Comment supprimer virus dans fichier .exe ?

Résolu
Bonjour,

J'ai tenté d'installer un programme de traitement de texte , j'ai naturellement exécuté le fichier setup.exe de ce programme que l'on m'a donné ; mais lors de l'execution mon anti-virus a détécté un virus nommé vitro qui est apparement incrusté dans le fichier setup.exe et je n'arrive pas à supprimer le virus sans que tous le fichier s'efface égalament (idem pour la mise en quarantaine) . Y'a t'il donc une manière d'isoler le virus afin de récuperer le fichier setup sain ?
Merci pour votre aide
roni
Configuration: Windows Vista Internet Explorer 8.0

16 réponses

  1. Contributeur sécurité
    Salut ,

    J'espère que tu n'as pas exécuté le fichier ! sinon Tu sera infecté par le pire nuisible du monde .... !

    on essaye de voir :

    Télécharge Random's System Information Tool (RSIT) par random/random et sauvegarde-le sur ton Bureau.

    ▶ Double-clique sur RSIT.exe afin de le lancer.

    ▶ Clique sur "Continue" à l'écran " Disclaimer of warranty ".

    ▶ Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.


    ▶ Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

    => Poste le contenu de log.txt (qui sera affiché) ainsi que de info.txt (qui sera réduit dans la Barre des Tâches).

    Note : Les deux rapports sont également sauvegardés ici : C:\rsit
    0
    1. Merci pour ton attention, je t'envoi cela dans quelques instants, le fichiers se trouve sur une clé usb ... mais j'imagine que ca a pu infecter l'ordi... a tt de suite
      0
      1. Voila le fichier info :

        info.txt logfile of random's system information tool 1.06 2009-09-06 11:47:57

        ======Uninstall list======

        -->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
        -->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
        -->MsiExec.exe /I{2EA870FA-585F-4187-903D-CB9FFD21E2E0}
        -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{31403E22-2FDB-452F-AE9E-20854633226D}\Setup.exe" -uninst
        -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A450831D-25F6-4F42-9662-D000B25E0D82}\setup.exe" -uninstall
        -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AA4BF92B-2AAF-11DA-9D78-000129760D75}\setup.exe" -uninstall
        -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B145EC69-66F5-11D8-9D75-000129760D75}\setup.exe" -uninstall
        -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B804C424-B66D-447A-84BD-C6B88C392C3A}\setup.exe" -uninstall
        -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F79A208D-D929-11D9-9D77-000129760D75}\setup.exe" -uninstall
        32 Bit HP CIO Components Installer-->MsiExec.exe /I{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}
        Acer Arcade Deluxe-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EFBDC2B0-FAA8-4B78-8DE1-AEBE7958FA37}\setup.exe" -uninstall
        Acer Crystal Eye webcam-->C:\Program Files\InstallShield Installation Information\{399C37FB-08AF-493B-BFED-20FBD85EDF7F}\setup.exe -runfromtemp -l0x040c -removeonly -u
        Acer Crystal Eye webcam-->C:\Program Files\InstallShield Installation Information\{AA047D7C-5E7C-4878-B75C-77589151B563}\setup.exe -runfromtemp -l0x0009 -removeonly
        Acer GridVista-->C:\Windows\UnInst32.exe GridV.UNI
        Acer Mobility Center Plug-In-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{11316260-6666-467B-AC34-183FCB5D4335}\setup.exe" -l0x40c -removeonly
        Acer ScreenSaver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}\setup.exe" -l0x9 -removeonly
        Acer Tour-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{94389919-B0AA-4882-9BE8-9F0B004ECA35}\setup.exe" -l0x40c -removeonly
        Acoolsoft PPT2Video Converter 3.0.0.38-->"C:\Program Files\Acoolsoft\PPT2Video Converter\unins000.exe"
        Activation Assistant for the 2007 Microsoft Office suites-->"C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
        Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
        Adobe Flash Player 10 Plugin-->MsiExec.exe /X{ECA1A3B6-898F-4DCE-9F04-714CF3BA126B}
        Adobe Reader 8.1.4-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81300000003}
        Apple Mobile Device Support-->MsiExec.exe /I{C337BDAF-CB4E-47E2-BE1A-CB31BB7DD0E3}
        Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
        Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
        Assistant de connexion Windows Live ID-->MsiExec.exe /X{10A44844-4465-456E-8C97-80BDD4F68845}
        avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
        Bricks of Egypt-->"C:\Program Files\Acer GameZone\Bricks of Egypt\Uninstall.exe" "C:\Program Files\Acer GameZone\Bricks of Egypt\install.log"
        Broadcom Gigabit Integrated Controller-->MsiExec.exe /X{D3B3B9B2-FE73-44CB-8C0A-F737D92F991B}
        CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
        CDBurnerXP-->"C:\Program Files\CDBurnerXP\unins000.exe"
        Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
        Ciel Auto-entrepreneur Facile 1.40-->MsiExec.exe /I{AF86BA3B-B465-4E12-B771-E12208FDB89B}
        DavkaWriter Platinum-->MsiExec.exe /I{7CCF4B02-5AAB-455C-904F-3347DBD542D9}
        FileZilla Client 3.2.6.1-->C:\Program Files\FileZilla FTP Client\uninstall.exe
        Galapago-->"C:\Program Files\Acer GameZone\Galapago\Uninstall.exe" "C:\Program Files\Acer GameZone\Galapago\install.log"
        Garmin WebUpdater-->MsiExec.exe /X{366FFC89-C800-4366-B903-B9C4314109A5}
        Gestionnaire pour appareils Windows Mobile-->MsiExec.exe /I{1F2A5DF9-40E1-4644-ADBD-D80F347BA6C8}
        GIMP 2.6.7-->"C:\Program Files\GIMP-2.0\setup\unins000.exe"
        Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
        Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_9DE96A29E721D90A.exe" /uninstall
        Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
        HDAUDIO Soft Data Fax Modem with SmartCP-->C:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFAOR2C06_118\UIU32m.exe -U -IAcrZUn32z.inf
        HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
        Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
        Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
        HP Customer Participation Program 8.0-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
        HP Imaging Device Functions 8.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
        HP OCR Software 8.0-->C:\Program Files\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
        HP Photosmart Essential-->MsiExec.exe /X{EB21A812-671B-4D08-B974-2A347F0D8F70}
        HP Photosmart.All-In-One Driver Software 8.0 .A-->C:\Program Files\HP\Digital Imaging\{282E5AB2-8E47-4571-B6FA-6B512555B557}\setup\hpzscr01.exe -datfile hposcr18.dat -onestop -showdisconnect -forcereboot
        HP Product Assistant-->MsiExec.exe /I{36FDBE6E-6684-462B-AE98-9A39A1B200CC}
        HP Solution Center 8.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
        HP Update-->MsiExec.exe /X{7059BDA7-E1DB-442C-B7A1-6144596720A4}
        HPSSupply-->MsiExec.exe /X{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}
        Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
        Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
        Intel PROSet Wireless-->Intel PROSet Wireless
        iTunes-->MsiExec.exe /I{99ECF41F-5CCA-42BD-B8B8-A8333E2E2944}
        IziSpot 4-->MsiExec.exe /X{117F577F-E35E-458A-87C5-FBF96879C5CE}
        Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216010FF}
        Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
        Jewel Quest Solitaire-->"C:\Program Files\Acer GameZone\Jewel Quest Solitaire\Uninstall.exe" "C:\Program Files\Acer GameZone\Jewel Quest Solitaire\install.log"
        K-Lite Codec Pack 3.9.0 Full-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
        Launch Manager-->C:\Windows\UnInst32.exe QtZgAcer.UNI
        LMSOFT Web Creator Pro 5-->C:\Program Files\Mindscape\LMSOFT Web Creator Pro 5\Uninstall.exe
        Luxor 2-->"C:\Program Files\Acer GameZone\Luxor 2\Uninstall.exe" "C:\Program Files\Acer GameZone\Luxor 2\install.log"
        Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
        Microsoft .NET Framework 3.5 SP1-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
        Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
        Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
        Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
        Microsoft Office InfoPath MUI (French) 2007-->MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}
        Microsoft Office Live Add-in 1.4-->MsiExec.exe /I{AE3CF174-872C-46C6-B9F6-C0593F3BC7B8}
        Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
        Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
        Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
        Microsoft Office Professional Plus 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
        Microsoft Office Professional Plus 2007-->MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}
        Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
        Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
        Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
        Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
        Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
        Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
        Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
        Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
        Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
        Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
        Microsoft Silverlight-->MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
        Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
        Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
        Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
        Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022-->MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
        Microsoft Works-->MsiExec.exe /I{6B1CB38D-E2E4-4A30-933D-EFDEBA76AD9C}
        Mise à jour du pilote du Gestionnaire pour appareils Windows Mobile-->MsiExec.exe /X{CB8CA439-DA83-419C-A4CF-5A0A50025144}
        Module de compatibilité pour Microsoft Office System 2007-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
        Mozilla Firefox (2.0)-->C:\Program Files\Mozilla Firefox\uninstall\uninst.exe
        MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
        MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
        MSXML 4.0 SP2 (KB941833)-->MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
        MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
        MSXML 4.0 SP2 Parser and SDK-->MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
        Mystery Case Files - Prime Suspects-->"C:\Program Files\Acer GameZone\Mystery Case Files - Prime Suspects\Uninstall.exe" "C:\Program Files\Acer GameZone\Mystery Case Files - Prime Suspects\install.log"
        Mystery Case Files Ravenhearst-->"C:\Program Files\Acer GameZone\Mystery Case Files Ravenhearst\Uninstall.exe" "C:\Program Files\Acer GameZone\Mystery Case Files Ravenhearst\install.log"
        NTI Backup NOW! 4.7-->"C:\Program Files\InstallShield Installation Information\{67ADE9AF-5CD9-4089-8825-55DE4B366799}\setup.exe" -removeonly
        NTI CD & DVD-Maker-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2} /l1036 CDM7
        NVIDIA Drivers-->C:\Windows\system32\NVUNINST.EXE UninstallGUI
        Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
        Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
        pdfforge Toolbar v1.0-->MsiExec.exe /X{B8B0FC8B-E69B-4215-AF1A-4BDFF20D794B}
        PDF-XChange 3.0-->"C:\Program Files\PDF-XChange 3 Pro\unins000.exe"
        PowerProducer 3.72-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\Setup.exe" -uninstall
        QuickTime-->MsiExec.exe /I{C78EAC6F-7A73-452E-8134-DBB2165C5A68}
        RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
        Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
        RICOH R5C83x/84x Flash Media Controller Driver Ver.3.52.02-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{59F6A514-9813-47A3-948C-8A155460CC2A}\Setup.exe" -l0x40c anything
        SIW version 2008-07-15-->"C:\Program Files\SIW\unins000.exe"
        Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
        TeamViewer 4-->C:\Program Files\TeamViewer\Version4\uninstall.exe
        Treasures of the Deep-->"C:\Program Files\Acer GameZone\Treasures of the Deep\Uninstall.exe" "C:\Program Files\Acer GameZone\Treasures of the Deep\install.log"
        Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
        Winbond CIR Drivers-->MsiExec.exe /X{427967BF-09F8-46D5-9275-37001CCBBA5D}
        Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
        Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
        Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
        Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}

        ======Security center information======

        AS: Windows Defender (disabled) (outdated)

        ======System event log======

        Computer Name: AharonBloch
        Event Code: 4374
        Message: Windows Servicing a déterminé que ce package KB958644(Security Update) n’est pas applicable à ce système.
        Record Number: 69909
        Source Name: Microsoft-Windows-Servicing
        Time Written: 20081023202213.000000-000
        Event Type: Avertissement
        User: AUTORITE NT\SYSTEM

        Computer Name: AharonBloch
        Event Code: 4374
        Message: Windows Servicing a déterminé que ce package KB958644(Security Update) n’est pas applicable à ce système.
        Record Number: 69910
        Source Name: Microsoft-Windows-Servicing
        Time Written: 20081023202213.000000-000
        Event Type: Avertissement
        User: AUTORITE NT\SYSTEM

        Computer Name: AharonBloch
        Event Code: 4227
        Message: TCP/IP n’a pas pu établir une connexion sortante car le point de terminaison local sélectionné a été récemment utilisé pour se connecter au même point de terminaison distant. Cette erreur se produit généralement lorsque les connexions sortantes sont ouvertes et fermées à un débit élevé, provoquant l’utilisation de tous les ports locaux disponibles et obligeant TCP/IP à réutiliser un port local pour une connexion sortante. Pour réduire le risque d’altération des données, la norme TCP/IP exige qu’un laps de temps minimal s’écoule entre des connexions successives d’un point de terminaison local à un point de terminaison distant.
        Record Number: 69926
        Source Name: Tcpip
        Time Written: 20081023202704.101807-000
        Event Type: Avertissement
        User:

        Computer Name: AharonBloch
        Event Code: 6008
        Message: L'arrêt système précédant à 01:02:56 le 24/10/2008 n'était pas prévu.
        Record Number: 69931
        Source Name: EventLog
        Time Written: 20081024053949.000000-000
        Event Type: Erreur
        User:

        Computer Name: AharonBloch
        Event Code: 4
        Message: Broadcom NetLink (TM) Gigabit Ethernet: The network link is down. Check to make sure the network cable is properly connected.
        Record Number: 69942
        Source Name: b57nd60x
        Time Written: 20081024053908.031325-000
        Event Type: Avertissement
        User:

        =====Application event log=====

        Computer Name: AharonBloch
        Event Code: 63
        Message: Le fournisseur OffPr

        Voila le fichier log

        Logfile of random's system information tool 1.06 (written by random/random)
        Run by Aharon at 2009-09-06 11:58:03
        Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
        System drive C: has 34 GB (30%) free of 114 GB
        Total RAM: 3070 MB (39% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 11:58:08, on 06/09/2009
        Platform: Windows Vista SP1 (WinNT 6.00.1905)
        MSIE: Internet Explorer v8.00 (8.00.6001.18813)
        Boot mode: Normal

        Running processes:
        C:\Windows\system32\Dwm.exe
        C:\Windows\Explorer.EXE
        C:\Program Files\Windows Defender\MSASCui.exe
        C:\Program Files\Synaptics\SynTP\SynTPStart.exe
        C:\Windows\RtHDVCpl.exe
        C:\Program Files\Launch Manager\QtZgAcer.EXE
        C:\Windows\System32\rundll32.exe
        C:\Program Files\Alwil Software\Avast4\ashDisp.exe
        C:\Program Files\pdfforge Toolbar\SearchSettings.exe
        C:\Program Files\Java\jre6\bin\jusched.exe
        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        C:\Windows\ehome\ehtray.exe
        C:\Program Files\Windows Media Player\wmpnscfg.exe
        C:\Windows\System32\rundll32.exe
        C:\Windows\system32\taskeng.exe
        C:\Windows\ehome\ehmsas.exe
        C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
        C:\Windows\system32\WerCon.exe
        C:\Windows\system32\wbem\unsecapp.exe
        C:\Users\Aharon\AppData\Local\Temp\RtkBtMnt.exe
        C:\Program Files\Java\jre6\bin\jucheck.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
        C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
        C:\Program Files\Microsoft\Office Live\OfficeLiveSignIn.exe
        C:\Program Files\Microsoft Office\Office12\POWERPNT.EXE
        C:\Program Files\Davka Corp\DavkaWriter\davwrite.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Windows\system32\SearchFilterHost.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Users\Aharon\Desktop\RSIT.exe
        C:\Program Files\trend micro\Aharon.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.cherche.us/keyword/%s
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ww12.cherche.us
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ww12.cherche.us
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tropal.net/
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ww12.cherche.us
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
        R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.cherche.us/keyword/%s
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://ww12.cherche.us
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
        R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll
        O1 - Hosts: ::1 localhost
        O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
        O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
        O2 - BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll
        O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll
        O3 - Toolbar: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll
        O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
        O4 - HKLM\..\Run: [ALaunch] C:\Acer\ALaunch\AlaunchClient.exe
        O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
        O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
        O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
        O4 - HKLM\..\Run: [PLFSet] rundll32.exe C:\Windows\PLFSet.dll,PLFDefSetting
        O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
        O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
        O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\pdfforge Toolbar\SearchSettings.exe
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
        O4 - HKCU\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
        O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
        O4 - Global Startup: Empowering Technology Launcher.lnk = ?
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
        O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
        O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
        O13 - Gopher Prefix:
        O15 - Trusted Zone: http://www.secuser.com
        O16 - DPF: Garmin Communicator Plug-In - https://my.garmin.com/mygarmin/m/GarminAxControl.CAB
        O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-5/myWebFaceInitialSetup1.0.1.2.cab
        O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
        O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-27-0.cab
        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
        O16 - DPF: {D79B6F43-F214-4E7A-9ECB-CCC8771F2416} (LauncherV1 Class) - http://www.tapuz.co.il/irc/main/launcher.cab
        O16 - DPF: {DFB5BCF1-06AE-4ABB-BFA8-1E228F41C50A} - https://www.bobtv.fr/download/cfweb_www.bobtv.fr-download_instmodule.exe
        O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
        O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
        O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
        O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
        O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
        O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
        O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
        O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
        O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
        O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
        O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
        O23 - Service: TeamViewer 4 (TeamViewer4) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
        O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
        0
        1. Contributeur sécurité
          Re,

          T'es clés usb sont infectés , + une toolbar infectée.

          On commence ^^' :

          ▶ Sous Vista :

          Désactive l'UAC qui peut gêner fortement la procédure de désinfection. :

          ▶ Menu Démarrer > Panneaux de configuration .

          ▶ Clique sur l'icône " Comptes d'utilisateurs " puis sur " Activer ou désactiver le contrôle des comptes d'utilisateurs " .

          ▶ Décoche la case : " Utiliser le contrôle des comptes d'utilisateurs pour vous aider à protéger votre ordinateur "

          ▶ Valide par OK , il sera demandé de redemarrer le PC , fais le ! .

          ▶ Pour t'aider :Tutoriel 1 - Tutoriel 2 - Tutoriel 3


          ========================

          ▶ TRÈS IMPORTANT :

          * Pendant toute la procédure de désinfection , vérifie que l'UAC soit bien désactivée.
          * Exécute toujours les programmes de désinfection en tant qu'administrateur ( Clic droit > "Exécuter en tant qu'admin..." )

          ========================

          Télécharge ToolBar S&D ( de Eric_71/Team IDN )

          ▶ Lance l'installation du programme en exécutant le fichier téléchargé et laisse le te guider pendant l'installation ..

          ! Déconnecte toi et ferme toutes tes applications en cours le temps de la manipe !

          ▶ Fais un clic droit sur le raccourci ToolbarS&D et choisis "exécuter en tant qu'administrateur"

          ▶ Tape sur 2 ( nettoyage ) puis tape sur [Entrée].

          ▶ Ne touche a rien pendant le scan

          ▶ Un rapport sera généré à la fin du processus : poste son contenu dans ta prochaine réponse

          NOTE:
          Le rapport est sauvegardé ici -> C:\TB.txt

          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

          **********************************************************
          ********************* Vista_Option 1(recherche) ****************
          **********************************************************

          Désactive l'UAC

          Télécharge UsbFix (de C_XX , Chiquitine29 , & Chimay8)
          > Ou ici : UsbFix

          ▶ Lance le fichier téléchargé, ne touche pas aux paramètres de l'installe !.

          ▶ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectés (!) sans les ouvrir (!)

          ▶ Fais un clic droit sur le raccourci UsbFix présent sur ton bureau et choisis "Exécuter en tant qu'administrateur" .

          ▶ Au menu principal choisis l'option " F " pour français et tape sur [entrée] .

          ▶ Au second menu Choisis l'option 1 (recherche)

          ▶ Laisse travailler l'outil

          ▶ Ensuite poste le rapport UsbFix.txt qui apparaîtra

          Notes :
          1- le rapport UsbFix.txt est sauvegardé a la racine du disque

          2- Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides

          3- "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
          Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
          Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
          0
          1. RE

            voici le rapport TB :

            -----------\\ ToolBar S&D 1.2.9 XP/Vista

            Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
            X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU T5550 @ 1.83GHz )
            BIOS : ZD1 v1.3809 3H09
            USER : Aharon ( Not Administrator ! )
            BOOT : Normal boot
            C:\ (Local Disk) - NTFS - Total:111 Go (Free:33 Go)
            D:\ (Local Disk) - NTFS - Total:108 Go (Free:107 Go)
            E:\ (Local Disk) - FAT32 - Total:149 Go (Free:131 Go)
            F:\ (CD or DVD)
            G:\ (USB) - FAT32 - Total:3816 Mo (Free:2 Go)

            "C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
            Option : [2] ( 06/09/2009|12:27 )

            [ UAC => 0 ]

            -----------\\ SUPPRESSION

            Supprime! - C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com

            -----------\\ Recherche de Fichiers / Dossiers ...

            -----------\\ [..\Internet Explorer\Main]

            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
            "Start Page"="https://www.google.fr/?gws_rd=ssl"
            "SEARCH PAGE"="http://ww12.cherche.us"
            "Local Page"="C:\\Windows\\system32\\blank.htm"
            "SearchMigratedDefaultURL"="http://ww12.cherche.us{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
            "Start Page_bak"="http://ww12.cherche.us"
            "Search Bar"="http://ww12.cherche.us"
            "Default_Search_URL"="http://www.cherche.us/keyword/%s"
            "Url"="https://www.msn.com/fr-fr/actualite/"

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
            "Start Page"="https://www.msn.com/fr-fr/"
            "Default_Page_URL"="https://fr.yahoo.com/"
            "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
            "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
            "Local Page"="C:\\Windows\\System32\\blank.htm"

            --------------------\\ Recherche d'autres infections

            Aucune autre infection trouvée !

            [ UAC => 1 ]

            1 - "C:\ToolBar SD\TB_1.txt" - 06/09/2009|12:27 - Option : [2]

            -----------\\ Fin du rapport a 12:27:49,63

            Voici le rapport USBfix

            ############################## | UsbFix V6.026 |

            User : Aharon (Administrateurs) # AHARONBLOCH
            Update on 06/09/2009 by Chiquitine29, C_XX & Chimay8
            Start at: 12:29:27 | 06/09/2009
            Website : http://pagesperso-orange.fr/NosTools/index.html

            Intel(R) Core(TM)2 Duo CPU T5550 @ 1.83GHz
            Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
            Internet Explorer 8.0.6001.18813
            Windows Firewall Status : Enabled

            C:\ -> Disque fixe local # 111,69 Go (34,09 Go free) [ACER] # NTFS
            D:\ -> Disque fixe local # 108,19 Go (107,83 Go free) [DATA] # NTFS
            E:\ -> Disque fixe local # 149,01 Go (131,88 Go free) [FREECOM HDD] # FAT32
            F:\ -> Disque CD-ROM
            G:\ -> Disque amovible # 3,73 Go (2,92 Go free) [AHARON] # FAT32

            ############################## | Processus actifs |

            C:\Windows\System32\smss.exe
            C:\Windows\system32\csrss.exe
            C:\Windows\system32\wininit.exe
            C:\Windows\system32\csrss.exe
            C:\Windows\system32\services.exe
            C:\Windows\system32\lsass.exe
            C:\Windows\system32\lsm.exe
            C:\Windows\system32\winlogon.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\SLsvc.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\Windows\system32\Dwm.exe
            C:\Program Files\Alwil Software\Avast4\ashServ.exe
            C:\Windows\Explorer.EXE
            C:\Windows\system32\WLANExt.exe
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\Program Files\Synaptics\SynTP\SynTPStart.exe
            C:\Windows\RtHDVCpl.exe
            C:\Program Files\Launch Manager\QtZgAcer.EXE
            C:\Windows\System32\rundll32.exe
            C:\Program Files\Alwil Software\Avast4\ashDisp.exe
            C:\Program Files\pdfforge Toolbar\SearchSettings.exe
            C:\Program Files\Java\jre6\bin\jusched.exe
            C:\Program Files\Common Files\Real\Update_OB\realsched.exe
            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            C:\Windows\ehome\ehtray.exe
            C:\Program Files\Windows Media Player\wmpnscfg.exe
            C:\Windows\System32\rundll32.exe
            C:\Windows\System32\spoolsv.exe
            C:\Windows\system32\taskeng.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\ehome\ehmsas.exe
            C:\Acer\ALaunch\ALaunchSvc.exe
            C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
            C:\Windows\system32\svchost.exe
            C:\Program Files\Intel\WiFi\bin\EvtEng.exe
            C:\Windows\system32\svchost.exe
            C:\Program Files\Common Files\LightScribe\LSSrvc.exe
            C:\Acer\Mobility Center\MobilityService.exe
            C:\Windows\System32\svchost.exe
            C:\Program Files\CDBurnerXP\NMSAccessU.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
            C:\Program Files\CyberLink\Shared Files\RichVideo.exe
            C:\Windows\system32\svchost.exe
            C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
            C:\Windows\System32\svchost.exe
            C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
            C:\Windows\system32\SearchIndexer.exe
            C:\Windows\system32\DRIVERS\xaudio.exe
            C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
            C:\Windows\system32\wbem\wmiprvse.exe
            C:\Windows\system32\wbem\wmiprvse.exe
            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            C:\Program Files\Windows Media Player\wmpnetwk.exe
            C:\Windows\system32\WerCon.exe
            C:\Windows\ehome\ehsched.exe
            C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
            C:\Windows\system32\wbem\unsecapp.exe
            C:\Users\Aharon\AppData\Local\Temp\RtkBtMnt.exe
            C:\Windows\ehome\ehRecvr.exe
            C:\Windows\system32\taskeng.exe
            C:\Windows\system32\svchost.exe
            C:\Program Files\Java\jre6\bin\jucheck.exe
            C:\Windows\system32\WUDFHost.exe
            C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
            C:\Windows\system32\msiexec.exe
            C:\Windows\system32\conime.exe
            C:\Windows\system32\NOTEPAD.EXE
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Internet Explorer\iexplore.exe

            ################## | Fichiers # Dossiers infectieux |

            Présent ! D:\install.exe
            Présent ! G:\MS32DLL.dll.vbs
            Présent ! G:\Recycler\S-5-3-42-2819952290-8240758988-879315005-3665
            Présent ! G:\Recycler\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx

            ################## | Suspect ! ... | https://www.virustotal.com/gui/ |

            ################## | Registre # Clés Run infectieuses |

            ################## | Registre # Mountpoints2 |

            HKCU\..\..\Explorer\MountPoints2\{2648f02c-93e9-11dd-b1fa-001e6817d35b}
            shell\AutoRun\command =E:\EXPLORER.EXE
            shell\explore\Command =E:\EXPLORER.EXE
            shell\open\Command =E:\EXPLORER.EXE

            HKCU\..\..\Explorer\MountPoints2\{76845ae3-e2da-11dd-9a35-001e6817d35b}
            shell\AutoRun\command =i.exe
            shell\explore\Command =i.exe
            shell\open\Command =i.exe

            ################## | ! Fin du rapport # UsbFix V6.026 ! |

            MERCI BCP
            0
            1. Contributeur sécurité
              En plus du conficker sur ta clé ! bref t'es mal barré !!! :x

              **********************************************************
              ********************* Vista_Option 2 (Nettoyage) ***************
              **********************************************************
              Toujours avec l'UAC désactivée :

              ▶ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectés (!) sans les ouvrir (!)

              ▶ Fais un clic droit sur le raccourci UsbFix présent sur ton bureau et choisis "Exécuter en tant qu'administrateur" .

              ▶ Au menu principal choisis l'option " F " pour français et tape sur [entrée] .

              ▶ Au second menu choisis l'option 2 ( Suppression )

              ▶ Ton bureau disparaîtra et le PC redémarrera .

              ▶ Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.

              ▶ Ensuite poste le rapport UsbFix.txt qui apparaîtra avec le bureau .

              ▶ Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

              Aide : Comment Utiliser UsbFix

              ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

              Désactive l'UAC

              **********************************************************
              ********************* Option S (Scan) *********************
              **********************************************************

              Télécharge AD-Remover ( de C_XX ) sur ton bureau :

              ! Déconnecte toi et ferme toutes applications en cours !

              • Double clique sur "AD-R.exe" pour lancer l'installation et laisse les paramètres d'installation par défaut .

              • fais un clic droit sur le raccourci Ad-remover qui est sur ton bureau et choisis "exécuter en tant qu'administrateur".

              • Au menu principal choisis l'option "S" et tape sur [entrée] .

              • Laisse travailler l'outil et ne touche à rien ...

              --> Poste le rapport qui apparait à la fin , sur le forum ... <--

              Notes:

              1- Le rapport est sauvegardé aussi sous C:\Ad-report-scan.log
              2- "Process.exe", une composante de l'outil, est détecté par certains antivirus :
              (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
              Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
              Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
              0
              1. voici le log usbfix

                ############################## | UsbFix V6.026 |

                User : Aharon (Administrateurs) # AHARONBLOCH
                Update on 06/09/2009 by Chiquitine29, C_XX & Chimay8
                Start at: 12:59:14 | 06/09/2009
                Website : http://pagesperso-orange.fr/NosTools/index.html

                Intel(R) Core(TM)2 Duo CPU T5550 @ 1.83GHz
                Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
                Internet Explorer 8.0.6001.18813
                Windows Firewall Status : Enabled

                C:\ -> Disque fixe local # 111,69 Go (34,09 Go free) [ACER] # NTFS
                D:\ -> Disque fixe local # 108,19 Go (107,83 Go free) [DATA] # NTFS
                E:\ -> Disque fixe local # 149,01 Go (131,88 Go free) [FREECOM HDD] # FAT32
                F:\ -> Disque CD-ROM
                G:\ -> Disque amovible # 3,73 Go (2,92 Go free) [AHARON] # FAT32

                ############################## | Processus actifs |

                C:\Windows\System32\smss.exe
                C:\Windows\system32\csrss.exe
                C:\Windows\system32\wininit.exe
                C:\Windows\system32\csrss.exe
                C:\Windows\system32\services.exe
                C:\Windows\system32\lsass.exe
                C:\Windows\system32\lsm.exe
                C:\Windows\system32\winlogon.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\SLsvc.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                C:\Windows\system32\WLANExt.exe
                C:\Windows\system32\Dwm.exe
                C:\Windows\Explorer.EXE
                C:\Windows\system32\taskeng.exe
                C:\Windows\System32\spoolsv.exe
                C:\Windows\system32\svchost.exe
                C:\Acer\ALaunch\ALaunchSvc.exe
                C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                C:\Windows\system32\svchost.exe
                C:\Program Files\Intel\WiFi\bin\EvtEng.exe
                C:\Windows\system32\svchost.exe
                C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                C:\Acer\Mobility Center\MobilityService.exe
                C:\Windows\System32\svchost.exe
                C:\Program Files\CDBurnerXP\NMSAccessU.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
                C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                C:\Windows\system32\svchost.exe
                C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
                C:\Windows\System32\svchost.exe
                C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
                C:\Windows\system32\SearchIndexer.exe
                C:\Windows\system32\DRIVERS\xaudio.exe
                C:\Windows\system32\WUDFHost.exe
                C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                C:\Windows\system32\wbem\wmiprvse.exe
                C:\Windows\system32\wbem\wmiprvse.exe
                C:\Program Files\Windows Defender\MSASCui.exe
                C:\Program Files\Synaptics\SynTP\SynTPStart.exe
                C:\Windows\RtHDVCpl.exe
                C:\Program Files\Launch Manager\QtZgAcer.EXE
                C:\Windows\System32\rundll32.exe
                C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
                C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                C:\Program Files\Java\jre6\bin\jusched.exe
                C:\Windows\system32\WerCon.exe
                C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
                C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                C:\Windows\System32\rundll32.exe
                C:\Windows\ehome\ehtray.exe
                C:\Program Files\Windows Media Player\wmpnscfg.exe
                C:\Program Files\Windows Media Player\wmpnetwk.exe
                C:\Windows\ehome\ehmsas.exe
                C:\Windows\system32\wbem\unsecapp.exe
                C:\Users\Aharon\AppData\Local\Temp\RtkBtMnt.exe
                C:\Windows\ehome\ehsched.exe
                C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Windows\ehome\ehRecvr.exe
                C:\Windows\system32\taskeng.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
                C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
                C:\Windows\system32\SearchProtocolHost.exe
                C:\Windows\system32\SearchFilterHost.exe
                C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\System32\mobsync.exe
                C:\Windows\system32\conime.exe

                ################## | Fichiers # Dossiers infectieux |

                Présent ! D:\install.exe
                Présent ! G:\MS32DLL.dll.vbs
                Présent ! G:\Recycler\S-5-3-42-2819952290-8240758988-879315005-3665
                Présent ! G:\Recycler\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx

                ################## | Suspect ! ... | https://www.virustotal.com/gui/ |

                ################## | Registre # Clés Run infectieuses |

                ################## | Registre # Mountpoints2 |

                HKCU\..\..\Explorer\MountPoints2\{2648f02c-93e9-11dd-b1fa-001e6817d35b}
                shell\AutoRun\command =E:\EXPLORER.EXE
                shell\explore\Command =E:\EXPLORER.EXE
                shell\open\Command =E:\EXPLORER.EXE

                HKCU\..\..\Explorer\MountPoints2\{76845ae3-e2da-11dd-9a35-001e6817d35b}
                shell\AutoRun\command =i.exe
                shell\explore\Command =i.exe
                shell\open\Command =i.exe

                ################## | ! Fin du rapport # UsbFix V6.026 ! |

                voici le log ad-report

                .
                ======= RAPPORT D'AD-REMOVER 1.1.4.5_T | UNIQUEMENT XP/VISTA/7 =======
                .
                Mit à jour par C_XX le 05/09/2009 à 12:20 PM
                Contact: AdRemover.contact@gmail.com
                Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
                .
                Lancé à: 13:02:17, 06/09/2009 | Mode Normal | Option: SCAN
                Exécuté de: C:\Program Files\Ad-Remover\
                Système d'exploitation: Microsoft® Windows Vista™ Home Premium Service Pack 1 v6.0.6001
                Nom du PC: AHARONBLOCH | Utilisateur actuel: Aharon
                .
                ============== ÉLÉMENT(S) TROUVÉ(S) ==============
                .
                .
                HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
                HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
                HKCR\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
                HKLM\Software\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
                .
                C:\Users\Aharon\AppData\LocalLow\Search Settings
                C:\Windows\Installer\a9ccaa.msi
                C:\Program Files\Windows Live\Messenger\Riched20.dll
                .
                ============== Scan additionnel ==============
                .
                .
                * Mozilla FireFox Version 2.0 *
                .
                Nom du profil: ahe19kzn.default (Aharon)
                .
                (Prefs.js) user_pref("browser.search.defaultenginename", "Google");
                (Prefs.js) user_pref("browser.search.selectedEngine", "Google");
                (Prefs.js) user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=");
                (Prefs.js) user_pref("browser.startup.homepage", "hxxp://www.cherche.us/");
                (Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.8.1");
                .
                .
                .
                * Internet Explorer Version 8.0.6001.18813 *
                .
                [HKEY_CURRENT_USER\..\Internet Explorer\Main]
                .
                Start Page: hxxp://www.google.fr/
                SEARCH PAGE: hxxp://www.cherche.us
                Start Page_bak: hxxp://www.cherche.us
                Search Bar: hxxp://www.cherche.us
                Default_Search_URL: hxxp://www.cherche.us/keyword/%s
                .
                [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
                .
                Start Page: hxxp://www.msn.com/
                Default_Page_URL: hxxp://fr.fr.acer.yahoo.com
                Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
                Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
                .
                [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
                .
                Tabs: res://ieframe.dll/tabswelcome.htm
                .
                ===================================
                .
                2249 Octet(s) - C:\Ad-Report-SCAN.log
                .
                107 Fichier(s) - C:\Users\Aharon\AppData\Local\Temp
                30 Fichier(s) - C:\Windows\Temp
                .
                1 Fichier(s) - C:\Program Files\Ad-Remover\BACKUP
                0 Fichier(s) - C:\Program Files\Ad-Remover\QUARANTINE
                .
                Fin à: 13:32:25 | 06/09/2009
                .
                ============== E.O.F ==============
                .
                merci bien
                0
                1. Contributeur sécurité
                  Re,

                  Relis les manips stp ; UsbFix option 2 !

                  **********************************************************
                  ********************* Option L (nettoyage) *********************
                  **********************************************************

                  ! Déconnecte toi et ferme toutes applications en cours !

                  • fais un clic droit sur le raccourci Ad-remover qui est sur ton bureau et choisis "exécuter en tant qu'administrateur".

                  • Au menu principal choisis l'option "L" et tape sur [entrée] .

                  • Laisse travailler l'outil et ne touche à rien ...

                  --> Poste le rapport qui apparait à la fin , sur le forum ... <--

                  Notes:

                  1- Le rapport est sauvegardé aussi sous C:\Ad-report-clean.log
                  2- "Process.exe", une composante de l'outil, est détecté par certains antivirus :
                  (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                  Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                  Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.


                  Aide en images (Nettoyage)

                  **********************************************************
                  ********************* Vista_Option 2 (Nettoyage) ***************
                  **********************************************************
                  Toujours avec l'UAC désactivée :

                  ▶ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectés (!) sans les ouvrir (!)

                  ▶ Fais un clic droit sur le raccourci UsbFix présent sur ton bureau et choisis "Exécuter en tant qu'administrateur" .

                  ▶ Au menu principal choisis l'option " F " pour français et tape sur [entrée] .

                  ▶ Au second menu choisis l'option 2 ( Suppression )

                  ▶ Ton bureau disparaîtra et le PC redémarrera .

                  ▶ Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.

                  ▶ Ensuite poste le rapport UsbFix.txt qui apparaîtra avec le bureau .

                  ▶ Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

                  Aide : Comment Utiliser UsbFix
                  0
                  1. rapport usbfix

                    ############################## | UsbFix V6.026 |

                    User : Aharon (Administrateurs) # AHARONBLOCH
                    Update on 06/09/2009 by Chiquitine29, C_XX & Chimay8
                    Start at: 17:57:14 | 06/09/2009
                    Website : http://pagesperso-orange.fr/NosTools/index.html

                    Intel(R) Core(TM)2 Duo CPU T5550 @ 1.83GHz
                    Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
                    Internet Explorer 8.0.6001.18813
                    Windows Firewall Status : Enabled

                    C:\ -> Disque fixe local # 111,69 Go (33,67 Go free) [ACER] # NTFS
                    D:\ -> Disque fixe local # 108,19 Go (107,83 Go free) [DATA] # NTFS
                    F:\ -> Disque CD-ROM
                    G:\ -> Disque amovible # 3,73 Go (2,92 Go free) [AHARON] # FAT32

                    ############################## | Processus actifs |

                    C:\Windows\System32\smss.exe
                    C:\Windows\system32\csrss.exe
                    C:\Windows\system32\wininit.exe
                    C:\Windows\system32\csrss.exe
                    C:\Windows\system32\services.exe
                    C:\Windows\system32\lsass.exe
                    C:\Windows\system32\lsm.exe
                    C:\Windows\system32\winlogon.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\System32\svchost.exe
                    C:\Windows\System32\svchost.exe
                    C:\Windows\System32\svchost.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\system32\LogonUI.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\system32\SLsvc.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\system32\svchost.exe
                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                    C:\Windows\system32\Dwm.exe
                    C:\Program Files\Alwil Software\Avast4\ashServ.exe
                    C:\Windows\Explorer.EXE
                    C:\Windows\system32\WLANExt.exe
                    C:\Windows\System32\spoolsv.exe
                    C:\Windows\system32\taskeng.exe
                    C:\Windows\system32\svchost.exe
                    C:\Acer\ALaunch\ALaunchSvc.exe
                    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                    C:\Windows\system32\svchost.exe
                    C:\Program Files\Intel\WiFi\bin\EvtEng.exe
                    C:\Windows\system32\svchost.exe
                    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                    C:\Acer\Mobility Center\MobilityService.exe
                    C:\Windows\System32\svchost.exe
                    C:\Program Files\CDBurnerXP\NMSAccessU.exe
                    C:\Windows\System32\svchost.exe
                    C:\Windows\system32\svchost.exe
                    C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
                    C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                    C:\Windows\system32\svchost.exe
                    C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
                    C:\Windows\System32\svchost.exe
                    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
                    C:\Windows\system32\SearchIndexer.exe
                    C:\Windows\system32\DRIVERS\xaudio.exe
                    C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                    C:\Windows\system32\runonce.exe
                    C:\Windows\system32\conime.exe
                    C:\Windows\system32\WUDFHost.exe
                    C:\Windows\system32\wbem\wmiprvse.exe
                    C:\Windows\system32\wbem\wmiprvse.exe
                    C:\Windows\system32\taskeng.exe
                    C:\Program Files\Windows Calendar\WinCal.exe

                    ################## | Fichiers # Dossiers infectieux |

                    Supprimé ! D:\install.exe
                    Supprimé ! G:\MS32DLL.dll.vbs
                    Supprimé ! G:\Recycler\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx
                    Supprimé ! G:\Recycler\S-5-3-42-2819952290-8240758988-879315005-3665

                    ################## | Autres |

                    ################## | Suspect ! ... | https://www.virustotal.com/gui/ |

                    ################## | Registre # Clés Run infectieuses |

                    ################## | Registre # Mountpoints2 |

                    Supprimé ! HKCU\...\Explorer\MountPoints2\{2648f02c-93e9-11dd-b1fa-001e6817d35b}\Shell\AutoRun\Command
                    Supprimé ! HKCU\...\Explorer\MountPoints2\{76845ae3-e2da-11dd-9a35-001e6817d35b}\Shell\AutoRun\Command

                    ################## | Listing des fichiers présent |

                    [21/12/2007 07:23|--a------|3377] C:\-20071221.log
                    [21/05/2008 20:56|--a------|3913] C:\-20080521.log
                    [06/09/2009 13:32|--a------|2565] C:\Ad-Report-SCAN.log
                    [18/09/2006 23:43|--a------|24] C:\autoexec.bat
                    [19/01/2008 09:45|-rahs----|333203] C:\bootmgr
                    [21/12/2007 13:31|-ra-s----|8192] C:\BOOTSECT.BAK
                    [18/09/2006 23:43|--a------|10] C:\config.sys
                    [11/08/2008 12:47|--a------|117] C:\finfos.txt
                    [?|?|?] C:\hiberfil.sys
                    [06/09/2009 11:35|--a------|1029] C:\InstallHelper.log
                    [11/08/2008 12:50|-rahs----|0] C:\IO.SYS
                    [11/11/2008 01:09|--a------|7] C:\ISACER.id
                    [16/08/2005 09:49|---------|40960] C:\junction.exe
                    [28/06/2007 10:44|--a------|512] C:\MDR.iss
                    [22/02/2008 18:11|--a------|20] C:\Medion.ini
                    [11/08/2008 12:46|--a------|438] C:\mpeg.txt
                    [11/08/2008 12:50|-rahs----|0] C:\MSDOS.SYS
                    [29/02/2004 17:44|--a------|52576] C:\orange.bmp
                    [?|?|?] C:\pagefile.sys
                    [22/02/2008 18:08|--a------|60] C:\Partition.txt
                    [22/02/2008 18:01|--a------|426] C:\RHDSetup.log
                    [21/12/2007 07:09|--a------|178] C:\setup.log
                    [25/03/2009 00:58|--ah-----|268] C:\sqmdata00.sqm
                    [30/04/2009 20:58|--ah-----|232] C:\sqmdata01.sqm
                    [01/05/2009 10:41|--ah-----|232] C:\sqmdata02.sqm
                    [02/05/2009 22:28|--ah-----|232] C:\sqmdata03.sqm
                    [03/05/2009 02:32|--ah-----|232] C:\sqmdata04.sqm
                    [21/06/2009 01:23|--ah-----|232] C:\sqmdata05.sqm
                    [07/07/2009 15:49|--ah-----|232] C:\sqmdata06.sqm
                    [01/02/2009 19:04|--ah-----|232] C:\sqmdata07.sqm
                    [01/02/2009 19:10|--ah-----|232] C:\sqmdata08.sqm
                    [01/02/2009 19:18|--ah-----|232] C:\sqmdata09.sqm
                    [17/02/2009 15:44|--ah-----|232] C:\sqmdata10.sqm
                    [17/02/2009 18:36|--ah-----|232] C:\sqmdata11.sqm
                    [04/03/2009 16:43|--ah-----|232] C:\sqmdata12.sqm
                    [04/03/2009 16:45|--ah-----|232] C:\sqmdata13.sqm
                    [04/03/2009 17:27|--ah-----|232] C:\sqmdata14.sqm
                    [06/03/2009 15:04|--ah-----|232] C:\sqmdata15.sqm
                    [08/03/2009 09:53|--ah-----|232] C:\sqmdata16.sqm
                    [08/03/2009 12:51|--ah-----|232] C:\sqmdata17.sqm
                    [08/03/2009 12:51|--ah-----|232] C:\sqmdata18.sqm
                    [08/03/2009 13:35|--ah-----|232] C:\sqmdata19.sqm
                    [25/03/2009 00:58|--ah-----|244] C:\sqmnoopt00.sqm
                    [30/04/2009 20:58|--ah-----|244] C:\sqmnoopt01.sqm
                    [01/05/2009 10:41|--ah-----|244] C:\sqmnoopt02.sqm
                    [02/05/2009 22:28|--ah-----|244] C:\sqmnoopt03.sqm
                    [03/05/2009 02:32|--ah-----|244] C:\sqmnoopt04.sqm
                    [21/06/2009 01:23|--ah-----|244] C:\sqmnoopt05.sqm
                    [07/07/2009 15:49|--ah-----|244] C:\sqmnoopt06.sqm
                    [01/02/2009 19:04|--ah-----|244] C:\sqmnoopt07.sqm
                    [01/02/2009 19:10|--ah-----|244] C:\sqmnoopt08.sqm
                    [01/02/2009 19:18|--ah-----|244] C:\sqmnoopt09.sqm
                    [17/02/2009 15:44|--ah-----|244] C:\sqmnoopt10.sqm
                    [17/02/2009 18:36|--ah-----|244] C:\sqmnoopt11.sqm
                    [04/03/2009 16:43|--ah-----|244] C:\sqmnoopt12.sqm
                    [04/03/2009 16:45|--ah-----|244] C:\sqmnoopt13.sqm
                    [04/03/2009 17:27|--ah-----|244] C:\sqmnoopt14.sqm
                    [06/03/2009 15:04|--ah-----|244] C:\sqmnoopt15.sqm
                    [08/03/2009 09:53|--ah-----|244] C:\sqmnoopt16.sqm
                    [08/03/2009 12:51|--ah-----|244] C:\sqmnoopt17.sqm
                    [08/03/2009 12:51|--ah-----|244] C:\sqmnoopt18.sqm
                    [08/03/2009 13:35|--ah-----|244] C:\sqmnoopt19.sqm
                    [06/09/2009 12:27|--a------|2236] C:\TB.txt
                    [06/09/2009 18:01|--a------|6895] C:\UsbFix.txt
                    [07/11/2007 08:00|--a------|17734] D:\eula.1028.txt
                    [07/11/2007 08:00|--a------|17734] D:\eula.1031.txt
                    [07/11/2007 08:00|--a------|10134] D:\eula.1033.txt
                    [07/11/2007 08:00|--a------|17734] D:\eula.1036.txt
                    [07/11/2007 08:00|--a------|17734] D:\eula.1040.txt
                    [07/11/2007 08:00|--a------|118] D:\eula.1041.txt
                    [07/11/2007 08:00|--a------|17734] D:\eula.1042.txt
                    [07/11/2007 08:00|--a------|17734] D:\eula.2052.txt
                    [07/11/2007 08:00|--a------|17734] D:\eula.3082.txt
                    [07/11/2007 08:00|--a------|1110] D:\globdata.ini
                    [07/11/2007 08:00|--a------|843] D:\install.ini
                    [07/11/2007 08:03|--a------|76304] D:\install.res.1028.dll
                    [07/11/2007 08:03|--a------|96272] D:\install.res.1031.dll
                    [07/11/2007 08:03|--a------|91152] D:\install.res.1033.dll
                    [07/11/2007 08:03|--a------|97296] D:\install.res.1036.dll
                    [07/11/2007 08:03|--a------|95248] D:\install.res.1040.dll
                    [07/11/2007 08:03|--a------|81424] D:\install.res.1041.dll
                    [07/11/2007 08:03|--a------|79888] D:\install.res.1042.dll
                    [07/11/2007 08:03|--a------|75792] D:\install.res.2052.dll
                    [07/11/2007 08:03|--a------|96272] D:\install.res.3082.dll
                    [05/01/2002 11:48|--a------|974848] D:\mfc70.dll
                    [05/01/2002 11:36|--a------|964608] D:\mfc70u.dll
                    [05/01/2002 10:37|--a------|344064] D:\msvcr70.dll
                    [07/11/2007 08:00|--a------|5686] D:\vcredist.bmp
                    [07/11/2007 08:09|--a------|1442522] D:\VC_RED.cab
                    [07/11/2007 08:12|--a------|232960] D:\VC_RED.MSI
                    [18/06/2009 00:44|---h-----|1150464] G:\~WRL0004.tmp
                    [05/09/2009 23:44|--a------|1622] G:\BOOTEX.LOG

                    ################## | Upload |

                    Veuillez envoyer le fichier : C:\Users\Aharon\Desktop\UsbFix_Upload_Me_AharonBloch.zip : https://www.androidworld.fr/
                    Merci pour votre contribution .

                    raport ad-report

                    .
                    ======= RAPPORT D'AD-REMOVER 1.1.4.5_T | UNIQUEMENT XP/VISTA/7 =======
                    .
                    Mit à jour par C_XX le 05/09/2009 à 12:20 PM
                    Contact: AdRemover.contact@gmail.com
                    Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
                    .
                    Lancé à: 18:05:13, 06/09/2009 | Mode Normal | Option: CLEAN
                    Exécuté de: C:\Program Files\Ad-Remover\
                    Système d'exploitation: Microsoft® Windows Vista™ Home Premium Service Pack 1 v6.0.6001
                    Nom du PC: AHARONBLOCH | Utilisateur actuel: Aharon
                    .
                    ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
                    .
                    .
                    HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
                    HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
                    HKCR\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
                    .
                    C:\Users\Aharon\AppData\LocalLow\Search Settings\kb128
                    C:\Users\Aharon\AppData\LocalLow\Search Settings\kb128\temp
                    C:\Users\Aharon\AppData\LocalLow\Search Settings\kb128\temp\ws-14490.log
                    C:\Users\Aharon\AppData\LocalLow\Search Settings\kb128\temp\ws-14493.log
                    C:\Users\Aharon\AppData\LocalLow\Search Settings
                    C:\Windows\Installer\a9ccaa.msi
                    C:\Program Files\Windows Live\Messenger\riched20.dll

                    (!) -- Fichiers temporaires supprimés.

                    .
                    ============== Scan additionnel ==============
                    .
                    .
                    * Mozilla FireFox Version 2.0 *
                    .
                    Nom du profil: ahe19kzn.default (Aharon)
                    .
                    (Prefs.js) user_pref("browser.search.defaultenginename", "Google");
                    (Prefs.js) user_pref("browser.search.selectedEngine", "Google");
                    (Prefs.js) user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=");
                    (Prefs.js) user_pref("browser.startup.homepage", "hxxp://www.cherche.us/");
                    (Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.8.1");
                    .
                    .
                    .
                    * Internet Explorer Version 8.0.6001.18813 *
                    .
                    [HKEY_CURRENT_USER\..\Internet Explorer\Main]
                    .
                    Start Page: Window Title
                    SEARCH PAGE: hxxp://www.cherche.us
                    Start Page_bak: hxxp://www.cherche.us
                    Search Bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                    Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                    Default_page_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                    .
                    [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
                    .
                    Start Page: hxxp://fr.msn.com/
                    Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                    Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                    Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                    Search bar: hxxp://search.msn.com/spbasic.htm
                    .
                    [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
                    .
                    Tabs: res://ieframe.dll/tabswelcome.htm
                    .
                    ===================================
                    .
                    2735 Octet(s) - C:\Ad-Report-CLEAN.log
                    2565 Octet(s) - C:\Ad-Report-SCAN.log
                    .
                    1 Fichier(s) - C:\Users\Aharon\AppData\Local\Temp
                    1 Fichier(s) - C:\Windows\Temp
                    .
                    21 Fichier(s) - C:\Program Files\Ad-Remover\BACKUP
                    2 Fichier(s) - C:\Program Files\Ad-Remover\QUARANTINE
                    .
                    Fin à: 18:36:37 | 06/09/2009
                    .
                    ============== E.O.F ==============
                    .
                    0
                    1. Contributeur sécurité
                      Re,

                      Très bien ... ! ;)

                      Refais RSIT et colle le rapport obtenu pour l'analyse.

                      ++
                      0
                      1. voila :)

                        Logfile of random's system information tool 1.06 (written by random/random)
                        Run by Aharon at 2009-09-06 19:28:14
                        Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
                        System drive C: has 39 GB (34%) free of 114 GB
                        Total RAM: 3070 MB (55% free)

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 19:28:33, on 06/09/2009
                        Platform: Windows Vista SP1 (WinNT 6.00.1905)
                        MSIE: Internet Explorer v8.00 (8.00.6001.18813)
                        Boot mode: Normal

                        Running processes:
                        C:\Windows\system32\Dwm.exe
                        C:\Windows\system32\taskeng.exe
                        C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
                        C:\Program Files\Windows Media Player\wmpnscfg.exe
                        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                        C:\Windows\explorer.exe
                        C:\Windows\system32\wbem\unsecapp.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\Program Files\Microsoft\Office Live\OfficeLiveSignIn.exe
                        C:\Program Files\Microsoft Office\Office12\POWERPNT.EXE
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\Users\Aharon\Desktop\RSIT.exe
                        C:\Program Files\trend micro\Aharon.exe

                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ww12.cherche.us
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Window Title
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ww12.cherche.us
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                        R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.cherche.us/keyword/%s
                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://ww12.cherche.us
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                        R3 - Default URLSearchHook is missing
                        O1 - Hosts: ::1 localhost
                        O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
                        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                        O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                        O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
                        O2 - BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll
                        O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
                        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                        O3 - Toolbar: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll
                        O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                        O4 - HKLM\..\Run: [ALaunch] C:\Acer\ALaunch\AlaunchClient.exe
                        O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
                        O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                        O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
                        O4 - HKLM\..\Run: [PLFSet] rundll32.exe C:\Windows\PLFSet.dll,PLFDefSetting
                        O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
                        O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
                        O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                        O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
                        O4 - HKCU\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
                        O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                        O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                        O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                        O4 - Global Startup: Empowering Technology Launcher.lnk = ?
                        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                        O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
                        O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
                        O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
                        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                        O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
                        O13 - Gopher Prefix:
                        O15 - Trusted Zone: http://www.secuser.com
                        O16 - DPF: Garmin Communicator Plug-In - https://my.garmin.com/mygarmin/m/GarminAxControl.CAB
                        O16 - DPF: {DFB5BCF1-06AE-4ABB-BFA8-1E228F41C50A} - https://www.bobtv.fr/download/cfweb_www.bobtv.fr-download_instmodule.exe
                        O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
                        O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                        O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                        O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
                        O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                        O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                        O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
                        O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
                        O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
                        O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                        O23 - Service: TeamViewer 4 (TeamViewer4) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
                        O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                        0
                        1. Contributeur sécurité
                          Re ,

                          OK ce rapport est clean :)

                          J'ai une question : la clé usb , tu travailles avec ? si oui ben ton PC de travail est infecté par conficker , on pourra le désinfecter si tu souhaites , mais une fois celui la désinfecter et je vais t'ouvrir un topic en écrivant ton pseudo ...

                          Bref on continue :

                          Télécharge MalwareBytes' Anti-Malware (MBAM) .

                          ▶ Double clique sur le fichier téléchargé pour lancer le processus d’installation , choisis " Français" et accepte lorsqu’il te le sera demandé de le mettre a jour.

                          ▶ Regarde bien ce Tuto pour bien utiliser le programme.

                          ! Déconnecte toi ferme toutes applications en cours !

                          ⇒ Lance MBAM.

                          ▶ Sous l'onglet paramètre, et coche la case : "Arrêter internet explorer pendant la suppression"

                          ▶ Clique maintenant sur l'onglet recherche et coche la case : "Exécuter un examen rapide".

                          ▶ Puis clique sur " Rechercher ".

                          ▶ Laisse le scanner le PC...

                          ▶ Une fois l'analyse terminée, clique sur "OK", Ensuite sur "Afficher les résultats"

                          ▶ Vérifie que tout est bien coché et clique sur " Supprimer la sélection.. "

                          ▶ Il se peut qu'il te demande de redémarrer pour finir la suppression des nuisibles, accepte en cliquant sur "Yes".

                          ▶ A la fin un rapport va s'ouvrir, sauvegarde le de manière a le retrouver en vu de le poster sur le forum.

                          ▶ Reviens sur le forum et copie et colle le rapport dans ta prochaine réponse .

                          Note: les rapport sont aussi rangé dans l'onglet Rapport/Log
                          0
                          1. Salut , désolé pour cette longue absence j 'ai du partir quelque jours...
                            voila le log

                            merci

                            Malwarebytes' Anti-Malware 1.41
                            Version de la base de données: 2775
                            Windows 6.0.6001 Service Pack 1

                            12/09/2009 22:30:49
                            mbam-log-2009-09-12 (22-30-49).txt

                            Type de recherche: Examen rapide
                            Eléments examinés: 104581
                            Temps écoulé: 6 minute(s), 10 second(s)

                            Processus mémoire infecté(s): 0
                            Module(s) mémoire infecté(s): 0
                            Clé(s) du Registre infectée(s): 1
                            Valeur(s) du Registre infectée(s): 0
                            Elément(s) de données du Registre infecté(s): 0
                            Dossier(s) infecté(s): 0
                            Fichier(s) infecté(s): 0

                            Processus mémoire infecté(s):
                            (Aucun élément nuisible détecté)

                            Module(s) mémoire infecté(s):
                            (Aucun élément nuisible détecté)

                            Clé(s) du Registre infectée(s):
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

                            Valeur(s) du Registre infectée(s):
                            (Aucun élément nuisible détecté)

                            Elément(s) de données du Registre infecté(s):
                            (Aucun élément nuisible détecté)

                            Dossier(s) infecté(s):
                            (Aucun élément nuisible détecté)

                            Fichier(s) infecté(s):
                            (Aucun élément nuisible détecté)
                            0
                            1. Contributeur sécurité
                              Re,

                              Bonjour :)

                              Réponds aux questions !

                              J'ai une question : la clé usb , tu travailles avec ? si oui ben ton PC de travail est infecté par conficker , on pourra le désinfecter si tu souhaites , mais une fois celui la désinfecter et je vais t'ouvrir un topic en écrivant ton pseudo ...


                              Comment va ton PC ? du mieux ??
                              0
                              1. salut

                                le pc va mieux

                                merci pour ton aide

                                a bientôt
                                0
                                1. Contributeur sécurité
                                  Re,

                                  Salut roni ;)

                                  Heu... c'est pas terminé ! ^^

                                  Refais moi un RSIT stp.
                                  1