Mémoire vive - Win32/Rootkit.Agent.ODG

Bonjour,
Cet après-midi en faisant un scan "intelligent" de mon ordinateur avec ESET Smart security, j'ai eu la désagréable surprise de trouver ça: "Mémoire vive - Win32/Rootkit.Agent.ODG cheval de troie - impossible de nettoyer"
J'ai aussi remarqué que des pages web s'ouvraient sous sous internet explorer (J'utlise Firefox+module ABP) avec de la pub...
Aidez-moi à y remédier, s'il-vous plait.
Merci.
Configuration: Windows Vista
Firefox 3.0.11

16 réponses

  1. Bonjour tony,

    I)Telecharger random's system information tool: (RSIT)

    Téléchargement de RSIT ici

    1)Double cliquer sur l’icône RSIT.exe .
    2)Cliquer sur "continue".
    3)L’analyse terminée, deux fichiers s’ouvriront, poste moi les 2 rapports stp.
    4)Si les 2 fichiers ne s’ouvrent pas, va dans C:\rsit , tu y trouvera les 2 fichiers info.txt et log.txt.
    2
    1. Voici les résultats:

      info.txt logfile of random's system information tool 1.06 2009-06-17 21:08:03

      ======Uninstall list======

      -->"C:\Program Files\HP Games\Bejeweled 2 Deluxe\Uninstall.exe"
      -->"C:\Program Files\HP Games\Blasterball 3\Uninstall.exe"
      -->"C:\Program Files\HP Games\Bricks of Egypt\Uninstall.exe"
      -->"C:\Program Files\HP Games\Chuzzle Deluxe\Uninstall.exe"
      -->"C:\Program Files\HP Games\Crystal Maze\Uninstall.exe"
      -->"C:\Program Files\HP Games\Digby's Donuts\Uninstall.exe"
      -->"C:\Program Files\HP Games\Diner Dash 2 Restaurant Rescue\Uninstall.exe"
      -->"C:\Program Files\HP Games\Diner Dash\Uninstall.exe"
      -->"C:\Program Files\HP Games\FATE\Uninstall.exe"
      -->"C:\Program Files\HP Games\Fish Tycoon\Uninstall.exe"
      -->"C:\Program Files\HP Games\Gem Shop\Uninstall.exe"
      -->"C:\Program Files\HP Games\Insaniquarium Deluxe\Uninstall.exe"
      -->"C:\Program Files\HP Games\Magic Academy\Uninstall.exe"
      -->"C:\Program Files\HP Games\Mah Jong Quest\Uninstall.exe"
      -->"C:\Program Files\HP Games\My HP Game Console\Uninstall.exe"
      -->"C:\Program Files\HP Games\Ocean Express\Uninstall.exe"
      -->"C:\Program Files\HP Games\Peggle\Uninstall.exe"
      -->"C:\Program Files\HP Games\Penguins!\Uninstall.exe"
      -->"C:\Program Files\HP Games\Polar Bowler\Uninstall.exe"
      -->"C:\Program Files\HP Games\Polar Golfer Pineapple Cup\Uninstall.exe"
      -->"C:\Program Files\HP Games\Polar Golfer\Uninstall.exe"
      -->"C:\Program Files\HP Games\Puzzle Express\Uninstall.exe"
      -->"C:\Program Files\HP Games\Ricochet Lost Worlds\Uninstall.exe"
      -->"C:\Program Files\HP Games\Slingo Deluxe\Uninstall.exe"
      -->"C:\Program Files\HP Games\Sudoku Quest\Uninstall.exe"
      -->"C:\Program Files\HP Games\Super Granny\Uninstall.exe"
      -->"C:\Program Files\HP Games\Tradewinds\Uninstall.exe"
      -->"C:\Program Files\HP Games\Treasure Island\Uninstall.exe"
      -->"C:\Program Files\HP Games\Virtual Villagers - A New Home\Uninstall.exe"
      -->"C:\Program Files\HP Games\Zuma Deluxe\Uninstall.exe"
      -->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
      Adobe After Effects CS4 Third Party Content-->MsiExec.exe /I{67A9747A-E1F5-4E9A-81CC-12B5D5B81B6E}
      Adobe AIR-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
      Adobe AIR-->MsiExec.exe /I{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}
      Adobe Anchor Service CS4-->MsiExec.exe /I{1618734A-3957-4ADD-8199-F973763109A8}
      Adobe Bridge CS4-->MsiExec.exe /I{83877DB1-8B77-45BC-AB43-2BAC22E093E0}
      Adobe CMaps CS4-->MsiExec.exe /I{94D398EB-D2FD-4FD1-B8C4-592635E8A191}
      Adobe Color - Photoshop Specific CS4-->MsiExec.exe /I{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}
      Adobe Color EU Extra Settings CS4-->MsiExec.exe /I{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}
      Adobe Color JA Extra Settings CS4-->MsiExec.exe /I{0D6013AB-A0C7-41DC-973C-E93129C9A29F}
      Adobe Color NA Recommended Settings CS4-->MsiExec.exe /I{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}
      Adobe Color Video Profiles CS CS4-->MsiExec.exe /I{63C24A08-70F3-4C8E-B9FB-9F21A903801D}
      Adobe Creative Suite 4 Master Collection-->C:\Program Files\Common Files\Adobe\Installers\b2d6abde968e6f277ddbfd501383e02\Setup.exe --uninstall=1
      Adobe Creative Suite 4 Master Collection-->MsiExec.exe /I{61D6891E-E822-4448-9F9A-0AAAAEB6AF6C}
      Adobe CSI CS4-->MsiExec.exe /I{0F723FC1-7606-4867-866C-CE80AD292DAF}
      Adobe Default Language CS4-->MsiExec.exe /I{C52E3EC1-048C-45E1-8D53-10B0C6509683}
      Adobe Dreamweaver CS4-->MsiExec.exe /I{30C8AA56-4088-426F-91D1-0EDFD3A25678}
      Adobe Drive CS4-->MsiExec.exe /I{16E16F01-2E2D-4248-A42F-76261C147B6C}
      Adobe Dynamiclink Support-->MsiExec.exe /I{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}
      Adobe Encore CS4 Codecs-->MsiExec.exe /I{FB2A5FCC-B81B-48C2-A009-7804694D83E9}
      Adobe ExtendScript Toolkit CS4-->MsiExec.exe /I{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}
      Adobe Extension Manager CS4-->MsiExec.exe /I{054EFA56-2AC1-48F4-A883-0AB89874B972}
      Adobe Flash CS4 Extension - Flash Lite STI fr-->MsiExec.exe /I{BD423B54-8668-44B6-8610-D24514445E88}
      Adobe Flash CS4 STI-fr-->MsiExec.exe /I{48F9998C-3BA0-42D3-82E6-5882441EB8CE}
      Adobe Flash CS4-->MsiExec.exe /I{F6E99614-F042-4459-82B7-8B38B2601356}
      Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
      Adobe Flash Player 10 Plugin-->MsiExec.exe /X{03DEEAD2-F3B7-45BF-9006-A25D015F00D2}
      Adobe Fonts All-->MsiExec.exe /I{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}
      Adobe Linguistics CS4-->MsiExec.exe /I{931AB7EA-3656-4BB7-864D-022B09E3DD67}
      Adobe Media Encoder CS4 Exporter-->MsiExec.exe /I{561968FD-56A1-49FD-9ED0-F55482C7C5BC}
      Adobe Media Encoder CS4 Importer-->MsiExec.exe /I{8186FF34-D389-4B7E-9A2F-C197585BCFBD}
      Adobe Media Encoder CS4-->MsiExec.exe /I{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}
      Adobe Media Player-->msiexec /qb /x {39F6E2B4-CFE8-C30A-66E8-489651F0F34C}
      Adobe Media Player-->MsiExec.exe /I{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}
      Adobe Output Module-->MsiExec.exe /I{BB4E33EC-8181-4685-96F7-8554293DEC6A}
      Adobe PDF Library Files CS4-->MsiExec.exe /I{F93C84A6-0DC6-42AF-89FA-776F7C377353}
      Adobe Photoshop CS4 Support-->MsiExec.exe /I{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}
      Adobe Photoshop CS4-->MsiExec.exe /I{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}
      Adobe Premiere Pro CS4 Third Party Content-->MsiExec.exe /I{C938BE91-3BB5-4B84-9EF6-88F0505D0038}
      Adobe Search for Help-->MsiExec.exe /I{F0E64E2E-3A60-40D8-A55D-92F6831875DA}
      Adobe Service Manager Extension-->MsiExec.exe /I{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}
      Adobe Setup-->MsiExec.exe /I{E8EE9410-8AC4-4F43-A626-DDECA75C79F3}
      Adobe Shockwave Player-->MsiExec.exe /X{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}
      Adobe Soundbooth CS4 Codecs-->MsiExec.exe /I{52232EF4-CC12-4C21-ABCF-ADB79618302D}
      Adobe Type Support CS4-->MsiExec.exe /I{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}
      Adobe Update Manager CS4-->MsiExec.exe /I{05308C4E-7285-4066-BAE3-6B50DA6ED755}
      Adobe WinSoft Linguistics Plugin-->MsiExec.exe /I{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}
      Adobe XMP Panels CS4-->MsiExec.exe /I{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}
      AdobeColorCommonSetCMYK-->MsiExec.exe /I{68243FF8-83CA-466B-B2B8-9F99DA5479C4}
      AdobeColorCommonSetRGB-->MsiExec.exe /I{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}
      AIM 6-->C:\Program Files\AIM6\uninst.exe
      Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
      Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
      Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
      Connect-->MsiExec.exe /I{B29AD377-CC12-490A-A480-1452337C618D}
      CyberLink DVD Suite-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\setup.exe" -uninstall
      CyberLink YouCam-->"C:\Program Files\InstallShield Installation Information\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\setup.exe" /z-uninstall
      CyberLink YouCam-->"C:\Program Files\InstallShield Installation Information\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\setup.exe" /z-uninstall
      Editeur Handling GTA-SA v2.0-->C:\Program Files\HandilingGTASA\Uninstal.exe
      GTA San Andreas-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}\setup.exe" -l0x40c -removeonly
      Hewlett-Packard Active Check for Health Check-->MsiExec.exe /X{254C37AA-6B72-4300-84F6-98A82419187E}
      Hewlett-Packard Asset Agent for Health Check-->MsiExec.exe /X{669D4A35-146B-4314-89F1-1AC3D7B88367}
      HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
      HP Active Support Library-->C:\Program Files\InstallShield Installation Information\{5DAA9C36-8F8B-462F-8CCA-E205BC3751F5}\setup.exe -runfromtemp -l0x0409
      HP Customer Experience Enhancements-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B16DA0F8-26BC-4FFC-9363-1D9F3E6C3E21}\setup.exe" -l0x9 -removeonly
      HP Doc Viewer-->MsiExec.exe /I{082702D5-5DD8-4600-BCE5-48B15174687F}
      HP Easy Setup - Frontend-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{51E5C397-0AA0-48DD-9CB6-7259AFFDFB0A}\setup.exe" -l0x9 -removeonly
      HP Help and Support-->MsiExec.exe /X{31216452-5540-4C96-B754-94890A63D5AB}
      HP Quick Launch Buttons 6.40 D1-->C:\Program Files\InstallShield Installation Information\{34D2AB40-150D-475D-AE32-BD23FB5EE355}\setup.exe -runfromtemp -l0x040c uninst
      HP QuickPlay 3.7-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{45D707E9-F3C4-11D9-A373-0050BAE317E1}\Setup.exe" -uninstall
      HP QuickTouch 1.00 D2-->MsiExec.exe /I{30DAA715-5032-40F9-A0AE-95C9AEBB3E3F}
      HP Total Care Advisor-->MsiExec.exe /X{f32502b5-5b64-4882-bf61-77f23edcac4f}
      HP Update-->MsiExec.exe /X{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}
      HP User Guides 0102-->MsiExec.exe /I{F48098CD-2D66-4861-85EC-DC1D4D09D5F9}
      HP Wireless Assistant-->MsiExec.exe /I{A5CE7175-080D-49AC-B5A3-E7E3502428F5}
      HPNetworkAssistant-->MsiExec.exe /I{228C6B46-64E2-404E-898A-EF0830603EF4}
      IDT Audio-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}\setup.exe" -l0x40c -remove -removeonly
      Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
      Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
      Intel® Matrix Storage Manager-->C:\Windows\system32\imsmudlg.exe -uninstall
      Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
      JMicron JMB38X Flash Media Controller-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{26604C7E-A313-4D12-867F-7C6E7820BE4C}\setup.exe" -l0x40c -removeonly
      K-Lite Mega Codec Pack 4.8.5-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
      kuler-->MsiExec.exe /I{098727E1-775A-4450-B573-3F441F1CA243}
      LabelPrint-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\setup.exe" -uninstall
      LightScribe System Software 1.12.33.2-->MsiExec.exe /X{582287DA-0806-4AC0-BF19-C15E3A466034}
      Madrics Nebular USB Analog Controller-->C:\PROGRA~1\MADRIC~1\UNWISE.EXE C:\PROGRA~1\MADRIC~1\INSTALL.LOG
      Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
      Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
      Microsoft .NET Framework 1.1 Hotfix (KB929729)-->"C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\M929729\M929729Uninstall.msp"
      Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
      Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
      Microsoft Office 2003 Web Components-->MsiExec.exe /I{90120000-00A4-0409-0000-0000000FF1CE}
      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0015-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0019-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0044-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
      Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
      Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
      Microsoft Office InfoPath MUI (French) 2007-->MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}
      Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
      Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
      Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
      Microsoft Office PowerPoint Viewer 2007 (French)-->MsiExec.exe /X{95120000-00AF-040C-0000-0000000FF1CE}
      Microsoft Office Professional Plus 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
      Microsoft Office Professional Plus 2007-->MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}
      Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
      Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
      Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
      Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
      Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
      Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
      Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
      Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
      Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
      Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
      Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
      Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
      Microsoft Works-->MsiExec.exe /I{3B160861-7250-451E-B5EE-8B92BF30A710}
      Microsoft Xbox 360 Accessories 1.1-->MsiExec.exe /X{9F5DF7FC-3AF2-4502-9084-F62FC00A5A3F}
      Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
      Mise à jour Microsoft Office Outlook 2007 Help (KB963677)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {51EFB347-1F3D-4BAC-8B79-F056B904FE21}
      Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
      Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
      Module de compatibilité pour Microsoft Office System 2007-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
      Mozilla Firefox (3.0.11)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
      MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
      MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
      muvee autoProducer 6.1-->C:\Program Files\InstallShield Installation Information\{35F83303-C0C0-46B7-B8A8-ADA7C2AC5645}\muveesetup.exe -removeonly -runfromtemp
      My HP Games-->"C:\Program Files\HP Games\Uninstall.exe"
      Notepad++-->C:\Program Files\Notepad++\uninstall.exe
      NVIDIA Drivers-->C:\Windows\system32\NVUNINST.EXE UninstallGUI
      Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
      PDF Settings CS4-->MsiExec.exe /I{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}
      Photoshop Camera Raw-->MsiExec.exe /I{CC75AB5C-2110-4A7F-AF52-708680D22FE8}
      Pixel Bender Toolkit-->MsiExec.exe /I{43509E18-076E-40FE-AF38-CA5ED400A5A9}
      Power2Go-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\setup.exe" -uninstall
      PowerBatch 6-->"C:\Program Files\Astase\PowerBatch\unins000.exe"
      PowerDirector-->"C:\Program Files\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\setup.exe" /z-uninstall
      ProtectSmart Hard Drive Protection-->MsiExec.exe /X{9D615069-AA8F-4E89-AE9D-77AAE90F529F}
      QuickPlay SlingPlayer 0.4.6-->"C:\Program Files\HP\QuickPlay\unins000.exe"
      Realtek 8169 8168 8101E 8102E Ethernet Driver-->C:\Program Files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe -runfromtemp -l0x040c -removeonly
      San Andreas Mod Installer-->"C:\Windows\San Andreas Mod Installer\uninstall.exe" "/U:C:\Program Files\San Andreas Mod Installer\Uninstall\uninstall.xml"
      Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
      Security Update for 2007 Microsoft Office System (KB969679)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {C66E4A6C-6E07-4C63-8CCD-2493B5087C73}
      Security Update for Microsoft Office Excel 2007 (KB969682)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {C03803BD-745A-46F8-8557-817DED578780}
      Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
      Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
      Security Update for Microsoft Office Word 2007 (KB969604)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {CF3D6499-709C-43D0-8908-BC5652656050}
      Suite Shared Configuration CS4-->MsiExec.exe /I{842B4B72-9E8F-4962-B3C1-1C422A5C4434}
      Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
      Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
      Update for Microsoft Office Outlook 2007 (KB969907)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {74F98B24-AFBD-4800-9BD6-87D349B5C462}
      Update for Outlook 2007 Junk Email Filter (kb970012)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {DC4A962B-9EC2-469C-BC9C-87312ADAEE81}
      Viewpoint Media Player-->C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
      VistaGlazz 1.1-->"C:\Program Files\CodeGazer\VistaGlazz\unins000.exe"
      Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
      Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
      Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
      WinPcap 4.1 beta5-->C:\Program Files\WinPcap\uninstall.exe

      ======Security center information======

      AS: Windows Defender

      ======System event log======

      Computer Name: Underworld
      Event Code: 263
      Message: Le service ‘StiSvc’ n'a peut-être pas annulé son inscription aux notifications d’événements de périphériques avant d’être arrêté.
      Record Number: 40025
      Source Name: PlugPlayManager
      Time Written: 20090612135626.000000-000
      Event Type: Avertissement
      User:

      Computer Name: Underworld
      Event Code: 1003
      Message: Votre ordinateur n'a pas pu renouveler son adresse à partir du réseau (à partir du serveur DHCP) pour la carte réseau dont l'adresse réseau est 00215D1A39D8. Il s'est produit l'erreur suivante :
      L'opération a été annulée par l'utilisateur.. Votre ordinateur va continuer à essayer d'obtenir sa propre adresse auprès du serveur d'adresse réseau (DHCP).
      Record Number: 39760
      Source Name: Microsoft-Windows-Dhcp-Client
      Time Written: 20090612125228.000000-000
      Event Type: Avertissement
      User:

      Computer Name: Underworld
      Event Code: 7022
      Message: Le service QuickPlay Task Scheduler (QTS) est en attente de démarrage.
      Record Number: 39600
      Source Name: Service Control Manager
      Time Written: 20090612112436.000000-000
      Event Type: Erreur
      User:

      Computer Name: Underworld
      Event Code: 7000
      Message: Le service Parallel port driver n'a pas pu démarrer en raison de l'erreur :
      Le service ne peut pas être démarré parce qu'il est désactivé ou qu'aucun périphérique activé ne lui est associé.
      Record Number: 39568
      Source Name: Service Control Manager
      Time Written: 20090612112402.000000-000
      Event Type: Erreur
      User:

      Computer Name: Underworld
      Event Code: 10
      Message: Erreur du fournisseur lors du stockage des notifications du pilote. Le service de disque virtuel VDS doit être redémarré. hr=80042505
      Record Number: 39182
      Source Name: VDS Dynamic Provider
      Time Written: 20090611192222.000000-000
      Event Type: Erreur
      User:

      =====Application event log=====

      Computer Name: Underworld
      Event Code: 8194
      Message: Erreur du service de cliché instantané des volumes : erreur lors de l’interrogation de l’interface IVssWriterCallback. hr = 0x80070005. Cette erreur est souvent due à des paramètres de sécurité incorrects dans le processus du rédacteur ou du demandeur.

      Opération :
      Données du rédacteur en cours de collecte

      Contexte :
      ID de classe du rédacteur: {e8132975-6f93-4464-a53e-1050253ae220}
      Nom du rédacteur: System Writer
      ID d’instance du rédacteur: {051fbe9e-5713-4116-b613-4716f7d15fc7}
      Record Number: 100
      Source Name: VSS
      Time Written: 20090607170420.000000-000
      Event Type: Erreur
      User:

      Computer Name: Underworld
      Event Code: 10010
      Message: Impossible de redémarrer l’application « C:\WINDOWS\System32\msiexec.exe » (pid 5628) - Le SID de l’application ne correspond pas à celui du conducteur..
      Record Number: 90
      Source Name: Microsoft-Windows-RestartManager
      Time Written: 20090607170348.549600-000
      Event Type: Avertissement
      User: Underworld\Admin

      Computer Name: Underworld
      Event Code: 513
      Message: Les services de chiffrement ont échoué lors du traitement de l’appel OnIdentity() dans l’objet System Writer.

      Details:
      AddCoreCsiFiles : BeginFileEnumeration() failed.

      System Error:
      Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
      .
      Record Number: 86
      Source Name: Microsoft-Windows-CAPI2
      Time Written: 20090607170306.000000-000
      Event Type: Erreur
      User:

      Computer Name: Underworld
      Event Code: 8193
      Message: Échec de la création d’un point de restauration sur le volume (Processus = C:\Windows\system32\msiexec.exe /V ; Description =  ; Hr = 0x80070057).
      Record Number: 72
      Source Name: System Restore
      Time Written: 20090607170136.000000-000
      Event Type: Erreur
      User:

      Computer Name: Underworld
      Event Code: 1015
      Message: La connexion au serveur est impossible. Erreur : 0x800401F0
      Record Number: 66
      Source Name: MsiInstaller
      Time Written: 20090607170031.000000-000
      Event Type: Avertissement
      User: Underworld\Admin

      =====Security event log=====

      Computer Name: Underworld
      Event Code: 4624
      Message: L’ouverture de session d’un compte s’est correctement déroulée.

      Sujet :
      ID de sécurité : S-1-5-18
      Nom du compte : WIN-Q68AFO1Z1EK$
      Domaine du compte : WORKGROUP
      ID d’ouverture de session : 0x3e7

      Type d’ouverture de session : 5

      Nouvelle ouverture de session :
      ID de sécurité : S-1-5-18
      Nom du compte : SYSTEM
      Domaine du compte : AUTORITE NT
      ID d’ouverture de session : 0x3e7
      GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

      Informations sur le processus :
      ID du processus : 0x250
      Nom du processus : C:\WINDOWS\System32\services.exe

      Informations sur le réseau :
      Nom de la station de travail :
      Adresse du réseau source : -
      Port source : -

      Informations détaillées sur l’authentification :
      Processus d’ouverture de session : Advapi
      Package d’authentification : Negotiate
      Services en transit : -
      Nom du package (NTLM uniquement) : -
      Longueur de la clé : 0

      Cet événement est généré lors de la création d’une ouverture de session. Il est généré sur l’ordinateur sur lequel l’ouverture de session a été effectuée.

      Le champ Objet indique le compte sur le système local qui a demandé l’ouverture de session. Il s’agit le plus souvent d’un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

      Le champ Type d’ouverture de session indique le type d’ouverture de session qui s’est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

      Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s’est connecté.

      Les champs relatifs au réseau indiquent la provenance d’une demande d’ouverture de session à distance. Le nom de la station de travail n’étant pas toujours disponible, peut être laissé vide dans certains cas.

      Les champs relatifs aux informations d’authentification fournissent des détails sur cette demande d’ouverture de session spécifique.
      - Le GUID d’ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
      - Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d’ouverture de session.
      - Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
      - La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n’a été demandée.
      Record Number: 131
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20090607165501.968998-000
      Event Type: Succès de l'audit
      User:

      Computer Name: Underworld
      Event Code: 4648
      Message: Tentative d’ouverture de session en utilisant des informations d’identification explicites.

      Sujet :
      ID de sécurité : S-1-5-18
      Nom du compte : WIN-Q68AFO1Z1EK$
      Domaine du compte : WORKGROUP
      ID d’ouverture de session : 0x3e7
      GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

      Compte dont les informations d’identification ont été utilisées :
      Nom du compte : SYSTEM
      Domaine du compte : AUTORITE NT
      GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

      Serveur cible :
      Nom du serveur cible : localhost
      Informations supplémentaires : localhost

      Informations sur le processus :
      ID du processus : 0x250
      Nom du processus : C:\WINDOWS\System32\services.exe

      Informations sur le réseau :
      Adresse du réseau : -
      Port : -

      Cet événement est généré lorsqu’un processus tente d’ouvrir une session pour un compte en spécifiant explicitement les informations d’identification de ce compte. Ceci se produit le plus souvent dans les configurations par lot comme les tâches planifiées, ou avec l’utilisation de la commande RUNAS.
      Record Number: 130
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20090607165501.968998-000
      Event Type: Succès de l'audit
      User:

      Computer Name: Underworld
      Event Code: 4905
      Message: Une tentative d’annulation d’inscription de la source d’un événement de sécurité a été effectuée.

      Sujet :
      ID de sécurité : S-1-5-18
      Nom du compte : WIN-Q68AFO1Z1EK$
      Domaine du compte : WORKGROUP
      ID d’ouverture de session : 0x3e7

      Processus :
      ID du processus : 0xecc
      Nom du processus : C:\WINDOWS\System32\VSSVC.exe

      Source de l’événement :
      Nom de la source : VSSAudit
      ID de la source de l’événement : 0x178512
      Record Number: 129
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20090607165441.379998-000
      Event Type: Succès de l'audit
      User:

      Computer Name: Underworld
      Event Code: 4904
      Message: Une tentative d’inscription de la source d’un événement de sécurité a été effectuée.

      Sujet :
      ID de sécurité : S-1-5-18
      Nom du compte : WIN-Q68AFO1Z1EK$
      Domaine du compte : WORKGROUP
      ID d’ouverture de session : 0x3e7

      Processus :
      ID du processus : 0xecc
      Nom du processus : C:\WINDOWS\System32\VSSVC.exe

      Source de l’événement :
      Nom de la source : VSSAudit
      ID de la source de l’événement : 0x178512
      Record Number: 128
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20090607165441.379998-000
      Event Type: Succès de l'audit
      User:

      Computer Name: Underworld
      Event Code: 1102
      Message: Le journal d’audit a été effacé.
      Objet :
      ID de sécurité : S-1-5-21-2560835692-2549748480-1463801519-1000
      Nom de compte : Admin
      Nom de domaine : Underworld
      ID de connexion : 0x105133
      Record Number: 127
      Source Name: Microsoft-Windows-Eventlog
      Time Written: 20090607165432.927998-000
      Event Type: Succès de l'audit
      User:

      ======Environment variables======

      "ComSpec"=%SystemRoot%\system32\cmd.exe
      "FP_NO_HOST_CHECK"=NO
      "OS"=Windows_NT
      "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\CyberLink\Power2Go
      "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
      "PROCESSOR_ARCHITECTURE"=x86
      "TEMP"=%SystemRoot%\TEMP
      "TMP"=%SystemRoot%\TEMP
      "USERNAME"=SYSTEM
      "windir"=%SystemRoot%
      "PROCESSOR_LEVEL"=6
      "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 23 Stepping 6, GenuineIntel
      "PROCESSOR_REVISION"=1706
      "NUMBER_OF_PROCESSORS"=2
      "TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
      "DFSTRACINGON"=FALSE
      "OnlineServices"=Online Services
      "Platform"=MCD
      "PCBRAND"=Pavilion

      -----------------EOF-----------------

      Logfile of random's system information tool 1.06 (written by random/random)
      Run by Admin at 2009-06-17 21:07:47
      Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
      System drive C: has 205 GB (69%) free of 296 GB
      Total RAM: 3068 MB (64% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 21:08:00, on 17/06/2009
      Platform: Windows Vista SP2 (WinNT 6.00.1906)
      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\taskeng.exe
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
      C:\Program Files\HP\QuickPlay\QPService.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
      C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
      C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
      C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
      C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
      C:\Program Files\ESET\ESET Smart Security\egui.exe
      C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
      C:\WINDOWS\System32\rundll32.exe
      C:\Program Files\IDT\WDM\sttray.exe
      C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
      C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
      C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
      C:\Windows\system32\SearchFilterHost.exe
      C:\Users\Admin\Desktop\RSIT.exe
      C:\Program Files\trend micro\Admin.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      O1 - Hosts: ::1 localhost
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
      O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
      O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
      O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0"
      O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
      O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
      O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
      O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
      O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
      O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
      O4 - HKLM\..\Run: [Power-monbootperso] "C:\power.bat"
      O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
      O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
      O8 - Extra context menu item: Ajouter la cible du lien à un fichier PDF existant - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
      O8 - Extra context menu item: Ajouter à un fichier PDF existant - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
      O8 - Extra context menu item: Convertir au format Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
      O8 - Extra context menu item: Convertir la cible du lien au format Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
      O13 - Gopher Prefix:
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O17 - HKLM\System\CCS\Services\Tcpip\..\{037A8B01-AB0B-4151-9884-24BF0D6FC9B7}: NameServer = 85.255.112.210,85.255.112.65
      O17 - HKLM\System\CCS\Services\Tcpip\..\{F51B00EA-55E8-4693-B6C9-A5DA57D81264}: NameServer = 85.255.112.210,85.255.112.65
      O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.210,85.255.112.65
      O17 - HKLM\System\CS1\Services\Tcpip\..\{037A8B01-AB0B-4151-9884-24BF0D6FC9B7}: NameServer = 85.255.112.210,85.255.112.65
      O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.112.210,85.255.112.65
      O17 - HKLM\System\CS2\Services\Tcpip\..\{037A8B01-AB0B-4151-9884-24BF0D6FC9B7}: NameServer = 85.255.112.210,85.255.112.65
      O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.210,85.255.112.65
      O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_030ac640\aestsrv.exe
      O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
      O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
      O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
      O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
      O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
      O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
      O23 - Service: HP Service (hpsrv) - Hewlett-Packard Corporation - C:\Windows\system32\Hpservice.exe
      O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
      O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
      O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
      O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe
      O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
      O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies, Inc. - C:\Program Files\WinPcap\rpcapd.exe
      O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_a7e996cd\STacSV.exe
      1
      1. ree,

        Tu as un détournement DNS fais ceci:

        Desactiver l'UAC:

        1)Cliquer sur le menu démarrer puis sur Panneau de configuration >> Comptes d'utilisateurs >>comptes d'utilisateurs (une 2ème fois),.
        2)clique sur Activer ou désactiver le contrôle des comptes d'utilisateurs:
        3)Une nouvelle fenêtre s'ouvre,Décoche la case Utiliser le contrôle des comptes d'utilisateurs pour vous aider à protéger votre ordinateur puis OK:
        4)Une demande s'affiche si vous voulez redémarrer votre ordinateur, clique sur redémarrer maintenant.
        https://forums.cnetfrance.fr

        Télécharger SmitFraudfix:

        Télécharger le logicielSmitFraudfix de S!Ri, balltrap34 et moe31 disponible ci dessous.

        http://siri.urz.free.fr/Fix/SmitfraudFix.exe

        Double-cliquez sur l'icône SmitFraudfix.
        Au menu taper 1 puis valide par la touche entrée pour lancer la recherche.
        Patienter(jusqu'à 20 minutes environ).
        A la fin du scan , le bloc notes va s'ouvrir contenant un rapport copie et colle le dans ta prochaine réponse.
        (note:le rapport se trouve dans C:\rapport.txt

        http://www.bibou0007.com/outils-specifiques-f78/tutorial-smitfraudfix-t115.htm
        1
        1. Merci beaucoup pour la réponse je vais essayer ca.
          Vous ne savez pas d'où cela peut venir?
          Merci encore pour votre aide.
          1
          1. Voici le résultat:

            SmitFraudFix v2.422

            Scan done at 8:20:32,33, 18/06/2009
            Run from C:\Windows\system32\SmitfraudFix
            OS: Microsoft Windows [version 6.0.6002] - Windows_NT
            The filesystem type is NTFS
            Fix run in normal mode

            »»»»»»»»»»»»»»»»»»»»»»»» Process

            C:\Windows\system32\csrss.exe
            C:\Windows\system32\wininit.exe
            C:\Windows\system32\csrss.exe
            C:\Windows\system32\services.exe
            C:\Windows\system32\lsass.exe
            C:\Windows\system32\lsm.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\nvvsvc.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\winlogon.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_a7e996cd\STacSV.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\SLsvc.exe
            C:\Windows\system32\rundll32.exe
            C:\Windows\system32\Hpservice.exe
            C:\Windows\System32\spoolsv.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_030ac640\aestsrv.exe
            C:\Program Files\ESET\ESET Smart Security\ekrn.exe
            C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
            C:\Program Files\Common Files\LightScribe\LSSrvc.exe
            C:\Windows\system32\svchost.exe
            C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
            C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
            C:\Windows\SMINST\BLService.exe
            C:\Program Files\CyberLink\Shared Files\RichVideo.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\SearchIndexer.exe
            C:\Windows\system32\Dwm.exe
            C:\Windows\Explorer.EXE
            C:\Windows\system32\taskeng.exe
            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
            C:\Program Files\HP\QuickPlay\QPService.exe
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\Windows\system32\taskeng.exe
            C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
            C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
            C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
            C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
            C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
            C:\Program Files\ESET\ESET Smart Security\egui.exe
            C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrobat_sl.exe
            C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
            C:\WINDOWS\System32\rundll32.exe
            C:\Program Files\IDT\WDM\sttray.exe
            C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\Windows\system32\DllHost.exe
            C:\Windows\system32\SearchProtocolHost.exe
            C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
            C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
            C:\Windows\system32\wbem\wmiprvse.exe
            C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
            C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
            C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
            C:\Windows\servicing\TrustedInstaller.exe
            C:\Windows\system32\SearchFilterHost.exe
            c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
            C:\Windows\system32\cmd.exe
            C:\Windows\system32\conime.exe
            C:\Windows\system32\wbem\wmiprvse.exe

            »»»»»»»»»»»»»»»»»»»»»»»» hosts

            »»»»»»»»»»»»»»»»»»»»»»»» C:\

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Admin

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Admin\AppData\Local\Temp

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Admin\Application Data

            »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Admin\FAVORI~1

            »»»»»»»»»»»»»»»»»»»»»»»» Desktop

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

            »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

            »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

            »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
            !!!Attention, following keys are not inevitably infected!!!

            o4Patch
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
            !!!Attention, following keys are not inevitably infected!!!

            IEDFix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
            !!!Attention, following keys are not inevitably infected!!!

            Agent.OMZ.Fix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» VACFix
            !!!Attention, following keys are not inevitably infected!!!

            VACFix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
            !!!Attention, following keys are not inevitably infected!!!

            404Fix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
            !!!Attention, following keys are not inevitably infected!!!

            SrchSTS.exe by S!Ri
            Search SharedTaskScheduler's .dll

            »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
            !!!Attention, following keys are not inevitably infected!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
            "AppInit_DLLs"=""
            "LoadAppInit_DLLs"=dword:00000000

            »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
            !!!Attention, following keys are not inevitably infected!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
            "Userinit"="C:\\Windows\\system32\\userinit.exe,"

            »»»»»»»»»»»»»»»»»»»»»»»» RK

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

            »»»»»»»»»»»»»»»»»»»»»»»» DNS

            Your computer may be victim of a DNS Hijack: 85.255.x.x detected !

            Description: Intel(R) WiFi Link 5100 AGN
            DNS Server Search Order: 85.255.112.210
            DNS Server Search Order: 85.255.112.65

            HKLM\SYSTEM\CCS\Services\Tcpip\..\{037A8B01-AB0B-4151-9884-24BF0D6FC9B7}: DhcpNameServer=192.168.2.1
            HKLM\SYSTEM\CCS\Services\Tcpip\..\{037A8B01-AB0B-4151-9884-24BF0D6FC9B7}: NameServer=85.255.112.210,85.255.112.65
            HKLM\SYSTEM\CCS\Services\Tcpip\..\{F51B00EA-55E8-4693-B6C9-A5DA57D81264}: NameServer=85.255.112.210,85.255.112.65
            HKLM\SYSTEM\CS1\Services\Tcpip\..\{037A8B01-AB0B-4151-9884-24BF0D6FC9B7}: DhcpNameServer=192.168.2.1
            HKLM\SYSTEM\CS1\Services\Tcpip\..\{037A8B01-AB0B-4151-9884-24BF0D6FC9B7}: NameServer=85.255.112.210,85.255.112.65
            HKLM\SYSTEM\CS1\Services\Tcpip\..\{F51B00EA-55E8-4693-B6C9-A5DA57D81264}: NameServer=85.255.112.210,85.255.112.65
            HKLM\SYSTEM\CS2\Services\Tcpip\..\{037A8B01-AB0B-4151-9884-24BF0D6FC9B7}: DhcpNameServer=192.168.2.1
            HKLM\SYSTEM\CS2\Services\Tcpip\..\{037A8B01-AB0B-4151-9884-24BF0D6FC9B7}: NameServer=85.255.112.210,85.255.112.65
            HKLM\SYSTEM\CS2\Services\Tcpip\..\{F51B00EA-55E8-4693-B6C9-A5DA57D81264}: NameServer=85.255.112.210,85.255.112.65
            HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
            HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: NameServer=85.255.112.210,85.255.112.65
            HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
            HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: NameServer=85.255.112.210,85.255.112.65
            HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
            HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: NameServer=85.255.112.210,85.255.112.65

            »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

            »»»»»»»»»»»»»»»»»»»»»»»» End
            1
            1. Bonjour,

              Vous ne savez pas d'où cela peut venir?

              Cela vient du fait que tu est surement aller sur des sites douteux(pornos) ou téléchargement de crack...

              C'est partit.

              I)Suppression de détournement DNS:

              Double-cliquer sur SmitFraudFix.exe pour lancer SmitFraudFix.
              choisir l'option 5 "recherche et suppression détournement DNS" (taper "5" puis entrée )
              A la fin du scan le bloc notes s'ouvrira contenant un rapport, fait moi un copier-coller de celui-ci.

              (note:le rapport se trouve dans C:\rapport.txt)

              Poste moi un nouveau rapport RSIT ensuite stp.
              1
              1. Désolé, je ne télécharge pas de cracks et je ne vais jamais sur des sites douteux :) mais un "ami" un peu bébête vient souvent en me racontant qu'il a encore piraté le site de la NASA, je lui ai demandé s'il savait ce qu'est une base MYSQL et il ne connait pas ^^ et Lui se ramène avec son disque dur externe rempli de truc pas très nets.

                Voici le rapport:

                SmitFraudFix v2.422

                Scan done at 16:33:24,15, 18/06/2009
                Run from C:\Users\Admin\Desktop\Logiciels\Apps\Securite\Antivirus\SmitfraudFix
                OS: Microsoft Windows [version 6.0.6002] - Windows_NT
                The filesystem type is NTFS
                Fix run in normal mode

                »»»»»»»»»»»»»»»»»»»»»»»» DNS Before Fix

                Your computer may be victim of a DNS Hijack: 85.255.x.x detected !

                Description: Intel(R) WiFi Link 5100 AGN
                DNS Server Search Order: 85.255.112.210
                DNS Server Search Order: 85.255.112.65

                HKLM\SYSTEM\CCS\Services\Tcpip\..\{037A8B01-AB0B-4151-9884-24BF0D6FC9B7}: DhcpNameServer=192.168.2.1
                HKLM\SYSTEM\CCS\Services\Tcpip\..\{037A8B01-AB0B-4151-9884-24BF0D6FC9B7}: NameServer=85.255.112.210,85.255.112.65
                HKLM\SYSTEM\CCS\Services\Tcpip\..\{F51B00EA-55E8-4693-B6C9-A5DA57D81264}: NameServer=85.255.112.210,85.255.112.65
                HKLM\SYSTEM\CS1\Services\Tcpip\..\{037A8B01-AB0B-4151-9884-24BF0D6FC9B7}: DhcpNameServer=192.168.2.1
                HKLM\SYSTEM\CS1\Services\Tcpip\..\{037A8B01-AB0B-4151-9884-24BF0D6FC9B7}: NameServer=85.255.112.210,85.255.112.65
                HKLM\SYSTEM\CS1\Services\Tcpip\..\{F51B00EA-55E8-4693-B6C9-A5DA57D81264}: NameServer=85.255.112.210,85.255.112.65
                HKLM\SYSTEM\CS2\Services\Tcpip\..\{037A8B01-AB0B-4151-9884-24BF0D6FC9B7}: DhcpNameServer=192.168.2.1
                HKLM\SYSTEM\CS2\Services\Tcpip\..\{037A8B01-AB0B-4151-9884-24BF0D6FC9B7}: NameServer=85.255.112.210,85.255.112.65
                HKLM\SYSTEM\CS2\Services\Tcpip\..\{F51B00EA-55E8-4693-B6C9-A5DA57D81264}: NameServer=85.255.112.210,85.255.112.65
                HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
                HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: NameServer=85.255.112.210,85.255.112.65
                HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
                HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: NameServer=85.255.112.210,85.255.112.65
                HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
                HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: NameServer=85.255.112.210,85.255.112.65

                »»»»»»»»»»»»»»»»»»»»»»»» DNS After Fix

                Description: Intel(R) WiFi Link 5100 AGN
                DNS Server Search Order: 192.168.2.1

                HKLM\SYSTEM\CCS\Services\Tcpip\..\{037A8B01-AB0B-4151-9884-24BF0D6FC9B7}: DhcpNameServer=192.168.2.1
                1
                1. Voici le rapport HijackThis:

                  Logfile of random's system information tool 1.06 (written by random/random)
                  Run by Admin at 2009-06-18 16:42:33
                  Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
                  System drive C: has 204 GB (69%) free of 296 GB
                  Total RAM: 3068 MB (65% free)

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 16:42:40, on 18/06/2009
                  Platform: Windows Vista SP2 (WinNT 6.00.1906)
                  MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                  Boot mode: Normal

                  Running processes:
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\Explorer.EXE
                  C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                  C:\Program Files\HP\QuickPlay\QPService.exe
                  C:\Program Files\Windows Defender\MSASCui.exe
                  C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
                  C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
                  C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                  C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                  C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                  C:\Program Files\ESET\ESET Smart Security\egui.exe
                  C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
                  C:\WINDOWS\System32\rundll32.exe
                  C:\Program Files\IDT\WDM\sttray.exe
                  C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\Program Files\Windows Live\Contacts\wlcomm.exe
                  C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
                  C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
                  C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
                  C:\Windows\system32\conime.exe
                  C:\Windows\system32\SearchFilterHost.exe
                  C:\Users\Admin\Desktop\Logiciels\Apps\Securite\Outils\RSIT.exe
                  C:\Program Files\trend micro\Admin.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                  O1 - Hosts: ::1 localhost
                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                  O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
                  O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
                  O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
                  O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
                  O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0"
                  O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
                  O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                  O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
                  O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
                  O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                  O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                  O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
                  O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
                  O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                  O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                  O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
                  O4 - HKLM\..\Run: [Power-monbootperso] "C:\power.bat"
                  O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                  O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
                  O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                  O8 - Extra context menu item: Ajouter la cible du lien à un fichier PDF existant - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
                  O8 - Extra context menu item: Ajouter à un fichier PDF existant - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
                  O8 - Extra context menu item: Convertir au format Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
                  O8 - Extra context menu item: Convertir la cible du lien au format Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                  O13 - Gopher Prefix:
                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                  O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_030ac640\aestsrv.exe
                  O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
                  O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
                  O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
                  O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                  O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
                  O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                  O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                  O23 - Service: HP Service (hpsrv) - Hewlett-Packard Corporation - C:\Windows\system32\Hpservice.exe
                  O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                  O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
                  O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
                  O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
                  O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe
                  O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                  O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies, Inc. - C:\Program Files\WinPcap\rpcapd.exe
                  O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_a7e996cd\STacSV.exe
                  1
                  1. Est-ce-que si je formate mon PC sa ira mieux?
                    1
                    1. Ba si tu format tu perdra toutes tes données..

                      Je croit que ton pote ta refilé une infection qui se transmet pas USB, on va voir ça:

                      Ton pc devrait déja aller mieux ?

                      ##################### | Vista _ Instal & recherche | ########################

                      Même demarche que pour XP , si vous demandez de faire désactiver L'UAC avant utilisation de UsbFix.
                      Voici un tuto : http://pagesperso-orange.fr/FindyKill.Ad.Remover/uac_vista.html
                      Ceci dis UsbFix peut fonctionner avec l'Uac actif...... :

                      ▶ Telecharge et install UsbFix : http://sd-1.archive-host.com/membres/up/127028005715545653/UsbFix.exe

                      (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir
                      • Fais un clic droit sur le raccourci UsbFix présent sur ton bureau et choisis "éxécuter en tant qu'administrateur" .
                      • Choisis l' option 1 ( Recherche )
                      • Laisse travailler l outil.
                      • Ensuite post le rapport UsbFix.txt qui apparaitra.
                      • Note : Le rapport UsbFix.txt est sauvegardé à la racine du disque. ( C:\UsbFix.txt )

                      ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
                      • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                      Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                      Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
                      0
                      1. Ok, je vais essayer sa!
                        Merci de m'aider, t'es super sympa!
                        0
                        1. Je suis en train de faire la recherche avec usbfix, mais je voulais rajouter que des sites s'ouvrent toujours (et maintenant je suis parfois redirigé vers des sites qui me proposent de télécharger des antivirus "sans spywares" mais c'est trèèèèssss probablement que c'est des trucs pas bien pour mon PC), et que j'ai encore ESET qui me dit que j'ai ce trojan...

                          Le scan vient de se terminer:
                          ############################## [ UsbFix V3.032 ]

                          # User : Admin (Administrateurs) # UNDERWORLD
                          # Update on 15/06/09 by Chiquitine29
                          # Start at: 20:25:56 | 18/06/2009
                          # Website : http://pagesperso-orange.fr/NosTools/usbfix.html

                          # Intel(R) Core(TM)2 Duo CPU P7350 @ 2.00GHz
                          # Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
                          # Internet Explorer 8.0.6001.18783
                          # Windows Firewall Status : Disabled

                          # C:\ # Disque fixe local # 288,81 Go (198,82 Go free) # NTFS
                          # D:\ # Disque fixe local # 9,27 Go (1,64 Go free) [HP_RECOVERY] # NTFS
                          # E:\ # Disque CD-ROM
                          # G:\ # Disque amovible
                          # H:\ # Disque fixe local # 465,65 Go (337,75 Go free) [LACIE] # FAT32

                          ############################## [ Processus actifs ]

                          C:\Windows\System32\smss.exe
                          C:\Windows\system32\csrss.exe
                          C:\Windows\system32\wininit.exe
                          C:\Windows\system32\csrss.exe
                          C:\Windows\system32\services.exe
                          C:\Windows\system32\lsass.exe
                          C:\Windows\system32\lsm.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\System32\svchost.exe
                          C:\Windows\system32\nvvsvc.exe
                          C:\Windows\System32\svchost.exe
                          C:\Windows\System32\svchost.exe
                          C:\Windows\System32\svchost.exe
                          C:\Windows\system32\winlogon.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_a7e996cd\STacSV.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\system32\SLsvc.exe
                          C:\Windows\system32\rundll32.exe
                          C:\Windows\system32\Hpservice.exe
                          C:\Windows\System32\spoolsv.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_030ac640\aestsrv.exe
                          C:\Program Files\ESET\ESET Smart Security\ekrn.exe
                          C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
                          C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                          C:\Windows\system32\svchost.exe
                          C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
                          C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
                          C:\Windows\SMINST\BLService.exe
                          C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\System32\svchost.exe
                          C:\Windows\system32\SearchIndexer.exe
                          C:\Windows\system32\Dwm.exe
                          C:\Windows\Explorer.EXE
                          C:\Windows\system32\taskeng.exe
                          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                          C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                          C:\Program Files\HP\QuickPlay\QPService.exe
                          C:\Program Files\Windows Defender\MSASCui.exe
                          C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                          C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                          C:\Program Files\ESET\ESET Smart Security\egui.exe
                          C:\Windows\system32\taskeng.exe
                          C:\WINDOWS\System32\rundll32.exe
                          C:\Windows\system32\DllHost.exe
                          C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
                          C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                          C:\Windows\system32\wbem\wmiprvse.exe
                          C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
                          C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
                          c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                          C:\Windows\system32\conime.exe
                          C:\Program Files\Mozilla Firefox\firefox.exe
                          C:\Windows\system32\mmc.exe
                          C:\Windows\System32\vds.exe
                          C:\Windows\system32\SearchProtocolHost.exe
                          C:\Windows\system32\SearchFilterHost.exe
                          C:\Windows\system32\wbem\wmiprvse.exe

                          ################## [ Registre Startup ]

                          HKCU_Main: "Local Page"="C:\\Windows\\system32\\blank.htm"
                          HKCU_Main: "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                          HKCU_Main: "Start Page"="https://www.google.fr/?gws_rd=ssl"
                          HKLM_logon: "Userinit"="C:\\Windows\\system32\\userinit.exe,"
                          HKLM_logon: "LegalNoticeCaption"=""
                          HKLM_logon: "LegalNoticeText"=""

                          HKLM_Run: SynTPEnh=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                          HKLM_Run: IAAnotif=C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
                          HKLM_Run: UCam_Menu="C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0"
                          HKLM_Run: QPService="C:\Program Files\HP\QuickPlay\QPService.exe"
                          HKLM_Run: Windows Defender=%ProgramFiles%\Windows Defender\MSASCui.exe -hide
                          HKLM_Run: QlbCtrl.exe=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
                          HKLM_Run: OnScreenDisplay=C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
                          HKLM_Run: HP Software Update=C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                          HKLM_Run: hpWirelessAssistant=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                          HKLM_Run: SunJavaUpdateSched="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                          HKLM_Run: egui="C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
                          HKLM_Run: Adobe Acrobat Speed Launcher="C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
                          HKLM_Run: Acrobat Assistant 8.0="C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
                          HKLM_Run: NvCplDaemon=RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                          HKLM_Run: NvMediaCenter=RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                          HKLM_Run: SysTrayApp=%ProgramFiles%\IDT\WDM\sttray.exe
                          HKLM_Run: Power-monbootperso="C:\power.bat"
                          HKLM_Run: HP Health Check Scheduler=c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                          HKLM_Run: combofix==\kmdcd:=\\Combobatch.bat
                          HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
                          HKCU_Run: LightScribe Control Panel=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
                          HKCU_Run: msnmsgr="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                          HKCU_Run: HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\AdobeUpdater=

                          ################## [ Fichiers # Dossiers infectieux ]

                          Présent ! C:\$Recycle.Bin\S-1-5-21-2560835692-2549748480-1463801519-1000\$R5JP7A9\n.com
                          Présent ! H:\$Recycle.Bin\$R1ZCLIS\AutoRun.exe
                          Présent ! H:\$Recycle.Bin\$RNKWYR3\sr2\Autorun.exe

                          ################## [ Registre # Clés Run infectieuses ]

                          ################## [ Registre # Mountpoints2 ]

                          ################## [ ! Fin du rapport # UsbFix V3.032 ! ]
                          0
                          1. ree,

                            on continue.

                            ##################### | Vista _ Suppression | ########################

                            (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d avoir été infectées sans les ouvrir

                            • Fais un clic droit sur le raccourci UsbFix présent sur ton bureau et choisis "éxécuter en tant qu'administrateur" .
                            • choisi l' option 2 ( Suppression )
                            • Ton bureau disparaitra et le pc redémarrera .
                            • Au redémarrage , UsbFix scannera ton pc , laisse travailler l outil.• Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .•

                            •Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )
                            ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                            Rends toi sur ce site :

                            https://www.virustotal.com/gui/

                            Clique sur parcourir et cherche ce fichier : C:\power.bat

                            Clique sur envoyer le fichier.

                            Un rapport va s'élaborer ligne à ligne.
                            Si le rapport ne s’affiche pas, clique sur afficher le dernier rapport.
                            Attends la fin. Il doit comprendre la taille du fichier envoyé.

                            Sauvegarde le rapport avec le bloc-note.

                            Copie le dans ta réponse.

                            Si VirusTotal indique que le fichier a déjà été analysé, cliquer sur le bouton Reanalyse le fichier maintenant.
                            0
                            1. Voici le rapport:

                              ############################## [ UsbFix V3.032 ]

                              # User : Admin (Administrateurs) # UNDERWORLD
                              # Update on 15/06/09 by Chiquitine29
                              # Start at: 20:41:57 | 18/06/2009
                              # Website : http://pagesperso-orange.fr/NosTools/usbfix.html

                              # Intel(R) Core(TM)2 Duo CPU P7350 @ 2.00GHz
                              # Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
                              # Internet Explorer 8.0.6001.18783
                              # Windows Firewall Status : Disabled

                              # C:\ # Disque fixe local # 288,81 Go (198,74 Go free) # NTFS
                              # D:\ # Disque fixe local # 9,27 Go (1,64 Go free) [HP_RECOVERY] # NTFS
                              # E:\ # Disque CD-ROM
                              # G:\ # Disque amovible
                              # H:\ # Disque fixe local # 465,65 Go (337,75 Go free) [LACIE] # FAT32

                              ############################## [ Processus actifs ]

                              C:\Windows\System32\smss.exe
                              C:\Windows\system32\csrss.exe
                              C:\Windows\system32\wininit.exe
                              C:\Windows\system32\csrss.exe
                              C:\Windows\system32\services.exe
                              C:\Windows\system32\lsass.exe
                              C:\Windows\system32\lsm.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\System32\svchost.exe
                              C:\Windows\system32\nvvsvc.exe
                              C:\Windows\System32\svchost.exe
                              C:\Windows\System32\svchost.exe
                              C:\Windows\system32\winlogon.exe
                              C:\Windows\System32\svchost.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_a7e996cd\STacSV.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\system32\SLsvc.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\system32\rundll32.exe
                              C:\Windows\system32\Hpservice.exe
                              C:\Windows\System32\spoolsv.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_030ac640\aestsrv.exe
                              C:\Program Files\ESET\ESET Smart Security\ekrn.exe
                              C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
                              C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                              C:\Windows\system32\svchost.exe
                              C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
                              C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
                              C:\Windows\SMINST\BLService.exe
                              C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\System32\svchost.exe
                              C:\Windows\system32\SearchIndexer.exe
                              C:\Windows\system32\WUDFHost.exe
                              C:\Windows\system32\Dwm.exe
                              C:\Windows\Explorer.EXE
                              C:\Windows\system32\taskeng.exe
                              C:\Windows\system32\runonce.exe
                              C:\Windows\system32\taskeng.exe
                              C:\Windows\system32\conime.exe
                              C:\Windows\system32\wbem\wmiprvse.exe
                              C:\Windows\system32\PresentationSettings.exe
                              C:\Windows\system32\SearchProtocolHost.exe
                              C:\Windows\system32\SearchFilterHost.exe

                              ################## [ Fichiers # Dossiers infectieux ]

                              Supprimé ! C:\$Recycle.Bin\S-1-5-21-2560835692-2549748480-1463801519-1000\$R5JP7A9\n.com
                              Supprimé ! H:\$Recycle.Bin\$R1ZCLIS\AutoRun.exe
                              Supprimé ! H:\$Recycle.Bin\$RNKWYR3\sr2\Autorun.exe

                              ################## [ Registre # Clés Run infectieuses ]

                              ################## [ Registre # Mountpoints2 ]

                              ################## [ Listing des fichiers présent ]

                              [17/06/2009 19:28|-rahs----|2] - C:\autoexec.bat
                              [11/04/2009 08:36|-rahs----|333257] - C:\bootmgr
                              [18/09/2006 23:43|-rahs----|10] - C:\config.sys
                              [?|?|?] - C:\hiberfil.sys
                              [11/06/2009 19:23|-rahs----|0] - C:\IO.SYS
                              [07/06/2009 18:55|--ah-----|371] - C:\IPH.PH
                              [11/06/2009 19:23|-rahs----|0] - C:\MSDOS.SYS
                              [?|?|?] - C:\pagefile.sys
                              [15/06/2009 22:47|---------|974] - C:\power.bat
                              [18/06/2009 18:14|--a------|2781] - C:\power.hta
                              [18/06/2009 16:46|--a------|708] - C:\rapport.txt
                              [18/06/2009 20:44|--a------|3486] - C:\UsbFix.txt
                              [07/06/2009 18:53|---hs----|13] - D:\BLOCK.RIN
                              [03/10/2006 22:02|---hs----|438328] - D:\bootmgr
                              [26/03/2008 17:08|---hs----|1089] - D:\Desktop.ini
                              [25/02/2009 14:26|---hs----|0] - D:\DRECOVERY
                              [10/09/2002 17:14|---hs----|8134] - D:\Folder.htt
                              [16/11/2008 16:26|---hs----|32] - D:\HPCD.sys
                              [17/06/2009 17:09|--ahs----|189] - D:\Master.log
                              [16/09/2002 15:37|---hs----|181898] - D:\protect.chinese hong kong
                              [16/09/2002 15:37|---hs----|181916] - D:\protect.chinese simplified
                              [16/09/2002 15:37|---hs----|181898] - D:\protect.chinese traditional
                              [27/04/2006 17:19|---hs----|181865] - D:\protect.czech
                              [03/11/2005 16:21|---hs----|181726] - D:\protect.danish
                              [10/09/2002 14:56|---hs----|181605] - D:\protect.dutch
                              [10/09/2002 14:50|---hs----|181651] - D:\protect.ed
                              [22/11/2004 16:28|---hs----|181648] - D:\protect.english
                              [03/11/2005 16:20|---hs----|181673] - D:\protect.finnish
                              [03/11/2005 16:19|---hs----|181736] - D:\protect.french
                              [03/11/2005 16:18|---hs----|181669] - D:\protect.german
                              [23/11/2005 16:56|---hs----|182689] - D:\protect.greek
                              [23/01/2006 10:18|---hs----|182605] - D:\protect.hebrew
                              [28/08/2007 15:58|---hs----|181696] - D:\protect.hungarian
                              [03/11/2005 16:17|---hs----|181554] - D:\protect.italian
                              [19/06/2007 16:22|---hs----|182351] - D:\protect.japanese
                              [24/11/2005 12:24|---hs----|218295] - D:\protect.korean
                              [03/11/2005 16:15|---hs----|181578] - D:\protect.norwegian
                              [25/04/2006 15:44|---hs----|181789] - D:\protect.polish
                              [03/11/2005 16:13|---hs----|181624] - D:\protect.portuguese
                              [27/10/2005 20:24|---hs----|181882] - D:\protect.portuguese brazilian
                              [28/06/2004 09:52|---hs----|211936] - D:\protect.russian
                              [03/11/2005 16:11|---hs----|181586] - D:\protect.spanish
                              [10/09/2002 15:15|---hs----|181602] - D:\protect.swedish
                              [12/08/2003 11:37|---hs----|181783] - D:\protect.turkish

                              ################## [ Vaccination ]

                              # C:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
                              # D:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
                              # H:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.

                              ################## [ ! Fin du rapport # UsbFix V3.032 ! ]
                              0
                              1. Finalement, il y a eu plein de nouveaux problèmes, j'avasi toujours un cheval de troie dans la memoire vive, et certains programmes de sécurité ne s'ouvraient plus.
                                J'ai formaté mon PC et puis sa va mieux! merci encore!
                                0