Program Files\ATKGFNEX\GFNEXSrv.exe
            C:\Windows\System32\spoolsv.exe
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\Dwm.exe
            C:\Windows\Explorer.EXE
            C:\Windows\SYSTEM32\taskeng.exe
            C:\Program Files\ASUS\ASUS Live Update\ALU.exe
            C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
            C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
            C:\Windows\RtHDVCpl.exe
            C:\Program Files\ASUS\ATK Media\DMedia.exe
            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            C:\Windows\ASScrPro.exe
            C:\Program Files\Common Files\Real\Update_OB\realsched.exe
            C:\Program Files\iTunes\iTunesHelper.exe
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
            C:\Program Files\Windows Sidebar\sidebar.exe
            C:\Program Files\Windows Live\Messenger\msnmsgr.exe
            C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
            C:\Windows\ehome\ehtray.exe
            C:\Program Files\Windows Media Player\wmpnscfg.exe
            C:\Program Files\OLYMPUS\m-trip\Bin\m-tripLauncher.exe
            C:\Windows\ehome\ehmsas.exe
            C:\Program Files\ATK Hotkey\Hcontrol.exe
            C:\Program Files\ATKOSD2\ATKOSD2.exe
            C:\Program Files\Wireless Console 2\wcourier.exe
            C:\Program Files\ASUS\Splendid\ACMON.exe
            C:\Program Files\P4G\BatteryLife.exe
            C:\Windows\System32\ACEngSvr.exe
            C:\Program Files\ATK Hotkey\ATKOSD.exe
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
            C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            C:\Program Files\Dassault Systemes\B11\intel_a\code\bin\CATSysDemon.exe
            C:\Program Files\Bonjour\mDNSResponder.exe
            C:\Windows\system32\svchost.exe
            C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
            C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
            C:\Windows\System32\MrobeService.exe
            C:\Windows\system32\svchost.exe
            C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
            C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\SearchIndexer.exe
            C:\Windows\SYSTEM32\taskeng.exe
            C:\Program Files\Windows Media Player\wmpnetwk.exe
            C:\Program Files\iPod\bin\iPodService.exe
            C:\Windows\system32\wbem\wmiprvse.exe
            C:\Windows\system32\wbem\unsecapp.exe
            C:\Program Files\Windows Live\Messenger\usnsvc.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Windows\system32\SearchProtocolHost.exe
            C:\Windows\system32\SearchFilterHost.exe
            C:\Windows\system32\cmd.exe
            C:\Windows\system32\conime.exe
            C:\Windows\system32\wbem\wmiprvse.exe

            »»»»»»»»»»»»»»»»»»»»»»»» hosts

            »»»»»»»»»»»»»»»»»»»»»»»» C:\

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\thomas

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\thomas\AppData\Local\Temp

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\thomas\Application Data

            »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

            C:\Users\thomas\AppData\Roaming\MICROS~1\Windows\STARTM~1\SMS TRAP.url FOUND !
            C:\Users\thomas\AppData\Roaming\MICROS~1\Windows\STARTM~1\VIP Casino.url FOUND !

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\thomas\FAVORI~1

            C:\Users\thomas\FAVORI~1\SMS TRAP.url FOUND !

            »»»»»»»»»»»»»»»»»»»»»»»» Desktop

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

            C:\Program Files\Google\googletoolbar1.dll FOUND !

            »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

            »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

            »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
            !!!Attention, following keys are not inevitably infected!!!

            o4Patch
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
            !!!Attention, following keys are not inevitably infected!!!

            IEDFix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» VACFix
            !!!Attention, following keys are not inevitably infected!!!

            VACFix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
            !!!Attention, following keys are not inevitably infected!!!

            404Fix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
            !!!Attention, following keys are not inevitably infected!!!

            SrchSTS.exe by S!Ri
            Search SharedTaskScheduler's .dll

            »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
            !!!Attention, following keys are not inevitably infected!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
            "AppInit_DLLs"=""
            "LoadAppInit_DLLs"=dword:00000000

            »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
            !!!Attention, following keys are not inevitably infected!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
            "Userinit"="C:\\Windows\\system32\\userinit.exe,"

            »»»»»»»»»»»»»»»»»»»»»»»» RK

            »»»»»»»»»»»»»»»»»»»»»»»» DNS

            Description: Attansic L1 Gigabit Ethernet 10/100/1000Base-T Controller
            DNS Server Search Order: 194.2.0.20
            DNS Server Search Order: 194.2.0.40

            HKLM\SYSTEM\CCS\Services\Tcpip\..\{1B21271B-0D47-4675-B03B-021025B8FA46}: NameServer=194.2.0.20,194.2.0.40
            HKLM\SYSTEM\CCS\Services\Tcpip\..\{880FBEAE-C8B8-4B32-8EB0-476BC458DA4A}: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS1\Services\Tcpip\..\{1B21271B-0D47-4675-B03B-021025B8FA46}: NameServer=194.2.0.20,194.2.0.40
            HKLM\SYSTEM\CS1\Services\Tcpip\..\{880FBEAE-C8B8-4B32-8EB0-476BC458DA4A}: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS3\Services\Tcpip\..\{1B21271B-0D47-4675-B03B-021025B8FA46}: NameServer=194.2.0.20,194.2.0.40
            HKLM\SYSTEM\CS3\Services\Tcpip\..\{880FBEAE-C8B8-4B32-8EB0-476BC458DA4A}: DhcpNameServer=192.168.1.1

            »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

            »»»»»»»»»»»»»»»»»»»»»»»» End
            0
            1. Modérateur
              Passe à la suite.
              0
              1. Pas de fichier texte ou alors je ne sais pas ou chercher...
                0
                1. Modérateur
                  Recommence UsbFix pour voir.
                  0
                  1. et donc je fais quoi ??
                    0
                    1. Modérateur
                      D'après ta liste, le rapport n'y figure pas.
                      0
                      1. je ne trouve pas le raport UsbFix.txt ? ou est il ? c'est quoi la racine moi la chui ds C j'ai plusieurs fichier texte mais aucun ne s'appel Usbfix
                        j'ai ad report
                        caavsteuplog
                        caisslog
                        cleannavi
                        devlist
                        finish
                        fixnavi
                        GA
                        lopR
                        RHDSetup ?
                        0
                        1. Modérateur
                          1/

                          ---> Supprime Lop S&D et le dossier Lop SD situé dans C:\.

                          2/

                          ---> Cherche le fichier suivant : C:\Program Files\trend micro\thomas.exe

                          ---> Clique droit dessus et choisis Exécuter en tant qu'administrateur.

                          ---> Choisis Do a system scan only.

                          ---> Coche les cases qui sont devant les lignes suivantes :

                          O2 - BHO: (no name) - {64466B8E-20A7-4A4A-AFF4-AAD9CA68B52C} - C:\Program Files\WebMediaViewer\hpmun.dll (file missing)

                          O2 - BHO: ZozyWin - {EFEA05D9-BCB2-4438-A4EB-BD467692C24F} - C:\Windows\system32\dzhoil.dll (file missing)

                          O4 - HKCU\..\Run: [ROAD DATA] "C:\ProgramData\Basefunkfunk.4wq9p"

                          O4 - HKCU\..\Run: [ciwsowu] c:\users\thomas\appdata\local\ciwsowu.exe ciwsowu

                          O4 - HKLM\..\Policies\Explorer\Run: [QuickTime Task] C:\Program Files\WebMediaViewer\qttask.exe

                          O9 - Extra button: (no name) - {3B8FB116-D358-48A3-A5C7-DB84F15CBB04} - http://www.ietoolexpress.com/redirect.php (file missing)

                          O9 - Extra 'Tools' menuitem: IExplorer Security - {3B8FB116-D358-48A3-A5C7-DB84F15CBB04} - http://www.ietoolexpress.com/redirect.php (file missing)

                          ---> Clique en bas sur Fix checked. Mets oui si HijackThis te demande quelque chose.

                          ---> Quitte HijackThis.

                          3/

                          --> Télécharge UsbFix (de Chiquitine29) sur ton Bureau :
                          http://sd-1.archive-host.com/membres/up/116615172019703188/UsbFix.exe

                          --> Lance l'installation avec les paramètres par défaut.

                          --> Branche tes sources de données externes à ton PC (clé USB, disque dur externe, etc...) sans les ouvrir.

                          --> Clique droit sur le raccourci UsbFix situé sur ton Bureau et choisis Exécuter en tant qu'administrateur.

                          --> Choisis l'option 1 (Nettoyage).

                          --> Le PC va redémarrer.

                          --> Après redémarrage, poste le rapport UsbFix.txt

                          Note : le rapport UsbFix.txt est sauvegardé à la racine du disque.

                          (Si le Bureau ne réapparait pas, presse Ctrl+Alt+Suppr, Onglet "Fichier", "Nouvelle tâche", tape explorer.exe et valide)

                          4/

                          - Télécharge SmitfraudFix (de de S!Ri, balltrap34 et moe31) sur ton Bureau.
                          http://siri.urz.free.fr/Fix/SmitfraudFix.exe

                          - Clique droit sur SmitfraudFix.exe et choisis Exécuter en tant qu'administrateur puis choisis l'option 1 puis Entrée.

                          - Un rapport sera généré, poste-le dans ta prochaine réponse.

                          [*] process.exe est détecté par certains antivirus comme étant un risktool. Il ne s'agit pas d'un virus mais d'un utilitaire destiné à mettre fin à des processus.[*]

                          ** Ne fais l'étape 2 que si on te le demande, on doit d'abord examiner le premier rapport de SmitfraudFix.
                          0
                          1. Modérateur
                            Je relis tout ce qu'on a fait et je dis la suite.
                            0
                            1. info.txt logfile of random's system information tool 1.04 2008-11-20 12:29:52

                              ======Uninstall list======

                              -->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
                              -->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
                              Ad-Aware-->MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
                              Adobe Flash Player ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
                              Adobe Flash Player Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
                              Adobe Reader 7.0.8 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A70800000002}
                              Apple Mobile Device Support-->MsiExec.exe /I{49C88E44-1B38-4FC6-824E-2BDA3063B0E3}
                              Apple Software Update-->MsiExec.exe /I{02DFF6B1-1654-411C-8D7B-FD6052EF016F}
                              Assistant de connexion Windows Live-->MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
                              ASUS Data Security Manager-->C:\Program Files\InstallShield Installation Information\{1C8521E5-5A7B-4A4E-A9CD-AD53116EAEE0}\SETUP.exe -runfromtemp -l0x0009 -removeonly
                              ASUS InstantFun-->MsiExec.exe /I{57B15AD4-8C9D-4164-82BB-E33D8644E757}
                              ASUS Live Update-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}\setup.exe" -l0x9
                              ASUS Splendid Video Enhancement Technology-->C:\Program Files\InstallShield Installation Information\{C0FC1C14-4824-4A73-87A6-9E888C9C3102}\SETUP.exe -runfromtemp -l0x0009 -removeonly
                              Asus_Camera_ScreenSaver-->"C:\Windows\ASUS Camera ScreenSaver Uninstaller.exe"
                              ATI Uninstaller-->C:\Program Files\ATI\CIM\Bin\Atisetup.exe -uninstall all
                              ATK Generic Function Service-->C:\Program Files\InstallShield Installation Information\{D3D54F3E-C5C3-443D-978F-87A72E5616E8}\SETUP.exe -runfromtemp -l0x0009 -removeonly
                              ATK Hotkey-->C:\Program Files\InstallShield Installation Information\{3912D529-02BC-4CA8-B5ED-0D0C20EB6003}\SETUP.exe -runfromtemp -l0x0009 -removeonly
                              ATK Media-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{139B0FFA-187E-4BA1-BCA6-6B56B2B6AB8C}\SETUP.EXE" -l0x9
                              ATKOSD2-->C:\Program Files\InstallShield Installation Information\{5C1DB4ED-E9B4-402D-BB14-D75D97D6C1A6}\SETUP.exe -runfromtemp -l0x0009 -removeonly
                              Attansic Ethernet Utility-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1F698102-5739-441E-96F0-74F4EA540F06}\SETUP.exe" -l0x9 -removeonly
                              Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
                              Bonjour-->MsiExec.exe /I{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}
                              ccc-Branding-->MsiExec.exe /I{6E32B134-CA8D-49DD-B94C-0DB155CE70B5}
                              CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
                              Ciel Devis Factures 6.0-->MsiExec.exe /I{F29DDAD0-447D-4BDB-80CB-4276B4D5C9A7}
                              Dassault Systemes Software B11-->"C:\Program Files\Dassault Systemes\B11\intel_a\code\bin\Uninstall.exe" "C:\Program Files\Dassault Systemes\B11" "CODE" "IS" "C:\WINDOWS\ISUN040C.EXE" "C:\Program Files\Dassault Systemes\B11\intel_a\Uninst.isu" "B11" "0"
                              DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
                              DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
                              DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
                              DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
                              Free Easy Burner V 3.8-->"C:\Program Files\Free Easy Burner\unins000.exe"
                              Google Toolbar for Internet Explorer-->MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
                              Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
                              HijackThis 2.0.2-->"C:\Users\thomas\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\M6KAMQST\HijackThis.exe" /uninstall
                              Intel(R) Matrix Storage Manager-->C:\Windows\System32\Imsmudlg.exe
                              Intel(R) PROSet/Wireless Software-->C:\Windows\Installer\iProInst.exe
                              iTunes-->MsiExec.exe /I{3DE0053C-FD9A-483E-B7C9-B06E4392206E}
                              JMB36X Raid Configurer-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}\SETUP.exe" -l0x9 -removeonly
                              LifeFrame2-->MsiExec.exe /I{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}
                              m:trip-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FABFD4E4-9216-4CF8-A594-F63AC74FEC3C}\SETUP.exe" -l0x40c UNINSTALL
                              Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
                              mCore-->MsiExec.exe /I{F5D7FAB5-A1FD-4DD3-983E-4155B09D7102}
                              mDriver-->MsiExec.exe /I{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}
                              Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
                              mHelp-->MsiExec.exe /I{8C6BB412-D3A8-4AAE-A01B-35B681789D68}
                              Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
                              Microsoft Works-->MsiExec.exe /I{6B1CB38D-E2E4-4A30-933D-EFDEBA76AD9C}
                              mMHouse-->MsiExec.exe /I{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}
                              Motorola SM56 Speakerphone Modem-->rundll32.exe sm56co6a.dll,SM56UnInstaller
                              mPfMgr-->MsiExec.exe /I{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}
                              MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
                              MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
                              MSXML 4.0 SP2 (KB941833)-->MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
                              MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                              MSXML 4.0 SP2 Parser and SDK-->MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
                              Navilog1 3.6.9-->"C:\Program Files\Navilog1\unins000.exe"
                              NB Probe-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6324A1EF-CEF4-43E3-8BCD-9EF3F67317FD}\setup.exe" -l0x9
                              neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
                              OFFICE One 150 Templates v7-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BA147801-8946-4BBE-BE17-A2199CE52C81}\setup.exe" -l0x40c -removeonly
                              OFFICE One 7.0-->MsiExec.exe /I{EA7D2E55-386E-488D-9880-F6B939534AAE}
                              OFFICE One BankPerfect-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2AE949D0-89B5-479B-A2C3-3482F68C1E7E}\setup.exe" -l0x40c -removeonly
                              OFFICE One ClipArt v7-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B8F3555E-B918-445E-97D1-BC4861C4EF59}\setup.exe" -l0x40c -removeonly
                              OFFICE One Fonts v7-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CC0C788C-7C68-47A9-BFBF-0DF7B205B4CC}\setup.exe" -l0x40c -removeonly
                              OFFICE One License v7-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E1A7B28B-AA31-442C-A4FA-598B65A7F5DA}\setup.exe" -l0x40c -removeonly
                              OFFICE One Menu v7-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{85C5827E-106F-4497-8066-B7CFEBBEA91D}\setup.exe" -l0x40c -removeonly
                              OFFICE One Notes v7-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5D2683BE-2C44-4DB5-BECD-87B324077A7F}\setup.exe" -l0x40c -removeonly
                              OFFICE One QuickPDF v7-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D85E64FE-A7F1-496B-858F-4D55A622C50D}\setup.exe" -l0x40c -removeonly
                              OFFICE One QuickZip v7-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{87DEF84E-51A5-4A0E-91C2-E012E92DE69B}\setup.exe" -l0x40c -removeonly
                              OFFICE One Safety-Box v7-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B243ABE9-57C2-4B97-BA6B-37DF6C0208ED}\setup.exe" -l0x40c -removeonly
                              OFFICE One Startup v7-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FEC30F06-A382-47D1-B828-859AC641EB1D}\setup.exe" -l0x40c -removeonly
                              OFFICE One v7 Paint.net-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2FE38EFA-06B3-4FC0-A06B-B173A3E3422E}\setup.exe" -l0x40c -removeonly
                              Online Alert Manager-->"C:\Program Files\WebMediaViewer\qttasku.exe"
                              OpenAL-->"C:\Program Files\OpenAL\OpenALwEAX.exe" /U
                              Power4Gear eXtreme-->C:\Program Files\InstallShield Installation Information\{8CFEBE9C-F29F-4C49-80E0-7106970F8734}\SETUP.exe -runfromtemp -l0x0009 -removeonly
                              QuickTime-->MsiExec.exe /I{08CA9554-B5FE-4313-938F-D4A417B81175}
                              RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
                              Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
                              Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                              Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                              Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
                              USB2.0 UVC 1.3M WebCam-->C:\Windows\Uninst.bat
                              VideoLAN VLC media player 0.8.6c-->C:\Program Files\VideoLAN\VLC\uninstall.exe
                              Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
                              Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
                              WinFlash-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DE10AB76-4756-4913-BE25-55D1C1051F9A}\setup.exe" -l0x9
                              Wireless Console 2-->C:\Program Files\InstallShield Installation Information\{83F73CB1-7705-49D1-9852-84D839CA2A45}\SETUP.exe -runfromtemp -l0x0009 -removeonly

                              ======Security center information======

                              AV: Norton Internet Security (outdated)
                              FW: Norton Internet Security
                              AS: Avira AntiVir PersonalEdition (outdated)
                              AS: Windows Defender (disabled)
                              AS: Norton Internet Security (outdated)

                              ======Environment variables======

                              "ComSpec"=%SystemRoot%\system32\cmd.exe
                              "FP_NO_HOST_CHECK"=NO
                              "OS"=Windows_NT
                              "Path"=%SYSTEMROOT%\SYSTEM32;%SYSTEMROOT%;%SYSTEMROOT%\SYSTEM32\WBEM;C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CORE-STATIC;C:\Program Files\QuickTime\QTSystem\
                              "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
                              "PROCESSOR_ARCHITECTURE"=x86
                              "TEMP"=%SystemRoot%\TEMP
                              "TMP"=%SystemRoot%\TEMP
                              "USERNAME"=SYSTEM
                              "windir"=%SystemRoot%
                              "PROCESSOR_LEVEL"=6
                              "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 10, GenuineIntel
                              "PROCESSOR_REVISION"=0f0a
                              "NUMBER_OF_PROCESSORS"=2
                              "configsetroot"=%SystemRoot%\ConfigSetRoot
                              "CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip
                              "QTJAVA"=C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip

                              -----------------EOF-----------------
                              0
                              1. Logfile of random's system information tool 1.04 (written by random/random)
                                Run by thomas at 2008-11-20 12:29:27
                                Microsoft® Windows Vista™ Édition Intégrale Service Pack 1
                                System drive C: has 12 GB (13%) free of 92 GB
                                Total RAM: 2046 MB (56% free)

                                Logfile of Trend Micro HijackThis v2.0.2
                                Scan saved at 12:29:50, on 20/11/2008
                                Platform: Windows Vista SP1 (WinNT 6.00.1905)
                                MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                                Boot mode: Normal

                                Running processes:
                                C:\Windows\system32\Dwm.exe
                                C:\Windows\SYSTEM32\taskeng.exe
                                C:\Program Files\ASUS\ASUS Live Update\ALU.exe
                                C:\Windows\Explorer.EXE
                                C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
                                C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                                C:\Windows\RtHDVCpl.exe
                                C:\Program Files\ASUS\ATK Media\DMedia.exe
                                C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                C:\Windows\ASScrPro.exe
                                C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                                C:\Program Files\iTunes\iTunesHelper.exe
                                C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                                C:\Program Files\Windows Sidebar\sidebar.exe
                                C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                                C:\Windows\ehome\ehtray.exe
                                C:\Windows\ehome\ehmsas.exe
                                C:\Program Files\Windows Media Player\wmpnscfg.exe
                                C:\Program Files\OLYMPUS\m-trip\Bin\m-tripLauncher.exe
                                C:\Windows\system32\wbem\unsecapp.exe
                                C:\Program Files\Internet Explorer\iexplore.exe
                                C:\Users\thomas\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\N2OZ8GWF\RSIT[1].exe
                                C:\Program Files\trend micro\thomas.exe

                                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.msn.com/
                                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.msn.com/
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                O1 - Hosts: ::1 localhost
                                O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                                O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                                O2 - BHO: (no name) - {64466B8E-20A7-4A4A-AFF4-AAD9CA68B52C} - C:\Program Files\WebMediaViewer\hpmun.dll (file missing)
                                O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                                O2 - BHO: ZozyWin - {EFEA05D9-BCB2-4438-A4EB-BD467692C24F} - C:\Windows\system32\dzhoil.dll (file missing)
                                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                                O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
                                O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
                                O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                                O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
                                O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\JM\JMInsIDE.exe
                                O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe
                                O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe
                                O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                                O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
                                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                                O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                                O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                                O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                                O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                                O4 - HKCU\..\Run: [ROAD DATA] "C:\ProgramData\Basefunkfunk.4wq9p"
                                O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                O4 - HKCU\..\Run: [ciwsowu] c:\users\thomas\appdata\local\ciwsowu.exe ciwsowu
                                O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                O4 - HKLM\..\Policies\Explorer\Run: [QuickTime Task] C:\Program Files\WebMediaViewer\qttask.exe
                                O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                O4 - Global Startup: m-trip Launcher.lnk = ?
                                O9 - Extra button: (no name) - {3B8FB116-D358-48A3-A5C7-DB84F15CBB04} - http://www.ietoolexpress.com/redirect.php (file missing)
                                O9 - Extra 'Tools' menuitem: IExplorer Security - {3B8FB116-D358-48A3-A5C7-DB84F15CBB04} - http://www.ietoolexpress.com/redirect.php (file missing)
                                O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
                                O13 - Gopher Prefix:
                                O17 - HKLM\System\CCS\Services\Tcpip\..\{1B21271B-0D47-4675-B03B-021025B8FA46}: NameServer = 194.2.0.20,194.2.0.40
                                O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                                O23 - Service: ADSM Service (ADSMService) - Unknown owner - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
                                O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
                                O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
                                O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
                                O23 - Service: Backbone Service (BBDemon) - Dassault Systemes - C:\Program Files\Dassault Systemes\B11\intel_a\code\bin\CATSysDemon.exe
                                O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                                O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                O23 - Service: MrobeService - OLYMPUS IMAGING CORP. - C:\Windows\System32\MrobeService.exe
                                O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                                O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
                                O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                                0
                                1. Oui mais c'est quoi RSIT ? moi sur mon pc j'ai antivir navilog et ad aware et MBAM ?
                                  0
                                  1. Modérateur
                                    Avec RSIT comme je te l'ai marqué.
                                    0
                                    1. j'ai déja supprimer le dossier RSIT hier ou avant hier quand tu me l'avais demandé, je fais l'analyse avec quel logiciel ? ac MBAM ? antivir ? Parcontre j'ai encore un dossier LOP SD alors que je l'ai supprimer, j'en fais quoi ?
                                      0
                                      1. Modérateur
                                        ---> Relance MBAM, va dans Quarantaine et supprime tout.

                                        ---> Supprime le dossier RSIT situé dans C:\

                                        ---> Refais un scan RSIT et poste les rapports.
                                        1
                                        • 1
                                        • 2
                                        • 3
                                        • 4