Ordinateur infecté

Résolu
Bonjour,
J'ai un problème avec mon ordi.
En effet je rame beaucoup et des fenetres intempestives apparaissent de temps en temps...
De plus, mon antivirus spybot me demande fréquemment si c'est moi qui modifie le registre et je refuse et des fenetres apparaissent par dizaines "modification du registre par ExlcudeFromKnownDlls refusée"
J'ai beau faire des analyses avec avast, rien de rien Aidez moi svp :(
Merci Beaucoup ;-)
Configuration: Windows Vista
Internet Explorer 7.0

37 réponses

Résumé de la discussion

Un problème de ralentissement et de fenêtres intempestives survient sur un PC sous Windows Vista avec Internet Explorer 7, Spybot signalant des modifications du registre et l'erreur ExlcudeFromKnownDlls refusée. Des conseils préconisent de limiter les outils de sécurité et de passer à ANTIVIR, en désinstallant Avast et Norton et en utilisant ANTIVIR en mode Expert avec un scan rootkit. D'autres réponses suggèrent de produire un rapport avec RSIT ou HijackThis et d'utiliser UsbFix pour nettoyer les éléments décrits dans le registre et les autoruns, notamment pour guider le nettoyage. En cas de doute, effectuer un diagnostic hors ligne et éviter les solutions rapides via de multiples outils peut éviter de masquer l'origine des lenteurs.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    perso je virerais avast et norton et je metterais ANTIVIR en français , et puis il faut choisir soit spybot ou windows défender un seul en mode résident pour info et Comprendre pourquoi votre ordinateur est ralenti
    1. -------------- UsbFix V2.414.1 ---------------

      * User : FMD - PC-DE-FMD
      * Outils mis a jours le 14/01/2009 par Chiquitine29 et Chimay8
      * Recherche effectuée à 22:34:38 le 14/01/2009
      * Windows Vista - Internet Explorer 7.0.6001.18000

      --------------- [ Processus actifs ] ----------------

      C:\Windows\System32\smss.exe
      C:\Windows\system32\csrss.exe
      C:\Windows\system32\wininit.exe
      C:\Windows\system32\csrss.exe
      C:\Windows\system32\services.exe
      C:\Windows\system32\lsass.exe
      C:\Windows\system32\lsm.exe
      C:\Windows\system32\winlogon.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\system32\LogonUI.exe
      C:\Windows\system32\Ati2evxx.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\SLsvc.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\Ati2evxx.exe
      C:\Windows\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\Windows\system32\DllHost.exe
      C:\Windows\system32\userinit.exe
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Windows\system32\runonce.exe
      C:\Windows\system32\conime.exe

      --------------- [ Informations lecteurs ] ----------------

      C: - Lecteur fixe
      D: - Lecteur amovible
      E: - Lecteur fixe

      --------------- [ Lecteur C ] ----------------

      C: - Lecteur fixe

      +- Listing des fichiers présents :

      [18/09/2006 22:43][--a------] C:\autoexec.bat
      [25/10/2007 09:54][--ah-----] C:\SWSTAMP.TXT
      [25/10/2007 09:54][--ah-----] C:\UsbFix.txt
      [18/09/2006 22:43][--a------] C:\config.sys
      [18/09/2006 22:43][--a------] C:\hiberfil.sys
      [18/09/2006 22:43][--a------] C:\pagefile.sys

      --------------- [ Lecteur D ] ----------------

      D: - Lecteur amovible

      +- Listing des fichiers présents :

      --------------- [ Lecteur E ] ----------------

      E: - Lecteur fixe

      +- Listing des fichiers présents :

      --------------- [ Registre / Startup ] ----------------

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
      "Userinit"="C:\\Windows\\system32\\userinit.exe,"

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
      "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
      "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
      Sidebar=C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
      TOSCDSPD=TOSCDSPD.EXE
      MsnMsgr="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      Skype="C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
      ehTray.exe=C:\Windows\ehome\ehTray.exe
      WMPNSCFG=C:\Program Files\Windows Media Player\WMPNSCFG.exe

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
      Windows Defender=%ProgramFiles%\Windows Defender\MSASCui.exe -hide
      RtHDVCpl=RtHDVCpl.exe
      TPwrMain=%ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
      HSON=%ProgramFiles%\TOSHIBA\TBS\HSON.exe
      SmoothView=%ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
      00TCrdMain=%ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
      KeNotify=C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
      HWSetup=\HWSetup.exe hwSetUP
      SVPWUTIL=C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
      NDSTray.exe=NDSTray.exe
      topi=C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
      Desktop SMS=C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe /auto
      StartCCC=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
      SynTPEnh=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      Toshiba Registration=C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
      Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      QuickTime Task="C:\Program Files\QuickTime\QTTask.exe" -atboottime
      XboxStat="C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
      SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
      avast!=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
      <NO NAME>=
      HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
      Installed=1
      <NO NAME>=
      HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
      NoChange=1
      Installed=1
      <NO NAME>=
      HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
      Installed=1
      <NO NAME>=

      --------------- [ Registre / Mountpoint2 ] ----------------

      Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{74e92d81-b1a1-11dd-90c8-001eec03bd6e}\Shell\AutoRun\command

      --------------- [ Nettoyage des disques ] ----------------

      --------------- [ Resumé ] ----------------

      -> /!\ Le resultat doit etre interprété par un spécialiste /!\

      [18/09/2006 22:43][--a------] C:\autoexec.bat

      --------------- [ Vaccination ] ----------------

      C:\autorun.inf -> Dossier autorun.inf crée par UsbFix !
      D:\autorun.inf -> Dossier autorun.inf crée par UsbFix !
      E:\autorun.inf -> Dossier autorun.inf crée par UsbFix !

      --------------- ! Fin du rapport ! ----------------
      1. Re,

        Ensuite si tu installe antivir configure le comme suit:

        ▶ Je te conseil de désinstaller AVAST comment le faire proprement

        ▶ Et norton comment désinstaller norton correctement

        ▶ D'installer cet Antivirus:

        ANTIVIR

        ▶ Double-clique sur l'icône d'Antivir (Parapluie) dans la barre des tâches.

        ▶ Dans Antivir, choisis Outils puis Configuration.

        ▶ Coche Mode Expert et coche Rech. Rootkit au dém. de la recherche à droite dans Autres réglages.

        Avast et Antivir : comparaisons, et passage à Antivir.

        ▶ Fait la mise à jour d'antivir et fait le scan en mode sans échec.

        Comment accéder au mode sans échec
        1. Salut,

          ▶ Désactive le « contrôle des comptes utilisateurs = UAC »
          (tu le réactiveras après ta désinfection): Ne pas oublier !!
          Désactiver l'UAC est nécessaire pour pouvoir faire fonctionner certains programmes sous Vista.
          - Vas dans Démarrer puis panneau de configuration
          - Double Clique sur l'icône "Comptes d'utilisateurs"
          - Clique ensuite sur désactiver et valide.
          comment désactiver L'UAC

          ▶ Télécharge hijackthis

          ▶ Enregistre la cible sous .... "le bureau"

          ▶ Fais un double-clic sur "HJTInstall.exe" afin de lancer l'installation

          ▶ Clique sur Install ensuite sur "I Accept"

          ▶ Clique sur" Do a scan system and save log file"

          ▶ Le bloc-notes s'ouvrira, fais un copier-coller de tout son contenu ici dans ta prochaine réponse

          ▶ Tuto hijackthis(Merci à Balltrap34)

          Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.
          1. Contributeur sécurité
            Télécharge le fichier d'installation d'HijackThis.

            Enregistre HJTInstall.exe sur ton bureau.

            Double-clique sur HJTInstall.exe pour lancer le programme

            Par défaut, il s'installera là :
            C:\Program Files\Trend Micro\HijackThis

            Accepte la licence en cliquant sur le bouton "I Accept"

            Choisis l'option "Do a system scan and save a log file"

            Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note

            Clique sur "Edition -> Sélectionner tout", puis sur "Edition -> Copier" pour copier tout le contenu du rapport

            Colle le rapport que tu viens de copier sur ce forum

            Ne fixe encore AUCUNE ligne, cela pourrait empêcher ton PC de fonctionner correctement

            Tutoriaux (ne fixe rien pour le moment !!)

            1. bonsoir, essayez avec malwarebytes anti-malwares pour voir s'il trouve des spywares ou d'autres nuisbles que provoquent ces ouvertures intempestives
              1. Contributeur sécurité
                bonjour, je retire mon message car il y a déjà beaucoup de monde @+
                1. Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 21:47:58, on 14/01/2009
                  Platform: Windows Vista SP1 (WinNT 6.00.1905)
                  MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                  Boot mode: Normal

                  Running processes:
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\Explorer.EXE
                  C:\Program Files\Windows Defender\MSASCui.exe
                  C:\Windows\RtHDVCpl.exe
                  C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
                  C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
                  C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
                  C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
                  C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe
                  C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe
                  C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
                  C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  C:\Windows\system32\wbem\unsecapp.exe
                  C:\Program Files\TOSHIBA\Registration\ToshibaRegistration.exe
                  C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                  C:\Program Files\Synaptics\SynTP\SynToshiba.exe
                  C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
                  C:\Program Files\Java\jre6\bin\jusched.exe
                  C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                  C:\Program Files\Windows Sidebar\sidebar.exe
                  C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  C:\Windows\ehome\ehtray.exe
                  C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                  C:\Program Files\Windows Media Player\wmpnscfg.exe
                  C:\Program Files\OpenOffice.org 3\program\soffice.exe
                  C:\Windows\ehome\ehmsas.exe
                  C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
                  C:\Program Files\OpenOffice.org 3\program\soffice.bin
                  C:\Program Files\Windows Mail\WinMail.exe
                  C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
                  C:\Windows\system32\wuauclt.exe
                  C:\Program Files\Internet Explorer\ieuser.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
                  C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                  C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe
                  C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
                  C:\Windows\system32\SearchFilterHost.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                  O1 - Hosts: ::1 localhost
                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                  O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                  O2 - BHO: NetXfer - {83B80A9C-D91A-4F22-8DCF-EA7204039F79} - C:\Program Files\Xi\NetXfer\NXIEHelper.dll
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
                  O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                  O3 - Toolbar: NetXfer - {C16CBAAC-A75C-4DB5-A0DD-CDF5CAFCDD3A} - C:\Program Files\Xi\NetXfer\NXToolBar.dll
                  O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                  O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                  O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                  O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
                  O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
                  O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
                  O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
                  O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
                  O4 - HKLM\..\Run: [HWSetup] \HWSetup.exe hwSetUP
                  O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
                  O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
                  O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
                  O4 - HKLM\..\Run: [Desktop SMS] C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe /auto
                  O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
                  O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
                  O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                  O4 - HKLM\..\Run: [XboxStat] "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  O4 - HKLM\..\Run: [Skytel] Skytel.exe
                  O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                  O4 - HKCU\..\Run: [TOSCDSPD] TOSCDSPD.EXE
                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
                  O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                  O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                  O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                  O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
                  O8 - Extra context menu item: Tout télécharger avec NetXfer - C:\Program Files\Xi\NetXfer\NXAddList.html
                  O8 - Extra context menu item: Télécharger avec NetXfer - C:\Program Files\Xi\NetXfer\NXAddLink.html
                  O9 - Extra button: eBay - Achetez, Vendez - {76577871-04EC-495E-A12B-91F7C3600AFA} - https://www.ebay.fr (file missing)
                  O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                  O9 - Extra button: Amazon.fr - {8A918C1D-E123-4E36-B562-5C1519E434CE} - https://www.amazon.fr/exec/obidos/subst/home/home.html/262-6263521-6325360?_encoding=UTF8&link_code=hom&tag=Toshibafrbholink-21 (file missing)
                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                  O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                  O13 - Gopher Prefix:
                  O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553550000} - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                  O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                  O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                  O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                  O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                  O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                  O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                  O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
                  O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
                  O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
                  O23 - Service: TOSHIBA Bluetooth Service - Unknown owner - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (file missing)
                  O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
                  1. Re,

                    ▶ Télécharge random's system information tool (RSIT) et enregistre le sur ton bureau.

                    ▶ Double clique sur RSIT.exe pour lancer l'outil.

                    ▶ Clique sur ' continue ' à l'écran Disclaimer.

                    ▶ Si l'outil HIjackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.

                    ▶ Une fois le scan fini , 2 rapports vont apparaitre. Poste le contenu des 2 rapports
                    ( log.txt & info.txt )

                    (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                    Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.
                    1. Contributeur
                      Salut,

                      plusieurs infections ! .... ^^

                      1- protocole à suivre pour Windows Vista :

                      *Désactiver le contrôle des comptes utilisateurs ou UAC (le réactiver seulement à la fin de la désinfection) :

                      Aller dans "démarrer" puis "panneau de configuration" :
                      --->Sur la droite de la fenêtre , cliques sur " affichage classique "
                      --->Double-Cliquer sur l'icône "Comptes d'utilisateurs"
                      --->Cliquer ensuite sur "Activer ou désactiver le contrôle ..." .
                      --->Décocher la case "utlisiser le contrôle ..." et cliquer sur OK .
                      Puis redémarrer le PC quand il le vous saura demandé ...

                      Tuto : https://forum.malekal.com/viewtopic.php?f=59&t=6517

                      * Important :
                      Pour installer ou pour lancer les outils, que tu utiliseras au court de la désinfection, fais toujours ainsi :
                      clique DROIT ( sur le setup d'installe ou l'outil ) -> choisis " Exécuter entant qu'administrateur " .
                      Fais ce-ci systématiquement ! ...

                      une fois ceci fait et pris en compte , commence par ce qui suit :

                      2- Important :
                      Désactive le "tea timer" de Spybot S&D en t'aidant de ce tuto animé (merci Balltrap ;) ) :
                      http://perso.orange.fr/rginformatique/section%20virus/demo%20spybot.htm
                      ( sur la 1er image , clique sur "tea timer" pour lancer l'animation ).

                      En effet , il risque de géner dans le bon déroulement des outils de désinfections et dans la répartion du registre ...

                      Tu le réactiveras une fois qu'on aura finis de désinfecter ( et pas avant ! ) .
                      /!\ Mais attention :
                      à ce moment là, le " TeaTimer " de Spybot proposera, par le biais de plusieurs pop-up, d'accepter ou non des modifications de registre ( survenuent lors de la désinfection )
                      -> il faudra alors les accepter toutes sans exeptions !

                      Puis part la suite , il faudra rester vigilant lorsque le "TeaTimer" donnera des alertes : accepter une modification uniquement si on en connait la provenance .
                      1. J'ai fait une analyse avec spybot et il me donne des élements a supprimer
                        "bluestreak"
                        "doubleclick"
                        "mediaplex"
                        1. Re,

                          Fait le rapport avec rsit car ton hijackthis et clean.

                          On va regarder sa de plus prés.

                          merci
                          1. Re,

                            Peut tu faire le rapport RSIT pour voir plus loin que l'hijackthis STP.

                            merci
                            1. Logfile of random's system information tool 1.05 (written by random/random)
                              Run by FMD at 2009-01-14 22:00:03
                              Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
                              System drive C: has 73 GB (61%) free of 119 GB
                              Total RAM: 2045 MB (46% free)

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 22:00:05, on 14/01/2009
                              Platform: Windows Vista SP1 (WinNT 6.00.1905)
                              MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                              Boot mode: Normal

                              Running processes:
                              C:\Windows\system32\Dwm.exe
                              C:\Windows\Explorer.EXE
                              C:\Program Files\Windows Defender\MSASCui.exe
                              C:\Windows\RtHDVCpl.exe
                              C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
                              C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
                              C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
                              C:\Windows\system32\taskeng.exe
                              C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
                              C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
                              C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe
                              C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe
                              C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
                              C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                              C:\Windows\system32\wbem\unsecapp.exe
                              C:\Program Files\TOSHIBA\Registration\ToshibaRegistration.exe
                              C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                              C:\Program Files\Synaptics\SynTP\SynToshiba.exe
                              C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
                              C:\Program Files\Java\jre6\bin\jusched.exe
                              C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                              C:\Program Files\Windows Sidebar\sidebar.exe
                              C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
                              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              C:\Windows\ehome\ehtray.exe
                              C:\Program Files\Windows Media Player\wmpnscfg.exe
                              C:\Program Files\OpenOffice.org 3\program\soffice.exe
                              C:\Windows\ehome\ehmsas.exe
                              C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
                              C:\Program Files\OpenOffice.org 3\program\soffice.bin
                              C:\Program Files\Windows Mail\WinMail.exe
                              C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
                              C:\Windows\system32\wuauclt.exe
                              C:\Program Files\Internet Explorer\ieuser.exe
                              C:\Program Files\Internet Explorer\iexplore.exe
                              C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
                              C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                              C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe
                              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                              C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                              C:\Windows\system32\SearchFilterHost.exe
                              C:\Users\FMD\Desktop\RSIT.exe
                              C:\Program Files\Trend Micro\HijackThis\FMD.exe

                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                              O1 - Hosts: ::1 localhost
                              O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                              O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                              O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                              O2 - BHO: NetXfer - {83B80A9C-D91A-4F22-8DCF-EA7204039F79} - C:\Program Files\Xi\NetXfer\NXIEHelper.dll
                              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
                              O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
                              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                              O3 - Toolbar: NetXfer - {C16CBAAC-A75C-4DB5-A0DD-CDF5CAFCDD3A} - C:\Program Files\Xi\NetXfer\NXToolBar.dll
                              O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                              O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                              O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                              O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
                              O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
                              O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
                              O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
                              O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
                              O4 - HKLM\..\Run: [HWSetup] \HWSetup.exe hwSetUP
                              O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
                              O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
                              O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
                              O4 - HKLM\..\Run: [Desktop SMS] C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe /auto
                              O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
                              O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                              O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
                              O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                              O4 - HKLM\..\Run: [XboxStat] "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                              O4 - HKLM\..\Run: [Skytel] Skytel.exe
                              O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                              O4 - HKCU\..\Run: [TOSCDSPD] TOSCDSPD.EXE
                              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
                              O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                              O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                              O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
                              O8 - Extra context menu item: Tout télécharger avec NetXfer - C:\Program Files\Xi\NetXfer\NXAddList.html
                              O8 - Extra context menu item: Télécharger avec NetXfer - C:\Program Files\Xi\NetXfer\NXAddLink.html
                              O9 - Extra button: eBay - Achetez, Vendez - {76577871-04EC-495E-A12B-91F7C3600AFA} - https://www.ebay.fr (file missing)
                              O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                              O9 - Extra button: Amazon.fr - {8A918C1D-E123-4E36-B562-5C1519E434CE} - https://www.amazon.fr/exec/obidos/subst/home/home.html/262-6263521-6325360?_encoding=UTF8&link_code=hom&tag=Toshibafrbholink-21 (file missing)
                              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                              O13 - Gopher Prefix:
                              O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
                              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553550000} - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                              O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                              O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
                              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
                              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                              O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
                              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                              O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                              O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                              O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                              O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                              O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
                              O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
                              O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
                              O23 - Service: TOSHIBA Bluetooth Service - Unknown owner - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (file missing)
                              O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
                              1. info.txt logfile of random's system information tool 1.05 2009-01-14 22:00:07

                                ======Uninstall list======

                                -->"C:\Program Files\InstallShield Installation Information\{A644254B-92F6-4970-8635-AB0775371E72}\setup.exe" --u:{A644254B-92F6-4970-8635-AB0775371E72}
                                -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{622E6F16-0904-49B6-BBE1-4CC836314CCF}\setup.exe" -l0x40c
                                -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{697AFC77-F318-4CD4-BF16-F50F4C1072DA}\setup.exe" -l0x40c
                                7-Zip 4.62-->"C:\Program Files\7-Zip\Uninstall.exe"
                                Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)-->MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7}
                                Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
                                Adobe Reader 8.1.2 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81200000003}
                                Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
                                ArcSoft Panorama Maker 4-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D45E8C45-B601-4A80-AFD8-E16338744DE1}\Setup.exe" -l0x40c
                                Assistant de connexion Windows Live-->MsiExec.exe /I{8984E374-6C93-427C-A3B9-AD92472FDCA0}
                                Atheros Driver Installation Program-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{28006915-2739-4EBE-B5E8-49B25D32EB33}\Setup.exe" -l0x40c -removeonly
                                Audacity 1.2.6-->"C:\Program Files\Audacity\unins000.exe"
                                avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
                                AVS Video Converter 6-->"C:\Program Files\AVS4YOU\AVSVideoConverter6\unins000.exe"
                                AVS4YOU Software Navigator 1.3-->"C:\Program Files\AVS4YOU\AVSSoftwareNavigator\unins000.exe"
                                Bluetooth Stack for Windows by Toshiba-->MsiExec.exe /X{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}
                                CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
                                Choice Guard-->MsiExec.exe /I{EBD5E7A9-DBB8-4E24-AE3A-CF9390AF1CCB}
                                Codeur Windows Media Série 9-->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
                                Codeur Windows Media Série 9-->MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
                                Desktop SMS-->MsiExec.exe /I{5980B928-1C95-4B3E-957B-B02D8147FF9E}
                                DJ Mix Pro-->C:\Program Files\DJ Mix Pro\uninstall.exe
                                DVD MovieFactory for TOSHIBA-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}\setup.exe" -l0x40c
                                Emdedded IR Driver-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{A6D4234C-CB02-4048-AC3E-AD09404FA35A}
                                Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_0531C63A913CC9D1.exe" /uninstall
                                GUILD WARS-->"C:\Program Files\GUILD WARS\Gw.exe" -uninstall
                                HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
                                Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
                                Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
                                Java(TM) SE Runtime Environment 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160000}
                                LimeWire 4.18.8-->"C:\Program Files\LimeWire\uninstall.exe"
                                LiveUpdate 3.2 (Symantec Corporation)-->"C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
                                LiveUpdate Notice (Symantec Corporation)-->MsiExec.exe /X{DBA4DB9D-EE51-4944-A419-98AB1F1249C8}
                                Manuels TOSHIBA-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5B1DD5AA-FF34-4D6E-A912-CB46BB7378DC}\setup.exe" -l0x40c -removeonly
                                MediaCoder 0.6.2-->C:\Program Files\MediaCoder\uninst.exe
                                Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
                                Microsoft Office Word Viewer 2003-->MsiExec.exe /I{9085040C-6000-11D3-8CFE-0150048383C9}
                                Microsoft Silverlight-->MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
                                Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
                                Microsoft Xbox 360 Accessories 1.0-->MsiExec.exe /X{7B845D3C-02DF-44A8-B1F9-19C3DC15DB96}
                                Morpheus Photo Animation Suite v3.00-->"C:\Program Files\Morpheus Photo Animation Suite\unins000.exe"
                                MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
                                MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
                                MSXML 4.0 SP2 (KB941833)-->MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
                                MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                                myphotobook 3.1-->C:\Program Files\myphotobook\uninst.exe
                                NetXfer 2.62.408-->"C:\Program Files\Xi\NetXfer\unins000.exe"
                                OpenOffice.org 3.0-->MsiExec.exe /I{6860B340-530D-46B3-91F8-1AE1F70F7C33}
                                Outils Club Internet-->"C:\Program Files\Club-Internet\Assistance\OutilsCI\uninstall.exe"
                                PhotoFiltre-->"C:\Program Files\PhotoFiltre\Uninst.exe"
                                Pro Evolution Soccer 2009-->MsiExec.exe /X{A8DB611A-D80E-450D-85F6-3ACDD164BE31}
                                QuickTime-->MsiExec.exe /I{8DC42D05-680B-41B0-8878-6C14D24602DB}
                                Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista-->C:\Program Files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe -runfromtemp -l0x040c -removeonly
                                Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
                                Réducteur de bruit lect. CD/DVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}\setup.exe" -l0x40c
                                Security Update for Windows Media Encoder (KB954156)-->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E} MSIPATCHREMOVE={E836F1B7-43FB-46B0-A0D9-E4D2A5951659} /qb
                                Skype™ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
                                Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
                                Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
                                TeamSpeak 2 RC2-->"C:\Program Files\Teamspeak2_RC2\unins000.exe"
                                Texas Instruments PCIxx21/x515/xx12 drivers.-->C:\Program Files\InstallShield Installation Information\{DB780B85-B4B5-4864-A49C-9B706B169C93}\setup.exe -runfromtemp -l0x040c
                                TOSHIBA Assist-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{12B3A009-A080-4619-9A2A-C6DB151D8D67}\setup.exe" -l0x40c
                                TOSHIBA ConfigFree-->C:\Program Files\InstallShield Installation Information\{78C6A78A-8B03-48C8-A47C-78BA1FCA2307}\setup.exe -runfromtemp -l0x040c uninstall -removeonly
                                TOSHIBA Disc Creator-->MsiExec.exe /X{5DA0E02F-970B-424B-BF41-513A5018E4C0}
                                TOSHIBA DVD PLAYER-->C:\Program Files\InstallShield Installation Information\{6C5F3BDC-0A1B-4436-A696-5939629D5C31}\setup.exe -runfromtemp -l0x040c -ADDREMOVE -removeonly
                                TOSHIBA Extended Tiles for Windows Mobility Center-->C:\Program Files\InstallShield Installation Information\{617C36FD-0CBE-4600-84B2-441CEB12FADF}\setup.exe -runfromtemp -l0x040c
                                TOSHIBA Flash Cards Support Utility-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{620BBA5E-F848-4D56-8BDA-584E44584C5E}
                                TOSHIBA Hardware Setup-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{5279374D-87FE-4879-9385-F17278EBB9D3} /l1036
                                TOSHIBA Mot de passe responsable-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE} /l1036
                                Toshiba Online Product Information-->C:\Program Files\InstallShield Installation Information\{2290A680-4083-410A-ADCC-7092C67FC052}\setup.exe -runfromtemp -l0x040c -removeonly
                                TOSHIBA SD Memory Utilities-->MsiExec.exe /X{EBFF48F5-3CFA-436F-8FD5-94FB01D3A0A7}
                                TOSHIBA Software Modem-->Tosmreg -U
                                TOSHIBA Value Added Package-->C:\Program Files\InstallShield Installation Information\{FEDD27A0-B306-45EF-BF58-B527406B42C8}\setup.exe -runfromtemp -l0x040c
                                VLC media player 0.9.6-->C:\Program Files\VideoLAN\VLC\uninstall.exe
                                Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
                                Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
                                Xilisoft Video Convertisseur-->C:\Program Files\Xilisoft\Video Convertisseur\Uninstall.exe

                                ======Security center information======

                                AV: avast! antivirus 4.8.1296 [VPS 090101-0]
                                AS: Windows Defender (disabled)
                                AS: avast! antivirus 4.8.1296 [VPS 090101-0]

                                System event log

                                Computer Name: PC-de-FMD
                                Event Code: 7036
                                Message: Le service Service de découverte automatique de Proxy Web pour les services HTTP Windows est entré dans l'état : arrêté.
                                Record Number: 68642
                                Source Name: Service Control Manager
                                Time Written: 20090114204313.000000-000
                                Event Type: Information
                                User:

                                Computer Name: PC-de-FMD
                                Event Code: 37
                                Message: Le fournisseur de temps NtpClient reçoit actuellement des données de temps valides à partir de time.windows.com,0x9 (ntp.m|0x9|0.0.0.0:123->207.46.197.32:123).
                                Record Number: 68643
                                Source Name: Microsoft-Windows-Time-Service
                                Time Written: 20090114204820.000000-000
                                Event Type: Information
                                User:

                                Computer Name: PC-de-FMD
                                Event Code: 35
                                Message: Le service de temps synchronise maintenant l'heure système avec la source de temps time.windows.com,0x9 (ntp.m|0x9|0.0.0.0:123->207.46.197.32:123).
                                Record Number: 68644
                                Source Name: Microsoft-Windows-Time-Service
                                Time Written: 20090114204844.000000-000
                                Event Type: Information
                                User:

                                Computer Name: PC-de-FMD
                                Event Code: 1
                                Message: L’heure du système est passée à 2009-01-14T20:48:44.681Z à partir de 2009-01-14T20:48:20.279Z.
                                Record Number: 68645
                                Source Name: Microsoft-Windows-Kernel-General
                                Time Written: 20090114204844.682525-000
                                Event Type: Information
                                User: AUTORITE NT\SERVICE LOCAL

                                Computer Name: PC-de-FMD
                                Event Code: 1
                                Message: L’heure du système est passée à 2009-01-14T20:48:44.690Z à partir de 2009-01-14T20:48:44.753Z.
                                Record Number: 68646
                                Source Name: Microsoft-Windows-Kernel-General
                                Time Written: 20090114204844.690000-000
                                Event Type: Information
                                User: AUTORITE NT\SERVICE LOCAL

                                Application event log

                                Computer Name: PC-de-FMD
                                Event Code: 1
                                Message: Le client des services de certification a démarré correctement.
                                Record Number: 20541
                                Source Name: Microsoft-Windows-CertificateServicesClient
                                Time Written: 20090114202724.578082-000
                                Event Type: Information
                                User: AUTORITE NT\SYSTEM

                                Computer Name: PC-de-FMD
                                Event Code: 1
                                Message: Le service Centre de sécurité Windows a démarré.
                                Record Number: 20542
                                Source Name: SecurityCenter
                                Time Written: 20090114202843.000000-000
                                Event Type: Information
                                User:

                                Computer Name: PC-de-FMD
                                Event Code: 101
                                Message: Niveau d'information : success

                                Le Planificateur a lancé LiveUpdate automatique.
                                Record Number: 20543
                                Source Name: Automatic LiveUpdate Scheduler
                                Time Written: 20090114203139.000000-000
                                Event Type: Information
                                User: AUTORITE NT\SYSTEM

                                Computer Name: PC-de-FMD
                                Event Code: 101
                                Message: Niveau d'information : success

                                LiveUpdate automatique a terminé.
                                Record Number: 20544
                                Source Name: Automatic LiveUpdate Scheduler
                                Time Written: 20090114203151.000000-000
                                Event Type: Information
                                User: AUTORITE NT\SYSTEM

                                Computer Name: PC-de-FMD
                                Event Code: 101
                                Message: Niveau d'information : success

                                L'exécution suivante a été planifiée pour intervenir approximativement à 1:01 AM.
                                Record Number: 20545
                                Source Name: Automatic LiveUpdate Scheduler
                                Time Written: 20090114203151.000000-000
                                Event Type: Information
                                User: AUTORITE NT\SYSTEM

                                Security event log

                                Computer Name: PC-de-FMD
                                Event Code: 5038
                                Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

                                Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
                                Record Number: 19749
                                Source Name: Microsoft-Windows-Security-Auditing
                                Time Written: 20090114210004.984400-000
                                Event Type: Échec de l'audit
                                User:

                                Computer Name: PC-de-FMD
                                Event Code: 5038
                                Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

                                Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
                                Record Number: 19750
                                Source Name: Microsoft-Windows-Security-Auditing
                                Time Written: 20090114210005.031200-000
                                Event Type: Échec de l'audit
                                User:

                                Computer Name: PC-de-FMD
                                Event Code: 5038
                                Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

                                Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
                                Record Number: 19751
                                Source Name: Microsoft-Windows-Security-Auditing
                                Time Written: 20090114210005.062400-000
                                Event Type: Échec de l'audit
                                User:

                                Computer Name: PC-de-FMD
                                Event Code: 5038
                                Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

                                Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
                                Record Number: 19752
                                Source Name: Microsoft-Windows-Security-Auditing
                                Time Written: 20090114210005.109200-000
                                Event Type: Échec de l'audit
                                User:

                                Computer Name: PC-de-FMD
                                Event Code: 5038
                                Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

                                Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
                                Record Number: 19753
                                Source Name: Microsoft-Windows-Security-Auditing
                                Time Written: 20090114210005.140400-000
                                Event Type: Échec de l'audit
                                User:

                                ======Environment variables======

                                "ComSpec"=%SystemRoot%\system32\cmd.exe
                                "FP_NO_HOST_CHECK"=NO
                                "OS"=Windows_NT
                                "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\ESTsoft\ALZip\
                                "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
                                "PROCESSOR_ARCHITECTURE"=x86
                                "TEMP"=%SystemRoot%\TEMP
                                "TMP"=%SystemRoot%\TEMP
                                "USERNAME"=SYSTEM
                                "windir"=%SystemRoot%
                                "PROCESSOR_LEVEL"=15
                                "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 104 Stepping 2, AuthenticAMD
                                "PROCESSOR_REVISION"=6802
                                "NUMBER_OF_PROCESSORS"=2
                                "CLASSPATH"=.;C:\Program Files\Java\jre1.6.0\lib\ext\QTJava.zip
                                "QTJAVA"=C:\Program Files\Java\jre1.6.0\lib\ext\QTJava.zip

                                -----------------EOF-----------------
                                • 1
                                • 2