Probleme avec malwreb - Page 2

Résolu
  1. retente le scan en ligne

    > Ouvre ce lien pour scanner ton PC avec un BitDefender en ligne (uniquement sous Internet Explorer) :

    http://www.bitdefender.fr/scan_fr/scan8/ie.html

    Utilisation :
    Cliquer sur "J'accepte" puis accepter également l'ActiveX bloqué par la barre anti-popup de Windows qui clignotera en haut et l'installer.
    Ensuite, cliquer sur "Cliquez ici pour scanner".
    Patienter jusqu'à la fin du scan qui peut durer assez longtemps...

    Copier/coller le rapport entier sur le forum.
    0
    1. je tai repondu mon ami
      0
  2. voila la première fois j ai scanner avec la mode nomal mon pc s est eteint apres 10 mn puis j ai recommencer avec la mode sans echec voici le rapport de bitdefender

    [General]
    App = "BitDefender Online Scanner v8"
    Date = 29:01:2009
    Time = 01:57:49
    Scan Path = "C:\Documents and Settings\benziane\Mes documents;C:\Documents and Settings\All Users\Documents;A:\;C:\;D:\;E:\;F:\;G:\;"

    [Engines Info]
    Virus Definitions = 1927245
    Engine build = "AVCORE v1.7 (build 8314.19) (i386) (Sep 29 2008 17:19:14)"
    Scan plugins = 16
    Archive plugins = 43
    Unpack plugins = 7
    E-mail plugins = 6
    System plugins = 4

    [Scan Statistics]
    Folders = 5383
    Files = 62070
    Archives = 1226
    Packed files = 4130
    Identified viruses = 1
    Infected files = 1
    Warnings = 0
    Suspect files = 0
    Disinfected files = 0
    Deleted files = 1
    Copied files = 0
    Moved files = 0
    Renamed files = 0
    I/O Errors = 8

    [Scan Settings]
    SecondAction = Delete
    FirstAction = Disinfect
    Heuristics = 1
    Enable Warnings = 1
    Exclude Ext =
    Extensions = exe;com;dll;ocx;scr;bin;dat;386;vxd;sys;wdm;cla;class;ovl;ole;hlp;doc;dot;xls;ppt;wbk;wiz;pot;ppa;xla;xlt;vbs;vbe;mdb;rtf;htm;hta;html;xml;xtp;php;asp;js;shs;chm;lnk;pif;prc;url;smm;pfd;msi;ini;csc;cmd;bas;
    Scan Emails = 1
    Scan Archives = 1
    Scan Packed = 1
    Scan Files = 1
    Scan Boot = 1
    Verify Memory = 0

    [Scan Results]
    Line00000001 = "D:\Programs\CrackDown.exe Infecté par: Backdoor.Bot.18029"
    Line00000000 = "D:\Programs\CrackDown.exe Supprimé"
    0
    1. relance MBAM
      0
      1. impossible cest le meme probleme, quant je scanne avec mbam apres deux minite mon pc s eteint je ne sais pas d'ou sa vient mon ami je t en prie dit moi comment faire je sais que je t etais demander plus excuse moi je ne sais pas comment faire.
        0
    2. tu as desactive toutes tes protections pendant le scan en ligne ?
      0
      1. ;)
        0
        1. j ai desactiver kasperky 2009 et la pare feu, ca pas marcher, cette foi ci il a mis 10 mn puis mon pc s est etint tout seul merci je fait koi maintenant
          0
      2. salut j ai fait un scanne avec malwareb en mode sans echec et voila le resultat

        Malwarebytes' Anti-Malware 1.33
        Version de la base de données: 1702
        Windows 5.1.2600 Service Pack 3

        29.01.2009 05:30:19
        mbam-log-2009-01-29 (05-30-19).txt

        Type de recherche: Examen complet (C:\|D:\|E:\|F:\|)
        Eléments examinés: 105372
        Temps écoulé: 1 hour(s), 7 minute(s), 31 second(s)

        Processus mémoire infecté(s): 0
        Module(s) mémoire infecté(s): 0
        Clé(s) du Registre infectée(s): 0
        Valeur(s) du Registre infectée(s): 0
        Elément(s) de données du Registre infecté(s): 0
        Dossier(s) infecté(s): 0
        Fichier(s) infecté(s): 2

        Processus mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Module(s) mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Clé(s) du Registre infectée(s):
        (Aucun élément nuisible détecté)

        Valeur(s) du Registre infectée(s):
        (Aucun élément nuisible détecté)

        Elément(s) de données du Registre infecté(s):
        (Aucun élément nuisible détecté)

        Dossier(s) infecté(s):
        (Aucun élément nuisible détecté)

        Fichier(s) infecté(s):
        C:\System Volume Information\_restore{C04DEC5B-597D-41C8-9592-7ABDDD782F57}\RP280\A0134295.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{C04DEC5B-597D-41C8-9592-7ABDDD782F57}\RP280\A0134296.exe (Adware.NetPumper) -> Quarantined and deleted successfully.
        0
        1. Salut l ami ,

          j ai vu tes mp (4) lol

          fais ceci :

          Télécharge ToolsCleaner sur ton bureau.
          -->
          http://pc-system.fr/
          http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner

          # Clique sur Recherche et laisse le scan agir ...
          # Clique sur Suppression pour finaliser.
          # Tu peux, si tu le souhaites, te servir des Options facultatives.
          # Clique sur Quitter pour obtenir le rapport.
          # Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

          ensuite :

          Rends toi sur ce site :

          https://www.virustotal.com/gui/

          Clique sur parcourir et cherche ce fichier : C:\WINDOWS\is-577BI.exe

          Clique sur Send File.

          Un rapport va s'élaborer ligne à ligne.

          Attends la fin. Il doit comprendre la taille du fichier envoyé.

          Sauvegarde le rapport avec le bloc-note.

          Copie le dans ta réponse.
          0
          1. [ Rapport ToolsCleaner version 2.3.0 (par A.Rothstein & dj QUIOU) ]

            -->- Recherche:

            C:\FindyKill.txt: trouvé !
            C:\_OtMoveIt: trouvé !
            C:\Rsit: trouvé !
            C:\Documents and Settings\benziane\Menu Démarrer\Programmes\FindyKill: trouvé !
            C:\Documents and Settings\benziane\Mes documents\Downloads\Programs\SmitFraudFix.exe: trouvé !
            C:\Documents and Settings\benziane\Mes documents\Downloads\Programs\OTMoveIt3.exe: trouvé !
            C:\Documents and Settings\benziane\Mes documents\Downloads\Programs\SmitFraudfix: trouvé !
            C:\Documents and Settings\benziane\Bureau\Rsit.exe: trouvé !
            C:\Program Files\FindyKill: trouvé !
            C:\Program Files\Trend Micro\hijackthis.log: trouvé !

            ---------------------------------
            -->- Suppression:

            C:\Documents and Settings\benziane\Mes documents\Downloads\Programs\SmitFraudFix.exe: supprimé !
            C:\FindyKill.txt: supprimé !
            C:\Documents and Settings\benziane\Mes documents\Downloads\Programs\OTMoveIt3.exe: supprimé !
            C:\Documents and Settings\benziane\Bureau\Rsit.exe: supprimé !
            C:\Program Files\Trend Micro\hijackthis.log: supprimé !
            C:\_OtMoveIt: supprimé !
            C:\Rsit: supprimé !
            C:\Documents and Settings\benziane\Menu Démarrer\Programmes\FindyKill: supprimé !
            C:\Documents and Settings\benziane\Mes documents\Downloads\Programs\SmitFraudfix: supprimé !
            C:\Program Files\FindyKill: supprimé !
            0
            1. MD5: 0e0e3be5577a529d4d5fb2e919e0d349
              First received: -
              Date 2009.01.09 17:38:04 (CET) [>19D]
              Résultats 0/37
              Permalink: analisis/569c586be808e551402f76b546efdb95
              0
              1. Télécharge combofix : http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                -> Double clique sur combofix.exe.
                -> Tape sur la touche 1 (Yes) pour démarrer le scan.
                -> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

                NOTE : Le rapport se trouve également ici : C:\Combofix.txt

                Avant d'utiliser ComboFix :

                -> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.

                -> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent géner fortement la procédure de recherche et de nettoyage de l'outil.

                Une fois fait, sur ton bureau double-clic sur Combofix.exe.

                - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

                /!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.

                - En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

                - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

                -> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

                -> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message
                0
                1. ComboFix 09-01-21.04 - benziane 2009-01-29 7:08:45.4 - [color=red][b]FAT32[/b][/color]x86
                  Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.447.149 [GMT 1:00]
                  Lancé depuis: c:\documents and settings\benziane\Bureau\ComboFix.exe
                  AV: Kaspersky Internet Security *On-access scanning disabled* (Updated)
                  FW: Kaspersky Internet Security *disabled*
                  * Un nouveau point de restauration a été créé

                  AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
                  .

                  (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                  .

                  c:\windows\system32\404Fix.exe
                  c:\windows\system32\Agent.OMZ.Fix.exe
                  c:\windows\system32\dumphive.exe
                  c:\windows\system32\IEDFix.C.exe
                  c:\windows\system32\IEDFix.exe
                  c:\windows\system32\o4Patch.exe
                  c:\windows\system32\Process.exe
                  c:\windows\system32\SrchSTS.exe
                  c:\windows\system32\tmp.reg
                  c:\windows\system32\VACFix.exe
                  c:\windows\system32\VCCLSID.exe
                  c:\windows\system32\WS2Fix.exe

                  .
                  ((((((((((((((((((((((((((((( Fichiers créés du 2008-12-28 au 2009-01-29 ))))))))))))))))))))))))))))))))))))
                  .

                  2009-01-29 00:35 . 2009-01-29 00:35 <REP> d-------- c:\program files\Ad-remover
                  2009-01-28 22:18 . 2009-01-28 22:18 <REP> d--hs---- C:\FOUND.001
                  2009-01-28 18:20 . 2009-01-28 18:20 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
                  2009-01-28 18:20 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
                  2009-01-28 18:20 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys
                  2009-01-28 18:10 . 2009-01-28 18:10 <REP> d-------- c:\program files\CCleaner
                  2009-01-28 17:30 . 2009-01-28 17:30 <REP> d--hs---- C:\FOUND.000
                  2009-01-28 13:12 . 2009-01-28 13:12 <REP> d-------- c:\documents and settings\benziane\IECompatCache
                  2009-01-28 03:43 . 2009-01-28 03:43 <REP> d--hs---- c:\documents and settings\benziane\IETldCache
                  2009-01-28 03:39 . 2009-01-28 03:39 <REP> d--h----- c:\windows\ie8
                  2009-01-27 15:50 . 2009-01-27 15:50 <REP> d-------- c:\program files\MacBoX_v.4
                  2009-01-22 16:39 . 2009-01-22 16:39 <REP> d-------- c:\documents and settings\benziane\Application Data\Bump Technologies, Inc
                  2009-01-20 13:43 . 2009-01-20 13:43 <REP> d-------- C:\temp
                  2009-01-20 03:15 . 2009-01-20 03:15 <REP> d-------- c:\program files\Fichiers communs\SWF Studio
                  2009-01-20 01:24 . 2009-01-20 01:24 <REP> d-------- c:\documents and settings\benziane\Application Data\vlc
                  2009-01-20 00:43 . 2009-01-20 00:43 673,792 --a------ c:\windows\is-577BI.exe
                  2009-01-20 00:43 . 2004-09-28 11:13 526,184 --a------ c:\windows\system32\XceedCry.dll
                  2009-01-20 00:43 . 2005-01-12 11:19 456,536 --a------ c:\windows\system32\XCEEDZIP.DLL
                  2009-01-20 00:43 . 2004-08-11 15:55 110,602 --a------ c:\windows\system32\xcdsfx32.bin
                  2009-01-20 00:43 . 2009-01-20 00:43 10,453 --a------ c:\windows\is-577BI.msg
                  2009-01-20 00:43 . 2009-01-20 00:43 554 --a------ c:\windows\is-577BI.lst
                  2009-01-17 17:24 . 2009-01-17 17:24 <REP> d-------- C:\cygwin
                  2009-01-15 02:22 . 2009-01-15 02:22 57,344 --------- c:\windows\system32\msrating.dll.mui
                  2009-01-15 02:21 . 2009-01-15 02:21 2,560 --------- c:\windows\system32\mshta.exe.mui
                  2009-01-15 02:19 . 2009-01-15 02:19 81,920 --------- c:\windows\system32\iedkcs32.dll.mui
                  2009-01-15 02:19 . 2009-01-15 02:19 4,096 --------- c:\windows\system32\ie4uinit.exe.mui
                  2009-01-15 02:04 . 2009-01-15 02:04 18,944 --------- c:\windows\system32\dllcache\corpol.dll
                  2009-01-15 00:16 . 2009-01-15 00:16 <REP> d-------- c:\documents and settings\benziane\WINDOWS
                  2009-01-15 00:16 . 1997-05-29 16:26 316,416 --a------ c:\windows\IsUn040c.exe
                  2009-01-15 00:13 . 2009-01-15 00:13 <REP> d-------- c:\documents and settings\benziane\Application Data\Yahoo!
                  2009-01-12 22:44 . 2009-01-12 22:44 170 --a------ C:\c0a80100.pac
                  2009-01-12 15:12 . 2009-01-12 15:12 <REP> d-------- c:\program files\Zone Labs
                  2009-01-12 14:51 . 2009-01-12 14:51 <REP> d-------- c:\windows\system32\ZoneLabs
                  2009-01-12 14:51 . 2008-07-09 09:05 1,086,952 --a------ c:\windows\system32\zpeng24.dll
                  2009-01-12 14:51 . 2009-01-12 17:20 352,854 --a------ c:\windows\system32\vsconfig.xml
                  2009-01-12 14:49 . 2009-01-12 14:49 <REP> d-------- c:\windows\Internet Logs
                  2009-01-10 22:25 . 2009-01-10 22:25 <REP> d-------- c:\windows\Lhsp
                  2009-01-10 22:24 . 2001-12-21 00:30 430,080 --a------ c:\windows\system32\MsRepl35.dll
                  2009-01-10 22:24 . 2001-12-21 00:30 252,176 --a------ c:\windows\system32\MSRD2x35.dll
                  2009-01-10 22:24 . 2001-12-21 00:30 123,664 --a------ c:\windows\system32\MSJInt35.dll
                  2009-01-10 22:24 . 2001-12-21 00:30 89,360 --a------ c:\windows\system32\VB5DB.dll
                  2009-01-10 22:24 . 2001-12-21 00:30 72,704 --a------ c:\windows\system32\ODBCTL32.dll
                  2009-01-10 22:24 . 2001-12-21 00:30 24,848 --a------ c:\windows\system32\MSJtEr35.dll
                  2009-01-10 22:23 . 2001-12-21 00:30 1,064,960 --a------ c:\windows\system32\MSJet35.dll
                  2009-01-10 22:23 . 2001-12-21 00:30 525,352 --a------ c:\windows\system32\DBGRID32.OCX
                  2009-01-10 22:23 . 2001-12-21 00:30 229,376 --a------ c:\windows\system32\FXIMG50G.OCX
                  2009-01-10 22:23 . 2001-12-21 00:30 195,584 --a------ c:\windows\system32\XVoice.dll
                  2009-01-10 22:23 . 2001-12-21 00:30 163,905 --a------ c:\windows\system32\AGENTCTL.DLL
                  2009-01-10 22:23 . 2001-12-21 00:30 121,856 --a------ c:\windows\system32\fxtls532.dll
                  2009-01-10 22:23 . 2001-12-21 00:30 46,080 --a------ c:\windows\system32\MCIWNDX.OCX
                  2009-01-10 22:23 . 2001-12-21 00:30 42,606 --a------ c:\windows\system32\PICN1813.ssm
                  2009-01-10 22:23 . 2001-12-21 00:30 34,382 --a------ c:\windows\system32\PICN1313.ssm
                  2009-01-10 22:23 . 2001-12-21 00:30 23,040 --a------ c:\windows\system32\PICN13.dll
                  2009-01-10 22:23 . 2001-12-21 00:30 14,031 --a------ c:\windows\system32\PICN8213.ssm
                  2009-01-09 14:36 . 2009-01-09 14:36 <REP> d-------- c:\program files\Babylon
                  2009-01-04 23:59 . 2009-01-04 23:59 <REP> d-------- c:\program files\TuneUp Utilities 2009
                  2009-01-04 23:59 . 2009-01-04 23:59 603,904 --a------ c:\windows\system32\TUProgSt.exe
                  2009-01-04 23:59 . 2009-01-04 23:59 360,192 --a------ c:\windows\system32\TuneUpDefragService.exe
                  2009-01-04 23:59 . 2008-12-11 13:31 27,904 --a------ c:\windows\system32\uxtuneup.dll
                  2009-01-04 01:22 . 2009-01-04 01:22 <REP> d-------- C:\fon bin
                  2009-01-03 12:03 . 2001-08-23 17:47 8,704 --a------ c:\windows\system32\kbdjpn.dll
                  2009-01-03 12:03 . 2001-08-23 17:47 8,704 --a------ c:\windows\system32\dllcache\kbdjpn.dll
                  2009-01-03 12:03 . 2001-08-23 17:47 8,192 --a------ c:\windows\system32\kbdkor.dll
                  2009-01-03 12:03 . 2001-08-23 17:47 8,192 --a------ c:\windows\system32\dllcache\kbdkor.dll
                  2009-01-03 12:03 . 2008-04-14 03:31 6,144 --a------ c:\windows\system32\kbd106.dll
                  2009-01-03 12:03 . 2001-08-17 22:55 6,144 --a------ c:\windows\system32\kbd101c.dll
                  2009-01-03 12:03 . 2001-08-17 22:55 6,144 --a------ c:\windows\system32\kbd101b.dll
                  2009-01-03 12:03 . 2008-04-14 03:31 6,144 --a------ c:\windows\system32\dllcache\kbd106.dll
                  2009-01-03 12:03 . 2001-08-17 22:55 6,144 --a------ c:\windows\system32\dllcache\kbd101c.dll
                  2009-01-03 12:03 . 2001-08-17 22:55 6,144 --a------ c:\windows\system32\dllcache\kbd101b.dll
                  2009-01-03 12:03 . 2001-08-17 22:55 5,632 --a------ c:\windows\system32\kbd103.dll
                  2009-01-03 12:03 . 2001-08-17 22:55 5,632 --a------ c:\windows\system32\dllcache\kbd103.dll
                  2009-01-02 20:58 . 2009-01-02 20:58 <REP> d-------- c:\documents and settings\LocalService\Bureau
                  2009-01-01 23:23 . 2009-01-01 23:23 <REP> d--hs---- c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
                  2008-12-29 20:05 . 2008-12-29 20:05 73 --a------ c:\windows\EurekaLog.ini

                  .
                  (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  2009-01-29 06:11 32 --sha-w c:\windows\system32\drivers\fidbox2.idx
                  2009-01-29 06:11 32 --sha-w c:\windows\system32\drivers\fidbox2.dat
                  2009-01-29 06:11 32 --sha-w c:\windows\system32\drivers\fidbox.idx
                  2009-01-29 06:11 32 --sha-w c:\windows\system32\drivers\fidbox.dat
                  2009-01-15 01:17 636,264 ----a-w c:\windows\system32\dllcache\iexplore.exe
                  2009-01-15 01:17 392,040 ----a-w c:\windows\system32\dllcache\iedkcs32.dll
                  2009-01-15 01:13 5,888,512 ----a-w c:\windows\system32\dllcache\mshtml.dll
                  2009-01-15 01:12 10,963,968 ----a-w c:\windows\system32\dllcache\ieframe.dll
                  2009-01-15 01:06 236,544 ----a-w c:\windows\system32\dllcache\webcheck.dll
                  2009-01-15 01:06 105,984 ----a-w c:\windows\system32\dllcache\url.dll
                  2009-01-15 01:06 1,182,720 ----a-w c:\windows\system32\dllcache\urlmon.dll
                  2009-01-15 01:05 911,872 ----a-w c:\windows\system32\wininet.dll
                  2009-01-15 01:05 911,872 ----a-w c:\windows\system32\dllcache\wininet.dll
                  2009-01-15 01:05 43,008 ----a-w c:\windows\system32\licmgr10.dll
                  2009-01-15 01:05 43,008 ----a-w c:\windows\system32\dllcache\licmgr10.dll
                  2009-01-15 01:05 193,536 ----a-w c:\windows\system32\dllcache\msrating.dll
                  2009-01-15 01:05 109,056 ----a-w c:\windows\system32\dllcache\occache.dll
                  2009-01-15 01:04 755,200 ----a-w c:\windows\system32\dllcache\VGX.dll
                  2009-01-15 01:04 25,600 ----a-w c:\windows\system32\dllcache\jsproxy.dll
                  2009-01-15 01:04 18,944 ----a-w c:\windows\system32\corpol.dll
                  2009-01-15 01:02 611,840 ----a-w c:\windows\system32\dllcache\mstime.dll
                  2009-01-15 01:02 593,920 ----a-w c:\windows\system32\dllcache\msfeeds.dll
                  2009-01-15 01:02 1,975,296 ----a-w c:\windows\system32\dllcache\iertutil.dll
                  2009-01-15 01:01 66,560 ----a-w c:\windows\system32\dllcache\mshtmled.dll
                  2009-01-15 01:01 59,904 ----a-w c:\windows\system32\dllcache\icardie.dll
                  2009-01-15 01:01 54,272 ----a-w c:\windows\system32\dllcache\msfeedsbs.dll
                  2009-01-15 01:01 46,592 ----a-w c:\windows\system32\dllcache\pngfilt.dll
                  2009-01-15 01:01 348,160 ----a-w c:\windows\system32\dllcache\dxtmsft.dll
                  2009-01-15 01:01 34,304 ----a-w c:\windows\system32\imgutil.dll
                  2009-01-15 01:01 34,304 ----a-w c:\windows\system32\dllcache\imgutil.dll
                  2009-01-15 01:01 216,064 ----a-w c:\windows\system32\dllcache\dxtrans.dll
                  2009-01-15 01:01 183,808 ----a-w c:\windows\system32\dllcache\iepeers.dll
                  2009-01-15 01:00 48,128 ----a-w c:\windows\system32\mshtmler.dll
                  2009-01-15 01:00 48,128 ----a-w c:\windows\system32\dllcache\mshtmler.dll
                  2009-01-15 01:00 45,568 ----a-w c:\windows\system32\mshta.exe
                  2009-01-15 01:00 45,568 ----a-w c:\windows\system32\dllcache\mshta.exe
                  2009-01-15 00:53 68,608 ----a-w c:\windows\system32\dllcache\hmmapi.dll
                  2009-01-15 00:50 156,160 ----a-w c:\windows\system32\msls31.dll
                  2009-01-15 00:50 156,160 ----a-w c:\windows\system32\dllcache\msls31.dll
                  2009-01-15 00:35 445,440 ----a-w c:\windows\system32\dllcache\ieapfltr.dll
                  2008-12-26 11:57 --------- d-----w c:\program files\Fichiers communs\xing shared
                  2008-12-26 11:56 499,712 ----a-w c:\windows\system32\msvcp71.dll
                  2008-12-26 11:56 348,160 ----a-w c:\windows\system32\msvcr71.dll
                  2008-12-23 16:59 --------- d-----w c:\documents and settings\benziane\Application Data\Simply Super Software
                  2008-12-23 16:59 --------- d-----w c:\documents and settings\All Users\Application Data\Simply Super Software
                  2008-12-22 19:56 --------- d-----w c:\program files\Microsoft Sync Framework
                  2008-12-22 19:55 --------- d-----w c:\program files\Windows Live SkyDrive
                  2008-12-22 19:55 --------- d-----w c:\program files\Microsoft
                  2008-12-22 19:39 --------- d-----w c:\program files\Fichiers communs\Windows Live
                  2008-12-16 13:54 96,976 ----a-w c:\windows\system32\drivers\klin.dat
                  2008-12-16 13:39 87,855 ----a-w c:\windows\system32\drivers\klick.dat
                  2008-12-16 13:39 --------- d-----w c:\program files\Kaspersky Lab
                  2008-12-16 13:38 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
                  2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
                  2008-12-11 10:57 333,952 ------w c:\windows\system32\dllcache\srv.sys
                  2008-12-02 23:01 410,984 ----a-w c:\windows\system32\deploytk.dll
                  2008-12-02 21:37 49,480 ----a-w c:\windows\system32\sirenacm.dll
                  2008-11-15 07:45 98,304 ----a-w c:\windows\system32\CmdLineExt.dll
                  2008-10-12 19:05 1,595 ----a-w c:\documents and settings\benziane\Application Data\SAS7_000.DAT
                  2008-09-09 20:57 251,392 ----a-w c:\program files\mozilla firefox\plugins\Copie de dap.dll
                  2008-08-28 08:57 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008082820080829\index.dat
                  .

                  ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  .
                  *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                  REGEDIT4

                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
                  "SpeedConnectStartUp"="e:\program files\CBS Software\SpeedConnect Internet Accelerator\SpeedConnectStartUp.exe" [2008-08-03 565760]
                  "IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2008-09-30 2606512]
                  "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2008-12-02 3882312]
                  "Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "tsnp325"="c:\windows\tsnp325.exe" [2007-04-21 270336]
                  "ISUSScheduler"="c:\program files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
                  "TrojanScanner"="c:\program files\Trojan Remover\Trjscan.exe" [2008-12-23 1230728]
                  "TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-12-26 185872]
                  "AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2008-07-29 206088]
                  "SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe]
                  "RTHDCPL"="RTHDCPL.EXE" [2006-12-19 c:\windows\RTHDCPL.exe]
                  "VTTimer"="VTTimer.exe" [2005-03-07 c:\windows\system32\VTTimer.exe]

                  c:\documents and settings\benziane\Menu D‚marrer\Programmes\D‚marrage\
                  No-IP DUC.lnk - e:\program files\No-IP\DUC20.exe [2008-07-20 1172992]

                  c:\documents and settings\benziane\Menu D‚marrer\Programmes\D‚marrage\
                  No-IP DUC.lnk - e:\program files\No-IP\DUC20.exe [2008-07-20 1172992]

                  c:\documents and settings\benziane\Menu D‚marrer\Programmes\D‚marrage\
                  No-IP DUC.lnk - e:\program files\No-IP\DUC20.exe [2008-07-20 1172992]

                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                  "msacm.l3codec"= l3codecp.acm

                  [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
                  "Yahoo! Pager"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
                  "MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" /background
                  "SpeedConnectStartUp"=e:\program files\CBS Software\SpeedConnect Internet Accelerator\SpeedConnectStartUp.exe -run
                  "CTFMON.EXE"=c:\windows\system32\ctfmon.exe
                  "DownloadAccelerator"="c:\program files\DAP\DAP.EXE" /STARTUP
                  "BitComet"="c:\program files\BitComet\BitComet.exe" /tray
                  "swg"=c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
                  "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                  "TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                  "FixCamera"=c:\windows\FixCamera.exe
                  "snp325"=c:\windows\vsnp325.exe
                  "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
                  "SpeedBitVideoAccelerator"="c:\program files\SpeedBit Video Accelerator\VideoAccelerator.exe"
                  "Athan"=c:\program files\Athan\Athan.exe
                  "Babylon Client"=c:\program files\Babylon\Babylon-Pro\Babylon.exe -AutoStart

                  [HKEY_LOCAL_MACHINE\software\microsoft\security center]
                  "SerialNumber"="A109A-K13-3ZXD-BAP5-TE"

                  [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
                  "DisableMonitoring"=dword:00000001

                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                  "%windir%\\system32\\sessmgr.exe"=
                  "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                  "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
                  "c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
                  "c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
                  "d:\\Program Files\\eMule\\emule.exe"=
                  "c:\\Program Files\\DAP\\DAP.EXE"=
                  "c:\\Program Files\\SpeedBit Video Accelerator\\VideoAccelerator.exe"=
                  "c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
                  "c:\\Program Files\\BitComet\\BitComet.exe"=
                  "c:\\Documents and Settings\\BENZIANE\\Mes documents\\reda\\TeamViewer3\\TeamViewer3\\TEAMVIEWER.exe"=
                  "c:\\WINDOWS\\system32\\dpvsetup.exe"=
                  "c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\french\\setup.exe"=
                  "c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.325\\French\\setup.exe"=
                  "c:\\Program Files\\Real\\RealPlayer\\RealPlay.exe"=
                  "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
                  "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                  "c:\\Program Files\\MacBoX_v.4\\GboxSC.exe"=
                  "c:\\Program Files\\TuneUp Utilities 2009\\Integrator.exe"=
                  "c:\\WINDOWS\\amcap.exe"=
                  "c:\\Program Files\\TuneUp Utilities 2009\\UpdateWizard.exe"=
                  "d:\\Program Files\\uTorrent\\uTorrent.exe"=
                  "c:\\Program Files\\cardshare\\GboxWell\\GboxWell v 2.00 .exe"=
                  "c:\\cygwin\\bin\\ioperm.exe"=
                  "c:\\Program Files\\MacBoX_v.4\\MacBoX_v.4.exe"=
                  "c:\\Program Files\\MacBoX_v.4\\gboxx86.exe"=
                  "c:\\Program Files\\MacBoX_v.4\\OpenCom.exe"=
                  "e:\\Program Files\\No-IP\\DUC20.exe"=
                  "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
                  "c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=

                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
                  "7561:TCP"= 7561:TCP:eMule
                  "7571:UDP"= 7571:UDP:eMule
                  "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
                  "24980:TCP"= 24980:TCP:BitComet 24980 TCP
                  "24980:UDP"= 24980:UDP:BitComet 24980 UDP
                  "23079:TCP"= 23079:TCP:BitComet 23079 TCP
                  "23079:UDP"= 23079:UDP:BitComet 23079 UDP
                  "1000:TCP"= 1000:TCP:utorrent
                  "1000:UDP"= 1000:UDP:utorrent
                  "5656:TCP"= 5656:TCP:MacBoX_v.4.exe
                  "5656:UDP"= 5656:UDP:MacBoX_.v4.exe
                  "80:TCP"= 80:TCP:HTTP

                  R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
                  R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\drivers\xfilt.sys [2008-08-02 17920]
                  R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [2008-03-13 26640]
                  R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2008-04-30 24592]
                  R4 ioperm;ioperm support for Cygwin driver;f:\compresse\gbox control\gbox control\ioperm.sys [2009-01-12 12800]
                  R4 sbbotdi;sbbotdi;c:\progra~1\SPEEDB~1\sbbotdi.sys [2008-09-09 35584]
                  R4 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2008-12-04 226640]
                  R4 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [2009-01-04 603904]
                  R4 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm --> c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm [?]
                  S3 maconfservice;Ma-Config Service;"d:\program files\ma-config.com\maconfservice.exe" --> d:\program files\ma-config.com\maconfservice.exe [?]
                  S3 SNP325;USB PC Camera (SNPSTD325);c:\windows\system32\drivers\snp325.sys [2008-08-02 10386432]

                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
                  UxTuneUp

                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
                  "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
                  .
                  Contenu du dossier 'Tâches planifiées'

                  2009-01-27 c:\windows\Tasks\AppleSoftwareUpdate.job
                  - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

                  2009-01-29 c:\windows\Tasks\User_Feed_Synchronization-{1C799B26-C1BD-4EB7-9AE7-87A3DAD61106}.job
                  - c:\windows\system32\msfeedssync.exe [2009-01-15 02:01]

                  2009-01-29 c:\windows\Tasks\Maintenance en 1 clic.job
                  - c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-12-12 15:04]
                  .
                  .
                  ------- Examen supplémentaire -------
                  .
                  mWindow Title =
                  IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
                  IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
                  IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
                  IE: &download with &dap - c:\program files\DAP\dapextie.htm
                  IE: download &all with dap - c:\program files\DAP\dapextie2.htm
                  IE: télécharger avec idm - c:\program files\Internet Download Manager\IEExt.htm
                  IE: télécharger le contenu de video flv avec idm - c:\program files\Internet Download Manager\IEGetVL.htm
                  IE: télécharger tous les liens avec idm - c:\program files\Internet Download Manager\IEGetAll.htm
                  LSP: c:\windows\system32\idmmbc.dll
                  Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
                  Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
                  DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                  FF - ProfilePath - c:\documents and settings\benziane\Application Data\Mozilla\Firefox\Profiles\edag7jrs.default\
                  FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1721964&SearchSource=3&q=
                  FF - prefs.js: browser.search.selectedEngine - Smartorrent Customized Web Search
                  FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
                  FF - prefs.js: keyword.URL - hxxp://search.speedbit.com/searchresults.asp?src=default&q=
                  FF - prefs.js: network.proxy.http_port - 8580
                  FF - prefs.js: network.proxy.type - 2
                  FF - component: c:\documents and settings\benziane\Application Data\IDM\idmmzcc2\components\idmmzcc.dll
                  FF - component: c:\documents and settings\benziane\Application Data\Mozilla\Firefox\Profiles\edag7jrs.default\extensions\{2f3a94fd-c89e-41c4-bbd6-18b11705e7f3}\components\FFAlert.dll
                  FF - component: c:\documents and settings\benziane\Application Data\Mozilla\Firefox\Profiles\edag7jrs.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
                  FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
                  FF - plugin: c:\documents and settings\benziane\Application Data\Mozilla\Firefox\Profiles\edag7jrs.default\extensions\{bb628310-0ab7-11db-9cd8-0800200c9a66}\plugins\nphardwaredetection.dll
                  FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
                  FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAskSBr.dll

                  ---- PARAMETRES FIREFOX ----
                  FF - user.js: network.http.max-connections-per-server - 8
                  FF - user.js: network.http.max-persistent-connections-per-server - 4
                  FF - user.js: content.max.tokenizing.time - 1800000
                  FF - user.js: content.notify.interval - 600000
                  FF - user.js: nglayout.initialpaint.delay - 600
                  FF - user.js: content.switch.threshold - 600000
                  .

                  **************************************************************************

                  catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                  Rootkit scan 2009-01-29 07:12:24
                  Windows 5.1.2600 Service Pack 3 FAT NTAPI

                  Recherche de processus cachés ...

                  Recherche d'éléments en démarrage automatique cachés ...

                  Recherche de fichiers cachés ...

                  Scan terminé avec succès
                  Fichiers cachés: 0

                  **************************************************************************
                  .
                  --------------------- CLES DE REGISTRE BLOQUEES ---------------------

                  [HKEY_USERS\S-1-5-21-448539723-1450960922-839522115-1003\Software\Microsoft\SystemCertificates\AddressBook*]
                  @Allowed: (Read) (RestrictedCode)
                  @Allowed: (Read) (RestrictedCode)

                  [HKEY_USERS\S-1-5-21-448539723-1450960922-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{3A40CEFA-FE67-EB93-6B3C-698C71F07F7A}*]
                  @Allowed: (Read) (RestrictedCode)
                  @Allowed: (Read) (RestrictedCode)
                  "oahbckcapbcdpofhaiomldgbfocbeb"=hex:6b,61,61,6b,68,6a,6d,67,67,68,61,63,66,68,
                  6b,62,61,67,6c,6d,6a,6c,00,00
                  "nafciobkipafkkfaimkopkifbgnj"=hex:6b,61,61,6b,68,6a,6d,67,67,68,61,63,66,68,
                  6b,62,61,67,6c,6d,6a,6c,00,00

                  [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{341d09c2-0b15-47a1-9070-d18374665969}]
                  @Denied: (Full) (Everyone)
                  "Model"=dword:000000f3
                  "Therad"=dword:0000001e
                  "MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
                  38,95,44,85,b1,12,f9,90,dd,23,a1,49,8c,bf,1a,9d,fe,41,71,cb,3f,46,a4,7c,ab,\

                  [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
                  @Denied: (Full) (Everyone)
                  "scansk"=hex(0):40,b6,8a,dd,c2,ac,ae,de,f1,60,6c,e6,a6,9d,a6,fd,04,51,76,9d,83,
                  00,84,c7,23,d4,fb,96,30,1d,2d,d1,99,c9,aa,75,13,5a,27,7c,00,00,00,00,00,00,\

                  [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6D2F20D5-13F7-9358-DFE4-538C732A13EE}\InProcServer32*]
                  "janggnodopmgglipncgd"=hex:6a,61,6c,66,6f,62,66,64,65,69,6e,63,69,65,66,6c,64,
                  6a,61,67,00,f9
                  "iangekmceocmambkho"=hex:6b,61,6c,66,70,63,6e,70,6b,6c,6b,62,6e,65,69,6c,6a,6e,
                  64,62,6e,6c,00,00

                  [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\•€|ÿÿÿÿ"•€|þ»Ñw*]
                  "C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
                  .
                  ------------------------ Autres processus actifs ------------------------
                  .
                  c:\program files\JAVA\JRE6\BIN\JQS.EXE
                  c:\program files\SPEEDBIT VIDEO ACCELERATOR\VIDEOACCELERATORSERVICE.EXE
                  c:\program files\SPEEDBIT VIDEO ACCELERATOR\VIDEOACCELERATORENGINE.EXE
                  c:\windows\system32\wscntfy.exe
                  c:\program files\Yahoo!\Messenger\ymsgr_tray.exe
                  c:\program files\Internet Download Manager\IEMonitor.exe
                  .
                  **************************************************************************
                  .
                  Heure de fin: 2009-01-29 7:15:16 - La machine a redémarré
                  ComboFix-quarantined-files.txt 2009-01-29 06:15:12

                  Avant-CF: 8'864'317'440 octets libres
                  Après-CF: 9,027,895,296 octets libres

                  375 --- E O F --- 2009-01-28 16:23:02
                  0
              2. ok

                Rends toi sur ce site :

                https://www.virustotal.com/gui/

                Clique sur parcourir et cherche ce fichier : C:\c0a80100.pac

                Clique sur Send File.

                Un rapport va s'élaborer ligne à ligne.

                Attends la fin. Il doit comprendre la taille du fichier envoyé.

                Sauvegarde le rapport avec le bloc-note.

                Copie le dans ta réponse.
                0
                1. Le fichier a déjà été analysé:
                  MD5: 7f85714b411db4c69b6f6d44edb45951
                  First received: -
                  Date 2009.01.29 07:25:09 (CET) [<1D]
                  Résultats 0/39
                  Permalink: analisis/73eab3c00b3b41c6aac04241ea2edf52
                  0
              3. ---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :
                http://oldtimer.geekstogo.com/OTMoveIt3.exe

                ---> Double-clique sur OTMoveIt3.exe afin de le lancer.

                ---> Copie (Ctrl+C) le texte suivant ci-dessous :

                :processes
                explorer.exe

                :files
                C:\c0a80100.pac

                :commands
                [emptytemp]
                [start explorer]


                ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

                ---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

                Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
                Accepte en cliquant sur YES.

                ---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
                Le nom du rapport correspond au moment de sa création : date_heure.log
                0
                1. ========== PROCESSES ==========
                  Process explorer.exe killed successfully.
                  ========== FILES ==========
                  C:\c0a80100.pac moved successfully.
                  ========== COMMANDS ==========
                  File delete failed. C:\DOCUME~1\benziane\LOCALS~1\Temp\~DF1E73.tmp scheduled to be deleted on reboot.
                  File delete failed. C:\DOCUME~1\benziane\LOCALS~1\Temp\~DF1E85.tmp scheduled to be deleted on reboot.
                  File delete failed. C:\DOCUME~1\benziane\LOCALS~1\Temp\~DF202E.tmp scheduled to be deleted on reboot.
                  File delete failed. C:\DOCUME~1\benziane\LOCALS~1\Temp\~DF2045.tmp scheduled to be deleted on reboot.
                  File delete failed. C:\DOCUME~1\benziane\LOCALS~1\Temp\~DF1619.tmp scheduled to be deleted on reboot.
                  File delete failed. C:\DOCUME~1\benziane\LOCALS~1\Temp\~DF162B.tmp scheduled to be deleted on reboot.
                  User's Temp folder emptied.
                  User's Temporary Internet Files folder emptied.
                  User's Internet Explorer cache folder emptied.
                  Local Service Temp folder emptied.
                  File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
                  Local Service Temporary Internet Files folder emptied.
                  File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_218.dat scheduled to be deleted on reboot.
                  Windows Temp folder emptied.
                  Java cache emptied.
                  FireFox cache emptied.
                  Temp folders emptied.
                  Explorer started successfully

                  OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01292009_073538

                  Files moved on Reboot...
                  File C:\DOCUME~1\benziane\LOCALS~1\Temp\~DF1E73.tmp not found!
                  File C:\DOCUME~1\benziane\LOCALS~1\Temp\~DF1E85.tmp not found!
                  File C:\DOCUME~1\benziane\LOCALS~1\Temp\~DF202E.tmp not found!
                  File C:\DOCUME~1\benziane\LOCALS~1\Temp\~DF2045.tmp not found!
                  File C:\DOCUME~1\benziane\LOCALS~1\Temp\~DF1619.tmp not found!
                  File C:\DOCUME~1\benziane\LOCALS~1\Temp\~DF162B.tmp not found!
                  C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat moved successfully.
                  C:\WINDOWS\temp\Perflib_Perfdata_218.dat moved successfully.
                  0
              4. ok

                je vais bouger l amis , alors je verrais tes réponses ce soir

                en attendant :

                repasse toolcleaner :

                Télécharge ToolsCleaner sur ton bureau.
                -->
                http://pc-system.fr/
                http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner

                # Clique sur Recherche et laisse le scan agir ...
                # Clique sur Suppression pour finaliser.
                # Tu peux, si tu le souhaites, te servir des Options facultatives.
                # Clique sur Quitter pour obtenir le rapport.
                # Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

                ensuite désinstal malewarebyte : panneau de configurationn \ ajout ete suppression \ malewarebyte

                et réinstal le : malwarebytes
                https://www.malwarebytes.com/

                puis refais le scan rapide et dis moi

                @+
                0
                1. [ Rapport ToolsCleaner version 2.3.0 (par A.Rothstein & dj QUIOU) ]

                  -->- Recherche:

                  C:\Combofix.txt: trouvé !
                  C:\Qoobox: trouvé !
                  C:\_OtMoveIt: trouvé !
                  C:\Documents and Settings\benziane\Bureau\ComboFix.exe: trouvé !
                  C:\Documents and Settings\benziane\Bureau\OTMoveIt3.exe: trouvé !

                  ---------------------------------
                  -->- Suppression:

                  C:\Documents and Settings\benziane\Bureau\ComboFix.exe: ERREUR DE SUPPRESSION !!
                  C:\Combofix.txt: supprimé !
                  C:\Documents and Settings\benziane\Bureau\OTMoveIt3.exe: supprimé !
                  C:\Qoobox: supprimé !
                  C:\_OtMoveIt: supprimé !
                  0
              5. j ai reinstalle le malwareb et ca marche pas, mon pc s 'eteint tout seul quant il scanne malgre que j ai desactiver kasperky 2009 d ou vient le probleme mon ami je suis dans le neant
                0
                1. bonjour en attendant le retour de chiquitine :

                  Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

                  -> http://images.malwareremoval.com/random/RSIT.exe

                  ! Déconnecte toi et ferme toutes tes applications en cours !

                  Double-clique sur " RSIT.exe " pour le lancer .

                  -> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

                  * Devant l'option "List files/folders created ..." , tu choisis : 2 months

                  * clique ensuite sur " Continue " pour lancer l'analyse ...

                  -> laisse faire le scan et ne touche pas au PC ...

                  Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

                  Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

                  Important : poste un rapport, puis l'autre dans la réponse suivante
                  Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum

                  ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )

                  0
                  Précédent
                  • 1
                  • 2