Suprimer un virus ver

Bonjour,
bjs mon pc infecté par un virus ver je n'ai aucune notion dansle domaine de protection je suis super hyper debutant merci de votre aide pour deleter ce virus voila le raport que j'ai fais avec hijackthis mais pour me cela ne veu absolument rien dire lol merci de votre aide

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe
C:\apps\ABoard\ABoard.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2S1.EXE
C:\apps\ABoard\AOSD.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\APPS\SMP\SmpSys.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
Configuration: Windows XP
Internet Explorer 6.0

14 réponses

  1. Contributeur sécurité
    bonjour,

    tu vas déjà commencer par poster un rapport hijackthis complet. celui ci n'y est pas

    une fois le bloc note ouvert
    ctrl+a pour tout sélectionner
    ctrl+c pour copier
    ctrl+v pour le coller ici
    0
    1. Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 14:03:56, on 28/10/2007
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\eHome\ehRecvr.exe
      C:\WINDOWS\eHome\ehSched.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\nvsvc32.exe
      C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
      C:\Program Files\Spyware Doctor\svcntaux.exe
      C:\Program Files\Spyware Doctor\swdsvc.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
      C:\Program Files\Spyware Doctor\SDTrayApp.exe
      C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
      C:\WINDOWS\ehome\mcrdsvc.exe
      C:\WINDOWS\ehome\ehtray.exe
      C:\WINDOWS\RTHDCPL.EXE
      C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
      C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe
      C:\apps\ABoard\ABoard.exe
      C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2S1.EXE
      C:\apps\ABoard\AOSD.exe
      C:\WINDOWS\system32\LVCOMSX.EXE
      C:\Program Files\Logitech\Video\LogiTray.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\DAEMON Tools\daemon.exe
      C:\WINDOWS\system32\RUNDLL32.EXE
      C:\APPS\SMP\SmpSys.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\Logitech\Video\FxSvr2.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\system32\dllhost.exe
      C:\WINDOWS\System32\alg.exe
      C:\WINDOWS\eHome\ehmsas.exe
      C:\Program Files\MSN Messenger\usnsvc.exe
      C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
      C:\Program Files\eMule\emule.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\befr.htm
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: (no name) - {6f0af263-93ba-47d9-8f99-134b3282e79a} - C:\WINDOWS\system32\lvceca.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
      O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
      O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
      O4 - HKLM\..\Run: [DetectorApp] C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe
      O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
      O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
      O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32"
      O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
      O4 - HKLM\..\Run: [EPSON Stylus C66 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2S1.EXE /P23 "EPSON Stylus C66 Series" /O6 "USB001" /M "Stylus C66"
      O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
      O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
      O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
      O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
      O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
      O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
      O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
      O4 - HKLM\..\RunOnce: [SpybotDeletingA9959] command /c del "C:\WINDOWS\system32\tmpE0.tmp.dll_tobedeleted_old"
      O4 - HKLM\..\RunOnce: [SpybotDeletingC2165] cmd /c del "C:\WINDOWS\system32\tmpE0.tmp.dll_tobedeleted_old"
      O4 - HKLM\..\RunOnce: [SpybotDeletingA9383] command /c del "C:\WINDOWS\system32\tmpB7.tmp.dll_tobedeleted_old"
      O4 - HKLM\..\RunOnce: [SpybotDeletingC7117] cmd /c del "C:\WINDOWS\system32\tmpB7.tmp.dll_tobedeleted_old"
      O4 - HKLM\..\RunOnce: [SpybotDeletingA5939] command /c del "C:\WINDOWS\system32\tmp1F0.tmp.dll_tobedeleted_old"
      O4 - HKLM\..\RunOnce: [SpybotDeletingC5633] cmd /c del "C:\WINDOWS\system32\tmp1F0.tmp.dll_tobedeleted_old"
      O4 - HKLM\..\RunOnce: [SpybotDeletingA6098] command /c del "C:\WINDOWS\system32\tmp1E6.tmp.dll_tobedeleted_old"
      O4 - HKLM\..\RunOnce: [SpybotDeletingC5081] cmd /c del "C:\WINDOWS\system32\tmp1E6.tmp.dll_tobedeleted_old"
      O4 - HKLM\..\RunOnce: [SpybotDeletingA5642] command /c del "C:\WINDOWS\system32\tmp1DB.tmp.dll_tobedeleted_old"
      O4 - HKLM\..\RunOnce: [SpybotDeletingC9624] cmd /c del "C:\WINDOWS\system32\tmp1DB.tmp.dll_tobedeleted_old"
      O4 - HKLM\..\RunOnce: [SpybotDeletingA2397] command /c del "C:\WINDOWS\system32\tmp1AA.tmp.dll_tobedeleted_old"
      O4 - HKLM\..\RunOnce: [SpybotDeletingC8989] cmd /c del "C:\WINDOWS\system32\tmp1AA.tmp.dll_tobedeleted_old"
      O4 - HKLM\..\RunOnce: [SpybotDeletingA6621] command /c del "C:\WINDOWS\system32\tmp17.tmp.dll_tobedeleted_old"
      O4 - HKLM\..\RunOnce: [SpybotDeletingC2819] cmd /c del "C:\WINDOWS\system32\tmp17.tmp.dll_tobedeleted_old"
      O4 - HKLM\..\RunOnce: [SpybotDeletingA1379] command /c del "C:\WINDOWS\system32\tmp16A.tmp.dll_tobedeleted_old"
      O4 - HKLM\..\RunOnce: [SpybotDeletingC4564] cmd /c del "C:\WINDOWS\system32\tmp16A.tmp.dll_tobedeleted_old"
      O4 - HKCU\..\Run: [SmpcSys] C:\APPS\SMP\SmpSys.exe
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [Log dash] C:\DOCUME~1\marco\APPLIC~1\BIRDCO~1\Bin ball grey.exe
      O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
      O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
      O4 - HKCU\..\RunOnce: [SpybotDeletingB5666] command /c del "C:\WINDOWS\system32\tmpE0.tmp.dll_tobedeleted_old"
      O4 - HKCU\..\RunOnce: [SpybotDeletingD3851] cmd /c del "C:\WINDOWS\system32\tmpE0.tmp.dll_tobedeleted_old"
      O4 - HKCU\..\RunOnce: [SpybotDeletingB260] command /c del "C:\WINDOWS\system32\tmpB7.tmp.dll_tobedeleted_old"
      O4 - HKCU\..\RunOnce: [SpybotDeletingD1614] cmd /c del "C:\WINDOWS\system32\tmpB7.tmp.dll_tobedeleted_old"
      O4 - HKCU\..\RunOnce: [SpybotDeletingB6698] command /c del "C:\WINDOWS\system32\tmp1F0.tmp.dll_tobedeleted_old"
      O4 - HKCU\..\RunOnce: [SpybotDeletingD6016] cmd /c del "C:\WINDOWS\system32\tmp1F0.tmp.dll_tobedeleted_old"
      O4 - HKCU\..\RunOnce: [SpybotDeletingB7584] command /c del "C:\WINDOWS\system32\tmp1E6.tmp.dll_tobedeleted_old"
      O4 - HKCU\..\RunOnce: [SpybotDeletingD1146] cmd /c del "C:\WINDOWS\system32\tmp1E6.tmp.dll_tobedeleted_old"
      O4 - HKCU\..\RunOnce: [SpybotDeletingB6337] command /c del "C:\WINDOWS\system32\tmp1DB.tmp.dll_tobedeleted_old"
      O4 - HKCU\..\RunOnce: [SpybotDeletingD811] cmd /c del "C:\WINDOWS\system32\tmp1DB.tmp.dll_tobedeleted_old"
      O4 - HKCU\..\RunOnce: [SpybotDeletingB6101] command /c del "C:\WINDOWS\system32\tmp1AA.tmp.dll_tobedeleted_old"
      O4 - HKCU\..\RunOnce: [SpybotDeletingD3379] cmd /c del "C:\WINDOWS\system32\tmp1AA.tmp.dll_tobedeleted_old"
      O4 - HKCU\..\RunOnce: [SpybotDeletingB1089] command /c del "C:\WINDOWS\system32\tmp17.tmp.dll_tobedeleted_old"
      O4 - HKCU\..\RunOnce: [SpybotDeletingD9705] cmd /c del "C:\WINDOWS\system32\tmp17.tmp.dll_tobedeleted_old"
      O4 - HKCU\..\RunOnce: [SpybotDeletingB5161] command /c del "C:\WINDOWS\system32\tmp16A.tmp.dll_tobedeleted_old"
      O4 - HKCU\..\RunOnce: [SpybotDeletingD5149] cmd /c del "C:\WINDOWS\system32\tmp16A.tmp.dll_tobedeleted_old"
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\lvceca.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\lvceca.dll
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\befr.htm
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
      O20 - Winlogon Notify: lvceca - C:\WINDOWS\SYSTEM32\lvceca.dll
      O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
      O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
      O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
      O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
      O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
      O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
      O23 - Service: USBDeviceService - Unknown owner - C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
      0
      1. voila le raport complettu peux m'aider pour la suite merci
        0
        1. Contributeur sécurité
          oui je regarde ton rapport à tout de suite
          0
          1. Contributeur sécurité
            re

            * Télécharge VundoFix.exe (par Atribune) sur ton Bureau

            http://www.atribune.org/ccount/click.php?id=4

            * Double-clique VundoFix.exe afin de le lancer

            * Clique sur le bouton Scan for Vundo

            * Lorsque le scan est complété, clique sur le bouton Remove Vundo

            * Une invite te demandera si tu veux supprimer les fichiers, clique YES

            * Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers

            * Tu verras une invite qui t'annonce que ton PC va redémarrer; clique OK

            * Copie/colle le contenu du rapport situé dans C:\vundofix.txt ainsi qu'un nouveau rapport HijackThis dans ta prochaine réponse

            Note: Il est possible que VundoFix soit confronté à un fichier qu'il ne peut supprimer. Si tel est le cas, l'outil se lancera au prochain redémarrage; il faut simplement suivre les instructions ci-haut, à partir de "clique sur le bouton Scan for Vundo".
            0
            1. vundofix indique pas de fichier infectés apres le scan je comprend pas tu crois autres probleme merci pour ton aide mais la je pige pas je fais quoi a present merci de me repondre
              0
              1. Contributeur sécurité
                tu postes le rapport de vundo stp

                0
                1. je ne vois pas le raport de vundo j'ai redemarer pc 2 fois deja je fais quoi a present merci on avance a petit pas je le repet suis pas un pro comme toi merci de ton aide
                  0
                  1. j'ai relancer avast et avant quand il effectuait le test memeoire il indiquait virus la il n'indiqueplus rien tu crois le scan avec vundo a reussis comment voir si je suis encore infecté par le virus ? merci
                    0
                    1. j'ai trouver raport vundo lol

                      VundoFix V6.5.11

                      Checking Java version...

                      Java version is 1.5.0.4
                      Old versions of java are exploitable and should be removed.

                      Java version is 1.5.0.10

                      Scan started at 15:46:11 28/10/2007

                      Listing files found while scanning....

                      No infected files were found.

                      Beginning removal...

                      VundoFix V6.5.11

                      Checking Java version...

                      Java version is 1.5.0.4
                      Old versions of java are exploitable and should be removed.

                      Java version is 1.5.0.10

                      Scan started at 15:48:17 28/10/2007

                      Listing files found while scanning....

                      No infected files were found.

                      Beginning removal...

                      VundoFix V6.5.11

                      Checking Java version...

                      Java version is 1.5.0.4
                      Old versions of java are exploitable and should be removed.

                      Java version is 1.5.0.10

                      Scan started at 15:53:19 28/10/2007

                      Listing files found while scanning....

                      No infected files were found.

                      Beginning removal...

                      VundoFix V6.5.11

                      Checking Java version...

                      Java version is 1.5.0.4
                      Old versions of java are exploitable and should be removed.

                      Java version is 1.5.0.10

                      Scan started at 16:01:00 28/10/2007

                      Listing files found while scanning....

                      C:\windows\system32\lvceca.dll

                      Beginning removal...

                      Attempting to delete C:\windows\system32\lvceca.dll
                      C:\windows\system32\lvceca.dll Has been deleted!

                      Performing Repairs to the registry.
                      Done!

                      VundoFix V6.5.11

                      Checking Java version...

                      Java version is 1.5.0.4
                      Old versions of java are exploitable and should be removed.

                      Java version is 1.5.0.10

                      Scan started at 16:08:52 28/10/2007

                      Listing files found while scanning....

                      No infected files were found.

                      voila dis moi ce que tu en pense merci
                      0
                      1. Contributeur sécurité
                        re

                        merci pour le rapport
                        c'est possible, mais pour li'nstant rien de sûr
                        reposte un rapport hijackthis stp
                        je serais là après diner
                        0
                        1. Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 19:34:02, on 28/10/2007
                          Platform: Windows XP SP2 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                          Boot mode: Normal

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\csrss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\WINDOWS\ehome\ehtray.exe
                          C:\WINDOWS\RTHDCPL.EXE
                          C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                          C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe
                          C:\apps\ABoard\ABoard.exe
                          C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2S1.EXE
                          C:\WINDOWS\system32\LVCOMSX.EXE
                          C:\Program Files\Logitech\Video\LogiTray.exe
                          C:\apps\ABoard\AOSD.exe
                          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                          C:\Program Files\DAEMON Tools\daemon.exe
                          C:\WINDOWS\system32\RUNDLL32.EXE
                          C:\WINDOWS\eHome\ehRecvr.exe
                          C:\Program Files\Spyware Doctor\SDTrayApp.exe
                          C:\WINDOWS\eHome\ehSched.exe
                          C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                          C:\APPS\SMP\SmpSys.exe
                          C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\WINDOWS\system32\nvsvc32.exe
                          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                          C:\Program Files\Spyware Doctor\svcntaux.exe
                          C:\Program Files\Spyware Doctor\swdsvc.exe
                          C:\Program Files\Logitech\Video\FxSvr2.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
                          C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
                          C:\WINDOWS\ehome\mcrdsvc.exe
                          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                          C:\WINDOWS\system32\dllhost.exe
                          C:\WINDOWS\System32\alg.exe
                          C:\Program Files\MSN Messenger\usnsvc.exe
                          C:\WINDOWS\eHome\ehmsas.exe
                          C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\WINDOWS\system32\wbem\wmiprvse.exe
                          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\befr.htm
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                          O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                          O2 - BHO: (no name) - {6f0af263-93ba-47d9-8f99-134b3282e79a} - C:\WINDOWS\system32\lvceca.dll (file missing)
                          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                          O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                          O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                          O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
                          O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                          O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                          O4 - HKLM\..\Run: [DetectorApp] C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe
                          O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                          O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
                          O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32"
                          O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
                          O4 - HKLM\..\Run: [EPSON Stylus C66 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2S1.EXE /P23 "EPSON Stylus C66 Series" /O6 "USB001" /M "Stylus C66"
                          O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
                          O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
                          O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
                          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                          O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
                          O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
                          O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
                          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                          O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
                          O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
                          O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
                          O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
                          O4 - HKLM\..\Run: [6068ae98] rundll32.exe "C:\WINDOWS\mliifd.dll",b
                          O4 - HKCU\..\Run: [SmpcSys] C:\APPS\SMP\SmpSys.exe
                          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                          O4 - HKCU\..\Run: [Log dash] C:\DOCUME~1\marco\APPLIC~1\BIRDCO~1\Bin ball grey.exe
                          O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
                          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                          O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
                          O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
                          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                          O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\lvceca.dll (file missing)
                          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\lvceca.dll (file missing)
                          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\befr.htm
                          O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
                          O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                          O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                          O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
                          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                          O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                          O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                          O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
                          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                          O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                          O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
                          O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
                          O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
                          O23 - Service: USBDeviceService - Unknown owner - C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
                          0
                          1. Contributeur sécurité
                            re

                            il te reste du norton dans ton pc, faudrait le désinstaller complètement
                            sert toi de ce lien
                            http://speedweb1.free.fr/frames2.php?page=divers3

                            * lance hijackthis puis coche ces ilgnes :

                            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
                            O2 - BHO: (no name) - {6f0af263-93ba-47d9-8f99-134b3282e79a} - C:\WINDOWS\system32\lvceca.dll (file missing)
                            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                            O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                            O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                            O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                            O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                            O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32"
                            O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
                            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                            O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
                            O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
                            O4 - HKLM\..\Run: [6068ae98] rundll32.exe "C:\WINDOWS\mliifd.dll",b
                            O4 - HKCU\..\Run: [Log dash] C:\DOCUME~1\marco\APPLIC~1\BIRDCO~1\Bin ball grey.exe
                            O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\lvceca.dll (file missing)
                            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\lvceca.dll (file missing)
                            O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

                            * toutes applications fermées et HORS CONNEXION clique sur fix checked

                            puis

                            OTMoveIt

                            Télécharge OTMoveIt (de Old_Timer) sur ton Bureau.
                            http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe

                            double-clique sur OTMoveIt.exe pour le lancer.
                            copie la liste qui se trouve en citation ci-dessous,
                            et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

                            C:\WINDOWS\mliifd.dll

                            clique sur MoveIt! pour lancer la suppression.
                            le résultat apparaitra dans le cadre Results.
                            clique sur Exit pour fermer.
                            poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

                            il te sera peut-être demander de redémarrer le pc pour achever la suppression.
                            si c'est le cas accepte par Yes.

                            puis

                            * Télécharge combofix.exe (par sUBs) sur ton Bureau
                            http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                            * Double clique combofix.exe.

                            * Tape sur la touche Y (Yes) pour démarrer le scan.

                            * Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse

                            NOTE : Le rapport se trouve également ici : C:\Combofix.txt

                            puis

                            * Télécharge LopXPMH sur ton Bureau.
                            http://www.alt-shift-return.org/Info/Fichiers/lopxpMH2.zip

                            * Dézippe-le (clic droit >> Extraire ici) et double clique sur le fichier lopxpMH.bat.
                            * Poste le contenu du rapport qui va s'ouvrir.

                            ainsi qu'un nouveau rapport hijackthis
                            0
                            1. merci de ton aide je fais cela cet aprem je te tiens au courrant la je rentre dans des choses qui vont etre difficile pour moi mais grace a ton aide je vais y arriver merci
                              0