Ordinateur très lent

Bonjour,
windows xp
firefox

mon antivirus bitdéfender sécurité 2008 à trouver, c'est dernier temps plein de fichiers infectés.Il les a supprimés mais le lendemain il y en avait autant. Ainsi que 3 fichiers qui n'ont pas plus être analyser faute de mots de passe.les 3 fichers avec mot de passe ce trouvait ds les data de adobe version 6 et 7.j'ai donc supprimé ces dossiers.j'ai téléchargé spybot search et destroy,fait une recherche et j'ai tout supprimé mais je n'ai pas sauvegardé le rapport,il y avait que des cookies. Et depuis ce temps il est super long à ouvrir une page internet ou lors d'un téléchargement,ou bien lorsque je clic sur un icone, il mais defois 5 min à s'ouvrir.
Pouvez vous m'aider? S'il vous plait, je ne sait pas quoi faire. merci d'avance
Configuration: Windows XP
Firefox 3.0.4

16 réponses

Résumé de la discussion

Le fil décrit une machine sous Windows XP et Firefox où BitDefender 2008 détecte des fichiers infectés récurrents, et où des dossiers Adobe contiennent des éléments protégés par mot de passe. Plusieurs réponses préconisent des outils de nettoyage comme Spybot S&D, ComboFix et SDFix, effectués en mode sans échec, puis la suppression des services et des entrées malveillantes du registre. Des consignes complémentaires suggèrent Malwarebytes, la mise à jour des navigateurs et d'Adobe Reader, ainsi que la révision des dossiers du bureau et la collecte de rapports. En outre, la discussion mentionne des délais et des retours d’expérience, notamment l’exécution de SDFix guidant vers un rapport Report.txt et la nécessité de poursuivre les mises à jour logicielles.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    slt,

    Télécharge ici :

    http://images.malwareremoval.com/random/RSIT.exe

    random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

    Double-clique sur RSIT.exe afin de lancer RSIT.

    Clique Continue à l'écran Disclaimer.

    Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

    Poste le contenu de log.txt (<<qui sera affiché)
    ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

    NB : Les rapports sont sauvegardés dans le dossier C:\rsit
    1. merci de ta réponse très rapide j'essaie ça ce soir car je dois partir au taff merci beaucoup de ton aide
    2. je l'ai téléchargé et j'ai réduit les 2 bloques "info bloc et log bloc" que faire ensuite merci
    3. Malwarebytes' Anti-Malware 1.30
      Version de la base de données: 1423
      Windows 5.1.2600 Service Pack 2

      26/11/2008 10:00:44
      mbam-log-2008-11-26 (10-00-08).txt

      Type de recherche: Examen complet (C:\|D:\|)
      Eléments examinés: 122302
      Temps écoulé: 1 hour(s), 12 minute(s), 38 second(s)

      Processus mémoire infecté(s): 0
      Module(s) mémoire infecté(s): 0
      Clé(s) du Registre infectée(s): 0
      Valeur(s) du Registre infectée(s): 0
      Elément(s) de données du Registre infecté(s): 0
      Dossier(s) infecté(s): 0
      Fichier(s) infecté(s): 2

      Processus mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Module(s) mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Clé(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Valeur(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Elément(s) de données du Registre infecté(s):
      (Aucun élément nuisible détecté)

      Dossier(s) infecté(s):
      (Aucun élément nuisible détecté)

      Fichier(s) infecté(s):
      C:\RECYCLER\S-1-5-21-1715567821-963894560-725345543-1004\Dc9.exe (Spyware.OnlineGames) -> No action taken.
      C:\RECYCLER\S-1-5-21-1715567821-963894560-725345543-1004\Dc8\Clone DVD2 2.8.9.2\Clonedvd2 v2.8.9.2 crack by TFT-TEAM.exe (Spyware.OnlineGames) -> No action taken.
      VOILA LE RAPPOERT DE MALWAREBYTES
      PS/Je n'est aucun rapport avec l'informaticien quelqu'un a posé un autre poste sur la page de mon probleme.
      ne confond pas merci
      Merci de ton aide
  2. Contributeur sécurité
    ok et si tu as gardé le rapport bitdefender colle le aussi
    1. Fichier journal de BitDefender
      Produit : BitDefender Internet Security 2008
      Version : BitDefender UIScanner V.11
      Date du journal : 12:41:59 23/11/2008
      Chemin du journal : C:\Documents and Settings\All Users\Application Data\BitDefender\Desktop\Profiles\Logs\deep_scan\1227440519_1_02.xml

      Analyse des chemins :Chemin0000: C:\
      Chemin0001: D:\
      Chemin0002: J:\

      Options d’analyse :Analyse contre les virus : Oui
      Détecter les adwares : Oui
      Analyse contre les spywares : Oui
      Analyse des applications : Oui
      Détecter les numéroteurs : Oui
      Analyse contre les Rootkits : Oui

      Options de sélection de cible :Analyse les clés du registre : Oui
      Analyse des cookies : Oui
      Analyser le secteur de boot : Oui
      Analyse des processus mémoire : Oui
      Analyser les archives : Oui
      Analyser les fichiers enpaquetés : Oui
      Analyser les emails : Oui
      Analyser tous les fichiers : Oui
      Analyse heuristique : Oui
      Extensions analysées :
      Extensions exclues :

      Traitement cibleAction par défaut pour les objets infectés : Désinfecter
      Action par défaut pour les objets suspects : Aucun
      Action par défaut pour les objets camouflés : Aucun

      Résumé de l'analyseNombre de signatures de virus : 2254256
      Plugins archives : 43
      Plug-ins messagerie : 6
      Plugins d'analyse : 12
      Plugins archives : 43
      Plug-ins système : 5
      Plug-ins décompression : 7

      Résumé de l'analyse généraleEléments analysés : 267627
      Eléments infectés : 3
      Eléments suspects : 0
      Eléments résolus : 3
      Virus individuels trouvés : 2
      Répertoires analysés : 5646
      Secteur de boot analysés : 6
      Archives analysés : 1948
      Erreurs I/O : 33
      Temps d'analyse : 00:00:47:15
      Fichiers par seconde : 94

      Résumé des processus analysésAnalysé(s) : 47
      Infecté(s) : 0

      Résumé des clés de registre analyséesAnalysé(s) : 887
      Infecté(s) : 0

      Résumé des cookies analysésAnalysé(s) : 131
      Infecté(s) : 0

      Problèmes non résolus :Nom de l'objet Nom de la menace Etat final

      Problèmes résolusNom de l'objet Nom de la menace Etat final
      [System]=]C:\Documents and Settings\Stéphane\Cookies\stéphane@atdmt[2].txt Cookie.ATDMT Effacé
      [System]=]C:\Documents and Settings\Stéphane\Cookies\stéphane@cetelem.solution.weborama[2].txt Cookie.Weborama Effacé
      [System]=]C:\Documents and Settings\Stéphane\Cookies\stéphane@weborama[1].txt Cookie.Weborama Effacé

      Objets non scannés :Nom de l'objet Raison Etat final
      C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig708\FRA\Data1.cab=]WebSearchENU.pdf Protégé par mot de passe Aucune action possible
      C:\WINDOWS\Cache\Adobe Reader 6.0.1\FRABIG\Data1.cab=]RdrMsgFRA.pdf Protégé par mot de passe Aucune action possible
      C:\WINDOWS\Cache\Adobe Reader 6.0.1\FRABIG\Data1.cab=]RdrMsgENU.pdf Protégé par mot de passe Aucune action possible
    2. info.txt logfile of random's system information tool 1.04 2008-11-25 21:50:29

      ======Uninstall list======

      -->C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
      -->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
      -->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
      -->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
      -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
      Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
      Adobe Reader 8.1.3 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81300000003}
      Alice ADSL - Installation principale-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CE5D7CE8-27E7-4452-AF33-F38F074BBD08}\setup.exe" -l0x40c -eth -pri
      Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
      Assistant de connexion Windows Live-->MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
      AVS Video Converter 6-->"C:\Program Files\AVS4YOU\AVSVideoConverter6\unins000.exe"
      AVS4YOU Software Navigator 1.2-->"C:\Program Files\AVS4YOU\AVSSoftwareNavigator\unins000.exe"
      Barre d'outils MSN-->C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\mtbs.exe c
      BitDefender Internet Security 2008-->MsiExec.exe /I{C7D66C23-7564-4072-AF39-9374AF3D5F48}
      CloneDVD2-->"C:\Program Files\Elaborate Bytes\CloneDVD2\CloneDVD2-uninst.exe" /D="C:\Program Files\Elaborate Bytes\CloneDVD2"
      Correctif pour Windows XP (KB935448)-->"C:\WINDOWS\$NtUninstallKB935448$\spuninst\spuninst.exe"
      Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
      Correctif Windows XP - KB873339-->C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe
      Correctif Windows XP - KB885835-->C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe
      Correctif Windows XP - KB885836-->C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe
      Correctif Windows XP - KB886185-->C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.exe
      Correctif Windows XP - KB887472-->C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.exe
      Correctif Windows XP - KB888302-->C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe
      Correctif Windows XP - KB890859-->"C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.exe"
      Correctif Windows XP - KB891781-->C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe
      Digital Photo Navigator 1.5-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B7EF4BD8-CA13-11D5-AE3D-005004B8E30C}\Setup.exe" -l0x9
      Easy CD-DA Extractor 12-->"C:\WINDOWS\Easy CD-DA Extractor 12\uninstall.exe" "/U:C:\Program Files\Easy CD-DA Extractor 12\irunin.xml"
      eMule-->"C:\Program Files\eMule\Uninstall.exe"
      Free FLV Converter V 5.3-->"C:\Program Files\Free FLV Converter\unins000.exe"
      Free Mp3 Wma Converter V 1.8.0-->"C:\Program Files\Free Audio Pack\unins000.exe"
      High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
      HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
      HP Extended Capabilities 6.1-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
      HP Imaging Device Functions 6.1-->C:\Program Files\HP\Digital Imaging\DigitalImagingMonitor\hpzscr01.exe -datfile hpqbud01.dat
      HP Photosmart Essential-->MsiExec.exe /X{D7CAE58E-26DE-49B7-A75D-EAEDF76726BE}
      HP PSC & OfficeJet 6.1.A-->"C:\Program Files\HP\Digital Imaging\{E5A8DDAB-AE80-48C6-A75B-D0FAB83B299D}\setup\hpzscr01.exe" -datfile hposcr08.dat
      HP Solution Center and Imaging Support Tools 6.1-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
      HP Update-->MsiExec.exe /X{FE57DE70-95DE-4B64-9266-84DA811053DB}
      Java(TM) 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
      K-Lite Codec Pack 2.72 Full-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
      Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
      Mise à jour de sécurité pour Lecteur Windows Media (KB911564)-->"C:\WINDOWS\$NtUninstallKB911564$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media 6.4 (KB925398)-->"C:\WINDOWS\$NtUninstallKB925398_WMP64$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media 9 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP9$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB890046)-->"C:\WINDOWS\$NtUninstallKB890046$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB893756)-->"C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB896358)-->"C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB896423)-->"C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB896428)-->"C:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB899587)-->"C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB899591)-->"C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB900725)-->"C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB901017)-->"C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB901214)-->"C:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB902400)-->"C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB905414)-->"C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB905749)-->"C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB908519)-->"C:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB911562)-->"C:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB911927)-->"C:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB913580)-->"C:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB914388)-->"C:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB914389)-->"C:\WINDOWS\$NtUninstallKB914389$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB918118)-->"C:\WINDOWS\$NtUninstallKB918118$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB918439)-->"C:\WINDOWS\$NtUninstallKB918439$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB919007)-->"C:\WINDOWS\$NtUninstallKB919007$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB920213)-->"C:\WINDOWS\$NtUninstallKB920213$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB920670)-->"C:\WINDOWS\$NtUninstallKB920670$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB920683)-->"C:\WINDOWS\$NtUninstallKB920683$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB920685)-->"C:\WINDOWS\$NtUninstallKB920685$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB922819)-->"C:\WINDOWS\$NtUninstallKB922819$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB923191)-->"C:\WINDOWS\$NtUninstallKB923191$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB923414)-->"C:\WINDOWS\$NtUninstallKB923414$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB923689)-->"C:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
      Mise à jour de sécurité pour Windows XP (KB923980)-->"C:\WINDOWS\$NtUninstallKB923980$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB924270)-->"C:\WINDOWS\$NtUninstallKB924270$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB924496)-->"C:\WINDOWS\$NtUninstallKB924496$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB924667)-->"C:\WINDOWS\$NtUninstallKB924667$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB925902)-->"C:\WINDOWS\$NtUninstallKB925902$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB926255)-->"C:\WINDOWS\$NtUninstallKB926255$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB926436)-->"C:\WINDOWS\$NtUninstallKB926436$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB927779)-->"C:\WINDOWS\$NtUninstallKB927779$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB927802)-->"C:\WINDOWS\$NtUninstallKB927802$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB928255)-->"C:\WINDOWS\$NtUninstallKB928255$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB928843)-->"C:\WINDOWS\$NtUninstallKB928843$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB929123)-->"C:\WINDOWS\$NtUninstallKB929123$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB930178)-->"C:\WINDOWS\$NtUninstallKB930178$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB931261)-->"C:\WINDOWS\$NtUninstallKB931261$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB931784)-->"C:\WINDOWS\$NtUninstallKB931784$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB932168)-->"C:\WINDOWS\$NtUninstallKB932168$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB933729)-->"C:\WINDOWS\$NtUninstallKB933729$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB935839)-->"C:\WINDOWS\$NtUninstallKB935839$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB935840)-->"C:\WINDOWS\$NtUninstallKB935840$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB936021)-->"C:\WINDOWS\$NtUninstallKB936021$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB938127)-->"C:\WINDOWS\$NtUninstallKB938127$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB941202)-->"C:\WINDOWS\$NtUninstallKB941202$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB941568)-->"C:\WINDOWS\$NtUninstallKB941568$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB941644)-->"C:\WINDOWS\$NtUninstallKB941644$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB941693)-->"C:\WINDOWS\$NtUninstallKB941693$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB943055)-->"C:\WINDOWS\$NtUninstallKB943055$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB943460)-->"C:\WINDOWS\$NtUninstallKB943460$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB943485)-->"C:\WINDOWS\$NtUninstallKB943485$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB944338)-->"C:\WINDOWS\$NtUninstallKB944338$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB944653)-->"C:\WINDOWS\$NtUninstallKB944653$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB945553)-->"C:\WINDOWS\$NtUninstallKB945553$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB946026)-->"C:\WINDOWS\$NtUninstallKB946026$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB947864)-->"C:\WINDOWS\$NtUninstallKB947864$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB948590)-->"C:\WINDOWS\$NtUninstallKB948590$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB948881)-->"C:\WINDOWS\$NtUninstallKB948881$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950749)-->"C:\WINDOWS\$NtUninstallKB950749$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950759)-->"C:\WINDOWS\$NtUninstallKB950759$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB953838)-->"C:\WINDOWS\$NtUninstallKB953838$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956390)-->"C:\WINDOWS\$NtUninstallKB956390$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB894391)-->"C:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB900485)-->"C:\WINDOWS\$NtUninstallKB900485$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB908531)-->"C:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB910437)-->"C:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB911280)-->"C:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB916595)-->"C:\WINDOWS\$NtUninstallKB916595$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB920872)-->"C:\WINDOWS\$NtUninstallKB920872$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB922582)-->"C:\WINDOWS\$NtUninstallKB922582$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB927891)-->"C:\WINDOWS\$NtUninstallKB927891$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB930916)-->"C:\WINDOWS\$NtUninstallKB930916$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB938828)-->"C:\WINDOWS\$NtUninstallKB938828$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB942763)-->"C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
      Mozilla Firefox (3.0.4)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
      MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
      MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
      Nero 7 Essentials-->MsiExec.exe /I{C4A0C307-053A-4335-8B28-60E901DB1036}
      Nokia Connectivity Cable Driver-->RUNDLL32.EXE nsesetup.dll,DoNTUninst
      NVIDIA Drivers-->C:\WINDOWS\system32\nvuide.exe UninstallGUI
      OpenOffice.org 2.4-->MsiExec.exe /I{2A1AA9CF-2E7D-4235-BDAB-8FA4291DD5D8}
      PowerDirector Express-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EDE721EC-870A-11D8-9D75-000129760D75}\setup.exe" -uninstall
      PowerDVD-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
      PowerProducer-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\setup.exe" -uninstall
      Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
      Samsung Master-->C:\Program Files\InstallShield Installation Information\{AEC0CEBC-0FC7-4716-8222-1C4A742719B1}\Setup.exe -runfromtemp -l0x040c -removeonly
      Samsung USB Driver-->"C:\Program Files\InstallShield Installation Information\{713E5AB1-2389-43A6-8313-CB4D3C44C4FA}\Setup.exe" -runfromtemp -l0x040c anything -removeonly
      Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
      SuperCopier2-->"C:\Program Files\SuperCopier2\SC2Uninst.exe"
      VideoLAN VLC media player 0.8.6f-->C:\Program Files\VideoLAN\VLC\uninstall.exe
      Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803$\spuninst\spuninst.exe"
      Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
      Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
      Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
      Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll

      ======Hosts File======

      127.0.0.1 www.007guard.com
      127.0.0.1 007guard.com
      127.0.0.1 008i.com
      127.0.0.1 www.008k.com
      127.0.0.1 008k.com
      127.0.0.1 www.00hq.com
      127.0.0.1 00hq.com
      127.0.0.1 010402.com
      127.0.0.1 www.032439.com
      127.0.0.1 032439.com

      ======Security center information======

      AV: Bitdefender Antivirus
      FW: Bitdefender Firewall

      ======Environment variables======

      "ComSpec"=%SystemRoot%\system32\cmd.exe
      "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
      "windir"=%SystemRoot%
      "FP_NO_HOST_CHECK"=NO
      "OS"=Windows_NT
      "PROCESSOR_ARCHITECTURE"=x86
      "PROCESSOR_LEVEL"=15
      "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 79 Stepping 2, AuthenticAMD
      "PROCESSOR_REVISION"=4f02
      "NUMBER_OF_PROCESSORS"=1
      "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
      "TEMP"=%SystemRoot%\TEMP
      "TMP"=%SystemRoot%\TEMP

      -----------------EOF-----------------
    3. Logfile of random's system information tool 1.04 (written by random/random)
      Run by Stéphane at 2008-11-25 21:49:50
      Microsoft Windows XP Édition familiale Service Pack 2
      System drive C: has 7 GB (7%) free of 97 GB
      Total RAM: 1023 MB (39% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 21:50:26, on 25/11/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\RunDLL32.exe
      C:\WINDOWS\RTHDCPL.EXE
      C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
      C:\Program Files\Microsoft IntelliType Pro\type32.exe
      C:\Program Files\Microsoft IntelliPoint\point32.exe
      C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\SuperCopier2\SuperCopier2.exe
      C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
      C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
      C:\Program Files\eMule\emule.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\wdfmgr.exe
      C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
      C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
      C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\alg.exe
      C:\Program Files\Windows Live\Messenger\usnsvc.exe
      C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\RunDLL32.exe
      C:\WINDOWS\RTHDCPL.EXE
      C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
      C:\Program Files\Microsoft IntelliType Pro\type32.exe
      C:\Program Files\Microsoft IntelliPoint\point32.exe
      C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
      C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
      C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Documents and Settings\Stéphane\Bureau\RSIT.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe
      C:\Program Files\trend micro\Stéphane.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://portail.free.fr/
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
      O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
      O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
      O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [SW20] C:\WINDOWS\system32\sw20.exe
      O4 - HKLM\..\Run: [SW24] C:\WINDOWS\system32\sw24.exe
      O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
      O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
      O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
      O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
      O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
      O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
      O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-21-1715567821-963894560-725345543-1005\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Isabelle')
      O4 - HKUS\S-1-5-21-1715567821-963894560-725345543-1005\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'Isabelle')
      O4 - HKUS\S-1-5-21-1715567821-963894560-725345543-1005\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" (User 'Isabelle')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - S-1-5-21-1715567821-963894560-725345543-1005 Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe (User 'Isabelle')
      O4 - S-1-5-21-1715567821-963894560-725345543-1005 User Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe (User 'Isabelle')
      O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
      O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
      O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
    4. j'ai mis l'ancien rapport Bitdéfender ainsi que les 2 blocs notes que tu me demandais.
      bon courage et encore merci de ton aide.j'attend ta réponse
  3. l informaticien qui est venu reparer mon ordi a changé sur mon pc la carte mere une barette memoire la carte graphique plus un nouvel ecran, tout cela pour 300 euros ce dernier a bien fonctionné une journée..il est tres tres long a telecharger les page internet j ai meme du son dans mes hauts parleurs comme un radio que j entends trers doucement...j ai comme anti virus norton et ccleaner..j avoue que je suis nulle en informatique. je me permets donc de vous demander de l aide.
    cordialement.bernadette
    1. Contributeur sécurité
      il a changé tout l'ordi alors :)
      1. presque oui mais c est pas pour autant qu il fonctionne..
      2. @dadou83470salut a tous

        http://pagesperso-orange.fr/rginformatique/section%20virus/demofairesontmessage.htm
        dadou fait ton message a toi sur le forum

        ,)
    2. Fichier journal de BitDefender
      Produit : BitDefender Internet Security 2008
      Version : BitDefender UIScanner V.11
      Date du journal : 12:41:59 23/11/2008
      Chemin du journal : C:\Documents and Settings\All Users\Application Data\BitDefender\Desktop\Profiles\Logs\deep_scan\1227440519_1_02.xml

      Analyse des chemins :Chemin0000: C:\
      Chemin0001: D:\
      Chemin0002: J:\

      Options d’analyse :Analyse contre les virus : Oui
      Détecter les adwares : Oui
      Analyse contre les spywares : Oui
      Analyse des applications : Oui
      Détecter les numéroteurs : Oui
      Analyse contre les Rootkits : Oui

      Options de sélection de cible :Analyse les clés du registre : Oui
      Analyse des cookies : Oui
      Analyser le secteur de boot : Oui
      Analyse des processus mémoire : Oui
      Analyser les archives : Oui
      Analyser les fichiers enpaquetés : Oui
      Analyser les emails : Oui
      Analyser tous les fichiers : Oui
      Analyse heuristique : Oui
      Extensions analysées :
      Extensions exclues :

      Traitement cibleAction par défaut pour les objets infectés : Désinfecter
      Action par défaut pour les objets suspects : Aucun
      Action par défaut pour les objets camouflés : Aucun

      Résumé de l'analyseNombre de signatures de virus : 2254256
      Plugins archives : 43
      Plug-ins messagerie : 6
      Plugins d'analyse : 12
      Plugins archives : 43
      Plug-ins système : 5
      Plug-ins décompression : 7

      Résumé de l'analyse généraleEléments analysés : 267627
      Eléments infectés : 3
      Eléments suspects : 0
      Eléments résolus : 3
      Virus individuels trouvés : 2
      Répertoires analysés : 5646
      Secteur de boot analysés : 6
      Archives analysés : 1948
      Erreurs I/O : 33
      Temps d'analyse : 00:00:47:15
      Fichiers par seconde : 94

      Résumé des processus analysésAnalysé(s) : 47
      Infecté(s) : 0

      Résumé des clés de registre analyséesAnalysé(s) : 887
      Infecté(s) : 0

      Résumé des cookies analysésAnalysé(s) : 131
      Infecté(s) : 0

      Problèmes non résolus :Nom de l'objet Nom de la menace Etat final

      Problèmes résolusNom de l'objet Nom de la menace Etat final
      [System]=]C:\Documents and Settings\Stéphane\Cookies\stéphane@atdmt[2].txt Cookie.ATDMT Effacé
      [System]=]C:\Documents and Settings\Stéphane\Cookies\stéphane@cetelem.solution.weborama[2].txt Cookie.Weborama Effacé
      [System]=]C:\Documents and Settings\Stéphane\Cookies\stéphane@weborama[1].txt Cookie.Weborama Effacé

      Objets non scannés :Nom de l'objet Raison Etat final
      C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig708\FRA\Data1.cab=]WebSearchENU.pdf Protégé par mot de passe Aucune action possible
      C:\WINDOWS\Cache\Adobe Reader 6.0.1\FRABIG\Data1.cab=]RdrMsgFRA.pdf Protégé par mot de passe Aucune action possible
      C:\WINDOWS\Cache\Adobe Reader 6.0.1\FRABIG\Data1.cab=]RdrMsgENU.pdf Protégé par mot de passe Aucune action possible

      j'avait suprimée les 3 fichier avec mot de passe carément le bloc data
      1. Contributeur sécurité
        je comprend pas bien pourquoi l'informaticien a changé tout cela sauf si c'est toi qui a demandé :)

        scan avec
        MalwareByte's Anti-Malware en mode normal et vire ce qui est trouvé et colle le rapport

        https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

        ____________________

        POUR ADOBE c'est rien c'est que les versions sont anciennes (vire les via ton panneau de configuration) ainsi que la version 8 puis

        Mettre a jour java:
        https://www.malekal.com/maintenir-java-adobe-reader-et-le-player-flash-a-jour/

        mettre a jour internet explorer
        https://www.01net.com/telecharger/windows/Internet/navigateur/fiches/33081.html

        mettre à jour adobe reader
        https://acrobat.adobe.com/fr/fr/acrobat/pdf-reader.html
        1. i cherchait d ou venait le soucis a savoir mon ecrn se mettait tout noir mon pc continait a tourner mais j etait obligé de le redemarrer. et de fil en aiguille il a tout changer pour me dire a la fin que cela provenait de la carte mere..j ai fais ce que tu m as dit enfin je pense...je te remercie infiniment du temps que tu m accordes.

          Malwarebytes' Anti-Malware 1.30
          Version de la base de données: 1424
          Windows 5.1.2600 Service Pack 2

          26/11/2008 08:29:46
          mbam-log-2008-11-26 (08-29-46).txt

          Type de recherche: Examen rapide
          Eléments examinés: 48478
          Temps écoulé: 6 minute(s), 6 second(s)

          Processus mémoire infecté(s): 0
          Module(s) mémoire infecté(s): 0
          Clé(s) du Registre infectée(s): 0
          Valeur(s) du Registre infectée(s): 1
          Elément(s) de données du Registre infecté(s): 0
          Dossier(s) infecté(s): 0
          Fichier(s) infecté(s): 4

          Processus mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Module(s) mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Clé(s) du Registre infectée(s):
          (Aucun élément nuisible détecté)

          Valeur(s) du Registre infectée(s):
          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\gowgoek (Adware.Navipromo.H) -> Quarantined and deleted successfully.

          Elément(s) de données du Registre infecté(s):
          (Aucun élément nuisible détecté)

          Dossier(s) infecté(s):
          (Aucun élément nuisible détecté)

          Fichier(s) infecté(s):
          C:\Documents and Settings\bernadette\Local Settings\Application Data\gowgoek_navps.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
          C:\Documents and Settings\bernadette\Local Settings\Application Data\gowgoek_nav.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
          C:\Documents and Settings\bernadette\Local Settings\Application Data\gowgoek.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
          C:\Documents and Settings\bernadette\Local Settings\Application Data\gowgoek.exe (Adware.Navipromo.H) -> Delete on reboot.
        2. @dadou83470dadou83, Poste ton probleme ailleur s'il te plaisce n'est pas moi qui regle les souci des autres, j'en ai assez avec mon ordi merci
        3. j'attend ta reponse car je ne sais pas ce que je dois faire du rapport d'analyse."quarantaine, supprimée?
          merci
        4. je travail avec mozilla firefox, dois-je mettre a jour internet exploreur?ou l'installer
      2. MILLES EXCUSES...SUIS DESOLE
        1. ce n'est pas grave, j'espère que toi aussi tu trouve des réponses à ta question.merci
      3. Contributeur sécurité
        juste mettre a jour car windows l'utilise pour se mettre a jour

        ok une infection navipromo:
        fais ceci

        télécharger sur le bureau
        Navilog.zip (IL MAFIOSO)
        http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

        = Double-Clic navilog1.zip
        = Extraire tout sur le bureau
        = Double-Clic navilog1 qui est sur le bureau
        = Appuyer sur une touche jusqu' arriver aux options
        = Choisir option 1

        un rapport : fixnavi.txt dans C : va se creer
        le copier/coller dans ton prochain message.
        1. je n'est pas vue l'option 1 mais j'ai fait francais puis recherche il est en train d'analyser.merci
          qu'es ce que je fait de mon resultat de malawarebites stp
        2. Search Navipromo version 3.6.9 commencé le 26/11/2008 à 11:04:23,68

          !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
          !!! Postez ce rapport sur le forum pour le faire analyser !!!
          !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

          Outil exécuté depuis C:\Program Files\navilog1
          Session actuelle : "Stéphane"

          Mise à jour le 05.11.2008 à 21h00 par IL-MAFIOSO

          Microsoft Windows XP [version 5.1.2600]
          Internet Explorer : 6.0.2900.2180
          Système de fichiers : NTFS

          Recherche executé en mode normal

          *** Recherche Programmes installés ***

          *** Recherche dossiers dans "C:\WINDOWS" ***

          *** Recherche dossiers dans "C:\Program Files" ***

          *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

          *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***

          *** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***

          *** Recherche dossiers dans "C:\Documents and Settings\Stéphane\applic~1" ***

          *** Recherche dossiers dans "C:\DOCUME~1\Isabelle\applic~1" ***

          *** Recherche dossiers dans "C:\Documents and Settings\Stéphane\locals~1\applic~1" ***

          *** Recherche dossiers dans "C:\DOCUME~1\Isabelle\locals~1\applic~1" ***

          *** Recherche dossiers dans "C:\Documents and Settings\Stéphane\menudm~1\progra~1" ***

          *** Recherche dossiers dans "C:\DOCUME~1\Isabelle\menudm~1\progra~1" ***

          *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
          pour + d'infos : http://www.gmer.net

          *** Recherche avec GenericNaviSearch ***
          !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
          !!! A vérifier impérativement avant toute suppression manuelle !!!

          * Recherche dans "C:\WINDOWS\system32" *

          * Recherche dans "C:\Documents and Settings\Stéphane\locals~1\applic~1" *

          * Recherche dans "C:\DOCUME~1\Isabelle\locals~1\applic~1" *

          *** Recherche fichiers ***

          *** Recherche clés spécifiques dans le Registre ***

          *** Module de Recherche complémentaire ***
          (Recherche fichiers spécifiques)

          1)Recherche nouveaux fichiers Instant Access :

          2)Recherche Heuristique :

          * Dans "C:\WINDOWS\system32" :

          * Dans "C:\Documents and Settings\Stéphane\locals~1\applic~1" :

          * Dans "C:\DOCUME~1\Isabelle\locals~1\applic~1" :

          3)Recherche Certificats :

          Certificat Egroup absent !
          Certificat Electronic-Group absent !
          Certificat Montorgueil absent !
          Certificat OOO-Favorit absent !
          Certificat Sunny-Day-Design-Ltd absent !

          4)Recherche fichiers connus :

          *** Analyse terminée le 26/11/2008 à 11:15:55,64 ***
      4. Contributeur sécurité
        ok désolé j'avais pas vu que quelqu'un avait mis un autre rapport malwarebyte!!!

        vide ta corbeille

        et vire ce qui a été trouvé par malwarebyte

        C:\RECYCLER\S-1-5-21-1715567821-963894560-725345543-1004\Dc9­.exe
        C:\RECYCLER\S-1-5-21-1715567821-963894560-725345543-1004\Dc8\Clone DVD2 2.8.9.2\Clonedvd2 v2.8.9.2 crack by TFT-TEAM.exe

        puis

        Télécharge Combofix de sUBs : aide ici : https://forum.pcastuces.com/sujet.asp?f=25&s=37315

        http://download.bleepingcomputer.com/sUBs/ComboFix.exe
        Sauvegarde le sur ton bureau et pas ailleurs !

        Aide à l’utilisation de combofix ici: http://bibou0007.forumpro.fr/tutos-f45/tutorial-combofix-t12­1.htm

        Double-clic sur combofix, Il va te poser une question, réponds par la touche 1 et entrée pour valider, laisse toi guider.
        Attends que combofix ait terminé, un rapport sera créé. Poste le rapport.
        1. VOICI LE RAPPORT, je doit partir je continue ce soir merci et dis moi ce que t'en pense
          ComboFix 08-11-26.03 - Stéphane 2008-11-26 11:44:43.1 - NTFSx86
          Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.448 [GMT 1:00]
          Lancé depuis: c:\documents and settings\Stéphane\Bureau\ComboFix.exe
          * Un nouveau point de restauration a été créé
          * Resident AV is active

          .
          [i] ADS - WINDOWS: deleted 48 bytes in 1 streams. /i

          (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
          .

          c:\documents and settings\Isabelle\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
          c:\windows\system32\_004232_.tmp.dll
          c:\windows\system32\_004233_.tmp.dll
          c:\windows\system32\_004234_.tmp.dll
          c:\windows\system32\_004235_.tmp.dll
          c:\windows\system32\_004242_.tmp.dll
          c:\windows\system32\_004243_.tmp.dll
          c:\windows\system32\_004244_.tmp.dll
          c:\windows\system32\_004245_.tmp.dll
          c:\windows\system32\_004247_.tmp.dll
          c:\windows\system32\_004248_.tmp.dll
          c:\windows\system32\_004249_.tmp.dll
          c:\windows\system32\_004250_.tmp.dll
          c:\windows\system32\_004251_.tmp.dll
          c:\windows\system32\_004252_.tmp.dll
          c:\windows\system32\_004253_.tmp.dll
          c:\windows\system32\_004254_.tmp.dll
          c:\windows\system32\_004255_.tmp.dll
          c:\windows\system32\_004256_.tmp.dll
          c:\windows\system32\_004257_.tmp.dll
          c:\windows\system32\_004258_.tmp.dll
          c:\windows\system32\_004261_.tmp.dll
          c:\windows\system32\_004262_.tmp.dll
          c:\windows\system32\_004266_.tmp.dll
          c:\windows\system32\_004267_.tmp.dll
          c:\windows\system32\_004269_.tmp.dll
          c:\windows\system32\_004270_.tmp.dll
          c:\windows\system32\_004271_.tmp.dll
          c:\windows\system32\_004272_.tmp.dll
          c:\windows\system32\_004273_.tmp.dll
          c:\windows\system32\_004274_.tmp.dll
          c:\windows\system32\_004275_.tmp.dll
          c:\windows\system32\_004276_.tmp.dll
          c:\windows\system32\_004277_.tmp.dll
          c:\windows\system32\_004278_.tmp.dll
          c:\windows\system32\_004279_.tmp.dll
          c:\windows\system32\_004281_.tmp.dll
          c:\windows\system32\_004282_.tmp.dll
          c:\windows\system32\_004283_.tmp.dll
          c:\windows\system32\_004284_.tmp.dll
          c:\windows\system32\_004285_.tmp.dll
          c:\windows\system32\_004286_.tmp.dll
          c:\windows\system32\_004287_.tmp.dll
          c:\windows\system32\_004290_.tmp.dll
          c:\windows\system32\_004291_.tmp.dll
          c:\windows\system32\_004292_.tmp.dll
          c:\windows\system32\_004293_.tmp.dll
          c:\windows\system32\_004295_.tmp.dll
          c:\windows\system32\_004296_.tmp.dll
          c:\windows\system32\_004297_.tmp.dll
          c:\windows\system32\_004299_.tmp.dll
          c:\windows\system32\_004302_.tmp.dll
          c:\windows\system32\_004303_.tmp.dll
          c:\windows\system32\_004307_.tmp.dll
          c:\windows\system32\_004308_.tmp.dll
          c:\windows\system32\_004310_.tmp.dll
          c:\windows\system32\_004312_.tmp.dll
          c:\windows\system32\_004313_.tmp.dll
          c:\windows\system32\_004315_.tmp.dll
          c:\windows\system32\_004316_.tmp.dll
          c:\windows\system32\_004317_.tmp.dll
          c:\windows\system32\_004318_.tmp.dll
          c:\windows\system32\_004321_.tmp.dll
          c:\windows\system32\_004322_.tmp.dll
          c:\windows\system32\_004323_.tmp.dll
          c:\windows\system32\_004324_.tmp.dll
          c:\windows\system32\_004325_.tmp.dll
          c:\windows\system32\_004330_.tmp.dll
          c:\windows\system32\_004332_.tmp.dll

          .
          ((((((((((((((((((((((((((((( Fichiers créés du 2008-10-26 au 2008-11-26 ))))))))))))))))))))))))))))))))))))
          .

          2008-11-26 11:02 . 2008-11-26 11:16 <REP> d-------- c:\program files\Navilog1
          2008-11-26 01:45 . 2008-11-26 08:35 <REP> d-------- c:\documents and settings\All Users\Application Data\NOS
          2008-11-26 01:44 . 2008-11-26 08:35 <REP> d-------- c:\program files\NOS
          2008-11-26 01:26 . 2008-11-26 01:25 410,976 --a------ c:\windows\system32\deploytk.dll
          2008-11-26 00:42 . 2008-11-26 00:42 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
          2008-11-26 00:42 . 2008-11-26 00:42 <REP> d-------- c:\documents and settings\Stéphane\Application Data\Malwarebytes
          2008-11-26 00:42 . 2008-11-26 00:42 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
          2008-11-26 00:42 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
          2008-11-26 00:42 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
          2008-11-25 21:49 . 2008-11-25 21:50 <REP> d-------- C:\rsit
          2008-11-25 21:49 . 2008-11-25 21:50 <REP> d-------- c:\program files\trend micro
          2008-11-22 21:53 . 2008-11-22 21:53 <REP> d-------- c:\documents and settings\All Users\Application Data\Elaborate Bytes
          2008-11-22 21:52 . 2008-11-22 21:52 <REP> d-------- c:\program files\Elaborate Bytes
          2008-11-16 21:13 . 2008-11-16 21:13 <REP> d-------- c:\documents and settings\Stéphane\Application Data\Leadertech
          2008-11-10 14:36 . 2008-11-10 14:36 <REP> d--h----- c:\windows\PIF
          2008-11-09 14:05 . 2008-11-09 14:05 <REP> d-------- c:\documents and settings\Stéphane\Application Data\AdobeUM
          2008-11-09 13:42 . 2008-11-09 13:42 <REP> d-------- c:\windows\Easy CD-DA Extractor 12
          2008-11-09 13:42 . 2008-11-09 13:42 <REP> d-------- c:\program files\Easy CD-DA Extractor 12
          2008-11-09 13:42 . 2008-11-12 10:41 <REP> d-a------ c:\documents and settings\All Users\Application Data\TEMP
          2008-11-09 13:42 . 2008-11-09 13:42 <REP> d-------- c:\documents and settings\All Users\Application Data\Easy CD-DA Extractor
          2008-11-09 12:45 . 2008-11-09 12:45 <REP> d-------- c:\program files\Free Audio Pack

          .
          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          2008-11-26 10:52 --------- d-----w c:\documents and settings\Stéphane\Application Data\OpenOffice.org2
          2008-11-26 10:51 81,984 ----a-w c:\windows\system32\bdod.bin
          2008-11-26 09:47 --------- d-----w c:\program files\eMule
          2008-11-26 00:51 --------- d-----w c:\program files\Fichiers communs\Adobe
          2008-11-26 00:35 --------- d-----w c:\documents and settings\Isabelle\Application Data\OpenOffice.org2
          2008-11-26 00:25 --------- d-----w c:\program files\Java
          2008-11-23 12:39 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
          2008-11-23 12:28 --------- d-----w c:\program files\Spybot - Search & Destroy
          2008-11-12 09:42 --------- d-----w c:\documents and settings\All Users\Application Data\Skype
          2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
          2008-10-22 16:58 --------- d-----w c:\program files\HP
          2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
          2008-09-24 19:33 484,352 ----a-w c:\windows\system32\lame_enc.dll
          2008-09-15 15:39 1,846,144 ----a-w c:\windows\system32\win32k.sys
          2008-09-15 15:39 1,846,144 ----a-w c:\windows\system32\dllcache\win32k.sys
          2008-09-04 16:45 1,106,944 ----a-w c:\windows\system32\msxml3.dll
          2008-08-28 10:04 333,056 ----a-w c:\windows\system32\dllcache\srv.sys
          2008-04-23 12:38 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
          .

          ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          .
          *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
          REGEDIT4

          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2006-03-02 15360]
          "SuperCopier2.exe"="c:\program files\SuperCopier2\SuperCopier2.exe" [2005-03-14 1057280]
          "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2006-06-01 94208]
          "MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
          "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "SW20"="c:\windows\system32\sw20.exe" [2006-05-18 208896]
          "SW24"="c:\windows\system32\sw24.exe" [2006-05-17 69632]
          "BDAgent"="c:\program files\BitDefender\BitDefender 2008\bdagent.exe" [2008-09-17 368640]
          "type32"="c:\program files\Microsoft IntelliType Pro\type32.exe" [2005-03-15 196608]
          "IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2005-03-24 217088]
          "NeroFilterCheck"="c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
          "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-06-28 32768]
          "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
          "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-26 136600]
          "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
          "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-06-01 7618560]
          "NvMediaCenter"="NvMCTray.dll" [2006-06-01 c:\windows\system32\nvmctray.dll]
          "RTHDCPL"="RTHDCPL.EXE" [2006-04-04 c:\windows\RTHDCPL.EXE]
          "BluetoothAuthenticationAgent"="bthprops.cpl" [2006-03-02 c:\windows\system32\bthprops.cpl]
          "nwiz"="nwiz.exe" [2006-06-01 c:\windows\system32\nwiz.exe]

          [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
          "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-03-02 15360]

          c:\documents and settings\Isabelle\Menu D‚marrer\Programmes\D‚marrage\
          OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 393216]

          c:\documents and settings\St‚phane\Menu D‚marrer\Programmes\D‚marrage\
          OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 393216]

          c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
          HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-12-15 282624]

          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
          "VIDC.X264"= x264vfw.dll
          "VIDC.3iv2"= 3ivxVfWCodec.dll

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
          "EnableFirewall"= 0 (0x0)

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
          "%windir%\\system32\\sessmgr.exe"=
          "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
          "c:\\Program Files\\eMule\\emule.exe"=
          "c:\\Program Files\\Messenger\\msmsgs.exe"=
          "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
          "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
          "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
          "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
          "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
          "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
          "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
          "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
          "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
          "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
          "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
          "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
          "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
          "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
          "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=

          R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\bdfndisf.sys [2007-07-30 86792]

          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
          bdx REG_MULTI_SZ scan

          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{caaa39ca-30a4-11dd-bcc5-001617714e61}]
          \Shell\AutoRun\command - EXPLORER.EXE
          \Shell\explore\Command - EXPLORER.EXE
          \Shell\open\Command - EXPLORER.EXE
          .
          - - - - ORPHELINS SUPPRIMES - - - -

          HKLM-Run-NWEReboot - (no file)
          Notify-dimsntfy - (no file)

          .
          ------- Examen supplémentaire -------
          .
          FireFox -: Profile - c:\documents and settings\Stéphane\Application Data\Mozilla\Firefox\Profiles\wh9bwm0l.default\
          FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
          FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://google.fr/
          FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npdeploytk.dll
          FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npjp2.dll
          FF -: plugin - c:\program files\Mozilla Firefox\plugins\npdeploytk.dll
          .

          **************************************************************************

          catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2008-11-26 11:52:22
          Windows 5.1.2600 Service Pack 2 NTFS

          Recherche de processus cachés ...

          Recherche d'éléments en démarrage automatique cachés ...

          Recherche de fichiers cachés ...

          Scan terminé avec succès
          Fichiers cachés: 0

          **************************************************************************

          [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bdfsfltr]
          "ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\

          [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bdfsfltr]
          "ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\

          [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
          "ImagePath"="\??\c:\docume~1\STPHAN~1\LOCALS~1\Temp\mc22.tmp"
          .
          ------------------------ Autres processus actifs ------------------------
          .
          c:\program files\Java\jre6\bin\jqs.exe
          c:\windows\system32\nvsvc32.exe
          c:\windows\system32\rundll32.exe
          c:\windows\system32\wdfmgr.exe
          c:\program files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
          c:\program files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
          c:\windows\system32\rundll32.exe
          c:\program files\BitDefender\BitDefender 2008\vsserv.exe
          c:\program files\OpenOffice.org 2.4\program\soffice.exe
          c:\program files\OpenOffice.org 2.4\program\soffice.bin
          c:\program files\HP\Digital Imaging\bin\hpqste08.exe
          .
          **************************************************************************
          .
          Heure de fin: 2008-11-26 11:55:46 - La machine a redémarré
          ComboFix-quarantined-files.txt 2008-11-26 10:55:42

          Avant-CF: 6 918 283 264 octets libres
          Après-CF: 7,601,422,336 octets libres

          WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
          [boot loader]
          timeout=2
          default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
          [operating systems]
          c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
          multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect

          249 --- E O F --- 2008-11-24 22:44:29
      5. Contributeur sécurité
        télécharge OTMoveIt

        http://oldtimer.geekstogo.com/OTMoveIt3.exe

        (de Old_Timer) sur ton Bureau.
        double-clique sur OTMoveIt.exe pour le lancer.
        copie la liste qui se trouve en citation ci-dessous,
        et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

        :services
        mchlnjDrv

        :reg
        [-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
        "ImagePath"="\??\c:\docume~1\STPHAN~1\LOCALS~1\Temp\mc22.tmp

        :files
        c:\docume~1\STPHAN~1\LOCALS~1\Temp\mc22.tmp
        C:\Windows\Temp\mc22.tmp

        :commands
        [purity]
        [emptytemp]
        [start explorer]

        clique sur MoveIt! pour lancer la suppression.
        le résultat apparaitra dans le cadre "Results".
        clique sur Exit pour fermer.
        poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

        il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.
        1. bonjour,
          j'espère que la journée n'a pas été trop dur!
          A mon tour,je vous poste le résultat.

          ========== SERVICES/DRIVERS ==========
          Unable to stop service mchlnjDrv .
          ========== REGISTRY ==========
          Registry key HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv\\ deleted successfully.
          HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv\\"ImagePath"|"\??\c:\docume~1\STPHAN~1\LOCALS~1\Temp\mc22.tmp /E : value set successfully!
          ========== FILES ==========
          File/Folder c:\docume~1\STPHAN~1\LOCALS~1\Temp\mc22.tmp not found.
          File/Folder C:\Windows\Temp\mc22.tmp not found.
          ========== COMMANDS ==========
          File delete failed. C:\DOCUME~1\STPHAN~1\LOCALS~1\Temp\hpodvd09.log scheduled to be deleted on reboot.
          File delete failed. C:\DOCUME~1\STPHAN~1\LOCALS~1\Temp\Perflib_Perfdata_a70.dat scheduled to be deleted on reboot.
          File delete failed. C:\DOCUME~1\STPHAN~1\LOCALS~1\Temp\~DF4FE8.tmp scheduled to be deleted on reboot.
          File delete failed. C:\DOCUME~1\STPHAN~1\LOCALS~1\Temp\~DF500A.tmp scheduled to be deleted on reboot.
          File delete failed. C:\DOCUME~1\STPHAN~1\LOCALS~1\Temp\~DF786E.tmp scheduled to be deleted on reboot.
          File delete failed. C:\DOCUME~1\STPHAN~1\LOCALS~1\Temp\~DF7886.tmp scheduled to be deleted on reboot.
          User's Temp folder emptied.
          User's Temporary Internet Files folder emptied.
          User's Internet Explorer cache folder emptied.
          Local Service Temp folder emptied.
          File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
          Local Service Temporary Internet Files folder emptied.
          File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_4e8.dat scheduled to be deleted on reboot.
          Windows Temp folder emptied.
          Java cache emptied.
          File delete failed. C:\Documents and Settings\Stéphane\Local Settings\Application Data\Mozilla\Firefox\Profiles\wh9bwm0l.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
          File delete failed. C:\Documents and Settings\Stéphane\Local Settings\Application Data\Mozilla\Firefox\Profiles\wh9bwm0l.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
          File delete failed. C:\Documents and Settings\Stéphane\Local Settings\Application Data\Mozilla\Firefox\Profiles\wh9bwm0l.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
          File delete failed. C:\Documents and Settings\Stéphane\Local Settings\Application Data\Mozilla\Firefox\Profiles\wh9bwm0l.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
          File delete failed. C:\Documents and Settings\Stéphane\Local Settings\Application Data\Mozilla\Firefox\Profiles\wh9bwm0l.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
          File delete failed. C:\Documents and Settings\Stéphane\Local Settings\Application Data\Mozilla\Firefox\Profiles\wh9bwm0l.default\XUL.mfl scheduled to be deleted on reboot.
          FireFox cache emptied.
          Temp folders emptied.
          Explorer started successfully

          OTMoveIt3 by OldTimer - Version 1.0.7.1 log created on 11262008_214430

          Files moved on Reboot...
          C:\DOCUME~1\STPHAN~1\LOCALS~1\Temp\hpodvd09.log moved successfully.
          File C:\DOCUME~1\STPHAN~1\LOCALS~1\Temp\Perflib_Perfdata_a70.dat not found!
          File C:\DOCUME~1\STPHAN~1\LOCALS~1\Temp\~DF4FE8.tmp not found!
          File C:\DOCUME~1\STPHAN~1\LOCALS~1\Temp\~DF500A.tmp not found!
          File C:\DOCUME~1\STPHAN~1\LOCALS~1\Temp\~DF786E.tmp not found!
          File C:\DOCUME~1\STPHAN~1\LOCALS~1\Temp\~DF7886.tmp not found!
          File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
          C:\WINDOWS\temp\Perflib_Perfdata_4e8.dat moved successfully.
          C:\Documents and Settings\Stéphane\Local Settings\Application Data\Mozilla\Firefox\Profiles\wh9bwm0l.default\Cache\_CACHE_001_ moved successfully.
          C:\Documents and Settings\Stéphane\Local Settings\Application Data\Mozilla\Firefox\Profiles\wh9bwm0l.default\Cache\_CACHE_002_ moved successfully.
          C:\Documents and Settings\Stéphane\Local Settings\Application Data\Mozilla\Firefox\Profiles\wh9bwm0l.default\Cache\_CACHE_003_ moved successfully.
          C:\Documents and Settings\Stéphane\Local Settings\Application Data\Mozilla\Firefox\Profiles\wh9bwm0l.default\Cache\_CACHE_MAP_ moved successfully.
          C:\Documents and Settings\Stéphane\Local Settings\Application Data\Mozilla\Firefox\Profiles\wh9bwm0l.default\urlclassifier3.sqlite moved successfully.
          C:\Documents and Settings\Stéphane\Local Settings\Application Data\Mozilla\Firefox\Profiles\wh9bwm0l.default\XUL.mfl moved successfully.
      6. Contributeur sécurité
        parfait

        Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
        http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
        Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
        • Redémarre ton ordinateur
        • Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
        • A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
        • Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
        • Choisis ton compte.
        Déroule la liste des instructions ci-dessous :
        • Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
        • Appuie sur Y pour commencer le processus de nettoyage.
        • Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
        • Appuie sur une touche pour redémarrer le PC.
        • Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
        • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
        • Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
        • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
        • Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum

        _____________

        puis
        remets un rapport RSIT et dis tes soucis

        ___________

        et par curiosité peux tu me dire pour quoi l'informaticien a changé tout ton matos? a cause de ce problème?
        1. desoler mais qu'es-ce que je fait du dossier qui c'est ouvert?
        2. [b]SDFix: Version 1.240 [/b]
          Run by St‚phane on 26/11/2008 at 23:25

          Microsoft Windows XP [version 5.1.2600]
          Running From: C:\SDFix

          [b]Checking Services [/b]:

          Restoring Default Security Values
          Restoring Default Hosts File

          Rebooting

          [b]Checking Files [/b]:

          No Trojan Files Found

          Removing Temp Files

          [b]ADS Check [/b]:

          C:\WINDOWS
          :184EC085164A85DE 48
          Total size: 48 bytes.
          WINDOWS: deleted 48 bytes in 1 streams.

          Checking for remaining Streams

          C:\WINDOWS
          No streams found.

          [b]Final Check [/b]:

          catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2008-11-26 23:30:40
          Windows 5.1.2600 Service Pack 2 NTFS

          scanning hidden processes ...

          scanning hidden services & system hive ...

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000a3a634c9b]
          [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\000a3a634c9b]

          scanning hidden registry entries ...

          scanning hidden files ...

          scan completed successfully
          hidden processes: 0
          hidden services: 0
          hidden files: 0

          [b]Remaining Services [/b]:

          Authorized Application Key Export:

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
          "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
          "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
          "C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
          "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
          "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Disabled:Windows Live Messenger (Phone)"
          "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
          "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
          "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
          "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
          "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
          "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
          "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
          "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
          "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
          "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
          "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
          "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe"
          "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
          "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
          "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
          "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
          "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

          [b]Remaining Files [/b]:

          [b]Files with Hidden Attributes [/b]:

          Wed 22 Oct 2008 949,072 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\advcheck.dll"
          Mon 15 Sep 2008 1,562,960 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDHelper.dll"
          Mon 7 Jul 2008 1,429,840 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
          Mon 7 Jul 2008 4,891,472 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
          Tue 16 Sep 2008 1,833,296 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
          Wed 22 Oct 2008 962,896 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\Tools.dll"

          [b]Finished![/b]
        3. cela faisais bien 2 mois que la mise à jour de windows ne voulais pas s'installer,et la elle ses exécuter jusqu'au bout. J'ai du autoriser plein de fenêtre de bitdefender et de spybot. Es-ce normal?
        4. @steff56la mise a jour a bien durer une demie heure,et je trouve que mon ordi marchais mieux, juste après le mode sans échec. j'espere ne pas avoir fait de bétise?
          a part ca ,qu'es ce que je fait de tout ce qu'il y a sur mon bureau et si j'en garde,quel est la fréquence d'utilisation?
          merci d'ance de répondre à mes questions
      7. Contributeur sécurité
        pour bitdefender et spybot c'est normal

        _____________

        remets un rapport RSIT et dis tes soucis

        ___________

        et par curiosité peux tu me dire pour quoi l'informaticien a changé tout ton matos? a cause de ce problème?
        1. et par curiosité peux tu me dire pour quoi l'informaticien a changé tout ton matos? a cause de ce problème?

          PS: Aucun informaticien n'a touché 0 mon pc c'était le poste d'une autre personne, je t'envoie le rapport RSIT suite à ma mise à jour de windows. J'espère que ça n'a pas foutu en l'air tous ce qu'on n'a fait!
          Une fois que l'on aura fini j'aimerai que tu me dise quoi garder ds mon bureau et comment on dois l'utiliser.
          Spybot - Search & Destroy. Navilog1. Malwarebytes' Anti-Malware .ComboFix.exe. RSIT.exe .OTMoveIt3.exe
          merci grand chef.

          Logfile of random's system information tool 1.04 (written by random/random)
          Run by Stéphane at 2008-11-27 22:32:55
          Microsoft Windows XP Édition familiale Service Pack 3
          System drive C: has 7 GB (7%) free of 97 GB
          Total RAM: 1023 MB (48% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 22:33:07, on 27/11/2008
          Platform: Windows XP SP3 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\csrss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Java\jre6\bin\jqs.exe
          C:\WINDOWS\system32\nvsvc32.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\wdfmgr.exe
          C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
          C:\WINDOWS\System32\alg.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\RunDLL32.exe
          C:\WINDOWS\RTHDCPL.EXE
          C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
          C:\Program Files\Microsoft IntelliType Pro\type32.exe
          C:\Program Files\Microsoft IntelliPoint\point32.exe
          C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
          C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
          C:\Program Files\Java\jre6\bin\jusched.exe
          C:\WINDOWS\system32\rundll32.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\SuperCopier2\SuperCopier2.exe
          C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
          C:\Program Files\Messenger\msmsgs.exe
          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
          C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
          C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
          C:\Program Files\Windows Live\Messenger\usnsvc.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\eMule\emule.exe
          C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
          C:\WINDOWS\system32\csrss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\RunDLL32.exe
          C:\WINDOWS\RTHDCPL.EXE
          C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
          C:\Program Files\Microsoft IntelliType Pro\type32.exe
          C:\Program Files\Microsoft IntelliPoint\point32.exe
          C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
          C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
          C:\Program Files\Java\jre6\bin\jusched.exe
          C:\WINDOWS\system32\rundll32.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Messenger\msmsgs.exe
          C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
          C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
          C:\WINDOWS\system32\HPZipm12.exe
          C:\Documents and Settings\Stéphane\Bureau\RSIT.exe
          C:\WINDOWS\system32\wbem\wmiprvse.exe
          C:\Program Files\trend micro\Stéphane.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://portail.free.fr/
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
          O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
          O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
          O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
          O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
          O4 - HKLM\..\Run: [SW20] C:\WINDOWS\system32\sw20.exe
          O4 - HKLM\..\Run: [SW24] C:\WINDOWS\system32\sw24.exe
          O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
          O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
          O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
          O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
          O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
          O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
          O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
          O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
          O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          O4 - HKUS\S-1-5-21-1715567821-963894560-725345543-1005\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Isabelle')
          O4 - HKUS\S-1-5-21-1715567821-963894560-725345543-1005\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe (User 'Isabelle')
          O4 - HKUS\S-1-5-21-1715567821-963894560-725345543-1005\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Isabelle')
          O4 - HKUS\S-1-5-21-1715567821-963894560-725345543-1005\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'Isabelle')
          O4 - HKUS\S-1-5-21-1715567821-963894560-725345543-1005\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" (User 'Isabelle')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - S-1-5-21-1715567821-963894560-725345543-1005 Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe (User 'Isabelle')
          O4 - S-1-5-21-1715567821-963894560-725345543-1005 User Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe (User 'Isabelle')
          O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
          O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
          O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
          O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
          O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
          O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
        2. ds ccleaner, je ne trouve pas l'option la case: effacer les fichiers de plus de 48 heures je continue quand meme le nettoyage?
      8. Contributeur sécurité
        ok parfait

        _____________

        mettre a jour internet explorer
        https://www.01net.com/telecharger/windows/Internet/navigateur/fiches/33081.html

        _____________

        utilise pour supprimer tes traces

        CCLEANER: (lance un nettoyage et répare 3 fois le registre) sans installer la barre yahoo
        (dans les options puis avancé :désactive la case: effacer les fichiers de plus de 48 heures)
        https://www.malekal.com/tutoriel-ccleaner/
        https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html
        ______________

        pour virer ce qui a été utilisé: et non utile:

        Télécharge ToolsCleaner sur ton bureau.
        --> http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
        # Clique sur Recherche et laisse le scan agir ...
        # Clique sur Suppression pour finaliser.
        # Tu peux, si tu le souhaites, te servir des Options facultatives.
        # Clique sur Quitter pour obtenir le rapport.
        # Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

        ps : pas besoin de m´envoyer le rapport si tout a ete supprimé

        garde ccleaner pour nettoyer tes traces de net tous les jours ou toutes les semaines

        et

        garde sypobt (désactive le tea timer: en allant dans MODE puis MODE AVANCE puis OUTILS puis RESIDENT car bitdefender fais déjà une analyse en temps réel)
        +/- malwarebyte en version gratuite

        mets a jour spybot et immunise toutes les semaines et scan avec les deux une fois par mois par exemple ou avant si tu as des soucis (pubs....)
        1. SUPER merci beaucoup de ton aide, il a l'air de bien carburer.
          ca me fait super plaisir. Toutes mes félicitations.<gras>

          </gras>1 dernier petit truck, combofix et toolsCleaner je supprime?
          la mise a jour windows internet exploreur 7 ne c'est pas mis à jour j'essayerai + tard.
          Bon courage pour la suite...et encore merci
        2. aprés l'installation de internet exploreur c'est fait toolscleaner.résultats:
          [ Rapport ToolsCleaner version 2.2.6 (par A.Rothstein & dj QUIOU) ]

          -->- Recherche:

          C:\Documents and Settings\Stéphane\Bureau\ComboFix.exe: trouvé !

          ---------------------------------
          -->- Suppression:

          C:\Documents and Settings\Stéphane\Bureau\ComboFix.exe: ERREUR DE SUPPRESSION !!
      9. Contributeur sécurité
        ok tu vire dans ce cas manuellement combofix

        bonne suite
        1. je vire aussi toolsclearner ou je peut m'en servir de tps en tps?
          bonne continuation a toi et merci de ton aide.
        2. a part ça mon problème est résolu
      10. Contributeur sécurité
        toolsclearner ou je peut m'en servir de tps en tps?

        tu vire tools cleaner