Sos mon ordi deconne

Résolu
Bonjour,
depuis 3 jours des fenetre souvre sur mon ordi toute les 2min c trop chiant j'ai deja essayer plusieur logiciel pour trouver les probleme mais je ni arrive pas " tel que OTMoveIt " puvais vous m'aider svp la accuelement je suis en train de faire un scanner mon ordi sur bitdefender online
Configuration: Windows XP Internet Explorer 8.0

15 réponses

  1. bonsoir,
    du calme, mais n'outilise pas non, plus les outils sans las connaitre.

    Télécharge random's system information tool (RSIT) et enregistre le sur ton bureau.
    http://images.malwareremoval.com/random/RSIT.exe

    Tuto : https://forum.pcastuces.com/randoms_system_information_tool_rsit-f31s31.htm
    Double clique sur RSIT.exe pour lancer l'outil.
    Clique sur ' continue ' à l'écran Disclaimer.
    Si l'outil HIjackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.
    Une fois le scan fini, 2 rapports vont apparaître. Poste le contenu des 2 rapports séparément. Ils se trouvent sur c :
    (log.txt & info.txt)
    (CTRL+A Pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)
    0
    1. es-que c bien les bon raport que je vous ai mis ????
      0
  2. merci pour ta reponce voici les rapport
    Logfile of random's system information tool 1.06 (written by random/random)
    Run by laurent at 2009-10-15 19:17:31
    Microsoft Windows XP Professionnel
    System drive C: has 128 GB (54%) free of 238 GB
    Total RAM: 2046 MB (67% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 19:17:32, on 15/10/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\SYSTEM32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\system32\avprot.exe
    C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\msprot.exe
    C:\WINDOWS\system32\lxcycoms.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Documents and Settings\laurent\Mes documents\telechargement\RSIT.exe
    C:\Program Files\trend micro\laurent.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail?u=https%253A//espaceclient2.orange.fr/nextecare/nextecare.do
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O3 - Toolbar: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
    O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /install
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [LXCYCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCYtime.dll,_RunDLLEntry@16
    O4 - HKLM\..\Run: [Antivirus Protection] C:\WINDOWS\system32\avprot.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: InterCasino France - {30C66393-FEF3-4758-BA00-803E3ABC88A2} - http://france.intercasino.com/ (file missing) (HKCU)
    O9 - Extra 'Tools' menuitem: InterCasino France - {30C66393-FEF3-4758-BA00-803E3ABC88A2} - http://france.intercasino.com/ (file missing) (HKCU)
    O15 - Trusted Zone: http://*.mappy.com
    O15 - Trusted Zone: http://*.orange.fr
    O15 - Trusted Zone: http://rw.search.ke.voila.fr
    O15 - Trusted Zone: http://orange.weborama.fr
    O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - https://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
    O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
    O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: lxcy_device - - C:\WINDOWS\system32\lxcycoms.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    0
    1. Atem information tool 1.06 (written by random/random)
      Run by laurent at 2009-10-15 19:14:43
      Microsoft Windows XP Professionnel Service Pack 3
      System drive C: has 128 GB (54%) free of 238 GB
      Total RAM: 2046 MB (67% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 19:14:43, on 15/10/2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\SYSTEM32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\System32\nvsvc32.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
      C:\WINDOWS\system32\RUNDLL32.EXE
      C:\WINDOWS\system32\avprot.exe
      C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\msprot.exe
      C:\WINDOWS\system32\lxcycoms.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Windows Live\Contacts\wlcomm.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Documents and Settings\laurent\Local Settings\Temporary Internet Files\Content.IE5\IK185Q1V\RSIT[1].exe
      C:\Program Files\trend micro\laurent.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail?u=https%253A//espaceclient2.orange.fr/nextecare/nextecare.do
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
      O2 - BHO: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
      O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
      O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
      O3 - Toolbar: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
      O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /install
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [LXCYCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCYtime.dll,_RunDLLEntry@16
      O4 - HKLM\..\Run: [Antivirus Protection] C:\WINDOWS\system32\avprot.exe
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
      O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra button: InterCasino France - {30C66393-FEF3-4758-BA00-803E3ABC88A2} - http://france.intercasino.com/ (file missing) (HKCU)
      O9 - Extra 'Tools' menuitem: InterCasino France - {30C66393-FEF3-4758-BA00-803E3ABC88A2} - http://france.intercasino.com/ (file missing) (HKCU)
      O15 - Trusted Zone: http://*.mappy.com
      O15 - Trusted Zone: http://*.orange.fr
      O15 - Trusted Zone: http://rw.search.ke.voila.fr
      O15 - Trusted Zone: http://orange.weborama.fr
      O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - https://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
      O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: lxcy_device - - C:\WINDOWS\system32\lxcycoms.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
      0
      1. tu es bien infecté !!!

        •/!\ Utilisateur de Vista : Ne pas oublier de désactiver l’UAC juste le temps de désinfection de ton pc, il sera à réactiver plus tard :
        Tuto : https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

        Télécharges ComboFix à partir de ce lien :

        https://forospyware.com

        ou ici :
        http://download.bleepingcomputer.com/sUBs/ComboFix.exe

        A lire
        https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

        Et important, enregistre le sur le bureau.

        Avant d'utiliser ComboFix :

        ► Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.

        ► Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.

        Une fois fait, sur ton bureau double-clic sur Combofix.exe.
        /!\Utilisateur de Vista : Clique droit sur le logo de smithfarudfix, « exécuter en tant qu’Administrateur »

        - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

        /!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.

        - En fin de scan il est possible que ComboFix ait besoin de redémarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

        - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

        ► Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

        ► Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

        Si ça ne marche pas, tu vires combofix de sur ton bureau et tu télécharge depuis ce lien jacombo qui est combofix renommé cela permet de contrer certaine infection, tu le mets sur ton bureau et tu suis les explications données dans la procédure de combofix
        http://sd-1.archive-host.com/membres/up/89820622056365782/jacombo.exe
        0
        1. voila c fait je vous copie le raport
          ComboFix 09-10-15.01 - laurent 15/10/2009 21:21.1.2 - NTFSx86
          Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.2046.1552 [GMT 2:00]
          Lancé depuis: c:\documents and settings\laurent\Mes documents\telechargement\ComboFix.exe
          .

          ((((((((((((((((((((((((((((( Fichiers créés du 2009-09-15 au 2009-10-15 ))))))))))))))))))))))))))))))))))))
          .

          2009-10-15 16:16 . 2009-10-15 16:47 -------- d-----w- c:\windows\BDOSCAN8
          2009-10-15 16:16 . 2009-10-15 16:16 -------- d-----w- c:\windows\LastGood
          2009-10-15 16:07 . 2009-10-15 16:07 -------- d-----w- c:\program files\Navilog1
          2009-10-14 18:19 . 2009-10-14 18:19 -------- d-----w- C:\_OTMoveIt
          2009-10-14 18:06 . 2009-10-14 18:06 579584 -c--a-w- c:\windows\system32\dllcache\user32.dll
          2009-10-14 18:04 . 2009-10-14 18:04 -------- d-----w- c:\windows\ERUNT
          2009-10-14 17:07 . 2009-10-14 18:17 -------- d-----w- C:\SDFix
          2009-10-14 16:59 . 2009-10-14 17:00 -------- dc-h--w- c:\windows\ie8
          2009-10-14 16:23 . 2009-10-14 16:23 -------- d-----w- c:\program files\Enigma Software Group
          2009-10-14 09:41 . 2009-10-15 17:17 -------- d-----w- c:\program files\trend micro
          2009-10-14 09:41 . 2009-10-14 09:42 -------- d-----w- C:\rsit
          2009-10-14 08:13 . 2009-10-14 08:13 -------- d-----w- C:\ABC 3GP Converter
          2009-10-14 08:13 . 2009-10-14 08:13 -------- d-----w- c:\documents and settings\All Users\Application Data\VOWSoft
          2009-10-14 07:30 . 2009-10-14 07:30 38912 ----a-w- c:\windows\system32\avprot.exe
          2009-10-14 07:30 . 2009-10-14 07:30 38912 ----a-w- c:\windows\msprot.exe
          2009-10-12 16:30 . 2009-10-12 16:30 -------- d-----w- C:\MMConverterPro2
          2009-10-12 16:25 . 2009-10-12 16:25 -------- d-----w- c:\program files\Fichiers communs\Apple
          2009-10-12 16:25 . 2009-10-12 16:25 -------- d-----w- c:\documents and settings\laurent\Local Settings\Application Data\Apple
          2009-10-12 16:25 . 2009-10-12 16:25 -------- d-----w- c:\program files\Apple Software Update
          2009-10-12 16:25 . 2009-10-12 16:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
          2009-10-12 16:25 . 2009-10-12 16:25 -------- d-----w- c:\documents and settings\laurent\Local Settings\Application Data\Apple Computer
          2009-10-09 07:01 . 2007-05-16 13:53 107520 ----a-w- c:\windows\system32\UnCasinoV5_FRA.exe
          2009-10-05 09:22 . 2009-10-14 07:43 -------- d-----w- c:\windows\system32\avsplugin
          2009-10-05 09:22 . 2007-02-16 05:10 60273 ----a-w- c:\windows\system32\pthreadGC2.dll
          2009-10-05 09:22 . 2006-12-31 08:16 313344 ----a-w- c:\windows\system32\avisynth.dll
          2009-10-05 09:22 . 2006-10-17 20:29 487479 ----a-w- c:\windows\system32\SkinMagic.dll
          2009-10-05 09:22 . 2004-05-26 18:37 719872 ----a-w- c:\windows\system32\devil.dll
          2009-10-05 09:15 . 2009-10-05 09:15 -------- d-----w- c:\documents and settings\laurent\Application Data\AVS4YOU
          2009-10-05 09:15 . 2009-10-05 09:15 -------- d-----w- c:\documents and settings\All Users\Application Data\AVS4YOU
          2009-10-05 09:14 . 2009-10-05 09:19 -------- d-----w- c:\program files\AVS4YOU
          2009-10-05 09:14 . 2009-10-05 09:19 -------- d-----w- c:\program files\Fichiers communs\AVSMedia
          2009-10-05 09:14 . 2008-08-13 09:22 974848 ----a-w- c:\windows\system32\mfc70.dll
          2009-10-05 09:14 . 2008-08-13 09:22 487424 ----a-w- c:\windows\system32\msvcp70.dll
          2009-10-05 09:14 . 2008-08-13 09:22 344064 ----a-w- c:\windows\system32\msvcr70.dll
          2009-10-05 09:14 . 2008-08-13 09:22 1700352 ----a-w- c:\windows\system32\GdiPlus.dll
          2009-10-03 09:46 . 2009-10-03 09:46 0 ----a-w- c:\windows\nsreg.dat
          2009-10-03 09:46 . 2009-10-03 09:46 -------- d-----w- c:\documents and settings\laurent\Local Settings\Application Data\Mozilla
          2009-09-30 19:10 . 2009-09-30 19:10 -------- d-----w- c:\documents and settings\laurent\Application Data\Xilisoft Corporation
          2009-09-30 19:07 . 2009-09-30 19:07 -------- d-----w- c:\program files\MIKSOFT
          2009-09-27 11:15 . 2008-04-13 17:33 221184 ----a-w- c:\windows\system32\wmpns.dll
          2009-09-27 09:35 . 2001-05-11 11:18 420240 ----a-w- c:\windows\system32\mpg4c32.dll
          2009-09-27 09:33 . 2004-08-14 04:31 180224 ----a-w- c:\windows\system32\ArcSoft Screen Saver.scr
          2009-09-27 09:32 . 2005-02-23 12:58 11776 ----a-w- c:\windows\system32\drivers\afc.sys
          2009-09-27 09:31 . 2009-09-27 09:33 -------- d-----w- c:\program files\ArcSoft
          2009-09-27 09:31 . 1995-08-01 02:44 212480 ----a-w- c:\windows\PCDLIB32.DLL
          2009-09-27 09:28 . 2009-09-27 09:28 -------- d-----w- c:\documents and settings\laurent\Application Data\muvee Technologies
          2009-09-27 09:17 . 2009-09-27 09:17 -------- d-----w- c:\program files\Fichiers communs\muvee Technologies
          2009-09-27 09:15 . 2009-09-27 09:15 -------- d-----w- c:\documents and settings\All Users\Application Data\muvee Technologies
          2009-09-27 09:15 . 2009-09-27 09:34 -------- d-----w- c:\program files\DV TS
          2009-09-27 09:15 . 2009-09-27 09:34 -------- d-----w- c:\windows\V3T
          2009-09-18 16:41 . 2009-09-18 16:41 -------- d-----w- c:\windows\Sun

          .
          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          2009-10-15 19:16 . 2009-08-18 16:43 -------- d-----w- c:\program files\lx_cats
          2009-10-14 09:34 . 2009-08-17 09:02 -------- d-----w- c:\documents and settings\laurent\Application Data\vlc
          2009-10-14 07:38 . 2009-08-17 22:34 -------- d-----w- c:\documents and settings\laurent\Application Data\dvdcss
          2009-09-30 20:12 . 2009-08-17 14:16 -------- d-----w- c:\documents and settings\laurent\Application Data\AdobeUM
          2009-09-27 09:33 . 2009-08-16 11:20 -------- d--h--w- c:\program files\InstallShield Installation Information
          2009-09-27 09:20 . 2009-08-16 12:58 25736 ----a-w- c:\documents and settings\laurent\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
          2009-09-10 12:54 . 2009-08-17 17:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
          2009-09-10 12:53 . 2009-08-17 17:14 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
          2009-08-31 13:00 . 2009-08-31 13:00 -------- d-----w- c:\program files\Ubi Soft
          2009-08-25 19:46 . 2009-08-25 19:46 -------- d-----w- c:\documents and settings\laurent\Application Data\DAEMON Tools Pro
          2009-08-25 19:30 . 2009-08-25 19:25 -------- d-----w- c:\documents and settings\laurent\Application Data\DAEMON Tools Lite
          2009-08-25 19:30 . 2009-08-25 19:30 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
          2009-08-25 19:30 . 2009-08-25 19:30 -------- d-----w- c:\program files\DAEMON Tools Toolbar
          2009-08-25 19:25 . 2009-08-25 19:25 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
          2009-08-23 23:19 . 2009-08-23 23:20 411368 ----a-w- c:\windows\system32\deploytk.dll
          2009-08-23 23:19 . 2009-08-23 23:19 -------- d-----w- c:\program files\Java
          2009-08-22 17:04 . 2009-08-22 13:38 -------- d-----w- c:\program files\Fichiers communs\Panda Software
          2009-08-22 16:41 . 2009-08-18 16:41 -------- d-----w- c:\program files\Abbyy FineReader 6.0 Sprint
          2009-08-22 15:45 . 2009-08-18 16:42 -------- d-----w- c:\program files\Lexmark 3400 Series
          2009-08-22 13:59 . 2009-08-22 13:59 0 ----a-w- c:\windows\system32\drivers\wnmsav.dat
          2009-08-22 13:45 . 2001-08-28 12:00 71248 ----a-w- c:\windows\system32\perfc00C.dat
          2009-08-22 13:45 . 2001-08-28 12:00 458230 ----a-w- c:\windows\system32\perfh00C.dat
          2009-08-22 12:38 . 2009-08-20 14:44 -------- d-----w- c:\documents and settings\laurent\Application Data\LG Electronics
          2009-08-20 14:50 . 2009-08-20 14:50 -------- d-----w- c:\program files\LG Electronics
          2009-08-20 09:52 . 2009-08-20 09:52 -------- d-----w- c:\program files\Sierra On-Line
          2009-08-19 06:45 . 2009-08-19 06:45 -------- d-----w- c:\documents and settings\laurent\Application Data\FaxCtr
          2009-08-18 16:45 . 2009-08-18 16:42 -------- d-----w- c:\program files\Lexmark Toolbar
          2009-08-18 16:43 . 2009-08-18 16:42 -------- d-----w- c:\program files\Lexmark Fax Solutions
          2009-08-18 16:42 . 2009-08-18 16:42 -------- d-----w- c:\documents and settings\All Users\Application Data\FaxCtr
          2009-08-17 17:14 . 2009-08-17 17:14 -------- d-----w- c:\documents and settings\laurent\Application Data\Malwarebytes
          2009-08-17 17:14 . 2009-08-17 17:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
          2009-08-17 17:11 . 2009-08-17 17:11 -------- d-----w- c:\program files\NVIDIA Corporation
          2009-08-17 17:11 . 2009-08-17 17:11 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
          2009-08-17 17:06 . 2009-08-17 17:06 -------- d-----w- c:\program files\SystemRequirementsLab
          2009-08-17 14:37 . 2009-08-17 14:37 -------- d-----w- c:\documents and settings\laurent\Application Data\Media Player Classic
          2009-08-17 14:12 . 2009-08-17 14:12 -------- d-----w- c:\program files\Fichiers communs\Adobe
          2009-08-17 11:23 . 2009-08-17 11:19 909 ----a-w- c:\windows\eReg.dat
          2009-08-17 10:09 . 2009-08-17 10:09 -------- d-----w- c:\program files\Fichiers communs\xing shared
          2009-08-17 10:09 . 2009-08-16 12:32 -------- d-----w- c:\program files\Fichiers communs\Real
          2009-08-17 08:40 . 2009-08-17 08:40 -------- d-----w- c:\documents and settings\laurent\Application Data\Lavasoft
          2009-08-16 11:29 . 2009-08-16 11:29 315392 ----a-w- c:\windows\HideWin.exe
          2009-08-16 09:59 . 2009-08-16 09:59 21892 ----a-w- c:\windows\system32\emptyregdb.dat
          .

          ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          .
          *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
          REGEDIT4

          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-08-16 39408]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-08-16 122368]
          "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
          "nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2009-07-08 1657376]
          "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-07-14 13877248]
          "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-07-14 86016]
          "LXCYCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCYtime.dll" [2006-02-24 65536]
          "Antivirus Protection"="c:\windows\system32\avprot.exe" [2009-10-14 38912]

          [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
          "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-13 15360]

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
          "EnableFirewall"= 0 (0x0)

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
          "c:\\Program Files\\OrangeHSS\\Connectivity\\ConnectivityManager.exe"=
          "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
          "%windir%\\system32\\sessmgr.exe"=
          "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
          "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
          "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
          "c:\\WINDOWS\\system32\\avprot.exe"=

          R3 lxcy_device;lxcy_device;c:\windows\system32\lxcycoms.exe -service --> c:\windows\system32\lxcycoms.exe -service [?]
          .
          .
          ------- Examen supplémentaire -------
          .
          uStart Page = hxxp://www.orange.fr/bin/frame.cgi?u=https%3A//espaceclient2.orange.fr/nextecare/nextecare.do
          uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
          DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
          DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
          DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
          DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
          DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
          FF - ProfilePath - c:\documents and settings\laurent\Application Data\Mozilla\Firefox\Profiles\l1wydwly.default\
          FF - prefs.js: browser.startup.homepage - hxxp://www.orange.fr/
          FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
          FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
          .
          - - - - ORPHELINS SUPPRIMES - - - -

          AddRemove-DAEMON Tools Toolbar - c:\program files\DAEMON Tools Toolbar\uninst.exe
          AddRemove-eMule - c:\program files\eMule\Uninstall.exe
          AddRemove-fwgxh - c:\documents and settings\laurent\local settings\application data\fwgxh.exe
          AddRemove-Xilisoft 3GP Video Converter - c:\3gp video converter\Uninstall.exe

          **************************************************************************

          catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2009-10-15 21:23
          Windows 5.1.2600 Service Pack 3 NTFS

          Recherche de processus cachés ...

          Recherche d'éléments en démarrage automatique cachés ...

          HKLM\Software\Microsoft\Windows\CurrentVersion\Run
          LXCYCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCYtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

          Recherche de fichiers cachés ...

          Scan terminé avec succès
          Fichiers cachés: 0

          **************************************************************************
          .
          --------------------- CLES DE REGISTRE BLOQUEES ---------------------

          [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Reinstall\:ôwjY*]
          "DisplayName"="???\18?\11\09"
          "DeviceDesc"="???\18?\11\09"
          "ProviderName"="???\11?\17?\11??"
          "MFG"="???????"
          "ReinstallString"=".10.1000.7"
          "DeviceInstanceIds"=multi:"d:\\drivers\\chipset\\driver\\x86_x64\\sbdrv\\smbus\\smbusati.inf\00"
          .
          --------------------- DLLs chargées dans les processus actifs ---------------------

          - - - - - - - > 'explorer.exe'(6304)
          c:\windows\system32\ieframe.dll
          c:\windows\system32\eappprxy.dll
          c:\windows\system32\webcheck.dll
          .
          Heure de fin: 2009-10-15 21:24
          ComboFix-quarantined-files.txt 2009-10-15 19:24

          Avant-CF: 134 599 131 136 octets libres
          Après-CF: 134 603 689 984 octets libres

          WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
          [boot loader]
          timeout=2
          default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
          [operating systems]
          c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
          multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /fastdetect /NoExecute=OptIn

          191
          0
        2. cela fait 1heur que j'ai fait ce que vous m'avais dit et mon ordi va tres bien plu aucun soussi je voulais vous remercier pour votre aide bonne continuation et encore merci
          0
      2. bonjour,
        ce n'est pas fini !!!

        suis le reste dans l'ordre jusqu'au bout , sinon, ça va revenir à l'état ou il était !!!

        /!\ Utilisateur de Vista : Ne pas oublier de désactiver l’UAC juste le temps de désinfection de ton pc, il sera à réactiver plus tard :
        Tuto : https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

        Télécharge Malwarebytes' Anti-Malware:
        https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

        ou ici : http://www.malwarebytes.org/mbam/program/mbam-setup.exe

        . sur la page cliques sur Télécharger Malwarebyte's Anti-Malware
        . enregistres le sur le bureau
        /!\Utilisateur de Vista : Clique droit sur le logo de smithfarudfix, « exécuter en tant qu’Administrateur »

        . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
        . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
        . si le pare-feu demande l'autorisation de se connecter pour malwarebytes, acceptes
        . Une fois la mise à jour terminé
        . rend-toi dans l'onglet, Recherche
        . Sélectionnes Exécuter un examen complet
        . Cliques sur Rechercher
        . Le scan démarre.
        . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
        . Cliques sur Ok pour poursuivre.
        . Si des malwares ont été détectés, cliques sur Afficher les résultats
        . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
        . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
        . rends toi dans l'onglet rapport/log
        . tu cliques dessus pour l'afficher une fois affiché
        . tu cliques sur edition en haut du boc notes,et puis sur sélectionner tous
        . tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
        . tu cliques droit dans le cadre de la reponse et coller

        Si tu as besoin d'aide regarde ce tutoriel :
        https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

        N'oublie pas de me poster son rapport

        télécharges Ccleaner à partir de cette adresses

        https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/

        .enregistres le sur le bureau
        .double-cliques sur le fichier pour lancer l'installation
        /!\Utilisateur de Vista : Clique droit sur le logo de smithfarudfix, « exécuter en tant qu’Administrateur »

        .sur la fenêtre de l'installation langage bien choisir français et OK
        .cliques sur suivant
        .lis la licence et j'accepte
        .cliques sur suivant
        .la tu ne gardes de coché que mettre un raccourci sur le bureau et puis contrôler automatiquement les mises à jour de Ccleaner
        .cliques sur intaller
        .cliques sur fermer
        .double-cliques sur l'icône de Ccleaner pour l'ouvrir
        .une fois ouvert tu cliques sur option et puis avancé
        .tu décoches effacer uniquement les fichiers, du dossier temp de windows plus vieux que 48 heures
        .cliques sur nettoyeur
        .cliques sur windows et dans la colonne avancé
        .cochesla première case vieilles données du perfetch que celle-la ce qui te donnes la case vielles données du perfetch et la case avancé qui c'est coché automatiquement mais que celle-la
        .cliques sur analyse une fois l'analyse terminé
        .cliques sur lancer le nettoyage et sur la demande de confirmation OK il vas falloir que tu le refasses une autre fois une fois fini vériffis en appuiant de nouveau sur analyse pour être sur qu'il n'y est plus rien
        .cliques maintenant sur registre et puis sur rechercher les erreurs
        .laisses tout cochées et cliques sur réparrer les erreurs sélectionnées
        .il te demande de sauvegarder OUI
        .tu lui donnes un nom pour pouvoir la retrouver et enregistre
        .cliques sur corriger toutes les erreurs sélectionnées et sur la demande de confirmation OK
        .il supprime et fermer tu vériffis en relancant rechercher les erreurs
        .tu retournes dans option et tu recoches la case effacer uniquement les fichiers, du dossier temp de windows plus vieux que 48 heures et sur nettoyeur, windows sous avancé tu décoches la première case vieilles données du perfetch
        .tu peux fermer Ccleaner

        pour aider si besion tutoriel: https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php

        ou plus ici: http://www.lescofofides.fr/forum/viewtopic.php?f=30&t=96

        on verra la suite une fois que j'ai le rapport deMBAM et des nouvelles de ton pc

        bonne journée ;-)
        0
        1. bonjour effectvement ce matin en demarent mon ordi j'ai pu voir que j'avais encore mon probleme et j'ai vu votre message donc voici le raport de Malwarebytes'

          Malwarebytes' Anti-Malware 1.41
          Version de la base de données: 2977
          Windows 5.1.2600 Service Pack 3

          18/10/2009 11:06:47
          mbam-log-2009-10-18 (11-06-47).txt

          Type de recherche: Examen complet (A:\|C:\|D:\|E:\|G:\|)
          Eléments examinés: 184318
          Temps écoulé: 32 minute(s), 9 second(s)

          Processus mémoire infecté(s): 0
          Module(s) mémoire infecté(s): 0
          Clé(s) du Registre infectée(s): 0
          Valeur(s) du Registre infectée(s): 0
          Elément(s) de données du Registre infecté(s): 0
          Dossier(s) infecté(s): 0
          Fichier(s) infecté(s): 0

          Processus mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Module(s) mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Clé(s) du Registre infectée(s):
          (Aucun élément nuisible détecté)

          Valeur(s) du Registre infectée(s):
          (Aucun élément nuisible détecté)

          Elément(s) de données du Registre infecté(s):
          (Aucun élément nuisible détecté)

          Dossier(s) infecté(s):
          (Aucun élément nuisible détecté)

          Fichier(s) infecté(s):
          (Aucun élément nuisible détecté)
          0
          1. bonjour,
            la suite avec ccliner, puis reposte moi un autre rapport RSIT,
            tu n'auras qu'un seul rapport log.txt, donc pas de panique !!!
            merci
            0
            1. Malwarebytes' Anti-Malware 1.41
              Version de la base de données: 2977
              Windows 5.1.2600 Service Pack 3

              18/10/2009 13:53:17
              mbam-log-2009-10-18 (13-53-17).txt

              Type de recherche: Examen complet (A:\|C:\|D:\|E:\|G:\|)
              Eléments examinés: 183112
              Temps écoulé: 31 minute(s), 43 second(s)

              Processus mémoire infecté(s): 0
              Module(s) mémoire infecté(s): 0
              Clé(s) du Registre infectée(s): 0
              Valeur(s) du Registre infectée(s): 0
              Elément(s) de données du Registre infecté(s): 0
              Dossier(s) infecté(s): 0
              Fichier(s) infecté(s): 0

              Processus mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Module(s) mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Clé(s) du Registre infectée(s):
              (Aucun élément nuisible détecté)

              Valeur(s) du Registre infectée(s):
              (Aucun élément nuisible détecté)

              Elément(s) de données du Registre infecté(s):
              (Aucun élément nuisible détecté)

              Dossier(s) infecté(s):
              (Aucun élément nuisible détecté)

              Fichier(s) infecté(s):
              (Aucun élément nuisible détecté)
              0
              1. Double clique sur RSIT.exe sur ton bureau pour lancer l'outil.
                Clique sur ' continue ' à l'écran Disclaimer.
                Si l'outil HIjackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.
                Une fois le scan fini, 1 rapport va apparaître. Poste le contenu . Il se trouve sur c :
                (log.txt)
                (CTRL+A Pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)
                0
                1. Edit, le message est passé en doublon,
                  bref, il faut faire un RSIT
                  merci
                  0
                  1. Logfile of random's system information tool 1.06 (written by random/random)
                    Run by laurent at 2009-10-18 14:01:46
                    Microsoft Windows XP Professionnel
                    System drive C: has 126 GB (53%) free of 238 GB
                    Total RAM: 2046 MB (62% free)

                    Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 14:01:53, on 18/10/2009
                    Platform: Windows XP SP3 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                    Boot mode: Normal

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\SYSTEM32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\System32\nvsvc32.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\lxcycoms.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\explorer.exe
                    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                    C:\Program Files\Windows Live\Contacts\wlcomm.exe
                    C:\Program Files\Internet Explorer\IEXPLORE.EXE
                    C:\Program Files\Internet Explorer\IEXPLORE.EXE
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\Documents and Settings\laurent\Mes documents\telechargement\RSIT.exe
                    C:\Program Files\trend micro\laurent.exe

                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail?u=https%253A//espaceclient2.orange.fr/nextecare/nextecare.do
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                    R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
                    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
                    O2 - BHO: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
                    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
                    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
                    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                    O3 - Toolbar: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
                    O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
                    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                    O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /install
                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                    O4 - HKLM\..\Run: [LXCYCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCYtime.dll,_RunDLLEntry@16
                    O4 - HKLM\..\Run: [Antivirus Protection] C:\WINDOWS\system32\avprot.exe
                    O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
                    O4 - HKLM\..\RunOnce: [WMC_0] C:\WINDOWS\system32\regsvr32.exe /s "C:\WINDOWS\system32\mp4sds32.ax"
                    O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
                    O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                    O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra button: InterCasino France - {30C66393-FEF3-4758-BA00-803E3ABC88A2} - http://france.intercasino.com/ (file missing) (HKCU)
                    O9 - Extra 'Tools' menuitem: InterCasino France - {30C66393-FEF3-4758-BA00-803E3ABC88A2} - http://france.intercasino.com/ (file missing) (HKCU)
                    O15 - Trusted Zone: http://*.mappy.com
                    O15 - Trusted Zone: http://*.orange.fr
                    O15 - Trusted Zone: http://rw.search.ke.voila.fr
                    O15 - Trusted Zone: http://orange.weborama.fr
                    O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - https://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
                    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                    O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
                    O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                    O23 - Service: lxcy_device - - C:\WINDOWS\system32\lxcycoms.exe
                    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                    0
                    1. quel est le nom de ton antivirus?
                      0
                      1. je pense que c universal101.com vu que c des page portant ce mon qui souvre toute les 2min ?
                        0
                        1. ce qu'il me semblait aussi :

                          •Télécharge Antivir en Francais : http://www.commentcamarche.net/telecharger/telecharger-55-antivir

                          Ou ici :
                          https://www.01net.com/telecharger/windows/Securite/antivirus-antitrojan/fiches/13198.html

                          •Configuration de Antivir :

                          clic droit sur son icône dans la barre des taches et sélectionner Configurer Antivir.

                          cocher la case : Mode Expert( en haut à gauche de la fenêtre)..

                          => Cliquer sur Scanner dans le volet de gauche :

                          > Dans "Fichiers" sélectionner Tous les fichiers.

                          > Dans procédure de recherche, cocher Autoriser l'arrêt, et dans "priorité scanner" sélectionner Moyen.

                          > Dans "Autres réglages" cocher toutes les cases.

                          NE SURTOUT PAS OUBLIER LA RECHERCHE DES ROOTKIT QUI EST TRES IMPORTANTE !

                          => Cliquer sur "Recherche" dans le volet de gauche et appliquer les mêmes paramètres que précédemment.

                          => Dérouler "Recherche" en cliquant sur le +. Cliquer sur "Heuristique" :

                          > Cocher "Heuristique de MacroVirus" et "Heuristique fichier Win32" avec degré d'indentification MOYEN !

                          => Dans le volet de gauche, dérouler "Guard" :
                          coche : contrôler pendant la lecture et l’écriture, puis à côté : tous les fichiers.
                          aide en images :
                          https://www.commentcamarche.net/faq/16831-tutoriel-configuration-optimale-d-antivir-personal#2-la-configuration

                          fais une mise à jour et lance un scan complet de ton pc, poste son rapport en copier coller sur ton prochain message
                          merci
                          0