Mayday: DOWNLOADER.VIRUS

Résolu
Bonjour a vous tous,

j'ai un probleme sur mon ordinateur et je voulais savoir si vous pouvez m'aider.
En fait mon antivirus reconnais l'existence de "DOWNLOADER.VIRUS" ET " INFOSTEDER.GAMPASS" mais il n'arrive pas a les enlever. Que faut il faire???

Merci d'avance de votre aide.

Ce que j'ai fais j'ai tourner Ad-Aware et CCleaner. J'ai vu ailleurs qu'il faut faire Spybot mais je ne sais pas comment le telecharger?

MERCI BCP DE votre aide
++ :)
Configuration: Windows XP
Firefox 2.0.0.14

9 réponses

  1. Contributeur sécurité
    slt,

    scan avec
    MalwareByte's Anti-Malware et vire ce qui est trouvé et colle le rapport

    https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

    ______________

    colle un rapport hijackthis

    http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download

    manuel :
    http://pagesperso-orange.fr/rginformatique/section%20virus/demohijack.htm
    https://leblogdeclaude.blogspot.com/2006/10/informatique-section-hijackthis.html

    Je conseille de renomer Hijackthis, pour contrer une éventuelle infection de Vundo.

    ex:Renomme le fichier HijackThis.exe en eden.exe pour cela, fais un clic droit sur le fichier HijackThis.exe et choisis renommer dans la liste

    Ensuite avec Explorer créer un dossier c:\hijackthis
    Décompresser Hijackthis dans ce dossier.
    C'est important pour les sauvegardes."
    0
    1. Salut,

      Merci pour votre aide.

      Alors j'ai fais tourner MalawareByte et Hijackthis voila les rapports:

      MalawareByte
      Malwarebytes' Anti-Malware 1.12
      Version de la base de données: 742

      Type de recherche: Examen complet (C:\|D:\|)
      Eléments examinés: 122017
      Temps écoulé: 1 hour(s), 32 minute(s), 18 second(s)

      Processus mémoire infecté(s): 0
      Module(s) mémoire infecté(s): 0
      Clé(s) du Registre infectée(s): 143
      Valeur(s) du Registre infectée(s): 9
      Elément(s) de données du Registre infecté(s): 0
      Dossier(s) infecté(s): 18
      Fichier(s) infecté(s): 74

      Processus mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Module(s) mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Clé(s) du Registre infectée(s):
      HKEY_CLASSES_ROOT\CLSID\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{53ced2d0-5e9a-4761-9005-648404e6f7e5} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\mywebsearchtoolbar.settingsplugin (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\mywebsearchtoolbar.settingsplugin.1 (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\funwebproducts.iecookiesmanager (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{0f8ecf4f-3646-4c3a-8881-8e138ffcaf70} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{b813095c-81c0-4e40-aa14-67520372b987} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{c9d7be3e-141a-4c85-8cd6-32461f3df2c7} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{cff4ce82-3aa2-451f-9b77-7165605fb835} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\funwebproducts.iecookiesmanager.1 (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{1e0de227-5ce4-4ea3-ab0c-8b03e1aa76bc} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\funwebproducts.datacontrol (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\funwebproducts.datacontrol.1 (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\funwebproducts.shellviewcontrol (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{2eff3cf7-99c1-4c29-bc2b-68e057e22340} (Adware.MyWebSearch) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2eff3cf7-99c1-4c29-bc2b-68e057e22340} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\funwebproducts.shellviewcontrol.1 (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\funwebproducts.htmlmenu (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\funwebproducts.htmlmenu.2 (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\mywebsearch.htmlpanel (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{3e720452-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3e720452-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\mywebsearch.htmlpanel.1 (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\mywebsearchtoolbar.toolbarplugin (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\mywebsearchtoolbar.toolbarplugin.1 (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\funwebproducts.popswattersettingscontrol (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{8e6f1832-9607-4440-8530-13be7c4b1d14} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{a9571378-68a1-443d-b082-284f960c6d17} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\funwebproducts.popswattersettingscontrol.1 (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{7473d292-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{7473d296-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin.1 (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{84da4fdf-a1cf-4195-8688-3e961f505983} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\funwebproducts.popswatterbarbutton (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\funwebproducts.popswatterbarbutton.1 (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{938aa51a-996c-4884-98ce-80dd16a5c9da} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\funwebproducts.htmlmenu.1 (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\screensavercontrol.screensaverinstaller (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\screensavercontrol.screensaverinstaller.1 (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\funwebproducts.browseroverlayembed (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{a6573479-9075-4a65-98a6-19fd29cf7374} (Adware.MyWebSearch) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{a6573479-9075-4a65-98a6-19fd29cf7374} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{d778513b-1c40-4819-b0c5-49e40b39afd0} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\funwebproducts.browseroverlayembed.1 (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\mywebsearch.outlookaddin (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{adb01e81-3c79-4272-a0f1-7b2be7a782dc} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\mywebsearch.outlookaddin.1 (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\funwebproducts.killerobjmanager (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\funwebproducts.killerobjmanager.1 (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\funwebproducts.historykillerscheduler (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\funwebproducts.historykillerscheduler.1 (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\funwebproducts.historyswattercontrolbar (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\funwebproducts.historyswattercontrolbar.1 (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\funwebproducts.browseroverlaybarbutton (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\funwebproducts.browseroverlaybarbutton.1 (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{d9fffb27-d62a-4d64-8cec-1ff006528805} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\mywebsearch.chatsessionplugin (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\mywebsearch.chatsessionplugin.1 (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{07b18eaa-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{07b18eac-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{f87d7fb5-9dc5-4c8c-b998-d8dfe02e2978} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Typelib\{07b18ea0-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25e} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25f} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Typelib\{0d26bc71-a633-4e71-ad31-eadc3a1b6a3a} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{1093995a-ba37-41d2-836e-091067c4ad17} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{120927bf-1700-43bc-810f-fab92549b390} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{17de5e5e-bfe3-4e83-8e1f-8755795359ec} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{1f52a5fa-a705-4415-b975-88503b291728} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{247a115f-06c2-4fb3-967d-2d62d3cf4f0a} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{2763e333-b168-41a0-a112-d35f96f410c0} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{2e3537fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Typelib\{29d67d3c-509a-4544-903f-c8c1b8236554} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{38a7c9da-8db7-4d0f-a7b1-c4b1a305bddb} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{3e1656ed-f60e-4597-b6aa-b6a58e171495} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{3e53e2cb-86db-4a4a-8bd9-ffeb7a64df82} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{3e720451-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{3e720453-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Typelib\{3e720450-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Typelib\{621feacd-8857-43a6-ae26-451d670d5370} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{63d0ed2b-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{63d0ed2d-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{6e74766c-4d93-4cc0-96d1-47b8e07ff9ca} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{72ee7f04-15bd-4845-a005-d6711144d86a} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{7473d291-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{7473d293-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{7473d295-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{7473d297-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Typelib\{7473d290-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{90449521-d834-4703-bb4e-d3aa44042ff8} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{991aac62-b100-47ce-8b75-253965244f69} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{bbabdc90-f3d5-4801-863a-ee6ae529862d} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{d6ff3684-ad3b-48eb-bbb4-b9e6c5a355c1} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{eb9e5c1c-b1f9-4c2b-be8a-27d6446fdaf8} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Typelib\{8ca01f0e-987c-49c3-b852-2f1ac4a7094c} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{8d292ec0-6792-4a38-82ed-73a087e41ba6} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Typelib\{8e6f1830-9607-4440-8530-13be7c4b1d14} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Typelib\{98635087-3f5d-418f-990c-b1efe0797a3b} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{a626cdbd-3d13-4f78-b819-440a28d7e8fc} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Typelib\{c8cecde3-1ae1-4c4a-ad82-6d5b00212144} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{de38c398-b328-4f4c-a3ad-1b5e4ed93477} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Typelib\{e47caee0-deea-464a-9326-3f2801535a4d} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{e79dfbc9-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{e79dfbcb-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Typelib\{e79dfbc0-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Typelib\{f42228fb-e84e-479e-b922-fbbd096e792c} (Adware.MyWebSearch) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> No action taken.
      HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-f3embed (Adware.MyWebSearch) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall (Adware.MyWebSearch) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> No action taken.
      HKEY_CURRENT_USER\Software\MyWebSearch (Adware.MyWebSearch) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> No action taken.

      Valeur(s) du Registre infectée(s):
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MyWebSearch Email Plugin (Adware.MyWebSearch) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\My Web Search Bar Search Scope Monitor (Adware.MyWebSearch) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MyWebSearch Email Plugin (Adware.MyWebSearch) -> No action taken.
      HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
      HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
      HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&Search\ (Adware.Hotbar) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\WMSDK\Sources\f3PopularScreensavers (Adware.MyWebSearch) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\FunWebProducts (Adware.MyWebSearch) -> No action taken.

      Elément(s) de données du Registre infecté(s):
      (Aucun élément nuisible détecté)

      Dossier(s) infecté(s):
      C:\Program Files\MyWebSearch (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\SrchAstt (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\Avatar (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\Cache (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\Game (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\History (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\icons (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\Message (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\Notifier (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\Settings (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\SrchAstt\1.bin (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\FunWebProducts (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\FunWebProducts\ScreenSaver (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\FunWebProducts\Shared (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\FunWebProducts\ScreenSaver\Images (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\FunWebProducts\Shared\Cache (Adware.MyWebSearch) -> No action taken.

      Fichier(s) infecté(s):
      C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\F3HISTSW.DLL (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\F3DTACTL.DLL (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\F3SHLLVW.DLL (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\F3POPSWT.DLL (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\M3SKIN.DLL (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\F3CJPEG.DLL (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\F3BROVLY.DLL (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\F3HTTPCT.DLL (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\M3MSG.DLL (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\Internet Explorer\msimg32.dll (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\Mozilla Firefox\plugins\NPMyWebS.dll (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\F3IMSTUB.DLL (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\F3REPROX.DLL (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\F3RESTUB.DLL (Adware.MyWeb.FunWeb) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\F3SCHMON.EXE (Adware.MyWeb.FunWeb) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\M3IDLE.DLL (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL (Adware.MyWebSearch) -> No action taken.
      C:\WINDOWS\system32\f3PSSavr.scr (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\F3BKGERR.JPG (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\F3SPACER.WMV (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\F3WALLPP.DAT (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\Avatar\COMMON.F3S (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\Cache\00EAEF0B.bin (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\Cache\00EAF1B4.bin (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\Cache\00EAF358.bin (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\Cache\00EAF543.bin (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\Cache\01D950FF (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\Cache\files.ini (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\History\search2 (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\icons\CM.ICO (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\icons\MFC.ICO (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\icons\PSS.ICO (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\icons\SMILEY.ICO (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\icons\WB.ICO (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\icons\ZWINKY.ICO (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\Message\COMMON.F3S (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\Notifier\COMMON.F3S (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\Notifier\DOG.F3S (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\Notifier\FISH.F3S (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\Notifier\KUNGFU.F3S (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\Notifier\LIFEGARD.F3S (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\Notifier\MAID.F3S (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\Notifier\MAILBOX.F3S (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\Notifier\OPERA.F3S (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\Notifier\ROBOT.F3S (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\Notifier\SEDUCT.F3S (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\Notifier\SURFER.F3S (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\Settings\prevcfg2.htm (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn.html (Adware.MyWebSearch) -> No action taken.
      C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html (Adware.MyWebSearch) -> No action taken.

      Hijackthis

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 20:36:57, on 12/05/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16640)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\S24EvMon.exe
      C:\WINDOWS\system32\ZCfgSvc.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
      C:\WINDOWS\system32\drivers\CDAC11BA.EXE
      C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\Program Files\Microsoft LifeCam\MSCamS32.exe
      C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
      C:\WINDOWS\system32\RegSrvc.exe
      C:\Program Files\Fichiers communs\RbtProt\sgsrv.exe
      C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\WLTRYSVC.EXE
      C:\WINDOWS\System32\bcmwltry.exe
      C:\WINDOWS\system32\SearchIndexer.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
      C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Skype\Phone\Skype.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Program Files\Skype\Plugin Manager\skypePM.exe
      C:\Program Files\Windows Live\Messenger\usnsvc.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
      O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
      O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
      O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
      O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
      O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
      O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
      O4 - Startup: IMVU.lnk = C:\Program Files\IMVU\IMVUClient.exe
      O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\sazar\Menu Démarrer\Programmes\IMVU\Run IMVU.lnk (file missing)
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
      O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - https://www.eset.com/
      O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
      O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: Bluetooth Service (btwdins) - Unknown owner - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
      O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
      O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
      O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
      O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe
      O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe
      O23 - Service: SoftGuard Service (SG_Service) - Unknown owner - C:\Program Files\Fichiers communs\RbtProt\sgsrv.exe
      O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
      O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
      O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
      0
      1. Contributeur sécurité
        Relance HijackThis, choisis "do a scan only" coche la case devant les lignes ci-dessous et clic en bas sur "fix checked".

        R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
        O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\sazar\Menu Démarrer\Programmes\IMVU\Run IMVU.lnk (file missing)

        __________

        lance cwshredder (faire fix) : a telecharger sur un des trois liens

        https://www.trendmicro.com/en_us/forHome.html
        https://www.01net.com/actualites/
        https://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/27497.html
        ______________

        télécharge combofix (par sUBs) ici :

        http://download.bleepingcomputer.com/sUBs/ComboFix.exe

        et enregistre le sur le bureau.

        déconnecte toi d'internet et ferme toutes tes applications.

        désactive tes protections (antivirus, parefeu, garde en temps réel de l'antispyware)

        double-clique sur combofix.exe et suis les instructions

        à la fin, il va produire un rapport C:\ComboFix.txt

        réactive ton parefeu, ton antivirus, la garde de ton antispyware

        copie/colle le rapport C:\ComboFix.txt dans ta prochaine réponse.

        Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi.

        Tu as un tutoriel complet ici :

        https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

        _____________________

        colle le rapport d'un scan en ligne
        avec un des suivants:

        bitdefender en ligne :
        http://www.bitdefender.fr/scan_fr/scan8/ie.html

        Panda en ligne :
        http://pandasoftware.fr

        Kaspersky en ligne
        https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
        0
        1. Merci jlpjlp,

          alors comme vous m'avez demande, j'ai:
          1- fixe les 5 lignes sur HijackThis
          2- lance cwshredder qui n'a rien trouve
          3- lance combofix et voila le rapport:
          ComboFix 08-05-11.1 - sazar 2008-05-12 21:14:16.1 - NTFSx86 MINIMAL
          Endroit: C:\Documents and Settings\sazar\Bureau\ComboFix.exe

          [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
          .

          (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
          .

          C:\WINDOWS\system32\,)),,,,,,),,)WW,),WWW,W,.exe
          C:\WINDOWS\system32\lsprst7.dll
          C:\WINDOWS\system32\prsgrc.dll
          C:\WINDOWS\system32\ssprs.dll

          .
          ((((((((((((((((((((((((((((( Fichiers créés 2008-04-12 to 2008-05-12 ))))))))))))))))))))))))))))))))))))
          .

          2008-05-12 18:31 . 2008-05-12 18:31 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
          2008-05-12 18:31 . 2008-05-12 18:31 <REP> d-------- C:\Documents and Settings\sazar\Application Data\Malwarebytes
          2008-05-12 18:31 . 2008-05-12 18:31 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
          2008-05-12 18:31 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
          2008-05-12 18:31 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
          2008-05-12 15:43 . 2008-05-12 16:03 <REP> d-------- C:\Documents and Settings\sazar\Application Data\skypePM
          2008-05-12 15:43 . 2008-05-12 15:43 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat
          2008-05-12 15:40 . 2008-05-12 15:40 <REP> d-------- C:\Program Files\Skype
          2008-05-12 15:40 . 2008-05-12 15:40 <REP> d-------- C:\Program Files\Fichiers communs\Skype
          2008-05-12 15:40 . 2008-05-12 17:40 <REP> d-------- C:\Documents and Settings\sazar\Application Data\Skype
          2008-04-21 18:02 . 2008-04-21 18:02 4,030 --a------ C:\WINDOWS\image.jpg
          2008-04-21 01:10 . 2008-04-21 01:10 <REP> d-------- C:\Program Files\Fichiers communs\xing shared
          2008-04-14 16:13 . 2008-04-14 16:13 <REP> d-------- C:\Documents and Settings\sazar\.spss
          2008-04-14 16:03 . 2008-04-14 16:03 <REP> d-------- C:\Documents and Settings\All Users\Application Data\SafeNet Sentinel
          2008-04-14 16:03 . 2008-04-14 16:03 1,024 --a------ C:\WINDOWS\system32\grcauth2.dll
          2008-04-14 16:03 . 2008-04-14 16:03 1,024 --a------ C:\WINDOWS\system32\grcauth1.dll
          2008-04-14 16:03 . 2008-04-14 16:08 114 --a------ C:\WINDOWS\system32\prsgrc.tgz
          2008-04-14 15:59 . 2008-04-14 15:59 <REP> d-------- C:\Program Files\SPSSInc
          2008-04-14 15:59 . 2008-04-22 15:24 <REP> d-------- C:\Program Files\Fichiers communs\SPSS
          2008-04-14 15:59 . 2008-04-14 15:59 <REP> d-------- C:\Documents and Settings\All Users\Application Data\SPSS
          2008-04-14 15:58 . 2008-04-14 15:58 0 --a------ C:\law.sp

          .
          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          2008-05-12 19:11 1,916 ----a-w C:\WINDOWS\system32\drivers\fwdrv.err
          2008-05-12 18:34 --------- d-----w C:\Program Files\Trend Micro
          2008-05-12 15:23 --------- d-----w C:\Program Files\Robot Office
          2008-05-12 13:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
          2008-05-10 00:39 --------- d-----w C:\Program Files\SPSS
          2008-05-09 03:01 --------- d-----w C:\Program Files\AMOS 5
          2008-05-06 20:38 --------- d-----w C:\Documents and Settings\sazar\Application Data\AdobeUM
          2008-04-20 23:09 --------- d-----w C:\Program Files\Fichiers communs\Real
          2008-04-05 15:29 --------- d-----w C:\Program Files\Western Digital Technologies
          2008-03-20 08:09 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys
          2008-03-18 21:17 --------- d-----w C:\Program Files\Windows Live
          2008-03-01 12:58 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
          2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
          2008-02-20 05:35 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
          .

          ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
          .
          .
          REGEDIT4
          *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00 15360]
          "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]
          "updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]
          "Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-04-30 17:33 22058792]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "vptray"="C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe" [2002-09-02 13:16 77824]
          "ATIModeChange"="Ati2mdxx.exe" [2002-08-28 18:17 28672 C:\WINDOWS\system32\Ati2mdxx.exe]
          "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-04-24 22:00 327680]
          "PRONoMgr.exe"="C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe" [2002-12-18 15:20 86016]
          "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312]
          "LifeCam"="C:\Program Files\Microsoft LifeCam\LifeExp.exe" [2007-05-17 23:45 279912]
          "TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-04-21 01:07 185896]

          [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
          "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]

          [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
          "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2007-02-05 15:39 294400]

          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
          C:\WINDOWS\system32\LgNotify.dll 2003-03-24 13:26 110592 C:\WINDOWS\system32\LgNotify.dll

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\OneCareMP]
          @="Service"

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
          "EnableFirewall"= 0 (0x0)

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
          "%windir%\\system32\\sessmgr.exe"=
          "C:\\Program Files\\Messenger\\msmsgs.exe"=
          "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
          "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
          "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
          "C:\\Program Files\\Sunbelt Software\\Personal Firewall\\kpf4gui.exe"=
          "C:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
          "C:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
          "C:\\Program Files\\iTunes\\iTunes.exe"=
          "C:\\Program Files\\SPSSInc\\SPSS16FR\\spss.com"=
          "C:\\Program Files\\SPSSInc\\SPSS16FR\\spss.exe"=
          "C:\\Program Files\\SPSSInc\\SPSS16FR\\SPSSWinWrapIDE.exe"=
          "C:\\Program Files\\Skype\\Phone\\Skype.exe"=

          R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2007-04-26 11:21]
          R3 WBSD;Winbond Secure Digital Storage (SD/MMC) Device Driver;C:\WINDOWS\system32\Drivers\WBSD.SYS [2003-03-20 18:24]
          S1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2007-04-26 11:21]
          S2 MSCamSvc;MSCamSvc;"C:\Program Files\Microsoft LifeCam\MSCamS32.exe" [2007-05-17 23:45]
          S2 SG_Service;SoftGuard Service;C:\Program Files\Fichiers communs\RbtProt\sgsrv.exe [2003-10-25 13:51]
          S2 SPF4;Sunbelt Personal Firewall 4;"C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe" [2007-04-26 11:21]
          S3 MBAMCatchMe;MBAMCatchMe;C:\WINDOWS\system32\drivers\mbamcatchme.sys [2008-05-05 20:46]
          S3 MSHUSBVideo;NX6000/NX3000/VX7000 Filter Driver;C:\WINDOWS\system32\Drivers\nx6000.sys [2007-04-12 23:46]
          S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 00:08]

          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
          \Shell\AutoRun\command - G:\LaunchU3.exe -a

          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{19dca3e2-1364-11dc-8aab-000cf100bcb5}]
          \Shell\AutoRun\command - WINFILE.exe

          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c2e4a960-2e20-11dc-8af8-0020e0817671}]
          \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL antihost.exe

          .
          Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
          "2008-05-07 16:20:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
          - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
          "2008-05-10 00:26:08 C:\WINDOWS\Tasks\Microsoft_Hardware_Launch_IcePick_exe.job"
          - C:\Program Files\Microsoft LifeCam\IcePick.exe
          "2008-05-12 19:05:02 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"
          - C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
          .
          **************************************************************************

          catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2008-05-12 21:18:11
          Windows 5.1.2600 Service Pack 2 NTFS

          Balayage processus cachés ...

          Balayage caché autostart entries ...

          Balayage des fichiers cachés ...

          Scan terminé avec succès
          Les fichiers cachés: 0

          **************************************************************************
          .
          --------------------- DLLs a chargé sous des processus courants ---------------------

          PROCESS: C:\WINDOWS\system32\winlogon.exe
          -> C:\WINDOWS\system32\NavLogon.dll
          .
          Temps d'accomplissement: 2008-05-12 21:20:46
          ComboFix-quarantined-files.txt 2008-05-12 19:20:28

          Pre-Run: 14,634,184,704 octets libres
          Post-Run: 14,629,834,752 octets libres

          137 --- E O F --- 2008-04-11 05:58:09

          4- lance bitdifender et voila le rapport:
          <HTML>
          <HEAD>
          <TITLE>BitDefender Online Scanner -Scan Report</TITLE>
          <META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
          <meta name="generator" content="Namo WebEditor v5.0(Trial)">
          </HEAD>
          <BODY BGCOLOR=#FFFFFF leftmargin="10" marginwidth="0" topmargin="20" marginheight="0" >

          <table align="center" border="0" cellpadding="0" cellspacing="0" width="90%">
          <tr>
          <td width="458">
          <p><font face="Arial" color=red><span style="font-size:14pt;"><b>BitDefender
          Online Scanner</b></span></font></p>
          </td>
          <td width="40%">
          <p> </p>
          </td>
          <td width="10%">
          <p> </p>
          </td>
          </tr>
          <tr>
          <td colspan="3" width="912">
          <p><font face="Arial"><span style="font-size:11pt;"><B>Scan report generated
          at: Mon, May 12, 2008 - 23:15:01</b></span></font></p>
          </td>
          </tr>

          <tr>
          <td width="458">
          <p><font face="Arial"><span style="font-size:11pt;"><B> </b></span></font></p>
          </td>
          <td width="40%">
          <p> </p>
          </td>
          <td width="10%">
          <p> </p>
          </td>
          </tr>

          <tr>
          <td width="458">
          <p><font face="Arial"><span style="font-size:11pt;"><B>Scan
          path: </b></span><span style="font-size:10pt;">C:\;D:\;E:\;F:\;</span></font></p>
          </td>
          <td width="40%">
          <p> </p>
          </td>
          <td width="10%">
          <p> </p>
          </td>
          </tr>

          <tr>
          <td width="458">
          <p><font face="Arial"><span style="font-size:11pt;"><B> </b></span></font></p>
          </td>
          <td width="40%">
          <p> </p>
          </td>
          <td width="10%">
          <p> </p>
          </td>
          </tr>

          <tr>
          <td width="458">
          <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
          <tr>
          <td width="451" colspan="2" bgcolor="#CCCCCC">
          <p><font face="Arial" size="2"><B>Statistics</b></font></p>
          </td>
          </tr>
          <tr>
          <td width="57%">
          <p><font face="Arial" size="2">Time</font></p>
          </td>
          <td width="43%" align="right">
          <p><font face="Arial" size="2">01:43:19</font></p>
          </td>
          </tr>
          <tr>
          <td width="57%">
          <p><font face="Arial" size="2">Files</font></p>
          </td>
          <td width="43%" align="right">
          <p><font face="Arial" size="2">318829</font></p>
          </td>
          </tr>
          <tr>
          <td width="57%">
          <p><font face="Arial" size="2">Folders</font></p>
          </td>
          <td width="43%" align="right">
          <p><font face="Arial" size="2">7555</font></p>
          </td>
          </tr>
          <tr>
          <td width="57%">
          <p><font face="Arial" size="2">Boot Sectors</font></p>
          </td>
          <td width="43%" align="right">
          <p><font face="Arial" size="2">3</font></p>
          </td>
          </tr>
          <tr>
          <td width="57%">
          <p><font face="Arial" size="2">Archives</font></p>
          </td>
          <td width="43%" align="right">
          <p><font face="Arial" size="2">10640</font></p>
          </td>
          </tr>
          <tr>
          <td width="57%">
          <p><font face="Arial" size="2">Packed Files</font></p>
          </td>
          <td width="43%" align="right">
          <p><font face="Arial" size="2">17144</font></p>
          </td>
          </tr>
          </table>
          </td>
          <td width="40%">
          <p> </p>
          </td>
          <td width="10%">
          <p> </p>
          </td>
          </tr>

          <tr>
          <td width="458">
          <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
          <tr>
          <td width="451" colspan="2" bgcolor="#CCCCCC">
          <p><font face="Arial" size="2"><B>Results</b></font></p>
          </td>
          </tr>
          <tr>
          <td width="57%">
          <p><font face="Arial" size="2">Identified Viruses </font></p>
          </td>
          <td width="43%" align="right">
          <p><font face="Arial" size="2">3</font></p>
          </td>
          </tr>
          <tr>
          <td width="57%">
          <p><font face="Arial" size="2">Infected Files </font></p>
          </td>
          <td width="43%" align="right">
          <p><font face="Arial" size="2">11</font></p>
          </td>
          </tr>
          <tr>
          <td width="57%">
          <p><font face="Arial" size="2">Suspect Files </font></p>
          </td>
          <td width="43%" align="right">
          <p><font face="Arial" size="2">0</font></p>
          </td>
          </tr>
          <tr>
          <td width="57%">
          <p><font face="Arial" size="2">Warnings</font></p>
          </td>
          <td width="43%" align="right">
          <p><font face="Arial" size="2">0</font></p>
          </td>
          </tr>
          <tr>
          <td width="57%">
          <p><font face="Arial" size="2">Disinfected</font></p>
          </td>
          <td width="43%" align="right">
          <p><font face="Arial" size="2">0</font></p>
          </td>
          </tr>
          <tr>
          <td width="57%">
          <p><font face="Arial" size="2">Deleted Files</font></p>
          </td>
          <td width="43%" align="right">
          <p><font face="Arial" size="2">15</font></p>
          </td>
          </tr>
          </table>
          </td>
          <td width="40%">
          <p> </p>
          </td>
          <td width="10%">
          <p> </p>
          </td>
          </tr>

          <tr>
          <td width="458">
          <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
          <tr>
          <td width="451" colspan="2" bgcolor="#CCCCCC">
          <p><font face="Arial" size="2"><B>Engines Info</b></font></p>
          </td>
          </tr>
          <tr>
          <td width="57%">
          <p><font face="Arial" size="2">Virus Definitions</font></p>
          </td>
          <td width="43%" align="right">
          <p><font face="Arial" size="2">1093271</font></p>
          </td>
          </tr>
          <tr>
          <td width="57%">
          <p><font face="Arial" size="2">Engine build</font></p>
          </td>
          <td width="43%" align="right">
          <p><font face="Arial" size="2">AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)</font></p>
          </td>
          </tr>
          <tr>
          <td width="57%">
          <p><font face="Arial" size="2">Scan plugins</font></p>
          </td>
          <td width="43%" align="right">
          <p><font face="Arial" size="2">14</font></p>
          </td>
          </tr>
          <tr>
          <td width="57%">
          <p><font face="Arial" size="2">Archive plugins</font></p>
          </td>
          <td width="43%" align="right">
          <p><font face="Arial" size="2">39</font></p>
          </td>
          </tr>
          <tr>
          <td width="57%">
          <p><font face="Arial" size="2">Unpack plugins</font></p>
          </td>
          <td width="43%" align="right">
          <p><font face="Arial" size="2">7</font></p>
          </td>
          </tr>
          <tr>
          <td width="57%">
          <p><font face="Arial" size="2">E-mail plugins</font></p>
          </td>
          <td width="43%" align="right">
          <p><font face="Arial" size="2">6</font></p>
          </td>
          </tr>
          <tr>
          <td width="57%">
          <p><font face="Arial" size="2">System plugins</font></p>
          </td>
          <td width="43%" align="right">
          <p><font face="Arial" size="2">1</font></p>
          </td>
          </tr>
          </table>
          </td>
          <td width="40%">
          <p> </p>
          </td>
          <td width="10%">
          <p> </p>
          </td>
          </tr>

          <tr>
          <td width="458">
          <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
          <tr>
          <td width="451" colspan="2" bgcolor="#CCCCCC">
          <p><font face="Arial" size="2"><B>Scan Settings</b></font></p>
          </td>
          </tr>
          <tr>
          <td width="57%">
          <p><font face="Arial" size="2">First Action</font></p>
          </td>
          <td width="43%" align="right">
          <p><font face="Arial" size="2">Disinfect</font></p>
          </td>
          </tr>
          <tr>
          <td width="57%">
          <p><font face="Arial" size="2">Second Action</font></p>
          </td>
          <td width="43%" align="right">
          <p><font face="Arial" size="2">Delete</font></p>
          </td>
          </tr>
          <tr>
          <td width="57%">
          <p><font face="Arial" size="2">Heuristics</font></p>
          </td>
          <td width="43%" align="right">
          <p><font face="Arial" size="2">Yes</font></p>
          </td>
          </tr>
          <tr>
          <td width="57%">
          <p><font face="Arial" size="2">Enable Warnings</font></p>
          </td>
          <td width="43%" align="right">
          <p><font face="Arial" size="2">Yes</font></p>
          </td>
          </tr>
          <tr>
          <td width="57%">
          <p><font face="Arial" size="2">Scanned Extensions</font></p>
          </td>
          <td width="43%" align="right">
          <p><font face="Arial" size="2">*;</font></p>
          </td>
          </tr>

          <tr>
          <td width="57%">
          <p><font face="Arial" size="2">Exclude Extensions</font></p>
          </td>
          <td width="43%" align="right">
          <p><font face="Arial" size="2"> </font></p>
          </td>
          </tr>
          <tr>
          <td width="57%">
          <p><font face="Arial" size="2">Scan Emails</font></p>
          </td>
          <td width="43%" align="right">
          <p><font face="Arial" size="2">Yes</font></p>
          </td>
          </tr>
          <tr>
          <td width="57%">
          <p><font face="Arial" size="2">Scan Archives</font></p>
          </td>
          <td width="43%" align="right">
          <p><font face="Arial" size="2">Yes</font></p>
          </td>
          </tr>
          <tr>
          <td width="57%">
          <p><font face="Arial" size="2">Scan Packed</font></p>
          </td>
          <td width="43%" align="right">
          <p><font face="Arial" size="2">Yes</font></p>
          </td>
          </tr>
          <tr>
          <td width="57%">
          <p><font face="Arial" size="2">Scan Files</font></p>
          </td>
          <td width="43%" align="right">
          <p><font face="Arial" size="2">Yes</font></p>
          </td>
          </tr>
          <tr>
          <td width="57%">
          <p><font face="Arial" size="2">Scan Boot</font></p>
          </td>
          <td width="43%" align="right">
          <p><font face="Arial" size="2">Yes</font></p>
          </td>
          </tr>
          </table>
          </td>
          <td width="40%">
          <p> </p>
          </td>
          <td width="10%">
          <p> </p>
          </td>
          </tr>

          <tr>
          <td colspan=2>  
          <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
          <tr>
          <td width="252" bgcolor="#CCCCCC">
          <p><font face="Arial" size="2"><B>Scanned File</b></font></p>
          </td>
          <td width="195" bgcolor="#CCCCCC" align="right">
          <p align="left"><b><font size="2" face="Arial"> Status</font></b></p>
          </td>
          </tr>
          <tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0E3C0000.VBN=>(Quarantine-PE)</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Infected with: Trojan.Packed.2797</font></p>
          </td>
          </tr><tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0E3C0000.VBN=>(Quarantine-PE)</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Disinfection failed</font></p>
          </td>
          </tr><tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0E3C0000.VBN=>(Quarantine-PE)</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Deleted</font></p>
          </td>
          </tr><tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0E5C0000.VBN=>(Quarantine-PE)</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Infected with: Trojan.Packed.2797</font></p>
          </td>
          </tr><tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0E5C0000.VBN=>(Quarantine-PE)</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Disinfection failed</font></p>
          </td>
          </tr><tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0E5C0000.VBN=>(Quarantine-PE)</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Deleted</font></p>
          </td>
          </tr><tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0E600000.VBN=>(Quarantine-PE)</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Infected with: Trojan.Packed.2797</font></p>
          </td>
          </tr><tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0E600000.VBN=>(Quarantine-PE)</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Disinfection failed</font></p>
          </td>
          </tr><tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0E600000.VBN=>(Quarantine-PE)</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Deleted</font></p>
          </td>
          </tr><tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0E600001.VBN=>(Quarantine-PE)</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Infected with: Trojan.Packed.2797</font></p>
          </td>
          </tr><tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0E600001.VBN=>(Quarantine-PE)</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Disinfection failed</font></p>
          </td>
          </tr><tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0E600001.VBN=>(Quarantine-PE)</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Deleted</font></p>
          </td>
          </tr><tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\Program Files\MediaSupplyCodec\MediaSupplyCodec.ocx</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Detected with: Adware.NetAdware.CW</font></p>
          </td>
          </tr><tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\Program Files\MediaSupplyCodec\MediaSupplyCodec.ocx</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Disinfection failed</font></p>
          </td>
          </tr><tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\Program Files\MediaSupplyCodec\MediaSupplyCodec.ocx</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Deleted</font></p>
          </td>
          </tr><tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\Program Files\Robot Office\Robot 17.5 crack\ROBOT_Expert_v17.zip=>Crack.zip=>robot.dll</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Infected with: Trojan.Packed.2797</font></p>
          </td>
          </tr><tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\Program Files\Robot Office\Robot 17.5 crack\ROBOT_Expert_v17.zip=>Crack.zip=>robot.dll</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Disinfection failed</font></p>
          </td>
          </tr><tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\Program Files\Robot Office\Robot 17.5 crack\ROBOT_Expert_v17.zip=>Crack.zip=>robot.dll</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Deleted</font></p>
          </td>
          </tr><tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\Program Files\Robot Office\Robot 17.5 crack\ROBOT_Expert_v17.zip=>Crack.zip</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Updated</font></p>
          </td>
          </tr><tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\Program Files\Robot Office\Robot 17.5 crack\ROBOT_Expert_v17.zip</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Updated</font></p>
          </td>
          </tr><tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\Program Files\Robot Office\ROBOT_Expert_v17\Crack.zip=>robot.dll</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Infected with: Trojan.Packed.2797</font></p>
          </td>
          </tr><tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\Program Files\Robot Office\ROBOT_Expert_v17\Crack.zip=>robot.dll</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Disinfection failed</font></p>
          </td>
          </tr><tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\Program Files\Robot Office\ROBOT_Expert_v17\Crack.zip=>robot.dll</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Deleted</font></p>
          </td>
          </tr><tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\Program Files\Robot Office\ROBOT_Expert_v17\Crack.zip</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Updated</font></p>
          </td>
          </tr><tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\QooBox\Quarantine\C\WINDOWS\system32\,)),,,,,,),,)WW,),WWW,W,.exe.vir</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Infected with: Packer.Malware.NaN.A</font></p>
          </td>
          </tr><tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\QooBox\Quarantine\C\WINDOWS\system32\,)),,,,,,),,)WW,),WWW,W,.exe.vir</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Disinfection failed</font></p>
          </td>
          </tr><tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\QooBox\Quarantine\C\WINDOWS\system32\,)),,,,,,),,)WW,),WWW,W,.exe.vir</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Deleted</font></p>
          </td>
          </tr><tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\System Volume Information\_restore{B0AB7F98-B9F0-4B4B-B73E-779241EA2DEC}\RP291\A0064317.com</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Infected with: Packer.Malware.NaN.A</font></p>
          </td>
          </tr><tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\System Volume Information\_restore{B0AB7F98-B9F0-4B4B-B73E-779241EA2DEC}\RP291\A0064317.com</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Disinfection failed</font></p>
          </td>
          </tr><tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\System Volume Information\_restore{B0AB7F98-B9F0-4B4B-B73E-779241EA2DEC}\RP291\A0064317.com</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Deleted</font></p>
          </td>
          </tr><tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\System Volume Information\_restore{B0AB7F98-B9F0-4B4B-B73E-779241EA2DEC}\RP300\A0066511.exe</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Infected with: Packer.Malware.NaN.A</font></p>
          </td>
          </tr><tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\System Volume Information\_restore{B0AB7F98-B9F0-4B4B-B73E-779241EA2DEC}\RP300\A0066511.exe</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Disinfection failed</font></p>
          </td>
          </tr><tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\System Volume Information\_restore{B0AB7F98-B9F0-4B4B-B73E-779241EA2DEC}\RP300\A0066511.exe</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Deleted</font></p>
          </td>
          </tr><tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\System Volume Information\_restore{B0AB7F98-B9F0-4B4B-B73E-779241EA2DEC}\RP300\A0066557.ocx</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Detected with: Adware.NetAdware.CW</font></p>
          </td>
          </tr><tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\System Volume Information\_restore{B0AB7F98-B9F0-4B4B-B73E-779241EA2DEC}\RP300\A0066557.ocx</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Disinfection failed</font></p>
          </td>
          </tr><tr>
          <td width="57%">
          <p><font face="Arial" size="2">C:\System Volume Information\_restore{B0AB7F98-B9F0-4B4B-B73E-779241EA2DEC}\RP300\A0066557.ocx</font></p>
          </td>
          <td width="43%" align="left">
          <p><font face="Arial" size="2">Deleted</font></p>
          </td>
          </tr>
          </table>
          </td>

          <td width="10%">
          <p> </p>
          </td>
          </tr>

          <tr>
          <td width="458">
          <p><font face="Arial"><span style="font-size:11pt;"><B> </b></span></font></p>
          </td>
          <td width="40%">
          <p> </p>
          </td>
          <td width="10%">
          <p> </p>
          </td>
          </tr>

          <tr>
          <td width="458">
          <p><font face="Arial"><span style="font-size:11pt;"><B> </b></span></font></p>
          </td>
          <td width="40%">
          <p> </p>
          </td>
          <td width="10%">
          <p> </p>
          </td>
          </tr>

          </table>
          <p> </p>

          </body>
          </html>

          Que faire maintenant?

          PS: il me donne toujours sur mon ordinateur que downlowder est encore present!!

          Merci encore pour votre aide tres precieuse ;)
          0
          1. bonjour

            et voila le rapport kaspersky
            Tuesday, May 13, 2008 8:03:03 AM
            Système d'exploitation : Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
            Kaspersky On-line Scanner version : 5.0.83.0
            Dernière mise à jour de la base antivirus Kaspersky : 12/05/2008
            Enregistrements dans la base antivirus Kaspersky : 684504
            Paramètres d'analyse
            Analyser avec la base antivirus suivante standard
            Analyser les archives vrai
            Analyser les bases de messagerie vrai
            Cible de l'analyse Poste de travail
            C:\
            D:\
            E:\
            F:\
            Statistiques de l'analyse
            Total d'objets analysés 91699
            Nombre de virus trouvés 0
            Nombre d'objets infectés 0 / 0
            Nombre d'objets suspects 0
            Durée de l'analyse 02:09:44

            C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.180.Crwl L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.180.gthr L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSS.log L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSStmp.log L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010001.wid L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010002.wid L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010003.wid L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010004.wid L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010005.wid L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010006.ci L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010006.wid L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010006.wsb L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010007.wid L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010008.wid L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010009.wid L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000A.ci L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000A.dir L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000A.wid L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000B.wid L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000C.wid L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000E.wid L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010011.wid L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010012.wid L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010013.wid L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010014.wid L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010016.wid L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010017.wid L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010018.wid L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010019.wid L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001A.wid L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001C.wid L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001E.wid L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001F.wid L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010020.wid L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010021.wid L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\CiMG000a.000 L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\INDEX.000 L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000 L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\Used0000.000 L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.000 L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk1.gthr L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk2.gthr L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.Ntfy28.gthr L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.Ntfy29.gthr L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\tmp.edb L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Windows.edb L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Temp\usgthrsvc\Ntf1.tmp L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Temp\usgthrsvc\Ntf2.tmp L'objet est verrouillé ignoré
            C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Temp\usgthrsvc\Perflib_Perfdata_16c.dat L'objet est verrouillé ignoré
            C:\Documents and Settings\LocalService\Cookies\index.dat L'objet est verrouillé ignoré
            C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Desktop Search\Logs\UNCFATPHLog.txt L'objet est verrouillé ignoré
            C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
            C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
            C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
            C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
            C:\Documents and Settings\LocalService\NTUSER.DAT L'objet est verrouillé ignoré
            C:\Documents and Settings\LocalService\ntuser.dat.LOG L'objet est verrouillé ignoré
            C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
            C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
            C:\Documents and Settings\NetworkService\NTUSER.DAT L'objet est verrouillé ignoré
            C:\Documents and Settings\NetworkService\ntuser.dat.LOG L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\Application Data\Microsoft\Modèles\Normal.dot L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\Application Data\Microsoft\Word\DÉMARRAGE\EN8Cwyw.dot L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\Application Data\Mozilla\Firefox\Profiles\f83y840x.default\cert8.db L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\Application Data\Mozilla\Firefox\Profiles\f83y840x.default\formhistory.dat L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\Application Data\Mozilla\Firefox\Profiles\f83y840x.default\history.dat L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\Application Data\Mozilla\Firefox\Profiles\f83y840x.default\key3.db L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\Application Data\Mozilla\Firefox\Profiles\f83y840x.default\parent.lock L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\Application Data\Mozilla\Firefox\Profiles\f83y840x.default\search.sqlite L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\Application Data\Mozilla\Firefox\Profiles\f83y840x.default\urlclassifier2.sqlite L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\Application Data\Skype\e-salim\call256.dbb L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\Application Data\Skype\e-salim\callmember256.dbb L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\Application Data\Skype\e-salim\chat512.dbb L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\Application Data\Skype\e-salim\chatmember256.dbb L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\Application Data\Skype\e-salim\chatmsg256.dbb L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\Application Data\Skype\e-salim\contactgroup256.dbb L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\Application Data\Skype\e-salim\dyncontent\bundle.dat L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\Application Data\Skype\e-salim\index2.dat L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\Application Data\Skype\e-salim\profile256.dbb L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\Application Data\Skype\e-salim\user1024.dbb L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\Cookies\index.dat L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\Local Settings\Application Data\Mozilla\Firefox\Profiles\f83y840x.default\Cache\_CACHE_001_ L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\Local Settings\Application Data\Mozilla\Firefox\Profiles\f83y840x.default\Cache\_CACHE_002_ L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\Local Settings\Application Data\Mozilla\Firefox\Profiles\f83y840x.default\Cache\_CACHE_003_ L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\Local Settings\Application Data\Mozilla\Firefox\Profiles\f83y840x.default\Cache\_CACHE_MAP_ L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\Local Settings\Temp\docactu_1171485514.doc L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\Local Settings\Temp\~DF8FD5.tmp L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\Local Settings\Temp\~DFC342.tmp L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\Local Settings\Temp\~DFF1.tmp L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\Local Settings\Temp\~DFFA2E.tmp L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\Local Settings\Temp\~WRF0000.tmp L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\NTUSER.DAT L'objet est verrouillé ignoré
            C:\Documents and Settings\sazar\ntuser.dat.LOG L'objet est verrouillé ignoré
            C:\Program Files\Sunbelt Software\Personal Firewall\logs\debug.log L'objet est verrouillé ignoré
            C:\Program Files\Sunbelt Software\Personal Firewall\logs\debug.log.idx L'objet est verrouillé ignoré
            C:\Program Files\Sunbelt Software\Personal Firewall\logs\error.log L'objet est verrouillé ignoré
            C:\Program Files\Sunbelt Software\Personal Firewall\logs\error.log.idx L'objet est verrouillé ignoré
            C:\Program Files\Sunbelt Software\Personal Firewall\logs\hips.log L'objet est verrouillé ignoré
            C:\Program Files\Sunbelt Software\Personal Firewall\logs\hips.log.idx L'objet est verrouillé ignoré
            C:\Program Files\Sunbelt Software\Personal Firewall\logs\ids.log L'objet est verrouillé ignoré
            C:\Program Files\Sunbelt Software\Personal Firewall\logs\ids.log.idx L'objet est verrouillé ignoré
            C:\Program Files\Sunbelt Software\Personal Firewall\logs\network.log L'objet est verrouillé ignoré
            C:\Program Files\Sunbelt Software\Personal Firewall\logs\network.log.idx L'objet est verrouillé ignoré
            C:\Program Files\Sunbelt Software\Personal Firewall\logs\system.log L'objet est verrouillé ignoré
            C:\Program Files\Sunbelt Software\Personal Firewall\logs\system.log.idx L'objet est verrouillé ignoré
            C:\Program Files\Sunbelt Software\Personal Firewall\logs\warning.log L'objet est verrouillé ignoré
            C:\Program Files\Sunbelt Software\Personal Firewall\logs\warning.log.idx L'objet est verrouillé ignoré
            C:\Program Files\Sunbelt Software\Personal Firewall\logs\web.log L'objet est verrouillé ignoré
            C:\Program Files\Sunbelt Software\Personal Firewall\logs\web.log.idx L'objet est verrouillé ignoré
            C:\System Volume Information\MountPointManagerRemoteDatabase L'objet est verrouillé ignoré
            C:\System Volume Information\_restore{B0AB7F98-B9F0-4B4B-B73E-779241EA2DEC}\RP300\change.log L'objet est verrouillé ignoré
            C:\WINDOWS\Debug\PASSWD.LOG L'objet est verrouillé ignoré
            C:\WINDOWS\SchedLgU.Txt L'objet est verrouillé ignoré
            C:\WINDOWS\SoftwareDistribution\ReportingEvents.log L'objet est verrouillé ignoré
            C:\WINDOWS\Sti_Trace.log L'objet est verrouillé ignoré
            C:\WINDOWS\system32\config\AppEvent.Evt L'objet est verrouillé ignoré
            C:\WINDOWS\system32\config\default L'objet est verrouillé ignoré
            C:\WINDOWS\system32\config\default.LOG L'objet est verrouillé ignoré
            C:\WINDOWS\system32\config\Internet.evt L'objet est verrouillé ignoré
            C:\WINDOWS\system32\config\SAM L'objet est verrouillé ignoré
            C:\WINDOWS\system32\config\SAM.LOG L'objet est verrouillé ignoré
            C:\WINDOWS\system32\config\SecEvent.Evt L'objet est verrouillé ignoré
            C:\WINDOWS\system32\config\SECURITY L'objet est verrouillé ignoré
            C:\WINDOWS\system32\config\SECURITY.LOG L'objet est verrouillé ignoré
            C:\WINDOWS\system32\config\software L'objet est verrouillé ignoré
            C:\WINDOWS\system32\config\software.LOG L'objet est verrouillé ignoré
            C:\WINDOWS\system32\config\SysEvent.Evt L'objet est verrouillé ignoré
            C:\WINDOWS\system32\config\system L'objet est verrouillé ignoré
            C:\WINDOWS\system32\config\system.LOG L'objet est verrouillé ignoré
            C:\WINDOWS\system32\h323log.txt L'objet est verrouillé ignoré
            C:\WINDOWS\system32\spool\PRINTERS\00002.SHD L'objet est verrouillé ignoré
            C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR L'objet est verrouillé ignoré
            C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP L'objet est verrouillé ignoré
            C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER L'objet est verrouillé ignoré
            C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP L'objet est verrouillé ignoré
            C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP L'objet est verrouillé ignoré
            C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA L'objet est verrouillé ignoré
            C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP L'objet est verrouillé ignoré
            C:\WINDOWS\wiadebug.log L'objet est verrouillé ignoré
            C:\WINDOWS\wiaservc.log L'objet est verrouillé ignoré
            C:\WINDOWS\WindowsUpdate.log L'objet est verrouillé ignoré
            D:\System Volume Information\MountPointManagerRemoteDatabase L'objet est verrouillé ignoré
            Analyse terminée.
            0
            1. Contributeur sécurité
              dommage que le rapport bitdefender ne soit pas bon car on voit pas les fichiers infectés. Vire ce qui est en quarantaine dans norton et recolle un rapport bitdefender .
              0
              1. salut,

                j'ai rescane avec bitdefender, il m'a dit qu'il n'y a pas de probleme sur l'ordinateur mais n'a pas fourni de rapport.

                Est ce que ca veux dire que le probeme est resolu?
                0
                1. Contributeur sécurité
                  si tu n'as aucun souci c'est bon
                  0
                  1. alors pour le moment il ne me donne plus de message d'alerte.

                    Merci jlpjlp pour ton aide si efficace.

                    Tres bonne continuation.
                    0