Alerte Virus - aucun anti-virus possible!

Salut tout le monde, j'ai un énorme souci!

J'ai du télécharger quelque chose qu'il ne fallait pas, et antivir a commencé à devenir un peu fou, avec plein d'alerte, puis au redémarrage de l'ordinateur, antivir ne pouvait plus démarrer (il me disait qu'un ficher essentiel à son démarrage a été supprimer). Résultat, je l'ai désinstaller pour le réinstaller, car j'avais garder le .exe , mais ça ne marche pas non plus...

En même temps, des antivirus (que je ne conaissait même pas) "Security Tools", et "Protection System" ont commencé à me faire des analyse, et me demande de payer une licence pour supprimer ce que le logiciel a trouvé...

J'ai voulu télécharger antivir à nouveau, seulement, aucun site où je peux télécharger un antivirus ne marche. On dirait que c'est fait expré! J'arrive à aller dans tout les sites, sauf ceux pour télécharger un antivirus... J'ai essayer avec bitdefender (même la version online) et avast...

En gros, j'ai plus d'antivirus, j'arrive plus à en télécharger, et mon ordi part en vrille...

Comment puis-je faire svp? Vous avez une idée?
Configuration: Windows XP
Firefox 3.5.3

26 réponses

  1. Contributeur sécurité
    Si tu as findykill ca veut dire que tu peux télécharger des logiciels ?

    Fais ceci :

    -+-+-+-+-> ComboFix <-+-+-+-

    [x] Télécharge ComboFIX ( de sUBs ) à cette adresse : http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    [x] /!\ Fermez toutes les fenêtres de programme ouvertes /!\

    [x] /!\ Désactivez toutes les protections résidentes ( Antivirus, Pare-Feu, AntiSpyware ) /!\

    [x] Double clique sur " Combofix.exe "

    [x] Suis les indications qui sont données à l'écran, à un moment tu auras un message te demandant d'installer la console de récupération, fais le

    [x] Combofix va maintenant déconnecter ton PC d'internet

    [x] Pendant le scan, ne touche à rien ( souris, clavier )

    [x] A la fin du scan, le rapport s'ouvrira automatiquement, copie/colle le dans ton prochain message.

    [o] Nb : Si jamais il ne s'ouvrait pas, il se trouve sous C:\Combofix.txt
    1
    1. Contributeur sécurité
      Salut, commence par faire ceci :

      -+-+-+-> RSIT <-+-+-+-

      [x] Télécharge Random's System Information Tool à cette adresse : http://images.malwareremoval.com/random/RSIT.exe

      [x] Double clique sur " RSIT.exe ".

      [x] Clique sur " Continue ".

      [x] Si hijackthis n'est pas présent il sera automatiquement téléchargé et tu devras accepter la license.

      [x] Une fois l'analyse finie, deux fichiers ( info.txt & log.txt ) s'ouvriront.

      [x] Copie colle le contenu des deux rapports dans ton prochain message

      [o] Si jamais tu as fermé les rapports sans faire attention, ils sont sous C:\rsit
      0
      1. merci pour ta réponse, mais ton lien ne veut pas s'ouvrir dans mon ordi... comme pour télécharger les antivirus il veut pas... mais j'ai déjà hijackthis et je peux faire un scan desuite pour l'envoyer
        0
        1. Logfile of HijackThis v1.99.1
          Scan saved at 18:23:03, on 08/10/2009
          Platform: Windows XP SP3 (WinNT 5.01.2600)
          MSIE: Internet Explorer v8.00 (8.00.6001.18702)

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\FastNetSrv.exe
          c:\APPS\HIDSERVICE\HIDSERVICE.exe
          C:\Program Files\Java\jre6\bin\jqs.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
          C:\WINDOWS\system32\o2flash.exe
          C:\WINDOWS\system32\HPZipm12.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
          C:\Program Files\Winsudate\gibsvc.exe
          C:\WINDOWS\system32\wbem\wmiapsrv.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\servises.exe
          C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\WINDOWS\RTHDCPL.EXE
          C:\WINDOWS\system32\WLan.exe
          C:\WINDOWS\system32\LVCOMSX.EXE
          C:\WINDOWS\system32\ElkCtrl.exe
          C:\WINDOWS\7SP_Files\Drive Icon\DrvIcon.exe
          C:\Program Files\Java\jre6\bin\jusched.exe
          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
          C:\Program Files\Fichiers communs\Nokia\MPlatform\NokiaMServer.exe
          C:\WINDOWS\system32\restorer32_a.exe
          C:\WINDOWS\system32\servises.exe
          C:\WINDOWS\system32\restorer64_a.exe
          C:\WINDOWS\Temp\_ex-08.exe
          C:\WINDOWS\system32\servises.exe
          C:\WINDOWS\7SP_Files\ViStart\ViStart.exe
          C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
          C:\Program Files\ViGlance\ViGlance.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\Program Files\SFR\Kit\9props.exe
          C:\WINDOWS\system32\servises.exe
          C:\WINDOWS\sc.exe
          C:\WINDOWS\7SP_Files\Styler\Styler.exe
          C:\WINDOWS\7SP_Files\VisualTaskTips\VisualTaskTips.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
          C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\F.tmp
          C:\WINDOWS\system32\restorer32_a.exe
          C:\WINDOWS\system32\cmd.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Protection System\PSYSTEM.EXE
          C:\Documents and Settings\All Users\Application Data\04827122\04827122.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=55729C844D6A45819CAD368B3E178C9F
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.sfr.fr/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O1 - Hosts: 169.254.187.210 HP000D9D01BBD2
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
          O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
          O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Program Files\Windows Live\Messenger\wlchtc.dll
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
          O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
          O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
          O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
          O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\WINDOWS\7SP_Files\Styler\TB\StylerTB.dll
          O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
          O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
          O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
          O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
          O4 - HKLM\..\Run: [WLAN] C:\WINDOWS\system32\WLan.exe
          O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
          O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
          O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
          O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
          O4 - HKLM\..\Run: [DrvIcon] C:\WINDOWS\7SP_Files\Drive Icon\DrvIcon.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [NokiaMServer] C:\Program Files\Fichiers communs\Nokia\MPlatform\NokiaMServer /watchfiles
          O4 - HKLM\..\Run: [TrayServer] C:\Program Files\MAGIX\Video_deluxe_15_Plus_Version_a_telecharger\TrayServer.exe
          O4 - HKLM\..\Run: [restorer32_a] C:\WINDOWS\system32\restorer32_a.exe
          O4 - HKLM\..\Run: [servises] C:\WINDOWS\system32\servises.exe
          O4 - HKLM\..\Run: [Regedit32] C:\WINDOWS\system32\regedit.exe
          O4 - HKLM\..\Run: [reader_s] C:\WINDOWS\System32\reader_s.exe
          O4 - HKLM\..\Run: [restorer64_a] C:\WINDOWS\system32\restorer64_a.exe
          O4 - HKLM\..\Run: [04827122] C:\Documents and Settings\All Users\Application Data\04827122\04827122.exe
          O4 - HKLM\..\Run: [PromoReg] C:\WINDOWS\Temp\_ex-08.exe
          O4 - HKCU\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t
          O4 - HKCU\..\Run: [TransBar] C:\WINDOWS\7SP_Files\TransBar\TransBar.exe /s
          O4 - HKCU\..\Run: [ViStart] C:\WINDOWS\7SP_Files\ViStart\ViStart
          O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
          O4 - HKCU\..\Run: [ViGlance] C:\Program Files\ViGlance\ViGlance.exe
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
          O4 - HKCU\..\Run: [Connexion SFR 9props.exe] "C:\Program Files\SFR\Kit\9props.exe" /trayicon
          O4 - HKCU\..\Run: [servises] C:\WINDOWS\system32\servises.exe
          O4 - HKCU\..\Run: [restorer32_a] C:\Documents and Settings\Michaël\restorer32_a.exe
          O4 - HKCU\..\Run: [restorer64_a] C:\Documents and Settings\Michaël\restorer64_a.exe
          O4 - HKCU\..\Run: [mserv] C:\Documents and Settings\Michaël\Application Data\seres.exe
          O4 - HKCU\..\Run: [svchost] C:\Documents and Settings\Michaël\Application Data\svcst.exe
          O4 - HKCU\..\Run: [Security Center] C:\WINDOWS\sc.exe
          O4 - HKCU\..\Run: [Protection System] C:\Program Files\Protection System\PSYSTEM.EXE
          O4 - Startup: Refresh Icon Cache.lnk = C:\WINDOWS\7SP_Files\Refresh Icon Cache\Refresh Icon Cache.exe
          O4 - Startup: Styler toolbar.lnk = C:\WINDOWS\7SP_Files\Styler\Styler.exe
          O4 - Startup: Styler.lnk = ?
          O4 - Startup: uecupd32.exe
          O4 - Startup: VisualTaskTips.lnk = C:\WINDOWS\7SP_Files\VisualTaskTips\VisualTaskTips.exe
          O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
          O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O11 - Options group: [INTERNATIONAL] International
          O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
          O16 - DPF: CabBuilder - http://ak.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
          O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Rawflow.cab
          O16 - DPF: {164B406B-0FD6-4E7F-BA7E-64D227D4CA37} (dnlplayer Class) - http://www.digitalwebbooks.com/reader/dbplugin.cab
          O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
          O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
          O16 - DPF: {46C66BBD-E667-4DAD-9682-58050E7C9FDC} (CDPass Class) - https://get.cryptobrowser.site/en/3344803/
          O16 - DPF: {4A85DBE0-BFB2-4119-8401-186A7C6EB653} - http://messenger.zone.msn.com/binary/MJSS.cab69309.cab
          O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://mikalive.spaces.live.com//PhotoUpload/MsnPUpld.cab
          O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
          O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/fr/scan8/oscan8.cab
          O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
          O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://mika-life.spaces.live.com/PhotoUpload/MsnPUpld.cab
          O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
          O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
          O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://caebmm.imgag.com/imgag/cp/install/crusher-cae.cab
          O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
          O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} (Java Plug-in 1.6.0_11) -
          O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} (Java Plug-in 1.6.0_13) -
          O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://gamenextfr.oberon-media.com/Gameshell/GameHost/1.0/OberonGameHost.cab
          O16 - DPF: {D1548A26-B8F6-4E86-AE74-E7062CCC2E2A} (igLoader Content on Demand) - http://www.miniclip.com/igloader/igloader.CAB
          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
          O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
          O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
          O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
          O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll
          O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
          O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
          O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\FICHIE~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
          O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
          O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
          O20 - Winlogon Notify: winrkq32 - winrkq32.dll (file missing)
          O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
          O23 - Service: fastnetsrv Service (fastnetsrv) - Sigma Designs In - C:\WINDOWS\system32\FastNetSrv.exe
          O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\MAGIX\Common\Database\bin\fbserver.exe
          O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
          O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
          O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
          O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
          O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
          O23 - Service: MySqlInventime - Unknown owner - c:\mysql\bin\mysqld-max-nt.exe
          O23 - Service: O2Micro Flash Memory (O2Flash) - Unknown owner - C:\WINDOWS\system32\o2flash.exe
          O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
          O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
          O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
          O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
          O23 - Service: Gestionnaire de mise à jour Winsudate (WinSvc) - Winsudate - C:\Program Files\Winsudate\gibsvc.exe
          0
          1. Contributeur sécurité
            Est ce que tu as un autre PC à côté de toi ?

            Essaie quand même de télécharger ceci :

            -+-+-+-> Findykill ( Infections Bagle ) <-+-+-+-

            /!\ Désactive tes protections résidentes ( Antivirus, Pare-Feu, Antispyware ) /!\

            [x] Télécharge Findykill à cette adresse : http://sd-1.archive-host.com/membres/up/116615172019703188/F­indyKill.exe

            [x] Branche tout tes médias amovibles sur ton PC

            [x] Lance Findykill ( clique droit -> éxecuter en tant qu'administrateur sous vista )

            [x] Choisis l'option F ( français ) puis l'option n°1 ( Recherche )

            [x] Laisse le scan s'opérer.

            [x] Copie/Colle le rapport qui s'ouvrira et poste le dans ta prochaine réponse

            [x] Note : Le rapport FindyKill.txt est sauvegardé a la racine du disque. ( C:\FindyKill.txt )
            0
            1. Contributeur sécurité
              Eh ben, une bonne panoplie d'infection dis donc.. je te prépare un script attend un peu ;)
              0
              1. j'ai essayer de suivre tes instruction avec findykill, seulement pendant la recherche il m'est venu un écran bleu, et j'ai du redémarrer...

                j'attend ton script ^^
                0
                1. alors, j'ai essayer de lancer combofix, mais il me dit que c'est dangereux de continuer, que le contenu du paquetage a été détérioré, et que je dois télécharger un nouvel examplaire depuis bleepingcomputer.com/... etc ...
                  et il me dit aussi que mon pc est peut être infecté par un virus modifiant les fichier "virut"

                  je fais quoi?
                  0
                  1. il veut pas le télécharger...
                    je vais essayer à partir d'un autre ordi...
                    0
                    1. c'est bizar, même avec mon autre ordi la page ne veut pas s'ouvrir...
                      0
                      1. Contributeur sécurité
                        Essaie ceci :

                        -+-+-+-> OTMoveIt <-+-+-+-

                        [x] Télécharge OTMoveIt (de Old_Timer) à cette adresse : https://www.luanagames.com/index.fr.html sur ton Bureau.

                        [x] Double-clique sur OTMoveIt.exe.

                        [x] Assure toi que la case Unregister Dll's and Ocx's soit bien cochée.

                        [x] Copie le texte en gras ci dessous et colle le dans le cadre de gauche de OTMoveIt nommé Paste List of Files/Folders to be moved

                        :processes
                        explorer.exe
                        04827122.exe
                        cmd.exe
                        restorer32_a.exe
                        F.tmp
                        VisualTaskTips.exe
                        Styler.exe
                        sc.exe
                        servises.exe
                        ViStart.exe
                        _ex-08.exe
                        restorer64_a.exe
                        gibsvc.exe
                        HPZipm12.exe
                        o2flash.exe

                        :reg
                        [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
                        "restorer32_a"=-
                        "servises"=-
                        "Regedit32"=-
                        "reader_s"=-
                        "restorer64_a"=-
                        "04827122"=-
                        "PromoReg"=-
                        "DWQueuedReporting"=-
                        "ViStart"=-
                        "servises"=-
                        "restorer32_a"=-
                        "restorer64_a"=-
                        "mserv"=-
                        "svchost"=-
                        "Security Center"=-
                        "Protection System"=-

                        :files
                        C:\WINDOWS\system32\restorer32_a.exe
                        C:\WINDOWS\system32\servises.exe
                        C:\WINDOWS\system32\restorer64_a.exe
                        C:\WINDOWS\Temp\_ex-08.exe
                        C:\WINDOWS\system32\servises.exe
                        C:\WINDOWS\7SP_Files\ViStart\ViStart.exeC:\WINDOWS\system32\F.tmp
                        C:\WINDOWS\system32\restorer32_a.exe
                        C:\WINDOWS\system32\cmd.exe
                        C:\Program Files\ViGlance\ViGlance.exe
                        C:\WINDOWS\system32\servises.exe
                        C:\Program Files\Winsudate\gibsvc.exe
                        C:\WINDOWS\sc.exe
                        C:\WINDOWS\7SP_Files\Styler\Styler.exe
                        C:\WINDOWS\7SP_Files\VisualTaskTips\VisualTaskTips.exe

                        :commands
                        [emptytemp]
                        [purity]
                        [start explorer]

                        </gras>

                        [x] Clique sur MoveIt! pour lancer la suppression.

                        [x] Si OTMoveIt propose de redémarrer ton PC, accepte.

                        [x] Lorsque un résultat apparaît dans le cadre Results, clique sur Exit.

                        [x] Dans ta future réponse, envoie le rapport de OTMoveIt situé sous C:\_OTMoveIt\MovedFiles

                        -----------------

                        Y'a énormement d'infections, dont virut, ca va être très dur de nettoyer le PC totalement, je te garantis rien, tu vas peut être devoir reformater ton PC.
                        0
                        1. ========== PROCESSES ==========
                          Process explorer.exe killed successfully.
                          Unable to kill process: 04827122.exe
                          Unable to kill process: cmd.exe
                          Process restorer32_a.exe killed successfully.
                          Unable to kill process: F.tmp
                          Process VisualTaskTips.exe killed successfully.
                          Process Styler.exe killed successfully.
                          Process sc.exe killed successfully.
                          Process servises.exe killed successfully.
                          Process ViStart.exe killed successfully.
                          Unable to kill process: _ex-08.exe
                          Process restorer64_a.exe killed successfully.
                          Unable to kill process: gibsvc.exe
                          Process HPZipm12.exe killed successfully.
                          Unable to kill process: o2flash.exe
                          ========== REGISTRY ==========
                          Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\restorer32_a deleted successfully.
                          Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\servises deleted successfully.
                          Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Regedit32 not found.
                          Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\reader_s not found.
                          Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\restorer64_a deleted successfully.
                          Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\04827122 not found.
                          Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\PromoReg not found.
                          Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\DWQueuedReporting deleted successfully.
                          Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ViStart deleted successfully.
                          Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\servises not found.
                          Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\restorer32_a not found.
                          Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\restorer64_a not found.
                          Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\mserv deleted successfully.
                          Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\svchost deleted successfully.
                          Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Security Center deleted successfully.
                          Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Protection System deleted successfully.
                          ========== FILES ==========
                          C:\WINDOWS\system32\restorer32_a.exe moved successfully.
                          C:\WINDOWS\system32\servises.exe moved successfully.
                          C:\WINDOWS\system32\restorer64_a.exe moved successfully.
                          C:\WINDOWS\Temp\_ex-08.exe moved successfully.
                          File/Folder C:\WINDOWS\system32\servises.exe not found.
                          File/Folder C:\WINDOWS\7SP_Files\ViStart\ViStart.exeC:\WINDOWS\system32\F.tmp not found.
                          File/Folder C:\WINDOWS\system32\restorer32_a.exe not found.
                          C:\WINDOWS\system32\cmd.exe moved successfully.
                          C:\Program Files\ViGlance\ViGlance.exe moved successfully.
                          File/Folder C:\WINDOWS\system32\servises.exe not found.
                          C:\Program Files\Winsudate\gibsvc.exe moved successfully.
                          C:\WINDOWS\sc.exe moved successfully.
                          C:\WINDOWS\7SP_Files\Styler\Styler.exe moved successfully.
                          C:\WINDOWS\7SP_Files\VisualTaskTips\VisualTaskTips.exe moved successfully.
                          ========== COMMANDS ==========
                          File delete failed. C:\DOCUME~1\MICHAL~1\LOCALS~1\Temp\NGLATempNokia\Nokia Sans Wide Bold v3.1.ttf scheduled to be deleted on reboot.
                          File delete failed. C:\DOCUME~1\MICHAL~1\LOCALS~1\Temp\NGLALog.txt scheduled to be deleted on reboot.
                          File delete failed. C:\DOCUME~1\MICHAL~1\LOCALS~1\Temp\~DF61F6.tmp scheduled to be deleted on reboot.
                          User's Temp folder emptied.
                          User's Temporary Internet Files folder emptied.
                          User's Internet Explorer cache folder emptied.
                          Local Service Temp folder emptied.
                          File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
                          Local Service Temporary Internet Files folder emptied.
                          File delete failed. C:\WINDOWS\temp\mta108367.dll scheduled to be deleted on reboot.
                          File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_708.dat scheduled to be deleted on reboot.
                          Windows Temp folder emptied.
                          Java cache emptied.
                          File delete failed. C:\Documents and Settings\Michaël\Local Settings\Application Data\Mozilla\Firefox\Profiles\miawbwnk.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
                          File delete failed. C:\Documents and Settings\Michaël\Local Settings\Application Data\Mozilla\Firefox\Profiles\miawbwnk.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
                          File delete failed. C:\Documents and Settings\Michaël\Local Settings\Application Data\Mozilla\Firefox\Profiles\miawbwnk.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
                          File delete failed. C:\Documents and Settings\Michaël\Local Settings\Application Data\Mozilla\Firefox\Profiles\miawbwnk.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
                          File delete failed. C:\Documents and Settings\Michaël\Local Settings\Application Data\Mozilla\Firefox\Profiles\miawbwnk.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
                          File delete failed. C:\Documents and Settings\Michaël\Local Settings\Application Data\Mozilla\Firefox\Profiles\miawbwnk.default\XUL.mfl scheduled to be deleted on reboot.
                          FireFox cache emptied.
                          Temp folders emptied.
                          Explorer started successfully

                          OTMoveIt3 by OldTimer - Version 1.0.7.0 log created on 10082009_192037
                          0
                          1. Contributeur sécurité
                            Ok on a viré une partie, refais un rapport hijackthis, et surtout, essaie de ne pas mettre en veille ton PC ni de le redémarrer, c'est très important.
                            0
                            1. Logfile of HijackThis v1.99.1
                              Scan saved at 19:38:49, on 08/10/2009
                              Platform: Windows XP SP3 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v8.00 (8.00.6001.18702)

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\Ati2evxx.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\spoolsv.exe
                              c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\FastNetSrv.exe
                              c:\APPS\HIDSERVICE\HIDSERVICE.exe
                              C:\Program Files\Java\jre6\bin\jqs.exe
                              C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                              C:\WINDOWS\system32\o2flash.exe
                              C:\WINDOWS\system32\HPZipm12.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
                              C:\WINDOWS\system32\wbem\wmiapsrv.exe
                              C:\WINDOWS\system32\Ati2evxx.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\5.tmp
                              C:\WINDOWS\system32\restorer32_a.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\TEMP\BNC.tmp
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                              C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                              C:\WINDOWS\RTHDCPL.EXE
                              C:\WINDOWS\system32\WLan.exe
                              C:\WINDOWS\system32\LVCOMSX.EXE
                              C:\WINDOWS\system32\ElkCtrl.exe
                              C:\WINDOWS\7SP_Files\Drive Icon\DrvIcon.exe
                              C:\Program Files\Java\jre6\bin\jusched.exe
                              C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                              C:\Program Files\Fichiers communs\Nokia\MPlatform\NokiaMServer.exe
                              C:\WINDOWS\system32\restorer32_a.exe
                              C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
                              C:\WINDOWS\system32\ctfmon.exe
                              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              C:\Program Files\SFR\Kit\9props.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
                              C:\Program Files\Mozilla Firefox\firefox.exe
                              C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=55729C844D6A45819CAD368B3E178C9F
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.sfr.fr/
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                              O1 - Hosts: 169.254.187.210 HP000D9D01BBD2
                              O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                              O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                              O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                              O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Program Files\Windows Live\Messenger\wlchtc.dll
                              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
                              O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
                              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                              O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                              O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                              O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\WINDOWS\7SP_Files\Styler\TB\StylerTB.dll
                              O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                              O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                              O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                              O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
                              O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                              O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                              O4 - HKLM\..\Run: [WLAN] C:\WINDOWS\system32\WLan.exe
                              O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
                              O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
                              O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
                              O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
                              O4 - HKLM\..\Run: [DrvIcon] C:\WINDOWS\7SP_Files\Drive Icon\DrvIcon.exe
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                              O4 - HKLM\..\Run: [NokiaMServer] C:\Program Files\Fichiers communs\Nokia\MPlatform\NokiaMServer /watchfiles
                              O4 - HKLM\..\Run: [TrayServer] C:\Program Files\MAGIX\Video_deluxe_15_Plus_Version_a_telecharger\TrayServer.exe
                              O4 - HKLM\..\Run: [restorer32_a] C:\WINDOWS\system32\restorer32_a.exe
                              O4 - HKLM\..\Run: [servises] C:\WINDOWS\system32\servises.exe
                              O4 - HKLM\..\Run: [Regedit32] C:\WINDOWS\system32\regedit.exe
                              O4 - HKLM\..\Run: [reader_s] C:\WINDOWS\System32\reader_s.exe
                              O4 - HKLM\..\Run: [restorer64_a] C:\WINDOWS\system32\restorer64_a.exe
                              O4 - HKLM\..\Run: [04827122] C:\Documents and Settings\All Users\Application Data\04827122\04827122.exe
                              O4 - HKLM\..\Run: [PromoReg] C:\WINDOWS\Temp\_ex-08.exe
                              O4 - HKCU\..\Run: [TransBar] C:\WINDOWS\7SP_Files\TransBar\TransBar.exe /s
                              O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
                              O4 - HKCU\..\Run: [ViGlance] C:\Program Files\ViGlance\ViGlance.exe
                              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                              O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                              O4 - HKCU\..\Run: [Connexion SFR 9props.exe] "C:\Program Files\SFR\Kit\9props.exe" /trayicon
                              O4 - HKCU\..\Run: [restorer32_a] C:\Documents and Settings\Michaël\restorer32_a.exe
                              O4 - Startup: Refresh Icon Cache.lnk = C:\WINDOWS\7SP_Files\Refresh Icon Cache\Refresh Icon Cache.exe
                              O4 - Startup: Styler toolbar.lnk = C:\_OTMoveIt\MovedFiles\10082009_192037\WINDOWS\7SP_Files\Styler\Styler.exe
                              O4 - Startup: Styler.lnk = ?
                              O4 - Startup: uecupd32.exe
                              O4 - Startup: VisualTaskTips.lnk = C:\_OTMoveIt\MovedFiles\10082009_192037\WINDOWS\7SP_Files\VisualTaskTips\VisualTaskTips.exe
                              O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                              O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
                              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
                              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O11 - Options group: [INTERNATIONAL] International
                              O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
                              O16 - DPF: CabBuilder - http://ak.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
                              O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Rawflow.cab
                              O16 - DPF: {164B406B-0FD6-4E7F-BA7E-64D227D4CA37} (dnlplayer Class) - http://www.digitalwebbooks.com/reader/dbplugin.cab
                              O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
                              O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
                              O16 - DPF: {46C66BBD-E667-4DAD-9682-58050E7C9FDC} (CDPass Class) - https://get.cryptobrowser.site/en/3344803/
                              O16 - DPF: {4A85DBE0-BFB2-4119-8401-186A7C6EB653} - http://messenger.zone.msn.com/binary/MJSS.cab69309.cab
                              O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://mikalive.spaces.live.com//PhotoUpload/MsnPUpld.cab
                              O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
                              O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                              O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/fr/scan8/oscan8.cab
                              O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
                              O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://mika-life.spaces.live.com/PhotoUpload/MsnPUpld.cab
                              O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
                              O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
                              O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://caebmm.imgag.com/imgag/cp/install/crusher-cae.cab
                              O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                              O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} (Java Plug-in 1.6.0_11) -
                              O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} (Java Plug-in 1.6.0_13) -
                              O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://gamenextfr.oberon-media.com/Gameshell/GameHost/1.0/OberonGameHost.cab
                              O16 - DPF: {D1548A26-B8F6-4E86-AE74-E7062CCC2E2A} (igLoader Content on Demand) - http://www.miniclip.com/igloader/igloader.CAB
                              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                              O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
                              O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
                              O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
                              O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll
                              O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
                              O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
                              O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\FICHIE~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
                              O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
                              O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                              O20 - Winlogon Notify: winrkq32 - winrkq32.dll (file missing)
                              O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
                              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                              O23 - Service: fastnetsrv Service (fastnetsrv) - Sigma Designs In - C:\WINDOWS\system32\FastNetSrv.exe
                              O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\MAGIX\Common\Database\bin\fbserver.exe
                              O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                              O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
                              O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                              O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
                              O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
                              O23 - Service: MySqlInventime - Unknown owner - c:\mysql\bin\mysqld-max-nt.exe
                              O23 - Service: O2Micro Flash Memory (O2Flash) - Unknown owner - C:\WINDOWS\system32\o2flash.exe
                              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                              O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                              O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
                              O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
                              O23 - Service: Gestionnaire de mise à jour Winsudate (WinSvc) - Unknown owner - C:\Program Files\Winsudate\gibsvc.exe (file missing)
                              0
                              1. Contributeur sécurité
                                Bien,

                                Télécharge SF.exe de C_XX . http://sd-1.archive-host.com/membres/up/16506160323759868/SF.exe

                                *Double clique sur SF.exe ("éxécuter en tant qu'administrateur pour vista) .

                                *Une fenetre Cmd va s'ouvrir .

                                *Tape winrkq32.dll dans cette fenetre et "entrée" .

                                *Patiente pendant la recherche .

                                *Une fenetre avec un log .txt va s'afficher .

                                *Copie/colle ce rapport dans ta prochaine réponse .

                                -------------------

                                Réessaye de passer Combofix
                                0
                                1. SF ne veut pas se lancer quand je double-clique...
                                  0
                                  1. Contributeur sécurité
                                    renomme le en ccm.exe

                                    renomme aussi combofix.exe en ccm1.exe

                                    et essaie de lancer les scan
                                    0
                                    1. j'ai renommer les 2, et aucun des 2 ne marche...
                                      0
                                      • 1
                                      • 2