Dd wd detecté mais pas sur poste de travail

yaya -  
jlpjlp Messages postés 52399 Statut Contributeur sécurité -
Bonjour a tous,

voila mon problème: j'avais un virus sur mon dd wd(320 go) j'ai donc voulu le formater, mais je pense que l'opération ne s'est pas bien déroulée, du coup mainteant a chaque fois que je branche mon dd, il est detecté dans les peripheriques de stockage usb, mais je ne le trouve pas sur le poste de travail. aucun autre dd n'est branché, donc ce n'est pas un problème de lettre.
j'ai essayé sur plusieurs ordi, j'ai toujours le meme problème

j'espere que vous allez pouvoir m'aider, mon dd est pratiquement neuf, et ca me saoulerai de devoir en acheter un autre!

merci d'avance
Configuration: Windows Vista

11 réponses

  1. Rouumain Messages postés 848 Date d'inscription   Statut Membre Dernière intervention   198
     
    Bonjour,

    je te conseillerais d'essayer de désintaller le disque dur dans le gestionnaire de périphérique sous Vista tu vas dans le poste de travail , puis l'onglet Propriété système et sur la gauche gestionnaire périphérique tu cherches ton DD dans les lecteurs de disque et clique droit dessus et tu desinstalles

    une fois effectuer tu débranche ton disque dur tu redémarres et tu rebranche le DD une fois le PC démarrer ,

    si aprés ça il ne detecte toujours pas le DD , tu fais Démarrer >> tu fais un click droit sur Ordinateur et tu clique sur Gérer et une fois le gestionnaire lancer tu vas sur la gauche dans Gestion des Disques et donnes nous les détails indiqués pour le DD .
    0
    1. yaya
       
      Bonjour,
      merci de m'avoir répondu aussi vite.
      j'ai fait les opérations que tu m'as dit de faire, et il ne le detecte toujours pas.
      par contre je ne sais pas vraiment ce qu'il faut que je donne comme details pour le dd, d'ailleur je ne le vois meme pas dans les gestions des disques
      que faire?
      0
  2. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    slt

    ▶ Télécharge FindyKill sur ton bureau :

    http://sd-1.archive-host.com/membres/up/127028005715545653/FindyKill.exe

    ! Déconnecte toi et ferme toutes applications en cours !

    • Double clique sur "FindyKill.exe" pour lancer l'installation et laisse les paramètres d'instalation par défaut .

    • Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...)

    • Double-clique sur le raccourci FindyKill qui est sur ton bureau pour lancer l'outil .

    • Au menu principal choisis l'option " F " pour français et tape sur [entrée] .

    • Au second menu Choisis l'option " 1 " (recherche) et tape sur [entrée]

    ▶ Laisse travailler l'outil et ne touche à rien ...

    --> Poste le rapport qui apparait à la fin , sur le forum ...

    ( le rapport est sauvegardé aussi sous C:\FindyKill.txt )
    ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

    • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
    Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
    Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

    Aides en images : http://pagesperso-orange.fr/NosTools/findykill.html
    0
    1. yaya
       
      merci de m'avoir repondu auss vite, je telecharge findykill, et je t'envoie ensuite le rapport.
      parcontre penses-tu qu'a chaque fois ( sur un ordi différent)que je voudrai utiliser mon dd, il faudra faire cette opération?
      0
  3. Rouumain Messages postés 848 Date d'inscription   Statut Membre Dernière intervention   198
     
    tentes de faire la manipulation de jlpjlp ,elle est bien détaillé et cella donnera un rapport clair
    0
  4. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    il me faut le rapport ....
    0
    1. yaya
       
      voila j'ia installer findykill, mais quand je le lance j'ai une fenetre qui s'ouvre ou y'a écrit getPaths.exe a cessé de fonctionner, ensuite j'ai la page principal de findykill qui s'avoure je tape f,1, ensuite j'ai accées refusé, qui s'affiche en rouge, et ca se ferme.
      desolée de vous déranger, mais la je ne sais pas quoi faire!
      0
    2. yaya
       
      en fait je vois dans gestion des disques, mon dd, appellé disque 1, avec un espace de 298 g0, non alloué, et non initialisé.
      voila je ne sais pas si c'est ca que tu voulais savoir?
      encore merci pour tout
      0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    ok tu es sous vista

    Utilisateurs de Vista /!\

    ▶ Désactivez le contrôle des comptes utilisateurs avant utilisation de cet outil:

    • Allez dans "Démarrer" puis Panneau de configuration.
    • Double Cliquez sur l'icône Comptes d'utilisateurs et sur "Activer ou désactiver le contrôle des comptes d'utilisateurs".
    • Décochez la case Utiliser le contrôle des comptes d'utilisateurs pour vous aider à protéger votre ordinateur.
    • Validez par OK et redémarrez .

    ▶ Aides en images ( Uac ) : http://pagesperso-orange.fr/NosTools/uac_vista.html
    0
  7. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    refais findykill en utilisant le message 8 au préalable car sous vista
    0
    1. yaya
       
      :-( encore un problème
      ca se lance, mais parcontre quand ca s'arrete, ca ferme la fenetre et je trouve pas le rapport dans le c:
      0
      1. yaya > yaya
         
        voila le rapport!
        ############################## | FindyKill V6.005 |

        # User : yaya (Administrateurs) # PC-DE-YAYA
        # Update on 11/07/09 by Chiquitine29 & C_XX
        # Start at: 16:22:17 | 12/07/2009
        # Website : http://pagesperso-orange.fr/NosTools/index.html

        # Intel(R) Core(TM)2 Duo CPU T5800 @ 2.00GHz
        # Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
        # Internet Explorer 8.0.6001.18783
        # Windows Firewall Status : Enabled

        # C:\ # Disque fixe local # 144,04 Go (68,6 Go free) [ACER] # NTFS
        # D:\ # Disque fixe local # 139,5 Go (139,41 Go free) [DATA] # NTFS
        # F:\ # Disque CD-ROM # 7,16 Go (0 Mo free) [RA3] # UDF
        # I:\ # Disque CD-ROM

        ############################## | Processus actifs |

        C:\Windows\System32\smss.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\wininit.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\services.exe
        C:\Windows\system32\lsass.exe
        C:\Windows\system32\lsm.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\nvvsvc.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\SLsvc.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\winlogon.exe
        C:\Windows\system32\vfsFPService.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\WLANExt.exe
        C:\Windows\System32\spoolsv.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\rundll32.exe
        C:\Program Files\Acer\Acer Bio Protection\CompPtcVUI.exe
        C:\Windows\system32\Dwm.exe
        C:\Windows\system32\taskeng.exe
        C:\Windows\Explorer.EXE
        C:\Windows\system32\agrsmsvc.exe
        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
        C:\Windows\system32\taskeng.exe
        C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
        C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
        C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
        C:\Windows\RtHDVCpl.exe
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\Program Files\Intel\WiFi\bin\EvtEng.exe
        C:\Windows\WindowsMobile\wmdc.exe
        C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
        C:\Program Files\uTorrent\uTorrent.exe
        C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
        C:\Program Files\Acer\Acer Bio Protection\BASVC.exe
        C:\Program Files\Common Files\LightScribe\LSSrvc.exe
        C:\Acer\Mobility Center\MobilityService.exe
        C:\Program Files\Nosibay\Mon Widget RMC\Launcher.exe
        C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
        C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
        C:\Windows\system32\PnkBstrA.exe
        C:\Windows\system32\PnkBstrB.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
        C:\Program Files\Cyberlink\Shared files\RichVideo.exe
        C:\Program Files\Acer\Acer VCM\RS_Service.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\SearchIndexer.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\Program Files\Larousse\Petit Larousse 2009\bin\Hyperappel.exe
        C:\Program Files\MagicDisc\MagicDisc.exe
        C:\Windows\system32\wbem\wmiprvse.exe
        C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
        C:\Program Files\Windows Media Player\wmpnscfg.exe
        C:\Program Files\Windows Media Player\wmpnetwk.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\Nosibay\Mon Widget RMC\Mon Widget RMC.exe
        C:\Windows\System32\mobsync.exe
        C:\Program Files\iPod\bin\iPodService.exe
        C:\Users\khaled\AppData\Local\Temp\RtkBtMnt.exe
        C:\Windows\system32\conime.exe
        C:\Program Files\IncrediMail\bin\IncMail.exe
        C:\Program Files\IncrediMail\bin\IMApp.exe
        C:\Program Files\Google\Chrome\Application\chrome.exe
        C:\Program Files\Google\Chrome\Application\chrome.exe
        C:\Program Files\IncrediMail\bin\ImNotfy.exe
        C:\Windows\system32\taskeng.exe
        C:\Program Files\Google\Chrome\Application\chrome.exe
        C:\Program Files\Google\Chrome\Application\chrome.exe
        C:\Program Files\Google\Chrome\Application\chrome.exe
        C:\Program Files\Google\Chrome\Application\chrome.exe
        C:\Windows\servicing\TrustedInstaller.exe
        C:\Windows\system32\wbem\wmiprvse.exe

        ################## | Registre Startup |

        R1 - HKCU\..\Main: "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
        R1 - HKCU\..\Main: "Start Page"="https://gamespace.daemon-tools.cc/fra/home"
        R1 - HKCU\..\Main: "Secondary Start Pages"=hex(7):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,\
        F2 - HKLM\..\logon:"Userinit"="C:\\Windows\\system32\\userinit.exe,"
        F2 - HKLM\..\logon:"LegalNoticeCaption"=""
        F2 - HKLM\..\logon:"LegalNoticeText"=""
        04 - HKLM\..\Run: Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
        04 - HKLM\..\Run: RtHDVCpl=RtHDVCpl.exe
        04 - HKLM\..\Run: QuickTime Task="C:\Program Files\QuickTime\QTTask.exe" -atboottime
        04 - HKLM\..\Run: AppleSyncNotifier=C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
        04 - HKLM\..\Run: iTunesHelper="C:\Program Files\iTunes\iTunesHelper.exe"
        04 - HKLM\..\Run: Windows Mobile Device Center=%windir%\WindowsMobile\wmdc.exe
        04 - HKLM\..\Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
        04 - HKCU\..\Run: uTorrent="C:\Program Files\uTorrent\uTorrent.exe"
        04 - HKCU\..\Run: Mon Widget RMC="C:\Program Files\Nosibay\Mon Widget RMC\launcher.exe"
        04 - HKCU\..\Run: WMPNSCFG=C:\Program Files\Windows Media Player\WMPNSCFG.exe
        04 - HKCU\..\Run: swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

        ################## | Fichiers # Dossiers infectieux |


        ################## | C:\Users\khaled\Temporary Internet Files |


        ################## | All Drives ... |

        Présent ! F:\autorun.inf [a5c971483a8c89d0408e7e270c3a2f4a]

        ################## | Registre # Clés Run infectieuses |


        ################## | Registre # Mountpoints2 |

        HKCU\..\..\Explorer\MountPoints2\E
        shell\AutoRun\command =E:\SETUP.EXE
        shell\configure\command =E:\SETUP.EXE
        shell\install\command =E:\SETUP.EXE

        HKCU\..\..\Explorer\MountPoints2\K
        shell\AutoRun\command =K:\SETUP.EXE
        shell\configure\command =K:\SETUP.EXE
        shell\install\command =K:\SETUP.EXE

        HKCU\..\..\Explorer\MountPoints2\{1e1720da-518d-11de-b2c1-00a0d1aaaada}
        shell\AutoRun\command =J:\Autorun.exe

        HKCU\..\..\Explorer\MountPoints2\{471dbc52-7c91-11dd-a89c-806e6f6e6963}
        shell\AutoRun\command =F:\Autorun.exe

        HKCU\..\..\Explorer\MountPoints2\{48941178-fafd-11dd-9e9c-0016ea7214a6}
        shell\AutoRun\command =

        HKCU\..\..\Explorer\MountPoints2\{48941190-fafd-11dd-9e9c-0016ea7214a6}
        shell\AutoRun\command =E:\SETUP.EXE
        shell\configure\command =E:\SETUP.EXE
        shell\install\command =E:\SETUP.EXE

        HKCU\..\..\Explorer\MountPoints2\{5e50cb13-1d6c-11de-a78e-00a0d1aaaada}
        shell\AutoRun\command =

        HKCU\..\..\Explorer\MountPoints2\{63616158-4965-11de-a0ff-00a0d1aaaada}
        shell\AutoRun\command =I:\Autorun.exe

        HKCU\..\..\Explorer\MountPoints2\{84952e48-4626-11de-a496-00a0d1aaaada}
        shell\AutoRun\command =G:\Autorun.exe

        ################## | Etat / Services / Informations |

        # Affichage des fichiers cachés : OK
        # Mode sans echec : OK
        # (!) Uac = 0x0

        # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
        # EapHost -> Start = 3 ( Good = 2 | Bad = 4 )
        # Wlansvc -> Start = 2 ( Good = 2 | Bad = 4 )
        # SharedAccess -> Start = 3 ( Good = 2 | Bad = 4 )
        # windefend -> Start = 2 ( Good = 2 | Bad = 4 )
        # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
        # wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )


        ################## | Cracks / Keygens / Serials |
        0
  8. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    ok fais l'option 2 et colle le rapport
    0
    1. yaya
       
      l'option 2, fait planter mon ordi, je fait quoi?
      0
  9. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    Télécharge RavAntivirus d'Evosla :
    http://ww25.evosla.com/compteur.php?soft=rav_antivirus

    # Si tu as une clé USB, disque dur externe, etc, branche-les sans les ouvrir avant de lancer ce FIX
    # Fais un clic droit sur le fichier .ZIP > Extraire sur > le Bureau
    # Doucle-clique sur >> RAV.exe << afin de lancer l'outil.
    # Une fois RAV ANTIVIRUS lancé, laisse-le réagir , il scanne automatiquement tout les lecteurs (disques fixes et amovibles)
    # Si infection > un log s'établira, sinon le soft affichera (très rapide) ==>Votre Ordinateur est sain .
    # Retire tes disques amovibles et redémarrez votre ordinateur.
    # Poste le rapport, si infection!

    2/ Télécharge sur le bureau Flash Disinfector (de SUBS) à cette adresse : http://www.techsupportforum.com/sectools/sUBs/Flash_Disinfector.exe

    Double-clique sur l’icône.
    Les icônes vont disparaître. C’est normal.
    Si un rapport est généré en cas d'infection, sauvegarde-le sur le bureau, et poste le ensuite
    Redémarre ensuite le PC.

    _________________

    Télécharge ici :

    http://images.malwareremoval.com/random/RSIT.exe

    random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

    Double-clique sur RSIT.exe afin de lancer RSIT.

    Clique Continue à l'écran Disclaimer.

    Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

    Poste le contenu de log.txt (<<qui sera affiché)
    ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

    NB : Les rapports sont sauvegardés dans le dossier C:\rsit
    0
  10. yaya
     
    salut à tous,

    désolée pour cette disparition, mais je n'étais pas chez moi, et du coup je n'avais pas internet.

    voila jlpjlp j'ai fait ce que tu m'avais demandé de faire: mon ordinateur est sain donc pour ca je n'ai pas de rapport.

    sinon voici les deux autres rapport ( log et info) j'espere vraiment que vous allez pouvoir m'aider à "retrouver" mon dd. encore merci pour votre aide
    0
  11. yaya
     
    Logfile of random's system information tool 1.06 (written by random/random)
    Run by khaled at 2009-08-05 18:48:38
    Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
    System drive C: has 34 GB (23%) free of 148 GB
    Total RAM: 3068 MB (58% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 18:49:10, on 05/08/2009
    Platform: Windows Vista SP2 (WinNT 6.00.1906)
    MSIE: Internet Explorer v8.00 (8.00.6001.18813)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\taskeng.exe
    C:\Windows\RtHDVCpl.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Windows\WindowsMobile\wmdc.exe
    C:\Program Files\Search Settings\SearchSettings.exe
    C:\Program Files\Nosibay\Mon Widget RMC\Launcher.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\Windows Media Player\wmplayer.exe
    C:\Users\khaled\AppData\Local\Temp\RtkBtMnt.exe
    C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
    C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe
    C:\Program Files\Nosibay\Mon Widget RMC\Mon Widget RMC.exe
    C:\Program Files\Google\Chrome\Application\chrome.exe
    C:\Program Files\Google\Chrome\Application\chrome.exe
    C:\Program Files\Google\Chrome\Application\chrome.exe
    C:\Program Files\Google\Chrome\Application\chrome.exe
    C:\Program Files\Google\Chrome\Application\chrome.exe
    C:\Program Files\Google\Chrome\Application\chrome.exe
    C:\Program Files\Google\Chrome\Application\chrome.exe
    C:\Program Files\Google\Chrome\Application\chrome.exe
    C:\Program Files\WinRAR\WinRAR.exe
    C:\Program Files\Google\Chrome\Application\chrome.exe
    C:\Users\khaled\Documents\Downloads\RSIT.exe
    C:\Program Files\trend micro\khaled.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=2&o=vp32&d=0908&m=aspire_8930
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fmz.qiwa.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=2&o=vp32&d=0908&m=aspire_8930
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=2&o=vp32&d=0908&m=aspire_8930
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: Mininova Toolbar - {f592709f-ff4a-4862-b659-4afabda56312} - C:\Program Files\Mininova\tbMini.dll
    R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb128\SearchSettings.dll
    O1 - Hosts: ::1 localhost
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
    O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb128\SearchSettings.dll
    O2 - BHO: Mininova Toolbar - {f592709f-ff4a-4862-b659-4afabda56312} - C:\Program Files\Mininova\tbMini.dll
    O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
    O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O3 - Toolbar: Mininova Toolbar - {f592709f-ff4a-4862-b659-4afabda56312} - C:\Program Files\Mininova\tbMini.dll
    O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll (file missing)
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
    O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
    O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
    O4 - HKCU\..\Run: [Mon Widget RMC] "C:\Program Files\Nosibay\Mon Widget RMC\launcher.exe"
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
    O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
    O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
    O4 - Global Startup: Hyperappel du Petit Larousse 2009.lnk = C:\Program Files\Larousse\Petit Larousse 2009\bin\Hyperappel.exe
    O9 - Extra button: Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe
    O9 - Extra 'Tools' menuitem: Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe
    O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
    O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: Unibet - {00000000-0000-0000-0000-000000000000} - C:\MicroGaming\Poker\unibetpokerMPP\MPPoker.exe (file missing) (HKCU)
    O13 - Gopher Prefix:
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://fichiers.touslesdrivers.com/maconfig/MaConfig_3_5_1_0.cab
    O16 - DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} (Flash Casino Helper Control) - https://plugins.valueactive.eu/flashax/iefax.cab
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
    O20 - Winlogon Notify: AWinNotifyVitaKey MC3000 - C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll
    O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
    O23 - Service: CLHNService - Unknown owner - C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
    O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
    O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
    O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
    O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
    O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
    O23 - Service: Google Desktop Manager 5.7.808.7150 (GoogleDesktopManager-080708-050100) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    O23 - Service: Service Google Update (gupdate1c9aee4fb3f3590) (gupdate1c9aee4fb3f3590) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iGroupTec Service (IGBASVC) - Unknown owner - C:\Program Files\Acer\Acer Bio Protection\BASVC.exe
    O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
    O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
    O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
    O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
    O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
    O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe
    O23 - Service: Raw Socket Service (RS_Service) - Acer Incorporated - C:\Program Files\Acer\Acer VCM\RS_Service.exe
    O23 - Service: Service CANALPLAY - Canal+ Distribution - C:\Program Files\Lecteur CANALPLAY\CanalPlayService.exe
    O23 - Service: Validity Fingerprint Service (vfsFPService) - Validity Sensors, Inc. - C:\Windows\system32\vfsFPService.exe
    0
  12. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    ok

    tu n'as pas d'antivirus???

    _______________

    Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
    https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

    * Lance l'installation du programme en exécutant le fichier téléchargé.
    * Double-clique maintenant sur le raccourci de Toolbar-S&D.
    * Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
    * Choisis maintenant l'option 2

    . Patiente jusqu'à la fin de la recherche.
    * Poste le rapport généré. (C:\TB.txt)

    __________

    scan avec malwarebyte , fais un scan minutieux et colle le rapport obtenu et vire ce qui est trouvé:

    https://www.malekal.com/tutoriel-malwarebyte-anti-malware/­

    ______________________

    colle un scan en ligne avec un des deux suivants:

    bitdefender en ligne :
    http://www.bitdefender.fr/scan_fr/scan8/ie.html

    Kaspersky en ligne
    https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
    0