Pc ralentit, souris figée, son saccadé

Bonjour,

depuis quelques temps mon pc portable ralentit, plante de temps à autres, le son est saccadé et la souris se fige.
J'ai cru que c'était dû au fait que le pc soit chargé en mémoire, j'ai donc acheté un disque dur externe et j'ai quasi tout mis dessus donc le pc est plus léger mais ça n'a rien changé à mon problème!
j'ai donc essayé de trouver ce qu'il avait avec antivirus, antimaleware, anti trojan, secuser en ligne... mais rien et lorsque je lance doctor spyware (version démo) il me trouve 1 trojan qui s'appelle trojan-pws gameonline et biensur sur la version démo on ne peut pas le supprimer!
aujourd'hui j'ai démarré le pc et il s'ouvre (après une longue attente) et le curseur ne bouge pas! meme après redémarrage il reste figé! donc je ne peux plus rien faire!
Pourriez-vous m'aider svp ( j'y connais rien en informatique!)
Merci d'avance!
Configuration: Windows XP edition familliale 2002 sous sp2

13 réponses

  1. Contributeur sécurité
    sllt

    si impossible en mode normal:
    essaye de demarrer en mode sans echec

    https://www.google.fr/search?q=mode+sans+echec&ie=utf-8&oe=utf-8&aq=t&rls=org.mozilla:fr:official&client=firefox-a&gws_rd=ssl

    puis

    télécharge combofix (par sUBs) ici :

    http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    et enregistre le sur le bureau.

    déconnecte toi d'internet et ferme toutes tes applications.

    désactive tes protections (antivirus, parefeu, garde en temps réel de l'antispyware)

    double-clique sur combofix.exe et suis les instructions

    à la fin, il va produire un rapport C:\ComboFix.txt

    réactive ton parefeu, ton antivirus, la garde de ton antispyware

    copie/colle le rapport C:\ComboFix.txt dans ta prochaine réponse.

    Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi.

    Tu as un tutoriel complet ici :

    https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

    ________________________________

    colle un rapport hijackthis

    http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download

    manuel :

    https://leblogdeclaude.blogspot.com/2006/10/informatique-section-hijackthis.html

    Je conseille de renomer Hijackthis, pour contrer une éventuelle infection de Vundo.

    ex:Renomme le fichier HijackThis.exe en eden.exe pour cela, fais un clic droit sur le fichier HijackThis.exe et choisis renommer dans la liste

    Ensuite avec Explorer créer un dossier c:\hijackthis
    Décompresser Hijackthis dans ce dossier.
    C'est important pour les sauvegardes."
    0
    1. Bonjour et merci déjà pour ta réponse rapide!
      alors par contre après avoir eu des problèmes de démarrage avec le pc , il s'est mit en veille prolongée tout seul et il s'est relancé et là ma souris fonctionnait de nouveau et j'ai voulu refaire un scan antimalware et le logiciel marchait plus! je l'ai de nouveau télécharger et j'ai fais un scan dont voici le rapport :
      Malwarebytes' Anti-Malware 1.28
      Version de la base de données: 1232
      Windows 5.1.2600 Service Pack 2

      2008-10-06 11:44:59
      mbam-log-2008-10-06 (11-44-59).txt

      Type de recherche: Examen rapide
      Eléments examinés: 45795
      Temps écoulé: 17 minute(s), 34 second(s)

      Processus mémoire infecté(s): 0
      Module(s) mémoire infecté(s): 0
      Clé(s) du Registre infectée(s): 0
      Valeur(s) du Registre infectée(s): 0
      Elément(s) de données du Registre infecté(s): 1
      Dossier(s) infecté(s): 0
      Fichier(s) infecté(s): 0

      Processus mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Module(s) mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Clé(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Valeur(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Elément(s) de données du Registre infecté(s):
      HKEY_CLASSES_ROOT\scrfile\shell\open\command\ (Broken.OpenCommand) -> Bad: ("%1" %*) Good: ("%1" /S) -> Quarantined and deleted successfully.

      Dossier(s) infecté(s):
      (Aucun élément nuisible détecté)

      Fichier(s) infecté(s):
      (Aucun élément nuisible détecté)

      Par la suite j'ai suivi la procédure de supression et depuis tout fonctionne normalement! meme le son!!!
      je ne sais pas ce que c'était comme infection mais je crois en être débarassé!
      Mais je ne sais pas comment faire pour en être certaine...
      Tu sais comment je dois faire? et est-ce que c'était cette chose qui empoisonnait mon pc??
      Merci encore d'avance!
      0
  2. Contributeur sécurité
    colle combofix et hijakchits pour verifer
    0
    1. Désolée je suis longue à comprendre alors ça m'a pris du temps! voici les rapports!
      Et petite rectif : le son est toujours saccadé:

      COMBOFIX:

      ComboFix 08-10-04.07 - MALLO Mickael 2008-10-06 14:32:24.1 - NTFSx86
      Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.570 [GMT 2:00]
      Lancé depuis: C:\Documents and Settings\MALLO Mickael\Bureau\ComboFix.exe

      [COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B][/COLOR]
      .

      (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
      .

      C:\Documents and Settings\MALLO Mickael\Cookies\mallo_mickael@linternaute[1].txt
      C:\WINDOWS\system32\_000008_.tmp.dll
      C:\WINDOWS\system32\dao350.dll
      D:\Autorun.inf

      .
      ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
      .

      -------\Legacy_MCHINJDRV

      ((((((((((((((((((((((((((((( Fichiers créés du 2008-09-06 au 2008-10-06 ))))))))))))))))))))))))))))))))))))
      .

      2008-10-06 13:55 . 2008-10-06 13:55 <REP> d-------- C:\Program Files\Trend Micro
      2008-10-06 11:15 . 2008-10-06 11:16 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
      2008-10-06 11:15 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
      2008-10-06 11:15 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
      2008-10-05 15:33 . 2008-10-05 15:33 850 --a------ C:\WINDOWS\system32\ProductTweaks.xml
      2008-10-05 15:33 . 2008-10-05 15:36 385 --a------ C:\WINDOWS\system32\user_gensett.xml
      2008-10-05 15:14 . 2008-10-05 15:14 <REP> d-------- C:\WINDOWS\system32\logs
      2008-10-05 15:03 . 2008-10-05 16:10 <REP> d-------- C:\Program Files\Fichiers communs\BitDefender
      2008-10-05 14:06 . 2008-10-05 14:14 <REP> d-------- C:\WINDOWS\BDOSCAN8
      2008-10-05 14:01 . 2008-10-05 14:01 19,973,241 --a------ C:\WINDOWS\VPTNFILE.577
      2008-10-05 13:59 . 2008-10-05 14:01 <REP> d-------- C:\WINDOWS\AU_Temp
      2008-10-05 11:36 . 2008-10-05 11:36 <REP> d----c--- C:\Documents and Settings\All Users\Application Data\Grisoft
      2008-10-02 19:07 . 2008-10-02 19:07 <REP> d-------- C:\WINDOWS\report
      2008-10-02 19:06 . 2008-10-05 14:01 <REP> d-------- C:\WINDOWS\AU_Backup
      2008-10-02 19:06 . 2008-10-02 19:06 1,966,305 --a------ C:\WINDOWS\tsc.ptn
      2008-10-02 19:06 . 2008-10-05 14:01 1,213,784 --a------ C:\WINDOWS\vsapi32.dll
      2008-10-02 19:06 . 2008-10-02 19:06 333,576 --a------ C:\WINDOWS\TSC.exe
      2008-10-02 19:06 . 2008-10-05 14:01 91,744 --a------ C:\WINDOWS\BPMNT.dll
      2008-10-02 19:06 . 2008-10-02 19:06 71,749 --a------ C:\WINDOWS\hcextoutput.dll
      2008-10-02 19:05 . 2008-10-02 19:06 19,963,953 --a------ C:\WINDOWS\VPTNFILE.575
      2008-09-26 11:16 . 2008-09-26 11:16 <REP> d-------- C:\Program Files\PC Inspector File Recovery
      2008-09-26 11:16 . 2002-02-18 18:40 6,200 --a------ C:\WINDOWS\system32\INT13EXT.VXD
      2008-09-17 15:17 . 2008-09-17 15:17 <REP> d-------- C:\Program Files\Trojan Remover
      2008-09-17 15:17 . 2008-09-17 15:17 <REP> d-------- C:\Documents and Settings\MALLO Mickael\Application Data\Simply Super Software
      2008-09-17 15:17 . 2008-09-17 15:17 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Simply Super Software
      2008-09-17 15:17 . 2006-05-25 15:52 162,304 --a------ C:\WINDOWS\system32\ztvunrar36.dll
      2008-09-17 15:17 . 2003-02-02 20:06 153,088 --a------ C:\WINDOWS\system32\UNRAR3.dll
      2008-09-17 15:17 . 2005-08-26 01:50 77,312 --a------ C:\WINDOWS\system32\ztvunace26.dll
      2008-09-17 15:17 . 2002-03-06 01:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
      2008-09-17 15:17 . 2006-06-19 13:01 69,632 --a------ C:\WINDOWS\system32\ztvcabinet.dll
      2008-09-17 14:38 . 2008-10-05 12:51 <REP> d-------- C:\Program Files\Spyware Doctor
      2008-09-17 14:38 . 2008-09-17 14:38 <REP> d-------- C:\Documents and Settings\MALLO Mickael\Application Data\PC Tools
      2008-09-17 14:38 . 2008-10-05 13:17 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
      2008-09-17 14:38 . 2008-08-25 11:36 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
      2008-09-17 14:38 . 2008-08-25 11:36 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
      2008-09-17 14:38 . 2008-08-25 11:36 40,840 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
      2008-09-17 14:38 . 2008-06-02 15:19 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
      2008-09-17 14:26 . 2008-10-05 14:01 823 --a------ C:\WINDOWS\TSC.INI
      2008-09-17 14:25 . 2008-10-05 13:59 170 --a------ C:\WINDOWS\GetServer.ini
      2008-09-17 14:24 . 2008-09-17 14:24 <REP> d-------- C:\WINDOWS\AU_Log
      2008-09-17 14:24 . 2008-09-17 14:24 507,904 --a------ C:\WINDOWS\TMUPDATE.DLL
      2008-09-17 14:24 . 2008-09-17 14:24 286,720 --a------ C:\WINDOWS\PATCH.EXE
      2008-09-17 14:24 . 2008-09-17 14:24 69,689 --a------ C:\WINDOWS\UNZIP.DLL
      2008-09-11 18:46 . 2008-09-22 23:09 54,156 --ah----- C:\WINDOWS\QTFont.qfn
      2008-09-11 18:46 . 2008-09-11 18:46 1,409 --a------ C:\WINDOWS\QTFont.for
      2008-09-11 18:33 . 2008-09-11 18:33 268 --ah-c--- C:\sqmdata04.sqm
      2008-09-11 18:33 . 2008-09-11 18:33 244 --ah-c--- C:\sqmnoopt03.sqm
      2008-09-11 18:33 . 2008-09-11 18:33 136 --ah-c--- C:\sqmdata05.sqm
      2008-09-11 10:00 . 2008-09-11 10:00 244 --ah-c--- C:\sqmnoopt02.sqm
      2008-09-11 10:00 . 2008-09-11 10:00 232 --ah-c--- C:\sqmdata03.sqm
      2008-09-11 10:00 . 2008-09-11 10:00 232 --ah-c--- C:\sqmdata02.sqm
      2008-09-07 18:43 . 2008-09-07 18:43 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Sophos
      2008-09-07 14:40 . 2008-09-07 14:41 <REP> d-------- C:\Program Files\SweetIM
      2008-09-07 14:40 . 2008-09-07 14:41 <REP> d-------- C:\Documents and Settings\All Users\Application Data\SweetIM

      .
      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2008-10-06 08:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
      2008-09-26 09:16 --------- d--h--w C:\Program Files\InstallShield Installation Information
      2008-09-24 11:38 1,958 ----a-w C:\Documents and Settings\MALLO Mickael\Application Data\wklnhst.dat
      2008-09-09 15:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg8
      2008-09-05 14:06 --------- d-----w C:\Program Files\Yahoo!
      2008-09-05 11:10 --------- d-----w C:\Program Files\Alwil Software
      2008-09-05 09:04 --------- d-----w C:\Documents and Settings\MALLO Mickael\Application Data\Malwarebytes
      2008-09-05 09:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Malwarebytes
      2008-09-05 00:13 --------- d-----w C:\Program Files\AVG
      2008-09-04 21:58 --------- d-----w C:\Program Files\AxBx
      2008-08-29 19:49 --------- d-----w C:\Program Files\Panicware
      2008-08-27 13:22 --------- d-----w C:\Documents and Settings\MALLO Mickael\Application Data\Samsung
      2008-08-27 13:18 --------- d-----w C:\Program Files\Samsung
      2008-08-26 17:21 --------- d-----w C:\Program Files\eMule
      2008-08-14 16:54 102,208 ------w C:\WINDOWS\system32\drivers\bdfndisf.sys
      .

      ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
      REGEDIT4

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
      "{EEE6C35D-6118-11DC-9C72-001320C79847}"= "C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [2008-07-06 173368]

      [HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
      [HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
      [HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
      [HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]

      [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
      2008-07-06 12:44 1164600 --a------ C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
      "{EEE6C35B-6118-11DC-9C72-001320C79847}"= "C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2008-07-06 1164600]

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
      "{EEE6C35B-6118-11DC-9C72-001320C79847}"= "C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2008-07-06 1164600]

      [HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
      [HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3]
      [HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
      [HKEY_CLASSES_ROOT\SWEETIE.SWEETIE]

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 15360]
      "WOOKIT"="C:\PROGRA~1\Wanadoo\Shell.exe" [BU]
      "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 1694208]
      "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-08-01 68856]
      "PopUpStopperFreeEdition"="C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe" [2005-03-17 536576]
      "MessengerPlus3"="C:\Program Files\MessengerPlus! 3\MsgPlus.exe" [2006-10-25 190024]
      "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [X]
      "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-11-10 344064]
      "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 75520]
      "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
      "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-06-19 729178]
      "QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2005-12-12 94208]
      "eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2005-12-22 405504]
      "Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2005-08-01 233534]
      "RecGuard"="C:\Windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
      "Reminder"="C:\Windows\CREATOR\Remind_XP.exe" [2006-02-09 643072]
      "hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-12-13 507904]
      "PlayerKiosquePlus"="C:\Program Files\Lecteur CANALPLAY\PlayerKiosquePlus.exe" [BU]
      "CanalPlayer"="C:\Program Files\Lecteur CANALPLAY\CanalPlayer.exe" [2006-08-31 1996648]
      "MessengerPlus3"="C:\Program Files\MessengerPlus! 3\MsgPlus.exe" [2006-10-25 190024]
      "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 282624]
      "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 256576]
      "TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-10-20 180269]
      "TVPService"="C:\Program Files\HP\TVPlay\TVPService.exe" [2006-04-03 135168]
      "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
      "PopUp Destroy"="C:\Program Files\PopUp Destroy\Popup-Destroy.exe" [BU]
      "SweetIM"="C:\Program Files\SweetIM\Messenger\SweetIM.exe" [2008-07-06 111928]
      "TrojanScanner"="C:\Program Files\Trojan Remover\Trjscan.exe" [2008-09-15 920144]

      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
      "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 15360]

      C:\Documents and Settings\MALLO Mickael\Menu D‚marrer\Programmes\D‚marrage\
      Palm Registration.lnk - C:\Program Files\Palm\register.exe [2005-08-08 2494464]

      C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
      D‚marrage rapide de HP Photosmart Premier.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2006-02-10 73728]
      HOTSYNCSHORTCUTNAME.lnk - C:\Program Files\Palm\Hotsync.exe [2004-06-09 471040]
      HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
      "NoDispSettingPage"= 1 (0x1)

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
      C:\WINDOWS\ntsys.exe [BU]

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
      "DisableMonitoring"=dword:00000001

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "%windir%\\system32\\sessmgr.exe"=
      "C:\\Program Files\\HP\\TVPlay\\TVPlay.exe"=
      "C:\\Program Files\\HP\\TVPlay\\TVPService.exe"=
      "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
      "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
      "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
      "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
      "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
      "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
      "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
      "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
      "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
      "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
      "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
      "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
      "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
      "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
      "C:\\Program Files\\Lecteur CANALPLAY\\CanalPlayer.exe"=
      "C:\\Program Files\\Lecteur CANALPLAY\\CanalPlayerHelper.exe"=
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
      "C:\\Program Files\\iTunes\\iTunes.exe"=
      "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
      "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
      "C:\\WINDOWS\\system32\\mcoinstall.exe"=

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
      "6346:TCP"= 6346:TCP:shareaza
      "6346:UDP"= 6346:UDP:shareaza

      R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
      R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
      R2 CyberLink Media Library Service(HP TVPlay);CyberLink Media Library Service(HP TVPlay);C:\Program Files\HP\TVPlay\Kernel\CLML_NTService\CLMLServer.exe [2006-04-03 1073152]
      R2 TVPCapSvc;CyberLink Background Capture Service (CBCS HP TVPlay);C:\Program Files\HP\TVPlay\Kernel\TV\TVPCapSvc.exe [2006-04-03 258147]
      R2 TVPSched;CyberLink Task Scheduler (CTS HP TVPlay);C:\Program Files\HP\TVPlay\Kernel\TV\TVPSched.exe [2006-04-03 114785]
      R3 HSFHWATI;HSFHWATI;C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys [2005-08-22 231424]
      R3 Service CANALPLAY;Service CANALPLAY;C:\Program Files\Lecteur CANALPLAY\CanalPlayService.exe [2006-08-31 370536]
      R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
      S3 MODBDA2;DiBcom MOD3000 TV receiver;C:\WINDOWS\system32\Drivers\modbda2.sys [2005-06-04 30464]
      S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2005-08-30 58320]
      S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2005-08-30 8304]
      S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2005-08-30 94000]
      S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d1b1b0ee-c930-11dc-ba69-0014a5e46bb0}]
      \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe killVBS.vbs
      .
      - - - - ORPHELINS SUPPRIMES - - - -

      ShellExecuteHooks-{DA16164D-96D5-4ACB-BCF7-BA486B8ABC1A} - (no file)

      .
      ------- Examen supplémentaire -------
      .
      R0 -: HKCU-Main,Start Page = hxxp://portail.free.fr/
      R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore

      O16 -: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
      C:\WINDOWS\Downloaded Program Files\oscan8.inf
      C:\WINDOWS\bdoscandellang.ini
      C:\WINDOWS\bdoscandel.exe
      C:\WINDOWS\Downloaded Program Files\live.ini
      C:\WINDOWS\Downloaded Program Files\scanoptions.tsi
      C:\WINDOWS\Downloaded Program Files\lang.ini
      C:\WINDOWS\Downloaded Program Files\ipsupd.dll
      C:\WINDOWS\Downloaded Program Files\bdupd.dll
      C:\WINDOWS\Downloaded Program Files\libfn.dll
      C:\WINDOWS\Downloaded Program Files\bdcore.dll
      C:\WINDOWS\Downloaded Program Files\oscan8.ocx
      .

      **************************************************************************

      catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2008-10-06 14:51:57
      Windows 5.1.2600 Service Pack 2 NTFS

      Recherche de processus cachés ...

      Recherche d'éléments en démarrage automatique cachés ...

      HKLM\Software\Microsoft\Windows\CurrentVersion\Run
      Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe??????????R????|?P???? ???B?????????????hLC? ??????

      Recherche de fichiers cachés ...

      C:\Documents and Settings\MALLO Mickael\Local Settings\Application Data\ApplicationHistory\hpqthb08.exe.a935d1e0.ini.inuse 0 bytes

      Scan terminé avec succès
      Fichiers cachés: 1

      **************************************************************************
      .
      ------------------------ Autres processus actifs ------------------------
      .
      C:\WINDOWS\system32\ati2evxx.exe
      C:\WINDOWS\system32\ati2evxx.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
      C:\WINDOWS\system32\wdfmgr.exe
      C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\PROGRA~1\HPQ\shared\HPQTOA~1.EXE
      C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe
      C:\PROGRA~1\WINDOW~4\MESSEN~1\msnmsgr.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
      C:\WINDOWS\system32\imapi.exe
      .
      **************************************************************************
      .
      Heure de fin: 2008-10-06 15:00:52 - La machine a redémarré [MALLO Mickael]
      ComboFix-quarantined-files.txt 2008-10-06 13:00:37
      ComboFix2.txt 2008-10-05 16:09:46
      ComboFix3.txt 2008-10-05 15:51:09

      Avant-CF: 56,933,572,608 octets libres
      Après-CF: 56,956,891,136 octets libres

      262

      HIJACKTHIS:

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 14:27, on 2008-10-06
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16705)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Program Files\HP\QuickPlay\QPService.exe
      C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
      C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
      C:\Program Files\Lecteur CANALPLAY\CanalPlayer.exe
      C:\Program Files\MessengerPlus! 3\MsgPlus.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\Program Files\HP\TVPlay\TVPService.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\SweetIM\Messenger\SweetIM.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Palm\Hotsync.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
      C:\Program Files\HP\TVPlay\Kernel\CLML_NTService\CLMLServer.exe
      C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\HP\TVPlay\Kernel\TV\TVPCapSvc.exe
      C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
      C:\Program Files\HP\TVPlay\Kernel\TV\TVPSched.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
      C:\Program Files\Lecteur CANALPLAY\CanalPlayService.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\Documents and Settings\MALLO Mickael\Bureau\scan.exe.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://portail.free.fr/
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
      R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
      O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
      O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
      O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
      O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
      O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
      O4 - HKLM\..\Run: [Reminder] C:\Windows\CREATOR\Remind_XP.exe
      O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
      O4 - HKLM\..\Run: [PlayerKiosquePlus] C:\Program Files\Lecteur CANALPLAY\PlayerKiosquePlus.exe /iconic
      O4 - HKLM\..\Run: [CanalPlayer] C:\Program Files\Lecteur CANALPLAY\CanalPlayer.exe /iconic
      O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [TVPService] "C:\Program Files\HP\TVPlay\TVPService.exe"
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [PopUp Destroy] C:\Program Files\PopUp Destroy\Popup-Destroy.exe
      O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe
      O4 - HKLM\..\Run: [winabc] rundll32.exe C:\DOCUME~1\MALLOM~1\LOCALS~1\Temp\ibb1.dll,abcLaunchEv
      O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe /boot
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
      O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKLM\..\Policies\Explorer\Run: [BianFeng] C:\Documents and Settings\MALLO Mickael\SendTo\WinHy.EXE
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Startup: Palm Registration.lnk = C:\Program Files\Palm\register.exe
      O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
      O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
      O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: CyberLink Media Library Service(HP TVPlay) - Cyberlink - C:\Program Files\HP\TVPlay\Kernel\CLML_NTService\CLMLServer.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
      O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
      O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
      O23 - Service: Service CANALPLAY - Canal+ Active - C:\Program Files\Lecteur CANALPLAY\CanalPlayService.exe
      O23 - Service: CyberLink Background Capture Service (CBCS HP TVPlay) (TVPCapSvc) - Unknown owner - C:\Program Files\HP\TVPlay\Kernel\TV\TVPCapSvc.exe
      O23 - Service: CyberLink Task Scheduler (CTS HP TVPlay) (TVPSched) - Unknown owner - C:\Program Files\HP\TVPlay\Kernel\TV\TVPSched.exe
      0
  3. Contributeur sécurité
    analyse ceci sur virus total et colle le rapport: https://www.virustotal.com/gui/

    C:\Documents and Settings\MALLO Mickael\SendTo\WinHy.EXE

    _______

    Télécharge RavAntivirus d'Evosla :
    http://ww25.evosla.com/compteur.php?soft=rav_antivirus

    # Si tu as une clé USB, disque dur externe, etc, branche-les sans les ouvrir avant de lancer ce FIX
    # Fais un clic droit sur le fichier .ZIP > Extraire sur > le Bureau
    # Doucle-clique sur >> RAV.exe << afin de lancer l'outil.
    # Une fois RAV ANTIVIRUS lancé, laisse-le réagir , il scanne automatiquement tout les lecteurs (disques fixes et amovibles)
    # Si infection > un log s'établira, sinon le soft affichera (très rapide) ==>Votre Ordinateur est sain .
    # Retire tes disques amovibles et redémarrez votre ordinateur.
    # Poste le rapport, si infection!

    _______

    telecharge combofix:

    http://download.bleepingcomputer.com/sUBs/ComboFix.exe
    Sauvegarde le sur ton bureau et pas ailleurs !

    Ferme tous tes navigateurs (donc copie ou imprime les instructions avant)

    Crée un nouveau document texte : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie dedans les lignes suivantes :

    File::
    C:\Program Files\SweetIM\Messenger\SweetIM.exe
    C:\Program Files\SweetIM
    C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
    C:\DOCUME~1\MALLOM~1\LOCALS~1\Temp\ibb1.dll

    Registry::
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{EEE6C35D-6118-11DC-9C72-001320C79847}"=-
    [HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
    [-HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
    [HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
    [-HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{EEE6C35B-6118-11DC-9C72-001320C79847}"=-
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{EEE6C35B-6118-11DC-9C72-001320C79847}"=-
    [HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
    [-HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3]
    [HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
    [-HKEY_CLASSES_ROOT\SWEETIE.SWEETIE]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SweetIM"=-

    Enregistre ce fichier sous le nom CFscript

    Fait un glisser/déposer de ce fichier CFscrïpt sur le fichier ComboFix.exe

    Clique sur le fichier CFScript, maintient le doigt enfoncé et glisse la souris pour que l'icône du CFScript vienne recouvrir l'icône de Combofix. Relache la souris. Combofix va démarrer.

    Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

    Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

    Ne touche à rien tant que le scan n'est pas terminé.

    Une fois le scan achevé, un rapport va s'afficher: poste son contenu.

    Remets aussi un rapport Hijackthis

    Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt
    0
    1. Voila déjà le rapport de combofix ( ça m'a pris du temps car il a mal fait redémarrer l'ordi je restais figée sur le bureau et il n'y avait aucun icone! j'ai donc dû relancer le pc !) je t'envoie après le rapport hijackthis!

      ComboFix 08-10-05.08 - MALLO Mickael 2008-10-06 16:40:07.2 - NTFSx86
      Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.588 [GMT 2:00]
      Lancé depuis: C:\Documents and Settings\MALLO Mickael\Bureau\ComboFix.exe
      Commutateurs utilisés :: C:\Documents and Settings\MALLO Mickael\Bureau\CFScript.txt

      [COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B][/COLOR]

      FILE ::
      C:\DOCUME~1\MALLOM~1\LOCALS~1\Temp\ibb1.dll
      C:\Program Files\SweetIM
      C:\Program Files\SweetIM\Messenger\SweetIM.exe
      C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
      .

      (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
      .

      C:\Program Files\SweetIM\Messenger\SweetIM.exe
      C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll

      .
      ((((((((((((((((((((((((((((( Fichiers créés du 2008-09-06 au 2008-10-06 ))))))))))))))))))))))))))))))))))))
      .

      2008-10-06 13:55 . 2008-10-06 13:55 <REP> d-------- C:\Program Files\Trend Micro
      2008-10-06 11:15 . 2008-10-06 11:16 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
      2008-10-06 11:15 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
      2008-10-06 11:15 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
      2008-10-05 15:33 . 2008-10-05 15:33 850 --a------ C:\WINDOWS\system32\ProductTweaks.xml
      2008-10-05 15:33 . 2008-10-05 15:36 385 --a------ C:\WINDOWS\system32\user_gensett.xml
      2008-10-05 15:14 . 2008-10-05 15:14 <REP> d-------- C:\WINDOWS\system32\logs
      2008-10-05 15:03 . 2008-10-05 16:10 <REP> d-------- C:\Program Files\Fichiers communs\BitDefender
      2008-10-05 14:06 . 2008-10-05 14:14 <REP> d-------- C:\WINDOWS\BDOSCAN8
      2008-10-05 14:01 . 2008-10-05 14:01 19,973,241 --a------ C:\WINDOWS\VPTNFILE.577
      2008-10-05 13:59 . 2008-10-05 14:01 <REP> d-------- C:\WINDOWS\AU_Temp
      2008-10-05 11:36 . 2008-10-05 11:36 <REP> d----c--- C:\Documents and Settings\All Users\Application Data\Grisoft
      2008-10-02 19:07 . 2008-10-02 19:07 <REP> d-------- C:\WINDOWS\report
      2008-10-02 19:06 . 2008-10-05 14:01 <REP> d-------- C:\WINDOWS\AU_Backup
      2008-10-02 19:06 . 2008-10-02 19:06 1,966,305 --a------ C:\WINDOWS\tsc.ptn
      2008-10-02 19:06 . 2008-10-05 14:01 1,213,784 --a------ C:\WINDOWS\vsapi32.dll
      2008-10-02 19:06 . 2008-10-02 19:06 333,576 --a------ C:\WINDOWS\TSC.exe
      2008-10-02 19:06 . 2008-10-05 14:01 91,744 --a------ C:\WINDOWS\BPMNT.dll
      2008-10-02 19:06 . 2008-10-02 19:06 71,749 --a------ C:\WINDOWS\hcextoutput.dll
      2008-10-02 19:05 . 2008-10-02 19:06 19,963,953 --a------ C:\WINDOWS\VPTNFILE.575
      2008-09-26 11:16 . 2008-09-26 11:16 <REP> d-------- C:\Program Files\PC Inspector File Recovery
      2008-09-26 11:16 . 2002-02-18 18:40 6,200 --a------ C:\WINDOWS\system32\INT13EXT.VXD
      2008-09-17 15:17 . 2008-09-17 15:17 <REP> d-------- C:\Program Files\Trojan Remover
      2008-09-17 15:17 . 2008-09-17 15:17 <REP> d-------- C:\Documents and Settings\MALLO Mickael\Application Data\Simply Super Software
      2008-09-17 15:17 . 2008-09-17 15:17 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Simply Super Software
      2008-09-17 15:17 . 2006-05-25 15:52 162,304 --a------ C:\WINDOWS\system32\ztvunrar36.dll
      2008-09-17 15:17 . 2003-02-02 20:06 153,088 --a------ C:\WINDOWS\system32\UNRAR3.dll
      2008-09-17 15:17 . 2005-08-26 01:50 77,312 --a------ C:\WINDOWS\system32\ztvunace26.dll
      2008-09-17 15:17 . 2002-03-06 01:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
      2008-09-17 15:17 . 2006-06-19 13:01 69,632 --a------ C:\WINDOWS\system32\ztvcabinet.dll
      2008-09-17 14:38 . 2008-10-05 12:51 <REP> d-------- C:\Program Files\Spyware Doctor
      2008-09-17 14:38 . 2008-09-17 14:38 <REP> d-------- C:\Documents and Settings\MALLO Mickael\Application Data\PC Tools
      2008-09-17 14:38 . 2008-10-05 13:17 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
      2008-09-17 14:38 . 2008-08-25 11:36 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
      2008-09-17 14:38 . 2008-08-25 11:36 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
      2008-09-17 14:38 . 2008-08-25 11:36 40,840 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
      2008-09-17 14:38 . 2008-06-02 15:19 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
      2008-09-17 14:26 . 2008-10-05 14:01 823 --a------ C:\WINDOWS\TSC.INI
      2008-09-17 14:25 . 2008-10-05 13:59 170 --a------ C:\WINDOWS\GetServer.ini
      2008-09-17 14:24 . 2008-09-17 14:24 <REP> d-------- C:\WINDOWS\AU_Log
      2008-09-17 14:24 . 2008-09-17 14:24 507,904 --a------ C:\WINDOWS\TMUPDATE.DLL
      2008-09-17 14:24 . 2008-09-17 14:24 286,720 --a------ C:\WINDOWS\PATCH.EXE
      2008-09-17 14:24 . 2008-09-17 14:24 69,689 --a------ C:\WINDOWS\UNZIP.DLL
      2008-09-11 18:46 . 2008-09-22 23:09 54,156 --ah----- C:\WINDOWS\QTFont.qfn
      2008-09-11 18:46 . 2008-09-11 18:46 1,409 --a------ C:\WINDOWS\QTFont.for
      2008-09-11 18:33 . 2008-09-11 18:33 268 --ah-c--- C:\sqmdata04.sqm
      2008-09-11 18:33 . 2008-09-11 18:33 244 --ah-c--- C:\sqmnoopt03.sqm
      2008-09-11 18:33 . 2008-09-11 18:33 136 --ah-c--- C:\sqmdata05.sqm
      2008-09-11 10:00 . 2008-09-11 10:00 244 --ah-c--- C:\sqmnoopt02.sqm
      2008-09-11 10:00 . 2008-09-11 10:00 232 --ah-c--- C:\sqmdata03.sqm
      2008-09-11 10:00 . 2008-09-11 10:00 232 --ah-c--- C:\sqmdata02.sqm
      2008-09-07 18:43 . 2008-09-07 18:43 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Sophos
      2008-09-07 14:40 . 2008-09-07 14:41 <REP> d-------- C:\Program Files\SweetIM
      2008-09-07 14:40 . 2008-09-07 14:41 <REP> d-------- C:\Documents and Settings\All Users\Application Data\SweetIM

      .
      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2008-10-06 08:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
      2008-09-26 09:16 --------- d--h--w C:\Program Files\InstallShield Installation Information
      2008-09-24 11:38 1,958 ----a-w C:\Documents and Settings\MALLO Mickael\Application Data\wklnhst.dat
      2008-09-09 18:07 2,864 ----a-w C:\WINDOWS\system32\winsock.dll
      2008-09-09 18:07 2,864 ----a-w C:\WINDOWS\system32\dllcache\winsock.dll
      2008-09-09 15:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg8
      2008-09-05 14:06 --------- d-----w C:\Program Files\Yahoo!
      2008-09-05 11:10 --------- d-----w C:\Program Files\Alwil Software
      2008-09-05 09:04 --------- d-----w C:\Documents and Settings\MALLO Mickael\Application Data\Malwarebytes
      2008-09-05 09:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Malwarebytes
      2008-09-05 00:13 --------- d-----w C:\Program Files\AVG
      2008-09-04 23:27 4,464 ----a-w C:\WINDOWS\system32\tmp.reg
      2008-09-04 21:58 --------- d-----w C:\Program Files\AxBx
      2008-09-02 21:58 88,576 ----a-w C:\WINDOWS\system32\AntiXPVSTFix.exe
      2008-09-02 14:51 86,528 ----a-w C:\WINDOWS\system32\VACFix.exe
      2008-08-29 19:49 --------- d-----w C:\Program Files\Panicware
      2008-08-28 20:36 82,432 ----a-w C:\WINDOWS\system32\IEDFix.C.exe
      2008-08-27 13:22 --------- d-----w C:\Documents and Settings\MALLO Mickael\Application Data\Samsung
      2008-08-27 13:18 --------- d-----w C:\Program Files\Samsung
      2008-08-26 17:21 --------- d-----w C:\Program Files\eMule
      2008-08-18 10:19 82,432 ----a-w C:\WINDOWS\system32\404Fix.exe
      2008-08-14 16:54 102,208 ------w C:\WINDOWS\system32\drivers\bdfndisf.sys
      2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
      2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
      2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
      2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
      2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
      2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
      2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
      2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
      2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
      2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
      2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
      2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
      2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
      2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
      2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
      2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
      2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
      2008-07-07 20:31 253,952 ----a-w C:\WINDOWS\system32\es.dll
      2008-07-07 20:31 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
      .

      et en ce qui concerne l'analyse RAV il n'a pas voulu me faire de rapport mais il m'a dit que l'ordi était infecté et il a supprimer le virus dont j'ai noté le nom : d:\folder.htt

      je te poste hijackthis dès que je l'ai fait!
      0
    2. Voila déjà le rapport de combofix ( ça m'a pris du temps car il a mal fait redémarrer l'ordi je restais figée sur le bureau et il n'y avait aucun icone! j'ai donc dû relancer le pc !) je t'envoie après le rapport hijackthis!

      ComboFix 08-10-05.08 - MALLO Mickael 2008-10-06 16:40:07.2 - NTFSx86
      Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.588 [GMT 2:00]
      Lancé depuis: C:\Documents and Settings\MALLO Mickael\Bureau\ComboFix.exe
      Commutateurs utilisés :: C:\Documents and Settings\MALLO Mickael\Bureau\CFScript.txt

      [COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B][/COLOR]

      FILE ::
      C:\DOCUME~1\MALLOM~1\LOCALS~1\Temp\ibb1.dll
      C:\Program Files\SweetIM
      C:\Program Files\SweetIM\Messenger\SweetIM.exe
      C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
      .

      (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
      .

      C:\Program Files\SweetIM\Messenger\SweetIM.exe
      C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll

      .
      ((((((((((((((((((((((((((((( Fichiers créés du 2008-09-06 au 2008-10-06 ))))))))))))))))))))))))))))))))))))
      .

      2008-10-06 13:55 . 2008-10-06 13:55 <REP> d-------- C:\Program Files\Trend Micro
      2008-10-06 11:15 . 2008-10-06 11:16 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
      2008-10-06 11:15 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
      2008-10-06 11:15 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
      2008-10-05 15:33 . 2008-10-05 15:33 850 --a------ C:\WINDOWS\system32\ProductTweaks.xml
      2008-10-05 15:33 . 2008-10-05 15:36 385 --a------ C:\WINDOWS\system32\user_gensett.xml
      2008-10-05 15:14 . 2008-10-05 15:14 <REP> d-------- C:\WINDOWS\system32\logs
      2008-10-05 15:03 . 2008-10-05 16:10 <REP> d-------- C:\Program Files\Fichiers communs\BitDefender
      2008-10-05 14:06 . 2008-10-05 14:14 <REP> d-------- C:\WINDOWS\BDOSCAN8
      2008-10-05 14:01 . 2008-10-05 14:01 19,973,241 --a------ C:\WINDOWS\VPTNFILE.577
      2008-10-05 13:59 . 2008-10-05 14:01 <REP> d-------- C:\WINDOWS\AU_Temp
      2008-10-05 11:36 . 2008-10-05 11:36 <REP> d----c--- C:\Documents and Settings\All Users\Application Data\Grisoft
      2008-10-02 19:07 . 2008-10-02 19:07 <REP> d-------- C:\WINDOWS\report
      2008-10-02 19:06 . 2008-10-05 14:01 <REP> d-------- C:\WINDOWS\AU_Backup
      2008-10-02 19:06 . 2008-10-02 19:06 1,966,305 --a------ C:\WINDOWS\tsc.ptn
      2008-10-02 19:06 . 2008-10-05 14:01 1,213,784 --a------ C:\WINDOWS\vsapi32.dll
      2008-10-02 19:06 . 2008-10-02 19:06 333,576 --a------ C:\WINDOWS\TSC.exe
      2008-10-02 19:06 . 2008-10-05 14:01 91,744 --a------ C:\WINDOWS\BPMNT.dll
      2008-10-02 19:06 . 2008-10-02 19:06 71,749 --a------ C:\WINDOWS\hcextoutput.dll
      2008-10-02 19:05 . 2008-10-02 19:06 19,963,953 --a------ C:\WINDOWS\VPTNFILE.575
      2008-09-26 11:16 . 2008-09-26 11:16 <REP> d-------- C:\Program Files\PC Inspector File Recovery
      2008-09-26 11:16 . 2002-02-18 18:40 6,200 --a------ C:\WINDOWS\system32\INT13EXT.VXD
      2008-09-17 15:17 . 2008-09-17 15:17 <REP> d-------- C:\Program Files\Trojan Remover
      2008-09-17 15:17 . 2008-09-17 15:17 <REP> d-------- C:\Documents and Settings\MALLO Mickael\Application Data\Simply Super Software
      2008-09-17 15:17 . 2008-09-17 15:17 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Simply Super Software
      2008-09-17 15:17 . 2006-05-25 15:52 162,304 --a------ C:\WINDOWS\system32\ztvunrar36.dll
      2008-09-17 15:17 . 2003-02-02 20:06 153,088 --a------ C:\WINDOWS\system32\UNRAR3.dll
      2008-09-17 15:17 . 2005-08-26 01:50 77,312 --a------ C:\WINDOWS\system32\ztvunace26.dll
      2008-09-17 15:17 . 2002-03-06 01:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
      2008-09-17 15:17 . 2006-06-19 13:01 69,632 --a------ C:\WINDOWS\system32\ztvcabinet.dll
      2008-09-17 14:38 . 2008-10-05 12:51 <REP> d-------- C:\Program Files\Spyware Doctor
      2008-09-17 14:38 . 2008-09-17 14:38 <REP> d-------- C:\Documents and Settings\MALLO Mickael\Application Data\PC Tools
      2008-09-17 14:38 . 2008-10-05 13:17 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
      2008-09-17 14:38 . 2008-08-25 11:36 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
      2008-09-17 14:38 . 2008-08-25 11:36 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
      2008-09-17 14:38 . 2008-08-25 11:36 40,840 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
      2008-09-17 14:38 . 2008-06-02 15:19 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
      2008-09-17 14:26 . 2008-10-05 14:01 823 --a------ C:\WINDOWS\TSC.INI
      2008-09-17 14:25 . 2008-10-05 13:59 170 --a------ C:\WINDOWS\GetServer.ini
      2008-09-17 14:24 . 2008-09-17 14:24 <REP> d-------- C:\WINDOWS\AU_Log
      2008-09-17 14:24 . 2008-09-17 14:24 507,904 --a------ C:\WINDOWS\TMUPDATE.DLL
      2008-09-17 14:24 . 2008-09-17 14:24 286,720 --a------ C:\WINDOWS\PATCH.EXE
      2008-09-17 14:24 . 2008-09-17 14:24 69,689 --a------ C:\WINDOWS\UNZIP.DLL
      2008-09-11 18:46 . 2008-09-22 23:09 54,156 --ah----- C:\WINDOWS\QTFont.qfn
      2008-09-11 18:46 . 2008-09-11 18:46 1,409 --a------ C:\WINDOWS\QTFont.for
      2008-09-11 18:33 . 2008-09-11 18:33 268 --ah-c--- C:\sqmdata04.sqm
      2008-09-11 18:33 . 2008-09-11 18:33 244 --ah-c--- C:\sqmnoopt03.sqm
      2008-09-11 18:33 . 2008-09-11 18:33 136 --ah-c--- C:\sqmdata05.sqm
      2008-09-11 10:00 . 2008-09-11 10:00 244 --ah-c--- C:\sqmnoopt02.sqm
      2008-09-11 10:00 . 2008-09-11 10:00 232 --ah-c--- C:\sqmdata03.sqm
      2008-09-11 10:00 . 2008-09-11 10:00 232 --ah-c--- C:\sqmdata02.sqm
      2008-09-07 18:43 . 2008-09-07 18:43 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Sophos
      2008-09-07 14:40 . 2008-09-07 14:41 <REP> d-------- C:\Program Files\SweetIM
      2008-09-07 14:40 . 2008-09-07 14:41 <REP> d-------- C:\Documents and Settings\All Users\Application Data\SweetIM

      .
      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2008-10-06 08:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
      2008-09-26 09:16 --------- d--h--w C:\Program Files\InstallShield Installation Information
      2008-09-24 11:38 1,958 ----a-w C:\Documents and Settings\MALLO Mickael\Application Data\wklnhst.dat
      2008-09-09 18:07 2,864 ----a-w C:\WINDOWS\system32\winsock.dll
      2008-09-09 18:07 2,864 ----a-w C:\WINDOWS\system32\dllcache\winsock.dll
      2008-09-09 15:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg8
      2008-09-05 14:06 --------- d-----w C:\Program Files\Yahoo!
      2008-09-05 11:10 --------- d-----w C:\Program Files\Alwil Software
      2008-09-05 09:04 --------- d-----w C:\Documents and Settings\MALLO Mickael\Application Data\Malwarebytes
      2008-09-05 09:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Malwarebytes
      2008-09-05 00:13 --------- d-----w C:\Program Files\AVG
      2008-09-04 23:27 4,464 ----a-w C:\WINDOWS\system32\tmp.reg
      2008-09-04 21:58 --------- d-----w C:\Program Files\AxBx
      2008-09-02 21:58 88,576 ----a-w C:\WINDOWS\system32\AntiXPVSTFix.exe
      2008-09-02 14:51 86,528 ----a-w C:\WINDOWS\system32\VACFix.exe
      2008-08-29 19:49 --------- d-----w C:\Program Files\Panicware
      2008-08-28 20:36 82,432 ----a-w C:\WINDOWS\system32\IEDFix.C.exe
      2008-08-27 13:22 --------- d-----w C:\Documents and Settings\MALLO Mickael\Application Data\Samsung
      2008-08-27 13:18 --------- d-----w C:\Program Files\Samsung
      2008-08-26 17:21 --------- d-----w C:\Program Files\eMule
      2008-08-18 10:19 82,432 ----a-w C:\WINDOWS\system32\404Fix.exe
      2008-08-14 16:54 102,208 ------w C:\WINDOWS\system32\drivers\bdfndisf.sys
      2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
      2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
      2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
      2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
      2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
      2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
      2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
      2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
      2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
      2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
      2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
      2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
      2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
      2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
      2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
      2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
      2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
      2008-07-07 20:31 253,952 ----a-w C:\WINDOWS\system32\es.dll
      2008-07-07 20:31 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
      .

      et en ce qui concerne l'analyse RAV il n'a pas voulu me faire de rapport mais il m'a dit que l'ordi était infecté et il a supprimer le virus dont j'ai noté le nom : d:\folder.htt

      je te poste hijackthis dès que je l'ai fait!
      0
  4. Voici rapport hijackthis :

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 17:30, on 2008-10-06
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16705)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\HP\TVPlay\Kernel\CLML_NTService\CLMLServer.exe
    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\HP\TVPlay\Kernel\TV\TVPCapSvc.exe
    C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    C:\Program Files\HP\TVPlay\Kernel\TV\TVPSched.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\HP\QuickPlay\QPService.exe
    C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
    C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
    C:\Program Files\Lecteur CANALPLAY\CanalPlayer.exe
    C:\Program Files\MessengerPlus! 3\MsgPlus.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
    C:\Program Files\HP\TVPlay\TVPService.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Palm\Hotsync.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Lecteur CANALPLAY\CanalPlayService.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Documents and Settings\MALLO Mickael\Bureau\scan.exe.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://portail.free.fr/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
    O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
    O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
    O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
    O4 - HKLM\..\Run: [Reminder] C:\Windows\CREATOR\Remind_XP.exe
    O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
    O4 - HKLM\..\Run: [PlayerKiosquePlus] C:\Program Files\Lecteur CANALPLAY\PlayerKiosquePlus.exe /iconic
    O4 - HKLM\..\Run: [CanalPlayer] C:\Program Files\Lecteur CANALPLAY\CanalPlayer.exe /iconic
    O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [TVPService] "C:\Program Files\HP\TVPlay\TVPService.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [PopUp Destroy] C:\Program Files\PopUp Destroy\Popup-Destroy.exe
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe /boot
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
    O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Palm Registration.lnk = C:\Program Files\Palm\register.exe
    O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: CyberLink Media Library Service(HP TVPlay) - Cyberlink - C:\Program Files\HP\TVPlay\Kernel\CLML_NTService\CLMLServer.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
    O23 - Service: Service CANALPLAY - Canal+ Active - C:\Program Files\Lecteur CANALPLAY\CanalPlayService.exe
    O23 - Service: CyberLink Background Capture Service (CBCS HP TVPlay) (TVPCapSvc) - Unknown owner - C:\Program Files\HP\TVPlay\Kernel\TV\TVPCapSvc.exe
    O23 - Service: CyberLink Task Scheduler (CTS HP TVPlay) (TVPSched) - Unknown owner - C:\Program Files\HP\TVPlay\Kernel\TV\TVPSched.exe
    0
    1. Contributeur sécurité
      si tu as la fin du rapport combofix je veux bien :)

      sinon pour verifier

      qu'il reste strictement rien:

      colle le rapport d'un scan en ligne
      avec un des suivants:

      bitdefender en ligne :
      http://www.bitdefender.fr/scan_fr/scan8/ie.html

      Panda en ligne :
      http://pandasoftware.fr

      Kaspersky en ligne
      https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
      0
      1. coucou !
        alors pour combofix je t'ai envoyé tout ce que j'avais alors désolée mais s'il y a une suite alors je ne l'ai pas!
        par contre j'ai fais l'analyse du pc avec bitdefender et c'était long ça a prit toute la nuit! voici le rapport :

        BitDefender Online Scanner

        Rapport d'analyse généré à: Tue, Oct 07, 2008 - 10:40:28

        Voie d'analyse: C:\;D:\;E:\;F:\;

        Statistiques

        Temps
        14:54:29

        Fichiers
        114816

        Directoires
        6117

        Secteurs de boot
        0

        Archives
        2316

        Paquets programmes
        8938

        Résultats

        Virus identifiés
        2

        Fichiers infectés
        3

        Fichiers suspects
        0

        Avertissements
        0

        Désinfectés
        0

        Fichiers effacés
        3

        Info sur les moteurs

        Définition virus
        1839875

        Version des moteurs
        AVCORE v1.7 (build 8314.19) (i386) (Sep 10 2008 19:37:42)

        Analyse des plugins
        16

        Archive des plugins
        43

        Unpack des plugins
        7

        E-mail plugins
        6

        Système plugins
        4

        Paramètres d'analyse

        Première action
        Désinfecté

        Seconde Action
        Supprimé

        Heuristique
        Oui

        Acceptez les avertissements
        Oui

        Extensions analysées
        exe;com;dll;ocx;scr;bin;dat;386;vxd;sys;wdm;cla;class;ovl;ole;hlp;doc;dot;xls;ppt;wbk;wiz;pot;ppa;xla;xlt;vbs;vbe;mdb;rtf;htm;hta;html;xml;xtp;php;asp;js;shs;chm;lnk;pif;prc;url;smm;pfd;msi;ini;csc;cmd;bas;

        Excludez les extensions

        Analyse d'emails
        Oui

        Analyse des Archives
        Oui

        Analyser paquets programmes
        Oui

        Analyse des fichiers
        Oui

        Analyse de boot
        Oui

        Fichier analysé
        Statut

        C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP116\A0027140.exe
        Détecté avec: Adware.XPAntiVirus.BD

        C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP116\A0027140.exe
        Supprimé

        C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP116\A0027145.sys
        Infecté par: Trojan.Avenger.B

        C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP116\A0027145.sys
        Supprimé

        C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP116\A0027173.sys
        Infecté par: Trojan.Avenger.B

        C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP116\A0027173.sys
        Supprimé
        0
    2. Contributeur sécurité
      si tout c'est bien passé désactive la restauration système pour purger les virus qui seraient dedans puis réactive là : https://www.informatruc.com

      encore des soucis???
      0
      1. J'ai toujours des problèmes de son il est toujours saccadé et mon curseur de souris est au ralentit et le pc rame aussi!
        Que faire? Pourquoi j'ai attrapé des virus alors que j'ai un antivirus avast qui est toujours en marche?
        0
    3. Contributeur sécurité
      avast c'est pas le top...

      scan avec super antispyware et colle le rapport

      http://www.01net.com/editorial/370512/superantispyware-v4.0/

      _____________________

      tu télécharge Lop S&D.exe sur ton Bureau.https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/LopSD.exe?attachauth=ANoY7co3ntqUavpZ3q1BG-h4pc13vqDZmhcNeEPChtsyrgAykRbhE8bZzhk979EfQD4AgwtQUHCaQ7ZQwNYMo3_0kA8htAspckDJtu2K5t6J9z6dLW4fpZyH4FpFL1tVMBZ8H-KnN7afZ5vt-WxZRpnynk-a0XmV_Y0C0q6DxGEDKie1TnPT7gFoZnoCnspzBmbW6ZzxA4fNr3oEDlbelNZON-LjF8nOmQ%3D%3D&attredirects=2

      * Double-clique dessus pour lancer l'installation
      * Puis double-clique sur le raccourci Lop S&D présent sur ton Bureau
      * Séléctionne la langue souhaitée , puis choisis l'option 1 (Recherche)
      * Patiente jusqu'à la fin du scan
      * Poste le rapport généré (C:\lopR.txt)
      0
      1. J'ai fais le scan super antispyware et il affiche une fenetre de rapport avec tout ce qu'il m'a trouvé d'infecté et biensur je ne sais pas sur quoi je dois cliquer car il n'y a que des onglets en anglais ...et je suis une bille en anglais! meme avec le traducteur je comprends rien! je n'arrive pas non plus à faire une capture d'écran pour te montrer la fenetre! est-ce que tu sais sur quoi je dois cliquer pour supprimer tout ce qu'il m'a trouvé?
        Merci d'avance encore pour le temps que tu me consacres!
        0
        1. finalement j'ai trouvé un tutoriel en français! voici le rapport :

          SUPERAntiSpyware Scan Log
          https://www.superantispyware.com/

          Generated 10/07/2008 at 09:46 PM

          Application Version : 4.21.1004

          Core Rules Database Version : 3591
          Trace Rules Database Version: 1578

          Scan type : Quick Scan
          Total Scan Time : 01:00:04

          Memory items scanned : 560
          Memory threats detected : 0
          Registry items scanned : 408
          Registry threats detected : 1
          File items scanned : 7695
          File threats detected : 11

          Adware.Tracking Cookie
          C:\Documents and Settings\MALLO Mickael\Cookies\mallo_mickael@mediaplex[1].txt
          C:\Documents and Settings\MALLO Mickael\Cookies\mallo_mickael@doubleclick[1].txt
          C:\Documents and Settings\MALLO Mickael\Cookies\mallo_mickael@weborama[1].txt
          C:\Documents and Settings\MALLO Mickael\Cookies\mallo_mickael@bluestreak[2].txt
          C:\Documents and Settings\MALLO Mickael\Cookies\mallo_mickael@tradedoubler[2].txt
          C:\Documents and Settings\MALLO Mickael\Cookies\mallo_mickael@bnpparibasnet.solution.weborama[2].txt
          C:\Documents and Settings\MALLO Mickael\Cookies\mallo_mickael@ads.pointroll[2].txt
          C:\Documents and Settings\MALLO Mickael\Cookies\mallo_mickael@smartadserver[2].txt
          C:\Documents and Settings\MALLO Mickael\Cookies\mallo_mickael@ad.yieldmanager[2].txt
          C:\Documents and Settings\MALLO Mickael\Cookies\mallo_mickael@xiti[1].txt
          C:\Documents and Settings\MALLO Mickael\Cookies\mallo_mickael@apmebf[1].txt

          Adware.IEPlugin
          HKCR\Remove

          Au fait, tu me dis que avast c'est pas top est-ce que tu pourrais me conseiller un bon antivirus?
          Merci beaucoup pour tout!
          0
          1. Voici le rapport de antivir :

            Avira AntiVir Personal
            Report file date: 2008-10-08 14:06

            Scanning for 1668572 virus strains and unwanted programs.

            Licensed to: Avira AntiVir PersonalEdition Classic
            Serial number: 0000149996-ADJIE-0001
            Platform: Windows XP
            Windows version: (Service Pack 2) [5.1.2600]
            Boot mode: Normally booted
            Username: MALLO Mickael
            Computer name: PC290951034918

            Version information:
            BUILD.DAT : 8.1.0.331 16934 Bytes 2008-08-12 11:46:00
            AVSCAN.EXE : 8.1.4.7 315649 Bytes 2008-06-26 08:57:53
            AVSCAN.DLL : 8.1.4.0 40705 Bytes 2008-05-26 07:56:40
            LUKE.DLL : 8.1.4.5 164097 Bytes 2008-06-12 12:44:19
            LUKERES.DLL : 8.1.4.0 12033 Bytes 2008-05-26 07:58:52
            ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 2007-07-18 10:33:34
            ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 2008-06-24 13:54:15
            ANTIVIR2.VDF : 7.0.6.217 3773440 Bytes 2008-09-26 12:00:22
            ANTIVIR3.VDF : 7.0.7.10 327168 Bytes 2008-10-08 12:00:30
            Engineversion : 8.1.1.35
            AEVDF.DLL : 8.1.0.5 102772 Bytes 2008-02-25 09:58:21
            AESCRIPT.DLL : 8.1.0.76 319867 Bytes 2008-10-08 12:00:58
            AESCN.DLL : 8.1.0.23 119156 Bytes 2008-07-10 12:44:49
            AERDL.DLL : 8.1.1.2 438644 Bytes 2008-10-08 12:00:56
            AEPACK.DLL : 8.1.2.3 364918 Bytes 2008-10-08 12:00:52
            AEOFFICE.DLL : 8.1.0.25 196986 Bytes 2008-10-08 12:00:48
            AEHEUR.DLL : 8.1.0.59 1438071 Bytes 2008-10-08 12:00:47
            AEHELP.DLL : 8.1.0.15 115063 Bytes 2008-07-10 12:44:48
            AEGEN.DLL : 8.1.0.36 315764 Bytes 2008-10-08 12:00:36
            AEEMU.DLL : 8.1.0.7 430452 Bytes 2008-07-31 08:33:21
            AECORE.DLL : 8.1.1.11 172406 Bytes 2008-10-08 12:00:33
            AEBB.DLL : 8.1.0.1 53617 Bytes 2008-07-10 12:44:48
            AVWINLL.DLL : 1.0.0.12 15105 Bytes 2008-07-09 08:40:05
            AVPREF.DLL : 8.0.2.0 38657 Bytes 2008-05-16 09:28:01
            AVREP.DLL : 8.0.0.2 98344 Bytes 2008-10-08 12:00:31
            AVREG.DLL : 8.0.0.1 33537 Bytes 2008-05-09 11:26:40
            AVARKT.DLL : 1.0.0.23 307457 Bytes 2008-02-12 08:29:23
            AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 2008-06-12 12:27:49
            SQLITE3.DLL : 3.3.17.1 339968 Bytes 2008-01-22 17:28:02
            SMTPLIB.DLL : 1.2.0.23 28929 Bytes 2008-06-12 12:49:40
            NETNT.DLL : 8.0.0.1 7937 Bytes 2008-01-25 12:05:10
            RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 2008-06-12 13:48:07
            RCTEXT.DLL : 8.0.52.0 86273 Bytes 2008-06-27 13:34:37

            Configuration settings for the scan:
            Jobname..........................: Local Hard Disks
            Configuration file...............: c:\program files\avira\antivir personaledition classic\alldiscs.avp
            Logging..........................: low
            Primary action...................: interactive
            Secondary action.................: ignore
            Scan master boot sector..........: on
            Scan boot sector.................: on
            Boot sectors.....................: C:, D:,
            Process scan.....................: on
            Scan registry....................: on
            Search for rootkits..............: off
            Scan all files...................: Intelligent file selection
            Scan archives....................: on
            Recursion depth..................: 20
            Smart extensions.................: on
            Macro heuristic..................: on
            File heuristic...................: medium

            Start of the scan: 2008-10-08 14:06

            The scan of running processes will be started
            Scan process 'HPZipm12.exe' - '1' Module(s) have been scanned
            Scan process 'avscan.exe' - '1' Module(s) have been scanned
            Scan process 'avcenter.exe' - '1' Module(s) have been scanned
            Scan process 'avgnt.exe' - '1' Module(s) have been scanned
            Scan process 'avguard.exe' - '1' Module(s) have been scanned
            Scan process 'sched.exe' - '1' Module(s) have been scanned
            Scan process 'WLLoginProxy.exe' - '1' Module(s) have been scanned
            Scan process 'iexplore.exe' - '1' Module(s) have been scanned
            Scan process 'CanalPlayService.exe' - '1' Module(s) have been scanned
            Scan process 'HPQTOA~1.EXE' - '1' Module(s) have been scanned
            Scan process 'alg.exe' - '1' Module(s) have been scanned
            Scan process 'hpqste08.exe' - '1' Module(s) have been scanned
            Scan process 'ashWebSv.exe' - '1' Module(s) have been scanned
            Scan process 'iPodService.exe' - '1' Module(s) have been scanned
            Scan process 'ashMaiSv.exe' - '1' Module(s) have been scanned
            Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
            Scan process 'TVPSched.exe' - '1' Module(s) have been scanned
            Scan process 'hpqwmiex.exe' - '1' Module(s) have been scanned
            Scan process 'wdfmgr.exe' - '1' Module(s) have been scanned
            Scan process 'TVPCapSvc.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'LSSrvc.exe' - '1' Module(s) have been scanned
            Scan process 'GoogleUpdaterService.exe' - '1' Module(s) have been scanned
            Scan process 'CLMLServer.exe' - '1' Module(s) have been scanned
            Scan process 'hpqimzone.exe' - '1' Module(s) have been scanned
            Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
            Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
            Scan process 'hpqtra08.exe' - '1' Module(s) have been scanned
            Scan process 'Hotsync.exe' - '1' Module(s) have been scanned
            Scan process 'SUPERAntiSpyware.exe' - '1' Module(s) have been scanned
            Scan process 'PSFree.exe' - '1' Module(s) have been scanned
            Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned
            Scan process 'msmsgs.exe' - '1' Module(s) have been scanned
            Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
            Scan process 'TVPService.exe' - '1' Module(s) have been scanned
            Scan process 'realsched.exe' - '1' Module(s) have been scanned
            Scan process 'iTunesHelper.exe' - '1' Module(s) have been scanned
            Scan process 'qttask.exe' - '1' Module(s) have been scanned
            Scan process 'MsgPlus.exe' - '1' Module(s) have been scanned
            Scan process 'CanalPlayer.exe' - '1' Module(s) have been scanned
            Scan process 'HP Wireless Assistant.exe' - '1' Module(s) have been scanned
            Scan process 'eabservr.exe' - '1' Module(s) have been scanned
            Scan process 'QPService.exe' - '1' Module(s) have been scanned
            Scan process 'SynTPEnh.exe' - '1' Module(s) have been scanned
            Scan process 'hpwuSchd2.exe' - '1' Module(s) have been scanned
            Scan process 'jusched.exe' - '1' Module(s) have been scanned
            Scan process 'atiptaxx.exe' - '1' Module(s) have been scanned
            Scan process 'ashServ.exe' - '1' Module(s) have been scanned
            Scan process 'aswUpdSv.exe' - '1' Module(s) have been scanned
            Scan process 'explorer.exe' - '1' Module(s) have been scanned
            Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
            Scan process 'lsass.exe' - '1' Module(s) have been scanned
            Scan process 'services.exe' - '1' Module(s) have been scanned
            Scan process 'winlogon.exe' - '1' Module(s) have been scanned
            Scan process 'csrss.exe' - '1' Module(s) have been scanned
            Scan process 'smss.exe' - '1' Module(s) have been scanned
            62 processes with 62 modules were scanned

            Starting master boot sector scan:
            Master boot sector HD0
            [INFO] No virus was found!

            Start scanning boot sectors:
            Boot sector 'C:\'
            [INFO] No virus was found!
            Boot sector 'D:\'
            [INFO] No virus was found!

            Starting to scan the registry.
            The registry was scanned ( '69' files ).

            Starting the file scan:

            Begin scan in 'C:\'
            C:\hiberfil.sys
            [WARNING] The file could not be opened!
            C:\pagefile.sys
            [WARNING] The file could not be opened!
            C:\Documents and Settings\MALLO Mickael\SendTo\WINHY.0LP
            [DETECTION] Is the TR/PSW.Stealer.31232.3 Trojan
            [NOTE] The file was moved to '493aa51b.qua'!
            C:\Program Files\Java\jre1.5.0_11\lib\rt.jar
            [0] Archive type: ZIP
            --> com/sun/org/apache/xalan/internal/xsltc/dom/Filter.class
            [WARNING] The file could not be read!
            Begin scan in 'D:\' <HP_RECOVERY>

            End of the scan: 2008-10-08 16:55
            Used time: 2:49:19 Hour(s)

            The scan has been done completely.

            5861 Scanning directories
            235230 Files were scanned
            1 viruses and/or unwanted programs were found
            0 Files were classified as suspicious:
            0 files were deleted
            0 files were repaired
            1 files were moved to quarantine
            0 files were renamed
            2 Files cannot be scanned
            235227 Files not concerned
            7146 Archives were scanned
            3 Warnings
            1 Notes
            0
            1. Contributeur sécurité
              ok

              encore des soucis?

              le rapport lop sd
              0
              1. RAS pour le moment ... pourvu que ça dure!
                Merci encore beaucoup pour ton aide qui m'a été si précieuse! je ne sais vraiment pas comment te remercier!
                Il faudrait qu'il y ait plus de gens comme toi! c'était très gentil de ta part de me consacrer autant de temps! maintenant si j'ai un soucis je sais à qui m'adresser!
                a bientôt peut-être!
                0
            2. Contributeur sécurité
              ok parfait pour virer ce que l'on a utilisé: lance tools cleaner
              http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner

              pour protéger gratos ton ordi

              https://www.commentcamarche.net/telecharger/ 4 securite

              mettre un antivirus

              ANTIVIR (en anglais mais très efficace)
              https://www.malekal.com/avira-free-security-antivirus-gratuit/ (merci Malekal)
              -------------
              des anti-espions :
              SPYBOT + MAWALWAREBYTE ANTIMALWARE

              +
              SPYWAREBLASTER pour immuniser le système contre vundo notamment mais en anglais (mais facile d'utilisation : il suffit de faire "update" pour mettre à jour tous les mois et ensuite" enable all protection" pour immuniser)...

              Rq : spybot et ad-aware on sorti de nouvelles versions cette année vérifiez que vous avez la dernière version
              --------
              un pare feu :
              celui de Windows ou mieux COMODO ou ONELINE ARMOR ou KERIO ou JETICO ou ZONE ALARM (mettre que le parefeu gratuit)

              https://www.clubic.com/telecharger-fiche11071-sunbelt-personal-firewall-ex-kerio.html
              https://manuelsdaide.com/contact/
              http://www.open-files.com/forum/index.php?showtopic=29277
              https://www.commentcamarche.net/telecharger/ 157 zonealarm

              -----------

              CCLEANER pour effacer les traces de surf
              0