Espace disque qui diminue

Résolu
Bonjour,

mon disque dur est partitionné en 3 disques (C;D;E)
le problème se trouve sur le disque C , dont l'espace libre diminue de jours en jours (2 Go la semaine dernière , 140 Mo aujourd'hui sur 24,6 Go) de plus la présentation du poste de travail a changé , il n'y a plus la séparation dossiers en tre les "documents" "disques durs" et "disque durs amovibles"
il y a 10 jours , mon fils a téléchargé un jeux pour jouer en ligne à WoW sur un serveur "privé" mais a tout désinstallé ensuite , je ne sais pas si ça a un rapport mais apparemment c'est depuis que j'ai le problème
j'ai voulu faire une restauration système , mais je n'ai pas de point de restauration au mois de mai (sauf 1 le 30) et pas accès au mois d'avril .
est-ce que quelqu'un a une soution , s'agit t'il d'un virus ? (j'ai antivir )
merci d'avance @+

--
pas très douée en informatique; mais je me soigne...
Configuration: windows xp internet explorer 6.0

23 réponses

Résumé de la discussion

Le fil décrit une diminution rapide de l'espace libre sur le disque C (2 Go la semaine dernière puis 140 Mo sur 24,6 Go), avec une réorganisation apparente du poste de travail. Des éléments suggèrent une infection potentielle liée à un téléchargement effectué par le fils, difficulté de restauration système et absence de points de réinitialisation, malgré l'antivirus actif. Plusieurs réponses proposent des actions techniques: suppression d'un dossier suspect et outils de nettoyage, puis analyse plus approfondie via hijackthis et VirusTotal pour identifier des barres d’outils et des composants malveillants. Enfin, les éléments recueillis pointent des modules publicitaires et des composants malveillants à supprimer, nécessitant une désinfection renforcée et une vérification approfondie du système et des points de restauration.

Bobot (l’IA à votre service)
  1. bonjour,
    ça y est apparemment tout est ok, l'espace est toujours là, je pense que ça venait des fichiers temporaires internet etc... mais comme il ne restait pas beaucoup de place je m'en rendais plus compte
    donc problème résolu, merci encore @+
    0
    1. apparemment il est stabilisé , mais je ne le saurai que dans 1 jours ou 2
      je te tiens au courant, encore merci de ta patience
      @+
      0
      1. ton espace disque diminue encore?
        0
        1. c'est chose faite
          ############################## [ UsbFix V3.028 | Cleaning ]

          # User : Emmanuelle (Administrateurs) # MAISON-2VQKWRVF
          # Update on 02/06/09 by Chiquitine29, C_XX & Chimay8
          # WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
          # Start at: 12:06:51 | 04/06/2009

          # AMD Athlon(tm) XP 2400+
          # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
          # Internet Explorer 6.0.2900.2180
          # Windows Firewall Status : Enabled
          # AV : AntiVir Desktop 9.0.1.26 [ Enabled | Updated ]

          # A:\ # Lecteur de disquettes 3 ½ pouces
          # C:\ # Disque fixe local # 24,65 Go (5,23 Go free) [Système] # NTFS
          # D:\ # Disque fixe local # 21,49 Go (1,36 Go free) [Nouveau nom] # NTFS
          # E:\ # Disque fixe local # 65,65 Go (30,43 Go free) [Emmanuelle] # NTFS
          # F:\ # Disque CD-ROM
          # G:\ # Disque CD-ROM
          # H:\ # Disque amovible # 1,9 Go (518,23 Mo free) # FAT32

          ############################## [ Processus actifs ]

          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\csrss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\logonui.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Avira\AntiVir Desktop\sched.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\userinit.exe
          C:\Program Files\Google\Update\GoogleUpdate.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Google\Update\GoogleUpdate.exe
          E:\PROGRAM FILES\A-SQUARED\a2service.exe
          C:\Program Files\Avira\AntiVir Desktop\avguard.exe
          C:\Program Files\Google\Update\GoogleUpdate.exe
          C:\Program Files\Java\jre6\bin\jqs.exe
          C:\Program Files\CyberLink\Shared Files\RichVideo.exe
          C:\Program Files\Google\Update\GoogleUpdate.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\wdfmgr.exe
          C:\WINDOWS\system32\UAService7.exe
          C:\WINDOWS\System32\wbem\wmiapsrv.exe
          C:\WINDOWS\System32\alg.exe
          C:\WINDOWS\system32\wbem\wmiprvse.exe
          C:\WINDOWS\system32\wbem\wmiprvse.exe
          C:\WINDOWS\system32\WgaTray.exe

          ################## [ Fichiers # Dossiers infectieux ]

          ################## [ Registre # Clés Run infectieuses ]

          ################## [ Registre # Mountpoints2 ]

          ################## [ Listing des fichiers présent ]

          [04/11/2008 17:08|--a--c---|20] - C:\ActiveX.log
          [25/11/2005 17:30|--a------|0] - C:\AUTOEXEC.BAT
          [03/01/2007 12:48|--a--c---|264] - C:\BDELog.txt
          [25/11/2005 17:48|--ahs----|212] - C:\boot.ini
          [30/08/2002 14:00|-rahs----|4952] - C:\Bootfont.bin
          [09/09/2008 08:04|--a--c---|3767] - C:\cleannavi.txt
          [25/11/2005 17:30|--a------|0] - C:\CONFIG.SYS
          [22/07/2007 13:52|--a--c---|0] - C:\conmgr.log
          [29/12/2005 20:17|-r-------|82] - C:\EDUFR1.BAT
          [09/09/2008 07:53|--a--c---|3752] - C:\fixnavi.txt
          [03/06/2009 16:31|--a------|523] - C:\hpfr3420.xml
          [03/06/2009 16:32|--a------|281377] - C:\hpfr3425.log
          [15/09/2006 10:38|--a--c---|100] - C:\index.ini
          [24/11/2008 17:59|--a--c---|1295] - C:\INSTALL.LOG
          [25/11/2005 17:30|-rahs----|0] - C:\IO.SYS
          [07/07/2007 14:38|--a--c---|1154] - C:\LEGO Creator Knights Kingdom Error Log_0.log
          [25/11/2005 17:30|-rahs----|0] - C:\MSDOS.SYS
          [25/11/2005 17:43|-rahs----|47564] - C:\NTDETECT.COM
          [25/11/2005 17:43|-rahs----|251712] - C:\ntldr
          [29/02/2004 17:44|--a--c---|52576] - C:\orange.bmp
          [?|?|?] - C:\pagefile.sys
          [21/05/2008 12:32|--a------|8320] - C:\playout.txt
          [16/12/2008 09:34|--a--c---|1308] - C:\resetlog.txt
          [29/01/2007 19:09|--ah-----|268] - C:\sqmdata00.sqm
          [28/02/2007 18:00|--ah-c---|268] - C:\sqmdata01.sqm
          [04/03/2007 20:54|--ah-c---|148] - C:\sqmdata02.sqm
          [04/03/2007 20:54|--ah-c---|136] - C:\sqmdata03.sqm
          [11/06/2007 17:49|--ah-c---|268] - C:\sqmdata04.sqm
          [01/07/2007 18:29|--ah-c---|268] - C:\sqmdata05.sqm
          [31/10/2007 11:44|--ah-c---|268] - C:\sqmdata06.sqm
          [31/10/2007 21:21|--ah-c---|268] - C:\sqmdata07.sqm
          [10/03/2008 19:28|--ah-c---|268] - C:\sqmdata08.sqm
          [16/05/2008 20:54|--ah-c---|232] - C:\sqmdata09.sqm
          [11/06/2008 11:16|--ah-c---|268] - C:\sqmdata10.sqm
          [13/12/2008 13:51|--ah-c---|268] - C:\sqmdata11.sqm
          [31/12/2008 15:44|--ah-c---|232] - C:\sqmdata12.sqm
          [19/11/2006 22:30|--ah-c---|268] - C:\sqmdata13.sqm
          [23/11/2006 18:31|--ah-c---|268] - C:\sqmdata14.sqm
          [28/11/2006 15:07|--ah-c---|268] - C:\sqmdata15.sqm
          [11/12/2006 09:22|--ah-c---|268] - C:\sqmdata16.sqm
          [25/12/2006 11:20|--ah-c---|268] - C:\sqmdata17.sqm
          [27/12/2006 10:59|--ah-c---|268] - C:\sqmdata18.sqm
          [29/01/2007 19:09|--ah-c---|268] - C:\sqmdata19.sqm
          [29/01/2007 19:09|--ah-----|136] - C:\sqmnoopt00.sqm
          [28/02/2007 18:00|--ah-c---|244] - C:\sqmnoopt01.sqm
          [04/03/2007 20:54|--ah-c---|244] - C:\sqmnoopt02.sqm
          [04/03/2007 20:54|--ah-c---|244] - C:\sqmnoopt03.sqm
          [04/03/2007 20:54|--ah-c---|136] - C:\sqmnoopt04.sqm
          [11/06/2007 17:49|--ah-c---|244] - C:\sqmnoopt05.sqm
          [01/07/2007 18:29|--ah-c---|244] - C:\sqmnoopt06.sqm
          [31/10/2007 11:44|--ah-c---|244] - C:\sqmnoopt07.sqm
          [31/10/2007 21:21|--ah-c---|244] - C:\sqmnoopt08.sqm
          [10/03/2008 19:28|--ah-c---|244] - C:\sqmnoopt09.sqm
          [16/05/2008 20:54|--ah-c---|244] - C:\sqmnoopt10.sqm
          [11/06/2008 11:16|--ah-c---|244] - C:\sqmnoopt11.sqm
          [13/12/2008 13:51|--ah-c---|244] - C:\sqmnoopt12.sqm
          [31/12/2008 15:44|--ah-c---|244] - C:\sqmnoopt13.sqm
          [23/11/2006 18:31|--ah-c---|244] - C:\sqmnoopt14.sqm
          [28/11/2006 15:07|--ah-c---|244] - C:\sqmnoopt15.sqm
          [11/12/2006 09:22|--ah-c---|244] - C:\sqmnoopt16.sqm
          [11/12/2006 09:22|--ah-c---|244] - C:\sqmnoopt17.sqm
          [25/12/2006 11:20|--ah-c---|244] - C:\sqmnoopt18.sqm
          [27/12/2006 10:59|--ah-c---|244] - C:\sqmnoopt19.sqm
          [03/06/2009 12:36|--a--c---|2442] - C:\TB.txt
          [10/01/2001 13:23|--a--c---|162304] - C:\UNWISE.EXE
          [04/06/2009 12:08|--a--c---|5797] - C:\UsbFix.txt
          [10/11/2001 22:52|--a------|10147] - D:\Air.mid
          [10/04/2006 03:21|--a------|98816] - D:\anvctrls.ocx
          [02/11/2006 05:29|--a------|114688] - D:\AnvilFlt.OCX
          [29/10/2003 12:59|--a------|43520] - D:\asUpgr.exe
          [11/11/2001 07:07|--a------|112] - D:\Autoplay.ply
          [17/06/2007 17:03|--a------|790278] - D:\D2P_1.3_FRA.exe
          [09/06/2005 05:46|--a------|29083] - D:\FugueGM.mid
          [02/09/2006 10:25|--a------|100] - D:\index.ini
          [28/12/2008 17:08|--a------|39424] - D:\jeux navigateur.doc
          [22/06/2002 13:03|--a------|3297] - D:\LoopDemo.mid
          [21/09/2001 14:57|--a------|20672] - D:\Loopo_a.wav
          [21/09/2001 15:07|--a------|37456] - D:\Loopo_b.wav
          [02/11/2006 13:07|--a------|552960] - D:\MidiCtl.ocx
          [10/11/2001 22:52|--a------|12070] - D:\Sonata-c.mid
          [26/09/2007 20:39|--a------|14145] - D:\ST5UNST.LOG
          [02/01/2006 10:14|--a------|3191488] - E:\a2freesetup.exe
          [29/12/2005 17:05|--a------|1202064] - E:\dvdaudioextractor.exe
          [29/12/2005 16:47|--a------|4082140] - E:\DVD_Player_5.0_XP.exe
          [07/11/2007 08:00|--a------|17734] - E:\eula.1028.txt
          [07/11/2007 08:00|--a------|17734] - E:\eula.1031.txt
          [07/11/2007 08:00|--a------|10134] - E:\eula.1033.txt
          [07/11/2007 08:00|--a------|17734] - E:\eula.1036.txt
          [07/11/2007 08:00|--a------|17734] - E:\eula.1040.txt
          [07/11/2007 08:00|--a------|118] - E:\eula.1041.txt
          [07/11/2007 08:00|--a------|17734] - E:\eula.1042.txt
          [07/11/2007 08:00|--a------|17734] - E:\eula.2052.txt
          [07/11/2007 08:00|--a------|17734] - E:\eula.3082.txt
          [07/11/2007 08:00|--a------|1110] - E:\globdata.ini
          [26/01/2007 11:09|--a------|7623680] - E:\harmonyFr.exe
          [11/12/2005 20:45|--a------|369152] - E:\Illusionsd_optique.pps
          [07/11/2007 08:00|--a------|843] - E:\install.ini
          [07/11/2007 08:03|--a------|76304] - E:\install.res.1028.dll
          [07/11/2007 08:03|--a------|96272] - E:\install.res.1031.dll
          [07/11/2007 08:03|--a------|91152] - E:\install.res.1033.dll
          [07/11/2007 08:03|--a------|97296] - E:\install.res.1036.dll
          [07/11/2007 08:03|--a------|95248] - E:\install.res.1040.dll
          [07/11/2007 08:03|--a------|81424] - E:\install.res.1041.dll
          [07/11/2007 08:03|--a------|79888] - E:\install.res.1042.dll
          [07/11/2007 08:03|--a------|75792] - E:\install.res.2052.dll
          [07/11/2007 08:03|--a------|96272] - E:\install.res.3082.dll
          [03/10/2006 09:27|--a------|31790221] - E:\k3d-all-in-one-setup-0.6.2.0.exe
          [17/10/2006 09:49|--a------|455168] - E:\loggiffy.exe
          [30/10/2008 18:33|--a------|4889180] - E:\LOMA_a7_win32.exe
          [16/12/2005 16:52|--a------|384000] - E:\maladiecontagieuse.pps
          [02/01/2006 10:20|--a------|8389040] - E:\Satsuki.Decoder.Pack.3.0.0.3.exe
          [29/12/2005 16:36|--a------|3058354] - E:\sudoku-extreme_sudoku_extreme_1.0_francais_18356.exe
          [29/12/2005 19:48|--a------|8295595] - E:\supertux_supertux_0.1.3_anglais_13403.zip
          [07/11/2007 08:00|--a------|5686] - E:\vcredist.bmp
          [07/11/2007 08:09|--a------|1442522] - E:\VC_RED.cab
          [07/11/2007 08:12|--a------|232960] - E:\VC_RED.MSI
          [12/01/2007 16:33|--a------|6927448] - E:\win9xm67.exe
          [31/10/2008 14:32|--a------|326656] - E:\YuLeech-bbo_fr_setup_0_1_exe.exe
          [02/10/2008 13:52|--ah-----|296] - H:\WMPInfo.xml
          [17/05/2006 19:30|--a------|559974] - H:\IMAG0104.JPG
          [23/07/2008 16:29|--a------|427545] - H:\IMAG1065.JPG
          [30/07/2008 19:37|--a------|460571] - H:\IMAG1069.JPG
          [31/07/2008 10:44|--a------|917230] - H:\IMAG1078.JPG
          [31/07/2008 19:21|--a------|663660] - H:\IMAG1101.JPG
          [01/08/2008 10:29|--a------|526383] - H:\IMAG1106.JPG
          [07/05/2006 11:32|--a------|515390] - H:\IMAG0025.JPG
          [07/05/2006 14:35|--a------|1061352] - H:\IMAG0037.JPG
          [10/05/2008 16:55|--a------|1091912] - H:\IMAG1034.JPG

          ################## [ Vaccination ]

          # C:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
          # D:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
          # E:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
          # H:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.

          ################## [ ! Fin du rapport # UsbFix V3.028 ! ]
          0
          1. bonjour,

            Branche tous tes disques amovibles susceptibles d’être contaminés (clée usb, disque dur externe, lecteur mp3) sans les ouvrir
            Relance UsbFix et fais l’option 2 suppression
            A la fin de la suppression tu auras un rapport, poste le dans ta prochaine réponse

            Relance UsbFix et fais l’option désinstaller
            0
            1. j'ai (enfin) passé usbfix
              ############################## [ UsbFix V3.028 | Scan ]

              # User : Emmanuelle (Administrateurs) # MAISON-2VQKWRVF
              # Update on 02/06/09 by Chiquitine29, C_XX & Chimay8
              # WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
              # Start at: 07:31:52 | 04/06/2009

              # AMD Athlon(tm) XP 2400+
              # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
              # Internet Explorer 6.0.2900.2180
              # Windows Firewall Status : Enabled
              # AV : AntiVir Desktop 9.0.1.26 [ Enabled | Updated ]

              # A:\ # Lecteur de disquettes 3 ½ pouces
              # C:\ # Disque fixe local # 24,65 Go (5,16 Go free) [Système] # NTFS
              # D:\ # Disque fixe local # 21,49 Go (1,36 Go free) [Nouveau nom] # NTFS
              # E:\ # Disque fixe local # 65,65 Go (30,43 Go free) [Emmanuelle] # NTFS
              # F:\ # Disque CD-ROM
              # G:\ # Disque CD-ROM
              # H:\ # Disque amovible # 1,9 Go (518,23 Mo free) # FAT32

              ############################## [ Processus actifs ]

              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\csrss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Avira\AntiVir Desktop\sched.exe
              C:\WINDOWS\System32\svchost.exe
              E:\PROGRAM FILES\A-SQUARED\a2service.exe
              C:\Program Files\Avira\AntiVir Desktop\avguard.exe
              C:\Program Files\Java\jre6\bin\jqs.exe
              C:\Program Files\Google\Update\GoogleUpdate.exe
              C:\Program Files\CyberLink\Shared Files\RichVideo.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\wdfmgr.exe
              C:\WINDOWS\system32\UAService7.exe
              C:\WINDOWS\System32\wbem\wmiapsrv.exe
              C:\WINDOWS\System32\alg.exe
              C:\WINDOWS\system32\wbem\wmiprvse.exe
              C:\WINDOWS\system32\WgaTray.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\SOUNDMAN.EXE
              D:\Program Files\QuickTime\qttask.exe
              E:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
              C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
              C:\Program Files\Java\jre6\bin\jusched.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Messenger\msmsgs.exe
              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              E:\Program Files\Microsoft ActiveSync\wcescomm.exe
              C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
              E:\PROGRA~1\MI3AA1~1\rapimgr.exe
              C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
              C:\WINDOWS\system32\ntvdm.exe
              C:\WINDOWS\system32\ntvdm.exe
              C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
              C:\Program Files\Sun\StarOffice 8\program\soffice.exe
              C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
              C:\Program Files\Sun\StarOffice 8\program\soffice.BIN
              E:\Program Files\IncrediMail\bin\IMApp.exe
              E:\Program Files\IncrediMail\bin\IncMail.exe
              C:\WINDOWS\system32\wbem\wmiprvse.exe
              C:\WINDOWS\SYSTEM32\WOWEXEC.EXE

              ################## [ Registre Startup ]

              HKCU_Main: "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
              HKCU_Main: "Search Page"="https://www.google.com/?gws_rd=ssl"
              HKCU_Main: "Start Page"="https://www.lci.fr/"
              HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
              HKLM_logon: "DefaultUserName"="Emmanuelle"
              HKLM_logon: "AltDefaultUserName"="Emmanuelle"
              HKLM_logon: "LegalNoticeCaption"=""
              HKLM_logon: "LegalNoticeText"=""
              HKLM_Run: NeroFilterCheck=C:\WINDOWS\system32\NeroCheck.exe
              HKLM_Run: SoundMan=SOUNDMAN.EXE
              HKLM_Run: DXM6Patch_981116=C:\WINDOWS\p_981116.exe /Q:A
              HKLM_Run: QuickTime Task="D:\Program Files\QuickTime\qttask.exe" -atboottime
              HKLM_Run: Sony Ericsson PC Suite="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
              HKLM_Run: Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
              HKLM_Run: RemoteControl="E:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
              HKLM_Run: LanguageShortcut="E:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
              HKLM_Run: avgnt="C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
              HKLM_Run: TkBellExe="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
              HKLM_Run: SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
              HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
              HKCU_Run: CTFMON.EXE=C:\WINDOWS\system32\ctfmon.exe
              HKCU_Run: MSMSGS="C:\Program Files\Messenger\msmsgs.exe" /background
              HKCU_Run: IncrediMail=E:\Program Files\IncrediMail\bin\IncMail.exe /c
              HKCU_Run: NBJ="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
              HKCU_Run: swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              HKCU_Run: H/PC Connection Agent="E:\Program Files\Microsoft ActiveSync\wcescomm.exe"
              HKCU_Run: Power2GoExpress=

              ################## [ Fichiers # Dossiers infectieux ]

              Found ! E:\install.exe

              ################## [ Registre # Clés Run infectieuses ]

              ################## [ Registre # Mountpoints2 ]

              HKCU\...\Explorer\MountPoints2\{dfdf793e-0618-11dc-b359-000e9b797b8f}\Shell\AutoRun\Command

              ################## [ ! Fin du rapport # UsbFix V3.028 ! ]

              0
              1. bonjour,

                Télécharges UsbFix de chiquitine29 :
                http://sd-1.archive-host.com/membres/up/127028005715545653/UsbFix.exe
                http://pagesperso-orange.fr/NosTools/usbfix.html

                Ce programme sert pour les infections qui se propagent par les disques amovibles
                Branche tous tes disques amovibles susceptibles d’être contaminés (clée usb, disque dur externe, lecteur mp3) sans les ouvrir

                Installes-le et fais l’option 1 recherche
                Laisses le travailler, il voudra surement redémarrer, acceptes
                Un rapport va apparaitre, poste son contenue dans ta prochaine réponse
                Voici une aide pour l’utiliser : https://www.malekal.com/usbfix-supprimer-virus-usb/
                0
                1. bonjour,
                  rapport après "suppression"
                  -----------\\ ToolBar S&D 1.2.8 XP/Vista

                  Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
                  X86-based PC ( Uniprocessor Free : AMD Athlon(tm) XP 2400+ )
                  BIOS : BIOS Date: 08/13/03 17:16:52 Ver: 08.00.08
                  USER : Emmanuelle ( Administrator )
                  BOOT : Normal boot
                  Antivirus : AntiVir Desktop 9.0.1.26 (Activated)
                  A:\ (USB)
                  C:\ (Local Disk) - NTFS - Total:24 Go (Free:5 Go)
                  D:\ (Local Disk) - NTFS - Total:21 Go (Free:1 Go)
                  E:\ (Local Disk) - NTFS - Total:65 Go (Free:30 Go)
                  F:\ (CD or DVD)
                  G:\ (CD or DVD)
                  H:\ (USB)
                  I:\ (USB)
                  J:\ (USB)
                  K:\ (USB)

                  "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
                  Option : [2] ( 03/06/2009|12:34 )

                  -----------\\ SUPPRESSION

                  Supprime! - C:\DOCUME~1\EMMANU~1\Favoris\France Torrent Search 2007 - ici Tous les liens torrent fr 2007 sur un seul site ! Tracker torrent Public.url

                  -----------\\ Recherche de Fichiers / Dossiers ...

                  -----------\\ Extensions

                  (Cl‚ment) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar

                  (Emmanuelle) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar

                  -----------\\ [..\Internet Explorer\Main]

                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                  "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
                  "Start Page"="https://www.lci.fr/"
                  "Search Page"="https://www.google.com/?gws_rd=ssl"
                  "Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                  "Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
                  "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                  "Start Page"="https://www.msn.com/fr-fr/"

                  --------------------\\ Recherche d'autres infections

                  --------------------\\ Cracks & Keygens ..

                  C:\DOCUME~1\EMMANU~1\Favoris\divers\ds\Nintendo DS ¯ Telechargement Gratuit T‚l‚charger gratuitement Films Music mp3 jeux PC livres magazines logiciels crack sur rapi.url
                  C:\DOCUME~1\EMMANU~1\Local Settings\Application Data\IM\Notifier\cracking_up.imn
                  C:\DOCUME~1\EMMANU~1\Local Settings\Application Data\IM\Runtime\NotifierThumbnail\E02C28C0-38CB-4505-B0F1-B6A2D6625408\cracking_up_thumb.bmp

                  1 - "C:\ToolBar SD\TB_1.txt" - 02/06/2009|19:59 - Option : [1]
                  2 - "C:\ToolBar SD\TB_2.txt" - 03/06/2009|12:36 - Option : [2]

                  -----------\\ Fin du rapport a 12:36:58,79
                  0
                  1. Exécute Toolbar sd et lance option 2 suppression
                    Laisses le travailler, il voudra surement redémarrer, acceptes
                    Un rapport va apparaitre, poste son contenue dans ta prochaine réponse
                    0
                    1. il faut éviter les cracks car ce sont des sources à virus
                      Est tu prête à les perdre car si je veux regler ton pb, il faudra les supprimer?
                      0
                      1. voici le rapport de tolbarSD
                        -----------\\ ToolBar S&D 1.2.8 XP/Vista

                        Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
                        X86-based PC ( Uniprocessor Free : AMD Athlon(tm) XP 2400+ )
                        BIOS : BIOS Date: 08/13/03 17:16:52 Ver: 08.00.08
                        USER : Emmanuelle ( Administrator )
                        BOOT : Normal boot
                        Antivirus : AntiVir Desktop 9.0.1.26 (Activated)
                        A:\ (USB)
                        C:\ (Local Disk) - NTFS - Total:24 Go (Free:5 Go)
                        D:\ (Local Disk) - NTFS - Total:21 Go (Free:1 Go)
                        E:\ (Local Disk) - NTFS - Total:65 Go (Free:30 Go)
                        F:\ (CD or DVD)
                        G:\ (CD or DVD)
                        H:\ (USB)
                        I:\ (USB)
                        J:\ (USB)
                        K:\ (USB)

                        "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
                        Option : [1] ( 02/06/2009|19:57 )

                        -----------\\ Recherche de Fichiers / Dossiers ...

                        C:\DOCUME~1\EMMANU~1\Favoris\France Torrent Search 2007 - ici Tous les liens torrent fr 2007 sur un seul site ! Tracker torrent Public.url

                        -----------\\ Extensions

                        (Cl‚ment) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar

                        (Emmanuelle) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar

                        -----------\\ [..\Internet Explorer\Main]

                        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                        "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
                        "Start Page"="https://www.lci.fr/"
                        "Search Page"="https://www.google.com/?gws_rd=ssl"
                        "Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"

                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                        "Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
                        "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                        "Start Page"="https://fr.yahoo.com/"

                        --------------------\\ Recherche d'autres infections

                        --------------------\\ Cracks & Keygens ..

                        C:\DOCUME~1\EMMANU~1\Favoris\divers\ds\Nintendo DS ¯ Telechargement Gratuit T‚l‚charger gratuitement Films Music mp3 jeux PC livres magazines logiciels crack sur rapi.url
                        C:\DOCUME~1\EMMANU~1\Local Settings\Application Data\IM\Notifier\cracking_up.imn
                        C:\DOCUME~1\EMMANU~1\Local Settings\Application Data\IM\Runtime\NotifierThumbnail\E02C28C0-38CB-4505-B0F1-B6A2D6625408\cracking_up_thumb.bmp

                        1 - "C:\ToolBar SD\TB_1.txt" - 02/06/2009|19:59 - Option : [1]

                        -----------\\ Fin du rapport a 19:59:39,21

                        0
                        1. n'oublie pas le post 5 pour toolbarsd
                          0
                          1. après un scann complet avec antivir il a trouvé un virus ADSPY/Agent.1562 j'ai réparé j'espère que ça va être bon
                            0
                            1. non, ne marque pas resolu car tu as au moins une infection qu'on a pas encore corrigé et c'est peut-être la cause de ton espace perdu.
                              0
                              1. encore moi,
                                ccleaner a fini , j'ai fait ATF-cleaner qui m'a refait gagner 1Go , me voilà à plus de 5 Go sur mon lecteur C
                                pas encore fait toolbar sd , ce soir au demain mais je m'en occupe
                                merci beaucoup de ton aide ,je marque "résolu" en espérant que les chiffres ne vont pas retomber ...
                                0
                                1. Après que ccleaner ait fini ou s'il ne finit pas,
                                  fais ceci stp:

                                  Télécharge aft-cleaner par atribune :
                                  http://www.atribune.org/ccount/click.php?id=1

                                  Double-clique ATF-Cleaner.exe afin de lancer le programme.
                                  Sous l'onglet Main, choisis : Select All
                                  Clique sur le bouton Empty Selected
                                  Si tu utilises le navigateur Firefox :
                                  Clique Firefox au haut et choisis : Select All
                                  Clique le bouton Empty Selected
                                  NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.
                                  Si tu utilises le navigateur Opera :
                                  Clique Opera au haut et choisis : Select All
                                  Clique le bouton Empty Selected
                                  NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.
                                  Clique Exit, du menu principal, afin de fermer le programme.
                                  Pour obtenir du Support technique, double-clique l'adresse électronique située au bas de chacun des menus.

                                  puis n'oublie pas de faire toolbar sd (voir post 5)
                                  0
                                  1. bonjour,
                                    tu peux arrêter ccleaner et changer guttman 35 passages et mettre effacement normale du fichier, ça sera plus rapide.

                                    puis redis moi si ça continue à bloquer
                                    0
                                    1. bon en fait pendant que je faisais une recherche (y compris dans dossiers cachés) pour éventuellement supprimer ce dossier manuellement , ccleaner a avancé , là il prend son temps sur un autre fichier du même style (toujours ce fichu téléchargement de mon fils Grrr) donc je le laisse faire
                                      merci d'être aussi réactif
                                      je te tiens au courant @+
                                      0
                                  2. me revoilà
                                    je suis en train de passer ccleaner mais j'ai l'impression qu'il "bloque" sur un fichier (temporaire internet (.rar) est-ce normal ? ça doit faire 1H qu'il est dessus
                                    0
                                    • 1
                                    • 2