Virus MSN

Bonjour,voila mon soucis, j'ai remarque que mon msn envoi des message instantané a mes contacts sans mon avis, quel est la Solution pour y remedier?
Merci d'avance.
Configuration: Windows Vista / Firefox 3.0.18

22 réponses

Résumé de la discussion

La problématique porte sur l'envoi de messages instantanés non autorisés via une application de messagerie, potentiellement dû à une infection ou à un piratage sur un poste Windows Vista et un navigateur obsolète. Des solutions proposées incluent l'utilisation d'HijackThis et RSIT pour diagnostiquer les traces de malware et partager les rapports pour analyse, puis Malwarebytes' Anti-Malware pour un examen approfondi. En cas de suspicion persistante, les journaux RSIT et le contenu du fichier hosts peuvent révéler des modifications système malveillantes, nécessitant un nettoyage des programmes indésirables et une restauration des paramètres.

Bobot (l’IA à votre service)
  1. Bonjour

    # Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
    Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
    Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.


    Télécharge et install UsbFix de C_XX
    Ici : : http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe
    Tutorial de Malekal_Morte si besoin, merci à lui : https://www.malekal.com/usbfix-supprimer-virus-usb/

    Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

    # Clic droit "Exécuter en tant qu'administrateur" sur le raccourci UsbFix présent sur ton bureau.

    # Choisi l option 2 (Suppression)

    # Laisse travailler l outil.

    # Ensuite post le rapport UsbFix.txt qui apparaîtra.

    # Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

    ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

    @+
    0
    1. ok, je vais le faire
      merci
      0
      1. Intel(R) Pentium(R) Dual CPU T3400 @ 2.16GHz
        Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
        Internet Explorer 7.0.6002.18005
        Windows Firewall Status : Enabled

        C:\ -> Disque fixe local # 144,09 Go (51,83 Go free) # NTFS
        D:\ -> Disque fixe local # 144 Go (69,37 Go free) # NTFS
        E:\ -> Disque CD-ROM
        F:\ -> Disque CD-ROM # 2,32 Go (0 Mo free) [FM2010] # UDF
        G:\ -> Disque CD-ROM

        ################## | Elements infectieux |

        C:\Users\Virginie\Documents - Raccourci.lnk
        F:\autorun.inf

        ################## | Registre |

        ################## | Mountpoints2 |

        HKCU\..\..\Explorer\MountPoints2\{1845bb55-64ec-11de-a2a7-001377d5b71e}
        shell\AutoRun\command =F:\InstallTomTomHOME.exe

        HKCU\..\..\Explorer\MountPoints2\{1fced380-ab32-11de-ac91-001377d5b71e}
        shell\AutoRun\command =F:\autorun.exe

        ################## | Vaccin |

        ################## | ! Fin du rapport # UsbFix V6.098 ! |
        0
        1. Re

          Pour de plus amples informations;fait ceci stp;merci

          a) Télécharge et installe le logiciel HijackThis :

          https://www.commentcamarche.net/telecharger/securite/11747-hijackthis/
          ou ici http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe
          ou ici https://www.clubic.com/telecharger-fiche17891-hijackthis.html

          -->Clique sur le setup pour lancer l'installation : laisse toi guider et ne modifie pas les paramètres d'installation .
          A la fin de l’installation, le programme se lance automatiquement : ferme le en cliquant sur la croix rouge.
          Au final, tu dois avoir un raccourci sur ton bureau et aussi un cheminement comme :
          "C:\ program files\Trend Micro\HijackThis\HijackThis.exe " .

          (Ne lance pas ce prg pour l'instant et fais la suite ... )

          b) Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

          -> http://images.malwareremoval.com/random/RSIT.exe

          ! Déconnecte toi et ferme toutes tes applications en cours !

          Double-clique sur " RSIT.exe " pour le lancer.

          Clic droit sous VISTA (exécuter en tant que…)

          -> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

          * Devant l'option "List files/folders created ..." , tu choisis : 2 months

          * clique ensuite sur " Continue " pour lancer l'analyse ...

          -> laisse faire le scan et ne touche pas au PC ...

          Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-notes).

          Poste le contenu de " log.txt " (c'est celui qui apparaît à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

          Important : poste un rapport, puis l'autre dans la réponse suivante ...
          Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum ...
          ( Et si "log.txt" seul, ne passe pas non plus , fais le en 2 fois ... merci ... )

          ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit

          @+
          0
      2. pardon, jai pas fai l'option 2
        0
        1. Intel(R) Pentium(R) Dual CPU T3400 @ 2.16GHz
          Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
          Internet Explorer 7.0.6002.18005
          Windows Firewall Status : Enabled

          C:\ -> Disque fixe local # 144,09 Go (51,69 Go free) # NTFS
          D:\ -> Disque fixe local # 144 Go (69,37 Go free) # NTFS
          E:\ -> Disque CD-ROM
          F:\ -> Disque CD-ROM
          G:\ -> Disque CD-ROM

          ################## | Elements infectieux |

          Supprimé ! C:\Users\Virginie\Documents - Raccourci.lnk
          Supprimé ! C:\$Recycle.Bin\S-1-5-21-3317431821-2754218308-1391888111-500
          Supprimé ! C:\$Recycle.Bin\S-1-5-21-648204624-3893815093-3798972402-1003
          Supprimé ! C:\$Recycle.Bin\S-1-5-21-648204624-3893815093-3798972402-1006
          Supprimé ! C:\$Recycle.Bin\S-1-5-21-648204624-3893815093-3798972402-500
          Supprimé ! C:\$Recycle.Bin\S-1-5-21-648204624-3893815093-3798972402-501
          Supprimé ! D:\$Recycle.Bin\S-1-5-21-648204624-3893815093-3798972402-1003
          Supprimé ! D:\$Recycle.Bin\S-1-5-21-648204624-3893815093-3798972402-1006
          Supprimé ! D:\$Recycle.Bin\S-1-5-21-648204624-3893815093-3798972402-501

          ################## | Registre |

          ################## | Mountpoints2 |

          Supprimé ! HKCU\...\Explorer\MountPoints2\{1845bb55-64ec-11de-a2a7-001377d5b71e}\Shell\AutoRun\Command
          Supprimé ! HKCU\...\Explorer\MountPoints2\{1fced380-ab32-11de-ac91-001377d5b71e}\Shell\AutoRun\Command

          ################## | Listing des fichiers présent |

          [18/09/2006 22:43|--a------|24] C:\autoexec.bat
          [11/04/2009 07:36|-rahs----|333257] C:\bootmgr
          [08/02/2008 10:31|-ra-s----|8192] C:\BOOTSECT.BAK
          [18/09/2006 22:43|--a------|10] C:\config.sys
          [27/04/2009 12:34|--a------|148] C:\dxlog.txt
          [07/01/2009 02:33|-rahs----|0] C:\IO.SYS
          [07/01/2009 02:33|-rahs----|0] C:\MSDOS.SYS
          [?|?|?] C:\pagefile.sys
          [03/11/2009 17:47|--a------|417] C:\RHDSetup.log
          [03/11/2009 18:04|--a------|173] C:\setup.log
          [29/04/2009 13:43|--a------|0] C:\Tech_Vista.log
          [06/03/2010 09:54|--a------|2241] C:\UsbFix.txt

          ################## | Vaccination |

          # C:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
          # D:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).

          ################## | Upload |

          Veuillez envoyer le fichier : C:\UsbFix_Upload_Me_LEROUX.zip : https://www.ionos.fr/?affiliate_id=77097
          Merci pour votre contribution .

          ################## | ! Fin du rapport # UsbFix V6.098 ! |
          0
          1. Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
            System drive C: has 53 GB (36%) free of 148 GB
            Total RAM: 3066 MB (69% free)

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 10:04:29, on 06/03/2010
            Platform: Windows Vista SP2 (WinNT 6.00.1906)
            MSIE: Internet Explorer v7.00 (7.00.6002.18005)
            Boot mode: Normal

            Running processes:
            C:\Windows\system32\taskeng.exe
            C:\Windows\system32\Dwm.exe
            C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe
            C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
            C:\Windows\system32\taskeng.exe
            C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
            C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe
            C:\Windows\system32\conime.exe
            C:\Windows\explorer.exe
            C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
            C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe
            C:\Users\Virginie\Downloads\RSIT.exe
            C:\Program Files\Trend Micro\HijackThis\Virginie.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.cherche.us
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.cherche.us
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
            R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.cherche.us/keyword/%s
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.cherche.us
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
            O1 - Hosts: ::1 localhost
            O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
            O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
            O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
            O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
            O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
            O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
            O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
            O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
            O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\system32\NeroCheck.exe
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
            O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
            O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
            O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
            O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
            O4 - HKCU\..\Run: [Speech Recognition] "C:\Windows\Speech\Common\sapisvr.exe" -SpeechUX -Startup
            O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
            O4 - Global Startup: BTTray.lnk = ?
            O4 - Global Startup: ZDWLan Utility.lnk = C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
            O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
            O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
            O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
            O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
            O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O13 - Gopher Prefix:
            O15 - Trusted Zone: *.chat-land.org
            O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
            O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
            O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
            O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
            O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
            O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
            O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
            O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
            O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
            O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
            O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
            O23 - Service: Samsung Update Plus - Unknown owner - C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe
            O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
            O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
            0
            1. [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

              [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

              ======List of files/folders created in the last 2 months======

              2010-03-06 09:54:27 ----RASHD---- C:\autorun.inf
              2010-03-06 09:50:11 ----A---- C:\UsbFix.txt
              2010-03-06 09:41:26 ----D---- C:\UsbFix
              2010-03-06 09:08:55 ----D---- C:\Users\Virginie\AppData\Roaming\QuickScan
              2010-03-04 20:41:08 ----SHD---- C:\Config.Msi
              2010-03-04 20:16:27 ----D---- C:\ProgramData\FLEXnet
              2010-02-04 20:41:55 ----D---- C:\ProgramData\Sun
              2010-02-04 20:41:53 ----D---- C:\Program Files\Common Files\Java
              2010-02-04 20:41:35 ----A---- C:\Windows\system32\javaws.exe
              2010-02-04 20:41:35 ----A---- C:\Windows\system32\javaw.exe
              2010-02-04 20:41:35 ----A---- C:\Windows\system32\java.exe
              2010-01-23 10:21:30 ----D---- C:\Program Files\Google
              2010-01-23 10:21:30 ----D---- C:\Program Files\DivX

              ======List of files/folders modified in the last 2 months======

              2010-03-06 10:03:48 ----D---- C:\Windows\Temp
              2010-03-06 10:00:56 ----D---- C:\Program Files\trend micro
              2010-03-06 09:56:55 ----D---- C:\Program Files\Mozilla Firefox
              2010-03-06 09:53:25 ----SHD---- C:\$Recycle.Bin
              2010-03-06 09:43:36 ----D---- C:\Windows\tracing
              2010-03-06 09:39:50 ----D---- C:\Users\Virginie\AppData\Roaming\Spyware Terminator
              2010-03-06 09:39:49 ----D---- C:\Program Files\Spyware Terminator
              2010-03-05 08:53:56 ----D---- C:\Windows\Prefetch
              2010-03-04 20:58:54 ----SHD---- C:\Windows\Installer
              2010-03-04 20:57:51 ----D---- C:\Program Files\Common Files\Adobe
              2010-03-04 20:57:50 ----D---- C:\Program Files\Common Files
              2010-03-04 20:55:56 ----D---- C:\Program Files\Adobe
              2010-03-04 20:55:31 ----D---- C:\Users\Virginie\AppData\Roaming\Adobe
              2010-03-04 20:55:31 ----D---- C:\ProgramData\Adobe
              2010-03-04 20:48:12 ----D---- C:\Windows\system32\drivers
              2010-03-04 20:42:49 ----D---- C:\Windows\System32
              2010-03-04 20:41:55 ----RD---- C:\Program Files
              2010-03-04 20:41:47 ----SHD---- C:\System Volume Information
              2010-03-04 20:16:27 ----D---- C:\ProgramData
              2010-03-04 19:57:40 ----RSD---- C:\Windows\Fonts
              2010-03-01 12:12:16 ----D---- C:\Program Files\Microsoft Silverlight
              2010-02-28 14:07:35 ----D---- C:\Windows\system32\catroot2
              2010-02-26 20:04:02 ----D---- C:\Windows\inf
              2010-02-26 20:04:02 ----A---- C:\Windows\system32\PerfStringBackup.INI
              2010-02-26 16:18:55 ----D---- C:\Windows
              2010-02-24 08:55:59 ----D---- C:\Windows\system32\catroot
              2010-02-24 08:55:53 ----D---- C:\Windows\winsxs
              2010-02-11 18:28:24 ----D---- C:\ProgramData\Spyware Terminator
              2010-02-09 17:16:45 ----D---- C:\ProgramData\Spybot - Search & Destroy
              2010-02-08 17:06:58 ----SD---- C:\Windows\Downloaded Program Files
              2010-02-08 14:47:36 ----D---- C:\Program Files\MyDefrag v4.2.5
              2010-02-04 20:41:29 ----D---- C:\Program Files\Java
              2010-02-01 15:41:49 ----SD---- C:\Users\Virginie\AppData\Roaming\Microsoft
              2010-01-23 11:34:10 ----D---- C:\Windows\Tasks
              2010-01-23 11:34:10 ----D---- C:\ProgramData\Google
              2010-01-23 10:29:59 ----D---- C:\Windows\system32\Tasks

              ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

              R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2009-11-25 23120]
              R1 aswSP;avast! Self Protection; C:\Windows\system32\drivers\aswSP.sys [2009-09-15 114768]
              R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2009-11-25 48560]
              R2 aswFsBlk;aswFsBlk; C:\Windows\system32\DRIVERS\aswFsBlk.sys [2009-09-15 20560]
              R2 aswMonFlt;aswMonFlt; C:\Windows\system32\DRIVERS\aswMonFlt.sys [2009-09-15 53328]
              R2 KMDFMEMIO;SAMSUNG Kernel Driver; C:\Windows\system32\DRIVERS\kmdfmemio.sys [2008-12-30 13312]
              R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2008-04-27 909824]
              R3 CmBatt;Pilote pour Batterie à méthode de contrôle ACPI Microsoft; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-21 14208]
              R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
              R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-09-23 26176]
              R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-07-07 2152088]
              R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda32v.sys [2009-01-22 52768]
              R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2008-07-27 7548000]
              R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\Windows\System32\Drivers\RootMdm.sys [2008-01-21 8192]
              R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2007-10-26 193456]
              R3 VMC302;Vimicro Camera Service VMC302; C:\Windows\System32\Drivers\VMC302.sys [2008-06-05 242048]
              R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2008-06-27 303616]
              R3 ZDPSp50;ZDPSp50 NDIS Protocol Driver; C:\Windows\System32\Drivers\ZDPSp50.sys [2004-10-25 17664]
              S2 adfs;adfs; C:\Windows\system32\drivers\adfs.sys []
              S3 ag52skom;ag52skom; C:\Windows\system32\drivers\ag52skom.sys []
              S3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2008-03-21 1203776]
              S3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller XP Driver; C:\Windows\system32\DRIVERS\bcm4sbxp.sys [2006-11-02 45056]
              S3 BthEnum;Pilote de bloc de demande Bluetooth; C:\Windows\system32\DRIVERS\BthEnum.sys [2008-01-21 19456]
              S3 BthPan;Périphérique Bluetooth (réseau personnel); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
              S3 BTHPORT;Pilote de port Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2008-04-29 220160]
              S3 BTHUSB;Pilote USB radio Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2008-04-29 29184]
              S3 btwaudio;Périphérique audio Bluetooth; C:\Windows\system32\drivers\btwaudio.sys [2008-02-14 80424]
              S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2007-07-15 80936]
              S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2007-07-15 16168]
              S3 driverhardwarev2;driverhardwarev2; \??\C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys [2009-05-29 14336]
              S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
              S3 HdAudAddService;Pilote de fonction UAA 1.1 Microsoft pour le service High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
              S3 ialm;ialm; C:\Windows\system32\DRIVERS\igdkmd32.sys [2006-10-19 1380864]
              S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
              S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
              S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
              S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
              S3 NETw3v32;Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw3v32.sys [2008-01-21 2225664]
              S3 PsSdk41;PsSdk41; \??\C:\Windows\system32\Drivers\pssdk41.sys [2009-05-04 36928]
              S3 RFCOMM;Périphérique Bluetooth (TDI protocole RFCOMM); C:\Windows\system32\DRIVERS\rfcomm.sys [2008-02-21 50688]
              S3 tosporte;Bluetooth COM Port; C:\Windows\system32\DRIVERS\tosporte.sys []
              S3 tosrfbd;Bluetooth RFBUS; C:\Windows\system32\DRIVERS\tosrfbd.sys []
              S3 tosrfbnp;Bluetooth RFBNEP; C:\Windows\System32\Drivers\tosrfbnp.sys []
              S3 Tosrfcom;Bluetooth RFCOMM; C:\Windows\System32\Drivers\tosrfcom.sys []
              S3 Tosrfhid;Bluetooth RFHID; C:\Windows\system32\DRIVERS\Tosrfhid.sys []
              S3 tosrfnds;Bluetooth Personal Area Network; C:\Windows\system32\DRIVERS\tosrfnds.sys []
              S3 TosRfSnd;Bluetooth Audio; C:\Windows\system32\drivers\tosrfsnd.sys []
              S3 Tosrfusb;Bluetooth USB Controller; C:\Windows\system32\DRIVERS\tosrfusb.sys []
              S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2009-08-28 40448]
              S3 usbbus;LGE Mobile Composite USB Device; C:\Windows\system32\DRIVERS\lgusbbus.sys [2007-07-11 12416]
              S3 UsbDiag;LGE Mobile USB Serial Port; C:\Windows\system32\DRIVERS\lgusbdiag.sys [2007-07-11 19840]
              S3 USBModem;LGE Mobile USB Modem; C:\Windows\system32\DRIVERS\lgusbmodem.sys [2007-07-11 21632]
              S3 usbvideo;Périphérique vidéo USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
              S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
              S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
              S3 xnacc;Contrôleur XBOX 360 pour le service de pilote Windows; C:\Windows\system32\DRIVERS\xnacc.sys [2008-01-21 521216]
              S3 ZD1211BU(ZyDAS);ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS); C:\Windows\system32\DRIVERS\zd1211Bu.sys [2005-10-28 402432]
              S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
              S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
              S4 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-21 88576]
              S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2008-01-21 11264]

              ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

              R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-08-28 144672]
              R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-11-25 18752]
              R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-11-25 138680]
              R2 BcmSqlStartupSvc;Service de démarrage SQL Server pour le Gestionnaire de contacts professionnels; C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [2008-01-16 30312]
              R2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
              R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
              R2 EvtEng;Intel® PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2008-07-10 819200]
              R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [2009-10-29 1074568]
              R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-03-17 73728]
              R2 NMSAccessU;NMSAccessU; C:\Program Files\CDBurnerXP\NMSAccessU.exe [2009-07-13 71096]
              R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2008-07-27 196608]
              R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2009-05-09 66872]
              R2 RegSrvc;Intel® PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2008-07-10 466944]
              R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2006-12-19 272024]
              R2 SBSDWSCService;SBSD Security Center Service; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
              R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
              R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2009-05-10 487424]
              R2 SQLBrowser;SQL Server Browser; C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2008-11-24 239968]
              R2 SQLWriter;Enregistreur VSS SQL Server; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-11-24 87904]
              R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-11-25 254040]
              R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-11-25 352920]
              R3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
              S2 Samsung Update Plus;Samsung Update Plus; C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe [2008-05-13 77480]
              S3 aspnet_state;Service d'état ASP.NET; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2009-03-30 31048]
              S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
              S3 iPod Service;Service de l’iPod; C:\Program Files\iPod\bin\iPodService.exe [2009-09-21 545568]
              S3 maconfservice;Ma-Config Service; C:\Program Files\ma-config.com\maconfservice.exe [2009-05-29 234864]
              S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ); C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2009-05-27 29262680]
              S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
              S4 MSSQLServerADHelper;SQL Server Active Directory Helper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2008-11-24 45408]

              -----------------EOF-----------------
              0
              1. par contre j'ai que le log
                pas l'autre
                0
                1. Re

                  Il est normalement ici:C:\rsit

                  Ensuite;Lance hijackthis ; ici : C:\Program Files\Trend Micro\HijackThis\Virginie.exe

                  mais cette fois clic sur "Do a system scan only"

                  ensuite coches les cases sur la gauche des ces lignes :
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ww12.cherche.us
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ww12.cherche.us
                  R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.cherche.us/keyword/%s
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://ww12.cherche.us
                  O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                  O4 - Global Startup: BTTray.lnk = ?
                  O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
                  ;ensuite tu cliques sur la fenêtre "Fix cheked".
                  HijackThis va te demander de confirmer que tu veux supprimer ces éléments. Cliques sur Yes (Oui) ) .

                  Tuto ici:https://www.bleepingcomputer.com/tutorials/comment-utiliser-hijackthis/#RDiag

                  Comment se comporte ton MSN? Envoies tu encore des messages?

                  @+
                  0
              2. info.txt logfile of random's system information tool 1.06 2009-05-12 11:30:25

                ======Uninstall list======

                -->MsiExec /X{DD1865F0-AD73-40FB-B23E-1822E02396FF}
                2007 Microsoft Office system-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROHYBRIDR /dll OSETUP.DLL
                7 Sins-->C:\Program Files\Monte Cristo\7 Sins\uninst.exe
                Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
                Adobe Flash Player ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
                Adobe Reader 8.1.2 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81200000003}
                Agere Systems HDA Modem-->agrsmdel
                Apple Mobile Device Support-->MsiExec.exe /I{162B71B8-8464-4680-A086-601D555B331D}
                Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
                Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
                Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
                Atheros WLAN Client-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{04983D37-2202-4295-94A2-8B547C66133F}\setup.exe" -l0x9
                avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
                BankPerfect 6.23-->"C:\Program Files\BankPerfect\uninstall.exe"
                Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
                CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
                Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
                Crysis(R)-->MsiExec.exe /I{000E79B7-E725-4F01-870A-C12942B7F8E4}
                CyberLink DVD Suite-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\setup.exe" -uninstall
                CyberLink Power2Go-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\setup.exe" -uninstall
                Easy Battery Manager-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6F730513-8688-4C3C-90A3-6B9792CE2EF3}\setup.exe" -l0x9 Remove
                Easy Display Manager-->"C:\Program Files\InstallShield Installation Information\{17283B95-21A8-4996-97DA-547A48DB266F}\setup.exe" -runfromtemp -l0x0009 -removeonly
                Easy Network Manager-->MsiExec.exe /I{A7581D39-EA20-4883-A480-80C21047052B}
                Easy SpeedUp Manager-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EF367AA4-070B-493C-9575-85BE59D789C9}\setup.exe" -l0x9 Remove
                Fichiers de prise en charge de l'installation de Microsoft SQL Server (Français)-->MsiExec.exe /X{3380F354-C5F7-4E71-8F51-EEE6C3F06C62}
                Football Manager 2009-->"C:\Program Files\Sports Interactive\Football Manager 2009\Uninstall_Football Manager 2009\Uninstall Football Manager 2009.exe"
                Foto-Mosaik 4.1.0-->"C:\Program Files\Foto-Mosaik\unins000.exe"
                Freecorder Toolbar 3.02 Application-->"C:\Windows\Freecorder Toolbar\uninstall.exe" "/U:C:\Program Files\Freecorder Toolbar\Uninstall\uninstall.xml"
                Galerie de photos Windows Live-->MsiExec.exe /X{44E54A81-9D91-4AA1-9417-80AFF134F5FF}
                Gestionnaire de contacts professionnels pour Outlook 2007 SP2-->"C:\Program Files\Microsoft Small Business\Business Contact Manager\SetupBootstrap\Setup.exe" /remove {69ca8988-1c6c-4285-b8af-db780a6e42af}
                Gestionnaire de contacts professionnels pour Outlook 2007 SP2-->MsiExec.exe /X{69CA8988-1C6C-4285-B8AF-DB780A6E42AF}
                HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
                Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
                Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
                imagine digital freedom - Samsung-->MsiExec.exe /X{8E106A57-A17E-431D-B48F-175E42EB9F74}
                Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
                Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
                Intel PROSet Wireless-->Intel PROSet Wireless
                Intel® Matrix Storage Manager-->C:\Program Files\Intel\Intel Matrix Storage Manager\Uninstall\imsmudlg.exe -uninstall
                iTunes-->MsiExec.exe /I{C26B06A9-27BB-45B0-9873-9C623EC2BA38}
                Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
                LabelPrint-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\setup.exe" -uninstall
                LG PC Suite-->C:\Program Files\InstallShield Installation Information\{993960EE-CA4D-443F-8F88-E24260DD5FD2}\setup.exe -runfromtemp -l0x040c -removeonly
                LG USB Modem driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C3ABE126-2BB2-4246-BFE1-6797679B3579}\setup.exe" -l0x40c LG -removeonly
                LightScribe System Software 1.12.37.1-->MsiExec.exe /X{004C5DA2-2051-4D25-94BA-51CF810C91EB}
                Ma-Config.com-->MsiExec.exe /X{E780E536-16CE-4CD1-8FE0-2D5E52FAA65B}
                Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
                Marvell Miniport Driver-->C:\Program Files\Marvell\Miniport Driver\Uninst.exe
                Microsoft .NET Framework 1.1 Hotfix (KB929729)-->"C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\M929729\M929729Uninstall.msp"
                Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
                Microsoft .NET Framework 3.5 SP1-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
                Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
                Microsoft Office 2003 Web Components-->MsiExec.exe /I{90A4040C-6000-11D3-8CFE-0150048383C9}
                Microsoft Office 2007 Primary Interop Assemblies-->MsiExec.exe /X{50120000-1105-0000-0000-0000000FF1CE}
                Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
                Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0015-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0015-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0019-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0019-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0044-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
                Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
                Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
                Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
                Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
                Microsoft Office InfoPath MUI (French) 2007-->MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}
                Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
                Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
                Microsoft Office Professional Hybrid 2007-->MsiExec.exe /X{91120000-0031-0000-0000-0000000FF1CE}
                Microsoft Office Professional Plus 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
                Microsoft Office Professional Plus 2007-->MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}
                Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
                Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
                Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
                Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
                Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
                Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
                Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
                Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
                Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
                Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
                Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
                Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
                Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
                Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
                Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
                Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
                Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
                Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
                Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
                Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
                Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
                Microsoft Office Small Business Connectivity Components-->MsiExec.exe /X{A939D341-5A04-4E0A-BB55-3E65B386432D}
                Microsoft Office Suite Activation Assistant-->MsiExec.exe /X{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}
                Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
                Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
                Microsoft SOAP Toolkit 2.0 SP2-->MsiExec.exe /I{36BEAD11-8577-49AD-9250-E06A50AE87B0}
                Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
                Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)-->MsiExec.exe /I{480DBB60-F0B6-45F2-B26F-1A2E11197791}
                Microsoft SQL Server 2005-->"C:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\ARPWrapper.exe" /Remove
                Microsoft SQL Server Native Client-->MsiExec.exe /I{1F24E48F-7692-4E89-8784-68DD4D2712A0}
                Microsoft SQL Server VSS Writer-->MsiExec.exe /I{A30179B7-997A-4D47-AA43-57AE59A9C78B}
                Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
                Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
                Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
                Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
                Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
                Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
                Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
                Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
                Mozilla Firefox (3.0.10)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
                NVIDIA Drivers-->C:\Windows\system32\nvuninst.exe UninstallGUI
                NVIDIA PhysX-->MsiExec.exe /X{DD1865F0-AD73-40FB-B23E-1822E02396FF}
                Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
                PhotoFiltre-->"C:\Program Files\PhotoFiltre\Uninst.exe"
                PlayCamera-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{804F1285-8CBF-408D-8CDC-D4D40003B2E4}\setup.exe" -l0x40c
                PowerDirector-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\setup.exe" -uninstall
                PowerDVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
                PowerProducer-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\setup.exe" -uninstall
                PunkBuster Services-->C:\Windows\system32\pbsvc.exe -u
                QuickTime-->MsiExec.exe /I{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}
                Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\setup.exe" -removeonly
                Samsung Magic Doctor-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{32D6A58F-9659-446C-BBFC-E6F2B41F24DC}\Setup.exe" -l0x9 Remove
                Samsung Mobility Panel-->MsiExec.exe /I{231F1242-35FB-4A1F-8E93-600BCE767941}
                Samsung Recovery Solution III-->"C:\Program Files\InstallShield Installation Information\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}\setup.exe" -runfromtemp -l0x040c -removeonly
                Samsung Update Plus-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\10\INTEL3~1\IDriver.exe /M{685707A4-911C-468D-BFC4-64A50E5E3A0C} /l1036
                Security Update for Windows Media Encoder (KB954156)-->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E} MSIPATCHREMOVE={E836F1B7-43FB-46B0-A0D9-E4D2A5951659} /qb
                Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
                Spyware Terminator-->"C:\Program Files\Spyware Terminator\unins000.exe"
                Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
                System Requirements Lab-->C:\Program Files\SystemRequirementsLab\Uninstall.exe
                Trojan Remover 6.7.8-->"C:\Program Files\Trojan Remover\unins000.exe"
                Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
                Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
                Update for Microsoft Office Outlook 2007 Help (KB957246)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {80E46078-C1C5-4AE8-8744-3EAFC812E118}
                Update for Microsoft Office Outlook 2007 Help (KB957246)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {80E46078-C1C5-4AE8-8744-3EAFC812E118}
                Update for Outlook 2007 Junk Email Filter (kb968503)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {5DD98950-4D10-4B79-8BF6-59726705207D}
                Update for Outlook 2007 Junk Email Filter (kb968503)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {5DD98950-4D10-4B79-8BF6-59726705207D}
                User Guide-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}\setup.exe" -l0x9 Remove
                Vimicro UVC Camera-->C:\Program Files\InstallShield Installation Information\{71A51B09-E7D3-11DB-A386-005056C00008}\setup.exe -runfromtemp -l0x0009 -removeonly
                VLC media player 0.9.8a-->C:\Program Files\VideoLAN\VLC\uninstall.exe
                WIDCOMM Bluetooth Software 6.0.1.6300-->MsiExec.exe /X{03D1988F-469F-4843-8E6E-E5FE9D17889D}
                Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
                Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
                Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
                Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
                Windows Live Movie Maker Bêta-->MsiExec.exe /X{F874DF52-A31F-44C1-A606-EF40F1549261}
                Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
                Windows Live Writer-->MsiExec.exe /X{2231CE39-B963-4B9D-823A-F412ECA637B1}
                Windows Media Encoder 9 Series-->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
                Windows Media Encoder 9 Series-->MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
                XLink Kai-->MsiExec.exe /X{87C24822-389C-45AA-9E75-0757B8F1A892}
                ZyDAS IEEE 802.11 b+g Wireless LAN - USB-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{581CE7EA-A30D-0000-1211-088635773309}\Setup.exe" -l0x9

                ======Hosts File======

                127.0.0.1 www.007guard.com
                127.0.0.1 007guard.com
                127.0.0.1 008i.com
                127.0.0.1 www.008k.com
                127.0.0.1 008k.com
                127.0.0.1 www.00hq.com
                127.0.0.1 00hq.com
                127.0.0.1 010402.com
                127.0.0.1 www.032439.com
                127.0.0.1 032439.com

                ======Security center information======

                AS: Spybot - Search and Destroy
                AS: Windows Defender
                AS: Spyware Terminator (disabled)

                ======System event log======

                Computer Name: LEROUX
                Event Code: 3004
                Message: L’agent de protection en temps réel Windows Defender a détecté des modifications. Microsoft vous recommande d’analyser les logiciels responsables de ces modifications, à la recherche de risques potentiels. Vous pouvez vous servir des informations relatives au fonctionnement de ces programmes pour autoriser ou non leur exécution, ou pour les supprimer de l’ordinateur. N’autorisez les modifications que si vous faites confiance au programme ou à l’éditeur de logiciel. Windows Defender ne peut pas annuler les modifications que vous autorisez.
                Pour plus d’informations, consultez les données suivantes :
                Non applicable
                ID d’analyse : {F30DEEBC-B377-457A-A6EC-CF58CF477DAA}
                Utilisateur : LEROUX\Virginie
                Nom : Unknown
                ID :
                ID de gravité :
                ID de catégorie :
                Chemin d’accès trouvé : clsid:HKLM\SOFTWARE\CLASSES\CLSID\{52B87208-9CCF-42C9-B88E-069281105805};regkey:HKLM\SOFTWARE\CLASSES\CLSID\{52B87208-9CCF-42C9-B88E-069281105805};regkey:HKLM\Software\Classes\*\shellex\ContextMenuHandlers\Trojan Remover;contextmenu:HKLM\Software\Classes\*\shellex\ContextMenuHandlers\Trojan Remover;file:C:\Program Files\Trojan Remover\Trshlex.dll
                Type d’alerte : Logiciel non classifié
                Type de détection :
                Record Number: 57610
                Source Name: Microsoft-Windows-Windows Defender
                Time Written: 20090512090935.000000-000
                Event Type: Avertissement
                User:

                Computer Name: LEROUX
                Event Code: 3004
                Message: L’agent de protection en temps réel Windows Defender a détecté des modifications. Microsoft vous recommande d’analyser les logiciels responsables de ces modifications, à la recherche de risques potentiels. Vous pouvez vous servir des informations relatives au fonctionnement de ces programmes pour autoriser ou non leur exécution, ou pour les supprimer de l’ordinateur. N’autorisez les modifications que si vous faites confiance au programme ou à l’éditeur de logiciel. Windows Defender ne peut pas annuler les modifications que vous autorisez.
                Pour plus d’informations, consultez les données suivantes :
                Non applicable
                ID d’analyse : {1FEE9A75-0CCB-41D6-ABB3-EEDDB50E50F7}
                Utilisateur : LEROUX\Virginie
                Nom : Unknown
                ID :
                ID de gravité :
                ID de catégorie :
                Chemin d’accès trouvé : regkey:HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\TrojanScanner;runkey:HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\TrojanScanner;file:C:\Program Files\Trojan Remover\Trjscan.exe
                Type d’alerte : Logiciel non classifié
                Type de détection :
                Record Number: 57613
                Source Name: Microsoft-Windows-Windows Defender
                Time Written: 20090512090938.000000-000
                Event Type: Avertissement
                User:

                Computer Name: LEROUX
                Event Code: 15016
                Message: Impossible d’initialiser le package de sécurité Kerberos pour l’authentification côté serveur. Le champ de données contient le numéro de l’erreur.
                Record Number: 57636
                Source Name: Microsoft-Windows-HttpEvent
                Time Written: 20090512091141.368555-000
                Event Type: Erreur
                User:

                Computer Name: LEROUX
                Event Code: 7000
                Message: Le service Parallel port driver n'a pas pu démarrer en raison de l'erreur :
                Le service ne peut pas être démarré parce qu'il est désactivé ou qu'aucun périphérique activé ne lui est associé.
                Record Number: 57674
                Source Name: Service Control Manager
                Time Written: 20090512091148.000000-000
                Event Type: Erreur
                User:

                Computer Name: LEROUX
                Event Code: 1001
                Message: L’initialisation de l’application a échoué. Dernière erreur : 0x80070032
                Record Number: 57725
                Source Name: Microsoft-Windows-LanguagePackSetup
                Time Written: 20090512091212.282355-000
                Event Type: Erreur
                User: AUTORITE NT\SYSTEM

                =====Application event log=====
                0
                1. Computer Name: LEROUX
                  Event Code: 1015
                  Message: L'ID événement 3013 du service Windows Search a été supprimé 10 fois depuis 10:01:47. Cet événement est utilisé pour supprimer les événements du service Windows Search qui se sont produits fréquemment dans une courte période. Voir l'ID événement 3013 pour plus de détails sur cet événement.
                  Record Number: 12286
                  Source Name: Microsoft-Windows-Search
                  Time Written: 20090512083026.000000-000
                  Event Type: Avertissement
                  User:

                  Computer Name: LEROUX
                  Event Code: 1530
                  Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

                  DÉTAIL -
                  1 user registry handles leaked from \Registry\User\S-1-5-21-648204624-3893815093-3798972402-1003:
                  Process 976 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-648204624-3893815093-3798972402-1003

                  Record Number: 12289
                  Source Name: Microsoft-Windows-User Profiles Service
                  Time Written: 20090512091043.000000-000
                  Event Type: Avertissement
                  User: AUTORITE NT\SYSTEM

                  Computer Name: LEROUX
                  Event Code: 1530
                  Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

                  DÉTAIL -
                  1 user registry handles leaked from \Registry\User\S-1-5-21-648204624-3893815093-3798972402-1003_Classes:
                  Process 976 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-648204624-3893815093-3798972402-1003_CLASSES

                  Record Number: 12290
                  Source Name: Microsoft-Windows-User Profiles Service
                  Time Written: 20090512091043.000000-000
                  Event Type: Avertissement
                  User: AUTORITE NT\SYSTEM

                  Computer Name: LEROUX
                  Event Code: 3
                  Message: La configuration du protocole AdminConnection\TCP n'est pas valide dans l'instance SQL MSSMLBIZ.
                  Record Number: 12306
                  Source Name: SQLBrowser
                  Time Written: 20090512091146.000000-000
                  Event Type: Avertissement
                  User:

                  Computer Name: LEROUX
                  Event Code: 10
                  Message: Le filtre d’événement avec la requête « SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99 » n’a pas pu être réactivé dans l’espace de noms « //./root/CIMV2 » à cause de l’erreur 0x80041003. Les événements ne peuvent pas être délivrés à travers ce filtre tant que le problème ne sera pas corrigé.
                  Record Number: 12312
                  Source Name: Microsoft-Windows-WMI
                  Time Written: 20090512091148.000000-000
                  Event Type: Erreur
                  User:

                  =====Security event log=====

                  Computer Name: LEROUX
                  Event Code: 5038
                  Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

                  Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
                  Record Number: 15334
                  Source Name: Microsoft-Windows-Security-Auditing
                  Time Written: 20090512093004.253355-000
                  Event Type: Échec de l'audit
                  User:

                  Computer Name: LEROUX
                  Event Code: 5038
                  Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

                  Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
                  Record Number: 15335
                  Source Name: Microsoft-Windows-Security-Auditing
                  Time Written: 20090512093004.393755-000
                  Event Type: Échec de l'audit
                  User:

                  Computer Name: LEROUX
                  Event Code: 5038
                  Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

                  Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
                  Record Number: 15336
                  Source Name: Microsoft-Windows-Security-Auditing
                  Time Written: 20090512093004.471755-000
                  Event Type: Échec de l'audit
                  User:

                  Computer Name: LEROUX
                  Event Code: 5038
                  Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

                  Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
                  Record Number: 15337
                  Source Name: Microsoft-Windows-Security-Auditing
                  Time Written: 20090512093004.549755-000
                  Event Type: Échec de l'audit
                  User:

                  Computer Name: LEROUX
                  Event Code: 5038
                  Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

                  Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
                  Record Number: 15338
                  Source Name: Microsoft-Windows-Security-Auditing
                  Time Written: 20090512093004.627755-000
                  Event Type: Échec de l'audit
                  User:

                  ======Environment variables======

                  "ComSpec"=%SystemRoot%\system32\cmd.exe
                  "FP_NO_HOST_CHECK"=NO
                  "OS"=Windows_NT
                  "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Microsoft SQL Server\90\Tools\binn\;C:\Program Files\QuickTime\QTSystem\
                  "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
                  "PROCESSOR_ARCHITECTURE"=x86
                  "TEMP"=%SystemRoot%\TEMP
                  "TMP"=%SystemRoot%\TEMP
                  "USERNAME"=SYSTEM
                  "windir"=%SystemRoot%
                  "PROCESSOR_LEVEL"=6
                  "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
                  "PROCESSOR_REVISION"=0f0d
                  "NUMBER_OF_PROCESSORS"=2
                  "TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
                  "DFSTRACINGON"=FALSE
                  "CLASSPATH"=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
                  "QTJAVA"=C:\Program Files\QuickTime\QTSystem\QTJava.zip

                  -----------------EOF-----------------
                  0
                  1. Re

                    As tu fixé les lignes ?
                    @+
                    0
                2. C bon j'ai fait ce que tu m'as dis.
                  Bein pour mon msn il se trouve, que je vois qu'il envoi des message, car se sont mes amis qui me le disent."c'est quoi le fichier que tu m'as envoye..."
                  alors que je n'ai rien envoye.
                  A part ça, tu as vu si j'avais un virus?
                  Mon probleme est il resolu?
                  en tout cas merci par avance c'est gentil
                  0
                  1. Re

                    Ton MSN envoie t'il encore des messages?

                    Ensuite :

                    1)Désinstalle Trojan Remover

                    2)Lance un scan avec Malwaresbytes;met le à jour avant;et poste moi le rapport à l'issue.
                    Supprime tout se qu'il trouve.

                    3)Installe Internet Explorer 8

                    4)Pour java utilises javaRa https://www.commentcamarche.net/faq/15645-supprimer-les-anciennes-versions-de-java-avec-javara

                    et un autre tutoriel javaRa http://www.libellules.ch/dotclear/index.php?post/2008/07/13/2689-javara

                    Décompresse le fichier sur le Bureau (Clic droit > Extraire tout).
                    * Double-cliques sur le répertoire JavaRa.
                    * Puis double-cliques sur le fichier JavaRa.exe (le exe peut ne pas s'afficher).
                    * Choisis Français puis cliques sur Select.
                    * Cliques sur Recherche de mises à jour.
                    * Sélectionne Mettre à jour via jucheck.exe puis clique sur Rechercher.
                    * Autorises le processus à se connecter s'il le demande, cliques sur Installer et suis les instructions d'installation qui prennent quelques minutes.
                    * L'installation est terminée, reviens à l'écran de JavaRa et cliques sur Effacer les anciennes versions.
                    * Cliques sur Oui pour confirmer. Laisses travailler et cliques ensuite sur OK, puis une deuxième fois sur OK.
                    * Un rapport va s'ouvrir. Postes-le dans ta prochaine réponse.
                    * Ferme l'application.

                    Note : le rapport se trouve aussi dans C:\ sous le nom JavaRa.log.

                    5)Pour vérifier les mises à jour logiciels à appliquer sur ton PC
                    https://www.flexera.com/products/operations/software-vulnerability-management.html
                    Divers liens te seront proposés pour les logiciels non à jour.

                    Ce n'est pas fini...

                    @+
                    0
                3. oui j'ai fixé les lignes que tu m'as dis de fixer.
                  0
                  1. lol, faut faire tout ça pour voir si je n'est pas de virus!!lol
                    0
                    1. Re

                      Non ;tout ceci pour mettre à jour ton PC.

                      PS: envoies tu encore des messages?

                      @+
                      0
                  2. a 1ere vu non
                    j'en envoi plus.
                    par contre je sais pas ou est trojan remover.
                    0
                    1. Re

                      Ici:C:\Program Files\Trojan Remover\

                      Tu désinstalles en cliquant sur ce fichier:unins000.exe

                      @+
                      0
                  3. et pour le scan de malweyre, je fais un scan minutieux ou rapide?
                    0
                    1. Re

                      Un scan complet;n'oublie pas la mise à jour avant.
                      @+
                      0
                  4. le scan malwayre est en marche, je n'ai pas trouve unistall pour trojan dans le dossier, je l'ai supprimer, et pour javara, malgres les liens que tu m'as donné je ne le trouve pas a telecharger.( il y a bien un onglet telecharger, mais cela m'amene sur une page en anglais).
                    0
                    1. concernant javara, je l'ai trouver mais impossible de faire la recherche via juchek, il ne cherche pas
                      0
                      1. Re

                        J'ai lu trop vite ;tu disposes de Java.
                        et avec mise à jour;donc pas de soucis de ce côté là.
                        Passe à la suite.
                        0
                    2. ok merci.j'ai lancé secunia....
                      0
                      1. bon il me reste windows update a faire, et attendre la fin de malwarebytes
                        0
                        1. Malwarebytes' Anti-Malware 1.44
                          Version de la base de données: 3510
                          Windows 6.0.6002 Service Pack 2
                          Internet Explorer 8.0.6001.18882

                          06/03/2010 13:41:08
                          mbam-log-2010-03-06 (13-41-08).txt

                          Type de recherche: Examen complet (C:\|D:\|)
                          Eléments examinés: 293956
                          Temps écoulé: 1 hour(s), 43 minute(s), 29 second(s)

                          Processus mémoire infecté(s): 0
                          Module(s) mémoire infecté(s): 0
                          Clé(s) du Registre infectée(s): 0
                          Valeur(s) du Registre infectée(s): 0
                          Elément(s) de données du Registre infecté(s): 0
                          Dossier(s) infecté(s): 0
                          Fichier(s) infecté(s): 0

                          Processus mémoire infecté(s):
                          (Aucun élément nuisible détecté)

                          Module(s) mémoire infecté(s):
                          (Aucun élément nuisible détecté)

                          Clé(s) du Registre infectée(s):
                          (Aucun élément nuisible détecté)

                          Valeur(s) du Registre infectée(s):
                          (Aucun élément nuisible détecté)

                          Elément(s) de données du Registre infecté(s):
                          (Aucun élément nuisible détecté)

                          Dossier(s) infecté(s):
                          (Aucun élément nuisible détecté)

                          Fichier(s) infecté(s):
                          (Aucun élément nuisible détecté)
                          0
                          • 1
                          • 2