DES PUBS IMPOSSIBLE A BLOQUER

Résolu
Bonjour,
j'ai chaque fois des pub du même type qui n'arrête pas de venir comment faire s'il vous plaît.
Merci de me répondre.
Configuration: Windows Vista
Firefox 3.0.11

25 réponses

  1. Contributeur sécurité
    Bonjour

    • Télécharge Random's System Information Tool (RSIT) de Random / Random et sauvegarde-le sur ton Bureau,

    -> http://images.malwareremoval.com/random/RSIT.exe

    • Double-clique sur RSIT.exe pour lancer le programme,
    • Clique sur continuer sur l'écran Disclaimer,
    • Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.
    • Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (<<qui sera affiché)
    ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches). Utilise une réponse différente pour chaque rapport sinon le message risque d’être trop long pour le forum.

    Tuto si besoin : https://forum.pcastuces.com/randoms_system_information_tool_rsit-f31s31.htm
    2
    1. Contributeur
      télécharge et installe asquared
      0
      1. bonjour croft42,
        il existe des extention pour firefox permettant de bloquer les pop ups (après tu choisis les sites auxquelles tu acceptes les pop up) type "yes popup"
        0
        1. Merci tout le monde,et toptitbal je vais faire se que tu ma dit a tout à l'heure.
          0
          1. Voila pour le fichier log.txt :

            Logfile of random's system information tool 1.06 (written by random/random)
            Run by Croft at 2009-06-28 17:48:18
            Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
            System drive C: has 77 GB (65%) free of 119 GB
            Total RAM: 2939 MB (44% free)

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 17:48:44, on 28/06/2009
            Platform: Windows Vista SP1 (WinNT 6.00.1905)
            MSIE: Internet Explorer v7.00 (7.00.6001.18248)
            Boot mode: Normal

            Running processes:
            c:\PROGRA~1\mcafee.com\agent\mcagent.exe
            C:\Windows\system32\Dwm.exe
            C:\Windows\system32\taskeng.exe
            C:\Windows\Explorer.exe
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\Program Files\Java\jre6\bin\jusched.exe
            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
            C:\Program Files\Google\Google EULA\GoogleEULALauncher.exe
            C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe
            C:\Windows\System32\igfxtray.exe
            C:\Windows\System32\hkcmd.exe
            C:\Windows\System32\igfxpers.exe
            C:\Windows\RtHDVCpl.exe
            C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
            C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
            C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
            C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
            C:\Program Files\Toshiba TEMPRO\TemproTray.exe
            C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
            C:\Program Files\Windows Sidebar\sidebar.exe
            C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
            C:\Program Files\Windows Live\Messenger\msnmsgr.exe
            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            C:\Windows\system32\igfxsrvc.exe
            C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
            C:\Windows\system32\igfxext.exe
            C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
            C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
            C:\Program Files\Windows Live\Contacts\wlcomm.exe
            C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
            C:\Program Files\Internet Explorer\ieuser.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
            C:\Windows\system32\Adobe\Shockwave 11\SwHelper_1150596.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\Users\Croft\Desktop\clavier+\Clavier.exe
            C:\Windows\system32\SearchFilterHost.exe
            C:\Users\Croft\Downloads\RSIT.exe
            C:\Program Files\trend micro\Croft.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
            F2 - REG:system.ini: Shell=Explorer.exe
            O1 - Hosts: ::1 localhost
            O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
            O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.3.3.2.dll
            O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
            O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
            O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
            O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
            O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
            O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
            O4 - HKLM\..\Run: [cfFncEnabler.exe] cfFncEnabler.exe
            O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
            O4 - HKLM\..\Run: [Google EULA Launcher] c:\Program Files\Google\Google EULA\GoogleEULALauncher.exe IE PA
            O4 - HKLM\..\Run: [Toshiba TEMPO] C:\Program Files\Toshiba TEMPRO\Toshiba.Tempo.UI.TrayApplication.exe
            O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
            O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
            O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
            O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
            O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
            O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
            O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
            O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
            O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
            O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start
            O4 - HKLM\..\Run: [jswtrayutil] "C:\Program Files\Jumpstart\jswtrayutil.exe"
            O4 - HKLM\..\Run: [Toshiba TEMPRO] C:\Program Files\Toshiba TEMPRO\TemproTray.exe
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [Msmsgs] C:\Users\Croft\AppData\Local\Temp\Rar$EX00.212\MSN passwords\MSN\Msn messanger.exe
            O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
            O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
            O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [TOSHIBA Online Product Information] C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            O4 - HKCU\..\Run: [iuqqoqo] "c:\users\croft\appdata\local\iuqqoqo.exe" iuqqoqo
            O4 - HKLM\..\Policies\Explorer\Run: [DirectX For Microsoft® Windows] C:\Windows\system32\fservice.exe
            O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
            O4 - HKUS\S-1-5-18\..\Run: [TOSHIBA Online Product Information] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [TOSHIBA Online Product Information] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe (User 'Default user')
            O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (User 'Default user')
            O4 - Startup: No-IP DUC.lnk = C:\Program Files\No-IP\DUC20.exe
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
            O8 - Extra context menu item: Tout télécharger avec BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
            O8 - Extra context menu item: Télécharger avec BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
            O8 - Extra context menu item: Télécharger toutes les vidéos avec BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
            O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
            O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
            O9 - Extra button: eBay - Achetez, Vendez - {76577871-04EC-495E-A12B-91F7C3600AFA} - https://www.ebay.fr (file missing)
            O9 - Extra button: Amazon.fr - {8A918C1D-E123-4E36-B562-5C1519E434CE} - https://www.amazon.fr/exec/obidos/subst/home/home.html/262-6263521-6325360?_encoding=UTF8&link_code=hom&tag=Toshibafrbholink-21 (file missing)
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
            O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.3.3.2.dll/206 (file missing)
            O13 - Gopher Prefix:
            O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
            O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
            O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
            O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
            O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
            O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: Jumpstart Wifi Protected Setup (jswpsapi) - Atheros Communications, Inc. - C:\Program Files\Jumpstart\jswpsapi.exe
            O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
            O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
            O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
            O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
            O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
            O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
            O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
            O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
            O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
            O23 - Service: SmartFaceVWatchSrv - Toshiba - C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe
            O23 - Service: TeamViewer 4 (TeamViewer4) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
            O23 - Service: Notebook Performance Tuning Service (TEMPRO) (TemproMonitoringService) - Toshiba Europe GmbH - C:\Program Files\Toshiba TEMPRO\TemproSvc.exe
            O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
            O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
            O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
            O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
            O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
            0
            1. Et pour le fichier info.txt :

              info.txt logfile of random's system information tool 1.06 2009-06-28 17:48:46

              ======Uninstall list======

              -->"C:\Program Files\InstallShield Installation Information\{A644254B-92F6-4970-8635-AB0775371E72}\setup.exe" --u:{A644254B-92F6-4970-8635-AB0775371E72}
              -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{622E6F16-0904-49B6-BBE1-4CC836314CCF}\setup.exe" -l0x40c
              -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{697AFC77-F318-4CD4-BF16-F50F4C1072DA}\setup.exe" -l0x40c
              Activation Assistant for the 2007 Microsoft Office suites-->"C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
              Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
              Adobe Flash Player ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
              Adobe Reader 8.1.3 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81300000003}
              Adobe Shockwave Player 11.5-->"C:\Windows\system32\Adobe\Shockwave 11\uninstaller.exe"
              Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
              ArtMoney SE v7.30.3-->"C:\Program Files\ArtMoney\Uninstall\unins000.exe"
              Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
              Atheros Driver Installation Program-->C:\Program Files\InstallShield Installation Information\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}\setup.exe -runfromtemp -l0x040c
              Atheros Wi-Fi Protected Setup Library-->C:\Program Files\InstallShield Installation Information\{B0BCDCBD-863D-4CAB-BF68-8D1F6B1BDC13}\setup.exe -runfromtemp -l0x040c -removeonly
              BitComet 1.12-->C:\Program Files\BitComet\uninst.exe
              Camera Assistant Software for Toshiba-->C:\Program Files\InstallShield Installation Information\{37C866E4-AA67-4725-9E95-A39968DD7960}\setup.exe -runfromtemp -l0x040c
              Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
              Cisco EAP-FAST Module-->MsiExec.exe /I{415B2719-AD3A-4944-B404-C472DB6085B3}
              Cisco LEAP Module-->MsiExec.exe /I{83770D14-21B9-44B3-8689-F7B523F94560}
              Cisco PEAP Module-->MsiExec.exe /I{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}
              DVD MovieFactory for TOSHIBA-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}\setup.exe" -l0x40c
              Favorit-->c:\users\croft\appdata\local\moceeuc.bat
              FileZilla Client 3.2.5-->C:\Program Files\FileZilla FTP Client\uninstall.exe
              Google Desktop-->C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
              Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_9DE96A29E721D90A.exe" /uninstall
              Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
              GunboundWC-->"D:\Gunbound\GunboundWC\unins000.exe"
              HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
              Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
              Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
              Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
              Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
              Intel(R) Graphics Media Accelerator Driver-->C:\Windows\system32\igxpun.exe -uninstall
              Intel® Matrix Storage Manager-->C:\Windows\system32\imsmudlg.exe -uninstall
              Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216013FF}
              Java(TM) 6 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160060}
              K-Lite Mega Codec Pack 4.8.5-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
              LimeWire PRO 4.12.3-->"C:\Program Files\LimeWire\uninstall.exe"
              Live-Player-->C:\Program Files\Live-Player\uninst.exe
              Manuels TOSHIBA-->C:\Program Files\InstallShield Installation Information\{5B0202A8-CC6B-4443-AD73-FE9DF1FC1622}\setup.exe -runfromtemp -l0x040c -removeonly
              McAfee SecurityCenter-->C:\Program Files\McAfee\MSC\mcuninst.exe
              Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
              Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
              Microsoft .NET Framework 3.5 SP1-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
              Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
              Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
              Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
              Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
              Microsoft Office OneNote MUI (French) 2007-->MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE}
              Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
              Microsoft Office PowerPoint Viewer 2007 (French)-->MsiExec.exe /X{95120000-00AF-040C-0000-0000000FF1CE}
              Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
              Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
              Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
              Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
              Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
              Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
              Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
              Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
              Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
              Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
              Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
              Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
              Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
              Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
              Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
              Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
              Microsoft Works-->MsiExec.exe /I{3B160861-7250-451E-B5EE-8B92BF30A710}
              Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
              Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
              Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
              Module de compatibilité pour Microsoft Office System 2007-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
              Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
              Mozilla Firefox (3.0.11)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
              MSN Reaper-->"C:\Program Files\MSN Reaper\uninst.exe"
              MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
              MSXML 4.0 SP2 (KB941833)-->MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
              MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
              myphotobook 3.6-->C:\Program Files\myphotobook\uninst.exe
              No-IP.com DUC (remove only)-->"C:\Program Files\No-IP\DUC20.exe" -uninstall
              Notepad++-->D:\Notepad++\uninstall.exe
              Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
              Panda ActiveScan 2.0-->C:\Program Files\Panda Security\ActiveScan 2.0\as2uninst.exe
              PhotoFiltre-->"C:\Program Files\PhotoFiltre\Uninst.exe"
              Picasa 2-->"C:\Program Files\Picasa2\Uninstall.exe"
              Realtek 8169 8168 8101E 8102E Ethernet Driver-->C:\Program Files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe -runfromtemp -l0x040c -removeonly
              Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -removeonly
              Realtek USB 2.0 Card Reader-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DC24971E-1946-445D-8A82-CE685433FA7D}\setup.exe" -l0x9 -removeonly
              Réducteur de bruit du lecteur de CD/DVD-->C:\Program Files\InstallShield Installation Information\{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}\setup.exe -runfromtemp -l0x040c -removeonly
              Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
              Security Update for 2007 Microsoft Office System (KB969679)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C66E4A6C-6E07-4C63-8CCD-2493B5087C73}
              Security Update for Microsoft Office Excel 2007 (KB969682)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C03803BD-745A-46F8-8557-817DED578780}
              Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
              Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
              Security Update for Microsoft Office Word 2007 (KB969604)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {CF3D6499-709C-43D0-8908-BC5652656050}
              Security Update for Windows Media Encoder (KB954156)-->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E} MSIPATCHREMOVE={E836F1B7-43FB-46B0-A0D9-E4D2A5951659} /qb
              Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
              TeamViewer 4-->C:\Program Files\TeamViewer\Version4\uninstall.exe
              TOSHIBA Assist-->C:\Program Files\InstallShield Installation Information\{12B3A009-A080-4619-9A2A-C6DB151D8D67}\setup.exe -runfromtemp -l0x040c -removeonly
              TOSHIBA ConfigFree-->MsiExec.exe /X{0D5D0BEE-FBA9-4928-A50D-6CDFAB827755}
              TOSHIBA Disc Creator-->MsiExec.exe /X{5DA0E02F-970B-424B-BF41-513A5018E4C0}
              TOSHIBA DVD PLAYER-->C:\Program Files\InstallShield Installation Information\{6C5F3BDC-0A1B-4436-A696-5939629D5C31}\setup.exe -runfromtemp -l0x040c -ADDREMOVE -removeonly
              TOSHIBA Extended Tiles for Windows Mobility Center-->C:\Program Files\InstallShield Installation Information\{617C36FD-0CBE-4600-84B2-441CEB12FADF}\setup.exe -runfromtemp -l0x040c
              TOSHIBA Face Recognition-->"C:\Program Files\InstallShield Installation Information\{C730E42C-935A-45BB-A0C5-37E5234D111B}\setup.exe" -runfromtemp -l0x040c -removeonly
              TOSHIBA Face Recognition-->MsiExec.exe /I{C730E42C-935A-45BB-A0C5-37E5234D111B}
              TOSHIBA Hardware Setup-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2883F6F5-0509-43F3-868C-D50330DD9DD3}\setup.exe" -l0x40c
              Toshiba Online Product Information-->C:\Program Files\InstallShield Installation Information\{2290A680-4083-410A-ADCC-7092C67FC052}\setup.exe -runfromtemp -l0x040c -removeonly
              TOSHIBA Recovery Disc Creator-->MsiExec.exe /X{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}
              TOSHIBA Software Modem-->Tosmreg -U
              TOSHIBA Supervisor Password-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4B1E87C3-00DE-4898-8E39-E390AAEF2391}\setup.exe" -l0x40c
              Toshiba TEMPRO-->MsiExec.exe /X{7C30283C-8DC7-4FBB-805E-52BEA5F580E8}
              TOSHIBA Value Added Package-->C:\Program Files\InstallShield Installation Information\{FEDD27A0-B306-45EF-BF58-B527406B42C8}\setup.exe -runfromtemp -l0x040c
              TRDCReminder-->C:\Program Files\InstallShield Installation Information\{773970F1-5EBA-4474-ADEE-1EA3B0A59492}\setup.exe -runfromtemp -l0x040c
              TRORDCLauncher-->C:\Program Files\InstallShield Installation Information\{E65C7D8E-186D-484B-BEA8-DEF0331CE600}\setup.exe -runfromtemp -l0x040c
              Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
              Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
              Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
              Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
              Windows Live OneCare safety scanner-->"C:\Program Files\Windows Live Safety Center\UnInstall.exe"
              Windows Live OneCare safety scanner-->MsiExec.exe /X{FE0646A7-19D0-41B4-A2BB-2C35D644270D}
              Windows Media Encoder 9 Series-->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
              Windows Media Encoder 9 Series-->MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
              Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}

              ======Security center information======

              AS: Windows Defender

              ======System event log======

              Computer Name: PC-de-Croft
              Event Code: 7031
              Message: Le service McAfee Real-time Scanner s'est terminé de manière inattendue. Ceci s'est produit 1 fois. L'action corrective suivante va être effectuée dans 60000 millisecondes : Redémarrer le service.
              Record Number: 25863
              Source Name: Service Control Manager
              Time Written: 20090628103218.000000-000
              Event Type: Erreur
              User:

              Computer Name: PC-de-Croft
              Event Code: 4226
              Message: TCP/IP a atteint la limite de sécurité imposée sur le nombre de tentatives de connexion TCP simultanées.
              Record Number: 25877
              Source Name: Tcpip
              Time Written: 20090628121809.111732-000
              Event Type: Avertissement
              User:

              Computer Name: PC-de-Croft
              Event Code: 3004
              Message: L’agent de protection en temps réel Windows Defender a détecté des modifications. Microsoft vous recommande d’analyser les logiciels responsables de ces modifications, à la recherche de risques potentiels. Vous pouvez vous servir des informations relatives au fonctionnement de ces programmes pour autoriser ou non leur exécution, ou pour les supprimer de l’ordinateur. N’autorisez les modifications que si vous faites confiance au programme ou à l’éditeur de logiciel. Windows Defender ne peut pas annuler les modifications que vous autorisez.
              Pour plus d’informations, consultez les données suivantes :
              Non applicable
              ID d’analyse : {719A3436-8796-4C6D-A9FE-B9397D0DA5F7}
              Utilisateur : PC-de-Croft\Croft
              Nom : Unknown
              ID :
              ID de gravité :
              ID de catégorie :
              Chemin d’accès trouvé : iemain:HKCU@S-1-5-21-1723914009-819404351-2468401903-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page
              Type d’alerte : Logiciel non classifié
              Type de détection :
              Record Number: 25880
              Source Name: Microsoft-Windows-Windows Defender
              Time Written: 20090628132942.000000-000
              Event Type: Avertissement
              User:

              Computer Name: PC-de-Croft
              Event Code: 1003
              Message: Votre ordinateur n'a pas pu renouveler son adresse à partir du réseau (à partir du serveur DHCP) pour la carte réseau dont l'adresse réseau est 002163F5A9D2. Il s'est produit l'erreur suivante :
              L'opération a été annulée par l'utilisateur.. Votre ordinateur va continuer à essayer d'obtenir sa propre adresse auprès du serveur d'adresse réseau (DHCP).
              Record Number: 25888
              Source Name: Microsoft-Windows-Dhcp-Client
              Time Written: 20090628145034.000000-000
              Event Type: Avertissement
              User:

              Computer Name: PC-de-Croft
              Event Code: 4227
              Message: TCP/IP n’a pas pu établir une connexion sortante car le point de terminaison local sélectionné a été récemment utilisé pour se connecter au même point de terminaison distant. Cette erreur se produit généralement lorsque les connexions sortantes sont ouvertes et fermées à un débit élevé, provoquant l’utilisation de tous les ports locaux disponibles et obligeant TCP/IP à réutiliser un port local pour une connexion sortante. Pour réduire le risque d’altération des données, la norme TCP/IP exige qu’un laps de temps minimal s’écoule entre des connexions successives d’un point de terminaison local à un point de terminaison distant.
              Record Number: 25892
              Source Name: Tcpip
              Time Written: 20090628145126.171000-000
              Event Type: Avertissement
              User:

              =====Application event log=====

              Computer Name: PC-de-Croft
              Event Code: 1000
              Message: Application défaillante iexplore.exe, version 7.0.6001.18248, horodatage 0x49f1c24f, module défaillant ntdll.dll, version 6.0.6001.18000, horodatage 0x4791a7a6, code d’exception 0xc0000005, décalage d’erreur 0x00065a20, ID du processus 0x244, heure de début de l’application 0x01c9f7eed0bae98e.
              Record Number: 3124
              Source Name: Application Error
              Time Written: 20090628130320.000000-000
              Event Type: Erreur
              User:

              Computer Name: PC-de-Croft
              Event Code: 508
              Message: wlcomm (5320) C:\Users\Croft\AppData\Local\Microsoft\Windows Live Contacts\{6a1efdc8-3ac2-4847-a1f7-25e54dfacfa5}\: Une requête pour lire à partir du fichier "C:\Users\Croft\AppData\Local\Microsoft\Windows Live Contacts\{6a1efdc8-3ac2-4847-a1f7-25e54dfacfa5}\DBStore\contacts.edb" à l'offset 3031040 (0x00000000002e4000) pour 8192 (0x00002000) octets a réussi mais a pris un temps anormalement long (3605 secondes) pour être traité par le système d'exploitation. Ce problème peut être causé par du matériel défaillant. Contactez le fabricant de votre matériel afin d'obtenir plus d'aide pour diagnostiquer le problème.
              Record Number: 3125
              Source Name: ESENT
              Time Written: 20090628145029.000000-000
              Event Type: Avertissement
              User:

              Computer Name: PC-de-Croft
              Event Code: 508
              Message: wlcomm (5320) C:\Users\Croft\AppData\Local\Microsoft\Windows Live Contacts\{6a1efdc8-3ac2-4847-a1f7-25e54dfacfa5}\: Une requête pour lire à partir du fichier "C:\Users\Croft\AppData\Local\Microsoft\Windows Live Contacts\{6a1efdc8-3ac2-4847-a1f7-25e54dfacfa5}\DBStore\LogFiles\edb.log" à l'offset 578048 (0x000000000008d200) pour 20992 (0x00005200) octets a réussi mais a pris un temps anormalement long (3605 secondes) pour être traité par le système d'exploitation. Ce problème peut être causé par du matériel défaillant. Contactez le fabricant de votre matériel afin d'obtenir plus d'aide pour diagnostiquer le problème.
              Record Number: 3126
              Source Name: ESENT
              Time Written: 20090628145029.000000-000
              Event Type: Avertissement
              User:

              Computer Name: PC-de-Croft
              Event Code: 1002
              Message: Le programme iuqqoqo.exe version 6.8.8.8 a cessé d’interagir avec Windows et a été fermé. Pour déterminer si des informations supplémentaires sont disponibles, consultez l’historique du problème dans l’application Rapports et solutions aux problèmes du Panneau de configuration. ID de processus : 8c0 Heure de début : 01c9f7d7463c78de Heure de fin : 29
              Record Number: 3128
              Source Name: Application Hang
              Time Written: 20090628152958.000000-000
              Event Type: Erreur
              User:

              Computer Name: PC-de-Croft
              Event Code: 1002
              Message: Le programme iexplore.exe version 7.0.6001.18248 a cessé d’interagir avec Windows et a été fermé. Pour déterminer si des informations supplémentaires sont disponibles, consultez l’historique du problème dans l’application Rapports et solutions aux problèmes du Panneau de configuration. ID de processus : c24 Heure de début : 01c9f7f37958835e Heure de fin : 218
              Record Number: 3130
              Source Name: Application Hang
              Time Written: 20090628153021.000000-000
              Event Type: Erreur
              User:

              =====Security event log=====

              Computer Name: PC-de-Croft
              Event Code: 5038
              Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

              Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
              Record Number: 4429
              Source Name: Microsoft-Windows-Security-Auditing
              Time Written: 20090628154841.861000-000
              Event Type: Échec de l'audit
              User:

              Computer Name: PC-de-Croft
              Event Code: 5038
              Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

              Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
              Record Number: 4430
              Source Name: Microsoft-Windows-Security-Auditing
              Time Written: 20090628154841.889000-000
              Event Type: Échec de l'audit
              User:

              Computer Name: PC-de-Croft
              Event Code: 5038
              Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

              Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
              Record Number: 4431
              Source Name: Microsoft-Windows-Security-Auditing
              Time Written: 20090628154841.919000-000
              Event Type: Échec de l'audit
              User:

              Computer Name: PC-de-Croft
              Event Code: 5038
              Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

              Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
              Record Number: 4432
              Source Name: Microsoft-Windows-Security-Auditing
              Time Written: 20090628154841.947000-000
              Event Type: Échec de l'audit
              User:

              Computer Name: PC-de-Croft
              Event Code: 5038
              Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

              Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
              Record Number: 4433
              Source Name: Microsoft-Windows-Security-Auditing
              Time Written: 20090628154841.975000-000
              Event Type: Échec de l'audit
              User:

              ======Environment variables======

              "ComSpec"=%SystemRoot%\system32\cmd.exe
              "FP_NO_HOST_CHECK"=NO
              "OS"=Windows_NT
              "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG
              "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
              "PROCESSOR_ARCHITECTURE"=x86
              "TEMP"=%SystemRoot%\TEMP
              "TMP"=%SystemRoot%\TEMP
              "USERNAME"=SYSTEM
              "windir"=%SystemRoot%
              "PROCESSOR_LEVEL"=6
              "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
              "PROCESSOR_REVISION"=0f0d
              "NUMBER_OF_PROCESSORS"=2
              "TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
              "DFSTRACINGON"=FALSE

              -----------------EOF-----------------
              0
              1. En attente d'une réponse ^^'
                0
                1. Contributeur sécurité
                  Désactive le contrôle des comptes utilisateurs
                  (tu le réactiveras après ta désinfection):

                  * Va dans démarrer puis panneau de configuration
                  * Double Clique sur l'icône "Comptes d'utilisateurs"
                  * Clique ensuite sur désactiver et valide.

                  Tuto : https://forum.malekal.com/viewtopic.php?f=59&t=6517

                  https://forum.pcastuces.com/navilog_de_il_mafioso_pour_vista-f31s12.htm

                  Télécharge Navilog1 (par IL-MAFIOSO) sur ton bureau

                  http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

                  Enregistre la cible (du lien) sous... et enregistre-le sur ton bureau.
                  Ensuite double clique sur navilog1.exe pour lancer l'installation.
                  Une fois l'installation terminée, clique droit sur le raccourci Navilog1 présent sur le bureau et choisis : « Exécuter en tant qu’administrateur »

                  Laisse-toi guider. Appuie sur une touche quand on te le demande.
                  Au menu principal, choisis 1 et valide.

                  < Ne fais pas le choix 2 >

                  Patiente le temps du scan. Il te sera peut-être demandé de redémarrer ton PC.
                  Laisse l'outil le faire automatiquement, sinon redémarre ton PC normalement s'il te le demande.

                  Patiente jusqu'au message "Scan terminé le......"
                  Appuie sur une touche comme demandé ; le bloc-notes va s'ouvrir.
                  Copie-colle l'intégralité dans ta réponse. Referme le bloc-notes.
                  1
                  1. Merci beaucoup je le fait tout de suite.
                    0
                    1. Il me donne sa:

                      Fix Navipromo version 4.0.0 commencé le 28/06/2009 à 18:50:23,85

                      !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                      !!! Postez ce rapport sur le forum pour le faire analyser !!!

                      Outil exécuté depuis C:\Program Files\navilog1

                      Mise à jour le 19.06.2009 à 20h00 par IL-MAFIOSO

                      Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
                      X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) Dual CPU T3400 @ 2.16GHz )
                      BIOS : InsydeH2O Version 1.80
                      USER : Croft ( Administrator )
                      BOOT : Normal boot

                      C:\ (Local Disk) - NTFS - Total:116 Go (Free:75 Go)
                      D:\ (Local Disk) - NTFS - Total:115 Go (Free:91 Go)
                      E:\ (CD or DVD)

                      Recherche exécutée en mode normal

                      Nettoyage exécuté au redémarrage de l'ordinateur

                      C:\Program Files\Live-Player supprimé !
                      c:\progra~2\micros~1\windows\startm~1\programs\Live-Player supprimé !
                      C:\Users\Croft\AppData\Local\virtualstore\Program Files\Live-Player supprimé !
                      C:\Users\Croft\AppData\Roaming\Live-Player supprimé !
                      c:\users\public\desktop\Live-Player.lnk supprimé !
                      C:\Users\Croft\AppData\Local\iuqqoqo.exe supprimé !
                      C:\Users\Croft\AppData\Local\iuqqoqo.dat supprimé !
                      C:\Users\Croft\AppData\Local\iuqqoqo_nav.dat supprimé !
                      C:\Users\Croft\AppData\Local\iuqqoqo_navps.dat supprimé !

                      Nettoyage contenu C:\Windows\Temp effectué !
                      Nettoyage contenu C:\Users\Croft\AppData\Local\Temp effectué !

                      *** Sauvegarde du Registre vers dossier Safebackup ***

                      sauvegarde du Registre réalisée avec succès !

                      *** Nettoyage Registre ***

                      Nettoyage Registre Ok

                      *** Scan terminé le 28/06/2009 à 19:01:19,72 ***
                      0
                      1. Contributeur sécurité
                        Bien.
                        Fais un nouveau RSIT, tu n'auras que le log.txt cette fois.
                        1
                        1. log.txt

                          Logfile of random's system information tool 1.06 (written by random/random)
                          Run by Croft at 2009-06-28 19:11:38
                          Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
                          System drive C: has 77 GB (65%) free of 119 GB
                          Total RAM: 2939 MB (61% free)

                          Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 19:11:50, on 28/06/2009
                          Platform: Windows Vista SP1 (WinNT 6.00.1905)
                          MSIE: Internet Explorer v7.00 (7.00.6001.18248)
                          Boot mode: Normal

                          Running processes:
                          c:\PROGRA~1\mcafee.com\agent\mcagent.exe
                          C:\Windows\system32\taskeng.exe
                          C:\Windows\system32\Dwm.exe
                          C:\Windows\Explorer.exe
                          C:\Windows\system32\conime.exe
                          C:\Program Files\Windows Defender\MSASCui.exe
                          C:\Program Files\Java\jre6\bin\jusched.exe
                          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                          C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
                          C:\Program Files\Google\Google EULA\GoogleEULALauncher.exe
                          C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe
                          C:\Windows\System32\igfxtray.exe
                          C:\Windows\System32\hkcmd.exe
                          C:\Windows\System32\igfxpers.exe
                          C:\Windows\system32\igfxsrvc.exe
                          C:\Windows\RtHDVCpl.exe
                          C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
                          C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
                          C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
                          C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
                          C:\Program Files\Toshiba TEMPRO\TemproTray.exe
                          C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                          C:\Program Files\Windows Sidebar\sidebar.exe
                          C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
                          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          C:\Program Files\No-IP\DUC20.exe
                          C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                          C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                          C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
                          C:\Windows\system32\igfxext.exe
                          C:\Program Files\Mozilla Firefox\firefox.exe
                          C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
                          C:\Program Files\Windows Live\Contacts\wlcomm.exe
                          C:\Windows\system32\SearchFilterHost.exe
                          C:\Users\Croft\Downloads\RSIT(2).exe
                          C:\Program Files\trend micro\Croft.exe

                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                          F2 - REG:system.ini: Shell=Explorer.exe
                          O1 - Hosts: ::1 localhost
                          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                          O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
                          O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.3.3.2.dll
                          O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                          O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
                          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
                          O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                          O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                          O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
                          O4 - HKLM\..\Run: [cfFncEnabler.exe] cfFncEnabler.exe
                          O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
                          O4 - HKLM\..\Run: [Google EULA Launcher] c:\Program Files\Google\Google EULA\GoogleEULALauncher.exe IE PA
                          O4 - HKLM\..\Run: [Toshiba TEMPO] C:\Program Files\Toshiba TEMPRO\Toshiba.Tempo.UI.TrayApplication.exe
                          O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
                          O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                          O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                          O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                          O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
                          O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
                          O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
                          O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
                          O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start
                          O4 - HKLM\..\Run: [jswtrayutil] "C:\Program Files\Jumpstart\jswtrayutil.exe"
                          O4 - HKLM\..\Run: [Toshiba TEMPRO] C:\Program Files\Toshiba TEMPRO\TemproTray.exe
                          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                          O4 - HKLM\..\Run: [Msmsgs] C:\Users\Croft\AppData\Local\Temp\Rar$EX00.212\MSN passwords\MSN\Msn messanger.exe
                          O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                          O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
                          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                          O4 - HKCU\..\Run: [TOSHIBA Online Product Information] C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe
                          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          O4 - HKLM\..\Policies\Explorer\Run: [DirectX For Microsoft® Windows] C:\Windows\system32\fservice.exe
                          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                          O4 - HKUS\S-1-5-18\..\Run: [TOSHIBA Online Product Information] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe (User 'SYSTEM')
                          O4 - HKUS\.DEFAULT\..\Run: [TOSHIBA Online Product Information] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe (User 'Default user')
                          O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (User 'Default user')
                          O4 - Startup: No-IP DUC.lnk = C:\Program Files\No-IP\DUC20.exe
                          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                          O8 - Extra context menu item: Tout télécharger avec BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
                          O8 - Extra context menu item: Télécharger avec BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
                          O8 - Extra context menu item: Télécharger toutes les vidéos avec BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
                          O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                          O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                          O9 - Extra button: eBay - Achetez, Vendez - {76577871-04EC-495E-A12B-91F7C3600AFA} - https://www.ebay.fr (file missing)
                          O9 - Extra button: Amazon.fr - {8A918C1D-E123-4E36-B562-5C1519E434CE} - https://www.amazon.fr/exec/obidos/subst/home/home.html/262-6263521-6325360?_encoding=UTF8&link_code=hom&tag=Toshibafrbholink-21 (file missing)
                          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                          O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.3.3.2.dll/206 (file missing)
                          O13 - Gopher Prefix:
                          O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                          O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
                          O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
                          O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
                          O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                          O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          O23 - Service: Jumpstart Wifi Protected Setup (jswpsapi) - Atheros Communications, Inc. - C:\Program Files\Jumpstart\jswpsapi.exe
                          O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
                          O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
                          O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
                          O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
                          O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
                          O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
                          O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
                          O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
                          O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
                          O23 - Service: SmartFaceVWatchSrv - Toshiba - C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe
                          O23 - Service: TeamViewer 4 (TeamViewer4) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
                          O23 - Service: Notebook Performance Tuning Service (TEMPRO) (TemproMonitoringService) - Toshiba Europe GmbH - C:\Program Files\Toshiba TEMPRO\TemproSvc.exe
                          O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
                          O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
                          O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
                          O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
                          O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
                          0
                          1. Contributeur sécurité
                            ---> Télécharge OTM (OldTimer) sur ton Bureau :
                            http://www.geekstogo.com/forum/files/file/402-otm-oldtimers-move-it/

                            ---> Double-clique sur OTM.exe afin de le lancer.

                            ---> Copie (Ctrl+C) le texte suivant ci-dessous :

                            :processes 
                            explorer.exe 
                            
                            :files 
                            c:\windows\system32\fservice.exe
                            c:\windows\system32\gamemon.des
                            
                            :reg
                            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
                            "DirectX For Microsoft® Windows"=-
                             
                            :commands 
                            [emptytemp] 
                            [start explorer] 
                            


                            ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

                            ---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

                            Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
                            Accepte en cliquant sur YES.

                            ---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
                            Le nom du rapport correspond au moment de sa création : date_heure.log
                            1
                            1. All processes killed
                              ========== PROCESSES ==========
                              No active process named explorer.exe was found!
                              ========== FILES ==========
                              File/Folder c:\windows\system32\fservice.exe not found.
                              c:\windows\system32\GameMon.des moved successfully.
                              ========== REGISTRY ==========
                              Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\\DirectX For Microsoft® Windows deleted successfully.
                              ========== COMMANDS ==========

                              [EMPTYTEMP]

                              User: All Users

                              User: Croft
                              ->Temporary Internet Files folder emptied: 61297138 bytes
                              ->Java cache emptied: 10230747 bytes
                              ->FireFox cache emptied: 37980135 bytes

                              User: Default
                              ->Temporary Internet Files folder emptied: 33170 bytes

                              User: Default User
                              ->Temporary Internet Files folder emptied: 0 bytes

                              User: Public

                              %systemdrive% .tmp files removed: 0 bytes
                              C:\Windows\msdownld.tmp folder deleted successfully.
                              %systemroot% .tmp files removed: 0 bytes
                              %systemroot%\System32 .tmp files removed: 0 bytes
                              Windows Temp folder emptied: 0 bytes

                              RecycleBin emptied: 0 bytes

                              Total Files Cleaned = 104,47 mb

                              OTM by OldTimer - Version 3.0.0.2 log created on 06282009_191750

                              Files moved on Reboot...

                              Registry entries deleted on Reboot...
                              0
                              1. Contributeur sécurité
                                Imprime ces instructions ou sauvegarde les sur ton Bureau car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

                                Télécharge Malwarebytes' Anti-Malware (MBAM) et enregistre le sur ton bureau à partir de ce lien :

                                https://download.cnet.com/Malwarebytes/3000-8022_4-10804572.html

                                A la fin du téléchargement, ferme toutes les fenêtres et programmes, y compris celui-ci.

                                Double-clique sur l'icône Download_mbam-setup.exe sur ton bureau pour démarrer le programme d'installation.

                                Pendant l'installation, suis les indications (en particulier le choix de la langue et l'autorisation d'accession à Internet). N'apporte aucune modification aux réglages par défaut et, en fin d'installation, vérifie que les options Update Malwarebytes' Anti-Malware et Launch Malwarebytes' Anti-Malware sont cochées.

                                MBAM démarrera automatiquement et enverra un message demandant à mettre à jour le programme avant de lancer une analyse. Comme MBAM se met automatiquement à jour en fin d'installation, clique sur OK pour fermer la boîte de dialogue. La fenêtre principale de MBAM s'affiche :

                                Dans l'onglet analyse, vérifie que "Exécuter un examen rapide" est coché et clique sur le bouton Rechercher pour démarrer l'analyse.

                                MBAM analyse ton ordinateur. L'analyse peut prendre un certain temps. Il suffit de vérifier de temps en temps son avancement.

                                Lorsque le message indiquant la fin de l’analyse s’affiche, clique sur « Afficher le résultat » pour poursuivre..

                                Si des malwares ont été détectés, leur liste s'affiche.
                                Coche tous les éléments détectés par Malwarebytes' Anti-Malware puis clique sur « Supprimer la sélection » afin d'éradiquer les malwares détectés. MBAM va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.

                                MBAM va ouvrir le bloc-notes et y copier le rapport d'analyse. Ferme le bloc-note. (Le rapport peut être retrouvé sous l'onglet Rapports/logs)

                                Ferme MBAM en cliquant sur Quitter.

                                Poste le rapport sur le forum.
                                1
                                1. Sa ces parceque je suis infecter ou pour les pubs ?
                                  0
                                  1. Contributeur sécurité
                                    C'est pour éliminer d'éventuels résidus.
                                    0
                                2. Malwarebytes' Anti-Malware 1.38
                                  Version de la base de données: 2346
                                  Windows 6.0.6001 Service Pack 1

                                  28/06/2009 19:34:01
                                  mbam-log-2009-06-28 (19-34-01).txt

                                  Type de recherche: Examen rapide
                                  Eléments examinés: 76941
                                  Temps écoulé: 4 minute(s), 2 second(s)

                                  Processus mémoire infecté(s): 0
                                  Module(s) mémoire infecté(s): 0
                                  Clé(s) du Registre infectée(s): 0
                                  Valeur(s) du Registre infectée(s): 0
                                  Elément(s) de données du Registre infecté(s): 0
                                  Dossier(s) infecté(s): 0
                                  Fichier(s) infecté(s): 1

                                  Processus mémoire infecté(s):
                                  (Aucun élément nuisible détecté)

                                  Module(s) mémoire infecté(s):
                                  (Aucun élément nuisible détecté)

                                  Clé(s) du Registre infectée(s):
                                  (Aucun élément nuisible détecté)

                                  Valeur(s) du Registre infectée(s):
                                  (Aucun élément nuisible détecté)

                                  Elément(s) de données du Registre infecté(s):
                                  (Aucun élément nuisible détecté)

                                  Dossier(s) infecté(s):
                                  (Aucun élément nuisible détecté)

                                  Fichier(s) infecté(s):
                                  C:\Windows\ktd32.atm (Backdoor.ProRat) -> Quarantined and deleted successfully.
                                  0
                                  1. Contributeur sécurité
                                    Bien.
                                    Comment se comporte ton PC ?
                                    0
                                    • 1
                                    • 2