Virus ? Trojan

Bonjour, sa fait un petit moment que j'ai cliqué sur un lien que quelqu'un m'a envoyé, hors on m'a appris que si j'avais cliqué sur ce lien c'était un trojan, c'est la personne en question qui me l'as dit (car son pc est infecter), mais voilà le mien aussi est infecter, j'ai essayer depuis un moment de m'en débarasser de différentes succès (tuto sur internet, conseil a des amis, informaticiens expert), mais je n'ai toujours pas réussi a enlevé ce trojan qui prodduit plusieurs erreur sur mon pc quand j'utilise internet (erreur que la page n'est pas accessible ou pas disponible alors que je suis déja allez dessus), ou msn (envoi un lien avec le trojan) , ou autres (antivirux bloqué lors des mises a jour)...

Si quelqu'un pouvait vraiment m'aider, je n'en plus de savoir que mon pc est infecter !

Système d'exploitation = Windows Vista
Antivirus = Antivir
Parefeu = Windows defender

Un grand et enorme merci a la personne qui se sera dévouée pour m'aider, d'avance !

++
Configuration: Windows Vista
Mozilla firefox

121 réponses

Résumé de la discussion

Une infection de type cheval de Troie est signalée après avoir cliqué sur un lien, provoquant des erreurs réseau et des blocages d’antivirus et de mises à jour sous Windows Vista. Plusieurs solutions utiles proposent des outils de nettoyage comme Ad-Remover (options B puis C), des diagnostics avec OTL ou UsbFix, et des nettoyages en mode sans échec. Le rapport généré après nettoyage par Ad-Remover liste les adwares supprimés (Kiwee Toolbar et AskBarDis, entre autres), ainsi que les clés de démarrage et les barres d’outils supprimées, accompagnant la réinitialisation des paramètres des navigateurs. En cas de persistance, d’autres outils comme UsbFix ou des procédures en séquence peuvent être utiles pour stabiliser le système et prévenir de futures infections.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Re,

    édité, ToolbarS&D ne voit pas la KiwiToolbar
    @+
    Faites ce que l'on vous demande, ni plus, ni moins.
    Ne créez pas de doublons, ni sur CCM ni sur un autre site. Merci
    2
    1. Contributeur sécurité
      Bonjour,

      ▶ Télécharge hijackthis

      ▶ Tout est expliqué sur mon site web pour l'installer et l'utiliser correctement.

      ▶ Poste le rapport obtenu dans le bloc note dans ta prochaine réponse.

      Comment copier/coller le rapport :

      ▶ Quand tu as le rapport à l écran, tu fais ctrl A pour "sélectionner tout" puis ctrl C pour "copier".

      ▶ ensuite tu viens sur le forum pour me répondre et tu fais ctrl V pour "coller" le rapport.
      0
      1. bonjour :

        Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

        ! Déconnecte toi et ferme toutes tes applications en cours !

        Double-clique sur " RSIT.exe " pour le lancer .

        -> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

        * Devant l'option "List files/folders created ..." , tu choisis : 2 months

        * clique ensuite sur " Continue " pour lancer l'analyse ...

        -> laisse faire le scan et ne touche pas au PC ...

        Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

        Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

        Important : poste un rapport, puis l'autre dans la réponse suivante
        Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum

        ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )
        0
        1. Contributeur sécurité
          Re,

          On va utiliser ComboFix.exe. Rends toi sur cette page web pour obtenir les liens de téléchargement, ainsi que des instructions pour exécuter l'outil:

          https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

          * Vérifie que tu as fermé/désactivé tous les programmes anti-virus, anti-malware ou anti-spyware afin qu'ils n'interfèrent pas avec le travail de ComboFix.

          Envoie le contenu de C:\ComboFix.txt dans ta prochaine réponse afin que je l'examine.
          0
          1. ok je vais faire çà, le pb c'est que je ne rentre pas che moi avant vendredi soir, je te posterai le rapport sur le sujet samedi matin, ok?
            0
            1. Contributeur sécurité
              Ok pas de problèmes ;-)

              @+
              0
              1. Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 14:34:00, on 14/03/2009
                Platform: Windows Vista SP1 (WinNT 6.00.1905)
                MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                Boot mode: Normal

                Running processes:
                C:\Windows\system32\taskeng.exe
                C:\Windows\system32\Dwm.exe
                C:\Windows\Explorer.EXE
                C:\Program Files\Windows Defender\MSASCui.exe
                C:\Windows\RtHDVCpl.exe
                C:\Windows\ZSSnp211.exe
                C:\Windows\Domino.exe
                C:\Windows\System32\rundll32.exe
                C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
                C:\Program Files\Java\jre6\bin\jusched.exe
                C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                C:\Program Files\Kiwee Toolbar\2.8.167\kwtbaim.exe
                C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                C:\Windows\ehome\ehtray.exe
                C:\Program Files\Windows Media Player\wmpnscfg.exe
                C:\Program Files\MSN Messenger\msnmsgr.exe
                C:\Windows\System32\mobsync.exe
                C:\Windows\ehome\ehmsas.exe
                C:\Windows\System32\rundll32.exe
                C:\Program Files\Internet Explorer\ieuser.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
                C:\Windows\system32\SearchFilterHost.exe
                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
                O1 - Hosts: ::1 localhost
                O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
                O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                O2 - BHO: Kiwee Toolbar - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - C:\Program Files\Kiwee Toolbar\2.8.167\KiweeIEToolbar.dll
                O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                O2 - BHO: (no name) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - (no file)
                O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
                O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                O3 - Toolbar: Kiwee Toolbar - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - C:\Program Files\Kiwee Toolbar\2.8.167\KiweeIEToolbar.dll
                O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                O4 - HKLM\..\Run: [ZSSnp211] C:\Windows\ZSSnp211.exe
                O4 - HKLM\..\Run: [Domino] C:\Windows\Domino.exe
                O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
                O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe"
                O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe"
                O4 - HKLM\..\Run: [PPort11reminder] "C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini
                O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
                O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                O4 - HKLM\..\Run: [KiweeHook] "C:\Program Files\Kiwee Toolbar\2.8.167\kwtbaim.exe"
                O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                O4 - HKCU\..\Run: [Magentic] C:\PROGRA~1\Magentic\bin\Magentic.exe /c
                O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
                O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
                O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
                O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                O13 - Gopher Prefix:
                O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
                O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
                O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.nullsoft.com/nsv/embed/nsvplayx_vp3_mp3.cab
                O17 - HKLM\System\CCS\Services\Tcpip\..\{CB150540-7459-451F-BE4E-392551A5C409}: NameServer = 192.168.1.1
                O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Program Files\AGI\common\win32\PythonService.exe
                O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
                O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                0
                1. Est ce que c'est çà qui faut geoffrey5, pour t'aider a résoudre mon pb?
                  0
                  1. Contributeur sécurité
                    Bonjour,

                    Oui c'est bien ça qu'il fallait ;-)

                    ▶ Télécharge Toolbar-S&D (de Team IDN) sur ton Bureau

                    ▶ Lance l'installation du programme en exécutant le fichier téléchargé.

                    Sous XP : Double-clique sur le raccourci de Toolbar-S&D.

                    Sous Vista : Fais un clic droit sur ToolbarSD et sélectionne "Exécuter en tant qu'administrateur".

                    ▶ Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.

                    ▶ Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.

                    ▶ Poste le rapport généré. (C:\TB.txt)
                    0
                    1. Toolbar-S&D ce lien me fait bien télécharger quelque chose, je le lance mais il génére une erreur quand je veux le lancer (je suis sous vista).
                      Est ce que cela est normal?
                      0
                      1. Voilà le message : Windows Vista ne trouve pas "'%systemdrive%\Toolbar SD\ ToolBarSD.cmd'. Vous avez peut-êtr tapé un nom incorrect dans le champ Exécuter ou un autre programme ne peut pas trouver un fichier système. Pour rechercher un fichier, cliquez sur le bouton Démarrer, puis Rechercher.

                        Le tout fourni avec un seul boutton "OK"
                        0
                        1. salut essaies en faisant ceci d abord :

                          Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

                          - Vas dans "Démarrer" puis Panneau de configuration.
                          - Double Clique sur l'icône Comptes d'utilisateurs et sur Activer ou désactiver le contrôle des comptes d'utilisateurs.
                          - Clique sur Continuer.
                          - Décoche la case Utiliser le contrôle des comptes d'utilisateurs pour vous aider à protéger votre ordinateur.
                          - Valide par OK et redémarre.

                          Tuto
                          0
                          1. Je me demande si j'ai pas zapé ou etre a côté de la plaque d'un truc.
                            0
                            1. desactives tes protections aussi le temps de la manip
                              0
                              1. -----------\\ ToolBar S&D 1.1.5 XP/Vista

                                Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
                                X86-based PC ( Multiprocessor Free : AMD Athlon(tm) 64 Processor 3800+ )
                                BIOS : )Phoenix - Award WorkstationBIOS v6.00PG
                                USER : MrX ( Not Administrator ! )
                                BOOT : Normal boot

                                "C:\ToolBar SD" ( MAJ : 26-08-2008|22:40 )
                                Option : [1] ( 27/03/2009|23:27 )

                                [ UAC => 1 ]

                                -----------\\ Recherche de Fichiers / Dossiers ...

                                -----------\\ [..\Internet Explorer\Main]

                                [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                                "Start Page"="https://www.google.fr/?gws_rd=ssl"
                                "SEARCH PAGE"="https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC"
                                "Local Page"="C:\\Windows\\system32\\blank.htm"
                                "SearchMigratedDefaultURL"="https://search.yahoo.com/web{searchTerms}&ei=utf-8&fr=b1ie7"
                                "Search Bar"="https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC"
                                "Url"="https://www.msn.com/fr-fr/actualite/"

                                [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                                "Start Page"="https://fr.yahoo.com/"
                                "Default_Page_URL"="https://fr.yahoo.com/"
                                "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                                "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"

                                --------------------\\ Recherche d'autres infections

                                Aucune autre infection trouvée !

                                [ UAC => 1 ]

                                -----------\\ Fin du rapport a 23:29:53,24
                                Est ce que c'est ce rapport ci qu'il faut que je post ou je me suis tromper. Merci de votre aide par avance.
                                0
                                1. salut pour avancer :(oui c'etait le bon rapport)

                                  *****************************************************
                                  *************** Option A (Recherche) ***************
                                  *****************************************************

                                  Télécharges AD-Remover ( de Cyrildu17 / C_XX ) sur ton bureau :

                                  /!\ Déconnectes toi et fermes toutes applications en cours

                                  ? Double clique sur le programme d'installation , et installe le dans son emplacement par défaut. ( C:\Program files )
                                  ? Double clique sur l'icône Ad-removersituée sur ton bureau
                                  ? Au menu principal choisi l'option "Recherche"
                                  ? Postes le rapport qui apparait à la fin .

                                  ( le rapport est sauvegardé aussi sous C:\Ad-report(date).log )

                                  (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                                  Note :

                                  "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                                  Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                                  Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall)

                                  Aides en images (Installation)
                                  Aides en images (Recherche)

                                  ensuite :

                                  *******************************************************
                                  *************** Option B (Suppression) ***************
                                  *******************************************************

                                  /!\ Déconnecte-toi et ferme toutes applications en cours /!\

                                  Double-clique sur AD-Remover pour le lancer : au menu principal, choisis l'option B.

                                  Choisis A

                                  Puis choisis S, le programme va travailler.

                                  Poste le rapport qui apparaît à la fin.

                                  (Le rapport est sauvegardé aussi sous C:\Ad-report.log)

                                  /!\ Si le Bureau ne réapparaît pas, presse Ctrl + Alt + Suppr, Onglet "Fichier", "Nouvelle tâche", tape explorer.exe et valide) /!\

                                  Note :

                                  "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                                  Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                                  Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...)


                                  Aides en images ( Nettoyage )

                                  ensuite :

                                  *************************************************************
                                  *************** Option C (Désinstallation) ***************
                                  *************************************************************

                                  * Relance "Ad-remover" : au menu principal choisis l'option "C" .
                                  * Clique sur ok quand l avertissement apparait.

                                  Fournis les 2 rapports stp

                                  ensuite :

                                  Fais ceci
                                  0
                                  1. Mon ordinateur me met un message quand j'ouvre ad-remover
                                    Attetion : "lecontrôle des comptes d'utilisateurs est activé à executer...."
                                    "Veuillez en parler a la personne qui vous aide"
                                    Est ce que ceci est normal?
                                    0
                                    1. Sinon Random's System Information Tool (RSIT) ma post 2 truc dans 2 word

                                      voici le 1 er :
                                      info.txt logfile of random's system information tool 1.06 2009-03-28 15:44:36

                                      ======Uninstall list======

                                      -->C:\Program Files\DialMessenger/uninstall.exe
                                      -->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
                                      Acer Picture Slide DVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{41581EF5-45A7-11DA-9D78-000129760D75}\Setup.exe" -uninstall
                                      Acer Plug and Record-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F6EFFB76-4A07-11DA-9D78-000129760D75}\Setup.exe" -uninstall
                                      Acer ScreenSaver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}\setup.exe" -l0x9 -removeonly
                                      Acer Zone MagicDirector-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F79A208D-D929-11D9-9D77-000129760D75}\Setup.exe" -uninstall
                                      Acer Zone Main Page-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EFBDC2B0-FAA8-4B78-8DE1-AEBE7958FA37}\Setup.exe" -uninstall
                                      Acer Zone MakeDisk-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B145EC69-66F5-11D8-9D75-000129760D75}\Setup.exe" -uninstall
                                      Acer Zone SoftDMA-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AA4BF92B-2AAF-11DA-9D78-000129760D75}\Setup.exe" -uninstall
                                      Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
                                      Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
                                      Adobe Flash Player 9 ActiveX-->C:\Windows\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
                                      Adobe Reader 7.0-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70000000000}
                                      Adobe Shockwave Player 11-->C:\Windows\system32\adobe\SHOCKW~1\UNWISE.EXE C:\Windows\system32\Adobe\SHOCKW~1\Install.log
                                      Ad-remover-->C:\Program Files\Ad-remover\Uninstall ADR.exe
                                      Age of Empires III-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{485775E8-AEB8-46BD-922B-242879E03DD5}
                                      Apple Mobile Device Support-->MsiExec.exe /I{44734179-8A79-4DEE-BB08-73037F065543}
                                      Apple Software Update-->MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}
                                      Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
                                      Assistant Publication de sites Web Microsoft 1.53-->RunDll32 ADVPACK.DLL,LaunchINFSection C:\Windows\INF\wpie3x86.inf,WebPostUninstall
                                      Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\setup.exe /REMOVE
                                      Brother MFL-Pro Suite-->"C:\Program Files\InstallShield Installation Information\{A3FEC306-FBFF-4B0D-95B9-F9C67C65079E}\Setup.exe" -runfromtemp -l0x040c Brunin03.dll -removeonly
                                      CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
                                      CD Installation DartyBox-->"C:\Program Files\InstallShield Installation Information\{2962D91C-4D8F-46F8-AD24-0E17A92207A2}\setup.exe" -runfromtemp -l0x040c -removeonly
                                      Counter-Strike Source LAN Edition-->C:\Windows\Counter-Strike Source LAN Edition Uninstaller.exe
                                      Détecteur de flux Windows Live Toolbar (Windows Live Toolbar)-->MsiExec.exe /X{EFFCB0F1-CFEC-48D4-B793-EBFCAE852976}
                                      DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
                                      DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
                                      DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
                                      DivX Plus DirectShow Filters-->C:\Program Files\DivX\DivXDSFiltersUninstall.exe /DSFILTERS
                                      DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
                                      Google Toolbar for Internet Explorer-->MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
                                      Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
                                      GoToAssist 8.0.0.508-->C:\Program Files\Citrix\GoToAssist\508\G2AUninstaller.exe /uninstall
                                      HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
                                      Installation de la DartyBox en Ethernet-->"C:\Program Files\InstallShield Installation Information\{793CE0A7-2A75-4485-A81E-DFCE8AAF1702}\setup.exe" -runfromtemp -l0x040c -eth -pri /hide_progress -removeonly
                                      Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
                                      Java(TM) 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
                                      Java(TM) 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
                                      Kiwee Toolbar-->"C:\Program Files\AGI\common\bootstrapper.exe" -uninstall"\"C:/Program Files/AGI/Python25\pythonw.exe\" \"C:\Program Files\AGI\common\pyagcore\installer.pyc\" -u KiweeToolbar"
                                      Ma-Config.com plugin-->MsiExec.exe /I{BF85A9D4-030F-4D2A-83CF-D4DDA0D3E68C}
                                      Marvell Miniport Driver-->C:\Program Files\Marvell\Miniport Driver\Uninst.exe
                                      Menus intelligents (Windows Live Toolbar)-->MsiExec.exe /X{0CC70FEF-5068-4CD5-B4DE-86FFD98EC929}
                                      Microsoft .NET Framework 3.5-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5\setup.exe
                                      Microsoft .NET Framework 3.5-->MsiExec.exe /I{2FC099BD-AC9B-33EB-809C-D332E1B27C40}
                                      Microsoft Office PowerPoint Viewer 2007 (French)-->MsiExec.exe /X{95120000-00AF-040C-0000-0000000FF1CE}
                                      Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
                                      Microsoft Office Word Viewer 2003-->MsiExec.exe /I{9085040C-6000-11D3-8CFE-0150048383C9}
                                      Microsoft SQL Server Compact 3.5 Design Tools FRA-->MsiExec.exe /X{043ECF7B-4724-4F7B-8A9D-BC22719E95F7}
                                      Microsoft SQL Server Compact 3.5 FRA-->MsiExec.exe /I{BE361597-42AC-4513-9BA6-FFAB310038FB}
                                      Microsoft SQL Server Desktop Engine (SONY_MEDIAMGR)-->MsiExec.exe /X{E09B48B5-E141-427A-AB0C-D3605127224A}
                                      Microsoft Visual Basic 6.0 Édition Professionnelle (Français)-->"C:\Program Files\Microsoft Visual Studio\VB98\Setup\1036\Setup.exe"
                                      Mozilla Firefox (2.0.0.20)-->C:\PROGRA~1\Mozilla Firefox\uninstall\helper.exe
                                      MSDN Library pour les éditions Microsoft Visual Studio 2008 Express-->C:\Program Files\Microsoft Visual Studio 9.0\MSDN Library for Microsoft Visual Studio 2008 Express Editions\install.exe
                                      MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
                                      MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
                                      MSXML 4.0 SP2 (KB941833)-->MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
                                      MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                                      MSXML 4.0 SP2 Parser and SDK-->MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
                                      NTI Backup NOW! 4.7-->"C:\Program Files\InstallShield Installation Information\{67ADE9AF-5CD9-4089-8825-55DE4B366799}\setup.exe" -removeonly
                                      NTI CD & DVD-Maker-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2} /l1036 CDM7
                                      NVIDIA Drivers-->C:\Windows\system32\NVUNINST.EXE UninstallGUI
                                      OpenOffice.org 2.3-->MsiExec.exe /I{FADB55D0-403F-4413-A268-CF0A6F1185C2}
                                      PaperPort Image Printer-->MsiExec.exe /X{332CC6BF-E6C7-48EE-BA3D-435E576AD67F}
                                      Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
                                      ScanSoft PaperPort 11-->MsiExec.exe /I{B6C89654-A6A2-477C-873B-724EC1C56407}
                                      Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                                      Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                                      Skype™ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
                                      TeamSpeak 2 RC2-->"C:\Program Files\Teamspeak2_RC2\unins000.exe"
                                      USB PC Camera(ZS0211)-->C:\Program Files\InstallShield Installation Information\{44D02D8B-FFB3-4245-8D26-68D10B4C4023}\setup.exe -runfromtemp -l0x040c -removeonly
                                      VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
                                      VideoLAN VLC media player 0.8.6c-->C:\Program Files\VideoLAN\VLC\uninstall.exe
                                      Windows Live Messenger-->MsiExec.exe /I{F6326B60-1B1D-4ABF-BFCD-7B7404F44411}
                                      Windows Live Sign-in Assistant-->MsiExec.exe /I{49672EC2-171B-47B4-8CE7-50D7806360D7}
                                      Windows Live Toolbar-->"C:\Program Files\Windows Live Toolbar\UnInstall.exe" {0A8C97AD-DEED-4894-B446-3ABA95A77D0D}
                                      Windows Live Toolbar-->MsiExec.exe /X{0A8C97AD-DEED-4894-B446-3ABA95A77D0D}
                                      World of Warcraft-->C:\Program Files\Common Files\Blizzard Entertainment\World of Warcraft Public Test-PTR\Uninstall.exe
                                      Wow Cartographe 1.07-->C:\Program Files\WowCartographe\uninst.exe

                                      ======Hosts File======

                                      127.0.0.1 www.007guard.com
                                      127.0.0.1 007guard.com
                                      127.0.0.1 008i.com
                                      127.0.0.1 www.008k.com
                                      127.0.0.1 008k.com
                                      127.0.0.1 www.00hq.com
                                      127.0.0.1 00hq.com
                                      127.0.0.1 010402.com
                                      127.0.0.1 www.032439.com
                                      127.0.0.1 032439.com

                                      ======Security center information======

                                      AS: Windows Defender

                                      ======System event log======

                                      Computer Name: PC-de-ELISABETH
                                      Event Code: 7000
                                      Message: Le service AG Windows Service n'a pas pu démarrer en raison de l'erreur :
                                      Accès refusé.
                                      Record Number: 180365
                                      Source Name: Service Control Manager
                                      Time Written: 20090328142330.000000-000
                                      Event Type: Erreur
                                      User:

                                      Computer Name: PC-de-ELISABETH
                                      Event Code: 7000
                                      Message: Le service Avira AntiVir Personal - Free Antivirus Guard n'a pas pu démarrer en raison de l'erreur :
                                      Accès refusé.
                                      Record Number: 180366
                                      Source Name: Service Control Manager
                                      Time Written: 20090328142330.000000-000
                                      Event Type: Erreur
                                      User:

                                      Computer Name: PC-de-ELISABETH
                                      Event Code: 7000
                                      Message: Le service Planificateur LiveUpdate automatique n'a pas pu démarrer en raison de l'erreur :
                                      Le chemin d'accès spécifié est introuvable.
                                      Record Number: 180375
                                      Source Name: Service Control Manager
                                      Time Written: 20090328142330.000000-000
                                      Event Type: Erreur
                                      User:

                                      Computer Name: PC-de-ELISABETH
                                      Event Code: 7000
                                      Message: Le service Cyberlink RichVideo Service(CRVS) n'a pas pu démarrer en raison de l'erreur :
                                      Accès refusé.
                                      Record Number: 180377
                                      Source Name: Service Control Manager
                                      Time Written: 20090328142330.000000-000
                                      Event Type: Erreur
                                      User:

                                      Computer Name: PC-de-ELISABETH
                                      Event Code: 3004
                                      Message: L’agent de protection en temps réel Windows Defender a détecté des modifications. Microsoft vous recommande d’analyser les logiciels responsables de ces modifications, à la recherche de risques potentiels. Vous pouvez vous servir des informations relatives au fonctionnement de ces programmes pour autoriser ou non leur exécution, ou pour les supprimer de l’ordinateur. N’autorisez les modifications que si vous faites confiance au programme ou à l’éditeur de logiciel. Windows Defender ne peut pas annuler les modifications que vous autorisez.
                                      Pour plus d’informations, consultez les données suivantes :
                                      Non applicable
                                      ID d’analyse : {7C8637DB-C1C0-49AA-8CCE-94E7EC0AC172}
                                      Utilisateur : PC-de-ELISABETH\ELISABETH
                                      Nom : Unknown
                                      ID :
                                      ID de gravité :
                                      ID de catégorie :
                                      Chemin d’accès trouvé : iemain:HKCU@S-1-5-21-2990967951-374719986-2540076956-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page
                                      Type d’alerte : Logiciel non classifié
                                      Type de détection :
                                      Record Number: 180425
                                      Source Name: Microsoft-Windows-Windows Defender
                                      Time Written: 20090328143324.000000-000
                                      Event Type: Avertissement
                                      User:

                                      =====Application event log=====

                                      Computer Name: PC-de-ELISABETH
                                      Event Code: 1
                                      Message: L’application (Age of Empires III, du fournisseur Microsoft) a le problème suivant : Age of Empires III est incompatible avec cette version de Windows. Pour plus d’informations, contactez Microsoft.
                                      Record Number: 63970
                                      Source Name: Microsoft-Windows-ApplicationExperienceInfrastructure
                                      Time Written: 20090328122524.642429-000
                                      Event Type: Avertissement
                                      User: PC-de-ELISABETH\ELISABETH

                                      Computer Name: PC-de-ELISABETH
                                      Event Code: 1
                                      Message: L’application (Age of Empires III, du fournisseur Microsoft) a le problème suivant : Age of Empires III est incompatible avec cette version de Windows. Pour plus d’informations, contactez Microsoft.
                                      Record Number: 63971
                                      Source Name: Microsoft-Windows-ApplicationExperienceInfrastructure
                                      Time Written: 20090328122549.977029-000
                                      Event Type: Avertissement
                                      User: PC-de-ELISABETH\ELISABETH

                                      Computer Name: PC-de-ELISABETH
                                      Event Code: 1530
                                      Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

                                      DÉTAIL -
                                      1 user registry handles leaked from \Registry\User\S-1-5-21-2990967951-374719986-2540076956-1000:
                                      Process 920 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2990967951-374719986-2540076956-1000

                                      Record Number: 63976
                                      Source Name: Microsoft-Windows-User Profiles Service
                                      Time Written: 20090328142101.000000-000
                                      Event Type: Avertissement
                                      User: AUTORITE NT\SYSTEM

                                      Computer Name: PC-de-ELISABETH
                                      Event Code: 1530
                                      Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

                                      DÉTAIL -
                                      1 user registry handles leaked from \Registry\User\S-1-5-21-2990967951-374719986-2540076956-1000_Classes:
                                      Process 920 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2990967951-374719986-2540076956-1000_CLASSES

                                      Record Number: 63977
                                      Source Name: Microsoft-Windows-User Profiles Service
                                      Time Written: 20090328142102.000000-000
                                      Event Type: Avertissement
                                      User: AUTORITE NT\SYSTEM

                                      Computer Name: PC-de-ELISABETH
                                      Event Code: 19011
                                      Message:
                                      Record Number: 63987
                                      Source Name: MSSQL$SONY_MEDIAMGR
                                      Time Written: 20090328142154.000000-000
                                      Event Type: Avertissement
                                      User:

                                      =====Security event log=====

                                      Computer Name: PC-de-ELISABETH
                                      Event Code: 4672
                                      Message: Privilèges spéciaux attribués à la nouvelle ouverture de session.

                                      Sujet :
                                      ID de sécurité : S-1-5-18
                                      Nom du compte : SYSTEM
                                      Domaine du compte : AUTORITE NT
                                      ID d’ouverture de session : 0x3e7

                                      Privilèges : SeAssignPrimaryTokenPrivilege
                                      SeTcbPrivilege
                                      SeSecurityPrivilege
                                      SeTakeOwnershipPrivilege
                                      SeLoadDriverPrivilege
                                      SeBackupPrivilege
                                      SeRestorePrivilege
                                      SeDebugPrivilege
                                      SeAuditPrivilege
                                      SeSystemEnvironmentPrivilege
                                      SeImpersonatePrivilege
                                      Record Number: 55285
                                      Source Name: Microsoft-Windows-Security-Auditing
                                      Time Written: 20081005172529.536902-000
                                      Event Type: Succès de l'audit
                                      User:

                                      Computer Name: PC-de-ELISABETH
                                      Event Code: 4648
                                      Message: Tentative d’ouverture de session en utilisant des informations d’identification explicites.

                                      Sujet :
                                      ID de sécurité : S-1-5-18
                                      Nom du compte : PC-DE-ELISABETH$
                                      Domaine du compte : WORKGROUP
                                      ID d’ouverture de session : 0x3e7
                                      GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

                                      Compte dont les informations d’identification ont été utilisées :
                                      Nom du compte : SYSTEM
                                      Domaine du compte : AUTORITE NT
                                      GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

                                      Serveur cible :
                                      Nom du serveur cible : localhost
                                      Informations supplémentaires : localhost

                                      Informations sur le processus :
                                      ID du processus : 0x280
                                      Nom du processus : C:\Windows\System32\services.exe

                                      Informations sur le réseau :
                                      Adresse du réseau : -
                                      Port : -

                                      Cet événement est généré lorsqu’un processus tente d’ouvrir une session pour un compte en spécifiant explicitement les informations d’identification de ce compte. Ceci se produit le plus souvent dans les configurations par lot comme les tâches planifiées, ou avec l’utilisation de la commande RUNAS.
                                      Record Number: 55286
                                      Source Name: Microsoft-Windows-Security-Auditing
                                      Time Written: 20081005172530.816111-000
                                      Event Type: Succès de l'audit
                                      User:

                                      Computer Name: PC-de-ELISABETH
                                      Event Code: 4624
                                      Message: L’ouverture de session d’un compte s’est correctement déroulée.

                                      Sujet :
                                      ID de sécurité : S-1-5-18
                                      Nom du compte : PC-DE-ELISABETH$
                                      Domaine du compte : WORKGROUP
                                      ID d’ouverture de session : 0x3e7

                                      Type d’ouverture de session : 5

                                      Nouvelle ouverture de session :
                                      ID de sécurité : S-1-5-18
                                      Nom du compte : SYSTEM
                                      Domaine du compte : AUTORITE NT
                                      ID d’ouverture de session : 0x3e7
                                      GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

                                      Informations sur le processus :
                                      ID du processus : 0x280
                                      Nom du processus : C:\Windows\System32\services.exe

                                      Informations sur le réseau :
                                      Nom de la station de travail :
                                      Adresse du réseau source : -
                                      Port source : -

                                      Informations détaillées sur l’authentification :
                                      Processus d’ouverture de session : Advapi
                                      Package d’authentification : Negotiate
                                      Services en transit : -
                                      Nom du package (NTLM uniquement) : -
                                      Longueur de la clé : 0

                                      Cet événement est généré lors de la création d’une ouverture de session. Il est généré sur l’ordinateur sur lequel l’ouverture de session a été effectuée.

                                      Le champ Objet indique le compte sur le système local qui a demandé l’ouverture de session. Il s’agit le plus souvent d’un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

                                      Le champ Type d’ouverture de session indique le type d’ouverture de session qui s’est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

                                      Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s’est connecté.

                                      Les champs relatifs au réseau indiquent la provenance d’une demande d’ouverture de session à distance. Le nom de la station de travail n’étant pas toujours disponible, peut être laissé vide dans certains cas.

                                      Les champs relatifs aux informations d’authentification fournissent des détails sur cette demande d’ouverture de session spécifique.
                                      - Le GUID d’ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
                                      - Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d’ouverture de session.
                                      - Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
                                      - La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n’a été demandée.
                                      Record Number: 55287
                                      Source Name: Microsoft-Windows-Security-Auditing
                                      Time Written: 20081005172530.816111-000
                                      Event Type: Succès de l'audit
                                      User:

                                      Computer Name: PC-de-ELISABETH
                                      Event Code: 4672
                                      Message: Privilèges spéciaux attribués à la nouvelle ouverture de session.

                                      Sujet :
                                      ID de sécurité : S-1-5-18
                                      Nom du compte : SYSTEM
                                      Domaine du compte : AUTORITE NT
                                      ID d’ouverture de session : 0x3e7

                                      Privilèges : SeAssignPrimaryTokenPrivilege
                                      SeTcbPrivilege
                                      SeSecurityPrivilege
                                      SeTakeOwnershipPrivilege
                                      SeLoadDriverPrivilege
                                      SeBackupPrivilege
                                      SeRestorePrivilege
                                      SeDebugPrivilege
                                      SeAuditPrivilege
                                      SeSystemEnvironmentPrivilege
                                      SeImpersonatePrivilege
                                      Record Number: 55288
                                      Source Name: Microsoft-Windows-Security-Auditing
                                      Time Written: 20081005172530.816111-000
                                      Event Type: Succès de l'audit
                                      User:

                                      Computer Name: PC-de-ELISABETH
                                      Event Code: 5033
                                      Message: Le pilote du Pare-feu Windows est correctement démarré.
                                      Record Number: 55289
                                      Source Name: Microsoft-Windows-Security-Auditing
                                      Time Written: 20081005172530.940911-000
                                      Event Type: Succès de l'audit
                                      User:

                                      ======Environment variables======

                                      "ComSpec"=%SystemRoot%\system32\cmd.exe
                                      "FP_NO_HOST_CHECK"=NO
                                      "OS"=Windows_NT
                                      "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Common Files\DivX Shared\
                                      "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
                                      "PROCESSOR_ARCHITECTURE"=x86
                                      "TEMP"=%SystemRoot%\TEMP
                                      "TMP"=%SystemRoot%\TEMP
                                      "USERNAME"=SYSTEM
                                      "windir"=%SystemRoot%
                                      "PROCESSOR_LEVEL"=15
                                      "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 95 Stepping 2, AuthenticAMD
                                      "PROCESSOR_REVISION"=5f02
                                      "NUMBER_OF_PROCESSORS"=1

                                      -----------------EOF-----------------
                                      0
                                      1. et voila le 2eme :

                                        Logfile of random's system information tool 1.06 (written by random/random)
                                        Run by ELISABETH at 2009-03-28 15:44:14
                                        Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
                                        System drive C: has 15 GB (21%) free of 73 GB
                                        Total RAM: 3071 MB (71% free)

                                        Logfile of Trend Micro HijackThis v2.0.2
                                        Scan saved at 15:44:33, on 28/03/2009
                                        Platform: Windows Vista SP1 (WinNT 6.00.1905)
                                        MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                                        Boot mode: Normal

                                        Running processes:
                                        C:\Windows\system32\taskeng.exe
                                        C:\Windows\system32\Dwm.exe
                                        C:\Windows\Explorer.EXE
                                        C:\Program Files\Windows Defender\MSASCui.exe
                                        C:\Windows\RtHDVCpl.exe
                                        C:\Windows\ZSSnp211.exe
                                        C:\Windows\Domino.exe
                                        C:\Windows\System32\rundll32.exe
                                        C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
                                        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                                        C:\Program Files\Kiwee Toolbar\2.8.167\kwtbaim.exe
                                        C:\Program Files\Java\jre6\bin\jusched.exe
                                        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                        C:\Windows\ehome\ehtray.exe
                                        C:\Program Files\Windows Media Player\wmpnscfg.exe
                                        C:\Program Files\DartyBox_v3\Bewan\AssistantDB\AssistantDB_Bewan.exe
                                        C:\Windows\System32\mobsync.exe
                                        C:\Windows\System32\rundll32.exe
                                        C:\Windows\ehome\ehmsas.exe
                                        C:\Program Files\Internet Explorer\ieuser.exe
                                        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                                        C:\Windows\system32\conime.exe
                                        C:\Program Files\Internet Explorer\iexplore.exe
                                        C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
                                        C:\Windows\system32\SearchFilterHost.exe
                                        C:\Users\ELISABETH\Desktop\RSIT.exe
                                        C:\Program Files\Trend Micro\HijackThis\ELISABETH.exe

                                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
                                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.fr.acer.yahoo.com
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                        R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                        R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
                                        O1 - Hosts: ::1 localhost
                                        O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
                                        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                                        O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                                        O2 - BHO: Kiwee Toolbar - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - C:\Program Files\Kiwee Toolbar\2.8.167\KiweeIEToolbar.dll
                                        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                        O2 - BHO: (no name) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - (no file)
                                        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                                        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
                                        O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                                        O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
                                        O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                        O3 - Toolbar: Kiwee Toolbar - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - C:\Program Files\Kiwee Toolbar\2.8.167\KiweeIEToolbar.dll
                                        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                        O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                                        O4 - HKLM\..\Run: [ZSSnp211] C:\Windows\ZSSnp211.exe
                                        O4 - HKLM\..\Run: [Domino] C:\Windows\Domino.exe
                                        O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                                        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                                        O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
                                        O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe"
                                        O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe"
                                        O4 - HKLM\..\Run: [PPort11reminder] "C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini
                                        O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
                                        O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
                                        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                                        O4 - HKLM\..\Run: [KiweeHook] "C:\Program Files\Kiwee Toolbar\2.8.167\kwtbaim.exe"
                                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                                        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                                        O4 - HKCU\..\Run: [Magentic] C:\PROGRA~1\Magentic\bin\Magentic.exe /c
                                        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                        O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                        O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
                                        O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                        O4 - HKCU\..\Run: [Assistant DartyBox] C:\Program Files\DartyBox_v3\Bewan\AssistantDB\AssistantDB_Bewan.exe -m
                                        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                                        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                        O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
                                        O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
                                        O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                                        O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                                        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                                        O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                                        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                                        O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
                                        O13 - Gopher Prefix:
                                        O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
                                        O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
                                        O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.nullsoft.com/nsv/embed/nsvplayx_vp3_mp3.cab
                                        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                                        O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\508\G2AWinLogon.dll
                                        O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Program Files\AGI\common\win32\PythonService.exe
                                        O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                        O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                        O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                        O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                                        O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                                        O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\508\g2aservice.exe
                                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                                        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                        O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
                                        O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                                        0
                                        1. bonne lecture :p
                                          en esperant que cela puisse servir.
                                          0
                                          • 1
                                          • 2
                                          • 3
                                          • 4
                                          • 5
                                          • 6
                                          • 7