Restauration système, écran noir, explorer.ex

Résolu
Bonjour,

Depuis 2 semaines je lutte avec mon pc (vista), il plantait (impossible d'ouvrir des fichiers). Alors on m'a conseillé de restaurer mon système, après cette restauration je n'arrivais plus à accédé à mon bureau (écran noir), alors j'ai fait une autre restauration qui celle la ne fonctionnait pas.

Alors j'ai de-nouveau fait une restauration encore plus ancienne. Celle la fonctionnait très bien, à part que l'écran était noir au démarrage, j'ai arrête le processus explorer.exe et ouvert un nouveau pour avoir mon bureau (en même temps j'ai remarqué que que tout les processus ne sont pas ouverts au démarrage).

Ensuite tout allait bien mais je me suis dit que mon pc devait etre infecté, alors j'ai lancé un scan avec un antimalware, j'ai 8 fichiers infectés. Mais depuis je n'arrive plus à ouvrir certain fichier et je suis tout les temps obligé de faire une nouvelle tâche (explorer.exe) pour avoir mon bureau. (je ne pense pas qu'une nouvelle restauration soit nécessaire, car celle que j'ai effectuée, à cette date mon pc fonctionnait normalement).

Alors la je perdu, je pense que mon pc est infecté mais je ne sais pas comment y remédier. Pouvez-vous m'aider ?

46 réponses

Résumé de la discussion

Le problème central porte sur un PC Windows Vista qui plante et affiche un écran noir après des restaurations système, obligeant à relancer explorer.exe pour accéder au bureau et gérer des processus manquants au démarrage. Plusieurs recommandations clés ont émergé, notamment l'exécution de Malwarebytes en mode sans échec pour éliminer les malwares et un nettoyage approfondi ensuite en mode normal. Des éléments supplémentaires indiquent l'utilisation de ComboFix et l'identification d’outils de sécurité désactivés, mais la solution recommandée reste le nettoyage après démarrage en mode sans échec. En outre, l'historique d'extensions et les services d'antivirus désactivés peuvent être source de redémarrages répétés et nécessitent une vérification des programmes de démarrage et des tâches planifiées.

Bobot (l’IA à votre service)
  1. bonjour c sest avec malewerebite que vous avez scanner
    0
    1. Non, avec emsisoft anti-malware. Car je n'arrive pas à lancer malwarebytes' (il est constament en chargement, c'est le même problème que j'avais avant mes restaurations).
      0
  2. Faite un scan avec malwaresbytes antimalwares ensuite installer microsoft essential security
    attention desinstaller avant tout les autres antivirus que vous avez
    0
    1. Ok ! Mais je n'arrive pas à lancer malwaresbytes antimalwares, il est toujours en chargement quand je double clic dessus. Et si je le lance en mode sans échec il n'y à aucun intérêt, je pense, non ?
      0
    2. Lancer malwaresbytes antimalwares en mode sans echec supprime les malwares donc pas de soucis supprimer d'abord un minimum en mode sans echec après repasser en mode normal pour approfondie le nettoyage
      0
  3. salut

    ▶ Télécharge TDSSKiller

    ▶ Lance le ( Utilisateurs de vista/Seven -> Clic droit puis " Exécuter en tant que........... " )

    L'outil va télécharger automatiquement la dernière version de TDSSKiller puis lancera une analyse.

    Patiente pendant le scan. A la fin de l'analyse, appuies sur une touche. Un rapport va s'ouvrir.

    ▶ Copie/Colle son contenu dans ta prochaine réponse.

    Note : Le rapport se trouve également sous C:\tdsskiller.txt.
    0
    1. 2011/01/28 14:47:14.0395 TDSS rootkit removing tool 2.4.15.0 Jan 22 2011 19:37:53
      2011/01/28 14:47:14.0395 ================================================================================
      2011/01/28 14:47:14.0395 SystemInfo:
      2011/01/28 14:47:14.0396
      2011/01/28 14:47:14.0396 OS Version: 6.0.6002 ServicePack: 2.0
      2011/01/28 14:47:14.0396 Product type: Workstation
      2011/01/28 14:47:14.0396 ComputerName: PC-DE-CLAUDE
      2011/01/28 14:47:14.0397 UserName: Claude
      2011/01/28 14:47:14.0397 Windows directory: C:\Windows
      2011/01/28 14:47:14.0397 System windows directory: C:\Windows
      2011/01/28 14:47:14.0397 Processor architecture: Intel x86
      2011/01/28 14:47:14.0397 Number of processors: 2
      2011/01/28 14:47:14.0397 Page size: 0x1000
      2011/01/28 14:47:14.0397 Boot type: Normal boot
      2011/01/28 14:47:14.0397 ================================================================================
      2011/01/28 14:47:19.0928 Initialize success
      2011/01/28 14:47:26.0909 ================================================================================
      2011/01/28 14:47:26.0909 Scan started
      2011/01/28 14:47:26.0909 Mode: Manual;
      2011/01/28 14:47:26.0909 ================================================================================
      2011/01/28 14:47:28.0538 Accelerometer (3b10711ad8656c097e0d16a41b29c54c) C:\Windows\system32\DRIVERS\Accelerometer.sys
      2011/01/28 14:47:28.0696 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
      2011/01/28 14:47:28.0810 adiusbaw (5609b325404f0bb0eabec05f1bc62116) C:\Windows\system32\DRIVERS\adiusbaw.sys
      2011/01/28 14:47:28.0944 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
      2011/01/28 14:47:29.0092 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
      2011/01/28 14:47:29.0158 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
      2011/01/28 14:47:29.0227 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
      2011/01/28 14:47:29.0345 AFD (a201207363aa900abf1a388468688570) C:\Windows\system32\drivers\afd.sys
      2011/01/28 14:47:29.0539 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
      2011/01/28 14:47:29.0650 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
      2011/01/28 14:47:30.0128 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
      2011/01/28 14:47:30.0554 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
      2011/01/28 14:47:31.0031 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
      2011/01/28 14:47:31.0544 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
      2011/01/28 14:47:31.0673 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\DRIVERS\amdk8.sys
      2011/01/28 14:47:31.0989 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
      2011/01/28 14:47:32.0195 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
      2011/01/28 14:47:32.0574 aswFsBlk (a0d86b8ac93ef95620420c7a24ac5344) C:\Windows\system32\drivers\aswFsBlk.sys
      2011/01/28 14:47:32.0926 aswMonFlt (bd9119468c32b7ecd1e0544d3f286a73) C:\Windows\system32\drivers\aswMonFlt.sys
      2011/01/28 14:47:33.0325 aswRdr (69823954bbd461a73d69774928c9737e) C:\Windows\system32\drivers\aswRdr.sys
      2011/01/28 14:47:33.0524 aswSP (7ecc2776638b04553f9a85bd684c3abf) C:\Windows\system32\drivers\aswSP.sys
      2011/01/28 14:47:33.0714 aswTdi (095ed820a926aa8189180b305e1bcfc9) C:\Windows\system32\drivers\aswTdi.sys
      2011/01/28 14:47:34.0231 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
      2011/01/28 14:47:34.0364 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
      2011/01/28 14:47:35.0274 BCM43XV (cf6a67c90951e3e763d2135dede44b85) C:\Windows\system32\DRIVERS\bcmwl6.sys
      2011/01/28 14:47:35.0465 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
      2011/01/28 14:47:35.0578 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
      2011/01/28 14:47:35.0854 bowser (74b442b2be1260b7588c136177ceac66) C:\Windows\system32\DRIVERS\bowser.sys
      2011/01/28 14:47:35.0933 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
      2011/01/28 14:47:35.0990 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
      2011/01/28 14:47:36.0474 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
      2011/01/28 14:47:36.0955 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
      2011/01/28 14:47:37.0408 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
      2011/01/28 14:47:37.0728 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
      2011/01/28 14:47:38.0049 BthEnum (da7b195275bda7f8fcf79b40e0f45dde) C:\Windows\system32\DRIVERS\BthEnum.sys
      2011/01/28 14:47:38.0391 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
      2011/01/28 14:47:38.0537 BthPan (5904efa25f829bf84ea6fb045134a1d8) C:\Windows\system32\DRIVERS\bthpan.sys
      2011/01/28 14:47:38.0670 BTHPORT (671134053d59e23704f08db19f11e10b) C:\Windows\system32\Drivers\BTHport.sys
      2011/01/28 14:47:38.0778 BTHUSB (93d7007e2c660dfcca6ae72622740b14) C:\Windows\system32\Drivers\BTHUSB.sys
      2011/01/28 14:47:39.0136 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
      2011/01/28 14:47:39.0239 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
      2011/01/28 14:47:39.0522 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\DRIVERS\circlass.sys
      2011/01/28 14:47:39.0718 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
      2011/01/28 14:47:40.0048 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
      2011/01/28 14:47:40.0347 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
      2011/01/28 14:47:40.0525 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
      2011/01/28 14:47:40.0848 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
      2011/01/28 14:47:40.0985 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
      2011/01/28 14:47:41.0339 DfsC (218d8ae46c88e82014f5d73d0236d9b2) C:\Windows\system32\Drivers\dfsc.sys
      2011/01/28 14:47:41.0482 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
      2011/01/28 14:47:41.0718 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
      2011/01/28 14:47:42.0167 DXGKrnl (5c7e2097b91d689ded7a6ff90f0f3a25) C:\Windows\System32\drivers\dxgkrnl.sys
      2011/01/28 14:47:42.0468 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
      2011/01/28 14:47:42.0712 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
      2011/01/28 14:47:42.0933 ELOADER (8dbfd1ed1ec1ee6c3977532912b18c21) C:\Windows\system32\Drivers\adildr.sys
      2011/01/28 14:47:43.0151 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
      2011/01/28 14:47:43.0488 enecir (4cd6b056c5fd9e97c06fe74c81479517) C:\Windows\system32\DRIVERS\enecir.sys
      2011/01/28 14:47:43.0805 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
      2011/01/28 14:47:44.0296 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
      2011/01/28 14:47:44.0511 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
      2011/01/28 14:47:44.0630 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
      2011/01/28 14:47:44.0904 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
      2011/01/28 14:47:45.0124 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
      2011/01/28 14:47:45.0414 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
      2011/01/28 14:47:45.0699 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
      2011/01/28 14:47:46.0017 fssfltr (d909075fa72c090f27aa926c32cb4612) C:\Windows\system32\DRIVERS\fssfltr.sys
      2011/01/28 14:47:46.0157 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
      2011/01/28 14:47:46.0371 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
      2011/01/28 14:47:46.0498 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys
      2011/01/28 14:47:46.0929 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
      2011/01/28 14:47:47.0183 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
      2011/01/28 14:47:47.0501 HidIr (d8df3722d5e961baa1292aa2f12827e2) C:\Windows\system32\DRIVERS\hidir.sys
      2011/01/28 14:47:47.0687 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
      2011/01/28 14:47:47.0988 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
      2011/01/28 14:47:48.0355 hpdskflt (24f3f496c18efc234777723a67a85f81) C:\Windows\system32\DRIVERS\hpdskflt.sys
      2011/01/28 14:47:48.0511 HpqKbFiltr (35956140e686d53bf676cf0c778880fc) C:\Windows\system32\DRIVERS\HpqKbFiltr.sys
      2011/01/28 14:47:48.0596 HpqRemHid (115c0933b3ed51dfbec4449348c8065b) C:\Windows\system32\DRIVERS\HpqRemHid.sys
      2011/01/28 14:47:49.0054 HSFHWAZL (46d67209550973257601a533e2ac5785) C:\Windows\system32\DRIVERS\VSTAZL3.SYS
      2011/01/28 14:47:49.0459 HSF_DPV (ec36f1d542ed4252390d446bf6d4dfd0) C:\Windows\system32\DRIVERS\VSTDPV3.SYS
      2011/01/28 14:47:49.0930 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
      2011/01/28 14:47:50.0479 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
      2011/01/28 14:47:50.0624 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
      2011/01/28 14:47:51.0051 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
      2011/01/28 14:47:51.0550 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
      2011/01/28 14:47:52.0383 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
      2011/01/28 14:47:52.0884 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
      2011/01/28 14:47:53.0073 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
      2011/01/28 14:47:53.0493 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
      2011/01/28 14:47:53.0691 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
      2011/01/28 14:47:54.0049 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
      2011/01/28 14:47:54.0275 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
      2011/01/28 14:47:54.0485 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
      2011/01/28 14:47:54.0831 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
      2011/01/28 14:47:54.0971 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
      2011/01/28 14:47:55.0280 JMCR (dedb6cc1b166928a8f3f68def1766db0) C:\Windows\system32\DRIVERS\jmcr.sys
      2011/01/28 14:47:55.0516 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
      2011/01/28 14:47:55.0715 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys
      2011/01/28 14:47:55.0894 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
      2011/01/28 14:47:56.0131 Lbd (b7c19ec8b0dd7efa58ad41ffeb8b8cda) C:\Windows\system32\DRIVERS\Lbd.sys
      2011/01/28 14:47:56.0255 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
      2011/01/28 14:47:56.0480 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
      2011/01/28 14:47:56.0520 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
      2011/01/28 14:47:56.0569 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
      2011/01/28 14:47:56.0670 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
      2011/01/28 14:47:56.0886 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
      2011/01/28 14:47:57.0053 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
      2011/01/28 14:47:57.0407 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
      2011/01/28 14:47:57.0673 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
      2011/01/28 14:47:57.0921 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
      2011/01/28 14:47:58.0383 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
      2011/01/28 14:47:58.0583 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
      2011/01/28 14:47:58.0741 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
      2011/01/28 14:47:59.0006 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
      2011/01/28 14:47:59.0108 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
      2011/01/28 14:47:59.0488 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
      2011/01/28 14:47:59.0778 mrxsmb (454341e652bdf5e01b0f2140232b073e) C:\Windows\system32\DRIVERS\mrxsmb.sys
      2011/01/28 14:47:59.0927 mrxsmb10 (2a4901aff069944fa945ed5bbf4dcde3) C:\Windows\system32\DRIVERS\mrxsmb10.sys
      2011/01/28 14:48:00.0495 mrxsmb20 (28b3f1ab44bdd4432c041581412f17d9) C:\Windows\system32\DRIVERS\mrxsmb20.sys
      2011/01/28 14:48:00.0850 msahci (5457dcfa7c0da43522f4d9d4049c1472) C:\Windows\system32\drivers\msahci.sys
      2011/01/28 14:48:01.0154 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
      2011/01/28 14:48:01.0520 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
      2011/01/28 14:48:01.0610 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
      2011/01/28 14:48:01.0953 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
      2011/01/28 14:48:02.0021 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
      2011/01/28 14:48:02.0189 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
      2011/01/28 14:48:02.0344 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
      2011/01/28 14:48:02.0541 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
      2011/01/28 14:48:02.0760 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
      2011/01/28 14:48:03.0134 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
      2011/01/28 14:48:03.0449 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
      2011/01/28 14:48:03.0787 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
      2011/01/28 14:48:04.0098 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
      2011/01/28 14:48:04.0264 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
      2011/01/28 14:48:04.0369 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
      2011/01/28 14:48:04.0492 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
      2011/01/28 14:48:04.0656 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
      2011/01/28 14:48:04.0836 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
      2011/01/28 14:48:05.0509 NETw5v32 (8de67bd902095a13329fd82c85a1fa09) C:\Windows\system32\DRIVERS\NETw5v32.sys
      2011/01/28 14:48:05.0757 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
      2011/01/28 14:48:06.0146 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
      2011/01/28 14:48:06.0424 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
      2011/01/28 14:48:07.0008 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
      2011/01/28 14:48:08.0120 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
      2011/01/28 14:48:08.0483 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
      2011/01/28 14:48:08.0892 NVENETFD (1657f3fbd9061526c14ff37e79306f98) C:\Windows\system32\DRIVERS\nvm60x32.sys
      2011/01/28 14:48:09.0270 NVHDA (d2f4c4b22969236382ca853b8daa2d4e) C:\Windows\system32\drivers\nvhda32v.sys
      2011/01/28 14:48:10.0027 nvlddmkm (24000b817cc84ac1555f41929879af5a) C:\Windows\system32\DRIVERS\nvlddmkm.sys
      2011/01/28 14:48:11.0013 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
      2011/01/28 14:48:11.0113 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
      2011/01/28 14:48:11.0989 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
      2011/01/28 14:48:13.0079 ohci1394 (6f310e890d46e246e0e261a63d9b36b4) C:\Windows\system32\DRIVERS\ohci1394.sys
      2011/01/28 14:48:13.0443 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
      2011/01/28 14:48:13.0592 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
      2011/01/28 14:48:13.0931 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
      2011/01/28 14:48:14.0073 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
      2011/01/28 14:48:14.0295 pciide (fc175f5ddab666d7f4d17449a547626f) C:\Windows\system32\drivers\pciide.sys
      2011/01/28 14:48:14.0511 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
      2011/01/28 14:48:15.0043 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
      2011/01/28 14:48:15.0537 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
      2011/01/28 14:48:15.0658 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys
      2011/01/28 14:48:16.0079 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
      2011/01/28 14:48:16.0375 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
      2011/01/28 14:48:16.0566 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
      2011/01/28 14:48:16.0893 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
      2011/01/28 14:48:17.0055 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
      2011/01/28 14:48:17.0321 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
      2011/01/28 14:48:17.0536 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
      2011/01/28 14:48:17.0794 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
      2011/01/28 14:48:18.0097 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
      2011/01/28 14:48:18.0310 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
      2011/01/28 14:48:18.0507 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys
      2011/01/28 14:48:18.0721 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
      2011/01/28 14:48:19.0015 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
      2011/01/28 14:48:19.0315 RFCOMM (34cc78c06587718c2ad6d3aa83b1f072) C:\Windows\system32\DRIVERS\rfcomm.sys
      2011/01/28 14:48:19.0610 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
      2011/01/28 14:48:19.0770 RTL8169 (7157e70a90cce49deb8885d23a073a39) C:\Windows\system32\DRIVERS\Rtlh86.sys
      2011/01/28 14:48:20.0211 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
      2011/01/28 14:48:20.0388 sdbus (126ea89bcc413ee45e3004fb0764888f) C:\Windows\system32\DRIVERS\sdbus.sys
      2011/01/28 14:48:20.0766 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
      2011/01/28 14:48:21.0073 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
      2011/01/28 14:48:21.0303 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
      2011/01/28 14:48:21.0531 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
      2011/01/28 14:48:21.0739 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys
      2011/01/28 14:48:21.0950 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
      2011/01/28 14:48:22.0162 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys
      2011/01/28 14:48:22.0310 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
      2011/01/28 14:48:22.0564 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
      2011/01/28 14:48:22.0678 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
      2011/01/28 14:48:22.0825 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
      2011/01/28 14:48:23.0174 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
      2011/01/28 14:48:23.0430 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
      2011/01/28 14:48:23.0590 sptd (71e276f6d189413266ea22171806597b) C:\Windows\system32\Drivers\sptd.sys
      2011/01/28 14:48:23.0590 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: 71e276f6d189413266ea22171806597b
      2011/01/28 14:48:23.0621 sptd - detected Locked file (1)
      2011/01/28 14:48:24.0040 srv (ff3cbc13db84d81f56931bc922cc37c4) C:\Windows\system32\DRIVERS\srv.sys
      2011/01/28 14:48:24.0372 srv2 (d15959d9f69f0d39a0153e9c244f20dd) C:\Windows\system32\DRIVERS\srv2.sys
      2011/01/28 14:48:24.0524 srvnet (faa0d553a49e85008c6bb3781987c574) C:\Windows\system32\DRIVERS\srvnet.sys
      2011/01/28 14:48:24.0728 STHDA (e69a606872650b46de54ec15dcc93529) C:\Windows\system32\DRIVERS\stwrt.sys
      2011/01/28 14:48:25.0074 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
      2011/01/28 14:48:25.0337 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
      2011/01/28 14:48:25.0537 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
      2011/01/28 14:48:25.0691 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
      2011/01/28 14:48:26.0039 SynTP (067cb9d745407a8c1b26e89a6a2ce152) C:\Windows\system32\DRIVERS\SynTP.sys
      2011/01/28 14:48:26.0419 Tcpip (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\drivers\tcpip.sys
      2011/01/28 14:48:26.0702 Tcpip6 (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\DRIVERS\tcpip.sys
      2011/01/28 14:48:28.0375 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
      2011/01/28 14:48:28.0458 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
      2011/01/28 14:48:28.0523 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
      2011/01/28 14:48:28.0649 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
      2011/01/28 14:48:28.0765 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
      2011/01/28 14:48:28.0927 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
      2011/01/28 14:48:29.0111 TuneUpUtilitiesDrv (f2107c9d85ec0df116939ccce06ae697) C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys
      2011/01/28 14:48:29.0213 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
      2011/01/28 14:48:29.0355 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
      2011/01/28 14:48:29.0538 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
      2011/01/28 14:48:29.0754 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
      2011/01/28 14:48:30.0070 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
      2011/01/28 14:48:30.0321 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
      2011/01/28 14:48:30.0402 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
      2011/01/28 14:48:30.0455 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
      2011/01/28 14:48:30.0536 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
      2011/01/28 14:48:30.0785 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
      2011/01/28 14:48:30.0890 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
      2011/01/28 14:48:31.0310 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
      2011/01/28 14:48:31.0520 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
      2011/01/28 14:48:31.0645 usbohci (7bdb7b0e7d45ac0402d78b90789ef47c) C:\Windows\system32\DRIVERS\usbohci.sys
      2011/01/28 14:48:31.0784 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
      2011/01/28 14:48:32.0082 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
      2011/01/28 14:48:32.0495 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
      2011/01/28 14:48:32.0801 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys
      2011/01/28 14:48:33.0146 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
      2011/01/28 14:48:33.0380 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
      2011/01/28 14:48:33.0440 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
      2011/01/28 14:48:33.0596 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
      2011/01/28 14:48:33.0701 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
      2011/01/28 14:48:33.0780 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
      2011/01/28 14:48:33.0986 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
      2011/01/28 14:48:34.0326 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
      2011/01/28 14:48:34.0638 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
      2011/01/28 14:48:34.0825 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
      2011/01/28 14:48:34.0932 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
      2011/01/28 14:48:34.0984 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
      2011/01/28 14:48:35.0459 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
      2011/01/28 14:48:35.0717 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
      2011/01/28 14:48:36.0210 winachsf (5c7bdcf5864db00323fe2d90fa26a8a2) C:\Windows\system32\DRIVERS\VSTCNXT3.SYS
      2011/01/28 14:48:36.0555 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys
      2011/01/28 14:48:36.0848 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys
      2011/01/28 14:48:37.0048 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
      2011/01/28 14:48:37.0314 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
      2011/01/28 14:48:37.0511 ================================================================================
      2011/01/28 14:48:37.0512 Scan finished
      2011/01/28 14:48:37.0512 ================================================================================
      2011/01/28 14:48:37.0533 Detected object count: 1
      2011/01/28 14:49:02.0734 Locked file(sptd) - User select action: Skip
      0
  4. si tu peut te servir de c cleanner fait une analyse et un reparage des erreurs
    0
    1. Je n'arrivais plus a rien faire, ni Ccleaner, ni Malwarebytes, ni TDSSKiller. Alors j'ai de nouveau fait une restauration de système, pour que mon pc fonctionne correctement. Et en effet j'ai attendu qu'il se rallume et tout marche. (Cela se passe exactement comme hier soir, donc si je ré-éteint l'ordinateur rien ne fonctionnera correctement). Je ne sais pas si j'arrive bien à me faire comprendre ?
      0
      1. Télécharge ici :OTL

        enregistre le sur ton Bureau.

        si tu as XP => double clique
        si tu as Vista ou windows 7 => clic droit "executer en tant que...."


        sur OTL.exe pour le lancer.

        ▶ Coche les 2 cases Lop et Purity

        ▶ Coche la case devant tous les utilisateurs

        ▶ règle age du fichier sur "60 jours"

        ▶ dans les 6 onglets de la moitié gauche , mets tout sur "tous"

        ne modifie pas ceci :

        "fichiers créés" et "fichiers Modifiés"


        ▶Clic sur Analyse.

        A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).

        Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\OTL.txt)

        ▶▶▶ NE LE POSTE PAS SUR LE FORUM (il est trop long)

        Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/

        ▶ Clique sur Parcourir et cherche le fichier ci-dessus.

        ▶ Clique sur Ouvrir.

        ▶ Clique sur "Cliquez ici pour déposer le fichier".

        juste au niveau du bouton , en fin de chargement du fichier , Un lien de cette forme apparaitra :

        http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

        ▶ Copie ce lien dans ta réponse.

        ▶▶ Tu feras la meme chose avec le "Extra.txt" qui logiquement sera aussi sur ton bureau.
        0
        1. J'ai lancé l'analyse de OTL. Il a planté, je l'ai relancé mais il replante au même endroit. Le programme "ne répond pas". Il plante à : " scanning service : wudfsvc... "
          0

      2. /!\ ATTENTION SUIVRE A LA LETTRE CES INDICATIONS/!\

        __________________________________________________________
        >Ce logiciel n'est à utiliser que prescrit par un helper qualifié et formé à l'outil.<
        >>>>>>>Ne pas utiliser en dehors de ce cas de figure : dangereux!<<<<<<<<
        =====================================================


        ▶ Surtout , pense à l'enregistrement à renommer Combofix en "ton prenom.exe" avant qu'il soit enregistré sur ton disque dur

        Telecharge ici : Combofix

        Avant d'utiliser ComboFix :

        Si tu utilises AVG, IL FAUT IMPERATIVEMENT LE DESINSTALLER avant d'utiliser Combofix car il peut causer des dégâts en interaction avec l'outil pouvant mener à la réinstallation totale du système.
        La simple désactivation du résident n'est pas suffisante.
        Télécharge le désinstalleur d'AVG sur ce lien : https://www.avg.com/fr-fr/avg-remover
        Choisis la version adéquate (32 ou 64 bits)/!\

        Les logiciels d'émulation de CD comme Daemon Tools peuvent gêner les outils de désinfection. Utilise Defogger pour les désactiver temporairement :

        ▶ Télécharge Defogger (de jpshortstuff) sur ton Bureau

        ▶ Lance le

        Une fenêtre apparait : clique sur "Disable"

        ▶ Fais redémarrer l'ordinateur si l'outil te le demande

        Note : Quand nous aurons terminé la désinfection, tu pourras réactiver ces logiciels en relançant Defogger et en cliquant sur "Re-enable"

        _________________________________________________________
        >> referme les fenêtres de tous les programmes en cours.
        >> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix,
        >>la protection en temps réel de ton Antivirus et de tes Antispywares,
        >>qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.

        °°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°


        si tu as XP => double clique
        si tu as Vista ou windows 7 => clic droit "executer en tant que...."


        sur combofix renommé

        ▶ !!!!!NE TOUCHE A RIEN PENDANT LE TRAVAIL DE COMBOFIX (SOURIS/CLAVIER.....)!!!!!

        ▶ n'oublie pas de reactiver la garde de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

        ▶▶ Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

        0
        1. Voici le résultat de Combofix :

          ComboFix 11-01-27.05 - Claude 28/01/2011 16:08:53.1.2 - x86
          Microsoft® Windows Vista(TM) Édition Familiale Premium 6.0.6002.2.1252.33.1036.18.3068.1802 [GMT 1:00]
          Lancé depuis: c:\users\Claude\Downloads\Claude.exe
          AV: avast! Antivirus *Disabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
          AV: Lavasoft Ad-Watch Live! Antivirus *Disabled/Updated* {DAAC1C79-1A96-9DFE-FC4C-6940214C33E6}
          SP: avast! Antivirus *Disabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
          SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {61CDFD9D-3CAC-9270-C6FC-52325ACB795B}
          SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
          .

          (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
          .

          c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013

          .
          ((((((((((((((((((((((((((((( Fichiers créés du 2010-12-28 au 2011-01-28 ))))))))))))))))))))))))))))))))))))
          .

          2011-01-28 15:21 . 2011-01-28 15:21 -------- d-----w- c:\users\Default\AppData\Local\temp
          2011-01-28 13:35 . 2010-11-10 04:33 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FB516652-497F-4421-B3D9-17B6A602DB5B}\mpengine.dll
          2011-01-28 12:48 . 2011-01-28 13:47 -------- d-----w- C:\tdsskiller
          2011-01-27 21:29 . 2011-01-27 21:34 -------- d-----w- c:\program files\Emsisoft Anti-Malware
          2011-01-27 21:23 . 2011-01-27 21:23 -------- d-----w- c:\users\Claude\AppData\Roaming\Malwarebytes
          2011-01-27 21:23 . 2011-01-27 21:23 -------- d-----w- c:\programdata\Malwarebytes
          2011-01-27 21:23 . 2011-01-28 13:11 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
          2011-01-27 20:55 . 2011-01-27 20:55 -------- d-----w- c:\program files\Macrovision Corporation
          2011-01-26 17:41 . 2011-01-26 17:41 -------- d-----w- c:\program files\Ad-Remover
          2011-01-06 13:44 . 2011-01-06 13:44 -------- d-----w- c:\program files\7-Zip
          2011-01-05 22:52 . 2011-01-05 22:52 -------- d-----w- c:\users\Claude\AppData\Local\networker
          2011-01-05 19:56 . 2011-01-05 19:56 -------- d-----w- c:\users\Claude\AppData\Roaming\OpenOffice.org
          2011-01-05 19:51 . 2011-01-05 19:51 -------- d-----w- c:\program files\JRE
          2011-01-05 19:51 . 2011-01-05 19:51 -------- d-----w- c:\program files\OpenOffice.org 3
          2011-01-05 19:36 . 2011-01-05 19:36 -------- d-----w- c:\users\Claude\AppData\Local\assembly
          2011-01-05 19:31 . 2011-01-28 13:33 -------- d-----w- c:\program files\Installer
          2011-01-05 19:31 . 2011-01-28 13:18 -------- d-----w- c:\windows\BackupIP
          2011-01-05 19:31 . 2010-12-16 16:03 11264 ------w- c:\windows\system32\Utils.dll
          2011-01-05 19:31 . 2010-01-20 23:58 197632 ------w- c:\windows\system32\Ionic.Zip.Reduced.dll
          2011-01-03 16:25 . 2011-01-03 16:45 -------- d-----w- c:\users\Claude\AppData\Roaming\FrostWire
          2011-01-03 16:24 . 2011-01-03 16:29 -------- d-----w- c:\program files\FrostWire

          .
          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          2011-01-13 08:47 . 2010-12-18 09:03 38848 ----a-w- c:\windows\avastSS.scr
          2011-01-13 08:47 . 2008-09-20 00:35 188216 ----a-w- c:\windows\system32\aswBoot.exe
          2011-01-13 08:41 . 2008-09-20 00:35 294608 ----a-w- c:\windows\system32\drivers\aswSP.sys
          2011-01-13 08:40 . 2008-09-20 00:35 47440 ----a-w- c:\windows\system32\drivers\aswTdi.sys
          2011-01-13 08:37 . 2008-09-20 00:35 23632 ----a-w- c:\windows\system32\drivers\aswRdr.sys
          2011-01-13 08:37 . 2008-09-20 00:35 51280 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
          2011-01-13 08:37 . 2008-09-20 00:35 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
          2010-11-18 18:44 . 2010-11-18 18:44 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
          2010-11-12 17:53 . 2010-05-06 21:53 472808 ----a-w- c:\windows\system32\deployJava1.dll
          2010-11-08 09:02 . 2009-10-31 00:59 98392 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
          2010-11-04 18:56 . 2010-12-17 17:43 345600 ----a-w- c:\windows\system32\wmicmiplugin.dll
          2010-11-04 18:55 . 2010-12-17 17:44 352768 ----a-w- c:\windows\system32\taskschd.dll
          2010-11-04 18:55 . 2010-12-17 17:43 270336 ----a-w- c:\windows\system32\taskcomp.dll
          2010-11-04 18:55 . 2010-12-17 17:44 601600 ----a-w- c:\windows\system32\schedsvc.dll
          2010-11-04 16:34 . 2010-12-17 17:43 171520 ----a-w- c:\windows\system32\taskeng.exe
          2010-11-02 06:01 . 2010-12-17 17:43 916480 ----a-w- c:\windows\system32\wininet.dll
          2010-11-02 05:57 . 2010-12-17 17:43 43520 ----a-w- c:\windows\system32\licmgr10.dll
          2010-11-02 05:57 . 2010-12-17 17:43 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
          2010-11-02 05:57 . 2010-12-17 17:43 71680 ----a-w- c:\windows\system32\iesetup.dll
          2010-11-02 05:57 . 2010-12-17 17:43 109056 ----a-w- c:\windows\system32\iesysprep.dll
          2010-11-02 05:01 . 2010-12-17 17:43 385024 ----a-w- c:\windows\system32\html.iec
          2010-11-02 04:26 . 2010-12-17 17:43 133632 ----a-w- c:\windows\system32\ieUnatt.exe
          2010-11-02 04:24 . 2010-12-17 17:43 1638912 ----a-w- c:\windows\system32\mshtml.tlb
          .

          ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          .
          *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
          REGEDIT4

          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
          "LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-02-26 2289664]
          "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
          "ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-10 218032]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-03-14 202032]
          "OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-11-01 554288]
          "hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-11-20 488752]
          "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-10-03 13826664]
          "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
          "avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2010-09-07 2838912]

          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
          "EnableUIADesktopToggle"= 0 (0x0)

          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
          "mixer1"=wdmaud.drv

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
          @="Service"

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\installer]
          2010-12-14 07:48 7168 ------w- c:\program files\Installer\lnetworker.exe

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
          2006-10-25 08:03 210472 ----a-w- c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe

          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
          "Microsoft Outlook"=c:\progra~1\MICROS~3\Office14\OUTLOOK.EXE /recycle

          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
          "HP Software Update"=c:\program files\Hp\HP Software Update\HPWuSchd2.exe
          "HP Health Check Scheduler"=c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
          "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
          "SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
          "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
          "QPService"="c:\program files\HP\QuickPlay\QPService.exe"

          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
          "DisableMonitoring"=dword:00000001

          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
          "DisableMonitoring"=dword:00000001

          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
          "DisableMonitoring"=dword:00000001

          R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
          R2 ELOADER;General Purpose USB Driver (adildr.sys);c:\windows\system32\Drivers\adildr.sys [2007-01-10 56088]
          R2 gupdate1ca110ffecaae6d;Service Google Update (gupdate1ca110ffecaae6d);c:\program files\Google\Update\GoogleUpdate.exe [2009-07-30 133104]
          R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-12-18 1389400]
          R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
          R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
          R3 WPFFontCache_v0400;Cache de police de Windows Presentation Foundation 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
          R4 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2008-09-20 717296]
          R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
          S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-09-08 64288]
          S1 aswSP;aswSP; [x]
          S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_e2247046\aestsrv.exe [2009-03-02 81920]
          S2 aswFsBlk;aswFsBlk; [x]
          S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-01-13 51280]
          S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2008-01-21 21504]
          S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2008-03-18 19456]
          S2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\SMINST\BLService.exe [2008-03-26 341328]
          S2 sdmBackupIP;Backup IP Network;c:\windows\BackupIP\service.exe [2010-12-16 8192]
          S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2010-06-14 1051976]
          S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
          S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [2008-01-24 52736]
          S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2008-04-11 84240]
          S3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-11-17 3668480]
          S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2009-06-26 66080]
          S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [2010-02-25 10064]

          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
          bthsvcs REG_MULTI_SZ BthServ
          LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
          HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
          UxTuneUp
          ezSharedSvc

          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
          2008-02-26 12:06 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
          .
          Contenu du dossier 'Tâches planifiées'

          2011-01-28 c:\windows\Tasks\Ad-Aware Update (Weekly).job
          - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-09-08 09:39]

          2011-01-28 c:\windows\Tasks\GlaryInitialize.job
          - c:\program files\Glary Utilities\initialize.exe [2010-06-27 08:01]

          2011-01-28 c:\windows\Tasks\Google Software Updater.job
          - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-07-30 12:17]

          2011-01-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
          - c:\program files\Google\Update\GoogleUpdate.exe [2009-07-30 12:19]

          2011-01-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
          - c:\program files\Google\Update\GoogleUpdate.exe [2009-07-30 12:19]

          2011-01-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1641100407-3025134362-3523676139-1000Core.job
          - c:\users\Claude\AppData\Local\Google\Update\GoogleUpdate.exe [2010-02-12 09:38]

          2011-01-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1641100407-3025134362-3523676139-1000UA.job
          - c:\users\Claude\AppData\Local\Google\Update\GoogleUpdate.exe [2010-02-12 09:38]

          2010-12-23 c:\windows\Tasks\HPCeeScheduleForClaude.job
          - c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2008-06-09 13:14]

          2011-01-28 c:\windows\Tasks\User_Feed_Synchronization-{E10B2A3E-B832-4A99-878B-AE1023C545F7}.job
          - c:\windows\system32\msfeedssync.exe [2010-12-17 04:25]
          .
          .
          ------- Examen supplémentaire -------
          .
          uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fr_fr&c=83&bd=Pavilion&pf=cnnb
          mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fr_fr&c=83&bd=Pavilion&pf=cnnb
          IE: &Envoyer à OneNote - c:\progra~1\MICROS~3\Office14\ONBttnIE.dll/105
          IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000
          Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
          DPF: {6CE31B8D-8340-4DBD-B78E-BF59620924DC} - hxxp://www.quest3d.com/webplugin/download/quest3dactivex2.cab
          FF - ProfilePath - c:\users\Claude\AppData\Roaming\Mozilla\Firefox\Profiles\s1i9xnn8.default\
          FF - prefs.js: browser.startup.homepage - hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fr_fr&c=83&bd=Pavilion&pf=cnnb
          FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
          FF - Ext: Java Console: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
          FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
          FF - Ext: Java Console: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
          FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
          FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
          FF - Ext: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
          FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
          FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
          FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
          FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
          FF - Ext: TVU Web Player: firefox@tvunetworks.com - %profile%\extensions\firefox@tvunetworks.com
          FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
          FF - user.js: yahoo.homepage.dontask - true
          FF - user.js: network.http.max-persistent-connections-per-server - 4
          FF - user.js: nglayout.initialpaint.delay - 600
          FF - user.js: content.notify.interval - 600000
          FF - user.js: content.max.tokenizing.time - 1800000
          FF - user.js: content.switch.threshold - 600000
          .
          .
          ------- Associations de fichier -------
          .
          JSEFile=NOTEPAD.EXE %1
          .scr=AutoCADScriptFile
          .
          - - - - ORPHELINS SUPPRIMES - - - -

          HKLM-Run-SynTPEnh - %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe

          **************************************************************************

          catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2011-01-28 16:21
          Windows 6.0.6002 Service Pack 2 NTFS

          Recherche de processus cachés ...

          Recherche d'éléments en démarrage automatique cachés ...

          Recherche de fichiers cachés ...

          c:\users\Claude\AppData\Local\Temp\catchme.dll 53248 bytes executable

          Scan terminé avec succès
          Fichiers cachés: 1

          **************************************************************************
          .
          --------------------- CLES DE REGISTRE BLOQUEES ---------------------

          [HKEY_USERS\S-1-5-21-1641100407-3025134362-3523676139-1000\Software\G*e*n*i*e*"!\FM Genie Scout 10]
          "GameDir"="c:\\Users\\Claude\\Documents\\Sports Interactive\\Football Manager 2010\\games"
          "ShortlistDir"="c:\\Users\\Claude\\Documents\\Sports Interactive\\Football Manager 2010\\shortlists"
          "ScreenshotsDir"="c:\\Users\\Claude\\Documents\\Sports Interactive\\Football Manager 2010"
          "SaveDir"="c:\\Users\\Claude\\Documents\\Sports Interactive\\Football Manager 2010\\"
          "HistoryDir"="c:\\Users\\Claude\\Desktop\\FM Genie Scout 10\\History Points"
          "LangDB"=""
          "LastSaveGame"="c:\\Users\\Claude\\Documents\\Sports Interactive\\Football Manager 2010\\games\\ETGFC.fm"
          "Language"="English"
          "LoadLangDB"=dword:00000000
          "CompressHistoryPoints"=dword:00000000
          "HighlightedAttributes"=dword:00000000
          "MinCondition"=dword:00000050
          "GraphStep"=dword:00000000
          "SkinName"="Steklo Black"
          "LastUpdateCheck"=dword:00000000
          "HighQualityGUI"=dword:00000001
          "AutomaticallyUpdateCheck"=dword:00000001
          "AdvancedGeneration"=dword:00000000
          "TranslateStaffSkills"=dword:00000001
          "TranslatePlayerSkills"=dword:00000001
          "TranslatePositions"=dword:00000001
          "ShowHistory"=dword:00000001
          "Version"=dword:0000006e
          "UniqueID"="55-E380-EC1F"
          "UseProxy"=dword:00000000
          "ProxyHost"=""
          "ProxyPort"=""
          "UseAuthentication"=dword:00000000
          "UserName"=""
          "UserPassword"=""
          .
          Heure de fin: 2011-01-28 16:25:38
          ComboFix-quarantined-files.txt 2011-01-28 15:25

          Avant-CF: 59 192 377 344 octets libres
          Après-CF: 59 125 919 744 octets libres

          - - End Of File - - BF39F4B58154558C770D36BA87F66725
          0
          1. ▶ Télécharge ici : Ad-remover sur ton bureau :

            ▶ Déconnecte toi et ferme toutes applications en cours !

            si tu as XP => double clique
            si tu as Vista ou windows 7 => clic droit "executer en tant que...."


            ▶ sur "Ad-R.exe" pour lancer l'installation et laisse les paramètres d'installation par défaut .

            ▶ clique le raccourci Ad-remover qui est sur ton bureau pour lancer l'outil .

            ▶ Au menu principal choisis "option Nettoyer" et tape sur [entrée] .

            ▶ Laisse travailler l'outil et ne touche à rien ...

            ▶ Poste le rapport qui apparait à la fin , sur le forum ...

            ( Le rapport est sauvegardé aussi sous C:\Ad-report.log )
            ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

            ▶ Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
            Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
            Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
            0
            1. Voici le rapport de Ad-R :

              ======= RAPPORT D'AD-REMOVER 2.0.0.2,D | UNIQUEMENT XP/VISTA/7 =======

              Mis à jour par TeamXscript le 20/01/11 à 19:00
              Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
              Site web: http://www.teamxscript.org

              C:\Program Files\Ad-Remover\main.exe (CLEAN [1]) -> Lancé à 16:59:38 le 28/01/2011, Mode normal

              Microsoft® Windows Vista(TM) Édition Familiale Premium Service Pack 2 (X86)
              Claude@PC-DE-CLAUDE (Hewlett-Packard HP Pavilion dv7 Notebook PC)

              ============== ACTION(S) ==============

              Service: "sdmBackupIP" Stoppé et supprimé

              Dossier supprimé: C:\Program Files\Installer
              Fichier supprimé: C:\Windows\system32\Utils.dll
              Dossier supprimé: C:\Windows\BackupIP
              Dossier supprimé: C:\ProgramData\Viewpoint
              Dossier supprimé: C:\Program Files\Viewpoint
              Dossier supprimé: C:\Users\Claude\AppData\Local\networker

              (!) -- Fichiers temporaires supprimés.

              Clé supprimée: HKLM\Software\Classes\CLSID\{03F998B2-0E00-11D3-A498-00104B6EB52E}
              Clé supprimée: HKLM\Software\Classes\CLSID\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
              Clé supprimée: HKLM\Software\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
              Clé supprimée: HKLM\Software\Classes\AxMetaStream.MetaStreamCtl
              Clé supprimée: HKLM\Software\Classes\AxMetaStream.MetaStreamCtl.1
              Clé supprimée: HKLM\Software\Classes\AxMetaStream.MetaStreamCtlSecondary
              Clé supprimée: HKLM\Software\Classes\AxMetaStream.MetaStreamCtlSecondary.1
              Clé supprimée: HKLM\Software\Install Pedia Limited
              Clé supprimée: HKLM\Software\MetaStream
              Clé supprimée: HKLM\Software\Viewpoint
              Clé supprimée: HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\installer
              Clé supprimée: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\ViewpointMediaPlayer
              Clé supprimée: HKLM\Software\Microsoft\Active Setup\Installed Components\{03F998B2-0E00-11D3-A498-00104B6EB52E}
              Clé supprimée: HKLM\Software\Microsoft\Active Setup\Installed Components\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}

              ============== SCAN ADDITIONNEL ==============

              ** Mozilla Firefox Version [3.6.6 (fr)] **

              -- C:\Users\Claude\AppData\Roaming\Mozilla\FireFox\Profiles\s1i9xnn8.default\Prefs.js --
              browser.download.dir, C:\\Users\\Claude\\Downloads
              browser.download.lastDir, G:\\VOITURES
              browser.startup.homepage, hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fr_fr&c=83&bd=Pavilion&pf=cnnb
              browser.startup.homepage_override.mstone, rv:1.9.2.6

              ========================================

              ** Internet Explorer Version [8.0.6001.18999] **

              [HKCU\Software\Microsoft\Internet Explorer\Main]
              Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
              Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
              Do404Search: 0x01000000
              Enable Browser Extensions: yes
              Local Page: C:\Windows\system32\blank.htm
              Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
              Show_ToolBar: yes
              Start Page: hxxp://fr.msn.com/

              [HKLM\Software\Microsoft\Internet Explorer\Main]
              AutoHide: yes
              Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
              Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
              Delete_Temp_Files_On_Exit: yes
              Local Page: C:\Windows\System32\blank.htm
              Search bar: hxxp://search.msn.com/spbasic.htm
              Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
              Start Page: hxxp://fr.msn.com/

              [HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
              Tabs: res://ieframe.dll/tabswelcome.htm
              Blank: res://mshtml.dll/blank.htm

              ========================================

              C:\Program Files\Ad-Remover\Quarantine: 45 Fichier(s)
              C:\Program Files\Ad-Remover\Backup: 16 Fichier(s)

              C:\Ad-Report-CLEAN[1].txt - 28/01/2011 (3651 Octet(s))
              C:\Ad-Report-SCAN[1].txt - 26/01/2011 (3733 Octet(s))

              Fin à: 17:01:41, 28/01/2011

              ============== E.O.F ==============
              0
              1. Ca bloque toujours au même endroit ! Est-ce que je dois me déconnecté d'internet et fermer les fenêtres ouvertes ?
                0
                1. ▶ Télécharge : Gmer (by Przemyslaw Gmerek) et enregistre-le sur ton bureau

                  Desactive toutes tes protections le temps du scan de gMer

                  Pour XP => double clique sur gmer.exe
                  Pour Vista et 7 => clique droit "executer en tant que...."

                  ▶ clique sur l'onglet rootkit,lances le scan,des lignes rouges vont apparaitre.

                  ▶ Les lignes rouges indiquent la presence d'un rootkit.Postes moi le rapport gmer (cliques sur copy,puis vas dans demarrer ,puis ouvres le bloc note,vas dans edition et cliques sur coller,le rapport gmer va apparaitre,postes moi le)
                  0
                  1. Ahahahah ! Maintenant on me dit que Gmer " a cessé de fonctionné " en plein milieu du scan. C'est pas facile...
                    0
                    1. tu as vu des lignes rouges ou pas ?
                      0
                      1. Mince ! Hier soir j'ai fait le scan en mode sans échec, mais j'ai oublié de copier le rapport. Depuis, je n'arrive plus à faire le scan complet, ça plante toujours que ça soit en mode sans échec ou normal. Mais par ailleurs, il me semble que je n'ai pas aperçu de lignes rouges (je ne suis pas sur à 100%).

                        Est-ce un problème pour la suite ?

                        Sinon pour finir, si ça peut t'aider, mon PC à l'air de fonctionner un peu mieux, j'arrive à lancer la plupart des logiciels (j'ai pas tout essayé) et il ne déconne plus au démarrage avec l'écran noir à la place du bureau. Mais il est encore assez lent
                        0

                        1. __________________________________________________
                          =>/!\Le script qui suit a été écrit spécialement cet ordinateur/!\ <=
                          =>il est fort déconseillé de le transposer sur un autre ordinateur !<=
                          ----------------------------------------------------------------------------


                          Toujours avec toutes les protections désactivées, fais ceci :

                          ▶ Ouvre le bloc-notes (Menu démarrer --> programmes --> accessoires --> bloc-notes)
                          ▶ Copie/colle dans le bloc-notes ce qui entre les lignes ci dessous (sans les lignes) :

                          ----------------------------------------------------------
                          KillAll::

                          File::
                          c:\windows\system32\Ionic.Zip.Reduced.dll

                          Registry::
                          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "ISUSPM"=-
                          [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\installer]

                          Netsvc::
                          ezSharedSvc

                          Firefox::
                          FF - Ext: Java Console: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
                          FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
                          FF - Ext: Java Console: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
                          FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
                          FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
                          FF - Ext: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
                          FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
                          FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}


                          ------------------------------------------------------------------

                          ▶ Enregistre ce fichier sur ton Bureau (et pas ailleurs !) sous le nom CFScript.txt
                          ▶ Quitte le Bloc Notes

                          ▶ Fais un glisser/déposer de ce fichier CFScript sur le fichier combofix

                          ▶ Patiente le temps du scan. Le Bureau va disparaître à plusieurs reprises : c'est normal ! Ne touche à rien tant que le scan n'est pas terminé.
                          ▶ Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
                          ▶ Si le fichier ne s'ouvre pas, il se trouve ici => C:\ComboFix.txt

                          0
                          1. Je glisse ce fichier sur l'exe combofix que j'ai renommé avec mon prénom ? Et ensuite le scan se lance tout seul ?
                            0
                          2. oui et tu le laisses bosser sans rien toucher
                            0
                        2. ComboFix 11-01-28.03 - Claude 29/01/2011 19:15:24.2.2 - x86
                          Microsoft® Windows Vista(TM) Édition Familiale Premium 6.0.6002.2.1252.33.1036.18.3068.1907 [GMT 1:00]
                          Lancé depuis: c:\users\Claude\Desktop\Claude.exe
                          Commutateurs utilisés :: c:\users\Claude\Desktop\CFScript.txt
                          AV: avast! Antivirus *Disabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
                          AV: Lavasoft Ad-Watch Live! Antivirus *Disabled/Updated* {DAAC1C79-1A96-9DFE-FC4C-6940214C33E6}
                          SP: avast! Antivirus *Disabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
                          SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {61CDFD9D-3CAC-9270-C6FC-52325ACB795B}
                          SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

                          FILE ::
                          "c:\windows\system32\Ionic.Zip.Reduced.dll"
                          .

                          (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                          .

                          c:\windows\system32\Ionic.Zip.Reduced.dll

                          .
                          ((((((((((((((((((((((((((((( Fichiers créés du 2010-12-28 au 2011-01-29 ))))))))))))))))))))))))))))))))))))
                          .

                          2011-01-29 18:27 . 2011-01-29 18:32 -------- d-----w- c:\users\Claude\AppData\Local\temp
                          2011-01-29 18:27 . 2011-01-29 18:27 -------- d-----w- c:\users\Default\AppData\Local\temp
                          2011-01-28 13:35 . 2010-11-10 04:33 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FB516652-497F-4421-B3D9-17B6A602DB5B}\mpengine.dll
                          2011-01-28 12:48 . 2011-01-28 13:47 -------- d-----w- C:\tdsskiller
                          2011-01-27 21:29 . 2011-01-27 21:34 -------- d-----w- c:\program files\Emsisoft Anti-Malware
                          2011-01-27 21:23 . 2011-01-27 21:23 -------- d-----w- c:\users\Claude\AppData\Roaming\Malwarebytes
                          2011-01-27 21:23 . 2011-01-27 21:23 -------- d-----w- c:\programdata\Malwarebytes
                          2011-01-27 21:23 . 2011-01-28 13:11 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
                          2011-01-27 20:55 . 2011-01-27 20:55 -------- d-----w- c:\program files\Macrovision Corporation
                          2011-01-26 17:41 . 2011-01-28 15:57 -------- d-----w- c:\program files\Ad-Remover
                          2011-01-06 13:44 . 2011-01-06 13:44 -------- d-----w- c:\program files\7-Zip
                          2011-01-05 19:56 . 2011-01-05 19:56 -------- d-----w- c:\users\Claude\AppData\Roaming\OpenOffice.org
                          2011-01-05 19:51 . 2011-01-05 19:51 -------- d-----w- c:\program files\JRE
                          2011-01-05 19:51 . 2011-01-05 19:51 -------- d-----w- c:\program files\OpenOffice.org 3
                          2011-01-05 19:36 . 2011-01-05 19:36 -------- d-----w- c:\users\Claude\AppData\Local\assembly
                          2011-01-03 16:25 . 2011-01-03 16:45 -------- d-----w- c:\users\Claude\AppData\Roaming\FrostWire
                          2011-01-03 16:24 . 2011-01-03 16:29 -------- d-----w- c:\program files\FrostWire

                          .
                          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                          .
                          2011-01-13 08:47 . 2010-12-18 09:03 38848 ----a-w- c:\windows\avastSS.scr
                          2011-01-13 08:47 . 2008-09-20 00:35 188216 ----a-w- c:\windows\system32\aswBoot.exe
                          2011-01-13 08:41 . 2008-09-20 00:35 294608 ----a-w- c:\windows\system32\drivers\aswSP.sys
                          2011-01-13 08:40 . 2008-09-20 00:35 47440 ----a-w- c:\windows\system32\drivers\aswTdi.sys
                          2011-01-13 08:37 . 2008-09-20 00:35 23632 ----a-w- c:\windows\system32\drivers\aswRdr.sys
                          2011-01-13 08:37 . 2008-09-20 00:35 51280 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
                          2011-01-13 08:37 . 2008-09-20 00:35 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
                          2010-11-18 18:44 . 2010-11-18 18:44 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
                          2010-11-12 17:53 . 2010-05-06 21:53 472808 ----a-w- c:\windows\system32\deployJava1.dll
                          2010-11-08 09:02 . 2009-10-31 00:59 98392 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
                          2010-11-04 18:56 . 2010-12-17 17:43 345600 ----a-w- c:\windows\system32\wmicmiplugin.dll
                          2010-11-04 18:55 . 2010-12-17 17:44 352768 ----a-w- c:\windows\system32\taskschd.dll
                          2010-11-04 18:55 . 2010-12-17 17:43 270336 ----a-w- c:\windows\system32\taskcomp.dll
                          2010-11-04 18:55 . 2010-12-17 17:44 601600 ----a-w- c:\windows\system32\schedsvc.dll
                          2010-11-04 16:34 . 2010-12-17 17:43 171520 ----a-w- c:\windows\system32\taskeng.exe
                          2010-11-02 06:01 . 2010-12-17 17:43 916480 ----a-w- c:\windows\system32\wininet.dll
                          2010-11-02 05:57 . 2010-12-17 17:43 43520 ----a-w- c:\windows\system32\licmgr10.dll
                          2010-11-02 05:57 . 2010-12-17 17:43 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
                          2010-11-02 05:57 . 2010-12-17 17:43 71680 ----a-w- c:\windows\system32\iesetup.dll
                          2010-11-02 05:57 . 2010-12-17 17:43 109056 ----a-w- c:\windows\system32\iesysprep.dll
                          2010-11-02 05:01 . 2010-12-17 17:43 385024 ----a-w- c:\windows\system32\html.iec
                          2010-11-02 04:26 . 2010-12-17 17:43 133632 ----a-w- c:\windows\system32\ieUnatt.exe
                          2010-11-02 04:24 . 2010-12-17 17:43 1638912 ----a-w- c:\windows\system32\mshtml.tlb
                          .

                          ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                          .
                          .
                          *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                          REGEDIT4

                          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
                          "LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-02-26 2289664]
                          "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-03-14 202032]
                          "OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-11-01 554288]
                          "hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-11-20 488752]
                          "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-10-03 13826664]
                          "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
                          "avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2011-01-13 3396624]

                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                          "EnableUIADesktopToggle"= 0 (0x0)

                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                          "mixer1"=wdmaud.drv

                          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
                          @="Service"

                          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
                          @="Driver"

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
                          2006-10-25 08:03 210472 ----a-w- c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe

                          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
                          "Microsoft Outlook"=c:\progra~1\MICROS~3\Office14\OUTLOOK.EXE /recycle

                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
                          "HP Software Update"=c:\program files\Hp\HP Software Update\HPWuSchd2.exe
                          "HP Health Check Scheduler"=c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                          "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
                          "SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
                          "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
                          "QPService"="c:\program files\HP\QuickPlay\QPService.exe"

                          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
                          "DisableMonitoring"=dword:00000001

                          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
                          "DisableMonitoring"=dword:00000001

                          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
                          "DisableMonitoring"=dword:00000001

                          R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
                          R2 ELOADER;General Purpose USB Driver (adildr.sys);c:\windows\system32\Drivers\adildr.sys [2007-01-10 56088]
                          R2 gupdate1ca110ffecaae6d;Service Google Update (gupdate1ca110ffecaae6d);c:\program files\Google\Update\GoogleUpdate.exe [2009-07-30 133104]
                          R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-12-18 1389400]
                          R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
                          R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
                          R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
                          R3 WPFFontCache_v0400;Cache de police de Windows Presentation Foundation 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
                          R4 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2008-09-20 717296]
                          R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
                          S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-09-08 64288]
                          S1 aswSP;aswSP; [x]
                          S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_e2247046\aestsrv.exe [2009-03-02 81920]
                          S2 aswFsBlk;aswFsBlk; [x]
                          S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-01-13 51280]
                          S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2008-01-21 21504]
                          S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2008-03-18 19456]
                          S2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\SMINST\BLService.exe [2008-03-26 341328]
                          S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2010-06-14 1051976]
                          S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [2008-01-24 52736]
                          S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2008-04-11 84240]
                          S3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-11-17 3668480]
                          S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2009-06-26 66080]
                          S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [2010-02-25 10064]

                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                          bthsvcs REG_MULTI_SZ BthServ
                          LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
                          HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

                          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
                          UxTuneUp

                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
                          2008-02-26 12:06 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
                          .
                          Contenu du dossier 'Tâches planifiées'

                          2011-01-28 c:\windows\Tasks\Ad-Aware Update (Weekly).job
                          - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-09-08 09:39]

                          2011-01-29 c:\windows\Tasks\GlaryInitialize.job
                          - c:\program files\Glary Utilities\initialize.exe [2010-06-27 08:01]

                          2011-01-29 c:\windows\Tasks\Google Software Updater.job
                          - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-07-30 12:17]

                          2011-01-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
                          - c:\program files\Google\Update\GoogleUpdate.exe [2009-07-30 12:19]

                          2011-01-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
                          - c:\program files\Google\Update\GoogleUpdate.exe [2009-07-30 12:19]

                          2011-01-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1641100407-3025134362-3523676139-1000Core.job
                          - c:\users\Claude\AppData\Local\Google\Update\GoogleUpdate.exe [2010-02-12 09:38]

                          2011-01-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1641100407-3025134362-3523676139-1000UA.job
                          - c:\users\Claude\AppData\Local\Google\Update\GoogleUpdate.exe [2010-02-12 09:38]

                          2011-01-28 c:\windows\Tasks\HPCeeScheduleForClaude.job
                          - c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2008-06-09 13:14]

                          2011-01-28 c:\windows\Tasks\User_Feed_Synchronization-{E10B2A3E-B832-4A99-878B-AE1023C545F7}.job
                          - c:\windows\system32\msfeedssync.exe [2010-12-17 04:25]
                          .
                          .
                          ------- Examen supplémentaire -------
                          .
                          IE: &Envoyer à OneNote - c:\progra~1\MICROS~3\Office14\ONBttnIE.dll/105
                          IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000
                          Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
                          DPF: {6CE31B8D-8340-4DBD-B78E-BF59620924DC} - hxxp://www.quest3d.com/webplugin/download/quest3dactivex2.cab
                          FF - ProfilePath - c:\users\Claude\AppData\Roaming\Mozilla\Firefox\Profiles\s1i9xnn8.default\
                          FF - prefs.js: browser.startup.homepage - hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fr_fr&c=83&bd=Pavilion&pf=cnnb
                          FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
                          FF - Ext: Java Console: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
                          FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
                          FF - Ext: Java Console: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
                          FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
                          FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
                          FF - Ext: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
                          FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
                          FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
                          FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
                          FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
                          FF - Ext: TVU Web Player: firefox@tvunetworks.com - %profile%\extensions\firefox@tvunetworks.com
                          FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
                          FF - user.js: yahoo.homepage.dontask - true
                          FF - user.js: network.http.max-persistent-connections-per-server - 4
                          FF - user.js: nglayout.initialpaint.delay - 600
                          FF - user.js: content.notify.interval - 600000
                          FF - user.js: content.max.tokenizing.time - 1800000
                          FF - user.js: content.switch.threshold - 600000
                          .
                          - - - - ORPHELINS SUPPRIMES - - - -

                          AddRemove-installer - c:\program files\Installer\un_installer_21627.exe

                          **************************************************************************

                          catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                          Rootkit scan 2011-01-29 19:32
                          Windows 6.0.6002 Service Pack 2 NTFS

                          Recherche de processus cachés ...

                          Recherche d'éléments en démarrage automatique cachés ...

                          Recherche de fichiers cachés ...

                          Scan terminé avec succès
                          Fichiers cachés: 0

                          **************************************************************************
                          .
                          --------------------- CLES DE REGISTRE BLOQUEES ---------------------

                          [HKEY_USERS\S-1-5-21-1641100407-3025134362-3523676139-1000\Software\G*e*n*i*e*"!\FM Genie Scout 10]
                          "GameDir"="c:\\Users\\Claude\\Documents\\Sports Interactive\\Football Manager 2010\\games"
                          "ShortlistDir"="c:\\Users\\Claude\\Documents\\Sports Interactive\\Football Manager 2010\\shortlists"
                          "ScreenshotsDir"="c:\\Users\\Claude\\Documents\\Sports Interactive\\Football Manager 2010"
                          "SaveDir"="c:\\Users\\Claude\\Documents\\Sports Interactive\\Football Manager 2010\\"
                          "HistoryDir"="c:\\Users\\Claude\\Desktop\\FM Genie Scout 10\\History Points"
                          "LangDB"=""
                          "LastSaveGame"="c:\\Users\\Claude\\Documents\\Sports Interactive\\Football Manager 2010\\games\\ETGFC.fm"
                          "Language"="English"
                          "LoadLangDB"=dword:00000000
                          "CompressHistoryPoints"=dword:00000000
                          "HighlightedAttributes"=dword:00000000
                          "MinCondition"=dword:00000050
                          "GraphStep"=dword:00000000
                          "SkinName"="Steklo Black"
                          "LastUpdateCheck"=dword:00000000
                          "HighQualityGUI"=dword:00000001
                          "AutomaticallyUpdateCheck"=dword:00000001
                          "AdvancedGeneration"=dword:00000000
                          "TranslateStaffSkills"=dword:00000001
                          "TranslatePlayerSkills"=dword:00000001
                          "TranslatePositions"=dword:00000001
                          "ShowHistory"=dword:00000001
                          "Version"=dword:0000006e
                          "UniqueID"="55-E380-EC1F"
                          "UseProxy"=dword:00000000
                          "ProxyHost"=""
                          "ProxyPort"=""
                          "UseAuthentication"=dword:00000000
                          "UserName"=""
                          "UserPassword"=""
                          .
                          --------------------- DLLs chargées dans les processus actifs ---------------------

                          - - - - - - - > 'Explorer.exe'(3896)
                          c:\program files\FileZilla FTP Client\fzshellext.dll
                          .
                          ------------------------ Autres processus actifs ------------------------
                          .
                          c:\windows\system32\nvvsvc.exe
                          c:\windows\System32\DriverStore\FileRepository\stwrt.inf_e2247046\STacSV.exe
                          c:\windows\system32\nvvsvc.exe
                          c:\program files\Alwil Software\Avast5\AvastSvc.exe
                          c:\folding@homecpu\1\Fah.exe
                          c:\folding@homecpu\2\Fah.exe
                          c:\folding@homecpu\1\FahCore_78.exe
                          c:\program files\Common Files\LightScribe\LSSrvc.exe
                          c:\folding@homecpu\2\FahCore_78.exe
                          c:\windows\system32\PnkBstrA.exe
                          c:\program files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
                          c:\program files\HP\QuickPlay\Kernel\TV\QPSched.exe
                          c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                          c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
                          c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
                          c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
                          c:\windows\system32\conime.exe
                          c:\windows\system32\wbem\unsecapp.exe
                          c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe
                          c:\windows\servicing\TrustedInstaller.exe
                          c:\program files\Windows Media Player\wmpnscfg.exe
                          c:\program files\Windows Media Player\wmpnetwk.exe
                          .
                          **************************************************************************
                          .
                          Heure de fin: 2011-01-29 19:40:44 - La machine a redémarré
                          ComboFix-quarantined-files.txt 2011-01-29 18:40
                          ComboFix2.txt 2011-01-28 15:25

                          Avant-CF: 58 009 964 544 octets libres
                          Après-CF: 57 980 866 560 octets libres

                          - - End Of File - - A135BEAED316BE51EB4CD7B684555600
                          0
                          • 1
                          • 2
                          • 3