Backdoor.Bot.68232 et Backdood.Bot.42447

Bonjour,
j'ai fait lancer mon antivirus et il a détecté 3 virus : Backdoor.Bot.68232 et Backdood.Bot.42447 (celui-là 2fois).
Je ne sais pas comment me débarrasser de ces virus... étant donné que mon antivirus n'y arrive pas =(
Le virus est dans les archives. (je ne sais pas si cela change quelque chose)

Mon antivirus est : BitDefender Security 2008

Je travaille sous Windows Vista.

et je suis une méga grande débutante !

donc si il y a quelqu'un qui sait comment faire pour me débarrasser de ces virus, dites-le-moi ! Merci

A noter, que je suis très très débutante en informatique...

encore merci pour votre aide
Configuration: Windows Vista
Firefox 3.0.4

33 réponses

Résumé de la discussion

Des utilisateurs signalent la détection par BitDefender Security 2008 de Backdoor.Bot.68232 et Backdoor.Bot.42447 dans des archives sous Windows Vista et recherchent une désinfection efficace. Plusieurs réponses proposent des démarches concrètes, comme passer par Ajout/Suppression de programmes pour désinstaller des éléments indésirables et utiliser des outils externes tels que GenProc pour générer des rapports système. D'autres échanges évoquent des précautions spécifiques sous Vista, notamment la désactivation du contrôle de comptes utilisateurs lors des manipulations et la consultation des procédures avant toute action. Enfin, des extraits de rapports de désinstallation et des listes de programmes montrent les difficultés sans indication d'une solution immédiate.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Bonsoir,

    Pour commencer : faire un petit nettoyage de l'ordi et du registre avec Ccleaner, regarde bien le Tuto CCleaner

    Ensuite :

    Télécharge le fichier d'installation d'HijackThis.

    Enregistre HJTInstall.exe sur ton bureau.

    Renomme Hijackthis en Tutu

    Double-clique sur HJTInstall.exe (tutu) pour lancer le programme

    Par défaut, il s'installera là :
    C:\Program Files\Trend Micro\HijackThis

    Accepte la licence en cliquant sur le bouton "I Accept"

    Choisis l'option "Do a system scan and save a log file"

    Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note

    Clique sur "Edition -> Sélectionner tout", puis sur "Edition -> Copier" pour copier tout le contenu du rapport

    Colle le rapport que tu viens de copier sur ce forum

    Ne fixe encore AUCUNE ligne, cela pourrait empêcher ton PC de fonctionner correctement

    Tutoriaux (ne fixe rien pour le moment !!)

    Pour ceux qui ont vista, ne pas oublier de désactiver Le contrôle des comptes utilisateurs

    0
    1. merci pour ton aide... je vais essayer...
      0
      1. voilà ce que j'obtiens comme rapport:

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 20:55:33, on 18/05/2009
        Platform: Windows Vista (WinNT 6.00.1904)
        MSIE: Internet Explorer v7.00 (7.00.6000.16830)
        Boot mode: Normal

        Running processes:
        C:\Windows\system32\Dwm.exe
        C:\Windows\system32\taskeng.exe
        C:\Windows\Explorer.EXE
        C:\Program Files\Windows Defender\MSASCui.exe
        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        C:\Windows\System32\rundll32.exe
        C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
        C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
        C:\Program Files\CyberLink\MagicSports\Kernel\MagicSports\MSPMirage.exe
        C:\Windows\System32\rundll32.exe
        C:\Program Files\Picasa2\PicasaMediaDetector.exe
        C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
        C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
        C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
        C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe
        C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\Program Files\HiYo\Bin\HiYo.exe
        C:\Program Files\Kiwee Toolbar\2.8.167\kwtbaim.exe
        C:\Program Files\Windows Sidebar\sidebar.exe
        C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
        C:\Windows\ehome\ehtray.exe
        C:\Users\Public\Downloads\VeohClient.exe
        C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
        C:\Program Files\Windows Media Player\wmpnscfg.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        C:\Users\Catherine\logiciel souris\SetPoint\SetPoint.exe
        C:\Windows\ehome\ehmsas.exe
        C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
        C:\Windows\system32\wbem\unsecapp.exe
        C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
        C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Windows\system32\wuauclt.exe
        C:\Windows\system32\conime.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Windows\system32\SearchFilterHost.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://format.packardbell.com/cgi-bin/redirect/?country=BEFR&range=AD&phase=8&key=IESTART
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://format.packardbell.com/cgi-bin/redirect/?country=BEFR&range=AD&phase=8&key=IESTART
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
        R3 - URLSearchHook: AGSearchHook Class - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - C:\Program Files\AGI\common\agcutils.dll
        O1 - Hosts: ::1 localhost
        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: AGSearchHook Class - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - C:\Program Files\AGI\common\agcutils.dll
        O2 - BHO: Kiwee Toolbar - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - C:\Program Files\Kiwee Toolbar\2.8.167\KiweeIEToolbar.dll
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
        O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
        O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Users\Public\Downloads\Plugins\reg\VeohToolbar.dll
        O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
        O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
        O3 - Toolbar: Kiwee Toolbar - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - C:\Program Files\Kiwee Toolbar\2.8.167\KiweeIEToolbar.dll
        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
        O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
        O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
        O4 - HKLM\..\Run: [MSPService] C:\Program Files\CyberLink\MagicSports\Kernel\MagicSports\MSPMirage.exe
        O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
        O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
        O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
        O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe"
        O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [zzz_ImInstaller_IncrediMail] "C:\Users\Catherine\AppData\Local\Temp\ImInstaller\IncrediMail\incredimail_install.exe" -startup -product IncrediMail -report -ffmsc 12345
        O4 - HKLM\..\Run: [HiYo] C:\Program Files\HiYo\bin\HiYo.exe /RunFromStartup
        O4 - HKLM\..\Run: [KiweeHook] "C:\Program Files\Kiwee Toolbar\2.8.167\kwtbaim.exe"
        O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
        O4 - HKLM\..\Run: [HPAIO_PrintFolderMgr] C:\Windows\system32\spool\DRIVERS\W32X86\hpoopm07.exe
        O4 - HKLM\..\Run: [SetupType] Portable
        O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
        O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
        O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
        O4 - HKCU\..\Run: [Veoh] "C:\Users\Public\Downloads\VeohClient.exe" /VeohHide
        O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] c:\program files\uniblue\registrybooster 2\StartRegistryBooster.exe
        O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
        O4 - HKCU\..\Run: [VeohPlugin] "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
        O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
        O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        O4 - Global Startup: Logitech SetPoint.lnk = C:\Users\Catherine\logiciel souris\SetPoint\SetPoint.exe
        O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
        O4 - Global Startup: StupAssist.lnk = C:\Program Files\Common Files\Nikon\Utilities\StupAssist.exe
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
        O13 - Gopher Prefix:
        O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
        O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
        O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
        O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
        O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Program Files\AGI\common\win32\PythonService.exe
        O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Unknown owner - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe (file missing)
        O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Unknown owner - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe (file missing)
        O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
        O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
        O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
        O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
        O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
        O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
        O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
        O23 - Service: Start BT in service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
        O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
        O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
        O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
        O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
        0
        1. Voilà ce que j'obtiens:

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 21:07:45, on 18/05/2009
          Platform: Windows Vista (WinNT 6.00.1904)
          MSIE: Internet Explorer v7.00 (7.00.6000.16830)
          Boot mode: Normal

          Running processes:
          C:\Windows\system32\Dwm.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\Explorer.EXE
          C:\Program Files\Windows Defender\MSASCui.exe
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\Windows\System32\rundll32.exe
          C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
          C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
          C:\Program Files\CyberLink\MagicSports\Kernel\MagicSports\MSPMirage.exe
          C:\Program Files\Picasa2\PicasaMediaDetector.exe
          C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
          C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
          C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe
          C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
          C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
          C:\Program Files\QuickTime\qttask.exe
          C:\Program Files\HiYo\Bin\HiYo.exe
          C:\Program Files\Kiwee Toolbar\2.8.167\kwtbaim.exe
          C:\Program Files\Windows Sidebar\sidebar.exe
          C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
          C:\Windows\ehome\ehtray.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
          C:\Users\Public\Downloads\VeohClient.exe
          C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
          C:\Program Files\Windows Media Player\wmpnscfg.exe
          C:\Windows\ehome\ehmsas.exe
          C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
          C:\Windows\System32\rundll32.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          C:\Users\Catherine\logiciel souris\SetPoint\SetPoint.exe
          C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
          C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
          C:\Windows\system32\rundll32.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://format.packardbell.com/cgi-bin/redirect/?country=BEFR&range=AD&phase=8&key=IESTART
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://format.packardbell.com/cgi-bin/redirect/?country=BEFR&range=AD&phase=8&key=IESTART
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          R3 - URLSearchHook: AGSearchHook Class - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - C:\Program Files\AGI\common\agcutils.dll
          O1 - Hosts: ::1 localhost
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: AGSearchHook Class - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - C:\Program Files\AGI\common\agcutils.dll
          O2 - BHO: Kiwee Toolbar - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - C:\Program Files\Kiwee Toolbar\2.8.167\KiweeIEToolbar.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
          O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
          O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Users\Public\Downloads\Plugins\reg\VeohToolbar.dll
          O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
          O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
          O3 - Toolbar: Kiwee Toolbar - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - C:\Program Files\Kiwee Toolbar\2.8.167\KiweeIEToolbar.dll
          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
          O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
          O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
          O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
          O4 - HKLM\..\Run: [MSPService] C:\Program Files\CyberLink\MagicSports\Kernel\MagicSports\MSPMirage.exe
          O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
          O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
          O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
          O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe"
          O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [zzz_ImInstaller_IncrediMail] "C:\Users\Catherine\AppData\Local\Temp\ImInstaller\IncrediMail\incredimail_install.exe" -startup -product IncrediMail -report -ffmsc 12345
          O4 - HKLM\..\Run: [HiYo] C:\Program Files\HiYo\bin\HiYo.exe /RunFromStartup
          O4 - HKLM\..\Run: [KiweeHook] "C:\Program Files\Kiwee Toolbar\2.8.167\kwtbaim.exe"
          O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
          O4 - HKLM\..\Run: [HPAIO_PrintFolderMgr] C:\Windows\system32\spool\DRIVERS\W32X86\hpoopm07.exe
          O4 - HKLM\..\Run: [SetupType] Portable
          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
          O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
          O4 - HKCU\..\Run: [Veoh] "C:\Users\Public\Downloads\VeohClient.exe" /VeohHide
          O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] c:\program files\uniblue\registrybooster 2\StartRegistryBooster.exe
          O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
          O4 - HKCU\..\Run: [VeohPlugin] "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
          O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
          O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          O4 - Global Startup: Logitech SetPoint.lnk = C:\Users\Catherine\logiciel souris\SetPoint\SetPoint.exe
          O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
          O13 - Gopher Prefix:
          O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
          O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
          O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
          O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
          O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Program Files\AGI\common\win32\PythonService.exe
          O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Unknown owner - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe (file missing)
          O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Unknown owner - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe (file missing)
          O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
          O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
          O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
          O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
          O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
          O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
          O23 - Service: Start BT in service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
          O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
          O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
          O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
          O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
          0
          1. Contributeur sécurité
            Télécharge GenProc sur ton bureau

            Double-clique sur GenProc.exe

            et poste le contenu du rapport qui s'ouvre à la suite de la question êtes vous aider par quelqu'un, répondre oui. Merci.

            Si pas de rapport .txt, regarder sur le bureau, il doit y avoir une icône Genproc qui renvoie sur internet avec la procédure.

            Voir comment utiliser GenProc

            Pour ceux qui ont Vista, ne pas oublier de désactiver Le contrôle des comptes utilisateurs

            IMPORTANT : Poste la procédure Genproc et ne fais rien d'autre pour l'instant ( souvent il faut ajouter des consignes à la manipe indiquée pour que cela fonctionne parfaitement )

            0
            1. Bonjour. Pourquoi demander un rapport genproc puisque le hijackthis montre des infections s'il vous plait ? ou sinon pourquoi demander un rapport hijackthis si c'est pour ne pas le lire ?

              Dis moi merci.
              0
          2. voilà ce que j'obtiens avec le programme que tu m'as dit de télécharger :

            Rapport GenProc 2.565 [1]
            @ mar. 19/05/2009 à 9:50:15
            @ Windows Vista "CSDVersion" does not exist
            @ Mozilla Firefox (3.0.4) [Navigateur par défaut]

            Dans CCleaner, clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures".
            Par la suite, laisse-le avec ses réglages par défaut. C'est tout.

            # Etape 1/ Télécharge :

            - Toolbar-S&D https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2 (Team IDN) sur ton Bureau.

            Redémarre en mode sans échec comme indiqué ici https://www.wekyo.com/demarrer-le-pc-en-mode-sans-echec-windows-7-et-8/ ; Choisis ta session courante *** Catherine *** (pour retrouver le rapport, clique sur le raccourci "Rapport GenProc[1]" sur ton bureau).

            # Etape 2/

            Lance Toolbar-S&D situé sur le Bureau.
            Tape sur "2" puis valide en appuyant sur "Entrée". Ne ferme pas la fenêtre lors de la suppression.

            # Etape 3/

            Lance CCleaner : "Nettoyeur"/"lancer le nettoyage" et c'est tout.

            # Etape 4/

            Redémarre normalement et poste, dans la même réponse :

            - Le contenu du rapport TB.txt situé dans C:\ ;
            - Un nouveau rapport HijackThis http://forum.telecharger.01net.com/forum/high-tech/PRODUITS/Questions-techniques/hijackthis-version-install-sujet_199100_1.htm ;
            - Un nouveau rapport GenProc ;

            Précise les difficultés que tu as eu (ce que tu n'as pas pu faire...) ainsi que l'évolution de la situation.

            ----------------------------------------------------------------------
            Sites officiels GenProc : www.alt-shift-return.org et www.genproc.com
            ----------------------------------------------------------------------

            ~~ Arguments de la procédure ~~

            # Détections [1] GenProc 2.565 mar. 19/05/2009 à 9:48:19
            Toolbar:le mar. 19/05/2009 à 9:48:46 "C:\Program Files\Kiwee Toolbar"

            et comme tu me l'as demandé, je n'ai rien fait .... rien de ce qui est écrit

            Encore merci pour ton aide...
            0
            1. Contributeur sécurité
              ok là tu peux me faire la procédure genproc et me poster les rapports.
              0
              1. ok...je ferais cela ce soir car maintenant je dois partir...
                et je te tiens au courant
                0
                1. voilà, j'ai fait tout ce qui est écrit et ce que j'obtiens:

                  Rapport TB

                  -----------\\ ToolBar S&D 1.2.8 XP/Vista

                  Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6000 )
                  X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU T7500 @ 2.20GHz )
                  BIOS : Ver 1.00PARTTBL
                  USER : Catherine ( Administrator )
                  BOOT : Fail-safe boot
                  Antivirus : Bitdefender Antivirus 8.0 (Activated)
                  Firewall : Norton 360 2007 (Activated)
                  C:\ (Local Disk) - NTFS - Total:178 Go (Free:77 Go)
                  D:\ (CD or DVD)

                  "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
                  Option : [2] ( mar. 19/05/2009|18:48 )

                  [ UAC => 0 ]

                  -----------\\ SUPPRESSION

                  Supprime! - C:\ProgramData\Kiwee Toolbar\config
                  Supprime! - C:\ProgramData\Kiwee Toolbar\images
                  Supprime! - C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Kiwee Toolbar
                  Supprime! - C:\Program Files\Kiwee Toolbar\2.8.167
                  Supprime! - C:\ProgramData\Kiwee Toolbar
                  Supprime! - C:\Program Files\Kiwee Toolbar

                  -----------\\ Recherche de Fichiers / Dossiers ...

                  -----------\\ [..\Internet Explorer\Main]

                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                  "Local Page"="C:\\Windows\\system32\\blank.htm"
                  "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                  "Start Page"="http://format.packardbell.com/cgi-bin/redirect/?country=BEFR&range=AD&phase=8&key=IESTART"
                  "Default_Page_URL"="http://format.packardbell.com/cgi-bin/redirect/?country=BEFR&range=AD&phase=8&key=IESTART"
                  "Url"="https://www.msn.com/fr-fr/actualite/"

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                  "Start Page"="https://www.msn.com/fr-fr/"
                  "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
                  "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                  "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"

                  --------------------\\ Recherche d'autres infections

                  Aucune autre infection trouvée !

                  [ UAC => 1 ]

                  1 - "C:\ToolBar SD\TB_1.txt" - mar. 19/05/2009|18:49 - Option : [2]

                  -----------\\ Fin du rapport a 18:49:57,12

                  Rapport Hijackthis
                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 19:03:11, on 19/05/2009
                  Platform: Windows Vista (WinNT 6.00.1904)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16830)
                  Boot mode: Normal

                  Running processes:
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\Explorer.EXE
                  C:\Program Files\Windows Defender\MSASCui.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\system32\wbem\unsecapp.exe
                  C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  C:\Windows\System32\rundll32.exe
                  C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
                  C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                  C:\Program Files\CyberLink\MagicSports\Kernel\MagicSports\MSPMirage.exe
                  C:\Program Files\Picasa2\PicasaMediaDetector.exe
                  C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                  C:\Windows\System32\rundll32.exe
                  C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                  C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe
                  C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
                  C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
                  C:\Program Files\QuickTime\qttask.exe
                  C:\Program Files\HiYo\Bin\HiYo.exe
                  C:\Program Files\Windows Sidebar\sidebar.exe
                  C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                  C:\Windows\ehome\ehtray.exe
                  C:\Users\Public\Downloads\VeohClient.exe
                  C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  C:\Users\Catherine\logiciel souris\SetPoint\SetPoint.exe
                  C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
                  C:\Windows\ehome\ehmsas.exe
                  C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
                  C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
                  C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  C:\Windows\system32\wuauclt.exe
                  C:\Windows\system32\SearchFilterHost.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://format.packardbell.com/...
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://format.packardbell.com/cgi-bin/redirect/?country=BEFR&range=AD&phase=8&key=IESTART
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                  R3 - URLSearchHook: AGSearchHook Class - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - C:\Program Files\AGI\common\agcutils.dll
                  O1 - Hosts: ::1 localhost
                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: AGSearchHook Class - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - C:\Program Files\AGI\common\agcutils.dll
                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                  O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll
                  O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Users\Public\Downloads\Plugins\reg\VeohToolbar.dll
                  O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
                  O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
                  O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                  O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
                  O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                  O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                  O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
                  O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                  O4 - HKLM\..\Run: [MSPService] C:\Program Files\CyberLink\MagicSports\Kernel\MagicSports\MSPMirage.exe
                  O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
                  O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
                  O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
                  O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                  O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe"
                  O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
                  O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                  O4 - HKLM\..\Run: [zzz_ImInstaller_IncrediMail] "C:\Users\Catherine\AppData\Local\Temp\ImInstaller\IncrediMail\incredimail_install.exe" -startup -product IncrediMail -report -ffmsc 12345
                  O4 - HKLM\..\Run: [HiYo] C:\Program Files\HiYo\bin\HiYo.exe /RunFromStartup
                  O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
                  O4 - HKLM\..\Run: [HPAIO_PrintFolderMgr] C:\Windows\system32\spool\DRIVERS\W32X86\hpoopm07.exe
                  O4 - HKLM\..\Run: [SetupType] Portable
                  O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                  O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                  O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                  O4 - HKCU\..\Run: [Veoh] "C:\Users\Public\Downloads\VeohClient.exe" /VeohHide
                  O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] c:\program files\uniblue\registrybooster 2\StartRegistryBooster.exe
                  O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
                  O4 - HKCU\..\Run: [VeohPlugin] "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                  O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
                  O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  O4 - Global Startup: Logitech SetPoint.lnk = C:\Users\Catherine\logiciel souris\SetPoint\SetPoint.exe
                  O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                  O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                  O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
                  O13 - Gopher Prefix:
                  O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
                  O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                  O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                  O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
                  O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
                  O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Program Files\AGI\common\win32\PythonService.exe
                  O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Unknown owner - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe (file missing)
                  O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Unknown owner - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe (file missing)
                  O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                  O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                  O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                  O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
                  O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
                  O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                  O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                  O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                  O23 - Service: Start BT in service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
                  O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                  O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                  O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
                  O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
                  0
                  1. Contributeur sécurité
                    ok tu peux refaire cette procédure.
                    0
                    1. Contributeur sécurité
                      Ensuite un tour dans ajout/suppression de programmes et tu désinstalles HiYo
                      0
                      1. coucou !
                        je viens d'installer le programme "rustbfix" et j'obtiens ceci:

                        ************************* Rustock.b-fix v. 1.01 -- By ejvindh *************************
                        mar. 19/05/2009 19:56:52,08

                        No Rustock.b-rootkits found

                        ******************************* End of Logfile ********************************

                        et viens de relancer Hijackis et me met ceci:

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 19:57:31, on 19/05/2009
                        Platform: Windows Vista (WinNT 6.00.1904)
                        MSIE: Internet Explorer v7.00 (7.00.6000.16830)
                        Boot mode: Normal

                        Running processes:
                        C:\Windows\system32\Dwm.exe
                        C:\Windows\Explorer.EXE
                        C:\Program Files\Windows Defender\MSASCui.exe
                        C:\Windows\system32\taskeng.exe
                        C:\Windows\system32\wbem\unsecapp.exe
                        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                        C:\Windows\System32\rundll32.exe
                        C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
                        C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                        C:\Program Files\CyberLink\MagicSports\Kernel\MagicSports\MSPMirage.exe
                        C:\Program Files\Picasa2\PicasaMediaDetector.exe
                        C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                        C:\Windows\System32\rundll32.exe
                        C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                        C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe
                        C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
                        C:\Program Files\QuickTime\qttask.exe
                        C:\Program Files\HiYo\Bin\HiYo.exe
                        C:\Program Files\Windows Sidebar\sidebar.exe
                        C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                        C:\Windows\ehome\ehtray.exe
                        C:\Users\Public\Downloads\VeohClient.exe
                        C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
                        C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                        C:\Users\Catherine\logiciel souris\SetPoint\SetPoint.exe
                        C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
                        C:\Windows\ehome\ehmsas.exe
                        C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
                        C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
                        C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
                        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                        C:\Windows\system32\wuauclt.exe
                        C:\Windows\system32\conime.exe
                        C:\Windows\system32\rundll32.exe
                        C:\Program Files\Mozilla Firefox\firefox.exe
                        C:\Windows\system32\SearchFilterHost.exe
                        C:\Windows\notepad.exe
                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://format.packardbell.com/...
                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://format.packardbell.com/...
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                        R3 - URLSearchHook: AGSearchHook Class - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - C:\Program Files\AGI\common\agcutils.dll
                        O1 - Hosts: ::1 localhost
                        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                        O2 - BHO: AGSearchHook Class - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - C:\Program Files\AGI\common\agcutils.dll
                        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                        O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll
                        O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Users\Public\Downloads\Plugins\reg\VeohToolbar.dll
                        O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
                        O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
                        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                        O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
                        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                        O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                        O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
                        O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                        O4 - HKLM\..\Run: [MSPService] C:\Program Files\CyberLink\MagicSports\Kernel\MagicSports\MSPMirage.exe
                        O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
                        O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
                        O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
                        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                        O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe"
                        O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
                        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                        O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                        O4 - HKLM\..\Run: [zzz_ImInstaller_IncrediMail] "C:\Users\Catherine\AppData\Local\Temp\ImInstaller\IncrediMail\incredimail_install.exe" -startup -product IncrediMail -report -ffmsc 12345
                        O4 - HKLM\..\Run: [HiYo] C:\Program Files\HiYo\bin\HiYo.exe /RunFromStartup
                        O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
                        O4 - HKLM\..\Run: [HPAIO_PrintFolderMgr] C:\Windows\system32\spool\DRIVERS\W32X86\hpoopm07.exe
                        O4 - HKLM\..\Run: [SetupType] Portable
                        O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                        O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                        O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                        O4 - HKCU\..\Run: [Veoh] "C:\Users\Public\Downloads\VeohClient.exe" /VeohHide
                        O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] c:\program files\uniblue\registrybooster 2\StartRegistryBooster.exe
                        O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
                        O4 - HKCU\..\Run: [VeohPlugin] "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
                        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                        O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
                        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                        O4 - Global Startup: Logitech SetPoint.lnk = C:\Users\Catherine\logiciel souris\SetPoint\SetPoint.exe
                        O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
                        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                        O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
                        O13 - Gopher Prefix:
                        O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
                        O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
                        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                        O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
                        O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
                        O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Program Files\AGI\common\win32\PythonService.exe
                        O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Unknown owner - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe (file missing)
                        O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Unknown owner - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe (file missing)
                        O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                        O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                        O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                        O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
                        O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
                        O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                        O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                        O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                        O23 - Service: Start BT in service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
                        O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                        O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                        O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
                        O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
                        0
                        1. Contributeur sécurité
                          oui ensuite tu me feras ceci :

                          Sous Vista : ▶ Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

                          ▶ Clique sur Démarrer puis sur panneau de configuration
                          ▶ Double Clique sur l'icône "Comptes d'utilisateurs"
                          ▶ Clique ensuite sur désactiver et valide.
                          ▶ Redémarre le PC.

                          Option 1 - Recherche :

                          ▶ télécharge smitfraudfix et enregistre le sur le bureau

                          ▶ Sous XP : Double clique sur smitfraudfix puis exécuter

                          ▶ sous vista : Clic-droit sur SmitfraudFix présent sur le bureau et choisis "Exécuter en tant qu'administrateur"

                          ▶ Sélectionner 1 pour créer un rapport des fichiers responsables de l'infection.

                          (attention : N utilises pas l option 2 si je ne te l ai pas demandé !!)

                          ▶ copier/coller le rapport dans la réponse.

                          Voici un tutoriel sonore et animé en cas de problème d'utilisation

                          (Attention : "process.exe", un composant de l'outil, est détecté par certains antivirus comme étant un "RiskTool".
                          Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains,
                          cet utilitaire pourrait arrêter des logiciels de sécurité.)

                          0
                          1. voilà le rapport que j'obtiens:

                            SmitFraudFix v2.416

                            Scan done at 21:10:29,80, mar. 19/05/2009
                            Run from C:\Users\Catherine\Desktop\SmitfraudFix
                            OS: Microsoft Windows [version 6.0.6000] - Windows_NT
                            The filesystem type is NTFS
                            Fix run in normal mode

                            »»»»»»»»»»»»»»»»»»»»»»»» Process

                            C:\Windows\system32\csrss.exe
                            C:\Windows\system32\wininit.exe
                            C:\Windows\system32\csrss.exe
                            C:\Windows\system32\services.exe
                            C:\Windows\system32\lsass.exe
                            C:\Windows\system32\lsm.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\System32\svchost.exe
                            C:\Windows\System32\svchost.exe
                            C:\Windows\system32\winlogon.exe
                            C:\Windows\System32\svchost.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\system32\SLsvc.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\System32\spoolsv.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\system32\Dwm.exe
                            C:\Windows\system32\taskeng.exe
                            C:\Windows\Explorer.EXE
                            C:\Program Files\Windows Defender\MSASCui.exe
                            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                            C:\Windows\System32\rundll32.exe
                            C:\Windows\System32\rundll32.exe
                            C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
                            C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                            C:\Program Files\CyberLink\MagicSports\Kernel\MagicSports\MSPMirage.exe
                            C:\Program Files\Picasa2\PicasaMediaDetector.exe
                            C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                            C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                            C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe
                            C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
                            C:\Program Files\QuickTime\qttask.exe
                            C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
                            C:\Program Files\Windows Sidebar\sidebar.exe
                            C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                            C:\Windows\ehome\ehtray.exe
                            C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                            C:\Users\Public\Downloads\VeohClient.exe
                            C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
                            C:\Windows\ehome\ehmsas.exe
                            C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                            C:\Users\Catherine\logiciel souris\SetPoint\SetPoint.exe
                            C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
                            C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
                            C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
                            C:\Program Files\AGI\common\win32\PythonService.exe
                            C:\Program Files\Bonjour\mDNSResponder.exe
                            C:\Windows\system32\svchost.exe
                            C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                            C:\Windows\System32\svchost.exe
                            C:\Windows\System32\svchost.exe
                            C:\Windows\system32\svchost.exe
                            C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                            C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\System32\svchost.exe
                            C:\Windows\system32\SearchIndexer.exe
                            C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
                            C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
                            C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
                            C:\Windows\System32\svchost.exe
                            C:\Windows\system32\wbem\wmiprvse.exe
                            C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                            C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
                            C:\Windows\system32\rundll32.exe
                            C:\Windows\system32\wbem\unsecapp.exe
                            C:\Windows\system32\taskeng.exe
                            C:\Program Files\Mozilla Firefox\firefox.exe
                            C:\Windows\system32\wbem\wmiprvse.exe
                            C:\Windows\system32\wuauclt.exe
                            C:\Windows\servicing\TrustedInstaller.exe
                            C:\Windows\system32\SearchProtocolHost.exe
                            C:\Windows\system32\SearchFilterHost.exe
                            C:\Windows\system32\cmd.exe
                            C:\Windows\system32\conime.exe

                            »»»»»»»»»»»»»»»»»»»»»»»» hosts

                            »»»»»»»»»»»»»»»»»»»»»»»» C:\

                            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

                            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

                            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

                            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

                            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

                            »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Catherine

                            »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\CATHER~1\AppData\Local\Temp

                            »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Catherine\Application Data

                            »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

                            »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\CATHER~1\FAVORI~1

                            »»»»»»»»»»»»»»»»»»»»»»»» Desktop

                            »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                            C:\Program Files\Google\googletoolbar1.dll FOUND !

                            »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

                            »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

                            »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
                            !!!Attention, following keys are not inevitably infected!!!

                            o4Patch
                            Credits: Malware Analysis & Diagnostic
                            Code: S!Ri

                            »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                            !!!Attention, following keys are not inevitably infected!!!

                            IEDFix
                            Credits: Malware Analysis & Diagnostic
                            Code: S!Ri

                            »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
                            !!!Attention, following keys are not inevitably infected!!!

                            Agent.OMZ.Fix
                            Credits: Malware Analysis & Diagnostic
                            Code: S!Ri

                            »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                            !!!Attention, following keys are not inevitably infected!!!

                            VACFix
                            Credits: Malware Analysis & Diagnostic
                            Code: S!Ri

                            »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                            !!!Attention, following keys are not inevitably infected!!!

                            404Fix
                            Credits: Malware Analysis & Diagnostic
                            Code: S!Ri

                            »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                            !!!Attention, following keys are not inevitably infected!!!

                            SrchSTS.exe by S!Ri
                            Search SharedTaskScheduler's .dll

                            »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                            !!!Attention, following keys are not inevitably infected!!!

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                            "AppInit_DLLs"="C:\\PROGRA~1\\Google\\GOOGLE~3\\GOEC62~1.DLL"
                            "LoadAppInit_DLLs"=dword:00000001

                            »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                            !!!Attention, following keys are not inevitably infected!!!

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                            "Userinit"="C:\\Windows\\system32\\userinit.exe,"

                            »»»»»»»»»»»»»»»»»»»»»»»» RK

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

                            »»»»»»»»»»»»»»»»»»»»»»»» DNS

                            HKLM\SYSTEM\CCS\Services\Tcpip\..\{E1FDF112-A18B-4DFE-B219-D93CE414DF0E}: DhcpNameServer=212.68.193.110 212.68.193.196
                            HKLM\SYSTEM\CS1\Services\Tcpip\..\{E1FDF112-A18B-4DFE-B219-D93CE414DF0E}: DhcpNameServer=212.68.193.110 212.68.193.196
                            HKLM\SYSTEM\CS3\Services\Tcpip\..\{E1FDF112-A18B-4DFE-B219-D93CE414DF0E}: DhcpNameServer=212.68.193.110 212.68.193.196
                            HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=212.68.193.110 212.68.193.196
                            HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=212.68.193.110 212.68.193.196
                            HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=212.68.193.110 212.68.193.196

                            »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

                            »»»»»»»»»»»»»»»»»»»»»»»» End

                            et maintenant il y a une page avec ceci écrit:

                            SmitFraudFix v2.416

                            1.Search
                            2.Clean <safe mode recommanded>
                            3.deleted trusted zone
                            4.check for updates
                            5.search and clean DNS Hijack
                            6.Proxy disable
                            L.french language
                            Q. quit

                            close all applications
                            computer may reboot

                            enter your choice <1,2,3,4,5,6,L,Q>:


                            Merci de me répondre !
                            a+
                            0
                            1. Contributeur sécurité
                              Option 2 - Nettoyage :

                              ▶ Redémarre le PC en mode sans échec

                              ▶ Relance smitfraudfix

                              ▶ Sélectionner 2 pour supprimer les fichiers responsables de l'infection.

                              ▶ A la question Voulez-vous nettoyer le registre ? répondre O (oui) afin de débloquer le fond d'écran et supprimer les clés de démarrage automatique de l'infection.

                              Le fix déterminera si le fichier wininet.dll est infecté. A la question Corriger le fichier infecté ? répondre O (oui) pour remplacer le fichier corrompu.

                              ▶ Enregistre le rapport sur ton bureau

                              ▶ Redémarrer en mode normal et poster le rapport.
                              0
                              1. je ferais tout cela cet après-midi...

                                Au fait , je désactive le contrôle des comptes utilisateurs ?

                                encore merci pour cet aide bien précieuse
                                0
                                1. voilà...Je viens de faire ce que tu m'as dit... Le message "le fichier wininet.dll est infecté" je ne l'ai pas eu.

                                  voici le rapport:
                                  SmitFraudFix v2.416

                                  Scan done at 16:20:42,85, mer. 20/05/2009
                                  Run from C:\Users\Catherine\Desktop\SmitfraudFix
                                  OS: Microsoft Windows [version 6.0.6000] - Windows_NT
                                  The filesystem type is NTFS
                                  Fix run in safe mode

                                  »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
                                  !!!Attention, following keys are not inevitably infected!!!

                                  SrchSTS.exe by S!Ri
                                  Search SharedTaskScheduler's .dll

                                  »»»»»»»»»»»»»»»»»»»»»»»» Killing process

                                  »»»»»»»»»»»»»»»»»»»»»»»» hosts

                                  127.0.0.1 localhost
                                  ::1 localhost

                                  »»»»»»»»»»»»»»»»»»»»»»»» VACFix

                                  VACFix
                                  Credits: Malware Analysis & Diagnostic
                                  Code: S!Ri

                                  »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                                  S!Ri's WS2Fix: LSP not Found.

                                  »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                                  GenericRenosFix by S!Ri

                                  »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

                                  C:\Program Files\Google\googletoolbar1.dll Deleted

                                  »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                                  IEDFix
                                  Credits: Malware Analysis & Diagnostic
                                  Code: S!Ri

                                  »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix

                                  Agent.OMZ.Fix
                                  Credits: Malware Analysis & Diagnostic
                                  Code: S!Ri

                                  »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

                                  404Fix
                                  Credits: Malware Analysis & Diagnostic
                                  Code: S!Ri

                                  »»»»»»»»»»»»»»»»»»»»»»»» RK

                                  »»»»»»»»»»»»»»»»»»»»»»»» DNS

                                  HKLM\SYSTEM\CCS\Services\Tcpip\..\{E1FDF112-A18B-4DFE-B219-D93CE414DF0E}: DhcpNameServer=212.68.193.110 212.68.193.196
                                  HKLM\SYSTEM\CS1\Services\Tcpip\..\{E1FDF112-A18B-4DFE-B219-D93CE414DF0E}: DhcpNameServer=212.68.193.110 212.68.193.196
                                  HKLM\SYSTEM\CS3\Services\Tcpip\..\{E1FDF112-A18B-4DFE-B219-D93CE414DF0E}: DhcpNameServer=212.68.193.110 212.68.193.196
                                  HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=212.68.193.110 212.68.193.196
                                  HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=212.68.193.110 212.68.193.196
                                  HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=212.68.193.110 212.68.193.196

                                  »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files

                                  »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                                  !!!Attention, following keys are not inevitably infected!!!

                                  »»»»»»»»»»»»»»»»»»»»»»»» RK.2

                                  »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                                  Registry Cleaning done.

                                  »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
                                  !!!Attention, following keys are not inevitably infected!!!

                                  SrchSTS.exe by S!Ri
                                  Search SharedTaskScheduler's .dll

                                  »»»»»»»»»»»»»»»»»»»»»»»» End
                                  0
                                  1. quand j'ai redémarré mon ordi, j'ai re-lancer mon antivirus habituel (BitDefender Security 2008 ) avec en plus l'analyse des archives... Et il m'a dit que tout était nickel !

                                    Donc,
                                    un TOUT grand MERCI à toi !!!!
                                    0
                                    1. Contributeur sécurité
                                      Bonjour, j'ai pas dit que cela était fini, il ya encore des choses à faire et à vérifier.

                                      Maintenant tu vas me faire ceci :

                                      désactiver L'UAC avant utilisation de UsbFix.

                                      Voici un tuto : http://pagesperso-orange.fr/FindyKill.Ad.Remover/uac_vista.html

                                      Telecharge et install UsbFix de C_XX & Chiquitine29

                                      Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

                                      # Fais un clic droit sur le raccourci UsbFix présent sur ton bureau et choisi éxécuter en tant qu'administrateur .

                                      # Choisi l option 1 ( Recherche )

                                      # Laisse travailler l outil.

                                      # Ensuite post le rapport UsbFix.txt qui apparaitra.

                                      # Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

                                      ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                                      # Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                                      Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                                      Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

                                      0
                                      • 1
                                      • 2