Pc rame

Bonjour,

j'ai mon pc qui est tres souvent et qui le reste longtemps a100%

je vous remercies pour votre aide



--
j'essaie d'apporter mon aide

33 réponses

Résumé de la discussion

Le problème principal est qu'un PC fonctionnant sous Windows XP affiche une utilisation CPU à 100% de manière répétée et prolongée, entraînant une lenteur et des comportements instables. Des réponses suggèrent des solutions anti-malware, notamment l'utilisation de ZHPDiag pour le diagnostic et la génération de rapports, puis l'envoi des résultats via des liens de partage afin d'identifier des éléments indésirables. Des analyses complémentaires reprennent des outils comme ComboFix et Ad-Remover pour nettoyer le système, avec des rapports détaillant les fichiers et clés de registre supprimés, notamment Conduit Engine et les barres d'outils associées. Par ailleurs, les éléments d'analyse dénotent des composants démarrage et des logiciels persistants, indiquant une remédiation potentielle complexe nécessitant une réinitialisation soignée du système.

Bobot (l’IA à votre service)
  1. salut

    ▶ Télécharge Reload_TDSSKiller

    ▶ Lance le

    choisis : lancer le nettoyage

    l'outil va automatiquement télécharger la derniere version puis

    TDSSKiller va s'ouvrir , clique sur "Start Scan"

    une fois qu'il a terminé , redemarre s'il te le demande pour finir de nettoyer

    sinon , ferme tdssKiller et le rapport s'affichera sur le bureau

    ▶ Copie/Colle son contenu dans ta prochaine réponse.
    0
    1. bonjour

      merci pour ton aide

      2011/08/05 16:05:22.0111 5188 TDSS rootkit removing tool 2.5.14.0 Aug 5 2011 16:09:29
      2011/08/05 16:05:22.0267 5188 ================================================================================
      2011/08/05 16:05:22.0267 5188 SystemInfo:
      2011/08/05 16:05:22.0267 5188
      2011/08/05 16:05:22.0267 5188 OS Version: 5.1.2600 ServicePack: 3.0
      2011/08/05 16:05:22.0267 5188 Product type: Workstation
      2011/08/05 16:05:22.0267 5188 ComputerName: NOM-EB85C523610
      2011/08/05 16:05:22.0267 5188 UserName: HP_Propriétaire
      2011/08/05 16:05:22.0267 5188 Windows directory: C:\WINDOWS
      2011/08/05 16:05:22.0267 5188 System windows directory: C:\WINDOWS
      2011/08/05 16:05:22.0267 5188 Processor architecture: Intel x86
      2011/08/05 16:05:22.0267 5188 Number of processors: 1
      2011/08/05 16:05:22.0267 5188 Page size: 0x1000
      2011/08/05 16:05:22.0267 5188 Boot type: Normal boot
      2011/08/05 16:05:22.0267 5188 ================================================================================
      2011/08/05 16:05:23.0752 5188 Initialize success
      2011/08/05 16:05:29.0392 3572 ================================================================================
      2011/08/05 16:05:29.0392 3572 Scan started
      2011/08/05 16:05:29.0392 3572 Mode: Manual;
      2011/08/05 16:05:29.0392 3572 ================================================================================
      2011/08/05 16:05:30.0392 3572 ACPI (e5e6dbfc41ea8aad005cb9a57a96b43b) C:\WINDOWS\system32\DRIVERS\ACPI.sys
      2011/08/05 16:05:30.0470 3572 ACPIEC (e4abc1212b70bb03d35e60681c447210) C:\WINDOWS\system32\drivers\ACPIEC.sys
      2011/08/05 16:05:30.0752 3572 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
      2011/08/05 16:05:30.0861 3572 AFD (355556d9e580915118cd7ef736653a89) C:\WINDOWS\System32\drivers\afd.sys
      2011/08/05 16:05:31.0299 3572 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
      2011/08/05 16:05:31.0705 3572 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
      2011/08/05 16:05:31.0799 3572 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
      2011/08/05 16:05:32.0064 3572 ati2mtag (c06659ff381423d6cb19a91c2a2f80ad) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
      2011/08/05 16:05:32.0377 3572 atksgt (3c4b9850a2631c2263507400d029057b) C:\WINDOWS\system32\DRIVERS\atksgt.sys
      2011/08/05 16:05:32.0439 3572 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
      2011/08/05 16:05:32.0502 3572 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
      2011/08/05 16:05:32.0580 3572 Avc (f8e6956a614f15a0860474c5e2a7de6b) C:\WINDOWS\system32\DRIVERS\avc.sys
      2011/08/05 16:05:32.0658 3572 AvgAsCln (856b0cee009946bf2d327e6b24fe7e3f) C:\WINDOWS\system32\DRIVERS\AvgAsCln.sys
      2011/08/05 16:05:32.0736 3572 bdfm (67c2a47db7190673350a3f9f5a1507cb) C:\WINDOWS\system32\drivers\bdfm.sys
      2011/08/05 16:05:32.0814 3572 Bdfndisf (d981965d8d6578d663cf53d70a03f95a) C:\WINDOWS\system32\DRIVERS\bdfndisf.sys
      2011/08/05 16:05:32.0892 3572 bdfsfltr (a21a4a0e6bdf0c2be0fabfa16d8c8f76) C:\WINDOWS\system32\drivers\bdfsfltr.sys
      2011/08/05 16:05:33.0095 3572 bdftdif (0bdbf842a39d6c5640ba4b8acf29aa06) C:\Program Files\Fichiers communs\BitDefender\BitDefender Firewall\bdftdif.sys
      2011/08/05 16:05:33.0174 3572 BDSelfPr (0d756ced21d977ae32539da1f41bf879) C:\Program Files\BitDefender\BitDefender 2010\bdselfpr.sys
      2011/08/05 16:05:33.0236 3572 BDVEDISK (375cd0b9f433465ec6f50d4df44e9448) C:\Program Files\BitDefender\BitDefender 2010\bdvedisk.sys
      2011/08/05 16:05:33.0424 3572 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
      2011/08/05 16:05:33.0595 3572 btaudio (74ef010b27a2bf44dd5649dd331899a0) C:\WINDOWS\system32\drivers\btaudio.sys
      2011/08/05 16:05:33.0736 3572 BTDriver (3c7c61c3d0b0f87136ad925ca624dc1c) C:\WINDOWS\system32\DRIVERS\btport.sys
      2011/08/05 16:05:33.0861 3572 BthEnum (b279426e3c0c344893ed78a613a73bde) C:\WINDOWS\system32\DRIVERS\BthEnum.sys
      2011/08/05 16:05:33.0939 3572 BTHMODEM (fca6f069597b62d42495191ace3fc6c1) C:\WINDOWS\system32\DRIVERS\bthmodem.sys
      2011/08/05 16:05:34.0033 3572 BthPan (80602b8746d3738f5886ce3d67ef06b6) C:\WINDOWS\system32\DRIVERS\bthpan.sys
      2011/08/05 16:05:34.0158 3572 BTHPORT (ef26202fee56f7607c6b794059df347a) C:\WINDOWS\system32\Drivers\BTHport.sys
      2011/08/05 16:05:34.0252 3572 BTHUSB (61364cd71ef63b0f038b7e9df00f1efa) C:\WINDOWS\system32\Drivers\BTHUSB.sys
      2011/08/05 16:05:34.0345 3572 BTKRNL (515617cc36e7c5bee744b3c62affb4f5) C:\WINDOWS\system32\DRIVERS\btkrnl.sys
      2011/08/05 16:05:34.0486 3572 BTWDNDIS (2ccd954aac705aaa98ad7e545bd44efe) C:\WINDOWS\system32\DRIVERS\btwdndis.sys
      2011/08/05 16:05:34.0580 3572 btwhid (af60e6ffef11cc9653d5edc0b238893b) C:\WINDOWS\system32\DRIVERS\btwhid.sys
      2011/08/05 16:05:34.0658 3572 BTWUSB (dceffeeae5672e57dd1343236fbb5763) C:\WINDOWS\system32\Drivers\btwusb.sys
      2011/08/05 16:05:34.0720 3572 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
      2011/08/05 16:05:34.0799 3572 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
      2011/08/05 16:05:34.0877 3572 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
      2011/08/05 16:05:35.0111 3572 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
      2011/08/05 16:05:35.0564 3572 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
      2011/08/05 16:05:35.0955 3572 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
      2011/08/05 16:05:36.0049 3572 dmboot (f5deadd42335fb33edca74ecb2f36cba) C:\WINDOWS\system32\drivers\dmboot.sys
      2011/08/05 16:05:36.0158 3572 dmio (5a7c47c9b3f9fb92a66410a7509f0c71) C:\WINDOWS\system32\drivers\dmio.sys
      2011/08/05 16:05:36.0283 3572 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
      2011/08/05 16:05:36.0377 3572 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
      2011/08/05 16:05:36.0549 3572 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
      2011/08/05 16:05:36.0908 3572 E100B (95974e66d3de4951d29e28e8bc0b644c) C:\WINDOWS\system32\DRIVERS\e100b325.sys
      2011/08/05 16:05:37.0080 3572 ENTECH (bdd170fecb0e496a914318009d85b819) C:\WINDOWS\system32\DRIVERS\ENTECH.SYS
      2011/08/05 16:05:37.0220 3572 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
      2011/08/05 16:05:37.0283 3572 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
      2011/08/05 16:05:37.0377 3572 Fips (31f923eb2170fc172c81abda0045d18c) C:\WINDOWS\system32\drivers\Fips.sys
      2011/08/05 16:05:37.0439 3572 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
      2011/08/05 16:05:37.0533 3572 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
      2011/08/05 16:05:37.0674 3572 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
      2011/08/05 16:05:37.0736 3572 Ftdisk (a86859b77b908c18c2657f284aa29fe3) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
      2011/08/05 16:05:37.0830 3572 GEARAspiWDM (4ac51459805264affd5f6fdfb9d9235f) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
      2011/08/05 16:05:37.0924 3572 gmer (b56eb0a2210980e76390bd670bcb618b) C:\WINDOWS\system32\DRIVERS\gmer.sys
      2011/08/05 16:05:38.0033 3572 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
      2011/08/05 16:05:38.0111 3572 hamachi (833051c6c6c42117191935f734cfbd97) C:\WINDOWS\system32\DRIVERS\hamachi.sys
      2011/08/05 16:05:38.0174 3572 HdAudAddService (2a013e7530beab6e569faa83f517e836) C:\WINDOWS\system32\drivers\HdAudio.sys
      2011/08/05 16:05:38.0283 3572 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
      2011/08/05 16:05:38.0330 3572 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
      2011/08/05 16:05:38.0455 3572 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
      2011/08/05 16:05:38.0580 3572 i8042prt (a09bdc4ed10e3b2e0ec27bb94af32516) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
      2011/08/05 16:05:38.0658 3572 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
      2011/08/05 16:05:38.0845 3572 IntcAzAudAddService (d87ffa95d630ec8d1482ca25c454846a) C:\WINDOWS\system32\drivers\RtkHDAud.sys
      2011/08/05 16:05:39.0064 3572 IntelIde (4b6da2f0a4095857a9e3f3697399d575) C:\WINDOWS\system32\DRIVERS\intelide.sys
      2011/08/05 16:05:39.0111 3572 intelppm (ad340800c35a42d4de1641a37feea34c) C:\WINDOWS\system32\DRIVERS\intelppm.sys
      2011/08/05 16:05:39.0158 3572 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
      2011/08/05 16:05:39.0267 3572 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
      2011/08/05 16:05:39.0345 3572 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
      2011/08/05 16:05:39.0439 3572 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
      2011/08/05 16:05:39.0502 3572 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
      2011/08/05 16:05:39.0580 3572 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
      2011/08/05 16:05:39.0674 3572 isapnp (355836975a67b6554bca60328cd6cb74) C:\WINDOWS\system32\DRIVERS\isapnp.sys
      2011/08/05 16:05:39.0720 3572 Kbdclass (16813155807c6881f4bfbf6657424659) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
      2011/08/05 16:05:39.0814 3572 kbdhid (94c59cb884ba010c063687c3a50dce8e) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
      2011/08/05 16:05:39.0892 3572 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
      2011/08/05 16:05:39.0970 3572 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
      2011/08/05 16:05:40.0049 3572 L8042Kbd (e141ab3701ea166109212dca4b28ca2c) C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys
      2011/08/05 16:05:40.0142 3572 L8042mou (f0f944e4da9a75dee6a37d4afc7e1bbc) C:\WINDOWS\system32\DRIVERS\L8042mou.Sys
      2011/08/05 16:05:40.0267 3572 LBeepKE (b28c741ae2912a079cf90041a9e5c0a4) C:\WINDOWS\system32\Drivers\LBeepKE.sys
      2011/08/05 16:05:40.0377 3572 LHidFilt (24e0ddb99aeccf86bb37702611761459) C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys
      2011/08/05 16:05:40.0455 3572 LHidKe (dd40c03d85649205ec086722474c8a63) C:\WINDOWS\system32\DRIVERS\LHidKE.Sys
      2011/08/05 16:05:40.0549 3572 libusb0 (e2f1dcf4a68cc6cf694fbfba1842f4cd) C:\WINDOWS\system32\drivers\libusb0.sys
      2011/08/05 16:05:40.0627 3572 lirsgt (4127e8b6ddb4090e815c1f8852c277d3) C:\WINDOWS\system32\DRIVERS\lirsgt.sys
      2011/08/05 16:05:40.0689 3572 LMouKE (2ebd4c02d259944869630a912ec86bce) C:\WINDOWS\system32\DRIVERS\LMouKE.Sys
      2011/08/05 16:05:40.0814 3572 ltmodem5 (919de7d76d2c0c0139e08b3e7592d62e) C:\WINDOWS\system32\DRIVERS\ltmdmnt.sys
      2011/08/05 16:05:40.0955 3572 LVUSBSta (a730fc8671a60666d6e877c544dd7cd4) C:\WINDOWS\system32\drivers\lvusbsta.sys
      2011/08/05 16:05:41.0049 3572 MBAMProtector (eca00eed9ab95489007b0ef84c7149de) C:\WINDOWS\system32\drivers\mbam.sys
      2011/08/05 16:05:41.0142 3572 MBAMSwissArmy (b18225739ed9caa83ba2df966e9f43e8) C:\WINDOWS\system32\drivers\mbamswissarmy.sys
      2011/08/05 16:05:41.0236 3572 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
      2011/08/05 16:05:41.0330 3572 Modem (510ade9327fe84c10254e1902697e25f) C:\WINDOWS\system32\drivers\Modem.sys
      2011/08/05 16:05:41.0377 3572 Mouclass (027c01bd7ef3349aaebc883d8a799efb) C:\WINDOWS\system32\DRIVERS\mouclass.sys
      2011/08/05 16:05:41.0439 3572 mouhid (124d6846040c79b9c997f78ef4b2a4e5) C:\WINDOWS\system32\DRIVERS\mouhid.sys
      2011/08/05 16:05:41.0502 3572 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
      2011/08/05 16:05:41.0595 3572 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
      2011/08/05 16:05:41.0689 3572 MRxSmb (0dc719e9b15e902346e87e9dcd5751fa) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
      2011/08/05 16:05:41.0767 3572 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
      2011/08/05 16:05:41.0845 3572 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
      2011/08/05 16:05:41.0939 3572 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
      2011/08/05 16:05:42.0033 3572 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
      2011/08/05 16:05:42.0361 3572 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
      2011/08/05 16:05:42.0424 3572 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
      2011/08/05 16:05:42.0549 3572 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
      2011/08/05 16:05:42.0611 3572 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
      2011/08/05 16:05:42.0705 3572 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
      2011/08/05 16:05:42.0767 3572 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
      2011/08/05 16:05:42.0892 3572 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
      2011/08/05 16:05:43.0033 3572 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
      2011/08/05 16:05:43.0127 3572 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
      2011/08/05 16:05:43.0267 3572 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
      2011/08/05 16:05:43.0361 3572 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
      2011/08/05 16:05:43.0455 3572 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
      2011/08/05 16:05:43.0611 3572 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
      2011/08/05 16:05:43.0705 3572 nm (1e421a6bcf2203cc61b821ada9de878b) C:\WINDOWS\system32\DRIVERS\NMnt.sys
      2011/08/05 16:05:43.0799 3572 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
      2011/08/05 16:05:43.0939 3572 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
      2011/08/05 16:05:44.0033 3572 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
      2011/08/05 16:05:44.0095 3572 NVR0Dev (61d6b1c71ad94f8485e966bebc36d092) C:\WINDOWS\nvoclock.sys
      2011/08/05 16:05:46.0158 3572 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
      2011/08/05 16:05:46.0252 3572 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
      2011/08/05 16:05:46.0392 3572 NwlnkIpx (8b8b1be2dba4025da6786c645f77f123) C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys
      2011/08/05 16:05:46.0486 3572 NwlnkNb (56d34a67c05e94e16377c60609741ff8) C:\WINDOWS\system32\DRIVERS\nwlnknb.sys
      2011/08/05 16:05:46.0595 3572 NwlnkSpx (c0bb7d1615e1acbdc99757f6ceaf8cf0) C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys
      2011/08/05 16:05:46.0689 3572 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
      2011/08/05 16:05:46.0783 3572 Parport (8fd0bdbea875d06ccf6c945ca9abaf75) C:\WINDOWS\system32\DRIVERS\parport.sys
      2011/08/05 16:05:46.0908 3572 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
      2011/08/05 16:05:47.0002 3572 ParVdm (9575c5630db8fb804649a6959737154c) C:\WINDOWS\system32\drivers\ParVdm.sys
      2011/08/05 16:05:47.0158 3572 PCANDIS5 (ceef86cb35abe95c40a88784f5b631ad) C:\WINDOWS\system32\PCANDIS5.SYS
      2011/08/05 16:05:47.0424 3572 PCI (043410877bda580c528f45165f7125bc) C:\WINDOWS\system32\DRIVERS\pci.sys
      2011/08/05 16:05:47.0564 3572 PCIIde (f4bfde7209c14a07aaa61e4d6ae69eac) C:\WINDOWS\system32\DRIVERS\pciide.sys
      2011/08/05 16:05:47.0642 3572 Pcmcia (f0406cbc60bdb0394a0e17ffb04cdd3d) C:\WINDOWS\system32\drivers\Pcmcia.sys
      2011/08/05 16:05:48.0002 3572 pepifilter (16bc447de474a9e125db39806714f1e1) C:\WINDOWS\system32\DRIVERS\lv302af.sys
      2011/08/05 16:05:48.0283 3572 pfc (957b82ec80ad7ead64e5e47df6b0dc40) C:\WINDOWS\system32\drivers\pfc.sys
      2011/08/05 16:05:48.0439 3572 PID_08A0 (7a31b09c7f037a1217b658465f19bbce) C:\WINDOWS\system32\DRIVERS\LV302AV.SYS
      2011/08/05 16:05:48.0642 3572 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
      2011/08/05 16:05:48.0845 3572 Profos (d90a33660d328a9f587580f0b38c85de) C:\Program Files\Fichiers communs\BitDefender\BitDefender Threat Scanner\profos.sys
      2011/08/05 16:05:48.0924 3572 Ps2 (390c204ced3785609ab24e9c52054a84) C:\WINDOWS\system32\DRIVERS\PS2.sys
      2011/08/05 16:05:49.0033 3572 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
      2011/08/05 16:05:49.0127 3572 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
      2011/08/05 16:05:49.0236 3572 PxHelp20 (86724469cd077901706854974cd13c3e) C:\WINDOWS\system32\Drivers\PxHelp20.sys
      2011/08/05 16:05:49.0549 3572 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
      2011/08/05 16:05:49.0642 3572 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
      2011/08/05 16:05:49.0767 3572 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
      2011/08/05 16:05:49.0908 3572 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
      2011/08/05 16:05:50.0002 3572 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
      2011/08/05 16:05:50.0095 3572 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
      2011/08/05 16:05:50.0205 3572 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
      2011/08/05 16:05:50.0299 3572 redbook (d8eb2a7904db6c916eb5361878ddcbae) C:\WINDOWS\system32\DRIVERS\redbook.sys
      2011/08/05 16:05:50.0408 3572 RFCOMM (851c30df2807fcfa21e4c681a7d6440e) C:\WINDOWS\system32\DRIVERS\rfcomm.sys
      2011/08/05 16:05:50.0502 3572 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
      2011/08/05 16:05:50.0611 3572 rtl8139 (d507c1400284176573224903819ffda3) C:\WINDOWS\system32\DRIVERS\RTL8139.SYS
      2011/08/05 16:05:50.0752 3572 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
      2011/08/05 16:05:50.0845 3572 Serial (93d313c31f7ad9ea2b75f26075413c7c) C:\WINDOWS\system32\drivers\Serial.sys
      2011/08/05 16:05:50.0939 3572 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
      2011/08/05 16:05:51.0017 3572 Sftfs (14cb193ecd4e71a32446790f9ecf39dd) C:\WINDOWS\system32\DRIVERS\Sftfsxp.sys
      2011/08/05 16:05:51.0142 3572 Sftplay (1f05637831caf19b069aaf361d720bb9) C:\WINDOWS\system32\DRIVERS\Sftplayxp.sys
      2011/08/05 16:05:51.0220 3572 Sftredir (423628f17862593d7d43e02187f4c1b5) C:\WINDOWS\system32\DRIVERS\Sftredirxp.sys
      2011/08/05 16:05:51.0252 3572 Sftvol (258ab73a01fa1b8d1a2a053c6bba5544) C:\WINDOWS\system32\DRIVERS\Sftvolxp.sys
      2011/08/05 16:05:51.0377 3572 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
      2011/08/05 16:05:51.0486 3572 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
      2011/08/05 16:05:51.0611 3572 sptd (73205bd9a388639c210636793fe3fd61) C:\WINDOWS\system32\Drivers\sptd.sys
      2011/08/05 16:05:51.0611 3572 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: 73205bd9a388639c210636793fe3fd61
      2011/08/05 16:05:51.0627 3572 sptd - detected LockedFile.Multi.Generic (1)
      2011/08/05 16:05:51.0674 3572 sr (39626e6dc1fb39434ec40c42722b660a) C:\WINDOWS\system32\DRIVERS\sr.sys
      2011/08/05 16:05:51.0799 3572 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
      2011/08/05 16:05:51.0908 3572 sscdbus (92b69020fc480219683d429dca068d71) C:\WINDOWS\system32\DRIVERS\sscdbus.sys
      2011/08/05 16:05:52.0017 3572 sscdmdfl (77a2869d40cc84af711c321f9b0c7a78) C:\WINDOWS\system32\DRIVERS\sscdmdfl.sys
      2011/08/05 16:05:52.0095 3572 sscdmdm (b4255635195a8413fcde7af5b7c4e382) C:\WINDOWS\system32\DRIVERS\sscdmdm.sys
      2011/08/05 16:05:52.0205 3572 ss_bus (5a1d0ca8a5f1e7b4ec50b9d76c001f0e) C:\WINDOWS\system32\DRIVERS\ss_bus.sys
      2011/08/05 16:05:52.0299 3572 ss_mdfl (f0a85580e36a3a85059037d39a9cf079) C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys
      2011/08/05 16:05:52.0377 3572 ss_mdm (84c3dbfd1bfa4adc0a950b3d5506cb00) C:\WINDOWS\system32\DRIVERS\ss_mdm.sys
      2011/08/05 16:05:52.0486 3572 StarOpen (306521935042fc0a6988d528643619b3) C:\WINDOWS\system32\drivers\StarOpen.sys
      2011/08/05 16:05:52.0564 3572 StillCam (3f669c9fc6411bdbc0155544aa876e46) C:\WINDOWS\system32\DRIVERS\serscan.sys
      2011/08/05 16:05:52.0642 3572 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
      2011/08/05 16:05:52.0736 3572 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
      2011/08/05 16:05:52.0783 3572 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
      2011/08/05 16:05:53.0017 3572 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
      2011/08/05 16:05:53.0158 3572 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
      2011/08/05 16:05:53.0220 3572 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
      2011/08/05 16:05:53.0314 3572 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
      2011/08/05 16:05:53.0408 3572 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
      2011/08/05 16:05:53.0533 3572 toshidpt (62c57e7411b5f20980e70530ca69d5a7) C:\WINDOWS\system32\drivers\Toshidpt.sys
      2011/08/05 16:05:53.0658 3572 tosporte (fe6ce38a53db70770b805262afceccef) C:\WINDOWS\system32\DRIVERS\tosporte.sys
      2011/08/05 16:05:53.0767 3572 Tosrfbd (81546df5dea8abf2c8864d6d1f724b35) C:\WINDOWS\system32\Drivers\tosrfbd.sys
      2011/08/05 16:05:53.0877 3572 Tosrfbnp (fe200eece7521061cdad658c6ee4f341) C:\WINDOWS\system32\Drivers\tosrfbnp.sys
      2011/08/05 16:05:53.0955 3572 Tosrfcom (d185be751021bcf1e5d58566d408314a) C:\WINDOWS\system32\Drivers\tosrfcom.sys
      2011/08/05 16:05:54.0033 3572 Tosrfhid (341612b9758054e5965bcd6ae111b8f9) C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys
      2011/08/05 16:05:54.0127 3572 tosrfnds (c52fd27b9adf3a1f22cb90e6bcf9b0cb) C:\WINDOWS\system32\DRIVERS\tosrfnds.sys
      2011/08/05 16:05:54.0220 3572 TosRfSnd (350814a87f8ba3b0e28278feddf36f82) C:\WINDOWS\system32\drivers\TosRfSnd.sys
      2011/08/05 16:05:54.0314 3572 Tosrfusb (ddb8a339e57d514768f45d33b11bdb50) C:\WINDOWS\system32\Drivers\tosrfusb.sys
      2011/08/05 16:05:54.0502 3572 Trufos (b16d66a71de03285e14e9f165b59eda4) C:\Program Files\Fichiers communs\BitDefender\BitDefender Threat Scanner\trufos.sys
      2011/08/05 16:05:54.0580 3572 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
      2011/08/05 16:05:54.0736 3572 UnlockerDriver5 (4847639d852763ee39415c929470f672) C:\Program Files\Unlocker\UnlockerDriver5.sys
      2011/08/05 16:05:54.0861 3572 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
      2011/08/05 16:05:54.0970 3572 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
      2011/08/05 16:05:55.0064 3572 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
      2011/08/05 16:05:55.0142 3572 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
      2011/08/05 16:05:55.0205 3572 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
      2011/08/05 16:05:55.0267 3572 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
      2011/08/05 16:05:55.0345 3572 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
      2011/08/05 16:05:55.0408 3572 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
      2011/08/05 16:05:55.0470 3572 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
      2011/08/05 16:05:55.0549 3572 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
      2011/08/05 16:05:55.0627 3572 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
      2011/08/05 16:05:55.0705 3572 VolSnap (46de1126684369bace4849e4fc8c43ca) C:\WINDOWS\system32\drivers\VolSnap.sys
      2011/08/05 16:05:55.0799 3572 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
      2011/08/05 16:05:55.0939 3572 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
      2011/08/05 16:05:56.0095 3572 WmBEnum (38932c4649f8baad6ce1000ac6503d5b) C:\WINDOWS\system32\drivers\WmBEnum.sys
      2011/08/05 16:05:56.0189 3572 WmFilter (58b3adab903fa1a78c86e6a42b80fe76) C:\WINDOWS\system32\drivers\WmFilter.sys
      2011/08/05 16:05:56.0267 3572 WmHidLo (be1951c6919efb86e95f8ef331e39c50) C:\WINDOWS\system32\drivers\WmHidLo.sys
      2011/08/05 16:05:56.0392 3572 WmVirHid (e45f01f4014d7ab13b8a0c41ebf48a3d) C:\WINDOWS\system32\drivers\WmVirHid.sys
      2011/08/05 16:05:56.0486 3572 WmXlCore (0398265dd65aae2ece180fa9d1e7b5bb) C:\WINDOWS\system32\drivers\WmXlCore.sys
      2011/08/05 16:05:56.0580 3572 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
      2011/08/05 16:05:56.0705 3572 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
      2011/08/05 16:05:56.0814 3572 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
      2011/08/05 16:05:56.0861 3572 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
      2011/08/05 16:05:56.0970 3572 XPADFL02 (6ab0d2d28e2a984fbba5295f2dd81878) C:\WINDOWS\system32\DRIVERS\xpadfl02.sys
      2011/08/05 16:05:57.0080 3572 MBR (0x1B8) (0ac6d996bce152aed9600e6d6b797e2e) \Device\Harddisk0\DR0
      2011/08/05 16:05:57.0142 3572 Boot (0x1200) (ff2b9fedb1002f23a60cd0dd64001ff6) \Device\Harddisk0\DR0\Partition0
      2011/08/05 16:05:57.0158 3572 Boot (0x1200) (65be55c188e9c2731f3bfafd831f10fb) \Device\Harddisk0\DR0\Partition1
      2011/08/05 16:05:57.0158 3572 ================================================================================
      2011/08/05 16:05:57.0158 3572 Scan finished
      2011/08/05 16:05:57.0158 3572 ================================================================================
      2011/08/05 16:05:57.0189 4932 Detected object count: 1
      2011/08/05 16:05:57.0189 4932 Actual detected object count: 1
      2011/08/05 16:06:47.0799 4932 LockedFile.Multi.Generic(sptd) - User select action: Skip
      0
      1. desactive ton antivirus
        desactive Windows defender si présent
        desactive ton pare-feu

        Ferme toutes tes appilications en cours

        telecharge et enregistre ceci sur ton bureau :

        Pre_Scan

        mirroir :

        http://www.archive-host.com

        s'il n'est pas sur ton bureau coupe-le de ton dossier telechargements et colle-le sur ton bureau

        Avertissement: Il y aura une extinction du bureau pendant le scan --> pas de panique.

        une fois telechargé lance-le , laisse faire le scan jusqu'à l'apparition de "Pre_scan.txt" sur le bureau.

        si 'outil est bloqué par l'infection utilise cette version : Version .pif

        si l'outil detecte un proxy et que tu n'en as pas installé clique sur "supprimer le proxy"

        si l'outil semble ne pas avoir fonctionné renomme-le winlogon , ou change son extension en .com ou .scr

        Il se peut qu'une multitude de fenêtres noires clignotent , laisse-le travailler

        Poste Pre_Scan_la_date_et_l'heure.txt qui apparaitra sur le bureau en fin de scan

        ▶▶▶ NE LE POSTE PAS SUR LE FORUM (il est trop long)

        clique sur ce lien : http://www.cijoint.fr/

        ▶ Clique sur Parcourir et cherche le fichier ci-dessus.

        ▶ Clique sur Ouvrir.

        ▶ Clique sur "Cliquez ici pour déposer le fichier".

        Un lien de cette forme :

        http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

        est ajouté dans la page.

        ▶ Copie ce lien dans ta réponse.

        si ton bureau ne reapparait pas => ctrl+alt+supp , gestionnaire des taches => onglet fichier => nouvelle tache puis tape explorer
        0
        1. http://www.cijoint.fr/cjlink.php?file=cj201108/cijPt1RLd5.txt
          0
          1. ▶ Télécharge ici : Ad-remover sur ton bureau :

            ▶ Déconnecte toi et ferme toutes applications en cours !

            si tu as XP => double clique
            si tu as Vista ou windows 7 => clic droit "executer en tant que...."


            ▶ sur "Ad-R.exe" pour lancer l'installation et laisse les paramètres d'installation par défaut .

            ▶ clique le raccourci Ad-remover qui est sur ton bureau pour lancer l'outil .

            ▶ Au menu principal choisis "option Nettoyer" et tape sur [entrée] .

            ▶ Laisse travailler l'outil et ne touche à rien ...

            ▶ Poste le rapport qui apparait à la fin , sur le forum ...

            ( Le rapport est sauvegardé aussi sous C:\Ad-report.log )
            ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

            0
            1. ======= RAPPORT D'AD-REMOVER 2.0.0.2,G | UNIQUEMENT XP/VISTA/7 =======

              Mis à jour par TeamXscript le 12/04/11
              Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
              Site web: http://www.teamxscript.org

              C:\Program Files\Ad-Remover\main.exe (CLEAN [2]) -> Lancé à 18:38:49 le 05/08/2011, Mode normal

              Microsoft Windows XP Édition familiale Service Pack 3 (X86)
              HP_Propriétaire@NOM-EB85C523610 ( )

              ============== ACTION(S) ==============

              Fichier supprimé: C:\WINDOWS\system32\ConduitEngine.tmp
              Dossier supprimé: C:\Documents and Settings\HP_Propriétaire.NOM-EB85C523610\Local Settings\Application Data\Conduit
              Dossier supprimé: C:\Program Files\Conduit
              Dossier supprimé: C:\Documents and Settings\HP_Propriétaire.NOM-EB85C523610\Local Settings\Application Data\ConduitEngine
              Dossier supprimé: C:\Program Files\ConduitEngine
              Dossier supprimé: C:\Documents and Settings\HP_Propriétaire.NOM-EB85C523610\Application Data\PriceGong

              (!) -- Fichiers temporaires supprimés.

              -- Fichier ouvert: C:\Documents and Settings\HP_Propriétaire.NOM-EB85C523610\Application Data\Mozilla\FireFox\Profiles\cbj9aost.default\Prefs.js --
              Ligne supprimée: user_pref("CT2851639.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT285...
              Ligne supprimée: user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1243674/1239347/FR", "\"0\"...
              Ligne supprimée: user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2851639", ...
              Ligne supprimée: user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo...
              Ligne supprimée: user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc...
              Ligne supprimée: user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo...
              Ligne supprimée: user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local...
              Ligne supprimée: user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\...
              Ligne supprimée: user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.5....
              Ligne supprimée: user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2851639",...
              Ligne supprimée: user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT2851639&octid=...
              Ligne supprimée: user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=EB_LOCALE",...
              Ligne supprimée: user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=fr", "\"634...
              Ligne supprimée: user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Documents and Settings\\HP_Propriétaire.NO...
              Ligne supprimée: user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.5.0.12");
              Ligne supprimée: user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://redirecterror.sfr.fr/?q=");
              Ligne supprimée: user_pref("CommunityToolbar.ToolbarsList", "CT2851639");
              Ligne supprimée: user_pref("CommunityToolbar.ToolbarsList2", "CT2851639");
              Ligne supprimée: user_pref("CommunityToolbar.ToolbarsList4", "CT2851639");
              Ligne supprimée: user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Fri Aug 05 2011 15:08:59 GMT+0200");
              Ligne supprimée: user_pref("CommunityToolbar.globalUserId", "47d9335b-a8cf-449a-979a-e890c913cf4f");
              Ligne supprimée: user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
              Ligne supprimée: user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
              Ligne supprimée: user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Tue Aug 02 2011 22:30:5...
              Ligne supprimée: user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440);
              Ligne supprimée: user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Fri Aug 05 2011 15:09:09 GMT+020...
              Ligne supprimée: user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
              Ligne supprimée: user_pref("CommunityToolbar.notifications.locale", "en");
              Ligne supprimée: user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
              Ligne supprimée: user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Fri Aug 05 2011 15:08:59 GMT+0200");
              Ligne supprimée: user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1305622559");
              Ligne supprimée: user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
              Ligne supprimée: user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
              Ligne supprimée: user_pref("CommunityToolbar.notifications.showTrayIcon", false);
              Ligne supprimée: user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
              Ligne supprimée: user_pref("CommunityToolbar.notifications.userId", "4787dcd5-8c65-4330-87ae-b8dbd5de62d2");
              -- Fichier Fermé --

              Clé supprimée: HKLM\Software\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}
              Clé supprimée: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}
              Clé supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30F9B915-B755-4826-820B-08FBA6BD249D}
              Clé supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30F9B915-B755-4826-820B-08FBA6BD249D}
              Clé supprimée: HKLM\Software\Classes\CLSID\{AC6240AE-33B6-40D3-8683-31BBE86049A0}
              Clé supprimée: HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{AC6240AE-33B6-40D3-8683-31BBE86049A0}
              Clé supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AC6240AE-33B6-40D3-8683-31BBE86049A0}
              Clé supprimée: HKLM\Software\Classes\Interface\{6E4C89CF-3061-4EE4-B22A-B7A8AAEA5CB3}
              Clé supprimée: HKLM\Software\Classes\Conduit.Engine
              Clé supprimée: HKLM\Software\Classes\Toolbar.CT2851639
              Clé supprimée: HKLM\Software\Conduit
              Clé supprimée: HKLM\Software\conduitEngine
              Clé supprimée: HKLM\Software\OpenCandy
              Clé supprimée: HKCU\Software\Conduit
              Clé supprimée: HKCU\Software\conduitEngine
              Clé supprimée: HKCU\Software\PriceGong
              Clé supprimée: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
              Clé supprimée: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2A214B9-BED2-4701-AD54-95AA57F1A32E}
              Clé supprimée: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine

              Valeur supprimée: HKLM\Software\Microsoft\Internet Explorer\Toolbar|{30F9B915-B755-4826-820B-08FBA6BD249D}

              ============== SCAN ADDITIONNEL ==============

              **** Mozilla Firefox Version [3.6.18 (fr)] ****

              FIREFOX.EXE\Shell\Open\Command - "C:\Program Files\Mozilla Firefox\Firefox.exe"
              Plugins\npExentCtl.dll (Exent Technologies Ltd.)
              HKLM_MozillaPlugins\@zylom.com/ZylomGamesPlayer (x)
              HKLM_MozillaPlugins\Adobe Reader (x)
              Extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} (Click to call with Skype)
              HKLM_Extensions|FFToolbar@bitdefender.com - C:\Program Files\BitDefender\BitDefender 2010\bdaphffext\
              HKLM_Extensions|{E6768F2A-D4C3-457D-A1A8-3472BF16267D} - C:\Program Files\Orange\ToolbarFR\FirefoxContainer\

              -- C:\Documents and Settings\HP_Propriétaire.NOM-EB85C523610\Application Data\Mozilla\FireFox\Profiles\cbj9aost.default --
              Extensions\adonis.cuhk@gmail.com (Google Docs Viewer)
              Extensions\docview@mozilla.org (1-click Document view)
              Extensions\jid0-YsfoH9UOyD2AHLMzoKlEDy5AZBg@jetpack (Open PDF in Google Docs Viewer)
              Extensions\outwit-docs@outwit.com (Outwit Docs)
              Extensions\{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} (uTorrentBar_FR Community Toolbar)
              Extensions\{5fb1186a-3398-4c47-b579-0f2eee222ad1} (OutWit Kernel)
              Extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b} (Easy YouTube Video Downloader)
              Searchplugins\orange.xml (?)
              User.js - keyword.URL, hxxp://redirecterror.sfr.fr/?q=
              Prefs.js - browser.download.dir, C:\\Documents and Settings\\HP_Propriétaire.NOM-EB85C523610\\Bureau
              Prefs.js - browser.download.lastDir, C:\\Documents and Settings\\HP_Propriétaire.NOM-EB85C523610\\Bureau
              Prefs.js - browser.startup.homepage, hxxp://messagerie-11.sfr.fr/webmail/mailbox.html#
              Prefs.js - browser.startup.homepage_override.mstone, rv:1.9.2.18
              Prefs.js - keyword.URL, hxxp://redirecterror.sfr.fr/?q=

              ========================================

              **** Google Chrome Version [12.0.742.122] ****

              Google Chrome\Shell\Open\Command - C:\Program Files\Google\Chrome\Application\Chrome.exe
              Extension\paoponfhfdfnjgddpnpjkambkcgdaaib (C:\DOCUME~1\HP_PRO~1.NOM\LOCALS~1\Temp\crx1E0F.tmp) (x)

              -- C:\Documents and Settings\HP_Propriétaire.NOM-EB85C523610\Local Settings\Application Data\Google\Chrome\User Data\Default --
              Preferences - default_search_provider: "Google" (Activé: true) (?)
              Preferences - homepage: hxxp://www.google.com
              Preferences - homepage_is_newtabpage: true
              Plugin - Chrome NaCl (Activé: false) (C:\Documents and Settings\HP_Propri\u00E9taire.NOM-EB85C523610\Local Settings\Application Data\Google\Chrome\Application\12.0.742.122\ppGoogleNaClPluginChrome.dll) (x)
              Plugin - Exent\u00AE AOD Gecko Plugin (Activé: true) (C:\Program Files\Mozilla Firefox\plugins\npExentCtl.dll)
              Plugin - Windows Genuine Advantage (Activé: true) (C:\Program Files\Mozilla Firefox\plugins\npLegitCheckPlugin.dll)
              Plugin - VLC Multimedia Plugin (Activé: true) (C:\Program Files\VideoLAN\VLC\npvlc.dll)
              Plugin - "Java" (Activé: true)
              Plugin - "Silverlight" (Activé: true)
              Plugin - "Chrome NaCl" (Activé: false)
              Plugin - "BitTorrent" (Activé: true)
              Plugin - "Exent\u00AE AOD Gecko Plugin" (Activé: true)
              Plugin - "Windows Genuine Advantage" (Activé: true)
              Plugin - "Zylom Plugin" (Activé: true)
              Plugin - "getPlusPlus for Adobe 162103" (Activé: true)
              Plugin - "DNA Plug-in" (Activé: true)
              Plugin - "VLC Multimedia Plugin" (Activé: true)

              ========================================

              **** Internet Explorer Version [8.0.6001.18702] ****

              HKCU_Main|Default_Page_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
              HKCU_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
              HKCU_Main|Search bar - hxxp://go.microsoft.com/fwlink/?linkid=54896
              HKCU_Main|Start Page - hxxp://fr.msn.com/
              HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink/?LinkId=54896
              HKLM_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
              HKLM_Main|Search bar - hxxp://search.msn.com/spbasic.htm
              HKLM_Main|Search Page - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
              HKLM_Main|Start Page - hxxp://fr.msn.com/
              HKCU_URLSearchHooks|{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} - "uTorrentBar_FR Toolbar" (C:\Program Files\uTorrentBar_FR\prxtbuTor.dll)
              HKCU_Toolbar\WebBrowser|{D3028143-6145-4318-99D3-3EDCE54A95A9} (C:\Program Files\Orange\ToolbarFR\ToolbarContainer101000315.dll)
              HKCU_Toolbar\WebBrowser|{05EEB91A-AEF7-4F8A-978F-FB83E7B03F8E} (C:\Program Files\uTorrentBar_FR\prxtbuTor.dll)
              HKLM_Toolbar|{381FFDE8-2394-4f90-B10D-FC6124A40F8C} (C:\Program Files\BitDefender\BitDefender 2010\IEToolbar.dll)
              HKLM_Toolbar|{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} (C:\Program Files\uTorrentBar_FR\prxtbuTor.dll)
              HKLM_ElevationPolicy\{28896082-F101-4C06-8D83-8ED9F94129C4} - C:\Program Files\uTorrentBar_FR\uTorrentBar_FRToolbarHelper.exe (?)
              HKLM_ElevationPolicy\{80B84A0A-EDA4-47fd-8BE1-6B49F4197BE6} - C:\Program Files\BitDefender\BitDefender 2010\about.exe\about.ex (x)
              HKLM_ElevationPolicy\{80B84A0A-EDA4-47fd-8BE1-6B49F4197BE7} - WindowsFolder\hh.exe (x)
              HKLM_ElevationPolicy\{8A8DC162-D79C-4736-A716-C9B30A9C2089} - C:\Documents and Settings\HP_Propriétaire.NOM-EB85C523610\Local Settings\Application Data\Conduit\CT2851639\uTorrentBar_FRAutoUpdateHelper.exe (x)
              HKLM_ElevationPolicy\{8EBFFAE0-F0A4-4ee6-8524-2751906624C4} - C:\Program Files\Player Metaboli\GPlayer.exe (x)
              HKLM_ElevationPolicy\{B2321D2F-1154-4d97-AD3E-2FE0BAE2897B} - C:\Program Files\SFR\Kit\9launch.exe (SFR)
              HKLM_ElevationPolicy\{C8FE2181-CAE7-49EE-9B04-DB7EB4DA544A} - C:\Program Files\Java\jre1.6.0_03\bin\ssvagent.exe (x)
              BHO\{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} - "uTorrentBar_FR Toolbar" (C:\Program Files\uTorrentBar_FR\prxtbuTor.dll)
              BHO\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8} - "Objet d'aide à la navigation SFR" (C:\Program Files\SFR\Kit\SFRNavErrorHelper.dll)
              BHO\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - "Skype Browser Helper" (C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll)

              ========================================

              C:\Program Files\Ad-Remover\Quarantine: 100 Fichier(s)
              C:\Program Files\Ad-Remover\Backup: 15 Fichier(s)

              C:\Ad-Report-CLEAN[1].txt - 05/08/2011 18:26:10 (448 Octet(s))
              C:\Ad-Report-CLEAN[2].txt - 05/08/2011 18:38:52 (12801 Octet(s))

              Fin à: 18:41:41, 05/08/2011

              ============== E.O.F ==============
              0
              1. desinstalle tout ce qui contient le mot Bar ou Toolbar

                =================================

                Télécharge ici :OTL

                ▶ enregistre le sur ton Bureau.

                si tu as XP => double clique
                si tu as Vista ou windows 7 => clic droit "executer en tant que...."


                sur OTL.exe pour le lancer.

                ▶ => Clique ici pour voir la Configuration

                ▶Clic sur Analyse.

                A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).

                Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\OTL.txt)

                ▶▶▶ NE LE POSTE PAS SUR LE FORUM (il est trop long)

                Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/

                ▶ Clique sur Parcourir et cherche le fichier ci-dessus.

                ▶ Clique sur Ouvrir.

                ▶ Clique sur "Cliquez ici pour déposer le fichier".

                juste au niveau du bouton , en fin de chargement du fichier , Un lien de cette forme apparaitra :

                http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

                ▶ Copie ce lien dans ta réponse.

                ▶▶ Tu feras la meme chose avec le "Extra.txt" qui logiquement sera aussi sur ton bureau.
                0
                1. j'ai windows qui m'annonce que OTL rencontre un probleme et doit fermer
                  0
                  1. ok fais sans toucher les reglages dans ce cas...
                    0
                    1. meme sans toucher les reglages

                      je peux pas executer OTL.exe
                      0
                      1. ▶ Télécharge ZHPDiag (de Nicolas Coolman)

                        ou :ZHPDiag

                        ▶ Enregistre le sur ton Bureau.

                        Une fois le téléchargement achevé,

                        ▶ lance ZHPDiag.exe et clique sur Unzip dans la fenêtre qui s'ouvre.

                        ▶ Clique sur le tournevis puis sur Tous pour cocher toutes les cases des options.

                        ▶ Clique sur la loupe pour lancer l'analyse.

                        A la fin de l'analyse,

                        ▶ clique sur l'appareil photo et enregistre le rapport sur ton Bureau.

                        Pour me le transmettre clique sur ce lien :

                        http://www.cijoint.fr/

                        ▶ Clique sur Parcourir et cherche le fichier C:\Documents and settings\le_nom_de_ta_session\.ZHPDiag.txt

                        ▶ Clique sur Ouvrir.

                        ▶ Clique sur "Cliquez ici pour déposer le fichier".

                        Un lien de cette forme :

                        http://www.cijoint.fr/cjlink.php?file=cj200905/cib7SU.txt

                        est ajouté dans la page.

                        ▶ Copie ce lien dans ta réponse.
                        0
                        1. http://www.cijoint.fr/cjlink.php?file=cj201108/cijfnpSkGd.txt
                          0

                          1. /!\ ATTENTION SUIVRE A LA LETTRE CES INDICATIONS/!\

                            __________________________________________________________
                            >Ce logiciel n'est à utiliser que prescrit par un helper qualifié et formé à l'outil.<
                            >>>>>>>Ne pas utiliser en dehors de ce cas de figure : dangereux!<<<<<<<<
                            =====================================================


                            ▶ Surtout , pense à l'enregistrement à renommer Combofix en "ton prenom.exe" avant qu'il soit enregistré sur ton disque dur

                            Telecharge ici : Combofix

                            Avant d'utiliser ComboFix :

                            Si tu utilises AVG, IL FAUT IMPERATIVEMENT LE DESINSTALLER avant d'utiliser Combofix car il peut causer des dégâts en interaction avec l'outil pouvant mener à la réinstallation totale du système.
                            La simple désactivation du résident n'est pas suffisante.
                            Télécharge le désinstalleur d'AVG sur ce lien : https://www.avg.com/fr-fr/avg-remover
                            Choisis la version adéquate (32 ou 64 bits)/!\

                            Les logiciels d'émulation de CD comme Daemon Tools peuvent gêner les outils de désinfection. Utilise Defogger pour les désactiver temporairement :

                            ▶ Télécharge Defogger (de jpshortstuff) sur ton Bureau

                            ▶ Lance le

                            Une fenêtre apparait : clique sur "Disable"

                            ▶ Fais redémarrer l'ordinateur si l'outil te le demande

                            Note : Quand nous aurons terminé la désinfection, tu pourras réactiver ces logiciels en relançant Defogger et en cliquant sur "Re-enable"

                            _________________________________________________________
                            >> referme les fenêtres de tous les programmes en cours.
                            >> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix,
                            >>la protection en temps réel de ton Antivirus et de tes Antispywares,
                            >>qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.

                            °°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°


                            si tu as XP => double clique
                            si tu as Vista ou windows 7 => clic droit "executer en tant que...."


                            sur combofix renommé

                            ¤¤¤¤¤¤¤¤¤¤ LAISSE-LE INSTALLER LA CONSOLE DE RECUPERATION S'IL TE LE DEMANDE ¤¤¤¤¤¤¤¤¤¤

                            ▶ !!!!!NE TOUCHE A RIEN PENDANT LE TRAVAIL DE COMBOFIX (SOURIS/CLAVIER.....)!!!!!

                            ▶ n'oublie pas de reactiver la garde de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

                            ▶▶ Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

                            0
                            1. ComboFix 11-08-05.02 - HP_Propriétaire 06/08/2011 1:03.1.1 - x86
                              Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.2047.1408 [GMT 2:00]
                              Lancé depuis: c:\documents and settings\HP_PropriÚtaire.NOM-EB85C523610\Bureau\laurent.exe
                              AV: BitDefender Antivirus *Disabled/Updated* {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
                              FW: BitDefender Pare-feu *Disabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
                              .
                              .
                              (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                              .
                              .
                              C:\dfinstall.log
                              c:\windows\iun6002.exe
                              c:\windows\regedit.com
                              c:\windows\system32\config\systemprofile\WINDOWS
                              c:\windows\system32\drivers\etc\lmhosts
                              c:\windows\system32\paypal.url
                              c:\windows\system32\ps2.bat
                              c:\windows\system32\tmp.reg
                              c:\windows\system32\VIRepair
                              c:\windows\system32\VIRepair\vi.sif
                              c:\windows\system32\winx.url
                              .
                              .
                              ((((((((((((((((((((((((((((( Fichiers créés du 2011-07-05 au 2011-08-05 ))))))))))))))))))))))))))))))))))))
                              .
                              .
                              2011-08-05 23:00 . 2011-08-05 23:00 -------- d--h--w- c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Voisinage d'impression
                              2011-08-05 22:40 . 2011-08-05 22:40 512 ----a-w- C:\PhysicalDisk0_MBR.bin
                              2011-08-05 22:18 . 2011-08-05 22:40 -------- d-----w- C:\ZHP
                              2011-08-05 16:25 . 2011-08-05 16:26 -------- d-----w- c:\program files\Ad-Remover
                              2011-08-05 14:59 . 2011-08-05 15:11 -------- d-----w- C:\Kill'em
                              2011-08-04 08:52 . 2011-08-04 08:52 -------- d-----w- c:\documents and settings\Default User\Menu Démarrer
                              2011-08-01 15:37 . 2011-08-01 15:37 -------- d-----w- c:\program files\Smart File Advisor
                              2011-08-01 15:37 . 2011-08-01 15:37 -------- d-----w- c:\program files\Smart Projects
                              2011-08-01 14:51 . 2011-08-01 14:51 -------- d-----w- c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Local Settings\Application Data\Temp
                              2011-08-01 14:50 . 2011-08-01 14:50 -------- d-----w- c:\program files\uTorrent
                              2011-08-01 14:50 . 2011-08-05 23:13 -------- d-----w- c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Application Data\uTorrent
                              2011-08-01 14:50 . 2011-08-01 14:50 -------- d-----w- c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Local Settings\Application Data\uTorrent
                              2011-08-01 14:16 . 2011-08-01 14:16 -------- d-----w- c:\program files\eChanblard
                              2011-08-01 13:53 . 2011-08-01 13:53 -------- d-----w- c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Local Settings\Application Data\SoftGrid Client
                              2011-08-01 13:53 . 2011-08-01 14:09 -------- d-----w- c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Application Data\SoftGrid Client
                              2011-08-01 13:52 . 2011-08-01 13:52 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\{90140011-0061-040C-0000-0000000FF1CE}
                              2011-08-01 13:52 . 2011-08-05 23:11 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\SoftGrid Client
                              2011-08-01 13:50 . 2011-08-04 08:52 -------- d-----w- c:\program files\Microsoft Application Virtualization Client
                              2011-08-01 13:50 . 2011-08-01 13:50 -------- d-----w- c:\documents and settings\All Users\Microsoft
                              2011-08-01 08:21 . 2011-08-01 08:21 709968 ----a-w- c:\windows\is-BND7O.exe
                              2011-07-29 19:54 . 2011-08-05 22:11 -------- d-----w- c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Application Data\Skype
                              2011-07-29 19:54 . 2011-07-29 19:54 -------- d-----r- c:\program files\Skype
                              2011-07-29 19:54 . 2011-07-29 19:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
                              2011-07-11 09:13 . 2011-07-11 09:13 3727360 ----a-w- c:\program files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
                              2011-07-10 13:53 . 2011-07-10 14:13 -------- d-----w- c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\DoctorWeb
                              .
                              .
                              .
                              (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                              .
                              2011-07-06 17:52 . 2008-12-05 16:10 22712 -c--a-w- c:\windows\system32\drivers\mbam.sys
                              2011-07-06 17:52 . 2008-12-05 16:10 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
                              2011-06-26 20:11 . 2011-06-26 20:11 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
                              2011-06-06 11:35 . 2010-03-06 17:18 1859072 ----a-w- c:\windows\system32\win32k.sys
                              2011-05-14 13:15 . 2005-11-07 14:18 73728 -c--a-w- c:\windows\ALCFDRTM.VER
                              .
                              .
                              ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                              .
                              .
                              *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                              REGEDIT4
                              .
                              [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
                              "{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e}"= "c:\program files\uTorrentBar_FR\prxtbuTor.dll" [2011-03-28 176936]
                              .
                              [HKEY_CLASSES_ROOT\clsid\{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e}]
                              .
                              [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e}]
                              2011-03-28 16:22 176936 ----a-w- c:\program files\uTorrentBar_FR\prxtbuTor.dll
                              .
                              [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8}]
                              2010-07-19 16:32 165184 ----a-w- c:\program files\SFR\Kit\SFRNavErrorHelper.dll
                              .
                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
                              "{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e}"= "c:\program files\uTorrentBar_FR\prxtbuTor.dll" [2011-03-28 176936]
                              .
                              [HKEY_CLASSES_ROOT\clsid\{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e}]
                              .
                              [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
                              "{05EEB91A-AEF7-4F8A-978F-FB83E7B03F8E}"= "c:\program files\uTorrentBar_FR\prxtbuTor.dll" [2011-03-28 176936]
                              .
                              [HKEY_CLASSES_ROOT\clsid\{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e}]
                              .
                              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                              "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]
                              "uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2011-08-01 639864]
                              "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
                              .
                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                              "Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2006-05-10 94208]
                              "BDAgent"="c:\program files\BitDefender\BitDefender 2010\bdagent.exe" [2011-05-14 1198048]
                              "BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2010\IEShow.exe" [2009-10-19 71152]
                              "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
                              "Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
                              "B2C_AGENT"="c:\documents and settings\All Users\Application Data\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe" [2011-06-14 404568]
                              "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-06 449584]
                              "Smart File Advisor"="c:\program files\Smart File Advisor\sfa.exe" [2011-04-04 280824]
                              .
                              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
                              "NoStrCmpLogical"= 1 (0x1)
                              .
                              [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Agent Serveur Média.lnk]
                              path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Agent Serveur Média.lnk
                              backup=c:\windows\pss\Agent Serveur Média.lnkCommon Startup
                              .
                              [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech SetPoint.lnk]
                              path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Logitech SetPoint.lnk
                              backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup
                              HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr
                              .
                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus DX4000 Series]
                              2006-02-21 04:00 131072 -c--a-w- c:\windows\system32\spool\drivers\w32x86\3\E_FATIBEE.EXE
                              .
                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
                              2005-01-18 15:37 217088 -c--a-w- c:\program files\Logitech\Video\LogiTray.exe
                              .
                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
                              2008-04-13 18:34 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
                              .
                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
                              "RDSessMgr"=3 (0x3)
                              "RasMan"=2 (0x2)
                              "mnmsrvc"=3 (0x3)
                              "helpsvc"=2 (0x2)
                              "ERSvc"=2 (0x2)
                              .
                              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
                              "LogitechVideoRepair"=c:\program files\Logitech\Video\ISStart.exe
                              "Start WingMan Profiler"=c:\program files\Logitech\Gaming Software\LWEMon.exe /noui
                              "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                              .
                              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                              "EnableFirewall"= 0 (0x0)
                              .
                              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                              "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
                              "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
                              "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
                              "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
                              "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
                              "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
                              "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
                              "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
                              "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
                              "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
                              "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
                              "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
                              "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
                              "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                              "c:\\WINDOWS\\system32\\sessmgr.exe"=
                              "c:\\Program Files\\Nero\\Nero8\\Nero Home\\NeroHome.exe"=
                              "%windir%\\system32\\sessmgr.exe"=
                              "c:\\Program Files\\DNA\\btdna.exe"=
                              "c:\\Program Files\\Orange\\RIM\\fscommand\\RIM.exe"=
                              "c:\\Program Files\\Orange\\RIM\\fscommand\\CKSocketServer.exe"=
                              "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                              "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
                              "c:\\Program Files\\Messenger\\msmsgs.exe"=
                              "c:\\Documents and Settings\\HP_Propriétaire.NOM-EB85C523610\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
                              "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
                              "c:\\Program Files\\eChanblard\\emule.exe"=
                              "c:\\Program Files\\uTorrent\\uTorrent.exe"=
                              .
                              R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [19/09/2007 17:04 639224]
                              R2 BDVEDISK;BDVEDISK;c:\program files\BitDefender\BitDefender 2010\bdvedisk.sys [22/09/2009 08:22 85128]
                              R2 cvhsvc;Client Virtualization Handler;c:\program files\Fichiers communs\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [28/02/2010 02:33 821664]
                              R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [27/07/2008 15:30 3712]
                              R2 sftlist;Application Virtualization Client;c:\program files\Microsoft Application Virtualization Client\sftlist.exe [24/04/2010 01:10 483688]
                              R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [07/12/2009 18:46 153448]
                              R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [19/10/2009 16:04 111312]
                              R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfsxp.sys [02/12/2009 22:23 554344]
                              R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplayxp.sys [02/12/2009 22:23 211432]
                              R3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirxp.sys [02/12/2009 22:23 20584]
                              R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvolxp.sys [02/12/2009 22:23 18280]
                              R3 sftvsa;Application Virtualization Service Agent;c:\program files\Microsoft Application Virtualization Client\sftvsa.exe [24/04/2010 01:10 209768]
                              S2 Arrakis3;BitDefender Serveur Arrakis;c:\program files\Fichiers communs\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe [19/10/2009 16:06 183880]
                              S2 maconfservice;Ma-Config Service;"c:\program files\ma-config.com\maconfservice.exe" --> c:\program files\ma-config.com\maconfservice.exe [?]
                              S2 PS3 Media Server;PS3 Media Server;c:\program files\PS3 Media Server\win32\service\wrapper.exe [13/01/2010 01:24 217088]
                              S3 cdiskdun;cdiskdun;\??\c:\docume~1\HP_PRO~1\LOCALS~1\Temp\cdiskdun.sys --> c:\docume~1\HP_PRO~1\LOCALS~1\Temp\cdiskdun.sys [?]
                              S3 fsbl;F-Secure BlackLight Engine Driver;\??\c:\program files\AntivirusFirewall\Anti-Virus\fsbl5380.sys --> c:\program files\AntivirusFirewall\Anti-Virus\fsbl5380.sys [?]
                              S3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [01/12/2010 22:27 33792]
                              S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [05/12/2008 18:10 22712]
                              S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [05/12/2008 18:10 41272]
                              S3 nosGetPlusHelper;getPlus(R) Helper 3004;c:\windows\System32\svchost.exe -k nosGetPlusHelper [05/08/2004 20:00 14336]
                              S3 osppsvc;Office Software Protection Platform;c:\program files\Fichiers communs\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [09/01/2010 21:37 4640000]
                              S3 XPADFL02;XPAD Filter Service 02;c:\windows\system32\drivers\xPADFL02.sys [01/12/2010 22:28 27904]
                              .
                              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                              getPlusHelper REG_MULTI_SZ getPlusHelper
                              bdx REG_MULTI_SZ scan
                              nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
                              .
                              Contenu du dossier 'Tâches planifiées'
                              .
                              2011-08-05 c:\windows\Tasks\User_Feed_Synchronization-{397C0F84-B55C-4781-AE45-D8685C6C4773}.job
                              - c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
                              .
                              .
                              ------- Examen supplémentaire -------
                              .
                              uInternet Settings,ProxyOverride = *.local
                              IE: ajouter cette page à vos favoris Orange - c:\docume~1\HP_PRO~1.NOM\LOCALS~1\Temp\cce125E.html
                              IE: Envoyer au périphérique &Bluetooth... - c:\program files\Belkin\Bluetooth Software\btsendto_ie_ctx.htm
                              IE: traduire la page - c:\docume~1\HP_PRO~1.NOM\LOCALS~1\Temp\cce125C.html
                              IE: traduire le texte sélectionné - c:\docume~1\HP_PRO~1.NOM\LOCALS~1\Temp\cce125D.html
                              DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
                              FF - ProfilePath - c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Application Data\Mozilla\Firefox\Profiles\cbj9aost.default\
                              FF - prefs.js: browser.startup.homepage - hxxp://messagerie-11.sfr.fr/webmail/mailbox.html#
                              FF - prefs.js: keyword.URL - hxxp://redirecterror.sfr.fr/?q=
                              FF - user.js: keyword.URL - hxxp://redirecterror.sfr.fr/?q=
                              .
                              - - - - ORPHELINS SUPPRIMES - - - -
                              .
                              ShellExecuteHooks-{56F9679E-7826-4C84-81F3-532071A8BCC5} - (no file)
                              SafeBoot-AVG Anti-Spyware Driver
                              SafeBoot-AVG Anti-Spyware Guard
                              AddRemove-WBFS Manager 3.0 - c:\program files\WBFS\WBFS Manager 3.0\uninstall.exe
                              .
                              .
                              .
                              **************************************************************************
                              .
                              catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                              Rootkit scan 2011-08-06 01:17
                              Windows 5.1.2600 Service Pack 3 NTFS
                              .
                              Recherche de processus cachés ...
                              .
                              Recherche d'éléments en démarrage automatique cachés ...
                              .
                              Recherche de fichiers cachés ...
                              .
                              Scan terminé avec succès
                              Fichiers cachés: 0
                              .
                              **************************************************************************
                              .
                              --------------------- DLLs chargées dans les processus actifs ---------------------
                              .
                              - - - - - - - > 'winlogon.exe'(1204)
                              c:\windows\system32\Ati2evxx.dll
                              .
                              - - - - - - - > 'explorer.exe'(5728)
                              c:\windows\system32\eappprxy.dll
                              c:\windows\system32\webcheck.dll
                              c:\windows\system32\WPDShServiceObj.dll
                              c:\windows\system32\btncopy.dll
                              c:\windows\system32\PortableDeviceTypes.dll
                              c:\windows\system32\PortableDeviceApi.dll
                              .
                              ------------------------ Autres processus actifs ------------------------
                              .
                              c:\windows\system32\Ati2evxx.exe
                              c:\windows\system32\Ati2evxx.exe
                              c:\windows\System32\SCardSvr.exe
                              c:\windows\system32\netdde.exe
                              c:\windows\system32\msdtc.exe
                              c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
                              c:\program files\Belkin\Bluetooth Software\bin\btwdins.exe
                              c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
                              c:\program files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                              c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
                              c:\windows\system32\msiexec.exe
                              c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
                              c:\program files\Fichiers communs\Nero\Lib\NMIndexingService.exe
                              c:\program files\NVIDIA Corporation\nTune\nTuneService.exe
                              c:\windows\system32\IoctlSvc.exe
                              c:\windows\system32\locator.exe
                              c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                              c:\windows\system32\dllhost.exe
                              c:\windows\system32\wbem\wmiapsrv.exe
                              c:\program files\Windows Media Player\WMPNetwk.exe
                              c:\windows\system32\SearchIndexer.exe
                              c:\windows\system32\SearchProtocolHost.exe
                              c:\windows\system32\dllhost.exe
                              c:\windows\system32\wscntfy.exe
                              c:\windows\system32\SearchFilterHost.exe
                              .
                              **************************************************************************
                              .
                              Heure de fin: 2011-08-06 01:20:57 - La machine a redémarré
                              ComboFix-quarantined-files.txt 2011-08-05 23:20
                              .
                              Avant-CF: 87 152 644 096 octets libres
                              Après-CF: 87 339 094 016 octets libres
                              .
                              - - End Of File - - 0ABB971A3C204A7F1BF75A965F164C47
                              0
                              1. tu n'as pas desintallé utorrentBar

                                vire-la

                                ========================

                                vire aussi adobe reader 9

                                =========================


                                __________________________________________________
                                =>/!\Le script qui suit a été écrit spécialement cet ordinateur/!\ <=
                                =>il est fort déconseillé de le transposer sur un autre ordinateur !<=
                                ----------------------------------------------------------------------------


                                Toujours avec toutes les protections désactivées, fais ceci :

                                ▶ Ouvre le bloc-notes (Menu démarrer --> programmes --> accessoires --> bloc-notes)
                                ▶ Copie/colle dans le bloc-notes ce qui entre les lignes ci dessous (sans les lignes) :

                                ----------------------------------------------------------
                                KillAll::

                                File::
                                c:\windows\is-BND7O.exe

                                Rootkit::
                                c:\documents and settings\HP_PROPRIETAIRE\LOCAL SETTINGS\Temp\cdiskdun.sys

                                Registry::
                                [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] => Microsoft Policies Explorer
                                "NoStrCmpLogical"=0
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                "Adobe Reader Speed Launcher"=-

                                Driver::
                                cdiskdun

                                ------------------------------------------------------------------

                                ▶ Enregistre ce fichier sur ton Bureau (et pas ailleurs !) sous le nom CFScript.txt
                                ▶ Quitte le Bloc Notes

                                ▶ Fais un glisser/déposer de ce fichier CFScript sur le fichier combofix

                                ▶ Patiente le temps du scan. Le Bureau va disparaître à plusieurs reprises : c'est normal ! Ne touche à rien tant que le scan n'est pas terminé.
                                ▶ Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
                                ▶ Si le fichier ne s'ouvre pas, il se trouve ici => C:\ComboFix.txt

                                0
                                1. utorrentbar ne se desinstalle pas j'ai viré utorrent mais ca n'a rien changer
                                  0
                                  1. je l'ai vire depuis programesfiles
                                    0
                                    1. --ComboFix 11-08-05.02 - HP_Propriétaire 06/08/2011 1:52.2.1 - x86
                                      Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.2047.1392 [GMT 2:00]
                                      Lancé depuis: c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Bureau\laurent.exe
                                      Commutateurs utilisés :: c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Bureau\CFScript.txt
                                      AV: BitDefender Antivirus *Disabled/Updated* {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
                                      FW: BitDefender Pare-feu *Disabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
                                      .
                                      FILE ::
                                      "c:\windows\is-BND7O.exe"
                                      .
                                      .
                                      (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                                      .
                                      .
                                      c:\windows\is-BND7O.exe
                                      .
                                      .
                                      ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                                      .
                                      .
                                      -------\Legacy_CDISKDUN
                                      -------\Service_cdiskdun
                                      .
                                      .
                                      ((((((((((((((((((((((((((((( Fichiers créés du 2011-07-06 au 2011-08-06 ))))))))))))))))))))))))))))))))))))
                                      .
                                      .
                                      2011-08-05 23:00 . 2011-08-05 23:00 -------- d--h--w- c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Voisinage d'impression
                                      2011-08-05 22:40 . 2011-08-05 22:40 512 ----a-w- C:\PhysicalDisk0_MBR.bin
                                      2011-08-05 22:18 . 2011-08-05 22:40 -------- d-----w- C:\ZHP
                                      2011-08-05 16:25 . 2011-08-05 16:26 -------- d-----w- c:\program files\Ad-Remover
                                      2011-08-05 14:59 . 2011-08-05 15:11 -------- d-----w- C:\Kill'em
                                      2011-08-04 08:52 . 2011-08-04 08:52 -------- d-----w- c:\documents and settings\Default User\Menu Démarrer
                                      2011-08-01 15:37 . 2011-08-05 23:14 -------- d-----w- c:\program files\Smart File Advisor
                                      2011-08-01 15:37 . 2011-08-01 15:37 -------- d-----w- c:\program files\Smart Projects
                                      2011-08-01 14:51 . 2011-08-02 20:24 -------- d-----w- c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Local Settings\Application Data\uTorrentBar_FR
                                      2011-08-01 14:51 . 2011-08-01 14:51 -------- d-----w- c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Local Settings\Application Data\Temp
                                      2011-08-01 14:50 . 2011-08-05 23:35 -------- d-----w- c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Application Data\uTorrent
                                      2011-08-01 14:16 . 2011-08-01 14:16 -------- d-----w- c:\program files\eChanblard
                                      2011-08-01 13:53 . 2011-08-01 13:53 -------- d-----w- c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Local Settings\Application Data\SoftGrid Client
                                      2011-08-01 13:53 . 2011-08-01 14:09 -------- d-----w- c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Application Data\SoftGrid Client
                                      2011-08-01 13:52 . 2011-08-01 13:52 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\{90140011-0061-040C-0000-0000000FF1CE}
                                      2011-08-01 13:52 . 2011-08-05 23:11 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\SoftGrid Client
                                      2011-08-01 13:50 . 2011-08-04 08:52 -------- d-----w- c:\program files\Microsoft Application Virtualization Client
                                      2011-08-01 13:50 . 2011-08-01 13:50 -------- d-----w- c:\documents and settings\All Users\Microsoft
                                      2011-07-29 19:54 . 2011-08-05 22:11 -------- d-----w- c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Application Data\Skype
                                      2011-07-29 19:54 . 2011-07-29 19:54 -------- d-----r- c:\program files\Skype
                                      2011-07-29 19:54 . 2011-07-29 19:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
                                      2011-07-11 09:13 . 2011-07-11 09:13 3727360 ----a-w- c:\program files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
                                      2011-07-10 13:53 . 2011-07-10 14:13 -------- d-----w- c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\DoctorWeb
                                      .
                                      .
                                      .
                                      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                                      .
                                      2011-07-06 17:52 . 2008-12-05 16:10 22712 -c--a-w- c:\windows\system32\drivers\mbam.sys
                                      2011-07-06 17:52 . 2008-12-05 16:10 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
                                      2011-06-26 20:11 . 2011-06-26 20:11 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
                                      2011-06-06 11:35 . 2010-03-06 17:18 1859072 ----a-w- c:\windows\system32\win32k.sys
                                      2011-05-14 13:15 . 2005-11-07 14:18 73728 -c--a-w- c:\windows\ALCFDRTM.VER
                                      .
                                      .
                                      ((((((((((((((((((((((((((((( SnapShot@2011-08-05_23.13.40 )))))))))))))))))))))))))))))))))))))))))
                                      .
                                      + 2011-08-06 00:05 . 2011-08-06 00:05 16384 c:\windows\Temp\Perflib_Perfdata_9e4.dat
                                      .
                                      ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                                      .
                                      .
                                      *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                                      REGEDIT4
                                      .
                                      [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8}]
                                      2010-07-19 16:32 165184 ----a-w- c:\program files\SFR\Kit\SFRNavErrorHelper.dll
                                      .
                                      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                      "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]
                                      "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
                                      .
                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                      "Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2006-05-10 94208]
                                      "BDAgent"="c:\program files\BitDefender\BitDefender 2010\bdagent.exe" [2011-05-14 1198048]
                                      "BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2010\IEShow.exe" [2009-10-19 71152]
                                      "B2C_AGENT"="c:\documents and settings\All Users\Application Data\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe" [2011-06-14 404568]
                                      "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-06 449584]
                                      "Smart File Advisor"="c:\program files\Smart File Advisor\sfa.exe" [2011-04-04 280824]
                                      .
                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
                                      "NoStrCmpLogical"= 1 (0x1)
                                      .
                                      [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Agent Serveur Média.lnk]
                                      path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Agent Serveur Média.lnk
                                      backup=c:\windows\pss\Agent Serveur Média.lnkCommon Startup
                                      .
                                      [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech SetPoint.lnk]
                                      path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Logitech SetPoint.lnk
                                      backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup
                                      .
                                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus DX4000 Series]
                                      2006-02-21 04:00 131072 -c--a-w- c:\windows\system32\spool\drivers\w32x86\3\E_FATIBEE.EXE
                                      .
                                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
                                      2005-01-18 15:37 217088 -c--a-w- c:\program files\Logitech\Video\LogiTray.exe
                                      .
                                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
                                      2008-04-13 18:34 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
                                      .
                                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
                                      "RDSessMgr"=3 (0x3)
                                      "RasMan"=2 (0x2)
                                      "mnmsrvc"=3 (0x3)
                                      "helpsvc"=2 (0x2)
                                      "ERSvc"=2 (0x2)
                                      .
                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
                                      "LogitechVideoRepair"=c:\program files\Logitech\Video\ISStart.exe
                                      "Start WingMan Profiler"=c:\program files\Logitech\Gaming Software\LWEMon.exe /noui
                                      "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                                      .
                                      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                                      "EnableFirewall"= 0 (0x0)
                                      .
                                      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
                                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
                                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
                                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
                                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
                                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
                                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
                                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
                                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
                                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
                                      "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
                                      "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
                                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
                                      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                                      "c:\\WINDOWS\\system32\\sessmgr.exe"=
                                      "c:\\Program Files\\Nero\\Nero8\\Nero Home\\NeroHome.exe"=
                                      "%windir%\\system32\\sessmgr.exe"=
                                      "c:\\Program Files\\DNA\\btdna.exe"=
                                      "c:\\Program Files\\Orange\\RIM\\fscommand\\RIM.exe"=
                                      "c:\\Program Files\\Orange\\RIM\\fscommand\\CKSocketServer.exe"=
                                      "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                                      "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
                                      "c:\\Program Files\\Messenger\\msmsgs.exe"=
                                      "c:\\Documents and Settings\\HP_Propriétaire.NOM-EB85C523610\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
                                      "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
                                      "c:\\Program Files\\eChanblard\\emule.exe"=
                                      .
                                      R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [19/09/2007 17:04 639224]
                                      R2 BDVEDISK;BDVEDISK;c:\program files\BitDefender\BitDefender 2010\bdvedisk.sys [22/09/2009 08:22 85128]
                                      R2 cvhsvc;Client Virtualization Handler;c:\program files\Fichiers communs\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [28/02/2010 02:33 821664]
                                      R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [27/07/2008 15:30 3712]
                                      R2 sftlist;Application Virtualization Client;c:\program files\Microsoft Application Virtualization Client\sftlist.exe [24/04/2010 01:10 483688]
                                      R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [19/10/2009 16:04 111312]
                                      R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfsxp.sys [02/12/2009 22:23 554344]
                                      R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplayxp.sys [02/12/2009 22:23 211432]
                                      R3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirxp.sys [02/12/2009 22:23 20584]
                                      R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvolxp.sys [02/12/2009 22:23 18280]
                                      R3 sftvsa;Application Virtualization Service Agent;c:\program files\Microsoft Application Virtualization Client\sftvsa.exe [24/04/2010 01:10 209768]
                                      S2 Arrakis3;BitDefender Serveur Arrakis;c:\program files\Fichiers communs\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe [19/10/2009 16:06 183880]
                                      S2 maconfservice;Ma-Config Service;"c:\program files\ma-config.com\maconfservice.exe" --> c:\program files\ma-config.com\maconfservice.exe [?]
                                      S2 PS3 Media Server;PS3 Media Server;c:\program files\PS3 Media Server\win32\service\wrapper.exe [13/01/2010 01:24 217088]
                                      S3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [07/12/2009 18:46 153448]
                                      S3 fsbl;F-Secure BlackLight Engine Driver;\??\c:\program files\AntivirusFirewall\Anti-Virus\fsbl5380.sys --> c:\program files\AntivirusFirewall\Anti-Virus\fsbl5380.sys [?]
                                      S3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [01/12/2010 22:27 33792]
                                      S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [05/12/2008 18:10 22712]
                                      S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [05/12/2008 18:10 41272]
                                      S3 nosGetPlusHelper;getPlus(R) Helper 3004;c:\windows\System32\svchost.exe -k nosGetPlusHelper [05/08/2004 20:00 14336]
                                      S3 osppsvc;Office Software Protection Platform;c:\program files\Fichiers communs\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [09/01/2010 21:37 4640000]
                                      S3 XPADFL02;XPAD Filter Service 02;c:\windows\system32\drivers\xPADFL02.sys [01/12/2010 22:28 27904]
                                      .
                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                                      getPlusHelper REG_MULTI_SZ getPlusHelper
                                      bdx REG_MULTI_SZ scan
                                      nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
                                      .
                                      Contenu du dossier 'Tâches planifiées'
                                      .
                                      2011-08-06 c:\windows\Tasks\User_Feed_Synchronization-{397C0F84-B55C-4781-AE45-D8685C6C4773}.job
                                      - c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
                                      .
                                      .
                                      ------- Examen supplémentaire -------
                                      .
                                      uInternet Settings,ProxyOverride = *.local
                                      IE: ajouter cette page à vos favoris Orange - c:\docume~1\HP_PRO~1.NOM\LOCALS~1\Temp\cce125E.html
                                      IE: Envoyer au périphérique &Bluetooth... - c:\program files\Belkin\Bluetooth Software\btsendto_ie_ctx.htm
                                      IE: traduire la page - c:\docume~1\HP_PRO~1.NOM\LOCALS~1\Temp\cce125C.html
                                      IE: traduire le texte sélectionné - c:\docume~1\HP_PRO~1.NOM\LOCALS~1\Temp\cce125D.html
                                      DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
                                      FF - ProfilePath - c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Application Data\Mozilla\Firefox\Profiles\cbj9aost.default\
                                      FF - prefs.js: browser.startup.homepage - hxxp://messagerie-11.sfr.fr/webmail/mailbox.html#
                                      FF - prefs.js: keyword.URL - hxxp://redirecterror.sfr.fr/?q=
                                      FF - user.js: keyword.URL - hxxp://redirecterror.sfr.fr/?q=
                                      .
                                      - - - - ORPHELINS SUPPRIMES - - - -
                                      .
                                      URLSearchHooks-{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} - c:\program files\uTorrentBar_FR\prxtbuTor.dll
                                      BHO-{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} - c:\program files\uTorrentBar_FR\prxtbuTor.dll
                                      Toolbar-{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} - c:\program files\uTorrentBar_FR\prxtbuTor.dll
                                      WebBrowser-{05EEB91A-AEF7-4F8A-978F-FB83E7B03F8E} - c:\program files\uTorrentBar_FR\prxtbuTor.dll
                                      HKCU-Run-uTorrent - c:\program files\uTorrent\uTorrent.exe
                                      AddRemove-uTorrentBar_FR Toolbar - c:\program files\uTorrentBar_FR\uninstall.exe
                                      .
                                      .
                                      .
                                      **************************************************************************
                                      .
                                      catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                      Rootkit scan 2011-08-06 02:05
                                      Windows 5.1.2600 Service Pack 3 NTFS
                                      .
                                      Recherche de processus cachés ...
                                      .
                                      Recherche d'éléments en démarrage automatique cachés ...
                                      .
                                      Recherche de fichiers cachés ...
                                      .
                                      Scan terminé avec succès
                                      Fichiers cachés: 0
                                      .
                                      **************************************************************************
                                      .
                                      --------------------- DLLs chargées dans les processus actifs ---------------------
                                      .
                                      - - - - - - - > 'winlogon.exe'(1204)
                                      c:\windows\system32\Ati2evxx.dll
                                      .
                                      - - - - - - - > 'explorer.exe'(3688)
                                      c:\windows\system32\eappprxy.dll
                                      c:\windows\system32\webcheck.dll
                                      c:\windows\system32\WPDShServiceObj.dll
                                      c:\windows\system32\btncopy.dll
                                      c:\windows\system32\PortableDeviceTypes.dll
                                      c:\windows\system32\PortableDeviceApi.dll
                                      .
                                      ------------------------ Autres processus actifs ------------------------
                                      .
                                      c:\windows\system32\Ati2evxx.exe
                                      c:\windows\system32\Ati2evxx.exe
                                      c:\windows\System32\SCardSvr.exe
                                      c:\windows\system32\netdde.exe
                                      c:\windows\system32\msdtc.exe
                                      c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
                                      c:\program files\Belkin\Bluetooth Software\bin\btwdins.exe
                                      c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
                                      c:\program files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                                      c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
                                      c:\windows\system32\msiexec.exe
                                      c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
                                      c:\program files\Fichiers communs\Nero\Lib\NMIndexingService.exe
                                      c:\program files\NVIDIA Corporation\nTune\nTuneService.exe
                                      c:\windows\system32\IoctlSvc.exe
                                      c:\windows\system32\locator.exe
                                      c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                                      c:\windows\system32\dllhost.exe
                                      c:\windows\system32\wbem\wmiapsrv.exe
                                      c:\program files\Windows Media Player\WMPNetwk.exe
                                      c:\windows\system32\SearchIndexer.exe
                                      c:\windows\system32\SearchProtocolHost.exe
                                      c:\windows\system32\dllhost.exe
                                      c:\windows\system32\SearchFilterHost.exe
                                      .
                                      **************************************************************************
                                      .
                                      Heure de fin: 2011-08-06 02:08:48 - La machine a redémarré
                                      ComboFix-quarantined-files.txt 2011-08-06 00:08
                                      .
                                      Avant-CF: 87 429 152 768 octets libres
                                      Après-CF: 87 489 523 712 octets libres
                                      .
                                      - - End Of File - - 11672960D73EF0A1FDA051D79CE9752E

                                      j'essaie d'apporter mon aide
                                      0
                                      1. fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

                                        ▶ Télécharge ici :

                                        Malwarebytes

                                        ▶ Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

                                        (NB : Si tu as un message d'erreur t'indiquant qu'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX

                                        ▶ Potasses le Tuto pour te familiariser avec le prg :

                                        ( cela dit, il est très simple d'utilisation ).

                                        relance malwarebytes en suivant scrupuleusement ces consignes :

                                        ! Déconnecte toi et ferme toutes applications en cours !

                                        ▶ Lance Malwarebyte's .

                                        Fais un examen dit "Complet" .

                                        ▶ Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
                                        ▶ à la fin tu cliques sur "résultat" .
                                        ▶ Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

                                        ▶ Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

                                        ▶ Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)

                                        0
                                        • 1
                                        • 2