Worm Rbot.gen (aide svp)

Bonjour,

Mon frère a passé la soirée à la maison hier et est allé sur l'ordinateur, depuis mon anti virus (avira) détecte souvent le virus "Worm RBOT.gen", Je le delete, mais à chaque fois il revient dans un autre dossier

Pouvez vous m'aider pour le supprimer svp?

Merci d'avance

Jess :)
Configuration: Windows XP
Firefox 3.0.8

19 réponses

  1. Contributeur sécurité
    slt,

    Télécharge ici :

    http://images.malwareremoval.com/random/RSIT.exe

    random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

    Double-clique sur RSIT.exe afin de lancer RSIT.

    Clique Continue à l'écran Disclaimer.

    Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

    Poste le contenu de log.txt (<<qui sera affiché)
    ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

    NB : Les rapports sont sauvegardés dans le dossier C:\rsit
    0
    1. Tout d'abords, merci à toi de te pencher sur mon problème :)

      Voici donc le log.txt

      Logfile of random's system information tool 1.06 (written by random/random)
      Run by Administrateur at 2009-04-09 13:30:11
      Microsoft Windows XP Professionnel Service Pack 3
      System drive C: has 62 GB (81%) free of 76 GB
      Total RAM: 495 MB (7% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 13:33:03, on 9/04/2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.20978)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
      C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Microsoft IntelliType Pro\itype.exe
      C:\WINDOWS\Mixer.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
      C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Peer2Me\Peer2Me.exe
      C:\Program Files\eMule\emule.exe
      C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
      C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
      C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\Program Files\Google\Update\GoogleUpdate.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
      C:\Program Files\Windows Live\Contacts\wlcomm.exe
      C:\Program Files\Mozilla Thunderbird\thunderbird.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Documents and Settings\Administrateur\Bureau\RSIT.exe
      C:\Program Files\Trend Micro\HijackThis\Administrateur.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Yoshi Ultimate
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
      O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\styler\TB\StylerTB.dll
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
      O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe 1
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
      O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
      O4 - HKLM\..\Run: [TQ566808] "D:\Setup.exe"
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKCU\..\Run: [Peer2Me] "C:\Program Files\Peer2Me\Peer2Me.exe"
      O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
      O4 - HKUS\S-1-5-19\..\RunOnce: [vista_sound_register.inf] rundll32.exe setupapi.dll,InstallHinfSection DefaultInstall 128 C:\WINDOWS\Media\vista_sound_register.inf (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\RunOnce: [vista_sound_register.inf] rundll32.exe setupapi.dll,InstallHinfSection DefaultInstall 128 C:\WINDOWS\Media\vista_sound_register.inf (User 'SERVICE RÉSEAU')
      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
      O4 - Global Startup: hp psc 1000 series.lnk = ?
      O4 - Global Startup: hpoddt01.exe.lnk = ?
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O14 - IERESET.INF: START_PAGE_URL=https://www.google.fr/?gws_rd=ssl
      O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
      O17 - HKLM\System\CCS\Services\Tcpip\..\{C0531356-9B55-4CDD-9258-2CFBF19AB39D}: NameServer = 10.1.1.21
      O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Google Update Service (gupdate1c9878c3befb068) (gupdate1c9878c3befb068) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
      O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
      O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
      0
      1. ET voila info.txt

        info.txt logfile of random's system information tool 1.06 2009-04-09 13:33:07

        ======Uninstall list======

        -->C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
        -->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
        -->MsiExec.exe /I{403EF592-953B-4794-BCEF-ECAB835C2095}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0015-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0019-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {5A2F65A4-808F-4A1E-973E-92E17824982D}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {2AB528A5-BB1B-4EBE-8E51-AD0C4CD33CA9}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {B3F4DC34-7F60-4B7C-A79F-1C13012D99D4}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0044-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
        Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
        Adobe Photoshop CS-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EFB21DE7-8C19-4A88-BB28-A766E16493BC}\setup.exe" -l0x40c
        Adobe Reader 9.1 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A91000000001}
        Apple Mobile Device Support-->MsiExec.exe /I{EC4455AB-F155-4CC1-A4C5-88F3777F9886}
        Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
        Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
        Assistant de connexion Windows Live-->MsiExec.exe /I{D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
        Avance ALS4000 Sound System-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" REMOVE
        Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
        Bonjour-->MsiExec.exe /I{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}
        CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
        Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
        Disque de souvenirs HP-->MsiExec.exe /X{B376402D-58EA-45EA-BD50-DD924EB67A70}
        eMule-->"C:\Program Files\eMule\Uninstall.exe"
        Galerie de photos Windows Live-->MsiExec.exe /X{44E54A81-9D91-4AA1-9417-80AFF134F5FF}
        Glary Utilities Pro 2.5.3-->"C:\Program Files\Glary Utilities\unins000.exe"
        Google Chrome-->"C:\Program Files\Google\Chrome\Application\1.0.154.53\Installer\setup.exe" --uninstall --system-level
        Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
        HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
        hp psc 1200 series-->MsiExec.exe /X{C900EF06-2E76-49C7-8DB0-41F629B21DC5}
        Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
        Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
        Intel(R) Extreme Graphics 2 Driver-->RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2572
        Intel(R) Network Connections 13.3.46.0-->MsiExec.exe /i{555D5F00-9CEE-4FE5-8C2A-5856A4DF94F4} ARPREMOVE=1
        iTunes-->MsiExec.exe /I{318AB667-3230-41B5-A617-CB3BF748D371}
        Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
        Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
        K-Lite Codec Pack 4.1.7 (Full)-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
        Ma-Config.com-->MsiExec.exe /X{EC7FE2ED-F305-41B7-90B8-3DAE9E35307A}
        Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
        Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
        Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
        Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
        Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
        Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
        Microsoft Calculatrice Plus-->MsiExec.exe /I{13922F10-BD74-4912-AB11-E34B35062700}
        Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
        Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
        Microsoft Office InfoPath MUI (French) 2007-->MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}
        Microsoft Office Language Pack 2007 Service Pack 1 (SP1)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {EC50B538-CBE1-42E6-B7FE-87AA540AADFB}
        Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
        Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
        Microsoft Office Professional Plus 2007-->"C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
        Microsoft Office Professional Plus 2007-->MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}
        Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
        Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
        Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
        Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
        Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
        Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
        Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
        Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
        Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
        Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
        Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
        Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
        Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
        Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
        Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - FRA\install.exe
        Mozilla Firefox (3.0)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
        Mozilla Thunderbird (2.0.0.21)-->C:\Program Files\Mozilla Thunderbird\uninstall\helper.exe
        MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
        MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
        MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
        MSXML 6.0 Parser (KB933579)-->MsiExec.exe /I{1787603C-E6E3-42D4-8034-55F358486F1D}
        Nero 7 Essentials-->MsiExec.exe /X{AAB93551-3FFE-42B2-8315-96252BBC1036}
        Nero 8 Lite 8.3.2.1-->"C:\Program Files\Nero\unins000.exe"
        OGA Notifier 1.7.0105.35.0-->MsiExec.exe /I{25E98ECB-5727-408E-B30A-2CAF86F5B310}
        Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
        Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
        PCI Audio Driver-->cmuninst.exe
        Peer2Me-->MsiExec.exe /I{C783600B-C726-4481-9BBE-06F560CF8968}
        Photo et imagerie HP 2.0 - All-in-One Pilote-->MsiExec.exe /X{6ECB39BD-73C2-44DD-B1A0-898207C58D8B}
        Photo et imagerie HP 2.0 - All-in-One-->MsiExec.exe /X{9867A917-5D17-40DE-83BA-BEA5293194B1}
        Photo et imagerie HP 2.0 - hp psc 1200 series-->C:\Program Files\Hewlett-Packard\Digital Imaging\{7C8BB31C-E09E-4c7d-BBF1-45E33B467FE1}\Setup\hpzscr01.exe -datfile hposcr02.dat -forcereboot
        PhotoFiltre Studio-->"C:\Program Files\PhotoFiltre Studio\Uninst.exe"
        QuickTime-->MsiExec.exe /I{F958CA02-BB40-4007-894B-258729456EE4}
        Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x40c -removeonly
        Security Update for 2007 Microsoft Office System (KB951550)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {B243E9A5-ED77-4F1B-B338-2486FD82DC85}
        Security Update for 2007 Microsoft Office System (KB951944)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
        Security Update for 2007 Microsoft Office System (KB958439)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {6491B8AA-D11C-4648-A461-6234B31EB7E2}
        Security Update for Microsoft Office Excel 2007 (KB958437)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {648FC016-2D6B-4A16-8D87-404533642F4B}
        Security Update for Microsoft Office PowerPoint 2007 (KB951338)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {558B709B-821B-4FC5-90FC-9A8890641E77}
        Security Update for Microsoft Office Publisher 2007 (KB950114)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {F9C3CDBA-1F00-4D4D-959D-75C9D3ACDD85}
        Security Update for Microsoft Office system 2007 (KB954326)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F}
        Security Update for Microsoft Office system 2007 (KB956828)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {885E081B-72BD-4E76-8E98-30B4BE468FAC}
        Security Update for Microsoft Office Word 2007 (KB956358)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {4551666D-0FD6-4C69-8A81-1C6F2E64517C}
        Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
        Spelling Dictionaries Support For Adobe Reader 9-->MsiExec.exe /I{AC76BA86-7AD7-5464-3428-900000000004}
        Turbo Lister 2-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{69640730-B830-4C24-BB5C-222DA1260548}
        Update for Microsoft Office Outlook 2007 (KB952142)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {4AD3A076-427C-491F-A5B7-7D1DE788A756}
        Update for Office 2007 (KB946691)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278}
        Update for Outlook 2007 Junk Email Filter (kb962871)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {297857BF-4011-449B-BD74-DB64D182821C}
        Version 2-->"C:\Program Files\deo\unins000.exe"
        VIA Gestionnaire de périphériques de plate-forme-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{20D4A895-748C-4D88-871C-FDB1695B0169}
        Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
        Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
        Windows Live Contrôle parental-->MsiExec.exe /X{D6A2DDE3-9D7C-412C-932A-756580D29919}
        Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
        Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}

        =====HijackThis Backups=====

        O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [SessMgr] C:\WINDOWS\sessmgr.exe /waitservice (User 'Default user') [2009-01-08]
        O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [SessMgr] C:\WINDOWS\sessmgr.exe /waitservice (User 'SYSTEM') [2009-01-08]
        O4 - HKLM\..\Policies\Explorer\Run: [MstInit] C:\DOCUME~1\ADMINI~1\LOCALS~1\APPLIC~1\mstinit.exe /waitservice [2009-01-08]
        F3 - REG:win.ini: load=C:\WINDOWS\System\esentutl.exe [2009-01-08]
        O4 - HKCU\..\Policies\Explorer\Run: [Esent Utl] C:\WINDOWS\System32\drivers\esentutl.exe /waitservice [2009-01-08]

        ======Hosts File======

        127.0.0.1 localhost

        ======Security center information======

        AV: Avira AntiVir PersonalEdition

        ======System event log======

        Computer Name: FB656F79DFBF450
        Event Code: 7026
        Message: Le pilote de démarrage système ou d'amorçage suivant n'a pas pu se charger :
        iaStor

        Record Number: 480
        Source Name: Service Control Manager
        Time Written: 20081121105421.000000+060
        Event Type: erreur
        User:

        Computer Name: FB656F79DFBF450
        Event Code: 17
        Message: AVGNTFLT successfully loaded

        Record Number: 479
        Source Name: avgntflt
        Time Written: 20081121105249.000000+060
        Event Type: Informations
        User:

        Computer Name: FB656F79DFBF450
        Event Code: 6005
        Message: Le service d'Enregistrement d'événement a démarré.

        Record Number: 478
        Source Name: EventLog
        Time Written: 20081121105238.000000+060
        Event Type: Informations
        User:

        Computer Name: FB656F79DFBF450
        Event Code: 6009
        Message: Microsoft (R) Windows (R) 5.01. 2600 Service Pack 3 Multiprocessor Free.

        Record Number: 477
        Source Name: EventLog
        Time Written: 20081121105238.000000+060
        Event Type: Informations
        User:

        Computer Name: FB656F79DFBF450
        Event Code: 7035
        Message: Un contrôle Arrêter a correctement été envoyé au service Ma-Config Service.

        Record Number: 476
        Source Name: Service Control Manager
        Time Written: 20081121105002.000000+060
        Event Type: Informations
        User: FB656F79DFBF450\Administrateur

        =====Application event log=====

        Computer Name: FB656F79DFBF450
        Event Code: 701
        Message: msnmsgr (996) La défragmentation en ligne a terminé un passage complet dans la base de données '\\.\C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\Messenger\jessicafrancotte@hotmail.com\SharingMetadata\Working\database_A0C4_1CF0_C41C_CA84\dfsr.db'.

        Record Number: 2852
        Source Name: ESENT
        Time Written: 20090214000101.000000+060
        Event Type: Informations
        User:

        Computer Name: FB656F79DFBF450
        Event Code: 700
        Message: msnmsgr (996) La défragmentation en ligne commence un passage complet dans la base de données '\\.\C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\Messenger\jessicafrancotte@hotmail.com\SharingMetadata\Working\database_A0C4_1CF0_C41C_CA84\dfsr.db'.

        Record Number: 2851
        Source Name: ESENT
        Time Written: 20090214000101.000000+060
        Event Type: Informations
        User:

        Computer Name: FB656F79DFBF450
        Event Code: 102
        Message: msnmsgr (996) \\.\C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\Messenger\jessicafrancotte@hotmail.com\SharingMetadata\Working\database_A0C4_1CF0_C41C_CA84\dfsr.db: Le moteur de base de données a démarré une nouvelle instance (0).

        Record Number: 2850
        Source Name: ESENT
        Time Written: 20090213153318.000000+060
        Event Type: Informations
        User:

        Computer Name: FB656F79DFBF450
        Event Code: 100
        Message: msnmsgr (996) Le moteur de base de données 5.01.2600.5512 est démarré.

        Record Number: 2849
        Source Name: ESENT
        Time Written: 20090213153318.000000+060
        Event Type: Informations
        User:

        Computer Name: FB656F79DFBF450
        Event Code: 101
        Message: msnmsgr (996) Le moteur de base de données est arrêté.

        Record Number: 2848
        Source Name: ESENT
        Time Written: 20090213153219.000000+060
        Event Type: Informations
        User:

        ======Environment variables======

        "ComSpec"=%SystemRoot%\system32\cmd.exe
        "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Intel\DMIX;C:\Program Files\QuickTime\QTSystem\
        "windir"=%SystemRoot%
        "FP_NO_HOST_CHECK"=NO
        "OS"=Windows_NT
        "PROCESSOR_ARCHITECTURE"=x86
        "PROCESSOR_LEVEL"=15
        "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 2 Stepping 9, GenuineIntel
        "PROCESSOR_REVISION"=0209
        "NUMBER_OF_PROCESSORS"=2
        "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
        "TEMP"=%SystemRoot%\TEMP
        "TMP"=%SystemRoot%\TEMP
        "CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip
        "QTJAVA"=C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip

        -----------------EOF-----------------
        0
        1. Contributeur sécurité
          Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
          http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
          guide: http://site-naheulbeuk.com/
          Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
          • Redémarre ton ordinateur
          • Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
          • A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
          • Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
          • Choisis ton compte.
          Déroule la liste des instructions ci-dessous :
          • Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
          • Appuie sur Y pour commencer le processus de nettoyage.
          • Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
          • Appuie sur une touche pour redémarrer le PC.
          • Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
          • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
          • Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
          • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
          • Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum

          Si SDfix ne se lance pas (ça arrive!)

          * Démarrer->Exécuter
          * Copie/colle ceci dans la fenêtre :

          %systemroot%\system32\cmd.exe /K %systemdrive%\SDFix\apps\FixPath.exe

          * Clique sur ok, et valide.
          * Redémarre et essaye de nouveau de lancer SDfix.
          0
          1. Voila^^

            [b]SDFix: Version 1.240 [/b]
            Run by Administrateur on jeu. 09/04/2009 at 13:53

            Microsoft Windows XP [version 5.1.2600]
            Running From: C:\SDFix

            [b]Checking Services [/b]:

            Restoring Default Security Values
            Restoring Default Hosts File

            Rebooting

            [b]Checking Files [/b]:

            No Trojan Files Found

            Removing Temp Files

            [b]ADS Check [/b]:

            [b]Final Check [/b]:

            catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
            Rootkit scan 2009-04-09 13:59:17
            Windows 5.1.2600 Service Pack 3 NTFS

            scanning hidden processes ...

            scanning hidden services & system hive ...

            scanning hidden registry entries ...

            scanning hidden files ...

            scan completed successfully
            hidden processes: 0
            hidden services: 0
            hidden files: 0

            [b]Remaining Services [/b]:

            Authorized Application Key Export:

            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
            "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
            "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
            "C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
            "C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
            "C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
            "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
            "C:\\Program Files\\ma-config.com\\maconfservice.exe"="C:\\Program Files\\ma-config.com\\maconfservice.exe:LocalSubNet:Enabled:maconfservice"
            "C:\\Program Files\\Mozilla Thunderbird\\thunderbird.exe"="C:\\Program Files\\Mozilla Thunderbird\\thunderbird.exe:*:Enabled:Mozilla Thunderbird"
            "C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"="C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe:*:Enabled:Windows Live Call"
            "C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"="C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
            "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"

            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
            "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
            "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
            "C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"="C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe:*:Enabled:Windows Live Call"
            "C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"="C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
            "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"

            [b]Remaining Files [/b]:

            [b]Files with Hidden Attributes [/b]:

            Sat 10 Jan 2009 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"

            [b]Finished![/b]
            0
            1. Ok je fais ça, mais la réponse va être longue a arriver ^^ Antivir prends énormément de temps! (lol)

              MErci encore à toi
              0
              1. Contributeur sécurité
                ok fais malwarebyte avant cela prend en scan rapide que quelques minutes
                0
                1. Voici le scan de malwarebyte de ce matin

                  Malwarebytes' Anti-Malware 1.32
                  Version de la base de données: 1631
                  Windows 5.1.2600 Service Pack 3

                  9/04/2009 12:07:30
                  mbam-log-2009-04-09 (12-07-30).txt

                  Type de recherche: Examen complet (C:\|E:\|)
                  Eléments examinés: 86845
                  Temps écoulé: 41 minute(s), 12 second(s)

                  Processus mémoire infecté(s): 0
                  Module(s) mémoire infecté(s): 0
                  Clé(s) du Registre infectée(s): 0
                  Valeur(s) du Registre infectée(s): 0
                  Elément(s) de données du Registre infecté(s): 0
                  Dossier(s) infecté(s): 0
                  Fichier(s) infecté(s): 0

                  Processus mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Module(s) mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Clé(s) du Registre infectée(s):
                  (Aucun élément nuisible détecté)

                  Valeur(s) du Registre infectée(s):
                  (Aucun élément nuisible détecté)

                  Elément(s) de données du Registre infecté(s):
                  (Aucun élément nuisible détecté)

                  Dossier(s) infecté(s):
                  (Aucun élément nuisible détecté)

                  Fichier(s) infecté(s):
                  (Aucun élément nuisible détecté)

                  Et voici celui en mode rapide de maintenant

                  Malwarebytes' Anti-Malware 1.32
                  Version de la base de données: 1631
                  Windows 5.1.2600 Service Pack 3

                  9/04/2009 15:15:55
                  mbam-log-2009-04-09 (15-15-55).txt

                  Type de recherche: Examen rapide
                  Eléments examinés: 50653
                  Temps écoulé: 6 minute(s), 13 second(s)

                  Processus mémoire infecté(s): 0
                  Module(s) mémoire infecté(s): 0
                  Clé(s) du Registre infectée(s): 0
                  Valeur(s) du Registre infectée(s): 0
                  Elément(s) de données du Registre infecté(s): 0
                  Dossier(s) infecté(s): 0
                  Fichier(s) infecté(s): 0

                  Processus mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Module(s) mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Clé(s) du Registre infectée(s):
                  (Aucun élément nuisible détecté)

                  Valeur(s) du Registre infectée(s):
                  (Aucun élément nuisible détecté)

                  Elément(s) de données du Registre infecté(s):
                  (Aucun élément nuisible détecté)

                  Dossier(s) infecté(s):
                  (Aucun élément nuisible détecté)

                  Fichier(s) infecté(s):
                  (Aucun élément nuisible détecté)

                  Je démarre Antivir ^^
                  0
                  1. Contributeur sécurité
                    le souci c'est que ton malwarebyte n'à pas été mis à jour . Donc le mettre à jour puis refaire un scan rapide et le coller
                    0
                2. Voila avec la mise à jour

                  Malwarebytes' Anti-Malware 1.36
                  Version de la base de données: 1958
                  Windows 5.1.2600 Service Pack 3

                  9/04/2009 16:02:34
                  mbam-log-2009-04-09 (16-02-34).txt

                  Type de recherche: Examen rapide
                  Eléments examinés: 65185
                  Temps écoulé: 4 minute(s), 37 second(s)

                  Processus mémoire infecté(s): 0
                  Module(s) mémoire infecté(s): 0
                  Clé(s) du Registre infectée(s): 0
                  Valeur(s) du Registre infectée(s): 0
                  Elément(s) de données du Registre infecté(s): 0
                  Dossier(s) infecté(s): 0
                  Fichier(s) infecté(s): 0

                  Processus mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Module(s) mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Clé(s) du Registre infectée(s):
                  (Aucun élément nuisible détecté)

                  Valeur(s) du Registre infectée(s):
                  (Aucun élément nuisible détecté)

                  Elément(s) de données du Registre infecté(s):
                  (Aucun élément nuisible détecté)

                  Dossier(s) infecté(s):
                  (Aucun élément nuisible détecté)

                  Fichier(s) infecté(s):
                  (Aucun élément nuisible détecté)

                  Antivir par contre lui est en train de scanner, il a déjà trouvé 5 infestations donc 1 dangereuse :(
                  0
                  1. Voila le report d'Antivir

                    Avira AntiVir Personal
                    Report file date: jeudi 9 avril 2009 15:18

                    Scanning for 1344762 virus strains and unwanted programs.

                    Licensed to: Avira AntiVir PersonalEdition Classic
                    Serial number: 0000149996-ADJIE-0001
                    Platform: Windows XP
                    Windows version: (Service Pack 3) [5.1.2600]
                    Boot mode: Normally booted
                    Username: SYSTEM
                    Computer name: FB656F79DFBF450

                    Version information:
                    BUILD.DAT : 8.2.0.347 16934 Bytes 16/03/2009 14:45:00
                    AVSCAN.EXE : 8.1.4.10 315649 Bytes 26/11/2008 08:30:58
                    AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 08:56:40
                    LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 13:44:19
                    LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 08:58:52
                    ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 08:31:45
                    ANTIVIR1.VDF : 7.1.2.12 3336192 Bytes 11/02/2009 15:37:53
                    ANTIVIR2.VDF : 7.1.3.0 1330176 Bytes 01/04/2009 09:08:17
                    ANTIVIR3.VDF : 7.1.3.35 137728 Bytes 09/04/2009 09:07:01
                    Engineversion : 8.2.0.138
                    AEVDF.DLL : 8.1.1.0 106868 Bytes 31/01/2009 15:33:15
                    AESCRIPT.DLL : 8.1.1.73 373114 Bytes 04/04/2009 09:07:18
                    AESCN.DLL : 8.1.1.10 127348 Bytes 04/04/2009 09:07:17
                    AERDL.DLL : 8.1.1.3 438645 Bytes 21/11/2008 08:31:58
                    AEPACK.DLL : 8.1.3.12 397687 Bytes 04/04/2009 09:07:16
                    AEOFFICE.DLL : 8.1.0.36 196987 Bytes 27/02/2009 15:30:54
                    AEHEUR.DLL : 8.1.0.114 1700214 Bytes 04/04/2009 09:07:11
                    AEHELP.DLL : 8.1.2.2 119158 Bytes 27/02/2009 15:30:50
                    AEGEN.DLL : 8.1.1.33 340340 Bytes 04/04/2009 09:07:07
                    AEEMU.DLL : 8.1.0.9 393588 Bytes 21/11/2008 08:31:52
                    AECORE.DLL : 8.1.6.7 176502 Bytes 04/04/2009 09:07:06
                    AEBB.DLL : 8.1.0.3 53618 Bytes 21/11/2008 08:31:49
                    AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 09:40:05
                    AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 10:28:01
                    AVREP.DLL : 8.0.0.2 98344 Bytes 21/11/2008 08:31:48
                    AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 12:26:40
                    AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 09:29:23
                    AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 13:27:49
                    SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 18:28:02
                    SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 13:49:40
                    NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 13:05:10
                    RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 14:48:07
                    RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 14:34:37

                    Configuration settings for the scan:
                    Jobname..........................: Complete system scan
                    Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
                    Logging..........................: low
                    Primary action...................: interactive
                    Secondary action.................: ignore
                    Scan master boot sector..........: on
                    Scan boot sector.................: on
                    Boot sectors.....................: C:, E:,
                    Process scan.....................: on
                    Scan registry....................: on
                    Search for rootkits..............: off
                    Scan all files...................: Intelligent file selection
                    Scan archives....................: on
                    Recursion depth..................: 20
                    Smart extensions.................: on
                    Macro heuristic..................: on
                    File heuristic...................: medium

                    Start of the scan: jeudi 9 avril 2009 15:18

                    The scan of running processes will be started
                    Scan process 'avscan.exe' - '1' Module(s) have been scanned
                    Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                    Scan process 'thunderbird.exe' - '1' Module(s) have been scanned
                    Scan process 'wlcomm.exe' - '1' Module(s) have been scanned
                    Scan process 'firefox.exe' - '1' Module(s) have been scanned
                    Scan process 'NMIndexingService.exe' - '1' Module(s) have been scanned
                    Scan process 'hposts08.exe' - '1' Module(s) have been scanned
                    Scan process 'hpoevm08.exe' - '1' Module(s) have been scanned
                    Scan process 'hpotdd01.exe' - '1' Module(s) have been scanned
                    Scan process 'hpohmr08.exe' - '1' Module(s) have been scanned
                    Scan process 'emule.exe' - '1' Module(s) have been scanned
                    Scan process 'iPodService.exe' - '1' Module(s) have been scanned
                    Scan process 'Peer2Me.exe' - '1' Module(s) have been scanned
                    Scan process 'NMIndexStoreSvr.exe' - '1' Module(s) have been scanned
                    Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
                    Scan process 'NMBgMonitor.exe' - '1' Module(s) have been scanned
                    Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
                    Scan process 'mixer.exe' - '1' Module(s) have been scanned
                    Scan process 'itype.exe' - '1' Module(s) have been scanned
                    Scan process 'iTunesHelper.exe' - '1' Module(s) have been scanned
                    Scan process 'ADeck.exe' - '1' Module(s) have been scanned
                    Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                    Scan process 'alg.exe' - '1' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'GoogleUpdate.exe' - '1' Module(s) have been scanned
                    Scan process 'mDNSResponder.exe' - '1' Module(s) have been scanned
                    Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
                    Scan process 'avguard.exe' - '1' Module(s) have been scanned
                    Scan process 'explorer.exe' - '1' Module(s) have been scanned
                    Scan process 'sched.exe' - '1' Module(s) have been scanned
                    Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'lsass.exe' - '1' Module(s) have been scanned
                    Scan process 'services.exe' - '1' Module(s) have been scanned
                    Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                    Scan process 'csrss.exe' - '1' Module(s) have been scanned
                    Scan process 'smss.exe' - '1' Module(s) have been scanned
                    40 processes with 40 modules were scanned

                    Starting master boot sector scan:
                    Master boot sector HD0
                    [INFO] No virus was found!
                    Master boot sector HD1
                    [INFO] No virus was found!

                    Start scanning boot sectors:
                    Boot sector 'C:\'
                    [INFO] No virus was found!
                    Boot sector 'E:\'
                    [INFO] No virus was found!

                    Starting to scan the registry.
                    The registry was scanned ( '49' files ).

                    Starting the file scan:

                    Begin scan in 'C:\'
                    C:\pagefile.sys
                    [WARNING] The file could not be opened!
                    C:\System Volume Information\_restore{BC1D65A5-AB67-433B-94E5-FC15C6484E10}\RP0\A0000126.exe
                    [DETECTION] Contains recognition pattern of the WORM/Rbot.Gen worm
                    [NOTE] The file was deleted!
                    C:\System Volume Information\_restore{BC1D65A5-AB67-433B-94E5-FC15C6484E10}\RP31\A0003585.exe
                    [DETECTION] Contains recognition pattern of the WORM/Rbot.Gen worm
                    [NOTE] The file was deleted!
                    C:\System Volume Information\_restore{BC1D65A5-AB67-433B-94E5-FC15C6484E10}\RP31\A0003586.exe
                    [DETECTION] Contains recognition pattern of the WORM/Rbot.Gen worm
                    [NOTE] The file was deleted!
                    C:\System Volume Information\_restore{BC1D65A5-AB67-433B-94E5-FC15C6484E10}\RP31\A0003587.exe
                    [DETECTION] Contains recognition pattern of the WORM/Rbot.Gen worm
                    [NOTE] The file was deleted!
                    Begin scan in 'E:\' <My Book>
                    E:\Téléchargement\Programmes divers\Photoshop CS3 Patch US to French.zip
                    [0] Archive type: ZIP
                    --> Traduction_Us-Fr.exe
                    [DETECTION] Is the TR/PWS.Vipgsm.A Trojan
                    [NOTE] The file was deleted!

                    End of the scan: jeudi 9 avril 2009 15:59
                    Used time: 41:38 Minute(s)

                    The scan has been done completely.

                    4783 Scanning directories
                    160037 Files were scanned
                    5 viruses and/or unwanted programs were found
                    0 Files were classified as suspicious:
                    5 files were deleted
                    0 files were repaired
                    0 files were moved to quarantine
                    0 files were renamed
                    1 Files cannot be scanned
                    160031 Files not concerned
                    1158 Archives were scanned
                    1 Warnings
                    5 Notes
                    0
                    1. Contributeur sécurité
                      ok parfait

                      vire ce qui est en quanrantaine dans antivir

                      ______________
                      ceci
                      C:\System Volume Information\_restore

                      c'est ta restauration: pour virer ce qui est dedans:

                      Désactive ta restauration systeme puis redemarre ton ordi puis réactive là comme ceci:
                      https://www.informatruc.com

                      _______________

                      mettre a jour internet explorer
                      pour XP
                      http://download.microsoft.com/...

                      _____________

                      mettre à jour adobe reader puis supprimer les anciennes version via le panneau de configuration
                      https://acrobat.adobe.com/fr/fr/acrobat/pdf-reader.html

                      _____________

                      Mettre a jour java:
                      https://javara.fr.malavida.com/

                      Télécharge JavaRa.zip de Paul 'Prm753' McLain et Fred de Vries.
                      Décompresse le fichier sur ton bureau (clique droit > Extraire tout.)
                      Double-clique sur le répertoire JavaRa obtenu.
                      Puis double-clique sur le fichier JavaRa.exe (le .exe peut ne pas s'afficher)
                      Clique sur Search For Updates.
                      Sélectionne Update Using jucheck.exe puis clique sur Search.
                      Autorise le processus à se connecter s'il te le demande, clique sur Install et suis les instructions d'installation. Cela prendra quelques minutes.
                      Quand l'installation est terminée, revient à l'écran de JavaRa et clique sur Remove Older Versions.
                      Clique sur Oui pour confirmer. L'outil va travailler, clique ensuite sur Ok, puis une deuxième fois sur Ok.
                      Un rapport va s'ouvrir, copie-colle le dans ta prochaine réponse.
                      Note : le rapport se trouve aussi à la racine de la partition système, en général C:\ sous le nom JavaRa.log
                      (c:\JavaRa.log)
                      Ferme l'application.

                      si cela ne fonctionne pas

                      https://www.java.com/fr/download/windows_manual.jsp?locale=fr&host=www.java.com:80

                      tu peux désinstaller les vieilles versions.

                      __________________

                      Télécharge et installe UsbFix de C_XX & Chiquitine29

                      Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d avoir été infectés sans les ouvrir</gras>

                      # Double clic sur le raccourci UsbFix présent sur ton bureau .

                      # Choisi l option 1 ( Recherche )

                      # Laisse travailler l outil.

                      # Ensuite post le rapport UsbFix.txt qui apparaitra.

                      # Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

                      ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

                      # Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                      Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                      Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
                      0
                      1. Houla, mon pc est extrénemnet lent Oo et j'arrive pas a ouvrir internet explorer

                        enfin, je l'utilise pas puisque j'utilise mozilla mais bon ^^

                        voici dans le log de java

                        JavaRa 1.13 Removal Log.

                        Report follows after line.

                        ------------------------------------

                        The JavaRa removal process was started on Thu Apr 09 20:04:06 2009

                        There was an error removing C:\Program Files\Java\jre1.6.0_05. The error returned was 32.

                        Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}

                        Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBB}

                        Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC}

                        Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610005

                        Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610005

                        Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610005

                        Found and removed: SOFTWARE\Classes\JavaPlugin.160_05

                        Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_05

                        Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_05

                        Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}

                        Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610005

                        Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610005

                        Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610005

                        Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160050}

                        Found and removed: Software\Classes\JavaPlugin.160_05

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

                        Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

                        Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

                        Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

                        Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

                        Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

                        Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

                        Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_05

                        Found and removed: Software\JavaSoft\Java2D\1.6.0_05

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

                        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

                        Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_05\

                        Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_05\bin\

                        Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_07\bin\

                        ------------------------------------

                        Finished reporting.
                        0
                        1. ############################## [ UsbFix V3.005 ]

                          # User : Administrateur (Administrateurs) # FB656F79DFBF450
                          # Update on 08/04/09 by C_XX & Chiquitine29
                          # Start at: 20:10:17 | 9/04/2009

                          # Intel(R) Pentium(R) 4 CPU 2.60GHz
                          # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
                          # Internet Explorer 7.0.5730.13
                          # Windows Firewall Status : Enabled
                          # AV : Avira AntiVir PersonalEdition 8.0.1.30 [ Enabled | Updated ]

                          # A:\ # Lecteur de disquettes 3 ½ pouces
                          # C:\ # Disque fixe local # 74,52 Go (65,02 Go free) # NTFS
                          # D:\ # Disque CD-ROM
                          # E:\ # Disque fixe local # 465,76 Go (390,21 Go free) [My Book] # NTFS
                          # F:\ # Disque CD-ROM

                          ############################## [ Processus actifs ]

                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\csrss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                          C:\Program Files\Bonjour\mDNSResponder.exe
                          C:\Program Files\Google\Update\GoogleUpdate.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\alg.exe
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\Program Files\iPod\bin\iPodService.exe
                          C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
                          C:\Program Files\Mozilla Thunderbird\thunderbird.exe
                          C:\Program Files\Mozilla Firefox\firefox.exe
                          C:\WINDOWS\system32\msiexec.exe
                          C:\WINDOWS\system32\wbem\wmiprvse.exe

                          ################## [ Registre # Startup ]

                          HKCU_Main: "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
                          HKCU_Main: "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                          HKCU_Main: "Start Page"="https://www.google.be/?gws_rd=ssl"
                          HKCU_Main: "Window Title"="Windows Yoshi Ultimate "
                          HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
                          HKLM_Run: avgnt="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                          HKLM_Run: AudioDeck=C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe 1
                          HKLM_Run: NeroFilterCheck=C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
                          HKLM_Run: QuickTime Task="C:\Program Files\QuickTime\qttask.exe" -atboottime
                          HKLM_Run: iTunesHelper="C:\Program Files\iTunes\iTunesHelper.exe"
                          HKLM_Run: itype="C:\Program Files\Microsoft IntelliType Pro\itype.exe"
                          HKLM_Run: C-Media Mixer=Mixer.exe /startup
                          HKLM_Run: TQ566808="D:\Setup.exe"
                          HKLM_Run: Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                          HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
                          HKCU_Run: ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe
                          HKCU_Run: BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}="C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
                          HKCU_Run: msnmsgr="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                          HKCU_Run: Peer2Me="C:\Program Files\Peer2Me\Peer2Me.exe"
                          HKCU_Run: eMuleAutoStart=C:\Program Files\eMule\emule.exe -AutoStart
                          HKCU_plorer: "NoDriveTypeAutoRun"=dword:00000091
                          HKLM_plorer: "HonorAutoRunSetting"=dword:00000001

                          ################## [ Informations ]

                          # Contenu de l'autorun E:\autorun.inf
                          [autorun]
                          open=wd_windows_tools\setup.exe
                          ICON=AUTORUN\WDLOGO.ICO

                          ################## [ Fichiers # Dossiers infectieux ]

                          Found ! E:\autorun.inf
                          Found ! E:\Setup.exe

                          ################## [ Registre # Clés infectieuses ]

                          # -> Not Found !

                          ################## [ Registre # Mountpoint2 ]

                          Found ! HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E\Shell\AutoRun\command
                          Found ! HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{18d032d8-b7b1-11dd-8221-001111761a86}\Shell\AutoRun\command

                          ################## [ ! Fin du rapport # UsbFix V3.005 ! ]
                          0
                          1. Contributeur sécurité
                            Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d avoir été infectés sans les ouvrir</gras>

                            # Double clic sur le raccourci UsbFix présent sur ton bureau

                            # choisi l option 2 ( Suppression )

                            # Ton bureau disparaitra et le pc redémarrera .

                            # Au redémarrage , UsbFix scannera ton pc , laisse travailler l outil.

                            # Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .

                            # Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

                            ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

                            ______________________

                            Télécharge ToolsCleaner sur ton bureau.
                            --> http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
                            # Clique sur Recherche et laisse le scan agir ...
                            # Clique sur Suppression pour finaliser.
                            # Tu peux, si tu le souhaites, te servir des Options facultatives.
                            # Clique sur Quitter pour obtenir le rapport.
                            # Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
                            0
                            1. Voila le rapport,

                              il a l'air d'avoir deleter des trucs^^

                              ############################## [ UsbFix V3.005 ]

                              # User : Administrateur (Administrateurs) # FB656F79DFBF450
                              # Update on 08/04/09 by C_XX & Chiquitine29
                              # Start at: 22:29:04 | 9/04/2009

                              # Intel(R) Pentium(R) 4 CPU 2.60GHz
                              # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
                              # Internet Explorer 7.0.5730.13
                              # Windows Firewall Status : Enabled
                              # AV : Avira AntiVir PersonalEdition 8.0.1.30 [ Enabled | Updated ]

                              # A:\ # Lecteur de disquettes 3 ½ pouces
                              # C:\ # Disque fixe local # 74,52 Go (63,89 Go free) # NTFS
                              # D:\ # Disque CD-ROM
                              # E:\ # Disque fixe local # 465,76 Go (390,21 Go free) [My Book] # NTFS
                              # F:\ # Disque CD-ROM

                              ############################## [ Processus actifs ]

                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\csrss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\logonui.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                              C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              C:\Program Files\Bonjour\mDNSResponder.exe
                              C:\Program Files\Google\Update\GoogleUpdate.exe
                              C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              C:\Program Files\Google\Update\GoogleUpdate.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\wbem\wmiprvse.exe
                              C:\WINDOWS\System32\alg.exe

                              ################## [ Fichiers # Dossiers infectieux ]

                              Deleted ! E:\autorun.inf
                              Deleted ! E:\Setup.exe

                              ################## [ Registre # Clés infectieuses ]

                              # -> Not Found !

                              ################## [ Registre # Mountpoint2 ]

                              Deleted ! HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\Shell\AutoRun\command

                              ################## [ Listing des fichiers présent ]

                              C:\AUTOEXEC.BAT
                              C:\NTDETECT.COM
                              C:\WGASetup.exe
                              C:\boot.ini

                              ################## [ ! Fin du rapport # UsbFix V3.005 ! ]
                              0
                              1. Contributeur sécurité
                                ok remets un rapport rsit et dis tes problèmes actuels
                                0
                            2. j'avais oublié hier

                              voici tCleaner

                              --> Recherche:

                              C:\UsbFix.txt: trouvé !
                              C:\SDFIX: trouvé !
                              C:\UsbFix: trouvé !
                              C:\Rsit: trouvé !
                              C:\Documents and Settings\Administrateur\Bureau\UsbFix.exe: trouvé !
                              C:\Documents and Settings\Administrateur\Bureau\UsbFix.lnk: trouvé !
                              C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\UsbFix: trouvé !
                              C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\UsbFix\UsbFix.lnk: trouvé !
                              C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
                              C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
                              C:\Program Files\Trend Micro\HijackThis: trouvé !
                              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
                              C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !
                              C:\UsbFix\Tools\UsbFix.exe: trouvé !

                              ---------------------------------
                              --> Suppression:

                              C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
                              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
                              C:\UsbFix.txt: supprimé !
                              C:\Documents and Settings\Administrateur\Bureau\UsbFix.exe: supprimé !
                              C:\Documents and Settings\Administrateur\Bureau\UsbFix.lnk: supprimé !
                              C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\UsbFix\UsbFix.lnk: supprimé !
                              C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
                              C:\UsbFix\Tools\UsbFix.exe: supprimé !
                              C:\SDFIX: supprimé !
                              C:\UsbFix: ERREUR DE SUPPRESSION !!
                              C:\Rsit: supprimé !
                              C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\UsbFix: supprimé !
                              C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
                              C:\Program Files\Trend Micro\HijackThis: supprimé !

                              Et voici le rapport de rist

                              Logfile of random's system information tool 1.06 (written by random/random)
                              Run by Administrateur at 2009-04-10 11:43:58
                              Microsoft Windows XP Professionnel Service Pack 3
                              System drive C: has 65 GB (86%) free of 76 GB
                              Total RAM: 495 MB (34% free)

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 11:46:45, on 10/04/2009
                              Platform: Windows XP SP3 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v7.00 (7.00.6000.20978)
                              Boot mode: Normal

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                              C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              C:\Program Files\Bonjour\mDNSResponder.exe
                              C:\Program Files\Google\Update\GoogleUpdate.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\explorer.exe
                              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                              C:\WINDOWS\system32\ctfmon.exe
                              C:\Program Files\Windows Live\Contacts\wlcomm.exe
                              C:\Program Files\Mozilla Thunderbird\thunderbird.exe
                              C:\Program Files\Mozilla Firefox\firefox.exe
                              C:\Documents and Settings\Administrateur\Bureau\RSIT.exe
                              C:\Program Files\trend micro\Administrateur.exe

                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                              O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                              O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
                              O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\styler\TB\StylerTB.dll
                              O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                              O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe 1
                              O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
                              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                              O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
                              O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
                              O4 - HKLM\..\Run: [TQ566808] "D:\Setup.exe"
                              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                              O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu
                              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                              O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
                              O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                              O4 - HKCU\..\Run: [Peer2Me] "C:\Program Files\Peer2Me\Peer2Me.exe"
                              O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
                              O4 - HKUS\S-1-5-19\..\RunOnce: [vista_sound_register.inf] rundll32.exe setupapi.dll,InstallHinfSection DefaultInstall 128 C:\WINDOWS\Media\vista_sound_register.inf (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\RunOnce: [vista_sound_register.inf] rundll32.exe setupapi.dll,InstallHinfSection DefaultInstall 128 C:\WINDOWS\Media\vista_sound_register.inf (User 'SERVICE RÉSEAU')
                              O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                              O4 - Global Startup: hp psc 1000 series.lnk = ?
                              O4 - Global Startup: hpoddt01.exe.lnk = ?
                              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
                              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
                              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O14 - IERESET.INF: START_PAGE_URL=https://www.google.fr/?gws_rd=ssl
                              O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
                              O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
                              O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
                              O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                              O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                              O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                              O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                              O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
                              O23 - Service: Google Update Service (gupdate1c9878c3befb068) (gupdate1c9878c3befb068) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                              O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                              O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
                              O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
                              O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
                              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                              0
                              1. Contributeur sécurité
                                pour finir:

                                télécharge OTMoveIt

                                http://oldtimer.geekstogo.com/OTMoveIt3.exe

                                (de Old_Timer) sur ton Bureau.
                                double-clique sur OTMoveIt.exe pour le lancer.
                                copie la liste qui se trouve en citation ci-dessous,
                                et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

                                :files
                                D:\Setup.exe
                                :reg
                                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                                "TQ566808"=-

                                clique sur MoveIt! pour lancer la suppression.
                                le résultat apparaitra dans le cadre "Results".
                                clique sur Exit pour fermer.
                                poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

                                il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

                                ____________________________

                                sinon internet explorer 8 est sorti
                                https://support.microsoft.com/fr-fr/allproducts

                                mettre a jour adobe reader avec la version 9
                                https://acrobat.adobe.com/fr/fr/acrobat/pdf-reader.html

                                et mettre a jour java avec javara:
                                https://javara.fr.malavida.com/

                                ________________________________

                                voilà tu peux virer ce qui a été utilisé

                                bonne suite!!!!

                                rq

                                pour protéger gratos ton ordi
                                http://www.commentcamarche.net/telecharger/logiciel 4 securite

                                mettre un antivirus

                                ANTIVIR
                                https://www.malekal.com/avira-free-security-antivirus-gratuit/ (merci Malekal)
                                -------------
                                des anti-espions :
                                MALWAREBYTE ANTIMALWARE + SPYBOT
                                +
                                SPYWAREBLASTER pour immuniser le système contre vundo notamment mais en anglais (mais facile d'utilisation : il suffit de faire "update" pour mettre à jour tous les mois et ensuite" enable all protection" pour immuniser)...

                                --------
                                un pare feu :
                                (celui de Windows) ou mieux COMODO ou KERIO ou JETICO ou ZONE ALARM (mettre que le parefeu gratuit)

                                http://www.clubic.com/telecharger-fiche11071-sunbelt-persona­l-firewall-e(...)
                                https://manuelsdaide.com/contact/
                                http://www.open-files.com/forum/index.php?showtopic=29277
                                https://www.commentcamarche.net/telecharger/ 157 zonealarm

                                -----------

                                CCLEANER pour effacer les traces de surf
                                0
                                1. Voila le rapport

                                  ========== FILES ==========
                                  File/Folder D:\Setup.exe not found.
                                  ========== REGISTRY ==========
                                  Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersio­n\Run not found.

                                  OTMoveIt3 by OldTimer - Version 1.0.10.0 log created on 04102009_153328

                                  Sinon, pour IE, la version 8 ne veux pas s'installé

                                  Pour adobe, c'est la version 9.1 que j'ai

                                  Pour java c'est fait aussi

                                  Ccleaner je l'avais déjà

                                  Encore merci à toi :)
                                  0
                                  1. Contributeur sécurité
                                    ok parfait . Tu retentera ie 8 plus tard peut être il passera sinon pas grave ou surf avec un autre comme firefox ou opéra ou safari
                                    0