Problème de scan au démarrage

Bonjour à tous,
je vous contacte car je suis une novice en informatique et j'ai grand besoin de votre aide.
J'ai acheté un pc HP dv6000 il y à maintenant 2 ans et jamais de soucis jusque la semaine dernière!!!
En effet il me demande constamment de faire un scan du disque local C, apparemment le disque dur. J'ai la possibilité d'annuler ce scan en tapant sur une touche avant 10 secondes!!!
J'ai tout essayé et il y a rien à faire il me le demande constamment!!!
Aidez moi je vous en supplie je suis étudiante et mon ordi est trop imp!!!
Merci à tous et bonne journée
Configuration: Windows Vista Internet Explorer 7.0

50 réponses

Résumé de la discussion

La problématique centrale est qu’un PC sous Windows Vista demande un scan du disque C au démarrage, évoquant un souci du disque dur ou une vérification automatisée. Plusieurs intervenants recommandent de désinstaller Sophos et d’installer un antivirus gratuit alternatif, comme Avira, puis d’effectuer une mise à jour et un scan complet, sans négliger le passage par CCleaner. D’autres conseils ciblent l’identification des programmes qui déclenchent le scan et l’usage d’outils comme HijackThis pour nettoyer les éléments indésirables, ainsi que la vérification SMART du disque. À noter, des échanges indiquent que le comportement peut varier selon le jour et que des vérifications matérielles (SMART) et les rapports du fabricant peuvent résoudre le mystère sans réinstallations répétées.

Bobot (l’IA à votre service)
  1. Morning,

    Ce n'est pas mal du tout. Tu as toutefois 2 applications HijackThis en exécution: C:\Users\CLOTHI~1\AppData\Local\Temp\hijackthis-2.0.2.exe et c:\Users\clothilde\Downloads\hijackthis-2.0.2.exe. Je pense que l'install a foiré d'une certaine manière... Si Hijackthis apparaît parmi dans Ajout/Suppr des programmes, supprime-le. Crée un dossier HJT à la racine de C: et télécharge Hijack à nouveau à partir de cette adresse: http://www.trendsecure.com/portal/fr/_download/HiJackThis.exe Fais clic droit / enregistrer sous et renomme-le en HJT.exe (au lieu de HiJackThis.exe). Sauvegarde-le dans le dossier C:\HJT que tu viens de créer. A l'avenir, lorsque tu fais un rapport hijack, tu lances donc C:\HJT\HJT.exe. Il est recommandé, pour Hijack:
    - de le renommer (pour contrer certains infections, comme Vundo)
    - de le laisser seul dans son propre dossier (d'où la création de C:\HJT)

    Suite des opérations:

    1. Désinstallation des barres d'outils inutiles. T'en as plein: Windows Live, Yahoo, Google. Commence par désactiver l'UAC, tu le réactiveras après. Tuto: https://forums.cnetfrance.fr/tutoriels-windows-7-8-et-autres-sytemes/104271-comment-desactiver-uac-dans-vista Ensuite, suis les instructions ici https://www.commentcamarche.net/faq/9685-supprimer-les-barres-d-outils-toolbars-indesirables pour la suppression en mode sans échec et la génération d'un rapport Toolbar S&D que tu colleras avec ta réponse

    2. Vire Adobe Acrobar Reader. Plus gourmand que la concurrence. Installe ceci à la place: https://download.cnet.com/Foxit-Reader/3000-18497_4-10313206.html?part=dl-116442&subj=dl&tag=button Lors de l'install, fais une installation personnalisée et décoche l'installation de je-ne-sais-plus-quelle-autre barre d'outils (Ask ?) ou encore la modification de la page de démarrage... Il sera en anglais (les traductions ont toujours une version de retard), mais ça ne devrait pas poser problème car tu l'utiliseras généralement en cliquant sur un pdf et en faisant un scroll... Pas souvent besoin d'aller se balader dans ses menus.

    3. Comme tu as un antivirus décent à présent, tu peux désactiver Windows Defender: https://www.tayo.fr/desactiver-windows-defender--anti-virus-aide.php

    4. Je n'aime pas Tuneup Utilities, mais bon, c'est une question de goût. Tu peux le garder si tu veux, mais désactive sa défragmentation automatique et installe un défragmenteur de disque digne de ce nom à la place. Tu as 3 produits excellents, PerfectDisk, Diskeeper et O&O Defrag (tous les 3 payants, mais bon ;-))

    5. Désactive et réactive par la suite la restauration. Tuto: https://www.tayo.fr/desactiver-restauration-windows-vista-tutoriel.php

    6. Fais une mise à jour. Installe le SP2 de Vista, IE 8... (pour l'install de IE 8: install personnalisé, tu dis que tu souhaites Google comme moteur de recherche par défaut et tu refuses toutes les options qu'il te propose à part la protection contre le phising).

    7. Une fois installé, abandonne IE 8 (lol !). Navigue avec Firefox à la place. http://www.mozilla-europe.org/fr/firefox/ A l'installation, il te proposera d'importer des choses à partir d'IE; refuse. Tu peux exporter manuellement les favoris IE plus tard. Installe Adblock Plus comme add-on Firefox http://slimgus.blogspot.com/2009/06/tuto-adblock.html

    8. Mmm, il y a aussi la config des services et je n'ai pas de tuto en fr. Par contre, bien expliqué ici: http://www.blackviper.com/service-configurations/black-vipers-windows-vista-service-pack-2-service-configurations/

    9. Si tu envisages utiliser des programmes qui demandent beaucoup beaucoup de mémoire, faudra acheter encore 1 Go de RAM.

    Walà, avec tout ceci ça devra mieux tourner

    Bon cours :-)
    0
    1. et voici lelog hijak:

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 21:05:12, on 22/10/2009
      Platform: Windows Vista SP1 (WinNT 6.00.1905)
      MSIE: Internet Explorer v8.00 (8.00.6001.18813)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\Dwm.exe
      C:\Windows\system32\taskeng.exe
      C:\Windows\Explorer.EXE
      C:\Program Files\Synaptics\SynTP\SynTPStart.exe
      C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
      C:\WINDOWS\RtHDVCpl.exe
      C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
      C:\Program Files\Hp\QuickPlay\QPService.exe
      C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
      C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
      C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
      C:\WINDOWS\System32\rundll32.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\WINDOWS\System32\rundll32.exe
      C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
      C:\Windows\system32\wuauclt.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
      C:\Program Files\Windows Live\Toolbar\wltuser.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
      C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
      C:\Windows\system32\SearchProtocolHost.exe
      c:\Users\clothilde\Downloads\hijackthis-2.0.2.exe
      C:\Users\CLOTHI~1\AppData\Local\Temp\hijackthis-2.0.2.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dailymotion.com/fr
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/...
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O1 - Hosts: ::1 localhost
      O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
      O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
      O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
      O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
      O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
      O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
      O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
      O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
      O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
      O4 - HKLM\..\Run: [WAWifiMessage] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
      O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
      O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
      O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
      O13 - Gopher Prefix:
      O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Plugin Control) - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
      O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
      O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
      O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
      O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
      O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
      O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
      O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
      O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
      O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
      O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe
      O23 - Service: @%SystemRoot%\System32\TUProgSt.exe,-1 (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\Windows\System32\TUProgSt.exe
      0
      1. coucou,
        voila le scan est fini jte donne le rapport:

        Avira AntiVir Personal
        Date de création du fichier de rapport : jeudi 22 octobre 2009 19:53

        La recherche porte sur 1815437 souches de virus.

        Détenteur de la licence : Avira AntiVir Personal - FREE Antivirus
        Numéro de série : 0000149996-ADJIE-0000001
        Plateforme : Windows Vista
        Version de Windows : (Service Pack 1) [6.0.6001]
        Mode Boot : Démarré normalement
        Identifiant : SYSTEM
        Nom de l'ordinateur : PC-DE-CLOTHILDE

        Informations de version :
        BUILD.DAT : 9.0.0.70 18071 Bytes 25/09/2009 12:03:00
        AVSCAN.EXE : 9.0.3.7 466689 Bytes 22/10/2009 17:52:13
        AVSCAN.DLL : 9.0.3.0 49409 Bytes 03/03/2009 09:21:02
        LUKE.DLL : 9.0.3.2 209665 Bytes 20/02/2009 10:35:11
        LUKERES.DLL : 9.0.2.0 13569 Bytes 03/03/2009 09:21:31
        ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 11:30:36
        ANTIVIR1.VDF : 7.1.4.132 5707264 Bytes 24/06/2009 17:52:12
        ANTIVIR2.VDF : 7.1.6.112 4833792 Bytes 15/10/2009 17:52:12
        ANTIVIR3.VDF : 7.1.6.139 238080 Bytes 22/10/2009 17:52:12
        Version du moteur : 8.2.1.44
        AEVDF.DLL : 8.1.1.2 106867 Bytes 22/10/2009 17:52:13
        AESCRIPT.DLL : 8.1.2.40 487804 Bytes 22/10/2009 17:52:13
        AESCN.DLL : 8.1.2.5 127346 Bytes 22/10/2009 17:52:13
        AERDL.DLL : 8.1.3.2 479604 Bytes 22/10/2009 17:52:13
        AEPACK.DLL : 8.2.0.2 422263 Bytes 22/10/2009 17:52:13
        AEOFFICE.DLL : 8.1.0.38 196987 Bytes 22/10/2009 17:52:13
        AEHEUR.DLL : 8.1.0.167 2011511 Bytes 22/10/2009 17:52:13
        AEHELP.DLL : 8.1.7.0 237940 Bytes 22/10/2009 17:52:12
        AEGEN.DLL : 8.1.1.68 364918 Bytes 22/10/2009 17:52:12
        AEEMU.DLL : 8.1.1.0 393587 Bytes 22/10/2009 17:52:12
        AECORE.DLL : 8.1.8.1 184693 Bytes 22/10/2009 17:52:12
        AEBB.DLL : 8.1.0.3 53618 Bytes 09/10/2008 13:32:40
        AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 07:47:30
        AVPREF.DLL : 9.0.3.0 44289 Bytes 22/10/2009 17:52:13
        AVREP.DLL : 8.0.0.3 155905 Bytes 20/01/2009 13:34:28
        AVREG.DLL : 9.0.0.0 36609 Bytes 07/11/2008 14:24:42
        AVARKT.DLL : 9.0.0.3 292609 Bytes 24/03/2009 14:05:22
        AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 30/01/2009 09:36:37
        SQLITE3.DLL : 3.6.1.0 326401 Bytes 28/01/2009 14:03:49
        SMTPLIB.DLL : 9.2.0.25 28417 Bytes 02/02/2009 07:20:57
        NETNT.DLL : 9.0.0.0 11521 Bytes 07/11/2008 14:40:59
        RCIMAGE.DLL : 9.0.0.25 2438913 Bytes 22/10/2009 17:52:12
        RCTEXT.DLL : 9.0.37.0 88321 Bytes 15/04/2009 09:07:05

        Configuration pour la recherche actuelle :
        Nom de la tâche...............................: Contrôle intégral du système
        Fichier de configuration......................: c:\program files\avira\antivir desktop\sysscan.avp
        Documentation.................................: bas
        Action principale.............................: interactif
        Action secondaire.............................: ignorer
        Recherche sur les secteurs d'amorçage maître..: marche
        Recherche sur les secteurs d'amorçage.........: marche
        Secteurs d'amorçage...........................: C:, D:,
        Recherche dans les programmes actifs..........: marche
        Recherche en cours sur l'enregistrement.......: marche
        Recherche de Rootkits.........................: marche
        Contrôle d'intégrité de fichiers système......: arrêt
        Fichier mode de recherche.....................: Tous les fichiers
        Recherche sur les archives....................: marche
        Limiter la profondeur de récursivité..........: 20
        Archive Smart Extensions......................: marche
        Heuristique de macrovirus.....................: marche
        Heuristique fichier...........................: moyen
        Catégories de dangers divergentes.............: +APPL,+GAME,+JOKE,+PCK,+SPR,

        Début de la recherche : jeudi 22 octobre 2009 19:53

        La recherche d'objets cachés commence.
        '98987' objets ont été contrôlés, '0' objets cachés ont été trouvés.

        La recherche sur les processus démarrés commence :
        Processus de recherche 'avscan.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'avscan.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'avcenter.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'sched.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'avguard.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'avgnt.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'FlashUtil10c.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'infocard.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'iexplore.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'wltuser.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'GoogleToolbarUser.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'iexplore.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'wuauclt.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'HPHC_Service.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'HpqToaster.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'SynTPEnh.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'rundll32.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'wmpnetwk.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'wmpnscfg.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'msnmsgr.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'LightScribeControlPanel.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'WmiPrvSE.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'sidebar.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'rundll32.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'WiFiMsg.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'HPWAMain.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'MSASCui.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'HPKBDAPP.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'QLBCTRL.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'QPService.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'IAAnotif.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'RtHDVCpl.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'sm56hlpr.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'SynTPStart.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'explorer.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'taskeng.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'dwm.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'taskeng.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'QPSched.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'hpqWmiEx.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'SearchIndexer.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'TUProgSt.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'SeaPort.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'QPCapSvc.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'LSSrvc.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'IAANTmon.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'spoolsv.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'SLsvc.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'audiodg.exe' - '0' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'winlogon.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'lsm.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'lsass.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'services.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'wininit.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'csrss.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'csrss.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'smss.exe' - '1' module(s) sont contrôlés
        '69' processus ont été contrôlés avec '69' modules

        La recherche sur les secteurs d'amorçage maître commence :
        Secteur d'amorçage maître HD0
        [INFO] Aucun virus trouvé !

        La recherche sur les secteurs d'amorçage commence :
        Secteur d'amorçage 'C:\'
        [INFO] Aucun virus trouvé !
        Secteur d'amorçage 'D:\'
        [INFO] Aucun virus trouvé !

        La recherche sur les renvois aux fichiers exécutables (registre) commence :
        Le registre a été contrôlé ( '47' fichiers).

        La recherche sur les fichiers sélectionnés commence :

        Recherche débutant dans 'C:\'
        C:\hiberfil.sys
        [AVERTISSEMENT] Impossible d'ouvrir le fichier !
        [REMARQUE] Ce fichier est un fichier système Windows.
        [REMARQUE] Il est correct que ce fichier ne puisse pas être ouvert pour la recherche.
        C:\pagefile.sys
        [AVERTISSEMENT] Impossible d'ouvrir le fichier !
        [REMARQUE] Ce fichier est un fichier système Windows.
        [REMARQUE] Il est correct que ce fichier ne puisse pas être ouvert pour la recherche.
        C:\Downloads\Software\gamingharbor_installer.exe
        [RESULTAT] Contient le modèle de détection du logiciel espion ou publicitaire ADSPY/PopMenu.B.1
        C:\HP\HPQWare\EasySetup\SetACL.exe
        [RESULTAT] Contient le modèle de détection de l'application APPL/ACLSet
        Recherche débutant dans 'D:\' <HP_RECOVERY>

        Début de la désinfection :
        C:\Downloads\Software\gamingharbor_installer.exe
        [RESULTAT] Contient le modèle de détection du logiciel espion ou publicitaire ADSPY/PopMenu.B.1
        [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4b4dac5f.qua' !
        C:\HP\HPQWare\EasySetup\SetACL.exe
        [RESULTAT] Contient le modèle de détection de l'application APPL/ACLSet
        [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4b54ac63.qua' !

        Fin de la recherche : jeudi 22 octobre 2009 21:01
        Temps nécessaire: 1:03:04 Heure(s)

        La recherche a été effectuée intégralement

        21488 Les répertoires ont été contrôlés
        429398 Des fichiers ont été contrôlés
        2 Des virus ou programmes indésirables ont été trouvés
        0 Des fichiers ont été classés comme suspects
        0 Des fichiers ont été supprimés
        0 Des virus ou programmes indésirables ont été réparés
        2 Les fichiers ont été déplacés dans la quarantaine
        0 Les fichiers ont été renommés
        2 Impossible de contrôler des fichiers
        429394 Fichiers non infectés
        3736 Les archives ont été contrôlées
        2 Avertissements
        4 Consignes
        98987 Des objets ont été contrôlés lors du Rootkitscan
        0 Des objets cachés ont été trouvés
        0
        1. re, ouai kel idée mais bon la cause principale est ma mere lol!!!je plaisante!
          c ok g suppr sophos g pris l'antivirus ke tu ma conseillé et la je suis en train de faire le scan et trop bizarre il me trouve 2 trucs alors ke dpuis mon probleme g fait des 10aines de scan avec sophos et rien!!!merci :))
          0
          1. oki doki... Bon cours !!

            (pfff, quelle idée, que celle d'aller en cours !)
            0
            1. ok pas de soucis!!par contre je ferai ca dans la soirée car la je v en cours!!
              je te tiens o courant et encore mille merci pour ton aide précieuse c super gentil de ta part!!!!!:)))
              0
              1. OK. Télécharge ceci: http://dlce.antivir.com/package/wks_avira/win32/fr/pecl/avira_antivir_personal_fr.zip

                Désinstalle Sophos. Regarde ici http://www.sophos.com/support/knowledgebase/article/12360.html la section Vista pour voir l'ordre de désinstallation (c'est important). Tu redémarreras le PC autant de fois qu'il te le demande.

                Si pas OK, pour une raison ou une autre, ne continue pas et fais signe.

                Passe un coup de CCleaner (fichiers + registres)

                Installe le programme que tu as téléchargé en suivant ce tuto: https://www.malekal.com/avira-free-security-antivirus-gratuit/ Fais le paramétrage, la mise à jour et un scan complet avec, histoire de.

                Reviens avec
                - le log de scan Antivir
                - un nouveau log hijackthis

                ++
                0
                1. voila g fait les fixed chek d 2 lignes
                  0
                  1. pour kk1 ki pige rien t fort!!!:))
                    alors pour l'anglais je pige léger sauf les truc courant lol
                    voila les info de sophos je fait tout de suite ce ke tu m'a dit

                    [Général]
                    Etat du contrôle sur accès = Actif
                    Droits utilisateur actuels = Administrateur Sophos

                    [Logiciel]
                    Sophos Anti-Virus = 7.6.12
                    Statut de la publication = Complet
                    Moteur de détection = 3.0.1
                    Données de détection = 4.46E
                    Eléments détectés = 1060863
                    Identités de détection = 247
                    Version des règles HIPS = 2.2.0
                    Version de la configuration HIPS = 1.0.4
                    Dernière mise à jour = 22/10/2009 13:55:09

                    [Fichiers d'identité de détection]
                    agen-ldn.ide
                    tdss-av.ide
                    fakea-pz.ide
                    silly-dv.ide
                    agen-lef.ide
                    bredo-d.ide
                    agen-lcw.ide
                    injec-jp.ide
                    spy-dv.ide
                    dloa-ctr.ide
                    fake-abm.ide
                    auto-aqv.ide
                    expiro-f.ide
                    tdss-au.ide
                    agen-lep.ide
                    bank-euf.ide
                    mdro-cfl.ide
                    bank-u.ide
                    fake-abr.ide
                    injec-jn.ide
                    injec-jr.ide
                    talsab-a.ide
                    bank-euk.ide
                    dldr-bl.ide
                    sbot-b.ide
                    swfdl-b.ide
                    servu-fx.ide
                    fake-aar.ide
                    hoster-a.ide
                    fakev-ou.ide
                    fakea-pq.ide
                    killa-ga.ide
                    fake-aai.ide
                    dloa-cto.ide
                    fakeal-l.ide
                    vb-ehp.ide
                    dwnl-hws.ide
                    agen-lcy.ide
                    injec-jo.ide
                    fake-abq.ide
                    autoi-gf.ide
                    fakev-oz.ide
                    fake-abg.ide
                    ddos-ad.ide
                    zbot-ht.ide
                    zbot-hx.ide
                    agen-lci.ide
                    agen-ldd.ide
                    expjs-g.ide
                    cariez-a.ide
                    bredo-g.ide
                    docdro-k.ide
                    agen-lcz.ide
                    pdfex-bz.ide
                    autoi-gg.ide
                    auto-arl.ide
                    dropr-bz.ide
                    fakea-pp.ide
                    mdro-cft.ide
                    dloa-ctd.ide
                    fakev-pb.ide
                    fake-aca.ide
                    fakea-qc.ide
                    silly-dw.ide
                    palevo-a.ide
                    auto-aro.ide
                    selges-a.ide
                    agen-lfx.ide
                    fakea-qh.ide
                    fake-aco.ide
                    fake-acb.ide
                    fake-acl.ide
                    drop-dq.ide
                    zbot-ia.ide
                    fake-acq.ide
                    auto-ars.ide
                    spy-dw.ide
                    dwnl-hwx.ide
                    fake-act.ide
                    sispro-a.ide
                    dldr-br.ide
                    forcud-a.ide
                    pws-bek.ide
                    dloa-cuh.ide
                    fake-ace.ide
                    auto-arv.ide
                    ircb-afh.ide
                    start-ce.ide
                    mdro-cge.ide
                    agen-lge.ide
                    agen-lgk.ide
                    vb-eif.ide
                    ircb-afj.ide
                    rbot-gyd.ide
                    renos-dq.ide
                    dnsch-mt.ide
                    zipcar-d.ide
                    vb-eil.ide
                    vb-eik.ide
                    vb-eii.ide
                    tdss-bc.ide
                    agen-lgr.ide
                    dldr-bt.ide
                    bredo-i.ide
                    agen-lgz.ide
                    agen-lgu.ide
                    sedjja-a.ide
                    bckd-qyr.ide
                    renos-dw.ide
                    zbot-ic.ide
                    agen-lhn.ide
                    mdro-cgj.ide
                    mdro-cgi.ide
                    auto-ufo.ide
                    hixpet-a.ide
                    auto-asa.ide
                    injec-jx.ide
                    palevo-c.ide
                    zbot-id.ide
                    bckd-qyx.ide
                    fakev-pi.ide
                    fake-ady.ide
                    fake-aea.ide
                    vkkont-a.ide
                    clomp-l.ide
                    vb-eip.ide
                    auto-asb.ide
                    zbot-ij.ide
                    bredoz-h.ide
                    mdro-cgr.ide
                    agen-lig.ide
                    agen-lij.ide
                    dloa-cus.ide
                    plank-b.ide
                    fujac-bf.ide
                    murlo-bj.ide
                    agen-lil.ide
                    dloa-cut.ide
                    agen-lio.ide
                    agen-lir.ide
                    clomp-m.ide
                    dloa-cuw.ide
                    fake-ael.ide
                    vb-eiw.ide
                    agen-lis.ide
                    kolab-d.ide
                    drop-dw.ide
                    zbot-il.ide
                    agen-liw.ide
                    vb-ejc.ide
                    banc-bgf.ide
                    vb-eja.ide
                    killba-c.ide
                    fake-aeq.ide
                    fake-aer.ide
                    agen-liy.ide
                    agen-lje.ide
                    zbot-io.ide
                    fake-aev.ide
                    fakere-e.ide
                    spy-dy.ide
                    zbot-ip.ide
                    dloa-cvd.ide
                    alure-e.ide
                    zbot-iq.ide
                    agen-ljn.ide
                    fake-aey.ide
                    pdfex-ce.ide
                    agen-ljr.ide
                    drop-dz.ide
                    bank-euo.ide
                    fake-afb.ide
                    sasfis-a.ide
                    vbinje-k.ide
                    agen-lka.ide
                    pdload-a.ide
                    swfdlr-q.ide
                    pdfjs-ds.ide
                    agen-lkm.ide
                    pws-ben.ide
                    fake-afe.ide
                    zbot-iu.ide
                    hiloti-h.ide
                    zipcar-e.ide
                    rimecu-b.ide
                    fakea-qp.ide
                    bancdl-e.ide
                    auto-ast.ide
                    zbot-iv.ide
                    zbot-jb.ide
                    auto-asx.ide
                    jsdown-s.ide
                    agen-lkx.ide
                    zbot-jg.ide
                    fake-afh.ide
                    realbo-b.ide
                    zbot-jj.ide
                    fakea-qq.ide
                    agen-lky.ide
                    downln-h.ide
                    dload-gy.ide
                    agen-llj.ide
                    agen-lli.ide
                    bckd-qzo.ide
                    agen-lkz.ide
                    pdfjs-ea.ide
                    psw-hh.ide
                    buzus-bk.ide
                    fakev-pk.ide
                    fake-afm.ide
                    lnkzip-b.ide
                    pws-bex.ide
                    psyme-ks.ide
                    xed-b.ide
                    dwnl-hxo.ide
                    dloa-cvp.ide
                    bredo-m.ide
                    vbinje-l.ide
                    dloa-cvo.ide
                    ircb-afr.ide
                    tdss-bh.ide
                    vbinje-m.ide
                    bank-eus.ide
                    start-cj.ide
                    harni-bz.ide
                    start-ci.ide
                    mdro-cgx.ide
                    dloa-cvr.ide
                    docdro-n.ide
                    dloa-cvs.ide
                    fake-afo.ide
                    renos-dy.ide
                    zipmal-b.ide
                    gpcode-e.ide
                    litis-a.ide
                    agen-lmx.ide
                    voter-f.ide
                    dldr-cb.ide
                    dnschg-a.ide
                    fake-afw.ide
                    agen-lne.ide
                    bank-eut.ide
                    vb-ejl.ide
                    bho-oc.ide
                    agen-lng.ide
                    dloa-cvx.ide
                    ifram-dd.ide

                    [Composants]
                    BackgroundScanClient.exe 1.0.0.3970 , taille 45608 octets
                    sav32cli.exe 2.28.000 , taille 232488 octets
                    SAVAdminService.exe 1.0.0.4000 , taille 80936 octets
                    SAVCleanupService.exe 1.0.0.3090 , taille 90112 octets
                    SavMain.exe 1.0.0.3980 , taille 2010152 octets
                    SavProgress.exe 1.0.0.3980 , taille 556072 octets
                    SavService.exe 1.0.0.3921 , taille 98304 octets
                    sdcdevcon.exe 1.0.0.3821 , taille 49152 octets
                    sdcservice.exe 1.0.0.4000 , taille 393216 octets
                    WSCClient.exe 1.0.0.4010 , taille 128056 octets
                    AuthorisedLists.dll 1.0.0.3921 , taille 147456 octets
                    BackgroundScanning.dll 1.0.0.3921 , taille 77824 octets
                    BHOManagement.dll 1.0.0.3980 , taille 180224 octets
                    Categories.dll 1.0.0.3090 , taille 7168 octets
                    ComponentManager.dll 1.0.0.3921 , taille 90112 octets
                    Configuration.dll 1.0.0.3980 , taille 286720 octets
                    DCManagement.dll 1.0.0.3970 , taille 94208 octets
                    DesktopMessaging.dll 1.0.0.3921 , taille 331776 octets
                    DriveProcessor.dll 1.0.0.3921 , taille 147456 octets
                    EEConsumer.dll 1.0.0.3921 , taille 110592 octets
                    FilterProcessors.dll 1.0.0.4021 , taille 233472 octets
                    FSDecomposer.dll 1.0.0.3921 , taille 98304 octets
                    ICAdapter.dll 1.0.0.3970 , taille 102400 octets
                    ICManagement.dll 1.0.0.4010 , taille 299008 octets
                    ICProcessors.dll 1.0.0.3980 , taille 258048 octets
                    LegacyConsumers.dll 1.0.0.3921 , taille 139264 octets
                    Localisation.dll 1.0.0.3921 , taille 126976 octets
                    Logging.dll 1.0.0.3921 , taille 462848 octets
                    msvcp71.dll 7.10.3077.0 , taille 499712 octets
                    msvcr71.dll 7.10.3052.4 , taille 348160 octets
                    osdp.dll 1.44.0.1461 , taille 121968 octets
                    Persistance.dll 1.0.0.3921 , taille 98304 octets
                    rkdisk.dll 1.4.1 , taille 102400 octets
                    SavAdapter.dll 1.0.0.4043 , taille 675840 octets
                    SAVI.dll 7.1.9.1461 , taille 490608 octets
                    SAVMSCM.DLL 2.00.1502 , taille 131072 octets
                    SavNeutralRes.dll 1.0.0.3090 , taille 651264 octets
                    SavRes.dll 1.0.0.4043 , taille 548864 octets
                    SavResChs.dll 1.0.0.3921 , taille 151552 octets
                    SavResCht.dll 1.0.0.3921 , taille 151552 octets
                    SavResDeu.dll 1.0.0.3921 , taille 163840 octets
                    SavResEng.dll 1.0.0.3921 , taille 151552 octets
                    SavResEsp.dll 1.0.0.3921 , taille 155648 octets
                    SavResFra.dll 1.0.0.3921 , taille 167936 octets
                    SavResIt.dll 1.0.0.3921 , taille 163840 octets
                    SavResJap.dll 1.0.0.3921 , taille 151552 octets
                    SavShellExt.dll 1.0.0.3921 , taille 315392 octets
                    ScanEditExports.dll 1.0.0.3755 , taille 29696 octets
                    ScanEditFacade.dll 1.0.0.3980 , taille 188416 octets
                    ScanManagement.dll 1.0.0.3980 , taille 237568 octets
                    Security.dll 1.0.0.3921 , taille 114688 octets
                    SIPSManagement.dll 1.0.0.3980 , taille 499712 octets
                    SophosBHO.dll 2.4.2.4020 , taille 240680 octets
                    SophosBHORes.dll 1.0.0.3800 , taille 65536 octets
                    sophos_detoured.dll 1.0.0.4030 , taille 195072 octets
                    SophtainerAdapter.dll 1.0.0.3921 , taille 110592 octets
                    SystemInformation.dll 1.0.0.3921 , taille 147456 octets
                    ThreatDetection.dll 1.0.0.4031 , taille 491520 octets
                    ThreatManagement.dll 1.0.0.4043 , taille 598016 octets
                    Translators.dll 1.0.0.3921 , taille 204800 octets
                    veex.dll 3.00.1.1461 , taille 1805424 octets
                    VirusDetection.dll 1.0.0.4010 , taille 466944 octets
                    sdccoinstaller.dll 1.0.0.3821 , taille 130104 octets
                    savonaccess.sys 3.10.0.300 , taille 93192 octets
                    SophosBootDriver.sys 1.0.0.101 , taille 20288 octets
                    SophosBootTasks.exe 2.0.0.3921 , taille 23552 octets

                    [Système]
                    Description = x64 Family 6 Model 23 Stepping 6
                    Revision = 5894
                    AddressWidth = 32
                    LoadPercentage = 13
                    Level = 6
                    DeviceID = CPU0
                    CurrentVoltage = 33
                    PowerManagementSupported = False
                    SocketDesignation = U2E1
                    StatusInfo = 3
                    Family = 190
                    Name = Intel(R) Core(TM)2 Duo CPU T8100 @ 2.10GHz
                    Manufacturer = GenuineIntel
                    DataWidth = 64
                    Stepping = 6
                    InstallDate =
                    ProcessorType = 3
                    Caption = x64 Family 6 Model 23 Stepping 6
                    L2CacheSize = 3072
                    VoltageCaps = 2
                    L3CacheSpeed = 0
                    CreationClassName = Win32_Processor
                    Architecture = 9
                    ErrorDescription =
                    Availability = 3
                    SystemName = PC-DE-CLOTHILDE
                    Role = CPU
                    NumberOfCores = 2
                    CurrentClockSpeed = 2101
                    SystemCreationClassName = Win32_ComputerSystem
                    PowerManagementCapabilities =
                    ConfigManagerUserConfig =
                    ErrorCleared =
                    L3CacheSize = 0
                    UniqueId =
                    ProcessorId = BFEBFBFF00010676
                    L2CacheSpeed = 2101
                    ExtClock = 800
                    CpuStatus = 1
                    ConfigManagerErrorCode =
                    OtherFamilyDescription =
                    Version = Modèle 7, niveau 6
                    Status = OK
                    NumberOfLogicalProcessors = 2
                    PNPDeviceID =
                    UpgradeMethod = 9
                    MaxClockSpeed = 2101
                    LastErrorCode =
                    Description =
                    CurrentTimeZone = 120
                    CSCreationClassName = Win32_ComputerSystem
                    DataExecutionPrevention_Available = True
                    ServicePackMinorVersion = 0
                    PAEEnabled = True
                    Debug = False
                    MUILanguages =
                    BuildNumber = 6001
                    TotalVisibleMemorySize = 2094780
                    DataExecutionPrevention_SupportPolicy = 2
                    Name = Microsoft® Windows Vista™ Édition Familiale Premium |C:\Windows|\Device\Harddisk0\Partition1
                    CSName = PC-DE-CLOTHILDE
                    BuildType = Multiprocessor Free
                    Manufacturer = Microsoft Corporation
                    PlusVersionNumber =
                    OSType = 18
                    InstallDate = 20080310 161027
                    RegisteredUser = clothilde
                    ProductType = 1
                    NumberOfUsers = 2
                    Caption = Microsoft® Windows Vista™ Édition Familiale Premium
                    QuantumType = 1
                    NumberOfProcesses = 77
                    LocalDateTime = 20091022 154920
                    TotalVirtualMemorySize = 4436368
                    WindowsDirectory = C:\Windows
                    OSArchitecture = 32 bits
                    SystemDrive = C:
                    CreationClassName = Win32_OperatingSystem
                    OSLanguage = 1036
                    ServicePackMajorVersion = 1
                    LargeSystemCache =
                    TotalSwapSpaceSize =
                    SizeStoredInPagingFiles = 2401980
                    Primary = True
                    SystemDirectory = C:\Windows\system32
                    NumberOfLicensedUsers = 0
                    DataExecutionPrevention_Drivers = True
                    CSDVersion = Service Pack 1
                    CountryCode = 33
                    OtherTypeDescription =
                    BootDevice = \Device\HarddiskVolume1
                    MaxProcessMemorySize = 2097024
                    SerialNumber = 89578-OEM-7332157-00061
                    QuantumLength = 1
                    OperatingSystemSKU = 3
                    MaxNumberOfProcesses = 4294967295
                    LastBootUpTime = 20091022 152001
                    FreeSpaceInPagingFiles = 2213336
                    SystemDevice = \Device\HarddiskVolume1
                    DataExecutionPrevention_32BitApplications = True
                    Organization = Hewlett-Packard
                    PlusProductID =
                    SuiteMask = 784
                    FreeVirtualMemory = 3120020
                    ForegroundApplicationBoost = 2
                    Version = 6.0.6001
                    Status = OK
                    FreePhysicalMemory = 1029224
                    EncryptionLevel = 256
                    Locale = 040c
                    Distributed = False
                    CodeSet = 1252
                    OSProductSuite = 768
                    0
                    1. je c pas comment tarrive a comprendre tout ce ke je te poste
                      J'pige pas grand-chose, en fait, mais je fais semblant de tout comprendre =)

                      Ton log s'améliore. Lance hijackthis à nouveau, coche ces lignes
                      O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
                      et
                      O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)

                      ferme les autres applis, clique sur "Fix checked" et ferme hijack. Pas besoin de redémarrer ta bécane cette fois-ci (comme quoi, l'informatique n'est pas si compliqué :-))

                      Bon, maintenant la suite:

                      1. Tu piges +/- l'anglais? (Lecture seulement)
                      2. M'as pas dit quelle est la version Sophos

                      ++
                      0
                      1. voila c fait: et si c complexe serieux je c pas comment tarrive a comprendre tout ce ke je te poste!!lol
                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 15:32:52, on 22/10/2009
                        Platform: Windows Vista SP1 (WinNT 6.00.1905)
                        MSIE: Internet Explorer v8.00 (8.00.6001.18813)
                        Boot mode: Normal

                        Running processes:
                        C:\Windows\system32\Dwm.exe
                        C:\Windows\system32\taskeng.exe
                        C:\Windows\Explorer.EXE
                        C:\Program Files\Synaptics\SynTP\SynTPStart.exe
                        C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
                        C:\WINDOWS\RtHDVCpl.exe
                        C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                        C:\Program Files\Hp\QuickPlay\QPService.exe
                        C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
                        C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
                        C:\Program Files\Windows Defender\MSASCui.exe
                        C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                        C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
                        C:\WINDOWS\System32\rundll32.exe
                        C:\WINDOWS\System32\rundll32.exe
                        C:\Program Files\Windows Sidebar\sidebar.exe
                        C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
                        C:\Program Files\Sophos\AutoUpdate\ALMon.exe
                        C:\Program Files\Windows Media Player\wmpnscfg.exe
                        C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
                        C:\Windows\system32\wuauclt.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
                        C:\Program Files\Windows Live\Toolbar\wltuser.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
                        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                        c:\Users\clothilde\Downloads\hijackthis-2.0.2.exe
                        C:\Users\CLOTHI~1\AppData\Local\Temp\hijackthis-2.0.2.exe

                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.dailymotion.com/fr
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                        R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                        O1 - Hosts: ::1 localhost
                        O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                        O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                        O2 - BHO: Sophos Web Content Scanner - {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - C:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll
                        O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
                        O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                        O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                        O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
                        O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
                        O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                        O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                        O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                        O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
                        O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
                        O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                        O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
                        O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
                        O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
                        O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
                        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                        O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                        O4 - HKLM\..\Run: [WAWifiMessage] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
                        O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                        O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
                        O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
                        O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                        O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
                        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                        O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
                        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                        O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                        O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                        O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                        O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                        O13 - Gopher Prefix:
                        O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Plugin Control) - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
                        O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
                        O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
                        O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
                        O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                        O20 - AppInit_DLLs: C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
                        O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
                        O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                        O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                        O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                        O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
                        O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
                        O23 - Service: Créateur de rapports d'état Sophos Anti-Virus (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
                        O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
                        O23 - Service: Sophos AutoUpdate Service - Sophos Plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
                        O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe
                        O23 - Service: @%SystemRoot%\System32\TUProgSt.exe,-1 (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\Windows\System32\TUProgSt.exe
                        0
                        1. g fait un hijak mais il me propose pas la page notes comme tal
                          Fais la 1ère option "do a system scan & save a log" (scan + log)

                          mdr c complexe l'informatique
                          Meuh, nan, les apparences sont trompeuses comme toujours

                          Kan je clik info il me donne ca:
                          M'voyons, suffit de ne pas cliquer un peu n'importe où... :P

                          Laisse donc tomber le scan MBAM et poste le dernier log hijack
                          0
                          1. kan je clik info il me donne ca:
                            * Trend Micro HijackThis v2.0.2 *

                            See bottom for version history.

                            The different sections of hijacking possibilities have been separated into the following groups.
                            You can get more detailed information about an item by selecting it from the list of found items OR highlighting the relevant line below, and clicking 'Info on selected item'.

                            R - Registry, StartPage/SearchPage changes
                            R0 - Changed registry value
                            R1 - Created registry value
                            R2 - Created registry key
                            R3 - Created extra registry value where only one should be
                            F - IniFiles, autoloading entries
                            F0 - Changed inifile value
                            F1 - Created inifile value
                            F2 - Changed inifile value, mapped to Registry
                            F3 - Created inifile value, mapped to Registry
                            N - Netscape/Mozilla StartPage/SearchPage changes
                            N1 - Change in prefs.js of Netscape 4.x
                            N2 - Change in prefs.js of Netscape 6
                            N3 - Change in prefs.js of Netscape 7
                            N4 - Change in prefs.js of Mozilla
                            O - Other, several sections which represent:
                            O1 - Hijack of auto.search.msn.com with Hosts file
                            O2 - Enumeration of existing MSIE BHO's
                            O3 - Enumeration of existing MSIE toolbars
                            O4 - Enumeration of suspicious autoloading Registry entries
                            O5 - Blocking of loading Internet Options in Control Panel
                            O6 - Disabling of 'Internet Options' Main tab with Policies
                            O7 - Disabling of Regedit with Policies
                            O8 - Extra MSIE context menu items
                            O9 - Extra 'Tools' menuitems and buttons
                            O10 - Breaking of Internet access by New.Net or WebHancer
                            O11 - Extra options in MSIE 'Advanced' settings tab
                            O12 - MSIE plugins for file extensions or MIME types
                            O13 - Hijack of default URL prefixes
                            O14 - Changing of IERESET.INF
                            O15 - Trusted Zone Autoadd
                            O16 - Download Program Files item
                            O17 - Domain hijack
                            O18 - Enumeration of existing protocols and filters
                            O19 - User stylesheet hijack
                            O20 - AppInit_DLLs autorun Registry value, Winlogon Notify Registry keys
                            O21 - ShellServiceObjectDelayLoad (SSODL) autorun Registry key
                            O22 - SharedTaskScheduler autorun Registry key
                            O23 - Enumeration of NT Services
                            O24 - Enumeration of ActiveX Desktop Components

                            Command-line parameters:
                            * /autolog - automatically scan the system, save a logfile and open it
                            * /ihatewhitelists - ignore all internal whitelists
                            * /uninstall - remove all HijackThis Registry entries, backups and quit
                            * /silentautuolog - the same as /autolog, except with no required user intervention

                            * Version history *

                            [v2.00.0]
                            * AnalyzeThis added for log file statistics
                            * Recognizes Windows Vista and IE7
                            * Fixed a few bugs in the O23 method
                            * Fixed a bug in the O22 method (SharedTaskScheduler)
                            * Did a few tweaks on the log format
                            * Fixed and improved ADS Spy
                            * Improved Itty Bitty Procman (processes are frozen before they are killed)
                            * Added listing of O4 autoruns from other users
                            * Added listing of the Policies Run items in O4 method, used by SmitFraud trojan
                            * Added /silentautolog parameter for system admins
                            * Added /deleteonreboot [file] parameter for system admins
                            * Added O24 - ActiveX Desktop Components enumeration
                            * Added Enhanced Security Confirguration (ESC) Zones to O15 Trusted Sites check
                            [v1.99.1]
                            * Added Winlogon Notify keys to O20 listing
                            * Fixed crashing bug on certain Win2000 and WinXP systems at O23 listing
                            * Fixed lots and lots of 'unexpected error' bugs
                            * Fixed lots of inproper functioning bugs (i.e. stuff that didn't work)
                            * Added 'Delete NT Service' function in Misc Tools section
                            * Added ProtocolDefaults to O15 listing
                            * Fixed MD5 hashing not working
                            * Fixed 'ISTSVC' autorun entries with garbage data not being fixed
                            * Fixed HijackThis uninstall entry not being updated/created on new versions
                            * Added Uninstall Manager in Misc Tools to manage 'Add/Remove Software' list
                            * Added option to scan the system at startup, then show results or quit if nothing found
                            [v1.99]
                            * Added O23 (NT Services) in light of newer trojans
                            * Integrated ADS Spy into Misc Tools section
                            * Added 'Action taken' to info in 'More info on this item'
                            [v1.98]
                            * Definitive support for Japanese/Chinese/Korean systems
                            * Added O20 (AppInit_DLLs) in light of newer trojans
                            * Added O21 (ShellServiceObjectDelayLoad, SSODL) in light of newer trojans
                            * Added O22 (SharedTaskScheduler) in light of newer trojans
                            * Backups of fixed items are now saved in separate folder
                            * HijackThis now checks if it was started from a temp folder
                            * Added a small process manager (Misc Tools section)
                            [v1.96]
                            * Lots of bugfixes and small enhancements! Among others:
                            * Fix for Japanese IE toolbars
                            * Fix for searchwww.com fake CLSID trick in IE toolbars and BHO's
                            * Attributes on Hosts file will now be restored when scanning/fixing/restoring it.
                            * Added several files to the LSP whitelist
                            * Fixed some issues with incorrectly re-encrypting data, making R0/R1 go undetected until a restart
                            * All sites in the Trusted Zone are now shown, with the exception of those on the nonstandard but safe domain list
                            [v1.95]
                            * Added a new regval to check for from Whazit hijack (Start Page_bak).
                            * Excluded IE logo change tweak from toolbar detection (BrandBitmap and SmBrandBitmap).
                            * New in logfile: Running processes at time of scan.
                            * Checkmarks for running StartupList with /full and /complete in HijackThis UI.
                            * New O19 method to check for Datanotary hijack of user stylesheet.
                            * Google.com IP added to whitelist for Hosts file check.
                            [v1.94]
                            * Fixed a bug in the Check for Updates function that could cause corrupt downloads on certain systems.
                            * Fixed a bug in enumeration of toolbars (Lop toolbars are now listed!).
                            * Added imon.dll, drwhook.dll and wspirda.dll to LSP safelist.
                            * Fixed a bug where DPF could not be deleted.
                            * Fixed a stupid bug in enumeration of autostarting shortcuts.
                            * Fixed info on Netscape 6/7 and Mozilla saying '%shitbrowser%' (oops).
                            * Fixed bug where logfile would not auto-open on systems that don't have .log filetype registered.
                            * Added support for backing up F0 and F1 items (d'oh!).
                            [v1.93]
                            * Added mclsp.dll (McAfee), WPS.DLL (Sygate Firewall), zklspr.dll (Zero Knowledge) and mxavlsp.dll (OnTrack) to LSP safelist.
                            * Fixed a bug in LSP routine for Win95.
                            * Made taborder nicer.
                            * Fixed a bug in backup/restore of IE plugins.
                            * Added UltimateSearch hijack in O17 method (I think).
                            * Fixed a bug with detecting/removing BHO's disabled by BHODemon.
                            * Also fixed a bug in StartupList (now version 1.52.1).
                            [v1.92]
                            * Fixed two stupid bugs in backup restore function.
                            * Added DiamondCS file to LSP files safelist.
                            * Added a few more items to the protocol safelist.
                            * Log is now opened immediately after saving.
                            * Removed rd.yahoo.com from NSBSD list (spammers are starting to use this, no doubt spyware authors will follow).
                            * Updated integrated StartupList to v1.52.
                            * In light of SpywareNuker/BPS Spyware Remover, any strings relevant to reverse-engineers are now encrypted.
                            * Rudimentary proxy support for the Check for Updates function.
                            [v1.91]
                            * Added rd.yahoo.com to the Nonstandard But Safe Domains list.
                            * Added 8 new protocols to the protocol check safelist, as well as showing the file that handles the protocol in the log (O18).
                            * Added listing of programs/links in Startup folders (O4).
                            * Fixed 'Check for Update' not detecting new versions.
                            [v1.9]
                            * Added check for Lop.com 'Domain' hijack (O17).
                            * Bugfix in URLSearchHook (R3) fix.
                            * Improved O1 (Hosts file) check.
                            * Rewrote code to delete BHO's, fixing a really nasty bug with orphaned BHO keys.
                            * Added AutoConfigURL and proxyserver checks (R1).
                            * IE Extensions (Button/Tools menuitem) in HKEY_CURRENT_USER are now also detected.
                            * Added check for extra protocols (O18).
                            [v1.81]
                            * Added 'ignore non-standard but safe domains' option.
                            * Improved Winsock LSP hijackers detection.
                            * Integrated StartupList updated to v1.4.
                            [v1.8]
                            * Fixed a few bugs.
                            * Adds detecting of free.aol.com in Trusted Zone.
                            * Adds checking of URLSearchHooks key, which should have only one value.
                            * Adds listing/deleting of Download Program Files.
                            * Integrated StartupList into the new 'Misc Tools' section of the Config screen!
                            [v1.71]
                            * Improves detecting of O6.
                            * Some internal changes/improvements.
                            [v1.7]
                            * Adds backup function! Yay!
                            * Added check for default URL prefix
                            * Added check for changing of IERESET.INF
                            * Added check for changing of Netscape/Mozilla homepage and default search engine.
                            [v1.61]
                            * Fixes Runtime Error when Hosts file is empty.
                            [v1.6]
                            * Added enumerating of MSIE plugins
                            * Added check for extra options in 'Advanced' tab of 'Internet Options'.
                            [v1.5]
                            * Adds 'Uninstall & Exit' and 'Check for update online' functions.
                            * Expands enumeration of autoloading Registry entries (now also scans for .vbs, .js, .dll, rundll32 and service)
                            [v1.4]
                            * Adds repairing of broken Internet access (aka Winsock or LSP fix) by New.Net/WebHancer
                            * A few bugfixes/enhancements
                            [v1.3]
                            * Adds detecting of extra MSIE context menu items
                            * Added detecting of extra 'Tools' menu items and extra buttons
                            * Added 'Confirm deleting/ignoring items' checkbox
                            [v1.2]
                            * Adds 'Ignorelist' and 'Info' functions
                            [v1.1]
                            * Supports BHO's, some default URL changes
                            [v1.0]
                            * Original release

                            A good thing to do after version updates is clear your Ignore list and re-add them, as the format of detected items sometimes changes.
                            0
                            1. voila g suppr tout ce ke tu ma dit g redémarrer et enc scan!!!mdr c complexe l'informatique.!g fait un hijak mais il me propose pas la page notes comme tal du coup jarrive pas a la poster!!
                              0
                              1. Voila g redémarrer l'ordi et il ma encore demander de faire un scan!!!

                                C'est à cause de cette ligne:
                                O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
                                MBAM n'a pas fini - pour une raison ou une autre - son boulot et se reprogramme lui-même au démarrage. Il faudrait le laisser finir, théoriquement.

                                Oui, tu fais "do a system scan only" et dans la fenêtre qui s'ouvre tu cocheras les lignes mentionnées.
                                0
                                1. voila g redémarrer l'ordi et il ma encore demander de faire un scan!!!
                                  g réouvert hijak mais il ne me propose pas ce ke tu ma demandé de décocher il me met juste la page avec do a systemescan, systeme scan only,view the lists of backups....etc
                                  0
                                  1. Ah, oui, coche cette ligne aussi avec les autres:

                                    - O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)

                                    avant de faire fix checked
                                    0
                                    1. lol tu vas me trouver bete mais kan tu me dit redemarre tu me dit l'ordi ou un nouvo scan mbam????lol
                                      0
                                      1. Mmmm, MBAM n'a pas encore fini, redémarre encore une fois pour lui permettre de finir.

                                        Après le redémarrage: ouvre à nouveau hijackthis, fais un scan. Coche les lignes suivantes:

                                        - O4 - HKCU\..\Run: [Software Informer] "C:\Program Files\Software Informer\softinfo.exe" -autorun
                                        - O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                        - O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                        - O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\\Messengermsnmsgr.exe" /background
                                        - O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
                                        - O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\\Reader9.0\Reader\Reader_sl.exe"

                                        Si tu n'utilises pas les raccourcis clavier HP (et je parie que non, car complètment inutiles), coche également ceci:
                                        - O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start

                                        Ferme toutes les autres applications (y compris ton navigateur Internet ou l'explorateur de fichiers) en laissant uniquement hijack ouvert

                                        Clique sur "fix checked". Ferme par la suite hijackthis et redémarre

                                        Reposte un nouveau hijackthis.

                                        Et dis-moi également quelle est ta version Sophos (tu devrais dénicher quelque part un "About Sophos" ou "A propos de" dans son menu)

                                        Pas de nouveau scan disque au démarrage, n'est-ce pas ? La vie est belle :-)

                                        ++
                                        0
                                        • 1
                                        • 2
                                        • 3