Proleme rundll32 error

Bonjour, quand j ouvre mon ordinateur une fenetre d erreur s ouvre et il y est inscrit error rundll32 error loading dll32 quesque ca veux dire?? comment puis je enlever cela ?? et depuis ce temps mon antivirus avast ne fonctionne plus aidez moi svp !!!!! je ne suis pas une pro en informatique merci
Configuration: Windows Vista Internet Explorer 7.0

29 réponses

Résumé de la discussion

Problème central: à l'ouverture du PC sous Windows Vista et Internet Explorer 7, une fenêtre d'erreur affiche 'error rundll32 error loading dll32' et Avast ne fonctionne plus. Plusieurs éléments de réponse recommandent d'imprimer puis d'installer Malwarebytes en français, puis de lancer un examen complet après mise à jour, afin de détecter et supprimer les objets infectés. En cas de succès partiel ou de redémarrage nécessaire, l'utilisateur est invité à consulter le rapport du logiciel et à relancer le scan, puis à vérifier que Avast retrouve son fonctionnement. D'autres échanges évoquent l'usage d'outils complémentaires et l'examen des rapports pour assurer que les programmes de sécurité retrouvent leur rôle après le nettoyage et la remise en route.

Bobot (l’IA à votre service)
  1. ####### | Install & recherche | #########

    Telecharge et install UsbFix de C_XX & Chiquitine29

    Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

    # Fais un clic droit sur le raccourci UsbFix présent sur ton bureau et choisi éxécuter en tant qu'administrateur .

    # Choisi l option 1 ( Recherche )

    # Laisse travailler l outil.

    # Ensuite post le rapport UsbFix.txt qui apparaitra.

    # Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

    ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

    # Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
    Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
    Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
    0
    1. merci je le fais des maintenant
      0
      1. ############################## [ UsbFix V3.020 # Scan ]

        # User : veronika (Administrators) # VERONIKA-PC
        # Update on 15/05/09 by Chiquitine29, C_XX & Chimay8
        # WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
        # Start at: 9:11:31 AM | 5/15/2009

        # Genuine Intel(R) CPU T2300 @ 1.66GHz
        # Microsoft® Windows Vista™ Ultimate (6.0.6001 32-bit) # Service Pack 1
        # Internet Explorer 7.0.6001.18000
        # Windows Firewall Status : Disabled

        # C:\ # Local Fixed Disk # 74.53 Go (35.05 Go free) # NTFS
        # D:\ # CD-ROM Disc

        ############################## [ Processus actifs ]

        C:\Windows\System32\smss.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\wininit.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\services.exe
        C:\Windows\system32\lsass.exe
        C:\Windows\system32\lsm.exe
        C:\Windows\system32\winlogon.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\SLsvc.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\Windows\System32\spoolsv.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\taskeng.exe
        C:\Windows\system32\Dwm.exe
        C:\Windows\Explorer.EXE
        C:\Windows\system32\taskeng.exe
        C:\Program Files\Windows Defender\MSASCui.exe
        C:\Program Files\Synaptics\SynTP\SynTPStart.exe
        C:\Windows\system32\taskeng.exe
        C:\Windows\System32\igfxpers.exe
        C:\Program Files\Windows Live\Family Safety\fsui.exe
        C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
        C:\Windows\system32\igfxsrvc.exe
        C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\Program Files\Alwil Software\Avast4\ashDisp.exe
        C:\Program Files\Windows Sidebar\sidebar.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\Program Files\Windows Live\Family Safety\fsssvc.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\PSIService.exe
        C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\SearchIndexer.exe
        C:\Program Files\Windows Sidebar\sidebar.exe
        C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\Windows\system32\wbem\unsecapp.exe
        C:\Windows\system32\wbem\wmiprvse.exe
        C:\Program Files\iPod\bin\iPodService.exe
        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        C:\Program Files\Windows Live\Contacts\wlcomm.exe
        C:\Program Files\Internet Explorer\ieuser.exe
        C:\Windows\system32\SearchProtocolHost.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Windows\system32\conime.exe
        C:\Windows\system32\SearchFilterHost.exe
        C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
        C:\Program Files\Windows Live\Toolbar\wltuser.exe
        C:\Windows\system32\wbem\wmiprvse.exe

        ################## [ Registre # Startup ]

        HKCU_Main: "Local Page"="C:\\Windows\\system32\\blank.htm"
        HKCU_Main: "Search Page"="https://www.google.com/?gws_rd=ssl"
        HKCU_Main: "Start Page"="https://www.google.com/?gws_rd=ssl"
        HKLM_logon: "Userinit"="C:\\Windows\\system32\\userinit.exe,"
        HKLM_logon: "LegalNoticeCaption"=""
        HKLM_logon: "LegalNoticeText"=""
        HKLM_Run: Windows Defender=%ProgramFiles%\Windows Defender\MSASCui.exe -hide
        HKLM_Run: NeroFilterCheck=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
        HKLM_Run: SynTPStart=C:\Program Files\Synaptics\SynTP\SynTPStart.exe
        HKLM_Run: IgfxTray=C:\Windows\system32\igfxtray.exe
        HKLM_Run: HotKeysCmds=C:\Windows\system32\hkcmd.exe
        HKLM_Run: Persistence=C:\Windows\system32\igfxpers.exe
        HKLM_Run: fssui="C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
        HKLM_Run: QlbCtrl.exe=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
        HKLM_Run: QuickTime Task="C:\Program Files\QuickTime\QTTask.exe" -atboottime
        HKLM_Run: Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
        HKLM_Run: iTunesHelper="C:\Program Files\iTunes\iTunesHelper.exe"
        HKLM_Run: avast!=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
        HKCU_Run: Sidebar=C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
        HKCU_Run: WindowsWelcomeCenter=rundll32.exe oobefldr.dll,ShowWelcomeCenter
        HKCU_Run: MsnMsgr="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
        HKCU_Run: swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        HKCU_Run: dll=rundll32 dll32,sm

        ################## [ Informations ]

        ################## [ Fichiers # Dossiers infectieux ]

        ################## [ Registre # Clés Run infectieuses ]

        ################## [ Registre # Mountpoints2 ]

        HKCU\Software\Microsoft\....\MountPoints2\{878f1aa5-0166-11de-b1c7-00163659f544}\Shell\AutoRun\command
        HKCU\Software\Microsoft\....\MountPoints2\{a6a58800-2698-11de-8fff-00163659f544}\Shell\AutoRun\command

        ################## [ ! Fin du rapport # UsbFix V3.020 ! ]
        0
        1. ######## | Suppression | ########

          Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

          # Double clic sur le raccourci UsbFix présent sur ton bureau

          # choisi l option 2 ( Suppression )

          # Ton bureau disparaitra et le pc redémarrera .

          # Au redémarrage , UsbFix scannera ton pc , laisse travailler l outil.

          # Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .

          # Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

          ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

          ######### | Désinstallation | #######

          # Double clic sur le raccourci UsbFix présent sur ton bureau

          # Choisi l option 3 ( Désinstaller ) ....
          0
          1. Ensuite postes moi un rsit pour evaluer tes infections

            Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

            ! Déconnecte toi et ferme toutes tes applications en cours !

            Double-clique sur " RSIT.exe " pour le lancer .

            -> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

            * Devant l'option "List files/folders created ..." , tu choisis : 2 months

            * clique ensuite sur " Continue " pour lancer l'analyse ...

            -> laisse faire le scan et ne touche pas au PC ...

            Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

            Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

            Important : poste un rapport, puis l'autre dans la réponse suivante
            Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum

            ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )
            0
            1. apres l etape 2 mon ordi c est eteint et a redemarrer mais l outil na pas fait aucun scan ?????????
              0
              1. Tu l'as executé en tant qu'administrateur (cliques droit avec la souris)
                0
                1. ############################## [ UsbFix V3.021 # Cleaning ]

                  # User : veronika (Administrators) # VERONIKA-PC
                  # Update on 16/05/09 by Chiquitine29, C_XX & Chimay8
                  # WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
                  # Start at: 2:35:10 PM | 5/16/2009

                  # Genuine Intel(R) CPU T2300 @ 1.66GHz
                  # Microsoft® Windows Vista™ Ultimate (6.0.6001 32-bit) # Service Pack 1
                  # Internet Explorer 7.0.6001.18000
                  # Windows Firewall Status : Disabled

                  # C:\ # Local Fixed Disk # 74.53 Go (35.02 Go free) # NTFS
                  # D:\ # CD-ROM Disc

                  ############################## [ Processus actifs ]

                  C:\Windows\System32\smss.exe
                  C:\Windows\system32\csrss.exe
                  C:\Windows\system32\wininit.exe
                  C:\Windows\system32\csrss.exe
                  C:\Windows\system32\services.exe
                  C:\Windows\system32\lsass.exe
                  C:\Windows\system32\lsm.exe
                  C:\Windows\system32\winlogon.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\system32\LogonUI.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\SLsvc.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  C:\Windows\System32\spoolsv.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\userinit.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\Explorer.EXE
                  C:\Windows\system32\taskeng.exe
                  C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  C:\Program Files\Bonjour\mDNSResponder.exe
                  C:\Program Files\Windows Live\Family Safety\fsssvc.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\PSIService.exe
                  C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\system32\SearchIndexer.exe
                  C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  C:\Windows\system32\runonce.exe
                  C:\Windows\system32\conime.exe
                  C:\Windows\system32\wbem\wmiprvse.exe

                  ################## [ Fichiers # Dossiers infectieux ]

                  ################## [ Registre # Clés Run infectieuses ]

                  ################## [ Registre # Mountpoints2 ]

                  Deleted ! HKCU\...\Explorer\MountPoints2\{878f1aa5-0166-11de-b1c7-00163659f544}\Shell\AutoRun\Command
                  Deleted ! HKCU\...\Explorer\MountPoints2\{a6a58800-2698-11de-8fff-00163659f544}\Shell\AutoRun\Command

                  ################## [ Listing des fichiers présent ]

                  [18/09/2006 05:43 PM|--a------|24] - C:\autoexec.bat
                  [19/01/2008 03:45 AM|-rahs----|333203] - C:\bootmgr
                  [23/02/2009 03:41 AM|-ra-s----|8192] - C:\BOOTSECT.BAK
                  [18/09/2006 05:43 PM|--a------|10] - C:\config.sys
                  [17/03/2007 07:41 AM|-rahs----|171136] - C:\grldr
                  [?|?|?] - C:\hiberfil.sys
                  [21/04/2009 10:26 AM|-rahs----|0] - C:\IO.SYS
                  [21/04/2009 10:26 AM|-rahs----|0] - C:\MSDOS.SYS
                  [?|?|?] - C:\pagefile.sys
                  [17/04/2009 03:34 PM|--a------|9934848] - C:\testcap.avi
                  [16/05/2009 02:36 PM|--a------|3190] - C:\UsbFix.txt

                  ################## [ Vaccination ]

                  # C:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.

                  ################## [ Cracks / Keygens / Serials ]

                  # -> Nothing found !

                  ################## [ ! Fin du rapport # UsbFix V3.021 ! ]
                  0
                  1. ############################## [ UsbFix V3.021 # Cleaning ]

                    # User : veronika (Administrators) # VERONIKA-PC
                    # Update on 16/05/09 by Chiquitine29, C_XX & Chimay8
                    # WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
                    # Start at: 2:35:10 PM | 5/16/2009

                    # Genuine Intel(R) CPU T2300 @ 1.66GHz
                    # Microsoft® Windows Vista™ Ultimate (6.0.6001 32-bit) # Service Pack 1
                    # Internet Explorer 7.0.6001.18000
                    # Windows Firewall Status : Disabled

                    # C:\ # Local Fixed Disk # 74.53 Go (35.02 Go free) # NTFS
                    # D:\ # CD-ROM Disc

                    ############################## [ Processus actifs ]

                    C:\Windows\System32\smss.exe
                    C:\Windows\system32\csrss.exe
                    C:\Windows\system32\wininit.exe
                    C:\Windows\system32\csrss.exe
                    C:\Windows\system32\services.exe
                    C:\Windows\system32\lsass.exe
                    C:\Windows\system32\lsm.exe
                    C:\Windows\system32\winlogon.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\System32\svchost.exe
                    C:\Windows\system32\LogonUI.exe
                    C:\Windows\System32\svchost.exe
                    C:\Windows\System32\svchost.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\system32\SLsvc.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\system32\svchost.exe
                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                    C:\Program Files\Alwil Software\Avast4\ashServ.exe
                    C:\Windows\System32\spoolsv.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\system32\userinit.exe
                    C:\Windows\system32\taskeng.exe
                    C:\Windows\system32\Dwm.exe
                    C:\Windows\system32\taskeng.exe
                    C:\Windows\Explorer.EXE
                    C:\Windows\system32\taskeng.exe
                    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                    C:\Program Files\Bonjour\mDNSResponder.exe
                    C:\Program Files\Windows Live\Family Safety\fsssvc.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\system32\PSIService.exe
                    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\System32\svchost.exe
                    C:\Windows\system32\SearchIndexer.exe
                    C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                    C:\Windows\system32\runonce.exe
                    C:\Windows\system32\conime.exe
                    C:\Windows\system32\wbem\wmiprvse.exe

                    ################## [ Fichiers # Dossiers infectieux ]

                    ################## [ Registre # Clés Run infectieuses ]

                    ################## [ Registre # Mountpoints2 ]

                    Deleted ! HKCU\...\Explorer\MountPoints2\{878f1aa5-0166-11de-b1c7-00163659f544}\Shell\AutoRun\Command
                    Deleted ! HKCU\...\Explorer\MountPoints2\{a6a58800-2698-11de-8fff-00163659f544}\Shell\AutoRun\Command

                    ################## [ Listing des fichiers présent ]

                    [18/09/2006 05:43 PM|--a------|24] - C:\autoexec.bat
                    [19/01/2008 03:45 AM|-rahs----|333203] - C:\bootmgr
                    [23/02/2009 03:41 AM|-ra-s----|8192] - C:\BOOTSECT.BAK
                    [18/09/2006 05:43 PM|--a------|10] - C:\config.sys
                    [17/03/2007 07:41 AM|-rahs----|171136] - C:\grldr
                    [?|?|?] - C:\hiberfil.sys
                    [21/04/2009 10:26 AM|-rahs----|0] - C:\IO.SYS
                    [21/04/2009 10:26 AM|-rahs----|0] - C:\MSDOS.SYS
                    [?|?|?] - C:\pagefile.sys
                    [17/04/2009 03:34 PM|--a------|9934848] - C:\testcap.avi
                    [16/05/2009 02:36 PM|--a------|3190] - C:\UsbFix.txt

                    ################## [ Vaccination ]

                    # C:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.

                    ################## [ Cracks / Keygens / Serials ]

                    # -> Nothing found !

                    ################## [ ! Fin du rapport # UsbFix V3.021 ! ]
                    0
                    1. voila le rapport apres la deuxieme etape
                      0
                      1. Parfait tu peux me poster le rsit maintenant
                        0
                        1. Tu as la procedure du rsit sur le post 6
                          0
                          1. info.txt logfile of random's system information tool 1.06 2009-05-16 14:57:26

                            ======Uninstall list======

                            -->C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
                            -->C:\Windows\UNNeroBackItUp.exe /UNINSTALL
                            -->C:\Windows\UNNeroMediaHome.exe /UNINSTALL
                            -->C:\Windows\UNNeroShowTime.exe /UNINSTALL
                            -->C:\Windows\UNNeroVision.exe /UNINSTALL
                            -->C:\Windows\UNRecode.exe /UNINSTALL
                            Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
                            Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
                            Adobe Reader 9.1 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A91000000001}
                            Apple Mobile Device Support-->MsiExec.exe /I{AFA20D47-69C3-4030-8DF8-D37466E70F13}
                            Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
                            Ares 2.1.1-->"C:\Program Files\Ares\uninstall.exe"
                            Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
                            avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
                            Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
                            Chessmaster Challenge (remove only)-->"C:\Program Files\PlayFirst\Chessmaster Challenge\Uninstall.exe"
                            Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
                            Conexant HD Audio-->C:\Program Files\CONEXANT\CNXT_HDAUDIO\UIU32a.exe -U -Iwis30B2a.inf
                            Galerie de photos Windows Live-->MsiExec.exe /X{44E54A81-9D91-4AA1-9417-80AFF134F5FF}
                            Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_BDA1448D3D255554.exe" /uninstall
                            Highlight Viewer (Windows Live Toolbar)-->MsiExec.exe /X{A5C4AD72-25FE-4899-B6DF-6D8DF63C93CF}
                            HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
                            Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
                            Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
                            HP Quick Launch Buttons 6.30 J1-->C:\Program Files\InstallShield Installation Information\{34D2AB40-150D-475D-AE32-BD23FB5EE355}\Setup.exe -runfromtemp -l0x0009 -removeonly uninst
                            Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
                            Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
                            Intel(R) Graphics Media Accelerator Driver-->C:\Windows\system32\igxpun.exe -uninstall
                            Intel(R) Network Connections Drivers-->Prounstl.exe
                            iTunes-->MsiExec.exe /I{5EFCBB42-36AB-4FF9-B90C-E78C7B9EE7B3}
                            Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
                            Map Button (Windows Live Toolbar)-->MsiExec.exe /X{7745B7A9-F323-4BB9-9811-01BF57A028DA}
                            Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
                            Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
                            Microsoft Search Enhancement Pack-->MsiExec.exe /I{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}
                            Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
                            Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
                            Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
                            Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
                            Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
                            Mozilla Firefox (3.0.6)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                            MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
                            Nero 7 Premium-->MsiExec.exe /I{235BBFC6-D863-4066-A01A-3BD504C31033}
                            Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
                            Quick Zip 4.60.019-->"C:\Program Files\QuickZip4\unins000.exe"
                            QuickTime-->MsiExec.exe /I{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}
                            Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -removeonly
                            RICOH R5C83x/84x Flash Media Controller Driver Ver.1.00.01A-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{59F6A514-9813-47A3-948C-8A155460CC2A}\setup.exe" -l0x9 anything
                            Smart Menus (Windows Live Toolbar)-->MsiExec.exe /X{F084395C-40FB-4DB3-981C-B51E74E1E83D}
                            Spelling Dictionaries Support For Adobe Reader 9-->MsiExec.exe /I{AC76BA86-7AD7-5464-3428-900000000004}
                            Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
                            Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
                            Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
                            Windows Live Contrôle parental-->MsiExec.exe /X{D6A2DDE3-9D7C-412C-932A-756580D29919}
                            Windows Live Favorites for Windows Live Toolbar-->MsiExec.exe /X{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}
                            Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
                            Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
                            Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
                            Windows Live Toolbar Extension (Windows Live Toolbar)-->MsiExec.exe /X{341201D4-4F61-4ADB-987E-9CCE4D83A58D}
                            Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
                            Windows Live Writer-->MsiExec.exe /X{2231CE39-B963-4B9D-823A-F412ECA637B1}

                            ======Security center information======

                            AS: Windows Defender

                            ======System event log======

                            Computer Name: veronika-PC
                            Event Code: 7000
                            Message: The Cyberlink RichVideo Service(CRVS) service failed to start due to the following error:
                            The system cannot find the path specified.
                            Record Number: 43473
                            Source Name: Service Control Manager
                            Time Written: 20090406000256.000000-000
                            Event Type: Error
                            User:

                            Computer Name: veronika-PC
                            Event Code: 6008
                            Message: The previous system shutdown at 9:42:25 PM on 05/04/2009 was unexpected.
                            Record Number: 43529
                            Source Name: EventLog
                            Time Written: 20090406014342.000000-000
                            Event Type: Error
                            User:

                            Computer Name: veronika-PC
                            Event Code: 15016
                            Message: Unable to initialize the security package Kerberos for server side authentication. The data field contains the error number.
                            Record Number: 43538
                            Source Name: Microsoft-Windows-HttpEvent
                            Time Written: 20090406014350.369551-000
                            Event Type: Error
                            User:

                            Computer Name: veronika-PC
                            Event Code: 7000
                            Message: The Cyberlink RichVideo Service(CRVS) service failed to start due to the following error:
                            The system cannot find the path specified.
                            Record Number: 43590
                            Source Name: Service Control Manager
                            Time Written: 20090406014412.000000-000
                            Event Type: Error
                            User:

                            Computer Name: veronika-PC
                            Event Code: 6008
                            Message: The previous system shutdown at 1:25:08 AM on 06/04/2009 was unexpected.
                            Record Number: 43650
                            Source Name: EventLog
                            Time Written: 20090406113648.000000-000
                            Event Type: Error
                            User:

                            =====Application event log=====

                            Computer Name: veronika-PC
                            Event Code: 1000
                            Message: Faulting application DllHost.exe, version 6.0.6000.16386, time stamp 0x4549b14e, faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code 0xc0000005, fault offset 0x019db5ed, process id 0x8ac, application start time 0x01c9d6548772efe1.
                            Record Number: 11216
                            Source Name: Application Error
                            Time Written: 20090516183140.000000-000
                            Event Type: Error
                            User:

                            Computer Name: veronika-PC
                            Event Code: 1530
                            Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.

                            DETAIL -
                            1 user registry handles leaked from \Registry\User\S-1-5-21-1921634279-322472747-1836765424-1000:
                            Process 932 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1921634279-322472747-1836765424-1000

                            Record Number: 11224
                            Source Name: Microsoft-Windows-User Profiles Service
                            Time Written: 20090516183359.000000-000
                            Event Type: Warning
                            User: NT AUTHORITY\SYSTEM

                            Computer Name: veronika-PC
                            Event Code: 1530
                            Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.

                            DETAIL -
                            2 user registry handles leaked from \Registry\User\S-1-5-21-1921634279-322472747-1836765424-1000_Classes:
                            Process 592 (\Device\HarddiskVolume1\Windows\System32\csrss.exe) has opened key \REGISTRY\USER\S-1-5-21-1921634279-322472747-1836765424-1000_CLASSES
                            Process 932 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1921634279-322472747-1836765424-1000_CLASSES

                            Record Number: 11225
                            Source Name: Microsoft-Windows-User Profiles Service
                            Time Written: 20090516183359.000000-000
                            Event Type: Warning
                            User: NT AUTHORITY\SYSTEM

                            Computer Name: veronika-PC
                            Event Code: 1000
                            Message: Faulting application DllHost.exe, version 6.0.6000.16386, time stamp 0x4549b14e, faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code 0xc0000005, fault offset 0x0163b5ed, process id 0xfac, application start time 0x01c9d655d03bc218.
                            Record Number: 11246
                            Source Name: Application Error
                            Time Written: 20090516184044.000000-000
                            Event Type: Error
                            User:

                            Computer Name: veronika-PC
                            Event Code: 1000
                            Message: Faulting application DllHost.exe, version 6.0.6000.16386, time stamp 0x4549b14e, faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code 0xc0000005, fault offset 0x0197b5ed, process id 0x8f8, application start time 0x01c9d65796a03120.
                            Record Number: 11261
                            Source Name: Application Error
                            Time Written: 20090516185337.000000-000
                            Event Type: Error
                            User:

                            =====Security event log=====

                            Computer Name: veronika-PC
                            Event Code: 5038
                            Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

                            File Name: \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
                            Record Number: 24582
                            Source Name: Microsoft-Windows-Security-Auditing
                            Time Written: 20090516185721.921534-000
                            Event Type: Audit Failure
                            User:

                            Computer Name: veronika-PC
                            Event Code: 5038
                            Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

                            File Name: \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
                            Record Number: 24583
                            Source Name: Microsoft-Windows-Security-Auditing
                            Time Written: 20090516185721.983934-000
                            Event Type: Audit Failure
                            User:

                            Computer Name: veronika-PC
                            Event Code: 5038
                            Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

                            File Name: \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
                            Record Number: 24584
                            Source Name: Microsoft-Windows-Security-Auditing
                            Time Written: 20090516185722.015134-000
                            Event Type: Audit Failure
                            User:

                            Computer Name: veronika-PC
                            Event Code: 5038
                            Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

                            File Name: \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
                            Record Number: 24585
                            Source Name: Microsoft-Windows-Security-Auditing
                            Time Written: 20090516185722.046334-000
                            Event Type: Audit Failure
                            User:

                            Computer Name: veronika-PC
                            Event Code: 5038
                            Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

                            File Name: \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
                            Record Number: 24586
                            Source Name: Microsoft-Windows-Security-Auditing
                            Time Written: 20090516185722.077534-000
                            Event Type: Audit Failure
                            User:

                            ======Environment variables======

                            "ComSpec"=%SystemRoot%\system32\cmd.exe
                            "FP_NO_HOST_CHECK"=NO
                            "OS"=Windows_NT
                            "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
                            "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
                            "PROCESSOR_ARCHITECTURE"=x86
                            "TEMP"=%SystemRoot%\TEMP
                            "TMP"=%SystemRoot%\TEMP
                            "USERNAME"=SYSTEM
                            "windir"=%SystemRoot%
                            "PROCESSOR_LEVEL"=6
                            "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 14 Stepping 8, GenuineIntel
                            "PROCESSOR_REVISION"=0e08
                            "NUMBER_OF_PROCESSORS"=2
                            "CLASSPATH"=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
                            "QTJAVA"=C:\Program Files\QuickTime\QTSystem\QTJava.zip

                            -----------------EOF-----------------
                            voila le premier r apport
                            0
                            1. Logfile of random's system information tool 1.06 (written by random/random)
                              Run by veronika at 2009-05-16 15:09:43
                              Microsoft® Windows Vista™ Ultimate Service Pack 1
                              System drive C: has 38 GB (50%) free of 76 GB
                              Total RAM: 1013 MB (34% free)

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 3:10:07 PM, on 16/05/2009
                              Platform: Windows Vista SP1 (WinNT 6.00.1905)
                              MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                              Boot mode: Normal

                              Running processes:
                              C:\Windows\system32\taskeng.exe
                              C:\Windows\system32\Dwm.exe
                              C:\Windows\system32\taskeng.exe
                              C:\Windows\Explorer.EXE
                              C:\Program Files\Windows Defender\MSASCui.exe
                              C:\Program Files\Synaptics\SynTP\SynTPStart.exe
                              C:\Windows\System32\hkcmd.exe
                              C:\Windows\System32\igfxpers.exe
                              C:\Program Files\Windows Live\Family Safety\fsui.exe
                              C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
                              C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
                              C:\Windows\system32\igfxsrvc.exe
                              C:\Program Files\iTunes\iTunesHelper.exe
                              C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                              C:\Program Files\Windows Sidebar\sidebar.exe
                              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              C:\Windows\system32\wbem\unsecapp.exe
                              C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                              C:\Program Files\Internet Explorer\ieuser.exe
                              C:\Program Files\Windows Sidebar\sidebar.exe
                              C:\Users\veronika\Desktop\RSIT.exe
                              C:\Program Files\trend micro\veronika.exe
                              C:\Windows\system32\SearchFilterHost.exe

                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
                              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local>
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                              O1 - Hosts: ::1 localhost
                              O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
                              O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                              O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
                              O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                              O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
                              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
                              O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                              O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                              O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                              O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                              O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
                              O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
                              O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                              O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                              O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                              O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
                              O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
                              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                              O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                              O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              O4 - HKCU\..\Run: [dll] rundll32 dll32,sm
                              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
                              O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
                              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
                              O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
                              O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
                              O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                              O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                              O13 - Gopher Prefix:
                              O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
                              O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://ma-config.com/activex/hardwaredetection_3_1_1_0.cab
                              O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                              O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                              O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
                              O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                              O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                              O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
                              O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe
                              0
                              1. Desactives ton uac le temps de la desinfection

                                Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

                                - Vas dans "Démarrer" puis Panneau de configuration.
                                - Double Clique sur l'icône Comptes d'utilisateurs et sur Activer ou désactiver le contrôle des comptes d'utilisateurs.
                                - Clique sur Continuer.
                                - Décoche la case Utiliser le contrôle des comptes d'utilisateurs pour vous aider à protéger votre ordinateur.
                                - Valide par OK et redémarre.

                                Tuto

                                Ensuite executes tous les logiciels utilisés en tant qu'administrateur (cliques droit avec la souris)

                                Télécharge TOOLBAR S&D( de Eric_71/Team IDN ) sur ton bureau :

                                ( Tuto : https://sites.google.com/site/toolbarsd/aideenimages )

                                !! Déconnecte toi et ferme toutes tes applications en cours le temps de la manipe !!

                                * Double-clique sur ToolBar SD.exe pour lancer l'outil et laisse toi guider ...
                                --> Tapes ( option " recherche " ) puis tape sur [Entrée].

                                Un rapport sera généré à la fin du processus : poste son contenu dans ta prochaine réponse

                                ( le rapport est en outre sauvegardé ici -> C:\TB.txt )
                                0
                                1. -----------\\ ToolBar S&D 1.2.8 XP/Vista

                                  Microsoft® Windows Vista™ Ultimate ( v6.0.6001 ) Service Pack 1
                                  X86-based PC ( Multiprocessor Free : Genuine Intel(R) CPU T2300 @ 1.66GHz )
                                  BIOS : Ver 1.00PARTTBLx
                                  USER : veronika ( Administrator )
                                  BOOT : Normal boot
                                  C:\ (Local Disk) - NTFS - Total:74 Go (Free:37 Go)
                                  D:\ (CD or DVD)

                                  "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
                                  Option : [1] ( 16/05/2009|15:38 )

                                  [ UAC => 0 ]

                                  -----------\\ Recherche de Fichiers / Dossiers ...

                                  -----------\\ [..\Internet Explorer\Main]

                                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                                  "Local Page"="C:\\Windows\\system32\\blank.htm"
                                  "Search Page"="https://www.google.com/?gws_rd=ssl"
                                  "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
                                  "Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
                                  "Default_Search_URL"="http://www.google.com/toolbar/ie8/sidebar.html"
                                  "Url"="http://www.microsoft.com/athome/community/rss.xml"
                                  "Url"="http://www.microsoft.com/atwork/community/rss.xml"
                                  "Url"="http://rss.msn.com/en-us/?feedoutput=rss&ocid=iehrs&unsub=true"

                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                                  "Start Page"="https://www.msn.com/fr-fr"
                                  "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
                                  "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                                  "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"

                                  --------------------\\ Recherche d'autres infections

                                  --------------------\\ Cracks & Keygens ..

                                  C:\Users\veronika\Favorites\YouTube - crackhead gets booked stealing at shoppers.url

                                  [ UAC => 1 ]

                                  1 - "C:\ToolBar SD\TB_1.txt" - 16/05/2009|15:39 - Option : [1]

                                  -----------\\ Fin du rapport a 15:39:42.99

                                  voila
                                  0
                                  1. Télécharges et installes le logiciel de diagnostic :

                                    ici Hijackthis
                                    ou ici Hijackthis
                                    ou ici Hijackthis

                                    ou renommé

                                    Ouvre hijackthis
                                    fais scan only
                                    coches ces lignes sur leur gauche:

                                    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
                                    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                                    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
                                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                                    O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                                    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                                    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
                                    O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
                                    O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
                                    O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
                                    O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://ma-config.com/activex/hardwaredetection_3_1_1_0.cab
                                    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

                                    tu les coches et tu clic sur "fix checked"

                                    et tu fermes le programme.
                                    0
                                    • 1
                                    • 2