Plantages répétitifs (écran bleu)

Bonjour,
salut à tous, je viens vers vous car je suis dépité.
Je viens d'acquérir un nouveau pc et je l'ai tout installé. tout allait bien lorsque des écrans bleu à répétition ce sont mis à apparaitre lorsque je lance le programme M4ng.
cela me fait aussi sauter mes codecs audio qui ne me permettent plus d'entendre le son via mon écran. Il faut que je les désinstallent pour ensuite les réinstaller. Je ne sais plus quoi faire. Un trojan, un virus ? bitedefender en ligne ne trouve rien.
voici l'erreur répétée dans le journal
Le filtre d’événement avec la requête « SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99 » n’a pas pu être réactivé dans l’espace de noms « //./root/CIMV2 » à cause de l’erreur 0x80041003. Les événements ne peuvent pas être délivrés à travers ce filtre tant que le problème ne sera pas corrigé.

apparemment j'ai aussi un problème avec ceci %windir%\system32\hnetcfg.dll

enfin tout va bien quoi...

ci joint un rapport Hijiack

je précise que j'ai fait un scan avec malwarebytes, ccleaner et regcleaner

merci beaucoup pour votre aide

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:33:07, on 18/02/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\ASUS\EPU-4 Engine\FourEngine.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Winamp Remote\bin\OrbTray.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Mio Technology\MioSync\mioSync.exe
C:\Program Files\D-Link\D-Link DWA-547 Wireless N Desktop Adapter\wirelesscm.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\mmc.exe
C:\Windows\system32\conime.exe
C:\Program Files\DVD Region Killer\RegKillTray.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [ElbyCheckAnyDVD] "C:\Program Files\SlySoft\AnyDVD\ElbyCheck.exe" /L AnyDVD
O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\Slysoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [RegKillElbyCheck] "C:\Program Files\DVD Region Killer\ElbyCheck.exe" /L RegKill
O4 - HKLM\..\Run: [RegKillTray] "C:\Program Files\DVD Region Killer\RegKillTray.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] c:\program files\registrybooster\StartRegistryBooster.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Global Startup: MioSync.lnk = C:\Program Files\Mio Technology\MioSync\mioSync.exe
O4 - Global Startup: Wireless Connection Manager.lnk = C:\Program Files\D-Link\D-Link DWA-547 Wireless N Desktop Adapter\wirelesscm.exe
O8 - Extra context menu item: &Traduire à partir de l'anglais - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Pages liées - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Pages similaires - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Recherche &Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O13 - Gopher Prefix:
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\Windows\system32\guard32.dll,avgrsstx.dll
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: Jumpstart Wifi Protected Setup (jswpsapi) - Atheros Communications, Inc. - C:\Program Files\D-Link\D-Link DWA-547 Wireless N Desktop Adapter\jswpsapi.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe

--
End of file - 7280 bytes
Configuration: Windows Vista
Firefox 3.0.6

26 réponses

Résumé de la discussion

Des écrans bleus répétés et une perte de son via l'écran apparaissent après l'installation sur un nouveau PC lors du lancement du programme M4ng, suscitant des doutes sur une infection. Plusieurs pistes autour des outils de sécurité sont discutées: Malwarebytes, CCleaner et HijackThis, avec des conseils comme la désactivation du contrôle de compte utilisateur pour faciliter la désinfection et l'emploi de ComboFix. Des retours indiquent que l'audio peut réapparaître après certaines opérations, des détails sur des disfonctionnements HDMI et des observations selon lesquelles le problème pourrait ne pas être un virus. En complément, les échanges suggèrent de sauvegarder les données sur un autre disque et d’utiliser RSIT pour obtenir des logs, afin d’orienter les mesures correctives sans perte irréversible.

Bobot (l’IA à votre service)
  1. Tu as bien installé tous les driver ? Si oui, essaye de reinstaller Windows .
    0
    1. c'est ce que j'espérais éviter...
      il faut que je sauvegarde mes données de C vers D donc, car sinon sur C tout sera effacer je crois ?
      0
  2. Euh non, pendant l'installation de Windows, tous sera suprimé donc je te conseil d'enregistré sur un disque dur externe .
    0
    1. Contributeur sécurité
      Salut,

      - Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.

      - Double-clique sur RSIT.exe afin de lancer le programme.

      - Clique sur Continue à l'écran Disclaimer.

      - Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

      - Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).

      Note : Les rapports sont sauvegardés dans le dossier C:\rsit.
      0
      1. alors je m'execute (merci de votre aide)
        Logfile of random's system information tool 1.05 (written by random/random)
        Run by Seb at 2009-02-18 01:10:38
        Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
        System drive C: has 543 GB (89%) free of 610 GB
        Total RAM: 3292 MB (55% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 01:10:47, on 18/02/2009
        Platform: Windows Vista SP1 (WinNT 6.00.1905)
        MSIE: Internet Explorer v7.00 (7.00.6001.18000)
        Boot mode: Normal

        Running processes:
        C:\Windows\system32\taskeng.exe
        C:\Windows\system32\Dwm.exe
        C:\Program Files\ASUS\EPU-4 Engine\FourEngine.exe
        C:\Windows\Explorer.EXE
        C:\Program Files\Windows Defender\MSASCui.exe
        C:\Program Files\Winamp\winampa.exe
        C:\Program Files\AVG\AVG8\avgtray.exe
        C:\Windows\System32\igfxtray.exe
        C:\Windows\System32\hkcmd.exe
        C:\Windows\System32\igfxpers.exe
        C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
        C:\Windows\RtHDVCpl.exe
        C:\Windows\system32\igfxsrvc.exe
        C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
        C:\Program Files\Windows Sidebar\sidebar.exe
        C:\Program Files\Winamp Remote\bin\OrbTray.exe
        C:\Windows\ehome\ehtray.exe
        C:\Program Files\Mio Technology\MioSync\mioSync.exe
        C:\Program Files\D-Link\D-Link DWA-547 Wireless N Desktop Adapter\wirelesscm.exe
        C:\Windows\system32\wbem\unsecapp.exe
        C:\Windows\ehome\ehmsas.exe
        C:\Windows\system32\mmc.exe
        C:\Windows\system32\conime.exe
        C:\Program Files\DVD Region Killer\RegKillTray.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
        C:\Windows\system32\NOTEPAD.EXE
        C:\Windows\system32\SearchFilterHost.exe
        C:\Users\Seb\Downloads\RSIT.exe
        C:\Program Files\Trend Micro\HijackThis\Seb.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
        O1 - Hosts: ::1 localhost
        O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
        O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
        O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
        O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
        O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
        O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
        O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
        O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
        O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
        O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
        O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
        O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
        O4 - HKLM\..\Run: [ElbyCheckAnyDVD] "C:\Program Files\SlySoft\AnyDVD\ElbyCheck.exe" /L AnyDVD
        O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\Slysoft\AnyDVD\AnyDVD.exe
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [RegKillElbyCheck] "C:\Program Files\DVD Region Killer\ElbyCheck.exe" /L RegKill
        O4 - HKLM\..\Run: [RegKillTray] "C:\Program Files\DVD Region Killer\RegKillTray.exe"
        O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
        O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
        O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
        O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
        O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
        O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] c:\program files\registrybooster\StartRegistryBooster.exe
        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
        O4 - Global Startup: MioSync.lnk = C:\Program Files\Mio Technology\MioSync\mioSync.exe
        O4 - Global Startup: Wireless Connection Manager.lnk = C:\Program Files\D-Link\D-Link DWA-547 Wireless N Desktop Adapter\wirelesscm.exe
        O8 - Extra context menu item: &Traduire à partir de l'anglais - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
        O8 - Extra context menu item: Pages liées - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
        O8 - Extra context menu item: Pages similaires - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
        O8 - Extra context menu item: Recherche &Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
        O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
        O13 - Gopher Prefix:
        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
        O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
        O20 - AppInit_DLLs: C:\Windows\system32\guard32.dll,avgrsstx.dll
        O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
        O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
        O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
        O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
        O23 - Service: Jumpstart Wifi Protected Setup (jswpsapi) - Atheros Communications, Inc. - C:\Program Files\D-Link\D-Link DWA-547 Wireless N Desktop Adapter\jswpsapi.exe
        O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
        0
        1. Je crois que Kevin est mieux renseigné sur se truc que moi ;-) alors si tu veus pas réinstaller XP, uilise sa technique mais si tu veus tous comme avant alors reinstalle XP.
          0
          1. merci, mais avant la solution radicale je vais essayer de comprendre ce qui a foiré. Le programme qui me fait planté, M4ng a fonctionné nickel le 15/02. je ne sais pas ce que j'ai foutu ensuite mais tout c'est mis à partir en sucette. le 16/02 au soir, plus de son, et près en avant les écrans bleu...
            j'ai désinstallé les codecs vidéo et tout, puis réinstallé que l'essentiel. je pige pas
            0
            1. OK avant, telecharge anticrash XP et installe le, tu verras, peut-etre que ça va t'aider ;-) !
              0
              1. Contributeur sécurité
                Re

                Tu es bien infecter...

                Fais ceci:

                ▶ Télécharge Combofix de sUBs

                ▶ et enregistre le sur le Bureau.

                ▶ désactive tes protections et ferme toutes tes applications(antivirus, parefeu, garde en temps réel de l'antispyware)

                Voici le tutoriel officiel de Bleeping Computer pour savoir l utiliser :

                https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

                ▶ Je te conseille d'installer la console de récupération !!
                0
                1. impossible de l'installer, il me met some files are corrupted try to downloada fresh copy...
                  j'ai essayé en mode sans echec mais rien a faire
                  0
                  1. Contributeur sécurité
                    fais ceci avant la manip 9

                    /!\IMPORTANT/!\
                    Désactive l'UAC (User Account Control ou Contrôle de Compte Utilisateur) le temps de la désinfection,tu le réactiveras après ta désinfection:
                    • Va dans Panneau de Configuration puis Comptes d'Utilisateurs.
                    • Clique sur Activer ou désactiver le contrôle des comptes utilisateurs.
                    • Décoche la case Utiliser le contrôle des comptes utilisateurs pour vous aider à protéger votre ordinateur.
                    • Clique sur OK pour enregistrer la modification et redémarre ton PC lorsque cela t'est demandé.

                    aide en cas de problèmes
                    0
                    1. Contributeur sécurité
                      Hello,comme d'hab j'oublie l'UAC :/

                      Merci chimay8
                      0
                      1. salut, ça je l'avais déjà fait hier en fait car vu sur un des topics ici. mais rien y fait...
                        0
                        1. Contributeur sécurité
                          Je vais te passer un autre lien...
                          0
                          1. Contributeur sécurité
                            Télécharge ICI
                            0
                            1. merci, j'ai réussi, voici le rapport complet. Ya t'il autre chose que je puisse faire ? cela pourrait il provenir de ANYDVD que j'ai installé avant les probèmes ?

                              ComboFix 09-02-17.02 - Seb 2009-02-18 16:22:05.1 - NTFSx86
                              Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.3292.2107 [GMT 1:00]
                              Lancé depuis: c:\users\Seb\Desktop\ComboFix.exe
                              FW: COMODO Firewall *enabled*
                              * Un nouveau point de restauration a été créé
                              .

                              (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                              .

                              c:\windows\system32\pthreadGC2.dll

                              .
                              ((((((((((((((((((((((((((((( Fichiers créés du 2009-01-18 au 2009-02-18 ))))))))))))))))))))))))))))))))))))
                              .

                              2009-02-18 01:10 . 2009-02-18 01:10 <REP> d-------- C:\rsit
                              2009-02-18 00:32 . 2009-02-18 00:32 <REP> d-------- c:\program files\Trend Micro
                              2009-02-18 00:30 . 2009-02-18 00:30 <REP> d-------- c:\users\Seb\AppData\Roaming\Uniblue
                              2009-02-18 00:22 . 2009-02-18 00:22 <REP> d-------- c:\users\Seb\AppData\Roaming\Malwarebytes
                              2009-02-18 00:22 . 2009-02-18 00:22 <REP> d-------- c:\users\All Users\Malwarebytes
                              2009-02-18 00:22 . 2009-02-18 00:22 <REP> d-------- c:\programdata\Malwarebytes
                              2009-02-18 00:22 . 2009-02-18 00:22 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
                              2009-02-18 00:22 . 2009-02-11 10:19 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
                              2009-02-18 00:22 . 2009-02-11 10:19 15,504 --a------ c:\windows\System32\drivers\mbam.sys
                              2009-02-17 19:48 . 2009-02-17 19:48 <REP> d-------- c:\program files\DVD Region Killer
                              2009-02-17 19:42 . 2009-02-17 19:42 <REP> d-------- c:\program files\DVD Decrypter
                              2009-02-17 19:08 . 2009-02-17 19:22 <REP> d-------- c:\program files\everest
                              2009-02-17 18:55 . 2009-02-17 18:55 21,764 --a------ c:\windows\System32\CoreAAC-uninstall.exe
                              2009-02-17 18:54 . 2009-02-17 18:54 <REP> d-------- c:\program files\AC3Filter
                              2009-02-17 18:54 . 2008-07-09 09:05 421,888 --a------ c:\windows\System32\ac3filter.acm
                              2009-02-17 18:54 . 2009-02-17 18:54 37,270 --a------ c:\windows\System32\OggDSUninst.exe
                              2009-02-17 18:53 . 2009-02-17 18:53 <REP> d-------- c:\program files\Haali
                              2009-02-17 18:53 . 2009-02-17 18:53 <REP> d-------- c:\program files\ffdshow
                              2009-02-17 18:53 . 2008-12-17 19:22 57,344 --a------ c:\windows\System32\ff_vfw.dll
                              2009-02-17 18:52 . 2009-02-17 18:52 <REP> d-------- c:\program files\Xvid
                              2009-02-17 18:52 . 2009-02-17 18:52 <REP> d-------- c:\program files\x264
                              2009-02-17 18:52 . 2009-01-01 22:28 819,200 --a------ c:\windows\System32\xvidcore.dll
                              2009-02-17 18:52 . 2008-12-03 22:11 180,224 --a------ c:\windows\System32\xvidvfw.dll
                              2009-02-17 18:52 . 2008-12-13 20:01 77,824 --a------ c:\windows\System32\xvid.ax
                              2009-02-17 17:31 . 2009-02-17 17:32 <REP> d-------- c:\users\All Users\Adobe
                              2009-02-17 17:31 . 2009-02-17 17:31 <REP> d-------- c:\program files\Common Files\Adobe
                              2009-02-17 17:21 . 2009-02-17 17:26 <REP> d-------- c:\program files\RegCleaner
                              2009-02-17 00:22 . 2009-02-17 18:49 <REP> d-------- c:\users\All Users\NOS
                              2009-02-17 00:22 . 2009-02-17 18:49 <REP> d-------- c:\programdata\NOS
                              2009-02-17 00:22 . 2009-02-17 18:49 <REP> d-------- c:\program files\NOS
                              2009-02-17 00:03 . 2009-02-17 00:03 <REP> d-------- c:\program files\TMPGEnc-2.525.64.184-FR-Free
                              2009-02-16 22:11 . 2009-02-16 22:11 <REP> d-------- c:\users\All Users\VistaCodecs
                              2009-02-16 22:11 . 2009-02-16 22:11 <REP> d-------- c:\programdata\VistaCodecs
                              2009-02-16 21:18 . 2009-02-16 21:18 <REP> d-------- c:\program files\COMODO
                              2009-02-16 21:18 . 2009-02-16 21:18 155,384 --a------ c:\windows\System32\guard32.dll
                              2009-02-16 21:09 . 2009-02-16 21:09 <REP> d-------- c:\windows\AsusInstAll
                              2009-02-16 21:09 . 2007-11-14 08:18 553 -r------- c:\windows\USetup.iss
                              2009-02-16 21:08 . 2009-02-16 21:09 33,215 --a------ c:\windows\Ascd_log.ini
                              2009-02-16 21:03 . 2009-02-18 15:15 <REP> d--h----- C:\$AVG8.VAULT$
                              2009-02-16 20:41 . 2008-12-04 12:34 328,728 --a------ c:\windows\System32\drivers\iaStor.sys
                              2009-02-16 19:55 . 2009-02-16 20:32 <REP> d-------- c:\windows\BDOSCAN8
                              2009-02-16 19:42 . 2009-02-18 15:06 <REP> d-------- c:\windows\System32\drivers\Avg
                              2009-02-16 19:42 . 2009-02-16 19:42 325,128 --a------ c:\windows\System32\drivers\avgldx86.sys
                              2009-02-16 19:42 . 2009-02-16 19:42 107,272 --a------ c:\windows\System32\drivers\avgtdix.sys
                              2009-02-16 19:42 . 2009-02-16 19:42 12,552 --a------ c:\windows\System32\drivers\avgrkx86.sys
                              2009-02-16 19:42 . 2009-02-16 19:42 10,520 --a------ c:\windows\System32\avgrsstx.dll
                              2009-02-16 19:36 . 2009-02-16 19:36 <REP> d-------- c:\users\All Users\ma-config.com
                              2009-02-16 19:36 . 2009-02-16 19:36 <REP> d-------- c:\programdata\ma-config.com
                              2009-02-16 19:36 . 2009-02-16 19:36 <REP> d-------- c:\program files\ma-config.com
                              2009-02-16 19:30 . 2009-02-16 19:30 <REP> d-------- c:\program files\CCleaner
                              2009-02-16 12:51 . 2009-02-16 13:05 <REP> d-------- c:\program files\Slysoft
                              2009-02-16 12:35 . 2008-12-02 12:04 398,336 --a------ c:\windows\System32\TVWizudlg.exe
                              2009-02-16 12:35 . 2008-12-02 12:03 140,288 --a------ c:\windows\System32\igfxtvcx.dll
                              2009-02-16 12:35 . 2008-12-02 12:00 121,232 --a------ c:\windows\System32\IScrNB.bmp
                              2009-02-15 19:44 . 2009-02-15 19:44 <REP> d-------- c:\program files\Common Files\NSV
                              2009-02-15 19:42 . 2009-02-16 12:35 <REP> d-------- c:\users\All Users\OrbNetworks
                              2009-02-15 19:42 . 2009-02-16 12:35 <REP> d-------- c:\programdata\OrbNetworks
                              2009-02-15 19:42 . 2009-02-15 19:42 <REP> d-------- c:\program files\Winamp Remote
                              2009-02-15 19:41 . 2009-02-16 18:56 <REP> d-------- c:\users\Seb\AppData\Roaming\Winamp
                              2009-02-15 19:41 . 2009-02-15 19:42 <REP> d-------- c:\program files\Winamp
                              2009-02-15 19:41 . 2008-11-06 17:37 129,784 --------- c:\windows\System32\pxafs.dll
                              2009-02-15 19:34 . 2009-02-15 19:35 <REP> d-------- c:\users\Seb\AppData\Roaming\dvdcss
                              2009-02-15 19:10 . 2009-02-15 19:40 3,096,026 --a------ C:\video.pass
                              2009-02-15 19:06 . 2009-02-17 17:12 <REP> d-------- c:\program files\M4ng Video Enhancer
                              2009-02-15 18:55 . 2009-02-15 18:55 <REP> d-------- c:\users\Seb\AppData\Roaming\WinBatch
                              2009-02-15 18:44 . 2009-02-17 00:35 118 --a------ C:\dgindex.bat
                              2009-02-15 10:25 . 2009-02-15 10:25 <REP> d-------- c:\users\All Users\Apple Computer
                              2009-02-15 10:25 . 2009-02-15 10:25 <REP> d-------- c:\programdata\Apple Computer
                              2009-02-15 10:25 . 2009-02-15 10:25 <REP> d-------- c:\program files\QuickTime Alternative
                              2009-02-15 10:25 . 2009-01-05 16:18 90,112 --a------ c:\windows\System32\QuickTimeVR.qtx
                              2009-02-15 10:25 . 2009-01-05 16:18 57,344 --a------ c:\windows\System32\QuickTime.qts
                              2009-02-15 10:24 . 2009-02-17 17:08 <REP> d-------- c:\program files\DirectVobSub
                              2009-02-15 10:22 . 2009-02-15 10:22 <REP> d-------- c:\users\All Users\Real
                              2009-02-15 10:22 . 2009-02-15 10:22 <REP> d-------- c:\program files\Real Alternative
                              2009-02-15 10:21 . 2009-02-17 18:51 <REP> d-------- c:\program files\m4ng codec pack
                              2009-02-15 10:18 . 2009-02-17 18:48 <REP> d-------- c:\program files\m4ng
                              2009-02-15 09:35 . 2009-02-15 10:19 <REP> d-------- c:\users\Seb\AppData\Roaming\DivX
                              2009-02-15 09:25 . 2008-06-20 02:14 781,344 --a------ c:\windows\System32\PresentationNative_v0300.dll
                              2009-02-15 09:25 . 2008-06-20 02:14 622,080 --a------ c:\windows\System32\icardagt.exe
                              2009-02-15 09:25 . 2008-06-20 02:14 326,160 --a------ c:\windows\System32\PresentationHost.exe
                              2009-02-15 09:25 . 2008-06-20 02:14 105,016 --a------ c:\windows\System32\PresentationCFFRasterizerNative_v0300.dll
                              2009-02-15 09:25 . 2008-06-20 02:14 97,800 --a------ c:\windows\System32\infocardapi.dll
                              2009-02-15 09:25 . 2008-06-20 02:14 43,544 --a------ c:\windows\System32\PresentationHostProxy.dll
                              2009-02-15 09:25 . 2008-06-20 02:14 37,384 --a------ c:\windows\System32\infocardcpl.cpl
                              2009-02-15 09:25 . 2008-06-20 02:14 11,264 --a------ c:\windows\System32\icardres.dll
                              2009-02-15 09:23 . 2009-02-15 09:23 <REP> d-------- c:\users\All Users\Soulseek
                              2009-02-15 09:23 . 2009-02-15 09:23 <REP> d-------- c:\programdata\Soulseek
                              2009-02-15 09:21 . 2008-07-27 19:03 282,112 --a------ c:\windows\System32\mscoree.dll
                              2009-02-15 09:21 . 2008-07-27 19:03 158,720 --a------ c:\windows\System32\mscorier.dll
                              2009-02-15 09:21 . 2008-07-27 19:03 96,760 --a------ c:\windows\System32\dfshim.dll
                              2009-02-15 09:21 . 2008-07-27 19:03 83,968 --a------ c:\windows\System32\mscories.dll
                              2009-02-15 09:21 . 2008-07-27 19:03 41,984 --a------ c:\windows\System32\netfxperf.dll
                              2009-02-15 09:12 . 2008-06-26 02:45 12,240,896 --a------ c:\windows\System32\NlsLexicons0007.dll
                              2009-02-15 09:12 . 2008-06-26 02:45 2,644,480 --a------ c:\windows\System32\NlsLexicons0009.dll
                              2009-02-15 09:12 . 2008-06-26 04:29 801,280 --a------ c:\windows\System32\NaturalLanguage6.dll
                              2009-02-15 09:12 . 2008-12-05 05:32 428,544 --a------ c:\windows\System32\EncDec.dll
                              2009-02-15 09:12 . 2008-12-05 05:32 293,376 --a------ c:\windows\System32\psisdecd.dll
                              2009-02-15 09:12 . 2008-12-05 05:31 217,088 --a------ c:\windows\System32\psisrndr.ax
                              2009-02-15 09:12 . 2008-12-05 05:31 177,664 --a------ c:\windows\System32\mpg2splt.ax
                              2009-02-15 09:12 . 2008-12-05 05:31 80,896 --a------ c:\windows\System32\MSNP.ax
                              2009-02-15 09:12 . 2008-04-23 05:41 57,856 --a------ c:\windows\System32\MSDvbNP.ax
                              2009-02-15 09:08 . 2008-11-01 02:21 4,240,384 --a------ c:\windows\System32\GameUXLegacyGDFs.dll
                              2009-02-15 09:08 . 2008-03-08 05:21 1,695,744 --a------ c:\windows\System32\gameux.dll
                              2009-02-15 09:08 . 2008-11-01 04:44 28,672 --a------ c:\windows\System32\Apphlpdm.dll
                              2009-02-15 09:00 . 2009-02-16 21:18 108,560 --a------ c:\windows\System32\drivers\cmdguard.sys
                              2009-02-15 09:00 . 2009-02-16 21:18 28,688 --a------ c:\windows\System32\drivers\cmdhlp.sys
                              2009-02-14 22:15 . 2009-02-14 22:15 <REP> d-------- c:\windows\System32\Macromed
                              2009-02-14 20:03 . 2009-02-17 19:08 <REP> d-------- c:\users\Seb\AppData\Roaming\uTorrent
                              2009-02-14 20:03 . 2009-02-14 20:03 <REP> d-------- c:\program files\uTorrent
                              2009-02-13 23:05 . 2009-02-16 21:13 <REP> d-------- c:\windows\System32\RTCOM
                              2009-02-13 23:03 . 2008-05-14 08:54 2,159,616 --a------ c:\windows\System32\RtkAPO.dll
                              2009-02-13 23:03 . 2009-02-16 21:09 319,456 --a------ c:\windows\DIFxAPI.dll
                              2009-02-13 23:03 . 2009-02-13 23:03 315,392 --a------ c:\windows\HideWin.exe
                              2009-02-13 23:03 . 2008-05-14 09:27 32,768 --a------ c:\windows\System32\RtkCoInst.dll
                              2009-02-13 23:02 . 2009-02-13 23:03 <REP> d-------- c:\program files\Common Files\InstallShield
                              2009-02-13 23:02 . 2009-02-13 23:02 <REP> d-------- c:\program files\ASUS
                              2009-02-13 23:02 . 2008-05-02 06:59 122,368 --a------ c:\windows\System32\drivers\Rtlh86.sys
                              2009-02-13 23:02 . 2006-01-10 09:50 24,576 -ra------ c:\windows\System32\AsIO.dll
                              2009-02-13 23:02 . 2007-12-17 10:14 12,400 -ra------ c:\windows\System32\drivers\AsIO.sys
                              2009-02-13 23:02 . 2008-01-04 13:34 11,832 --a------ c:\windows\System32\drivers\AsInsHelp64.sys
                              2009-02-13 23:02 . 2008-01-04 13:34 10,216 --a------ c:\windows\System32\drivers\AsInsHelp32.sys
                              2009-02-13 23:01 . 2009-02-13 23:03 <REP> d-------- c:\program files\Realtek
                              2009-02-13 22:55 . 2009-02-16 20:51 19,564 --a------ c:\windows\System32\results.xml
                              2009-02-13 22:41 . 2009-02-16 20:41 <REP> d-------- c:\program files\Intel
                              2009-02-13 22:41 . 2009-02-13 22:41 <REP> d-------- C:\Intel

                              .
                              (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                              .
                              2009-02-13 20:46 --------- d-----w c:\program files\Windows Mail
                              2009-02-13 16:39 --------- d-sh--w c:\programdata\Modèles
                              2009-02-13 16:39 --------- d-sh--w c:\programdata\Menu Démarrer
                              2009-02-13 16:39 --------- d-sh--w c:\programdata\Favoris
                              2009-02-13 16:39 --------- d-sh--w c:\programdata\Bureau
                              2009-02-13 16:39 --------- d-sh--w c:\program files\Fichiers communs
                              2009-01-16 07:23 920,088 ----a-w c:\windows\System32\igxpun.exe
                              2009-01-15 06:11 827,392 ----a-w c:\windows\System32\wininet.dll
                              2009-01-13 08:45 954,368 ----a-w c:\windows\system32\drivers\athr.sys
                              2008-12-29 19:22 2,330,643 ----a-w c:\windows\System32\x264vfw.dll
                              2008-12-23 10:02 670,232 ----a-w c:\windows\System32\igfxcfg.exe
                              2008-12-23 10:02 256,536 ----a-w c:\windows\System32\igfxsrvc.exe
                              2008-12-23 10:02 178,712 ----a-w c:\windows\System32\igfxext.exe
                              2008-12-23 10:02 178,712 ----a-w c:\windows\System32\hkcmd.exe
                              2008-12-23 10:02 154,136 ----a-w c:\windows\System32\igfxpers.exe
                              2008-12-23 10:02 150,040 ----a-w c:\windows\System32\igfxtray.exe
                              2008-12-23 09:51 147,456 ----a-w c:\windows\System32\igfxCoIn_v1624.dll
                              2008-12-23 09:43 3,411,968 ----a-w c:\windows\System32\igdumd32.dll
                              2008-12-23 09:43 2,476,032 ----a-w c:\windows\system32\drivers\igdkmd32.sys
                              2008-12-23 09:42 445,796 ----a-w c:\windows\System32\igcompkrng500.bin
                              2008-12-23 09:42 2,026,604 ----a-w c:\windows\System32\igkrng500.bin
                              2008-12-23 09:38 536,576 ----a-w c:\windows\System32\igdumdx32.dll
                              2008-12-23 09:33 2,256,896 ----a-w c:\windows\System32\igd10umd32.dll
                              2008-12-23 09:24 2,359,296 ----a-w c:\windows\System32\ig4dev32.dll
                              2008-12-23 09:23 3,895,296 ----a-w c:\windows\System32\ig4icd32.dll
                              2008-12-23 08:57 258,048 ----a-w c:\windows\System32\igfxTMM.dll
                              2008-12-23 08:56 69,632 ----a-w c:\windows\System32\oemdspif.dll
                              2008-12-23 08:56 52,224 ----a-w c:\windows\System32\igfxsrvc.dll
                              2008-12-23 08:56 24,576 ----a-w c:\windows\System32\igfxexps.dll
                              2008-12-23 08:56 217,088 ----a-w c:\windows\System32\igfxpph.dll
                              2008-12-23 08:56 135,168 ----a-w c:\windows\System32\igfxdo.dll
                              2008-12-23 08:56 106,496 ----a-w c:\windows\System32\hccutils.dll
                              2008-12-23 08:55 5,672,960 ----a-w c:\windows\System32\igfxress.dll
                              2008-12-23 08:55 221,184 ----a-w c:\windows\System32\igfxdev.dll
                              2008-12-11 00:33 86,016 ----a-w c:\windows\System32\dpl100.dll
                              2008-12-11 00:33 200,704 ----a-w c:\windows\System32\dtu100.dll
                              2008-12-09 02:28 593,920 ----a-w c:\windows\System32\dpuGUI11.dll
                              2008-12-09 02:28 57,344 ----a-w c:\windows\System32\dpv11.dll
                              2008-12-09 02:28 344,064 ----a-w c:\windows\System32\dpus11.dll
                              2008-12-09 02:28 294,912 ----a-w c:\windows\System32\dpu11.dll
                              2008-12-02 11:49 8,198,680 ----a-w c:\windows\System32\TVWSetup.exe
                              2008-12-02 11:40 155,648 ----a-w c:\windows\System32\igfxCoIn_v1608.dll
                              2008-12-02 11:31 97,048 ----a-w c:\windows\System32\igfcg500m.bin
                              2008-12-02 11:31 139,824 ----a-w c:\windows\System32\igfcg500.bin
                              2008-01-21 02:43 174 --sha-w c:\program files\desktop.ini
                              .

                              ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                              .
                              .
                              *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                              REGEDIT4

                              [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
                              2008-08-06 15:20 279944 --a------ c:\program files\AskBarDis\bar\bin\askBar.dll

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
                              "{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-08-06 279944]

                              [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
                              [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

                              [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
                              "{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-08-06 279944]

                              [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
                              [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

                              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                              "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
                              "Orb"="c:\program files\Winamp Remote\bin\OrbTray.exe" [2008-04-01 507904]
                              "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
                              "WindowsWelcomeCenter"="oobefldr.dll" [2008-01-21 c:\windows\System32\oobefldr.dll]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                              "WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-04 36352]
                              "RegKillTray"="c:\program files\DVD Region Killer\RegKillTray.exe" [2002-04-13 49152]
                              "RegKillElbyCheck"="c:\program files\DVD Region Killer\ElbyCheck.exe" [2001-12-06 45056]
                              "Persistence"="c:\windows\system32\igfxpers.exe" [2008-12-23 154136]
                              "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-12-23 150040]
                              "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-12-04 186904]
                              "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-12-23 178712]
                              "ElbyCheckAnyDVD"="c:\program files\SlySoft\AnyDVD\ElbyCheck.exe" [2003-09-20 45056]
                              "COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2009-02-16 1850616]
                              "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-16 1601304]
                              "AnyDVD"="c:\program files\Slysoft\AnyDVD\AnyDVD.exe" [2003-09-29 175616]
                              "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
                              "RtHDVCpl"="RtHDVCpl.exe" [2008-05-20 c:\windows\RtHDVCpl.exe]

                              c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
                              MioSync.lnk - c:\program files\Mio Technology\MioSync\mioSync.exe [2009-02-13 638976]
                              Wireless Connection Manager.lnk - c:\program files\D-Link\D-Link DWA-547 Wireless N Desktop Adapter\wirelesscm.exe [2009-02-13 30138368]

                              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                              "EnableLUA"= 0 (0x0)
                              "EnableUIADesktopToggle"= 0 (0x0)

                              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
                              "AppInit_DLLs"=c:\windows\system32\guard32.dll avgrsstx.dll

                              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                              "vidc.X264"= x264vfw.dll
                              "msacm.divxa32"= DivXa32.acm
                              "msacm.ac3filter"= ac3filter.acm

                              [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1446501199-1864174522-333908962-1000]
                              "EnableNotifications"=dword:00000001
                              "EnableNotificationsRef"=dword:00000001

                              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
                              "{6BE26F92-E21C-4153-92C4-54BE984982F7}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
                              "{0F083220-0977-4C4B-87E4-291C257B2204}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
                              "{DD827E8B-AFDA-46FB-87FD-D5803ED56AF3}"= UDP:c:\program files\Winamp Remote\bin\Orb.exe:Orb
                              "{E6D22540-C0B7-47D6-A194-65C14F789BD9}"= TCP:c:\program files\Winamp Remote\bin\Orb.exe:Orb
                              "{0A563615-B9A9-4707-A2D7-51831B8FDC00}"= UDP:c:\program files\Winamp Remote\bin\OrbTray.exe:OrbTray
                              "{FE25E637-8B18-4910-91C4-95FD575FFCC3}"= TCP:c:\program files\Winamp Remote\bin\OrbTray.exe:OrbTray
                              "{8E9181B5-2ED0-444A-84C2-26F1C018B2D7}"= UDP:c:\program files\Winamp Remote\bin\OrbIR.exe:OrbIR
                              "{EA7A134E-B64E-42E3-8202-B8C79BCC3D0E}"= TCP:c:\program files\Winamp Remote\bin\OrbIR.exe:OrbIR
                              "{3DE3CE88-0F79-4FA3-B06C-DCDBAE0FCF0B}"= UDP:c:\program files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
                              "{123AE001-374F-442D-8A38-F709ABC4EE9D}"= TCP:c:\program files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
                              "{CE995BDD-FED1-400C-8CD7-6C064A401832}"= UDP:48113:LocalSubnet:LocalSubnet:maconfig_tcp
                              "{FCDC0500-3E87-4C06-B8DC-8F708E871249}"= TCP:48113:LocalSubnet:LocalSubnet:maconfig_udp
                              "{5E65B9C5-70FF-490D-9C8D-9644A81D22F5}"= UDP:c:\program files\ma-config.com\maconfservice.exe:maconfservice
                              "{3AF0C595-270A-47CF-A157-17CCA29C3D75}"= TCP:c:\program files\ma-config.com\maconfservice.exe:maconfservice
                              "{66BF34BA-24C4-40C8-B8DF-796D0986C852}"= c:\program files\AVG\AVG8\avgam.exe:avgam.exe
                              "{40A2531B-F226-4F89-B408-3027F2390BA7}"= c:\program files\AVG\AVG8\avgemc.exe:avgemc.exe
                              "{5217E73F-A7F2-46D0-9E4E-5342E88BADD5}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
                              "{A31FF707-108B-4B91-B5AB-C39886AAB025}"= c:\program files\AVG\AVG8\avgnsx.exe:avgnsx.exe

                              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
                              "EnableFirewall"= 0 (0x0)

                              R0 AvgRkx86;avgrkx86.sys;c:\windows\System32\drivers\avgrkx86.sys [2009-02-16 12552]
                              R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [2009-02-16 325128]
                              R1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [2009-02-16 107272]
                              R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\System32\drivers\cmdguard.sys [2009-02-15 108560]
                              R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\System32\drivers\cmdhlp.sys [2009-02-15 28688]
                              R1 jswpslwf;JumpStart Wireless Filter Driver;c:\windows\System32\drivers\jswpslwf.sys [2009-02-13 20384]
                              R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-02-16 903960]
                              R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-02-16 298264]
                              R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\System32\drivers\IntcHdmi.sys [2008-09-22 112128]
                              R3 RegKill;RegKill;c:\windows\System32\drivers\RegKill.sys [2003-09-20 3840]
                              S3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\program files\everest\kerneld.wnt [2009-02-17 26224]
                              S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\D-Link\D-Link DWA-547 Wireless N Desktop Adapter\jswpsapi.exe [2009-02-13 954368]
                              S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [2009-01-24 216232]

                              [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{270ffd3f-f9eb-11dd-8649-806e6f6e6963}]
                              \shell\AutoRun\command - d:\.\Bin\ASSETUP.exe
                              .
                              Contenu du dossier 'Tâches planifiées'

                              2009-02-17 c:\windows\Tasks\User_Feed_Synchronization-{57F4B2A5-A859-48E9-9173-AB799FBB5169}.job
                              - c:\windows\system32\msfeedssync.exe [2008-01-21 03:24]
                              .
                              - - - - ORPHELINS SUPPRIMES - - - -

                              HKCU-Run-Uniblue RegistryBooster 2009 - c:\program files\registrybooster\StartRegistryBooster.exe

                              .
                              ------- Examen supplémentaire -------
                              .
                              IE: &Traduire à partir de l'anglais - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html
                              IE: Pages liées - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
                              IE: Pages similaires - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
                              IE: Recherche &Google - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
                              IE: Version de la page actuelle disponible dans le cache Google - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
                              DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                              FF - ProfilePath - c:\users\Seb\AppData\Roaming\Mozilla\Firefox\Profiles\qg753xbp.default\
                              FF - prefs.js: keyword.URL - about:neterror?e=query&u=
                              1 fichier(s) déplacé(s).
                              FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
                              FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
                              .

                              **************************************************************************

                              catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                              Rootkit scan 2009-02-18 16:24:43
                              Windows 6.0.6001 Service Pack 1 NTFS

                              Recherche de processus cachés ...

                              Recherche d'éléments en démarrage automatique cachés ...

                              Recherche de fichiers cachés ...

                              Scan terminé avec succès
                              Fichiers cachés: 0

                              **************************************************************************
                              .
                              --------------------- DLLs chargées dans les processus actifs ---------------------

                              - - - - - - - > 'winlogon.exe'(672)
                              c:\windows\system32\guard32.dll

                              - - - - - - - > 'lsass.exe'(740)
                              c:\windows\system32\guard32.dll
                              .
                              Heure de fin: 2009-02-18 16:26:48
                              ComboFix-quarantined-files.txt 2009-02-18 15:26:46

                              Avant-CF: 565 080 104 960 octets libres
                              Après-CF: 565,039,693,824 octets libres

                              314 --- E O F --- 2009-02-15 23:10:36
                              0
                              1. si tu viens d'installer le windows ca na rien avoir avec les virus .essaie donc de chercher des drivers plus recents de ta carte mere si ca marche pas achte toi une carte audio ca coute pas chere.bonne chance.
                                0
                                1. Contributeur sécurité
                                  Fais un scan en ligne avec Kaspersky (avec Internet Explorer)

                                  CLIQUE ICI

                                  - En bas à droite, clique sur Démarrer Online-scaner

                                  - Dans la nouvelle fenêtre qui s’affiche, clique sur J’accepte

                                  - Accepte les Contrôles ActiveX

                                  - Choisis Poste de travail pour le scan.

                                  - Celui-ci terminé, sauvegarde (Choisis fichier texte) et poste le rapport
                                  0
                                  1. ok, je suis en train. Par contre c'est vraiment bizarre, car tout a l'heure après combofix, mon periphérique audio à refonctionné. et là, j'ai rippé un dvd avec m4ng et il a ressauté. c'est le périphérique HDMI device. Et là, je regarde de nouveaux et il fonctionne !!!C'est à n'y rien comprendre.
                                    0
                                    1. Tant mieux si ça marche ^_^ .
                                      0
                                      1. kaspersky n'a rien trouvé, je refais un scan sur les zones critiques. Merci beaucoup pour votre aide si précieuse.
                                        0
                                        • 1
                                        • 2