Au secour virus cheval de troie

Bonjour,

J'ai un gros soucis, dès que je me connecte un virus est détecté par mon antivirus Avira.

Je le mets donc en quarantaine mais il réapparait à chaque fois que je repard sur internet ou msn.

Aidez-moi s'il vous plait.

Merci beaucoup.
Configuration: Windows Vista Internet Explorer 7.0

24 réponses

Résumé de la discussion

Un problème de malware réapparaît après quarantaine dès que la connexion Internet débute, en particulier lors de l'accès à Internet et MSN, malgré l'action d'Avira sur Windows Vista et IE 7. Plusieurs réponses suggèrent d'utiliser des outils de nettoyage comme ComboFix et d'imprimer les rapports pour évaluer les éléments suspects, tout en désactivant temporairement l’antivirus et les anti-spywares pour ne pas gêner le scan. D'autres messages demandent le nom et le chemin du fichier suspect pour vérifier s'il s'agit d'un faux positif, et rapportent les éléments détectés, y compris des modifications de registres et des pilotes. Certains messages insistent sur l'identification précise des éléments suspects et précisent que des faux positifs ou des outils système peuvent influencer le diagnostic.

Bobot (l’IA à votre service)
  1. J'ai purgé mais je n'ai pas vérifié la mise à jour logiciel.

    Je suis en train de le faire, du moins je crois car c'est long et on ne m'a pas proposé de liens pour le moment, c'est peut-être normal?

    Merci encore

    Je te donne le résultat quand c'est terminé
    0
    1. C'est nickel, l'alerte virus n'apparait plus.

      Je te remercie du temps que tu m'a accordé, c'est vraiment sympa...
      0
      1. Re

        As tu appliqué ce qu'il t'est demandé dans le post précédent?
        0
    2. Et celui de log:

      Logfile of random's system information tool 1.06 (written by random/random)
      Run by Ezaier at 2009-07-09 19:17:20
      Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
      System drive C: has 53 GB (35%) free of 153 GB
      Total RAM: 958 MB (27% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 19:17:23, on 09/07/2009
      Platform: Windows Vista SP1 (WinNT 6.00.1905)
      MSIE: Internet Explorer v7.00 (7.00.6001.18248)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Windows\system32\taskeng.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
      C:\Program Files\Synaptics\SynTP\SynTPStart.exe
      C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
      C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Windows\System32\rundll32.exe
      C:\Program Files\HP\QuickPlay\QPService.exe
      C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
      C:\Program Files\Unlocker\UnlockerAssistant.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
      C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Users\Ezaier\Program Files\DNA\btdna.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\Internet Explorer\ieuser.exe
      C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
      C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
      C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
      C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
      C:\Windows\system32\SearchFilterHost.exe
      C:\Users\Ezaier\Desktop\RSIT.exe
      C:\Program Files\Trend Micro\HijackThis\Ezaier.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://fr.gdark.com
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.gdark.com
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      R3 - Default URLSearchHook is missing
      O1 - Hosts: ::1 localhost
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
      O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
      O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
      O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
      O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
      O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
      O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
      O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\Ezaier\Program Files\DNA\btdna.exe"
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
      O13 - Gopher Prefix:
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
      O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
      O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
      O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
      O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
      O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
      O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
      O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
      O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
      O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
      0
      1. Re

        1)Pour vérifier les mises à jour logiciels à appliquer sur ton PC
        https://www.flexera.com/products/operations/software-vulnerability-management.html
        Divers liens te seront proposés pour les logiciels non à jour.

        2)Purge la restauration sur Vista.
        Comment faire :

        http://www.pcinpact.com/astuces/windows-vista/241-vista-desactiver-restauration-systeme-points.html

        Ton PC se porte t-il mieux?

        @+
        0
    3. Et voici le rapport info texte de RSIT:

      info.txt logfile of random's system information tool 1.06 2009-07-09 19:17:29

      ======Uninstall list======

      -->C:\Program Files\Conexant\SmartAudio\SETUP.EXE -U -ISmartAudio -SM=SMAUDIO.EXE,1801
      -->C:\Program Files\Nero\Nero 7\\nero\uninstall\UNNERO.exe /UNINSTALL
      -->C:\Windows\UNNeroBackItUp.exe /UNINSTALL
      -->C:\Windows\UNNeroMediaHome.exe /UNINSTALL
      -->C:\Windows\UNNeroShowTime.exe /UNINSTALL
      -->C:\Windows\UNNeroVision.exe /UNINSTALL
      -->C:\Windows\UNRecode.exe /UNINSTALL
      32 Bit HP CIO Components Installer-->MsiExec.exe /I{2614F54E-A828-49FA-93BA-45A3F756BFAA}
      ActiveCheck component for HP Active Support Library-->MsiExec.exe /X{254C37AA-6B72-4300-84F6-98A82419187E}
      Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
      Adobe Reader 9.1.2 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A91000000001}
      Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
      Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
      AuthenTec Fingerprint Sensor Minimum Install-->MsiExec.exe /X{7F362F06-A9A3-440F-8B19-6A01A72723C4}
      Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE
      Broadcom 802.11 Wireless LAN Adapter-->"C:\Program Files\Broadcom\Broadcom 802.11\Driver\bcmwlu00.exe" verbose /rootkey="Software\Broadcom\802.11\UninstallInfo" /rootdir="C:\Program Files\Broadcom\Broadcom 802.11\Driver"
      CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
      Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
      Conexant HD Audio-->C:\Program Files\CONEXANT\CNXT_AUDIO_HDA\UIU32a.exe -U -IQv30CFza.INF
      ESU for Microsoft Vista-->MsiExec.exe /I{AD3FDC40-BCF4-476D-A2D6-C4B154DD9DF5}
      Galerie de photos Windows Live-->MsiExec.exe /X{44E54A81-9D91-4AA1-9417-80AFF134F5FF}
      Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_9DE96A29E721D90A.exe" /uninstall
      Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
      Hauppauge MCE XP/Vista Software Encoder (2.0.25149)-->C:\PROGRA~1\WinTV\UNSftMCE.EXE C:\PROGRA~1\WinTV\softMCE.LOG
      HDAUDIO Soft Data Fax Modem with SmartCP-->C:\Program Files\CONEXANT\CNXT_MODEM_HDA_HSF\UIU32m.exe -U -IwqcVenz.inf
      HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
      HP Active Support Library-->"C:\Program Files\InstallShield Installation Information\{0295F89F-F698-4101-9A7D-49F407EC2D82}\setup.exe" -runfromtemp -l0x0409 -removeonly
      HP Customer Participation Program 8.0-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
      HP Deskjet All-In-One Software 8.0-->C:\Program Files\HP\Digital Imaging\{24557DC0-0839-496f-82F9-C4EB72EFE4FA}\setup\hpzscr01.exe -datfile hposcr12.dat
      HP Help and Support-->MsiExec.exe /I{0054A0F6-00C9-4498-B821-B5C9578F433E}
      HP Imaging Device Functions 8.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
      HP Photosmart Essential-->MsiExec.exe /X{EB21A812-671B-4D08-B974-2A347F0D8F70}
      HP Product Assistant-->MsiExec.exe /I{36FDBE6E-6684-462B-AE98-9A39A1B200CC}
      HP Quick Launch Buttons 6.40 H2-->C:\Program Files\InstallShield Installation Information\{34D2AB40-150D-475D-AE32-BD23FB5EE355}\Setup.exe -runfromtemp -l0x040c -removeonly uninst
      HP QuickPlay 3.2-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{45D707E9-F3C4-11D9-A373-0050BAE317E1}\Setup.exe" -uninstall
      HP Solution Center 8.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
      HP Update-->MsiExec.exe /X{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}
      HP Wireless Assistant-->MsiExec.exe /I{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}
      HPAsset component for HP Active Support Library-->MsiExec.exe /X{669D4A35-146B-4314-89F1-1AC3D7B88367}
      HPNetworkAssistant-->MsiExec.exe /I{228C6B46-64E2-404E-898A-EF0830603EF4}
      HPSSupply-->MsiExec.exe /X{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}
      Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
      Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
      Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
      LightScribe System Software 1.10.19.1-->MsiExec.exe /X{59046D29-2E6B-4224-BF0D-64F3E7A93F7B}
      Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
      Microsoft .NET Framework 3.5 SP1-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
      Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
      Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
      Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
      Microsoft Office InfoPath MUI (French) 2007-->MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}
      Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
      Microsoft Office Outlook Connector-->MsiExec.exe /I{95120000-0120-040C-0000-0000000FF1CE}
      Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
      Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
      Microsoft Office Professional Plus 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
      Microsoft Office Professional Plus 2007-->MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}
      Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
      Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
      Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
      Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
      Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
      Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
      Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
      Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
      Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
      Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
      Microsoft Search Enhancement Pack-->MsiExec.exe /X{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
      Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
      Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
      Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
      Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
      Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
      Mise à jour Microsoft Office Outlook 2007 Help (KB963677)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {51EFB347-1F3D-4BAC-8B79-F056B904FE21}
      Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
      Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
      MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
      MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
      Nero 7 Ultra Edition-->MsiExec.exe /X{A20A58C4-6784-4B4B-86CC-94E2E3671036}
      neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
      NetWaiting-->C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\setup.exe -runfromtemp -l0x040c -removeonly
      NVIDIA Drivers-->C:\Windows\system32\NVUNINST.EXE UninstallGUI
      Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
      RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{59F6A514-9813-47A3-948C-8A155460CC2A}\setup.exe" -l0x40c anything
      Security Update for 2007 Microsoft Office System (KB951550)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {B243E9A5-ED77-4F1B-B338-2486FD82DC85}
      Security Update for 2007 Microsoft Office System (KB951944)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
      Security Update for 2007 Microsoft Office System (KB960003)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {F04F8702-18D0-458D-921E-146FB7CD38CF}
      Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
      Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
      Security Update for Microsoft Office Excel 2007 (KB959997)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {9EAC3AEC-5C81-4856-A05B-DE9DC236D740}
      Security Update for Microsoft Office PowerPoint 2007 (KB951338)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {558B709B-821B-4FC5-90FC-9A8890641E77}
      Security Update for Microsoft Office Publisher 2007 (KB950114)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {F9C3CDBA-1F00-4D4D-959D-75C9D3ACDD85}
      Security Update for Microsoft Office system 2007 (KB954326)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F}
      Security Update for Microsoft Office system 2007 (KB956828)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {885E081B-72BD-4E76-8E98-30B4BE468FAC}
      Security Update for Microsoft Office Word 2007 (KB956358)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {4551666D-0FD6-4C69-8A81-1C6F2E64517C}
      Security Update for Outlook 2007 (KB946983)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {66B9496E-C0C3-4065-9868-85CCA92126C3}
      Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
      Unlocker 1.8.7-->C:\Program Files\Unlocker\uninst.exe
      Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
      Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
      Update for Office 2007 (KB934391)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {B3091818-7C56-4C45-BE7D-CA23027A5EA5}
      Update for Outlook 2007 Junk Email Filter (kb970012)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {DC4A962B-9EC2-469C-BC9C-87312ADAEE81}
      VLC 0.9.8-->"C:\Program Files\VLC\unins000.exe"
      VLC media player 0.9.8a-->C:\Program Files\VideoLAN\VLC\uninstall.exe
      Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
      Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
      Windows Live Contrôle parental-->MsiExec.exe /X{D6A2DDE3-9D7C-412C-932A-756580D29919}
      Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
      Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
      Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
      Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
      Windows Live Writer-->MsiExec.exe /X{2231CE39-B963-4B9D-823A-F412ECA637B1}

      ======Security center information======

      AS: Windows Defender

      ======System event log======

      Computer Name: PC-de-Ezaier
      Event Code: 7000
      Message: Le service Parallel port driver n'a pas pu démarrer en raison de l'erreur :
      Le service ne peut pas être démarré parce qu'il est désactivé ou qu'aucun périphérique activé ne lui est associé.
      Record Number: 22825
      Source Name: Service Control Manager
      Time Written: 20090709171046.000000-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-Ezaier
      Event Code: 7022
      Message: Le service CyberLink Background Capture Service (CBCS) est en attente de démarrage.
      Record Number: 22865
      Source Name: Service Control Manager
      Time Written: 20090709171108.000000-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-Ezaier
      Event Code: 7022
      Message: Le service Service HP CUE DeviceDiscovery est en attente de démarrage.
      Record Number: 22866
      Source Name: Service Control Manager
      Time Written: 20090709171108.000000-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-Ezaier
      Event Code: 7001
      Message: Le service CyberLink Task Scheduler (CTS) dépend du service CyberLink Background Capture Service (CBCS) qui n'a pas pu démarrer en raison de l'erreur :
      Après démarrage, le service s'est arrêté dans un état d'attente.
      Record Number: 22868
      Source Name: Service Control Manager
      Time Written: 20090709171108.000000-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-Ezaier
      Event Code: 19
      Message: Une erreur matérielle corrigée s’est produite.

      Source de l’erreur : vérification d’ordinateur corrigée

      Type d’erreur : Erreur de bus/d’interconnexion

      ID du processeur valide : Oui
      ID du processeur : 0x1
      Numéro de banque : 1
      Type de transaction : N/A
      Participation du processeur : Le nœud local a répondu à la demande.
      Type de demande : Prérécupération
      Mémoire-E/S : Générique
      Niveau de hiérarchie mémoire : Générique
      Délai d’attente : Oui
      Record Number: 22877
      Source Name: Microsoft-Windows-WHEA-Logger
      Time Written: 20090709171110.842953-000
      Event Type: Avertissement
      User: AUTORITE NT\SERVICE LOCAL

      =====Application event log=====

      Computer Name: PC-de-Ezaier
      Event Code: 1000
      Message: Application défaillante findstr.exe, version 6.0.6001.18000, horodatage 0x47918ac0, module défaillant findstr.exe, version 6.0.6001.18000, horodatage 0x47918ac0, code d’exception 0xc0000005, décalage d’erreur 0x0000465d, ID du processus 0xd28, heure de début de l’application 0x01c9fff248f99b00.
      Record Number: 2035
      Source Name: Application Error
      Time Written: 20090708173759.000000-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-Ezaier
      Event Code: 1000
      Message: Application défaillante findstr.exe, version 6.0.6001.18000, horodatage 0x47918ac0, module défaillant findstr.exe, version 6.0.6001.18000, horodatage 0x47918ac0, code d’exception 0xc0000005, décalage d’erreur 0x00004677, ID du processus 0x7b0, heure de début de l’application 0x01c9fff2e121ff80.
      Record Number: 2036
      Source Name: Application Error
      Time Written: 20090708174215.000000-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-Ezaier
      Event Code: 10
      Message: Le filtre d’événement avec la requête « SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99 » n’a pas pu être réactivé dans l’espace de noms « //./root/CIMV2 » à cause de l’erreur 0x80041003. Les événements ne peuvent pas être délivrés à travers ce filtre tant que le problème ne sera pas corrigé.
      Record Number: 2077
      Source Name: Microsoft-Windows-WMI
      Time Written: 20090708183522.000000-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-Ezaier
      Event Code: 10
      Message: Le filtre d’événement avec la requête « SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99 » n’a pas pu être réactivé dans l’espace de noms « //./root/CIMV2 » à cause de l’erreur 0x80041003. Les événements ne peuvent pas être délivrés à travers ce filtre tant que le problème ne sera pas corrigé.
      Record Number: 2116
      Source Name: Microsoft-Windows-WMI
      Time Written: 20090708203552.000000-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-Ezaier
      Event Code: 10
      Message: Le filtre d’événement avec la requête « SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99 » n’a pas pu être réactivé dans l’espace de noms « //./root/CIMV2 » à cause de l’erreur 0x80041003. Les événements ne peuvent pas être délivrés à travers ce filtre tant que le problème ne sera pas corrigé.
      Record Number: 2149
      Source Name: Microsoft-Windows-WMI
      Time Written: 20090709171045.000000-000
      Event Type: Erreur
      User:

      =====Security event log=====

      Computer Name: PC-de-Ezaier
      Event Code: 5038
      Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

      Nom du fichier : \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
      Record Number: 2900
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20090709171723.204353-000
      Event Type: Échec de l'audit
      User:

      Computer Name: PC-de-Ezaier
      Event Code: 5038
      Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

      Nom du fichier : \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
      Record Number: 2901
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20090709171723.235553-000
      Event Type: Échec de l'audit
      User:

      Computer Name: PC-de-Ezaier
      Event Code: 5038
      Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

      Nom du fichier : \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
      Record Number: 2902
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20090709171723.266753-000
      Event Type: Échec de l'audit
      User:

      Computer Name: PC-de-Ezaier
      Event Code: 5038
      Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

      Nom du fichier : \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
      Record Number: 2903
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20090709171723.313553-000
      Event Type: Échec de l'audit
      User:

      Computer Name: PC-de-Ezaier
      Event Code: 5038
      Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

      Nom du fichier : \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
      Record Number: 2904
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20090709171723.344753-000
      Event Type: Échec de l'audit
      User:

      ======Environment variables======

      "ComSpec"=%SystemRoot%\system32\cmd.exe
      "FP_NO_HOST_CHECK"=NO
      "OS"=Windows_NT
      "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
      "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
      "PROCESSOR_ARCHITECTURE"=x86
      "TEMP"=%SystemRoot%\TEMP
      "TMP"=%SystemRoot%\TEMP
      "USERNAME"=SYSTEM
      "windir"=%SystemRoot%
      "PROCESSOR_LEVEL"=15
      "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 104 Stepping 1, AuthenticAMD
      "PROCESSOR_REVISION"=6801
      "NUMBER_OF_PROCESSORS"=2
      "TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
      "DFSTRACINGON"=FALSE

      -----------------EOF-----------------
      0
      1. Antivir a trouvé 2 virus que j'ai supprimé.

        Voici le rapport de Toolcleaner:

        [ Rapport ToolsCleaner version 2.3.7 (par A.Rothstein & dj QUIOU) ]

        --> Recherche:

        C:\Combofix.txt: trouvé !
        C:\TB.txt: trouvé !

        ---------------------------------
        --> Suppression:

        C:\Combofix.txt: supprimé !
        C:\TB.txt: supprimé !
        0
        1. Bonjour Guillaume,

          Merci pour ces infos, c'est bon j'ai fais ce que tu m'a dit.

          Dois-je faire autre chose ?
          Puis-je supprimer les programmes téléchargés de mon bureau ?

          Merci
          0
          1. Re

            Antivir n'a rien trouvé?

            1)Télécharges tools cleaner afin de supprimer les logiciels de désinfection inutiles

            ---> Télécharge Toolscleaner sur ton Bureau.
            http://www.commentcamarche.net/telecharger/telechargement 34055291 toolscleaner
            * Double-clique sur ToolsCleaner2.exe pour le lancer.
            * Clique sur Recherche et laisse le scan agir.
            * Clique sur Suppression pour finaliser.
            * Tu peux, si tu le souhaites, te servir des Options Facultatives.
            * Clique sur Quitter pour obtenir le rapport.
            * Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

            2)Purge la restauration sur Vista.
            Comment faire :

            http://www.pcinpact.com/astuces/windows-vista/241-vista-desactiver-restauration-systeme-points.html

            3)Reactive l'UAC(contrôle utilisateur)

            Comment se comporte ton PC?

            Une dernière verification.

            1- Télécharge et installe le logiciel HijackThis :

            http://www.commentcamarche.net/telecharger/telecharger 159 hijackthis
            ou ici http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe
            ou ici https://www.clubic.com/telecharger-fiche17891-hijackthis.html

            -->Clique sur le setup pour lancer l'installation : laisse toi guider et ne modifie pas les paramètres d'installation .
            A la fin de l’installation, le programme se lance automatiquement : ferme le en cliquant sur la croix rouge.
            Au final, tu dois avoir un raccourci sur ton bureau et aussi un cheminement comme :
            "C:\ program files\Trend Micro\HijackThis\HijackThis.exe " .

            (Ne lance pas ce prg pour l'instant et fais la suite ... )

            2- Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

            -> http://images.malwareremoval.com/random/RSIT.exe

            ! Déconnecte toi et ferme toutes tes applications en cours !

            Double-clique sur " RSIT.exe " pour le lancer.

            Clic droit sous VISTA (exécuter en tant que…)

            -> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

            * Devant l'option "List files/folders created ..." , tu choisis : 2 months

            * clique ensuite sur " Continue " pour lancer l'analyse ...

            -> laisse faire le scan et ne touche pas au PC ...

            Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-notes).

            Poste le contenu de " log.txt " (c'est celui qui apparaît à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

            Important : poste un rapport, puis l'autre dans la réponse suivante ...
            Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum ...
            ( Et si "log.txt" seul, ne passe pas non plus , fais le en 2 fois ... merci ... )

            ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )

            @+
            0
        2. Voici le rapport :

          Malwarebytes' Anti-Malware 1.38
          Version de la base de données: 2394
          Windows 6.0.6001 Service Pack 1

          08/07/2009 22:15:28
          mbam-log-2009-07-08 (22-15-28).txt

          Type de recherche: Examen complet (C:\|)
          Eléments examinés: 178436
          Temps écoulé: 40 minute(s), 19 second(s)

          Processus mémoire infecté(s): 0
          Module(s) mémoire infecté(s): 0
          Clé(s) du Registre infectée(s): 2
          Valeur(s) du Registre infectée(s): 0
          Elément(s) de données du Registre infecté(s): 0
          Dossier(s) infecté(s): 2
          Fichier(s) infecté(s): 4

          Processus mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Module(s) mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Clé(s) du Registre infectée(s):
          HKEY_CURRENT_USER\SOFTWARE\BlueRaTech (Trojan.DNSChanger) -> Quarantined and deleted successfully.
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BlueRaTech (Trojan.DNSChanger) -> Quarantined and deleted successfully.

          Valeur(s) du Registre infectée(s):
          (Aucun élément nuisible détecté)

          Elément(s) de données du Registre infecté(s):
          (Aucun élément nuisible détecté)

          Dossier(s) infecté(s):
          c:\Users\Ezaier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BlueRaTech (Trojan.DNSChanger) -> Quarantined and deleted successfully.
          C:\Program Files\BlueRaTech (Trojan.DNSChanger) -> Quarantined and deleted successfully.

          Fichier(s) infecté(s):
          c:\program files\blueratech\Uninstall.exe (Trojan.DNSChanger) -> Quarantined and deleted successfully.
          c:\program files\WinRAR\Patch.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
          c:\Qoobox\quarantine\C\Windows\System32\MSIVXpopnintxibpxvtniweeretjgcfbsavxp.dll.vir (Spyware.Agent) -> Quarantined and deleted successfully.
          c:\Users\Ezaier\AppData\Roaming\microsoft\Windows\start menu\Programs\blueratech\Uninstall.lnk (Trojan.DNSChanger) -> Quarantined and deleted successfully.

          Merci
          0
          1. Bonjour

            1)Un petit nettoyage avec ceci:
            C - Ccleaner :

            https://filehippo.com/download_ccleaner/

            .enregistres le sur le bureau
            .double-cliques ou clic droit sous vista sur le fichier pour lancer l'installation
            .sur la fenêtre de l'installation langage bien choisir français et OK
            .cliques sur suivant
            .lis la licence et j'accepte
            .cliques sur suivant
            .la tu ne gardes de coché que mettre un raccourci sur le bureau et puis contrôler automatiquement les mises à jour de Ccleaner
            .cliques sur installer
            .cliques sur fermer
            .double-cliques ou clic droit sous vista sur l'icône de Ccleaner pour l'ouvrir
            .une fois ouvert tu cliques sur option et puis avancé
            .tu décoches effacer uniquement les fichiers, du dossier temp de windows plus vieux que 48 heures
            .cliques sur nettoyeur
            .cliques sur windows et dans la colonne avancé
            .coches la première case vieilles données du perfetch ce qui te donnes la case vielles données du perfetch et la case avancé qui c'est coché automatiquement mais que celle-la
            .cliques sur analyse une fois l'analyse terminé
            .cliques sur lancer le nettoyage et sur la demande de confirmation OK il vas falloir que tu le refasses une autre fois une fois fini vérifies en appuyant de nouveau sur analyse pour être sur qu'il n'y est plus rien
            .clique maintenant sur registre et puis sur rechercher les erreurs
            .laisse tout coché et clique sur réparer les erreurs sélectionnées
            .il te demande de sauvegarder OUI
            .tu lui donnes un nom pour pouvoir la retrouver et enregistre
            .clique sur corriger toutes les erreurs sélectionnées et sur la demande de confirmation OK
            .il supprime et fermer tu vérifies en relançant rechercher les erreurs
            .tu retournes dans option et tu recoches la case effacer uniquement les fichiers, du dossier temp de windows plus vieux que 48 heures et sur nettoyeur, windows sous avancé tu décoches la première case vieilles données du perfetch
            .tu peux fermer Ccleaner.

            Tuto : https://jesses.pagesperso-orange.fr/Docs/Logiciels/CCleaner.htm

            2)Lance ensuite une analyse complète avec Antivir

            Merci
            @+

            0
        3. Voici le rapport de Toolbar:

          -----------\\ ToolBar S&D 1.2.8 XP/Vista

          Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
          X86-based PC ( Multiprocessor Free : AMD Athlon(tm) 64 X2 Dual-Core Processor TK-53 )
          BIOS : PhoenixBIOS 4.0 Release 6.1
          USER : Ezaier ( Administrator )
          BOOT : Normal boot
          C:\ (Local Disk) - NTFS - Total:149 Go (Free:53 Go)
          D:\ (CD or DVD)

          "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
          Option : [2] ( 08/07/2009|21:26 )

          [ UAC => 1 ]

          -----------\\ SUPPRESSION

          Supprime! - C:\Program Files\AskBarDis\bar
          Supprime! - C:\Program Files\AskBarDis\unins000.dat
          Supprime! - C:\Program Files\AskBarDis\unins000.exe
          Supprime! - C:\Users\Ezaier\FAVORI~1\Speckly - torrent search simplified.url
          Supprime! - C:\Program Files\AskBarDis

          -----------\\ Recherche de Fichiers / Dossiers ...

          -----------\\ [..\Internet Explorer\Main]

          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
          "Local Page"="C:\\Windows\\system32\\blank.htm"
          "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
          "Start Page"="https://www.google.fr/?gws_rd=ssl"
          "Default_Search_URL"="http://fr.gdark.com"
          "SearchMigratedDefaultURL"="http://fr.gdark.com/...{searchTerms}"
          "Url"="https://www.msn.com/fr-fr/actualite/"

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
          "Start Page"="https://www.msn.com/fr-fr/"
          "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
          "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
          "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"

          --------------------\\ Recherche d'autres infections

          --------------------\\ Cracks & Keygens ..

          C:\Users\Ezaier\Desktop\Ma musique\Ma musique\I.A.M\De la planŠte mars\06 Piste 6. Crack.wma

          [ UAC => 1 ]

          1 - "C:\ToolBar SD\TB_1.txt" - 08/07/2009|21:10 - Option : [1]
          2 - "C:\ToolBar SD\TB_2.txt" - 08/07/2009|21:26 - Option : [2]

          -----------\\ Fin du rapport a 21:26:55,78
          0
          1. re

            la suite...
            0
        4. Ah merci ça marche :

          -----------\\ ToolBar S&D 1.2.8 XP/Vista

          Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
          X86-based PC ( Multiprocessor Free : AMD Athlon(tm) 64 X2 Dual-Core Processor TK-53 )
          BIOS : PhoenixBIOS 4.0 Release 6.1
          USER : Ezaier ( Administrator )
          BOOT : Normal boot
          C:\ (Local Disk) - NTFS - Total:149 Go (Free:53 Go)
          D:\ (CD or DVD)

          "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
          Option : [1] ( 08/07/2009|21:10 )

          [ UAC => 1 ]

          -----------\\ Recherche de Fichiers / Dossiers ...

          C:\Program Files\AskBarDis
          C:\Program Files\AskBarDis\bar
          C:\Program Files\AskBarDis\unins000.dat
          C:\Program Files\AskBarDis\unins000.exe
          C:\Program Files\AskBarDis\bar\bin
          C:\Program Files\AskBarDis\bar\Settings
          C:\Program Files\AskBarDis\bar\bin\askBar.dll
          C:\Program Files\AskBarDis\bar\bin\askPopStp.dll
          C:\Program Files\AskBarDis\bar\bin\psvince.dll
          C:\Program Files\AskBarDis\bar\Settings\config.dat
          C:\Program Files\AskBarDis\bar\Settings\config.dat.bak
          C:\Users\Ezaier\FAVORI~1\Speckly - torrent search simplified.url

          -----------\\ [..\Internet Explorer\Main]

          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
          "Local Page"="C:\\Windows\\system32\\blank.htm"
          "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
          "Start Page"="https://www.google.fr/?gws_rd=ssl"
          "Default_Search_URL"="http://fr.gdark.com"
          "SearchMigratedDefaultURL"="http://fr.gdark.com/...{searchTerms}"
          "Url"="https://www.msn.com/fr-fr/actualite/"

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
          "Start Page"="http://fr.gdark.com"
          "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
          "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
          "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"

          --------------------\\ Recherche d'autres infections

          --------------------\\ Cracks & Keygens ..

          C:\Users\Ezaier\Desktop\Ma musique\Ma musique\I.A.M\De la planŠte mars\06 Piste 6. Crack.wma

          [ UAC => 1 ]

          1 - "C:\ToolBar SD\TB_1.txt" - 08/07/2009|21:10 - Option : [1]

          -----------\\ Fin du rapport a 21:10:59,14
          0
          1. Re

            1)Relance Toolbar-S&D en double-cliquant(ou clic droit sous Vista) sur le raccourci. Tape sur "2" puis valide en appuyant sur "Entrée".

            ! Ne ferme pas la fenêtre lors de la suppression !

            Un rapport sera généré, poste son contenu ici.

            NOTE : Si ton Bureau ne réapparait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
            Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."
            Tape explorer puis valide.

            2)Télécharge Malwarebytes anti malware ici
            http://www.malwarebytes.org/mbam.php

            * Installe le (choisis bien "français" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

            (NB : S'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : https://www.malekal.com/tutorial-aboutbuster/

            * Potasse le tuto pour te familiariser avec le prg :

            https://forum.pcastuces.com/sujet.asp?f=31&s=3

            (cela dis, il est très simple d’utilisation).

            relance malwarebytes en suivant scrupuleusement ces consignes :

            ! Déconnecte toi et ferme toutes applications en cours !

            * Lance Malwarebyte's .

            Fais un examen dit "Complet" .

            --> Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
            --> à la fin tu cliques sur "résultat" .
            --> Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

            Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

            Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)

            @+
            0
        5. Bonjour Guillaume,

          Quand j'exécute Toolbar , après avoir entré F et 1, quelques minutes après s'affiche le message "Utilitaire (QGREP) de recherche de chaines de caractères a cessé de fonctionné".

          La recherche n'avance donc pas.

          Que faire s'il te plait?

          Merci
          0
          1. Re

            Sous Vista lance l'application avec un clic droit(exécuter en tant que...)
            0
        6. Voici le rapport combofix:

          ComboFix 09-07-07.01 - Ezaier 07/07/2009 19:52.1 - NTFSx86
          Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.33.1036.18.958.431 [GMT 2:00]
          Lancé depuis: c:\users\Ezaier\Desktop\adfghi.exe
          SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
          .

          (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
          .

          c:\windows\system32\drivers\MSIVXhplhrpxcdotrqxtfymcvxotmerxqnbcp.sys
          c:\windows\system32\MSIVXcount
          c:\windows\system32\MSIVXoekwknmpbbvijibteyrjjalfdmbsspnt.dll
          c:\windows\system32\MSIVXpopnintxibpxvtniweeretjgcfbsavxp.dll
          c:\windows\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job

          .
          ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
          .

          -------\Service_MSIVXserv.sys

          ((((((((((((((((((((((((((((( Fichiers créés du 2009-06-07 au 2009-07-07 ))))))))))))))))))))))))))))))))))))
          .

          2009-07-07 18:00 . 2009-07-07 18:01 -------- d-----w- c:\users\Ezaier\AppData\Local\temp
          2009-07-06 18:56 . 2009-07-06 18:56 -------- d-----w- c:\users\Ezaier\AppData\Roaming\Desktopicon
          2009-07-06 18:56 . 2009-07-06 18:56 -------- d-----w- c:\program files\Unlocker
          2009-06-23 12:24 . 2009-06-23 12:24 -------- d-----w- c:\users\Ezaier\AppData\Local\Google
          2009-06-23 11:41 . 2009-06-23 11:42 -------- d-----w- c:\program files\Common Files\Adobe
          2009-06-23 11:39 . 2009-06-23 11:39 -------- d-----w- c:\program files\Google
          2009-06-23 11:39 . 2009-06-23 11:44 -------- d-----w- c:\users\Ezaier\AppData\Local\Adobe
          2009-06-23 11:38 . 2009-07-02 16:59 -------- d-----w- c:\programdata\NOS
          2009-06-23 11:38 . 2009-07-02 16:59 -------- d-----w- c:\program files\NOS
          2009-06-21 10:57 . 2009-06-21 10:57 -------- d-----w- c:\users\Ezaier\AppData\Roaming\Hewlett-Packard
          2009-06-19 12:35 . 2009-06-19 12:38 164980 ----a-w- c:\windows\hpqins00.dat
          2009-06-10 20:12 . 2009-07-02 16:59 -------- d-----w- c:\windows\system32\Macromed
          2009-06-09 09:33 . 2009-06-09 09:33 -------- d-----w- c:\program files\BlueRaTech

          .
          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          2009-07-07 17:50 . 2009-05-29 10:30 89246 ----a-w- c:\programdata\nvModes.dat
          2009-07-07 17:48 . 2009-06-04 08:01 -------- d-----w- c:\users\Ezaier\AppData\Roaming\DNA
          2009-07-06 20:19 . 2008-01-21 08:40 672322 ----a-w- c:\windows\system32\perfh00C.dat
          2009-07-06 20:19 . 2008-01-21 08:40 124434 ----a-w- c:\windows\system32\perfc00C.dat
          2009-07-06 20:14 . 2009-06-04 08:01 -------- d-----w- c:\program files\DNA
          2009-07-02 16:34 . 2009-06-04 08:01 -------- d-----w- c:\users\Ezaier\AppData\Roaming\BitTorrent
          2009-06-21 10:56 . 2009-06-01 14:03 -------- d-----w- c:\programdata\Hewlett-Packard
          2009-06-09 18:04 . 2009-05-29 12:07 -------- d-----w- c:\programdata\Microsoft Help
          2009-06-07 10:12 . 2009-06-01 14:43 -------- d-----w- c:\program files\Microsoft Silverlight
          2009-06-07 09:55 . 2009-05-29 09:29 101560 ----a-w- c:\users\Ezaier\AppData\Local\GDIPFONTCACHEV1.DAT
          2009-06-07 09:52 . 2009-06-07 09:52 -------- d-----w- c:\users\Ezaier\AppData\Roaming\vlc
          2009-06-07 09:50 . 2009-06-07 09:50 -------- d-----w- c:\program files\VideoLAN
          2009-06-07 09:50 . 2009-06-07 09:50 -------- d-----w- c:\program files\VLC
          2009-06-07 09:39 . 2009-06-07 09:39 -------- d-----w- c:\programdata\Downloaded Installations
          2009-06-05 18:08 . 2009-06-05 17:21 -------- d-----w- c:\users\Ezaier\AppData\Roaming\Image Zone Express
          2009-06-05 17:57 . 2009-06-01 14:18 -------- d-----w- c:\users\Ezaier\AppData\Roaming\HP
          2009-06-05 17:56 . 2009-06-01 14:03 148096 ----a-w- c:\windows\hpoins12.dat
          2009-06-05 17:43 . 2009-06-01 14:09 -------- d-----w- c:\programdata\HPSSUPPLY
          2009-06-05 17:41 . 2009-06-05 17:41 -------- d-----w- c:\users\Ezaier\AppData\Roaming\Printer Info Cache
          2009-06-05 11:15 . 2009-06-05 11:15 -------- d-----w- c:\programdata\HP Product Assistant
          2009-06-04 08:01 . 2009-06-04 08:01 -------- d-----w- c:\program files\BitTorrent
          2009-06-04 08:01 . 2009-06-04 08:01 -------- d-----w- c:\program files\AskBarDis
          2009-06-01 18:29 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
          2009-06-01 18:29 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
          2009-06-01 18:14 . 2009-06-01 18:14 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
          2009-06-01 18:03 . 2009-06-01 18:03 -------- d-----w- c:\program files\MSXML 4.0
          2009-06-01 14:55 . 2009-06-01 14:03 -------- d-----w- c:\programdata\HP
          2009-06-01 14:43 . 2009-06-01 14:37 -------- d-----w- c:\program files\Microsoft
          2009-06-01 14:43 . 2009-06-01 14:42 -------- d-----w- c:\program files\Microsoft Office Outlook Connector
          2009-06-01 14:42 . 2009-06-01 14:36 -------- d-----w- c:\program files\Windows Live
          2009-06-01 14:41 . 2009-06-01 14:41 -------- d-----w- c:\program files\Microsoft Sync Framework
          2009-06-01 14:39 . 2009-06-01 14:39 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
          2009-06-01 14:37 . 2009-06-01 14:37 -------- d-----w- c:\program files\Windows Live SkyDrive
          2009-06-01 14:31 . 2009-06-01 14:31 -------- d-----w- c:\program files\Common Files\Windows Live
          2009-06-01 14:20 . 2009-06-01 14:20 -------- d-----w- c:\programdata\WEBREG
          2009-06-01 14:12 . 2009-06-01 14:09 -------- d-----w- c:\program files\Common Files\HP
          2009-06-01 14:12 . 2009-05-29 09:32 -------- d-----w- c:\program files\HP
          2009-06-01 14:08 . 2009-06-01 14:08 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
          2009-05-29 12:41 . 2009-05-29 12:32 -------- d-----w- c:\users\Ezaier\AppData\Roaming\Ahead
          2009-05-29 12:41 . 2009-05-29 12:41 -------- d-----w- c:\programdata\LightScribe
          2009-05-29 12:31 . 2009-05-29 12:31 -------- d-----w- c:\programdata\Ahead
          2009-05-29 12:30 . 2009-05-29 12:29 -------- d-----w- c:\program files\Common Files\Ahead
          2009-05-29 12:29 . 2009-05-29 12:29 -------- d-----w- c:\programdata\Nero
          2009-05-29 12:29 . 2009-05-29 12:29 -------- d-----w- c:\program files\Nero
          2009-05-29 12:19 . 2009-05-29 12:19 -------- d-----w- c:\programdata\Avira
          2009-05-29 12:19 . 2009-05-29 12:19 -------- d-----w- c:\program files\Avira
          2009-05-29 12:14 . 2009-05-29 12:14 -------- d-----w- c:\program files\Microsoft Works
          2009-05-29 12:13 . 2006-11-02 12:37 -------- d-----w- c:\program files\MSBuild
          2009-05-29 12:12 . 2009-05-29 12:12 -------- d-----w- c:\program files\Microsoft.NET
          2009-05-29 12:08 . 2009-05-29 12:08 -------- d-----w- c:\program files\Microsoft Visual Studio 8
          2009-05-29 10:30 . 2009-05-29 10:30 -------- d-----w- c:\programdata\NVIDIA
          2009-05-29 10:26 . 2009-05-29 09:33 -------- d-----w- c:\programdata\CyberLink
          2009-05-29 10:25 . 2009-05-29 09:32 -------- d--h--w- c:\program files\InstallShield Installation Information
          2009-05-29 10:21 . 2009-05-29 09:28 680 ----a-w- c:\users\Ezaier\AppData\Local\d3d9caps.dat
          2009-05-29 10:13 . 2009-05-29 09:42 -------- d-----w- c:\program files\Hewlett-Packard
          2009-05-29 10:11 . 2009-05-29 10:11 -------- d-----w- c:\program files\Broadcom
          2009-05-29 10:11 . 2009-05-29 10:11 6656 ----a-w- c:\windows\system32\bcmwlrc.dll
          2009-05-29 10:11 . 2009-05-29 10:11 87280 ----a-w- c:\windows\system32\bcmwlcoi.dll
          2009-05-29 10:11 . 2009-05-29 10:11 3809280 ----a-w- c:\windows\system32\bcmihvsrv.dll
          2009-05-29 10:11 . 2009-05-29 10:11 3502080 ----a-w- c:\windows\system32\bcmihvui.dll
          2009-05-29 10:11 . 2009-05-29 10:11 1331192 ----a-w- c:\windows\system32\drivers\BCMWL6.SYS
          2009-05-29 10:10 . 2009-05-29 10:10 -------- d-----w- c:\users\Ezaier\AppData\Roaming\GTek
          2009-05-29 10:08 . 2009-05-29 09:52 -------- d-----w- c:\program files\CONEXANT
          2009-05-29 10:04 . 2009-05-29 10:04 -------- d-----w- c:\users\Ezaier\AppData\Roaming\WinBatch
          2009-05-29 10:01 . 2009-05-29 10:01 -------- d-----w- c:\program files\Common Files\LightScribe
          2009-05-29 10:00 . 2009-05-29 10:00 0 --sha-r- c:\windows\system32\drivers\103C_HP_cNB_Pavilion dv6500 Notebook PC_Y5335KV_0U_QCNF73245ZY_EU_4A_I30CF_SQuanta_V85.17_F.06_T070723_WV3-1_L40C_M959_J160_7AMD_8F81_91.70_#090529_N10DE054C_(GQ200EA#ABF)_XMOBILE_CN10_Z_2Rev 1_G10DE0531.MRK
          2009-05-29 09:56 . 2009-05-29 09:56 -------- d-----w- c:\program files\Fingerprint Sensor
          2009-05-29 09:54 . 2009-05-29 09:32 -------- d-----w- c:\program files\Common Files\InstallShield
          2009-05-29 09:53 . 2009-05-29 09:53 -------- d-----w- c:\program files\NetWaiting
          2009-05-29 09:51 . 2009-05-29 09:51 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_SynTP_01000.Wdf
          2009-05-29 09:51 . 2009-05-29 09:51 -------- d-----w- c:\program files\Synaptics
          2009-05-29 09:47 . 2009-05-29 09:32 -------- d-----w- c:\program files\HP DVB-T TV Tuner
          2009-05-29 09:41 . 2009-05-29 09:41 -------- d-----w- c:\program files\WinTV
          2009-05-29 09:33 . 2009-05-29 09:33 -------- d-----w- c:\users\Ezaier\AppData\Roaming\InstallShield
          2009-05-29 09:31 . 2009-05-29 09:31 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
          2009-05-29 09:26 . 2009-05-29 09:26 -------- d-sh--we c:\programdata\Modèles
          2009-05-29 09:26 . 2009-05-29 09:26 -------- d-sh--we c:\programdata\Menu Démarrer
          2009-05-29 09:26 . 2009-05-29 09:26 -------- d-sh--we c:\programdata\Favoris
          2009-05-29 09:26 . 2009-05-29 09:26 -------- d-sh--we c:\programdata\Bureau
          2009-05-29 09:26 . 2009-05-29 09:26 -------- d-sh--we c:\program files\Fichiers communs
          2009-04-09 11:32 . 2009-04-09 11:32 89088 ----a-w- c:\users\Ezaier\AppData\Roaming\Desktopicon\eBayShortcuts.exe
          .

          ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          .
          *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
          REGEDIT4

          [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
          2008-09-29 15:24 325000 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll

          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
          "LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-10-18 455968]
          "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-05-16 153136]
          "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
          "BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-06-04 321344]
          "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
          "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-23 39408]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
          "hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-10-03 480560]
          "SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-14 102400]
          "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
          "QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-08-01 202032]
          "HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-12-04 75016]
          "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-06-20 1316136]
          "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-03 13556256]
          "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-12-03 92704]
          "QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-04-23 176128]
          "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
          "NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
          "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
          "UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2008-05-02 15872]

          c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
          HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]

          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
          "EnableLUA"= 0 (0x0)
          "EnableUIADesktopToggle"= 0 (0x0)

          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
          "aux"=wdmaud.drv

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
          @="Service"

          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3354235940-999707340-3439262856-1000]
          "EnableNotificationsRef"=dword:00000001

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
          "{57118C55-E588-45BF-92BA-A8DE73723C6A}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
          "{FA3B75AA-1776-4BD3-BBBE-E407FF9645FB}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
          "{DF9C8D3D-11EC-4508-A838-D329B2D6F0D4}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
          "{AC32D25A-9132-49E7-B1F7-8C9F94FBD72E}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
          "{1C725935-3D7F-476A-A470-EE831E797614}"= UDP:c:\program files\DNA\btdna.exe:DNA (TCP-In)
          "{A3E002D1-77A3-4A8D-A816-025DC2DA878C}"= TCP:c:\program files\DNA\btdna.exe:DNA (UDP-In)
          "{C8AC012E-F2A5-4D52-9111-72410AF5BF2A}"= UDP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent (TCP-In)
          "{5E550572-FE40-497F-8A44-B96A5E6C5A05}"= TCP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent (UDP-In)

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
          "c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent

          R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [29/05/2009 14:20 108289]
          S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [29/05/2009 12:06 193840]
          S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [01/06/2009 16:42 55280]
          S3 fsssvc;Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [06/02/2009 18:08 533360]

          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
          HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
          hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
          "c:\program files\Common Files\LightScribe\LSRunOnce.exe"
          .
          .
          ------- Examen supplémentaire -------
          .
          uStart Page = hxxp://www.google.fr/
          uDefault_Search_URL = hxxp://fr.gdark.com
          uSearchMigratedDefaultURL = hxxp://fr.gdark.com/search.php?cx=partner-pub-7902900401080901%3Ae94ctf-nqmg&cof=FORID%3A10&ie=UTF-8&q={searchTerms}
          mStart Page = hxxp://fr.gdark.com
          uSearchURL,(Default) = hxxp://fr.gdark.com
          IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
          DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
          .

          **************************************************************************

          catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2009-07-07 20:01
          Windows 6.0.6001 Service Pack 1 NTFS

          Recherche de processus cachés ...

          Recherche d'éléments en démarrage automatique cachés ...

          Recherche de fichiers cachés ...

          Scan terminé avec succès
          Fichiers cachés: 0

          **************************************************************************
          .
          --------------------- CLES DE REGISTRE BLOQUEES ---------------------

          [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
          @Denied: (A) (Users)
          @Denied: (A) (Everyone)
          @Allowed: (B 1 2 3 4 5) (S-1-5-20)
          "BlindDial"=dword:00000000
          .
          Heure de fin: 2009-07-07 20:04
          ComboFix-quarantined-files.txt 2009-07-07 18:04

          Avant-CF: 68 440 039 424 octets libres
          Après-CF: 69 351 604 224 octets libres

          213 --- E O F --- 2009-06-09 18:04
          0
          1. Re

            1)=> Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):
            http://www.commentcamarche.net/faq/sujet 8343 vista desactiver l uac
            * Va dans démarrer puis panneau de configuration
            * Double Clique sur l'icône "Comptes d'utilisateurs"
            * Clique ensuite sur désactiver et valide.

            2)Voici une première chose de faite avec ComboFix...

            3)Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
            https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

            Lors du scan coupe ta connection internet.

            * Lance l'installation du programme en exécutant le fichier téléchargé.
            * Double-clique maintenant sur le raccourci de Toolbar-S&D.
            * Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
            * Choisis maintenant l'option 1. Patiente jusqu'à la fin de la recherche.
            0
        7. je ne peux pas télécharger combofix, ça m'alarme de virus détecté....
          ça donne rien!
          0
          1. Re

            Il te faut désactivé ton antivirus et éventuellement ton antyspyware;comme mentionné dans le post précédent...
            0
        8. Je te fais ça dessuite, je bataille avec l'imprimante, ça ne veut plus imprimer maintenant.
          C'est pas grâve...

          Merci
          0
          1. Bonjour,

            j'ai fais ce que tu m'avais dit mais tojours rien...

            je me demande si je cherche le bon truc au moins : je ne trouve pas MSIVX dans System 32!!

            Merci
            0
            1. Re

              as tu fais Combofix?
              Peux tu me poster le rapport stp
              Merci
              0
          2. ouvre n'importe quelle fenètre de l'explorateur (Documents par exemple)
            clique sur organiser, puis sur option des dossiers et recherche, affichage et dans le menu déroulant tu choisis afficher les fichiers et dossiers cachés, et la normalement tu peux voir la Dll et la supprimer
            0
            1. Bonjour Lilou

              Lis bien et si tu peux imprime ces informations et applique à la lettre.

              Télécharge combofix : http://download.bleepingcomputer.com/sUBs/ComboFix.exe
              ->Renomme le en adfghi pour l’enregistrer sur ton bureau
              -> Double clique combofix.exe.
              -> Tape sur la touche 1 (Yes) pour démarrer le scan.
              -> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

              NOTE : Le rapport se trouve également ici : C:\Combofix.txt

              Avant d'utiliser ComboFix :

              -> Déconnecte toi d'Internet et referme les fenêtres de tous les programmes en cours.

              -> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.

              Une fois fait, sur ton bureau double-clic sur Combofix.exe.

              - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

              -Attention Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programme. Risque de figer l'ordinateur

              - En fin de scan il est possible que ComboFix ait besoin de redémarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

              - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

              -> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

              -> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

              !\ Ne touche à rien tant que le scan n'est pas terminé. /!\ : risque de figer l'ordinateur (plantage complet)

              ::Si combofix détecte quelque chose et de demande a redémarrer tu accepte

              @+
              0
          3. En effet, je ne retrouve pas le chemin d'accès: je vais jusqu'à system 32 mais dedans, je ne retrouve pas MSIVX.

            Que faire s'il te plait ?

            Merci
            0
            1. J'ai installé unlocker mais je ne retrouve pas la dll.
              0
              1. J'ai un peu de mal à suivre, désolé je ne suis pas très douée!!!
                C'est quoi une dll, comment la supprimer ?
                Ou trouver le logiciel unlocker?

                Merci
                0
                1. tu del avec unlocker et tu passe ccleaner complet et tu défragmente avec JKdefrag et pas avec celui de windows
                  0
                  1. tu utilise le logiciel unlocker pour supprimer la dll, et tu nettoie ton PC avec ccleaner, et installe un antispyware (spybot S&D)
                    0
                    • 1
                    • 2