Application win 32 invalide malgre demarches

Bonjour,

J'ai à nouveau des problèmes avec le virus baggle très certainement seulement malgré l'utilisation de la dernière version (11.21) d'elibagla et de multiples scan mon antivirus antivir reste toujours en difficulté
Par ailleurs ma synchronisation avec mon palm ne peut plus se faire ...
Quelqu'un aurait il une solution à me proposer ? peut etre ai je mal effectué les étapes des procédures decrites ds le forum?

Merci pour votre aide !! ;)
Configuration: Windows Vista
Firefox 2.0.0.13

23 réponses

Résumé de la discussion

Problème récurrent : un malware décrit comme baggle persiste malgré l’utilisation de la dernière version d’un outil dédié et de multiples scans, et la synchronisation avec le Palm ne fonctionne plus. Plusieurs éléments de réponse suggèrent des étapes de diagnostic et de correction, notamment la vérification des définitions et des analyses MBAM, puis l’envoi des rapports pour affiner le diagnostic. D'autres propositions évoquent l’emploi de HijackThis pour générer un log système et guider ensuite des actions sur les éléments de démarrage, les barres d’outils et les programmes suspects. Des éléments détectés, tels que des barres d’outils et des services système suspects, peuvent nécessiter une désactivation manuelle et une révision des autorisations après HijackThis.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Bonjour,

    déjà une partie en automatique;

    relance OTMoveIt, clique sur le bouton cleanUP.

    Normalement l'ordi va redémarrer.

    reste : elibagla, systemscan, navilog et toolscleaner
    0
    1. Contributeur sécurité
      Bpnjour,

      on va éliminer à la main.

      Clique sur Unselect all

      Relance SystemScan

      Coche uniquement ces cases :

      - Recent Files, 30 days

      Puis clic sur scan now, sois patient.
      Une fois le scan terminé, un rapport va s'ouvrir, copie et colle son contenu ici .

      @+
      N'acceptez jamais une désinfection par mp.
      0
      1. slt,

        VOICI LE RAPPORT :

        SystemScan - www.suspectfile.com - ver. 3.5.5 (code: holifay & bReAkdOWn)

        Running on: Windows VISTA (6000.6.0)
        System directory: C:\Windows
        SystemScan file: C:\Users\Grégory\Desktop\sys1128.exe
        Running in: User mode
        Date: 12/04/2008
        Time: 11:51:29

        Output limited to:
        -Recent files
        -Suspicious Files

        ===================== RECENT FILES =====================

        Showing files newer than 30 days

        ----- recent files in C:\
        19/03/2008 17:08:40 13030 byte 24 days old -- PDOXUSRS.NET
        03/04/2008 01:13:31 (DIR) 0 byte 9 days old -- Diskeeper
        07/04/2008 14:50:27 9948 byte 5 days old -- resolve.log
        07/04/2008 15:18:32 3574 byte 5 days old -- avenger.txt
        07/04/2008 15:19:27 (DIR) 0 byte 5 days old -- Avenger
        07/04/2008 15:22:45 (DIR) 0 byte 5 days old -- prog téléchargés
        08/04/2008 22:50:12 2799 byte 4 days old -- InfoSat2.txt
        09/04/2008 16:51:57 2822 byte 3 days old -- InfoSat.txt
        09/04/2008 21:00:56 (DIR) 0 byte 3 days old -- _OTMoveIt
        10/04/2008 22:23:05 2515 byte 2 days old -- fixnavi.txt
        11/04/2008 09:59:01 (DIR) 0 byte 1 days old -- Program Files
        11/04/2008 09:59:02 (DIR) 0 byte 1 days old -- ProgramData
        11/04/2008 20:30:16 1922629632 byte 1 days old -- pagefile.sys
        11/04/2008 20:30:52 10311 byte 1 days old -- VCIError.log
        12/04/2008 00:15:08 (DIR) 0 byte 0 days old -- Windows
        12/04/2008 00:18:38 (DIR) 0 byte 0 days old -- System Volume Information
        12/04/2008 10:38:00 (DIR) 0 byte 0 days old -- Mes Patients

        ----- recent files in C:\Windows\
        19/03/2008 16:34:27 (DIR) 0 byte 24 days old -- Speech
        20/03/2008 07:59:33 (DIR) 0 byte 23 days old -- Lhsp
        23/03/2008 05:28:38 (DIR) 0 byte 20 days old -- registration
        02/04/2008 23:39:46 (DIR) 0 byte 10 days old -- Help
        03/04/2008 09:34:50 69 byte 9 days old -- NeroDigital.ini
        04/04/2008 23:16:25 (DIR) 0 byte 8 days old -- Downloaded Installations
        06/04/2008 18:56:34 (DIR) 0 byte 6 days old -- erdnt
        06/04/2008 20:12:53 819200 byte 6 days old -- gmer.dll
        06/04/2008 20:12:53 80 byte 6 days old -- gmer_uninstall.cmd
        07/04/2008 14:11:11 (DIR) 0 byte 5 days old -- PIF
        07/04/2008 14:52:01 250 byte 5 days old -- gmer.ini
        07/04/2008 14:56:16 0 byte 5 days old -- gmer.reg
        07/04/2008 14:56:27 0 byte 5 days old -- gmer.bat
        07/04/2008 15:10:30 (DIR) 0 byte 5 days old -- Minidump
        08/04/2008 23:22:57 63 byte 4 days old -- vbaddin.ini
        08/04/2008 23:25:13 (DIR) 0 byte 4 days old -- AppPatch
        08/04/2008 23:30:15 (DIR) 0 byte 4 days old -- winsxs
        09/04/2008 12:26:41 (DIR) 0 byte 3 days old -- Tasks
        09/04/2008 16:32:00 (DIR) 0 byte 3 days old -- Debug
        11/04/2008 11:27:37 (DIR) 0 byte 1 days old -- BDOSCAN8
        11/04/2008 20:25:24 3421 byte 1 days old -- bthservsdp.dat
        11/04/2008 20:25:25 1294 byte 1 days old -- SchedLgU.Txt
        11/04/2008 20:28:36 395282 byte 1 days old -- ntbtlog.txt
        11/04/2008 20:36:11 19671 byte 1 days old -- WindowsUpdate.log
        12/04/2008 00:15:08 (DIR) 0 byte 0 days old -- Downloaded Program Files
        12/04/2008 09:51:35 67584 byte 0 days old -- bootstat.dat
        12/04/2008 09:53:11 (DIR) 0 byte 0 days old -- inf
        12/04/2008 09:53:11 (DIR) 0 byte 0 days old -- System32
        12/04/2008 10:09:11 (DIR) 0 byte 0 days old -- Installer
        12/04/2008 11:50:15 (DIR) 0 byte 0 days old -- Temp
        12/04/2008 11:50:50 (DIR) 0 byte 0 days old -- Prefetch

        ----- recent files in C:\Windows\Downloaded Program Files\

        ----- recent files in C:\Windows\system\

        ----- recent files in C:\Windows\system32\
        22/03/2008 20:29:51 (DIR) 0 byte 21 days old -- Samsung_USB_Drivers
        23/03/2008 05:29:04 (DIR) 0 byte 20 days old -- config
        23/03/2008 05:30:09 (DIR) 0 byte 20 days old -- wbem
        02/04/2008 22:37:20 (DIR) 0 byte 10 days old -- DRVSTORE
        02/04/2008 23:23:39 (DIR) 0 byte 10 days old -- oodag
        06/04/2008 07:56:20 19836024 byte 6 days old -- mrt.exe
        08/04/2008 23:25:16 (DIR) 0 byte 4 days old -- migration
        08/04/2008 23:25:18 (DIR) 0 byte 4 days old -- fr-FR
        08/04/2008 23:28:23 491864 byte 4 days old -- FNTCACHE.DAT
        08/04/2008 23:29:19 (DIR) 0 byte 4 days old -- catroot
        08/04/2008 23:29:19 (DIR) 0 byte 4 days old -- catroot2
        09/04/2008 12:26:41 (DIR) 0 byte 3 days old -- Tasks
        09/04/2008 21:00:56 (DIR) 0 byte 3 days old -- drivers
        12/04/2008 09:53:11 735670 byte 0 days old -- perfh00C.dat
        12/04/2008 09:53:11 1637270 byte 0 days old -- PerfStringBackup.INI
        12/04/2008 09:53:11 120642 byte 0 days old -- perfc009.dat
        12/04/2008 09:53:11 139434 byte 0 days old -- perfc00C.dat
        12/04/2008 09:53:11 648736 byte 0 days old -- perfh009.dat
        12/04/2008 10:51:29 2368 byte 0 days old -- 7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
        12/04/2008 10:51:30 2368 byte 0 days old -- 7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0

        ----- recent files in C:\Windows\system32\drivers\
        06/04/2008 20:12:53 86097 byte 6 days old -- gmer.sys
        09/04/2008 19:12:01 61632 byte 3 days old -- avipbb.sys

        ----- recent files in C:\Windows\temp\
        11/04/2008 11:38:14 13946 byte 1 days old -- lpksetup-20080411-113711-0.log
        11/04/2008 11:38:15 622 byte 1 days old -- lpksetup-20080411-113814-0.log

        ----- recent files in C:\Program Files\
        22/03/2008 18:55:45 (DIR) 0 byte 21 days old -- Samsung
        22/03/2008 20:27:04 (DIR) 0 byte 21 days old -- InstallShield Installation Information
        26/03/2008 23:36:47 (DIR) 0 byte 17 days old -- Mozilla Firefox
        02/04/2008 22:27:13 (DIR) 0 byte 10 days old -- Common Files
        02/04/2008 22:47:09 (DIR) 0 byte 10 days old -- Microsoft Windows OneCare Live
        04/04/2008 23:16:18 (DIR) 0 byte 8 days old -- Adobe
        04/04/2008 23:27:22 (DIR) 0 byte 8 days old -- Ripp-it_AM
        04/04/2008 23:28:39 (DIR) 0 byte 8 days old -- Windows Live Safety Center
        07/04/2008 09:04:22 (DIR) 0 byte 5 days old -- neuf Talk
        08/04/2008 23:24:57 (DIR) 0 byte 4 days old -- Apoint
        08/04/2008 23:25:16 (DIR) 0 byte 4 days old -- Internet Explorer
        08/04/2008 23:25:19 (DIR) 0 byte 4 days old -- Windows Mail
        09/04/2008 17:04:55 (DIR) 0 byte 3 days old -- Trend Micro
        09/04/2008 19:09:58 (DIR) 0 byte 3 days old -- Avira
        10/04/2008 22:23:16 (DIR) 0 byte 2 days old -- Navilog1
        11/04/2008 09:59:05 (DIR) 0 byte 1 days old -- Malwarebytes' Anti-Malware
        11/04/2008 10:11:06 (DIR) 0 byte 1 days old -- CCleaner
        12/04/2008 10:36:16 (DIR) 0 byte 0 days old -- VisualCab

        ----- recent files in C:\Program Files\Common Files\
        20/03/2008 23:05:04 (DIR) 0 byte 23 days old -- Application
        20/03/2008 23:05:54 (DIR) 0 byte 23 days old -- Ankiro
        28/03/2008 23:46:34 (DIR) 0 byte 15 days old -- Windows Media Metering

        ----- recent files in C:\Users\Grégory\AppData\Roaming\
        19/03/2008 01:24:01 (DIR) 0 byte 24 days old -- AlauxSoft
        20/03/2008 23:08:47 (DIR) 0 byte 23 days old -- SPAMfighter
        23/03/2008 13:06:42 (DIR) 0 byte 20 days old -- Samsung
        29/03/2008 00:00:25 (DIR) 0 byte 14 days old -- Windows Media Metering
        05/04/2008 21:26:40 (DIR) 0 byte 7 days old -- Adobe
        11/04/2008 09:59:19 (DIR) 0 byte 1 days old -- Malwarebytes

        ----- recent files in C:\Users\GRGORY~1\AppData\Local\Temp\
        09/04/2008 16:55:57 134 byte 3 days old -- 1261250.od
        09/04/2008 16:55:57 0 byte 3 days old -- CVR3EC2.tmp.cvr
        09/04/2008 17:10:26 5270 byte 3 days old -- logcalb2
        09/04/2008 17:12:52 134 byte 3 days old -- 2275921.od
        09/04/2008 17:12:52 0 byte 3 days old -- CVRBA51.tmp.cvr
        09/04/2008 17:16:09 (DIR) 0 byte 3 days old -- outlook logging
        09/04/2008 17:45:12 7776 byte 3 days old -- logcalb3
        09/04/2008 17:46:52 134 byte 3 days old -- 4316906.od
        09/04/2008 17:46:52 0 byte 3 days old -- CVRDEEA.tmp.cvr
        09/04/2008 17:58:00 (DIR) 0 byte 3 days old -- AVSETUP_47fce788
        09/04/2008 17:58:51 134 byte 3 days old -- 5035671.od
        09/04/2008 17:58:51 0 byte 3 days old -- CVRD697.tmp.cvr
        09/04/2008 18:54:16 12368 byte 3 days old -- logcalb4
        09/04/2008 20:32:02 134 byte 3 days old -- 5300812.od
        09/04/2008 20:32:02 0 byte 3 days old -- CVRE22D.tmp.cvr
        09/04/2008 20:36:14 113842 byte 3 days old -- logcalb5
        09/04/2008 20:47:26 (DIR) 0 byte 3 days old -- MessengerCache
        09/04/2008 21:46:38 0 byte 3 days old -- CVR2F39.tmp.cvr
        09/04/2008 21:46:38 134 byte 3 days old -- 9776953.od
        09/04/2008 22:26:39 7250 byte 3 days old -- logcalb6
        09/04/2008 22:26:52 134 byte 3 days old -- 12190750.od
        09/04/2008 22:26:52 0 byte 3 days old -- CVR41E.tmp.cvr
        09/04/2008 22:52:38 7250 byte 3 days old -- logcalb7
        10/04/2008 06:04:49 0 byte 2 days old -- CVR4AD5.tmp.cvr
        10/04/2008 06:04:49 134 byte 2 days old -- 39668437.od
        10/04/2008 06:09:40 5090 byte 2 days old -- logcalb8
        10/04/2008 07:02:29 1400 byte 2 days old -- wmplog00.sqm
        10/04/2008 21:49:22 0 byte 2 days old -- CVR5A23.tmp.cvr
        10/04/2008 21:49:22 134 byte 2 days old -- 53303843.od
        10/04/2008 22:24:00 19484 byte 2 days old -- logcalb9
        11/04/2008 09:09:19 0 byte 1 days old -- CVRDFEC.tmp.cvr
        11/04/2008 09:09:19 134 byte 1 days old -- 94101484.od
        11/04/2008 09:09:21 0 byte 1 days old -- CVRE8B6.tmp.cvr
        11/04/2008 09:09:21 134 byte 1 days old -- 94103734.od
        11/04/2008 09:24:43 8198 byte 1 days old -- logcalb10
        11/04/2008 12:34:38 0 byte 1 days old -- CVRDED5.tmp.cvr
        11/04/2008 12:34:38 134 byte 1 days old -- 4382437.od
        11/04/2008 12:45:29 5738 byte 1 days old -- logcalb11
        11/04/2008 16:05:18 0 byte 1 days old -- CVRBCAD.tmp.cvr
        11/04/2008 16:05:18 134 byte 1 days old -- 17022125.od
        11/04/2008 16:05:19 134 byte 1 days old -- 17023453.od
        11/04/2008 16:05:19 0 byte 1 days old -- CVRC1DD.tmp.cvr
        11/04/2008 20:08:58 24104 byte 1 days old -- logcalb12
        11/04/2008 20:13:45 0 byte 1 days old -- CVR3519.tmp.cvr
        11/04/2008 20:13:45 134 byte 1 days old -- 31929625.od
        11/04/2008 20:22:28 1394 byte 1 days old -- wmplog01.sqm
        11/04/2008 20:31:20 1658 byte 1 days old -- wmplog02.sqm
        11/04/2008 20:32:43 0 byte 1 days old -- CVR7238.tmp.cvr
        11/04/2008 20:32:43 134 byte 1 days old -- 160328.od
        11/04/2008 20:36:03 865 byte 1 days old -- jusched.log
        12/04/2008 00:19:45 273 byte 0 days old -- libFNP_events.log
        12/04/2008 00:40:45 (DIR) 0 byte 0 days old -- VBE
        12/04/2008 00:40:52 (DIR) 0 byte 0 days old -- Google Toolbar
        12/04/2008 01:27:02 (DIR) 0 byte 0 days old -- MYINK
        12/04/2008 02:13:33 8288 byte 0 days old -- logcalb13
        12/04/2008 09:51:28 1272 byte 0 days old -- wmplog03.sqm
        12/04/2008 09:52:43 31832 byte 0 days old -- Grégory.bmp
        12/04/2008 09:57:41 180224 byte 0 days old -- ~DFA003.tmp
        12/04/2008 09:57:41 512 byte 0 days old -- ~DFA00A.tmp
        12/04/2008 09:57:46 180224 byte 0 days old -- ~DF2C6.tmp
        12/04/2008 09:57:46 512 byte 0 days old -- ~DF2F7.tmp
        12/04/2008 09:58:34 0 byte 0 days old -- CVR376C.tmp.cvr
        12/04/2008 09:58:34 134 byte 0 days old -- 48510828.od
        12/04/2008 09:58:36 0 byte 0 days old -- CVR3EAF.tmp.cvr
        12/04/2008 09:58:36 134 byte 0 days old -- 48512687.od
        12/04/2008 09:58:48 (DIR) 0 byte 0 days old -- Journalisation d'Outlook
        12/04/2008 10:01:20 1196032 byte 0 days old -- ~DFCD1F.tmp
        12/04/2008 10:12:34 134 byte 0 days old -- 49350890.od
        12/04/2008 10:12:34 0 byte 0 days old -- CVR8EA.tmp.cvr
        12/04/2008 11:40:26 16384 byte 0 days old -- ~DFCCFA.tmp
        12/04/2008 11:50:16 36 byte 0 days old -- systemscan.ini
        12/04/2008 11:50:18 (DIR) 0 byte 0 days old -- nsx7B2C.tmp
        12/04/2008 11:50:18 16384 byte 0 days old -- ~DFD653.tmp
        12/04/2008 11:50:26 14134 byte 0 days old -- logcalb14

        ===================== SUSPICIOUS FILES =====================
        EXE and DLL files packed with runtime packers, found in: C:\; C:\Windows\; C:\Windows\system32\

        C:\Windows\FAVPID.DLL --> is compressed with UPX
        C:\Windows\system32\Uharc.exe --> is compressed with UPX

        ==========================================
        Scan completed in 0,3 minutes
        End of report

        ~~~~~~~~~~~~~~~~~~~~~-----CREDITS-----~~~~~~~~~~~~~~~~~~~~~
        SystemScan uses some freeware tools that remain property of their authors:

        * SteelWerX Registry Console Tool, Who Am I (Bobby Flekman: www.xs4all.nl/~fstaal01) --> "Registry scan", "PC accounts "
        * dumphive (Markus Stephany)--> "Registry scan"
        * Listdlls (M.Russinovich, B.Cogswell: www.sysinternals.com) --> "Loaded modules"
        * Catchme & MBR Rootkit detector (gmer: www.gmer.net) --> "Hidden objects", "Alternate Data Streams" & "Master Boot Record"
        ---> NOTE: SystemScan integrates "The Avenger" from Swandog46 (http://swandog46.geekstogo.com) to allow you to remove malwares found in this log

        Thanks to all of them for their hard work
        0
    2. Contributeur sécurité
      Bonsoir Lyonnais

      Avec UAC désactivé + Clique-droit sur "ToolsCleaner.exe" > "Exécuter en tant qu'administrateur".
      ToolsCleaner (A.Rothstein) http://a-rothstein.changelog.fr/TC/ToolsCleaner2.exe
      .... fonctionne très bien.

      Peut-être essayer Erase!Beta de A.Rothstein
      Mais n'ayant pas accès à l'espace Zeb-Sécu. le lien m'est inaccessible.
      C'est une version bêta.

      Al.
      0
      1. UAC et administrateur compris cela pose problème mais est ce que Vista est compatible avec cette application :)
        0
    3. Contributeur sécurité
      re,

      relance Toolscleaner avec un clic droit et exécuter en tant qu'administrateur.

      poste le rapport.
      0
      1. non même en administrateur le programme ne répond pas et reste apparemment bloqué
        0
    4. slt,
      Tcleaner ne fonctionne pas le programme finit par rester sans réponse je te joins le rapport de Hijackthis

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 00:27, on 2008-04-12
      Platform: Windows Vista (WinNT 6.00.1904)
      MSIE: Internet Explorer v7.00 (7.00.6000.16643)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\Dwm.exe
      C:\WINDOWS\system32\taskeng.exe
      C:\Windows\Explorer.EXE
      C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
      D:\Program Files\SPAMfighter\SFAgent.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Neuf\Media Center\MediaCenter.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Windows\ehome\ehtray.exe
      D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\Program Files\Palm\Hotsync.exe
      D:\Program Files\MyInk\My Ink Resident.exe
      C:\Program Files\My Book\WD Backup\uBBMonitor.exe
      C:\Windows\ehome\ehmsas.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Windows\System32\mobsync.exe
      C:\WINDOWS\system32\taskeng.exe
      C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
      C:\Windows\system32\wbem\unsecapp.exe
      C:\Program Files\Neuf\Media Center\httpd\httpd.exe
      C:\Program Files\Neuf\Media Center\httpd\httpd.exe
      C:\PROGRA~1\MICROS~4\Office12\OUTLOOK.EXE
      C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.neuf.fr/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://windowsxlive.net/
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
      O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\GOOGLE~1.DLL
      O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll
      O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
      O4 - HKLM\..\Run: [SPAMfighter Agent] "D:\Program Files\SPAMfighter\SFAgent.exe" update delay 60
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [Neuf Media Center] "C:\Program Files\Neuf\Media Center\MediaCenter.exe"
      O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
      O4 - Startup: BOINC Manager.lnk = D:\Program Files\BOINC\boincmgr.exe
      O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\Palm\Hotsync.exe
      O4 - Global Startup: My Ink Resident.lnk = ?
      O4 - Global Startup: WD Backup Monitor.lnk = C:\Program Files\My Book\WD Backup\uBBMonitor.exe
      O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      O8 - Extra context menu item: Chercher avec Copernic Agent - res://C:\Program Files\Copernic Agent\CopernicAgentExt.rdl/INTEGRATION_MENU_SEARCHEXT
      O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
      O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE12\EXCEL.EXE/3000
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
      O8 - Extra context menu item: Transfert par Image Converter 2 Plus - C:\Program Files\Sony\Image Converter 2\menu.htm
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
      O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
      O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
      O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
      O13 - Gopher Prefix:
      O15 - Trusted Zone: https://www.google.fr/?gws_rd=ssl
      O15 - Trusted Zone: https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
      O15 - Trusted Zone: *.sony-europe.com
      O15 - Trusted Zone: *.sonystyle-europe.com
      O15 - Trusted Zone: *.vaio-link.com
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - http://update.microsoft.com/...
      O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
      O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
      O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
      O23 - Service: Diskeeper - Diskeeper Corporation - D:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
      O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
      O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
      O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
      O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
      O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
      O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
      O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
      O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - D:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
      O23 - Service: SPAMfighter Update Service - SPAMfighter ApS - D:\Program Files\SPAMfighter\sfus.exe
      O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
      O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
      O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
      O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
      O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
      O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
      O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
      O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
      O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
      O23 - Service: VAIO Cooporated Initialisation (VCI) - Sony Corporation - C:\Program Files\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe
      O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
      O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
      O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
      O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
      O23 - Service: Service de lancement de WlanCfg (Wlancfg) - Unknown owner - C:\Program Files\AOLbox\Gateway\wlancfg.exe (file missing)
      O24 - Desktop Component 1: (no name) - C:\Program Files\Mozilla Firefox\Wallpaper_dynamique_V4_1024x768\wallpaper.htm
      0
      1. Contributeur sécurité
        Re,

        Il doit y avoir un réglage du type préférences ou options pour changer ta virgule en point.

        On va prendre un point de restauration propre.

        Ouvre ce lien :

        http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/fr_docid/20020830101856924

        Dans un premier temps tu l'utilises pour désactiver ta restauration système.

        Tu fermes la fenêtre.

        Dans un deuxième temps, tu réactive ta restauration système.

        Tu utilises MBAM et CCleaner une fois par mois (ou toutes les 3 semaines).

        Tu utilises ATF Cleaner tous les jours.

        * Télécharge ToolsCleaner de A.Roshtein sur ton Bureau.

        http://a-rothstein.changelog.fr/TC/ToolsCleaner2.exe
        hxxp://pagesperso-orange.fr/AceRothstein/ToolsCleaner2.exe

        * Clique sur Recherche et laisse le scan se terminer.

        * Clique, sur Suppression pour finaliser.

        * Tu peux, si tu le souhaites, te servir des Options facultatives.

        * Clique sur Quitter, pour que le rapport puisse se créer.

        * Poste moi le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur( C:\).
        0
        1. En tout cas Lyonnais je te remercie beaucoup pour le temps et la patience dont tu as fait preuve pour m'aider et indiquer les procédures de manière si pédagogique :)

          C'est à souligner c extremement sympa de ta part

          Merci beaucoup
          0
      2. Contributeur sécurité
        Bonjour,

        le fichier de Bit Defender correspond à SystemScan. Donc pas de souci.

        Pour MBAM, tu le réopuivres. Tu as un onglet log/rapports.

        Tu devrais y trouver le tiens. Essaye de le poster en réponse.
        0
        1. salut,

          bon j'ai réussi à retrouver le fichier du rapport de MBAM mais en mode sans echec, l'ai déplacé et retrouvé en mode normal voici le contenu :

          Malwarebytes' Anti-Malware 1.11
          Database version: 611

          Scan type: Full Scan (C:\|D:\|)
          Objects scanned: 217377
          Time elapsed: 1 hour(s), 0 minute(s), 48 second(s)

          Memory Processes Infected: 0
          Memory Modules Infected: 0
          Registry Keys Infected: 0
          Registry Values Infected: 0
          Registry Data Items Infected: 0
          Folders Infected: 0
          Files Infected: 1

          Memory Processes Infected:
          (No malicious items detected)

          Memory Modules Infected:
          (No malicious items detected)

          Registry Keys Infected:
          (No malicious items detected)

          Registry Values Infected:
          (No malicious items detected)

          Registry Data Items Infected:
          (No malicious items detected)

          Folders Infected:
          (No malicious items detected)

          Files Infected:
          C:\System Volume Information\_restore{A86CFCA8-1E78-4E36-8351-E4E4DF02E898}\RP410\A0075640.exe (Rogue.Installer) -> No action taken.

          Actuellement je n'ai plus de souci particulier à part un changement dans l'utilisation du point ou de la virgule dans excel concernant les chiffres (mode anglais vs mode "français")
          0
      3. Contributeur sécurité
        re,

        Lis bien et exécute cette manip dans l’ordre.

        #Télécharge et installe ces logiciels (si tu ne les as pas) pour les 3 premiers
        mets les à jour, comme indiqué dans les démos ou tutos.

        Ne les utilise pas tout de suite.

        Antispywares et autres :

        Télécharge Malwarebytes' Anti-Malware (MBAM) et enregistre le sur ton bureau à partir de ce lien :

        https://www.malwarebytes.com/

        A la fin du téléchargement, ferme toutes les fenêtres et programmes, y compris celui-ci.

        Double-clique sur l'icône Download_mbam-setup.exe sur ton bureau pour démarrer le programme d'installation.

        Pendant l'installation, suis les indications (en particulier le choix de la langue et l'autorisation d'accession à Internet). N'apporte aucune modification aux réglages par défaut et, en fin d'installation, vérifie que les options Update Malwarebytes' Anti-Malware et Launch Malwarebytes' Anti-Malware sont cochées.

        MBAM démarrera automatiquement et enverra un message demandant à mettre à jour le programme avant de lancer une analyse. Comme MBAM se met automatiquement à jour en fin d'installation, clique sur OK pour fermer la boîte de dialogue.

        Nettoyeurs (de fichiers inutiles) et autres :

        *Ccleaner (gratuit)
        Téléchargement :
        https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html
        Tuto :
        https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php

        Lors de l’installation, [décoche] l’option qui t’installerait la barre Yahoo !

        ========================================
        ->Affiche tous les fichiers et dossiers :
        clique sur démarrer/panneau de configuration (en affichage classique)/option des dossiers/affichage

        [Coche] « afficher les dossiers et fichiers cachés »

        [Décoche] la case « Masquer les fichiers protégés du système d'exploitation (recommandé) »

        [Décoche] « masquer les extensions dont le type est connu »

        Puis fais [appliquer] pour valider les changements.

        Et [Ok]
        .

        =======================================

        ->Démarre en mode sans échec :
        Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
        Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec
        puis tape « entrée ».
        Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
        (Si F8 ne marche pas utilise la touche F5).

        ========================================
        ->Lance CCleaner.

        Suppression des fichiers temporaires

        Va dans la section "Options" situé dans la marge gauche.
        Décoche "Avancé"
        Retourne ensuite dans la section "Nettoyeur"
        Fais bien attention de cocher toutes ces cases dans la marge gauche (Internet Explorer/Windows Explorer/Système)
        • Clique sur [Analyse]
        • Patiente le temps du scan, qui peut prendre un peu de temps si c'est la première fois.
        • Une fois le scan terminé, clique sur [Lancer le Nettoyage]

        ========================================
        Lance Malwarebytes AntiMalware

        Dans l'onglet analyse, vérifie que "Exécuter un examen complet" est coché et clique sur le bouton Rechercher pour démarrer l'analyse.

        MBAM analyse ton ordinateur. L'analyse peut prendre un certain teps. Il suffit de vérifier de temps en temps son avancement.

        A la fin de l'analyse, un message s'affiche indiquant la fin de l'analyse. Clique sur OK pour poursuivre.

        Si des malwares ont été détectés, leur liste s'affiche.
        En cliquant sur Suppression (?) , MBAM va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.

        MBAM va ouvrir le bloc-notes et y copier le rapport d'analyse. Ferme le bloc-note. (Le rapport peut être retrouvé sous l'onglet Rapports/logs)

        Ferme MBAM en cliquant sur Quitter.
        ========================================

        ->Relance CCleaner.
        Suppression des incohérences du registre

        • Clique sur l'icône [Erreurs] situés dans la marge à gauche
        • Puis clique sur [Analyser les erreurs]
        • Patiente pendant que CCleaner scan ton registre.
        • Une fois le scan terminé, coche toutes les entrèes qu'il t'aura trouvée.
        • Tu peux cliquer ensuite sur [Corriger les erreurs].

        Si tu n'est pas sur de ce que tu fais, tu peux choisir de sauvegarder les entrées cochées pour les restaurer ultérieurement.
        ========================================
        ->Vide ta Corbeille.
        ========================================
        ->Redémarre en mode normal,

        - > Ouvre ce lien pour scanner ton PC avec un BitDefender en ligne (uniquement sous Internet Explorer) :

        https://www.bitdefender.com/toolbox/

        Utilisation :
        Cliquer sur "J'accepte" puis accepter également l'ActiveX bloqué par la barre anti-popup du SP2 qui clignotera en haut et l'installer.
        Ensuite, cliquer sur "Cliquez ici pour scanner".
        Patienter jusqu'à la fin du scan qui peut durer assez longtemps...

        Copier/coller le rapport entier sur le forum.

        Tutoriel en images ici : http://pageperso.aol.fr/rginformatique/mapage/defender.htm (merci à Balltrap34 pour cette réalisation)
        [Recoche] la case « Masquer les fichiers protégés du système d'exploitation (recommandé) »

        Relance Hijackthis et copie/colle un nouveau rapport sur le forum.

        Et dis moi ou en sont tes problèmes.
        0
        1. slt,

          concernant malware, il a trouvé un élément qu'il a corrigé mais je ne retrouve pas le rapport ds Rapport/logs

          le scan de bitdefender

          BitDefender Online Scanner

          Rapport d'analyse généré à: Fri, Apr 11, 2008 - 12:30:30

          Voie d'analyse: C:\;D:\;E:\;F:\;G:\;H:\;

          Statistiques

          Temps

          01:01:40

          Fichiers

          186837

          Directoires

          22428

          Secteurs de boot

          0

          Archives

          2499

          Paquets programmes

          20135

          Résultats

          Virus identifiés

          1

          Fichiers infectés

          1

          Fichiers suspects

          0

          Avertissements

          0

          Désinfectés

          0

          Fichiers effacés

          1

          Info sur les moteurs

          Définition virus

          1137585

          Version des moteurs

          AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)

          Analyse des plugins

          16

          Archive des plugins

          41

          Unpack des plugins

          7

          E-mail plugins

          6

          Système plugins

          5

          Paramètres d'analyse

          Première action

          Désinfecté

          Seconde Action

          Supprimé

          Heuristique

          Oui

          Acceptez les avertissements

          Oui

          Extensions analysées

          exe;com;dll;ocx;scr;bin;dat;386;vxd;sys;wdm;cla;class;ovl;ole;hlp;doc;dot;xls;ppt;wbk;wiz;pot;ppa;xla;xlt;vbs;vbe;mdb;rtf;htm;hta;html;xml;xtp;php;asp;js;shs;chm;lnk;pif;prc;url;smm;pfd;msi;ini;csc;cmd;bas;

          Excludez les extensions

          Analyse d'emails

          Oui

          Analyse des Archives

          Oui

          Analyser paquets programmes

          Oui

          Analyse des fichiers

          Oui

          Analyse de boot

          Oui

          Fichier analysé

          Statut

          C:\Users\Grégory\Desktop\sys73766.exe=>(NSIS o)=>zlib_nsis0011

          Infecté par: DeepScan:Generic.Zlob.38B68927

          C:\Users\Grégory\Desktop\sys73766.exe=>(NSIS o)=>zlib_nsis0011

          Echec de la désinfection

          C:\Users\Grégory\Desktop\sys73766.exe=>(NSIS o)=>zlib_nsis0011

          Supprimé

          C:\Users\Grégory\Desktop\sys73766.exe=>(NSIS o)

          Echec de la mise à jour
          0
      4. voici l'e rapport de virus total

        Fichier Uharc.exe reçu le 2008.04.10 23:39:52 (CET)Antivirus Version Dernière mise à jour Résultat
        AhnLab-V3 2008.4.10.2 2008.04.10 -
        AntiVir 7.6.0.81 2008.04.10 -
        Authentium 4.93.8 2008.04.10 -
        Avast 4.8.1169.0 2008.04.10 -
        AVG 7.5.0.516 2008.04.10 -
        BitDefender 7.2 2008.04.10 -
        CAT-QuickHeal 9.50 2008.04.10 -
        ClamAV 0.92.1 2008.04.10 -
        DrWeb 4.44.0.09170 2008.04.10 -
        eSafe 7.0.15.0 2008.04.09 suspicious Trojan/Worm
        eTrust-Vet 31.3.5687 2008.04.10 -
        Ewido 4.0 2008.04.10 -
        F-Prot 4.4.2.54 2008.04.10 -
        F-Secure 6.70.13260.0 2008.04.10 -
        FileAdvisor 1 2008.04.10 -
        Fortinet 3.14.0.0 2008.04.10 -
        Ikarus T3.1.1.26 2008.04.10 -
        Kaspersky 7.0.0.125 2008.04.10 -
        McAfee 5271 2008.04.10 -
        Microsoft 1.3408 2008.04.10 -
        NOD32v2 3017 2008.04.10 -
        Norman 5.80.02 2008.04.10 -
        Panda 9.0.0.4 2008.04.10 -
        Prevx1 V2 2008.04.10 -
        Rising 20.39.32.00 2008.04.10 -
        Sophos 4.28.0 2008.04.10 -
        Sunbelt 3.0.1032.0 2008.04.08 -
        Symantec 10 2008.04.10 -
        TheHacker 6.2.92.272 2008.04.10 -
        VBA32 3.12.6.4 2008.04.06 -
        VirusBuster 4.3.26:9 2008.04.10 -
        Webwasher-Gateway 6.6.2 2008.04.10 -

        Information additionnelle
        File size: 111104 bytes
        MD5...: 26417fd1147cb9f567d0e4d230f0cef5
        SHA1..: ce566589bab6d5ebe6cd1e9c584db8110a9ff03f
        SHA256: fd9e6778d64f71c9785e91c2bd343c4a2b618f5238265bfa55ca1bf7d5e4b814
        SHA512: 8b68a7b522d0fd1468820c1ec00b38437113dfc1453d7593c022187230e7c752<BR>45bfd7504d9b7920f43d9fdae0d2788992ca47bd192fb06bd6dad5b36b705249
        PEiD..: UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser
        PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x48faf0<BR>timedatestamp.....: 0x41c602be (Sun Dec 19 22:37:50 2004)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 3 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>UPX0 0x1000 0x74000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e<BR>UPX1 0x75000 0x1b000 0x1ae00 7.92 57f6316bf62e1e327d639b5767ac1a7d<BR>UPX2 0x90000 0x1000 0x200 1.46 0ac17f51fcac00f3f4c9eb96f7e267fd<BR><BR>( 2 imports ) <BR>> KERNEL32.DLL: LoadLibraryA, GetProcAddress, ExitProcess<BR>> USER32.dll: CharToOemA<BR><BR>( 0 exports ) <BR>
        packers: UPX
        packers: UPX
        packers: UPX
        0
        1. Contributeur sécurité
          re,

          je veux vérifier un autre fichier

          Rends toi sur ce site :

          https://www.virustotal.com/gui/

          Clique sur parcourir et cherche ce fichier : C:\Windows\system32\Uharc.exe

          Clique sur Send File.

          Un rapport va s'élaborer ligne à ligne.

          Attends la fin. Il doit comprendre la taille du fichier envoyé.

          Sauvegarde le rapport avec le bloc-note.

          Copie le dans ta réponse.

          0
          1. oui je l'ai supprimé depuis qq jours
            0
            1. Contributeur sécurité
              Re,

              as tu supprimé ton crack ?
              0
              1. Contributeur sécurité
                Re,

                supprime ton crack.

                Supprime tout ce que tu as téléchargé puis créé de Navilog.

                Ensuite,

                Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

                - Va dans démarrer puis panneau de configuration
                - Double Clique sur l'icône "Comptes d'utilisateurs"
                - Clique ensuite sur désactiver et valide.

                Télécharge maintenant Navilog1 depuis-ce lien :

                http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

                Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
                Ensuite double clique sur navilog1.exe pour lancer l'installation.
                Une fois l'installation terminée, Fais un Clic-droit sur le raccourci Navilog1 présent sur ton bureau et choisis "Exécuter

                en tant qu'administrateur".

                Au menu principal, Fais le choix 1
                Laisse toi guider et patiente.
                Patiente jusqu'au message :
                *** Analyse Termine le ..... ***
                Appuie sur une touche le blocnote va s'ouvrir.
                Copie-colle l'intégralité du rapport dans une réponse.
                Referme le blocnote
                Le rapport fixnavi.txt est en outre sauvegardé dans %systemdrive%.
                0
                1. Voici le rapport de navilog

                  Search Navipromo version 3.5.3 commencé le 2008-04-10 à 22:10:19.60

                  !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                  !!! Postez ce rapport sur le forum pour le faire analyser !!!
                  !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

                  Outil exécuté depuis C:\Program Files\navilog1
                  Session actuelle : "Grégory"

                  Mise à jour le 09.04.2008 à 20h00 par IL-MAFIOSO

                  Microsoft Windows Vista 6.0.6000
                  Internet Explorer : 7.0.6000.16643
                  Système de fichiers : NTFS

                  Executé en mode normal

                  *** Recherche Programmes installés ***

                  *** Recherche dossiers dans C:\Windows ***

                  *** Recherche dossiers dans C:\Program Files ***

                  *** Recherche dossiers dans C:\ProgramData ***

                  *** Recherche dossiers dans C:\ProgramData\Microsoft\Windows\Start Menu\Programs ***

                  *** Recherche dossiers dans C:\Users\Gr‚gory\AppData\Local\virtualstore\Program Files ***

                  *** Recherche dossiers dans C:\Users\Gr‚gory\AppData\Roaming ***

                  *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
                  pour + d'infos : http://www.gmer.net

                  Aucun Fichier trouvé

                  *** Recherche avec GenericNaviSearch ***
                  !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
                  !!! A vérifier impérativement avant toute suppression manuelle !!!

                  * Recherche dans C:\Windows\system32 *

                  * Recherche dans C:\Users\Gr‚gory\AppData\Local\Microsoft *

                  * Recherche dans C:\Users\Gr‚gory\AppData\Local\virtualstore\windows\system32 *

                  * Recherche dans C:\Users\Gr‚gory\AppData\Local *

                  * Recherche dans "C:\Users\ADMINI~1\AppData\Local" *

                  * Recherche dans "C:\Users\PROMOCOM\AppData\Local" *

                  *** Recherche fichiers ***

                  *** Recherche clés spécifiques dans le Registre ***

                  *** Module de Recherche complémentaire ***
                  (Recherche fichiers spécifiques)

                  1)Recherche nouveaux fichiers Instant Access :

                  2)Recherche Heuristique :

                  * Dans C:\Windows\system32 :

                  * Dans C:\Users\Gr‚gory\AppData\Local\Microsoft :

                  * Dans C:\Users\Gr‚gory\AppData\Local\virtualstore\windows\system32 :

                  * Dans C:\Users\Gr‚gory\AppData\Local :

                  * Dans "C:\Users\ADMINI~1\AppData\Local" :

                  * Dans "C:\Users\PROMOCOM\AppData\Local" :

                  3)Recherche Certificats :

                  Certificat Egroup absent !
                  Certificat Electronic-Group absent !
                  Certificat OOO-Favorit absent !
                  Certificat Sunny-Day-Design-Ltd absent !

                  4)Recherche fichiers connus :

                  *** Analyse terminée le 2008-04-10 à 22:23:05.16 ***
                  0
              2. Contributeur sécurité
                Bonsoir Lyonnais,

                Une petite incursion, SVP.

                C'est tout de même surprenant ce diagnostic de SystemScan.
                SUSPICIOUS FILES:
                C:\Windows\FAVPID.DLL --> is compressed with UPX
                C:\Windows\system32\Uharc.exe --> is compressed with UPX

                Pour le second, il n'y a pas que SystemScan qui surprend.

                Regarde:
                - chez PrevX ==> DEFINITION OF: UHARC.EXE
                Safety Rating: Known Malware, do not run
                Malware Family: Part of Malware group - Dialer InstantAccess
                - un autre ici https://www.luanagames.com/index.fr.html (supprimé)
                - surtout ici aussi http://forum.telecharger.01net.com/telecharger/securite_virus_et_assimiles/trojan_et_spywares/au_secours_infecte_par_not-a-virus__resolu-418839/messages-1.html par jean-chretien1 (analyse Virustotal + renommé et déplacé)

                Bonne continuation
                Al.
                0
                1. Contributeur sécurité
                  Re,

                  tu m'en donneras le résultat.

                  Avais tu téléchargé un crack juste avant l'infection par bagle ?

                  Si oui, l'as tu supprimé ?

                  Rends toi sur ce site :

                  https://www.virustotal.com/gui/

                  Clique sur parcourir et cherche ce fichier : C:\Windows\FAVPID.DLL

                  Clique sur Send File.

                  Un rapport va s'élaborer ligne à ligne.

                  Attends la fin. Il doit comprendre la taille du fichier envoyé.

                  Sauvegarde le rapport avec le bloc-note.

                  Copie le dans ta réponse.

                  Télécharger OTMoveIt2 par OldTimer
                  http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe

                  * Enregistrer ce fichier sur le Bureau.
                  * Faire un double clic sur OTMoveIt2.exe pour lancer l'exécution de l'outil. (Note: Si vous utilisez Vista, faire un clic droit sur le fichier puis choisir Exécuter en tant qu'administrateur).
                  * Copier les lignes en gras ci-dessous dans le Presse-papiers en les sélectionnant TOUTES puis en appuyant simultanément sur les touches CTRL et C (ou, après les avoir sélectionnées, en faisant un clic droit puis en choisissant Copier):

                  C:\Windows\system32\drivers\downld

                  * Retourner dans la fenêtre de OTMoveIt2, faire un clic droit dans la zone "Paste Standard List of Files/Folders to Move" (sous la barre bleu clair) puis choisir Coller.

                  * Cliquer sur le bouton rouge Moveit!.
                  * Copier tout ce qui se trouve dans la zone Results (sous la barre verte) dans le Presse-papiers en sélectionnant TOUTES LES LIGNES puis en appuyant simultanément sur les touches CTRL et C (ou, après les avoir sélectionnées, en faisant un clic droit puis en choisissant Copier), et coller ces résulats en réponse sur le forum.
                  * Fermer OTMoveIt2

                  Note: Si un fichier ou un dossier ne peut pas être déplacé immédiatement, un redémarrage sera peut-être nécessaire afin de terminer le processus de déplacement. Si le redémarrage de la machine vous est demandé, choisir Oui/Yes. Dans ce cas, après le redémarrage, ouvrir le Bloc-notes (Démarrer->Tous les programmes->Accessoires->Bloc-notes), cliquer sur Fichier->Ouvrir, dans la zone "Nom du fichier" taper *.log et appuyer sur la touche Entrée, naviguer jusqu'au dossier C:\_OTMoveIt\MovedFiles, puis ouvrir le fichier .log le plus récent; ensuite faire un copier/coller du contenu de ce document en réponse sur le forum.

                  Clique sur ce lien :
                  http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
                  pour télécharger navilog1.exe.

                  Choisis Enregistrer

                  et enregistre-le sur ton bureau.

                  Ensuite double clique sur navilog1.exe pour lancer l'installation.
                  Une fois l'installation terminée, le fix s'exécutera automatiquement.
                  (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

                  Laisse-toi guider. Au menu principal, choisis 1 et valides.
                  (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

                  Patiente jusqu'au message :
                  *** Analyse Termine le ..... ***
                  Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
                  Copie-colle l'intégralité du rapport dans ta réponse. Referme le blocnote.
                  Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)
                  0
                  1. slt,
                    voici le rapport d'antivir je m'attele au reste ;)

                    AntiVir PersonalEdition Classic
                    Report file date: 2008-04-09 19:12

                    Scanning for 1190068 virus strains and unwanted programs.

                    Licensed to: Avira AntiVir PersonalEdition Classic
                    Serial number: 0000149996-ADJIE-0001
                    Platform: Windows Vista
                    Windows version: (plain) [6.0.6000]
                    Username: SYSTEM
                    Computer name: GR-BBACE4CAFDD

                    Version information:
                    BUILD.DAT : 270 15603 Bytes 2007-09-19 13:32:00
                    AVSCAN.EXE : 7.0.6.1 290856 Bytes 2007-08-23 12:16:29
                    AVSCAN.DLL : 7.0.6.0 49192 Bytes 2007-08-16 11:23:51
                    LUKE.DLL : 7.0.5.3 147496 Bytes 2007-08-14 14:32:47
                    LUKERES.DLL : 7.0.6.1 10280 Bytes 2007-08-21 11:35:20
                    ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 2007-07-18 13:27:15
                    ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 2008-03-07 17:12:01
                    ANTIVIR2.VDF : 7.0.3.127 649216 Bytes 2008-04-07 17:12:01
                    ANTIVIR3.VDF : 7.0.3.142 84480 Bytes 2008-04-09 17:12:01
                    AVEWIN32.DLL : 7.6.0.81 3424768 Bytes 2008-04-09 17:12:01
                    AVWINLL.DLL : 1.0.0.7 14376 Bytes 2007-02-26 09:36:26
                    AVPREF.DLL : 7.0.2.2 25640 Bytes 2007-07-18 06:39:17
                    AVREP.DLL : 7.0.0.1 155688 Bytes 2007-04-16 12:16:24
                    AVPACK32.DLL : 7.6.0.3 360488 Bytes 2008-04-09 17:12:01
                    AVREG.DLL : 7.0.1.6 30760 Bytes 2007-07-18 06:17:06
                    AVARKT.DLL : 1.0.0.20 278568 Bytes 2007-08-28 11:26:33
                    AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 2007-07-18 06:10:18
                    NETNT.DLL : 7.0.0.0 7720 Bytes 2007-03-08 10:09:42
                    RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 2007-08-07 11:38:13
                    RCTEXT.DLL : 7.0.62.0 86056 Bytes 2007-08-21 11:50:37
                    SQLITE3.DLL : 3.3.17.1 339968 Bytes 2007-07-23 08:37:21

                    Configuration settings for the scan:
                    Jobname..........................: Complete system scan
                    Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
                    Logging..........................: low
                    Primary action...................: interactive
                    Secondary action.................: ignore
                    Scan master boot sector..........: off
                    Scan boot sector.................: on
                    Boot sectors.....................: D:,
                    Scan memory......................: on
                    Process scan.....................: on
                    Scan registry....................: on
                    Search for rootkits..............: off
                    Scan all files...................: Intelligent file selection
                    Scan archives....................: on
                    Recursion depth..................: 20
                    Smart extensions.................: on
                    Macro heuristic..................: on
                    File heuristic...................: medium

                    Start of the scan: 2008-04-09 19:12

                    The scan of running processes will be started
                    Scan process 'avscan.exe' - '1' Module(s) have been scanned
                    Scan process 'SearchFilterHost.exe' - '1' Module(s) have been scanned
                    Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                    Scan process 'sched.exe' - '1' Module(s) have been scanned
                    Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                    Scan process 'avguard.exe' - '1' Module(s) have been scanned
                    Scan process 'WmiPrvSE.exe' - '1' Module(s) have been scanned
                    Scan process 'TrustedInstaller.exe' - '1' Module(s) have been scanned
                    Scan process 'InputPersonalization.exe' - '1' Module(s) have been scanned
                    Scan process 'msiexec.exe' - '1' Module(s) have been scanned
                    Scan process 'httpd.exe' - '1' Module(s) have been scanned
                    Scan process 'httpd.exe' - '1' Module(s) have been scanned
                    Scan process 'sidebar.exe' - '1' Module(s) have been scanned
                    Scan process 'SearchProtocolHost.exe' - '1' Module(s) have been scanned
                    Scan process 'ehmsas.exe' - '1' Module(s) have been scanned
                    Scan process 'wmpnetwk.exe' - '1' Module(s) have been scanned
                    Scan process 'uBBMonitor.exe' - '1' Module(s) have been scanned
                    Scan process 'My Ink Resident.exe' - '1' Module(s) have been scanned
                    Scan process 'Hotsync.exe' - '1' Module(s) have been scanned
                    Scan process 'ehtray.exe' - '1' Module(s) have been scanned
                    Scan process 'wmpnscfg.exe' - '1' Module(s) have been scanned
                    Scan process 'MediaCenter.exe' - '1' Module(s) have been scanned
                    Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
                    Scan process 'sidebar.exe' - '1' Module(s) have been scanned
                    Scan process 'SFAgent.exe' - '1' Module(s) have been scanned
                    Scan process 'jusched.exe' - '1' Module(s) have been scanned
                    Scan process 'VAIOUpdt.exe' - '1' Module(s) have been scanned
                    Scan process 'taskeng.exe' - '1' Module(s) have been scanned
                    Scan process 'explorer.exe' - '1' Module(s) have been scanned
                    Scan process 'dwm.exe' - '1' Module(s) have been scanned
                    Scan process 'taskeng.exe' - '1' Module(s) have been scanned
                    Scan process 'taskeng.exe' - '1' Module(s) have been scanned
                    Scan process 'WUDFHost.exe' - '1' Module(s) have been scanned
                    Scan process 'SDWinSec.exe' - '1' Module(s) have been scanned
                    Scan process 'VESMgrSub.exe' - '1' Module(s) have been scanned
                    Scan process 'msfwsvc.exe' - '1' Module(s) have been scanned
                    Scan process 'SearchIndexer.exe' - '1' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'wanmpsvc.exe' - '1' Module(s) have been scanned
                    Scan process 'VCI_TASK.exe' - '1' Module(s) have been scanned
                    Scan process 'VCSW.exe' - '1' Module(s) have been scanned
                    Scan process 'VESMgr.exe' - '1' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'stacsv.exe' - '1' Module(s) have been scanned
                    Scan process 'sfus.exe' - '1' Module(s) have been scanned
                    Scan process 'RegSrvc.exe' - '1' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'mdm.exe' - '1' Module(s) have been scanned
                    Scan process 'GoogleUpdaterService.exe' - '1' Module(s) have been scanned
                    Scan process 'DkService.exe' - '1' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
                    Scan process 'AOLacsd.exe' - '1' Module(s) have been scanned
                    Scan process 'PhotoshopElementsFileAgent.exe' - '1' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'S24EvMon.exe' - '1' Module(s) have been scanned
                    Scan process 'EvtEng.exe' - '1' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'SLsvc.exe' - '1' Module(s) have been scanned
                    Scan process 'audiodg.exe' - '0' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                    Scan process 'lsm.exe' - '1' Module(s) have been scanned
                    Scan process 'lsass.exe' - '1' Module(s) have been scanned
                    Scan process 'services.exe' - '1' Module(s) have been scanned
                    Scan process 'csrss.exe' - '1' Module(s) have been scanned
                    Scan process 'wininit.exe' - '1' Module(s) have been scanned
                    Scan process 'csrss.exe' - '1' Module(s) have been scanned
                    Scan process 'smss.exe' - '1' Module(s) have been scanned
                    74 processes with 74 modules were scanned

                    Start scanning boot sectors:
                    Boot sector 'C:\'
                    [NOTE] No virus was found!
                    Boot sector 'D:\'
                    [NOTE] No virus was found!

                    Starting to scan the registry.
                    The registry was scanned ( '15' files ).

                    Starting the file scan:

                    Begin scan in 'C:\' <VAIO Grégory ROBERT>
                    C:\pagefile.sys
                    [WARNING] The file could not be opened!

                    End of the scan: 2008-04-09 20:44
                    Used time: 1:31:51 min

                    14595 Scanning directories
                    462588 Files were scanned
                    0 viruses and/or unwanted programs were found
                    0 Files were classified as suspicious:
                    0 files were deleted
                    0 files were repaired
                    0 files were moved to quarantine
                    0 files were renamed
                    1 Files cannot be scanned
                    462588 Files not concerned
                    3338 Archives were scanned
                    4 Warnings
                    10 Notes
                    0
                  2. oui un crack keygen mais qui je pense fonctionne sans installation mais bon je ne sais pas où un autre programme aurait pu s'installer ...

                    Quant à navilog celà ne fonctionne pas, il ne trouve pas certains fichiers

                    Je te joins le reste

                    Fichier FAVPID.DLL reçu le 2008.04.09 20:49:08 (CET)Antivirus Version Dernière mise à jour Résultat
                    AhnLab-V3 2008.4.9.0 2008.04.09 -
                    AntiVir 7.6.0.81 2008.04.09 -
                    Authentium 4.93.8 2008.04.09 -
                    Avast 4.8.1169.0 2008.04.09 -
                    AVG 7.5.0.516 2008.04.09 -
                    BitDefender 7.2 2008.04.09 -
                    CAT-QuickHeal 9.50 2008.04.08 -
                    ClamAV 0.92.1 2008.04.09 -
                    DrWeb 4.44.0.09170 2008.04.09 -
                    eSafe 7.0.15.0 2008.04.09 -
                    eTrust-Vet 31.3.5684 2008.04.09 -
                    Ewido 4.0 2008.04.09 -
                    F-Prot 4.4.2.54 2008.04.08 -
                    F-Secure 6.70.13260.0 2008.04.09 -
                    FileAdvisor 1 2008.04.09 -
                    Fortinet 3.14.0.0 2008.04.09 -
                    Ikarus T3.1.1.26 2008.04.09 -
                    Kaspersky 7.0.0.125 2008.04.09 -
                    McAfee 5270 2008.04.09 -
                    Microsoft 1.3408 2008.04.09 -
                    NOD32v2 3014 2008.04.09 -
                    Norman 5.80.02 2008.04.09 -
                    Panda 9.0.0.4 2008.04.08 -
                    Prevx1 V2 2008.04.09 -
                    Rising 20.39.12.00 2008.04.08 -
                    Sophos 4.28.0 2008.04.09 -
                    Symantec 10 2008.04.09 -
                    TheHacker 6.2.92.270 2008.04.09 -
                    VBA32 3.12.6.4 2008.04.06 -
                    VirusBuster 4.3.26:9 2008.04.09 -
                    Webwasher-Gateway 6.6.2 2008.04.09 -

                    Information additionnelle
                    File size: 150528 bytes
                    MD5...: baa94be6605b4cf77cbc31f2c1d9cecb
                    SHA1..: 9efc1606962925f884fc07d6bbbc34a5461569f4
                    SHA256: fd5daa464d832c2be44807fb1140d5f3fee37fa8290eff64ecb954fe1e4aed58
                    SHA512: 5ffea34370b99bf479ac315fe5d25ff737cd38a8a2f870143c635fbdaeff25ba<BR>5f0b6eebdcd81cdbb3d551436b28c46081e6b74d4ba5bd911506bb2a310cbdfa
                    PEiD..: -
                    PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x4601a0<BR>timedatestamp.....: 0x2a425e19 (Fri Jun 19 22:22:17 1992)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 3 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>UPX0 0x1000 0x3c000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e<BR>UPX1 0x3d000 0x24000 0x23400 7.91 7ee6aa91449bbb25a3a5cb812e07156b<BR>.rsrc 0x61000 0x2000 0x1400 3.70 7ee15b6d4827a6e3c419eddbdd873fa4<BR><BR>( 7 imports ) <BR>> KERNEL32.DLL: LoadLibraryA, GetProcAddress<BR>> advapi32.dll: RegFlushKey<BR>> comctl32.dll: ImageList_Add<BR>> gdi32.dll: SaveDC<BR>> ole32.dll: IsEqualGUID<BR>> oleaut32.dll: VariantClear<BR>> user32.dll: GetDC<BR><BR>( 5 exports ) <BR>FAVPIDEnum, FAVPIDFree, FAVPIDGetUFD, FAVPIDIdentify, FAVPIDInit<BR>
                    packers: UPX
                    packers: UPX
                    packers: UPX

                    C:\Windows\system32\drivers\downld moved successfully.

                    OTMoveIt2 by OldTimer - Version 1.0.4.1 log created on 04092008_210056
                    0
                2. Contributeur sécurité
                  Re,

                  antivir ne fonctionne pas ?
                  Télécharge ce programme puis double clic dessus (ferme ton antivirus le temps du téléchargement s'il te détecte quoi que ce soit et réactive le après)
                  http://www.suspectfile.com/systemscan/

                  Clique sur Unselect all

                  Coche uniquement ces cases :

                  - Recent Files, 30 days

                  - Suspicious files

                  Puis clic sur scan now, sois patient.
                  Une fois le scan terminé, un rapport va s'ouvrir, copie et colle son contenu ici
                  0
                  1. oui antivir ne se charge pas avec les programmes de démarrage et lorsque je le fais manuellement il me sort la phrase typique de l'application win32 invalide. Par contre dans l'analyse Hijackthis je remarque que Apoint.exe était un des fichiers repéré par elibagle comme étant infecté... De plus un certain nombre d'accès étaient déniés lors du scan d'Elibagle (par exemple pour adobe ou pour les drivers Printers etc ...) (désolé de mettre les infos au fur et à mesure entre le taff et mon problèmes d'ordi :))

                    Sinon je te poste les résultats de ce que tu m'as demandé :

                    SystemScan - www.suspectfile.com - ver. 3.5.5 (code: holifay & bReAkdOWn)

                    Running on: Windows VISTA (6000.6.0)
                    System directory: C:\Windows
                    SystemScan file: C:\Users\Grégory\Desktop\sys73766.exe
                    Running in: User mode
                    Date: 2008-04-09
                    Time: 17:46:07

                    Output limited to:
                    -Recent files
                    -Suspicious Files

                    ===================== RECENT FILES =====================

                    Showing files newer than 30 days

                    ----- recent files in C:\
                    03-04-2008 01:13:31 (DIR) 0 byte 6 days old -- Diskeeper
                    19-03-2008 17:08:40 13030 byte 21 days old -- PDOXUSRS.NET
                    06-04-2008 19:46:45 (DIR) 0 byte 3 days old -- System Volume Information
                    07-04-2008 14:50:27 9948 byte 2 days old -- resolve.log
                    07-04-2008 15:18:32 3574 byte 2 days old -- avenger.txt
                    07-04-2008 15:19:27 (DIR) 0 byte 2 days old -- Avenger
                    07-04-2008 15:22:45 (DIR) 0 byte 2 days old -- prog téléchargés
                    07-04-2008 22:56:26 (DIR) 0 byte 2 days old -- Mes Patients
                    08-04-2008 22:50:12 2799 byte 1 days old -- InfoSat2.txt
                    09-04-2008 00:47:28 (DIR) 0 byte 0 days old -- ProgramData
                    09-04-2008 16:31:58 (DIR) 0 byte 0 days old -- Windows
                    09-04-2008 16:35:10 1922629632 byte 0 days old -- pagefile.sys
                    09-04-2008 16:35:41 10166 byte 0 days old -- VCIError.log
                    09-04-2008 16:51:57 2822 byte 0 days old -- InfoSat.txt
                    09-04-2008 17:04:55 (DIR) 0 byte 0 days old -- Program Files

                    ----- recent files in C:\Windows\
                    02-04-2008 23:39:46 (DIR) 0 byte 7 days old -- Help
                    03-04-2008 09:34:50 69 byte 6 days old -- NeroDigital.ini
                    19-03-2008 16:34:27 (DIR) 0 byte 21 days old -- Speech
                    20-03-2008 07:59:33 (DIR) 0 byte 20 days old -- Lhsp
                    23-03-2008 05:28:38 (DIR) 0 byte 17 days old -- registration
                    04-04-2008 23:16:25 (DIR) 0 byte 5 days old -- Downloaded Installations
                    06-04-2008 18:56:34 (DIR) 0 byte 3 days old -- erdnt
                    06-04-2008 20:12:53 819200 byte 3 days old -- gmer.dll
                    06-04-2008 20:12:53 80 byte 3 days old -- gmer_uninstall.cmd
                    07-04-2008 14:11:11 (DIR) 0 byte 2 days old -- PIF
                    07-04-2008 14:52:01 250 byte 2 days old -- gmer.ini
                    07-04-2008 14:56:16 0 byte 2 days old -- gmer.reg
                    07-04-2008 14:56:27 0 byte 2 days old -- gmer.bat
                    07-04-2008 15:10:30 (DIR) 0 byte 2 days old -- Minidump
                    08-04-2008 23:22:57 63 byte 1 days old -- vbaddin.ini
                    08-04-2008 23:23:43 (DIR) 0 byte 1 days old -- Installer
                    08-04-2008 23:25:13 (DIR) 0 byte 1 days old -- AppPatch
                    08-04-2008 23:30:15 (DIR) 0 byte 1 days old -- winsxs
                    09-04-2008 10:10:20 (DIR) 0 byte 0 days old -- Downloaded Program Files
                    09-04-2008 10:12:06 (DIR) 0 byte 0 days old -- BDOSCAN8
                    09-04-2008 12:26:41 (DIR) 0 byte 0 days old -- Tasks
                    09-04-2008 16:32:00 (DIR) 0 byte 0 days old -- Debug
                    09-04-2008 16:34:12 949 byte 0 days old -- bthservsdp.dat
                    09-04-2008 16:34:13 32616 byte 0 days old -- SchedLgU.Txt
                    09-04-2008 16:35:28 67584 byte 0 days old -- bootstat.dat
                    09-04-2008 16:38:55 1176728 byte 0 days old -- WindowsUpdate.log
                    09-04-2008 16:55:34 (DIR) 0 byte 0 days old -- inf
                    09-04-2008 16:55:35 (DIR) 0 byte 0 days old -- System32
                    09-04-2008 17:42:29 (DIR) 0 byte 0 days old -- Temp
                    09-04-2008 17:44:17 (DIR) 0 byte 0 days old -- Prefetch

                    ----- recent files in C:\Windows\Downloaded Program Files\

                    ----- recent files in C:\Windows\system\

                    ----- recent files in C:\Windows\system32\
                    02-04-2008 22:37:20 (DIR) 0 byte 7 days old -- DRVSTORE
                    02-04-2008 23:23:39 (DIR) 0 byte 7 days old -- oodag
                    22-03-2008 20:29:51 (DIR) 0 byte 18 days old -- Samsung_USB_Drivers
                    23-03-2008 05:29:04 (DIR) 0 byte 17 days old -- config
                    23-03-2008 05:30:09 (DIR) 0 byte 17 days old -- wbem
                    06-04-2008 07:56:20 19836024 byte 3 days old -- mrt.exe
                    08-04-2008 22:46:34 (DIR) 0 byte 1 days old -- drivers
                    08-04-2008 23:25:16 (DIR) 0 byte 1 days old -- migration
                    08-04-2008 23:25:18 (DIR) 0 byte 1 days old -- fr-FR
                    08-04-2008 23:28:23 491864 byte 1 days old -- FNTCACHE.DAT
                    08-04-2008 23:29:19 (DIR) 0 byte 1 days old -- catroot
                    08-04-2008 23:29:19 (DIR) 0 byte 1 days old -- catroot2
                    09-04-2008 12:26:41 (DIR) 0 byte 0 days old -- Tasks
                    09-04-2008 16:55:34 1637270 byte 0 days old -- PerfStringBackup.INI
                    09-04-2008 16:55:35 735670 byte 0 days old -- perfh00C.dat
                    09-04-2008 16:55:35 120642 byte 0 days old -- perfc009.dat
                    09-04-2008 16:55:35 139434 byte 0 days old -- perfc00C.dat
                    09-04-2008 16:55:35 648736 byte 0 days old -- perfh009.dat
                    09-04-2008 17:35:34 2368 byte 0 days old -- 7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
                    09-04-2008 17:35:34 2368 byte 0 days old -- 7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0

                    ----- recent files in C:\Windows\system32\drivers\
                    06-04-2008 20:12:53 86097 byte 3 days old -- gmer.sys
                    08-04-2008 22:46:37 (DIR) 0 byte 1 days old -- downld

                    ----- recent files in C:\Windows\temp\
                    08-04-2008 23:13:23 13042 byte 1 days old -- lpksetup-20080408-231305-0.log
                    08-04-2008 23:13:24 622 byte 1 days old -- lpksetup-20080408-231323-0.log
                    08-04-2008 23:22:58 200 byte 1 days old -- VisioCA.log
                    08-04-2008 23:44:02 13946 byte 1 days old -- lpksetup-20080408-234340-0.log
                    08-04-2008 23:44:03 622 byte 1 days old -- lpksetup-20080408-234402-0.log
                    09-04-2008 00:39:14 13946 byte 0 days old -- lpksetup-20080409-003859-0.log
                    09-04-2008 00:39:15 622 byte 0 days old -- lpksetup-20080409-003914-0.log
                    09-04-2008 01:32:00 836 byte 0 days old -- MpCmdRun.log
                    09-04-2008 11:38:47 13946 byte 0 days old -- lpksetup-20080409-113835-0.log
                    09-04-2008 11:38:48 622 byte 0 days old -- lpksetup-20080409-113847-0.log
                    09-04-2008 16:51:59 13946 byte 0 days old -- lpksetup-20080409-165041-0.log
                    09-04-2008 16:52:00 622 byte 0 days old -- lpksetup-20080409-165200-0.log

                    ----- recent files in C:\Program Files\
                    02-04-2008 22:27:13 (DIR) 0 byte 7 days old -- Common Files
                    02-04-2008 22:47:09 (DIR) 0 byte 7 days old -- Microsoft Windows OneCare Live
                    13-03-2008 19:15:30 (DIR) 0 byte 27 days old -- Microsoft Money 2005
                    22-03-2008 18:55:45 (DIR) 0 byte 18 days old -- Samsung
                    22-03-2008 20:27:04 (DIR) 0 byte 18 days old -- InstallShield Installation Information
                    26-03-2008 23:36:47 (DIR) 0 byte 14 days old -- Mozilla Firefox
                    04-04-2008 23:16:18 (DIR) 0 byte 5 days old -- Adobe
                    04-04-2008 23:27:22 (DIR) 0 byte 5 days old -- Ripp-it_AM
                    04-04-2008 23:28:39 (DIR) 0 byte 5 days old -- Windows Live Safety Center
                    07-04-2008 09:04:22 (DIR) 0 byte 2 days old -- neuf Talk
                    07-04-2008 22:56:32 (DIR) 0 byte 2 days old -- VisualCab
                    08-04-2008 23:24:57 (DIR) 0 byte 1 days old -- Apoint
                    08-04-2008 23:25:16 (DIR) 0 byte 1 days old -- Internet Explorer
                    08-04-2008 23:25:19 (DIR) 0 byte 1 days old -- Windows Mail
                    09-04-2008 17:04:55 (DIR) 0 byte 0 days old -- Trend Micro

                    ----- recent files in C:\Program Files\Common Files\
                    20-03-2008 23:05:04 (DIR) 0 byte 20 days old -- Application
                    20-03-2008 23:05:54 (DIR) 0 byte 20 days old -- Ankiro
                    28-03-2008 23:46:34 (DIR) 0 byte 12 days old -- Windows Media Metering

                    ----- recent files in C:\Users\Grégory\AppData\Roaming\
                    19-03-2008 01:24:01 (DIR) 0 byte 21 days old -- AlauxSoft
                    20-03-2008 23:08:47 (DIR) 0 byte 20 days old -- SPAMfighter
                    23-03-2008 13:06:42 (DIR) 0 byte 17 days old -- Samsung
                    29-03-2008 00:00:25 (DIR) 0 byte 11 days old -- Windows Media Metering
                    05-04-2008 21:26:40 (DIR) 0 byte 4 days old -- Adobe

                    ----- recent files in C:\Users\GRGORY~1\AppData\Local\Temp\
                    09-04-2008 16:42:34 173 byte 0 days old -- jusched.log
                    09-04-2008 16:55:57 134 byte 0 days old -- 1261250.od
                    09-04-2008 16:55:57 0 byte 0 days old -- CVR3EC2.tmp.cvr
                    09-04-2008 17:05:42 (DIR) 0 byte 0 days old -- {60b47bb9-b519-4bfc-bcec-aa0bae4fdeb7}
                    09-04-2008 17:09:26 31832 byte 0 days old -- Grégory.bmp
                    09-04-2008 17:10:26 5270 byte 0 days old -- logcalb2
                    09-04-2008 17:12:52 134 byte 0 days old -- 2275921.od
                    09-04-2008 17:12:52 0 byte 0 days old -- CVRBA51.tmp.cvr
                    09-04-2008 17:13:20 (DIR) 0 byte 0 days old -- Journalisation d'Outlook
                    09-04-2008 17:16:09 (DIR) 0 byte 0 days old -- outlook logging
                    09-04-2008 17:42:29 37 byte 0 days old -- systemscan.ini
                    09-04-2008 17:42:30 16384 byte 0 days old -- ~DF82E.tmp
                    09-04-2008 17:42:30 (DIR) 0 byte 0 days old -- nslD9BE.tmp
                    09-04-2008 17:45:12 7776 byte 0 days old -- logcalb3

                    ===================== SUSPICIOUS FILES =====================
                    EXE and DLL files packed with runtime packers, found in: C:\; C:\Windows\; C:\Windows\system32\

                    C:\Windows\FAVPID.DLL --> is compressed with UPX
                    C:\Windows\system32\Uharc.exe --> is compressed with UPX

                    ==========================================
                    Scan completed in 0.2 minutes
                    End of report

                    ~~~~~~~~~~~~~~~~~~~~~-----CREDITS-----~~~~~~~~~~~~~~~~~~~~~
                    SystemScan uses some freeware tools that remain property of their authors:

                    * SteelWerX Registry Console Tool, Who Am I (Bobby Flekman: www.xs4all.nl/~fstaal01) --> "Registry scan", "PC accounts "
                    * dumphive (Markus Stephany)--> "Registry scan"
                    * Listdlls (M.Russinovich, B.Cogswell: www.sysinternals.com) --> "Loaded modules"
                    * Catchme & MBR Rootkit detector (gmer: www.gmer.net) --> "Hidden objects", "Alternate Data Streams" & "Master Boot Record"
                    ---> NOTE: SystemScan integrates "The Avenger" from Swandog46 (http://swandog46.geekstogo.com) to allow you to remove malwares found in this log

                    Thanks to all of them for their hard work
                    0
                  2. j'ai désinstallé et réinstallé à nouveau antivir et ca fonctionne là je fais un scan :)
                    0
                3. Contributeur sécurité
                  Bonjour,

                  on essaye comme ça :

                  Fais une analyse par HijackThis, comme ceci:

                  1)- Avec connexion au Net en service,
                  Télécharge la version finale de Hijackthis (Trend Secure) ==> HijackThis™ 2.0 .2 < http://www.trendsecure.com/portal/en-US/threat_analytics/hijackthis.php?page=download > avec un installeur. Sur la page, choisis « Download HijackThis Installer » et enregistre-le sur le bureau. Tu dois voir une nouvelle icône « HJTInstall.exe » sur le bureau.

                  2)- Installation : clic-droit sur l’ icône « HJTInstall.exe » présente sur ton bureau et choisis : "Exécuter en tant qu'administrateur" dans le menu déroulant qui s'affiche.
                  - Ensuite, clic sur « Exécuter », puis sur « Install ».
                  - Accepte la licence en cliquant sur le bouton "I Accept"
                  - Le programme s’installe de lui-même dans un dossier dédié.
                  - Par défaut, il s'installera en C:\Program Files\Trend Micro\HijackThis
                  - Et un raccourci pour lancer l’analyse apparaît sur le bureau.

                  Note: Comme cette version est appelée à rester sur le PC, faire un clic-droit sur HJTInstall.exe > Propriétés > Onglet compatibilité > coche la case "Exécuter en tant qu'administrateur" en bas .
                  - Cette solution pérennise le choix qui peut être obtenu de manière provisoire par « clic-droit sur l'icône de raccourci/Exécuter en tant qu'administrateur» dans le menu contextuel.

                  3)Analyse :
                  •-Important à faire en priorité si tu possèdes le logiciel Spybot S&D > Désactive le Tea Timer de Spybot en passant par les options de Spybot: il faut une fois dans le logiciel il faut aller dans le menu "Mode" => coche "Mode avancé" => "Outils"(en bas de page)=> "Résident" => et tu décoches cette case: "Résident Tea Timer" .
                  - Tu ne dois plus voir l'icône du Tea Timer dans la barre de tâches (Systray près de l’horloge)!

                  •-Arrête tous les programmes en cours et ferme toutes les fenêtres.
                  •- Puis, double-clic sur le raccourci HJT créé sur le bureau, et clic sur "Do a system scan and save a logfile" pour lancer l'analyse.
                  - À la fin du scan le bloc-notes va s'ouvrir sur le bureau
                  - Tu fais un copier/coller de tout son contenu.
                  - Et tu le postes sur le forum.
                  - Il sera enregistré dans le dossier C:\Program Files\Trend Micro\HijackThis, sous hijackthis.log.

                  Ensuite, si cela a fonctionné; désinstalle et réinstalle ton antivirus.

                  scan complet si ça fonctionne;

                  tiens moi au courant dès que Hijackthis fonctionne.

                  Supprime une éventuelle version de combofix.
                  0
                  1. Voici les résultats de Hijackthis

                    Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 17:11, on 2008-04-09
                    Platform: Windows Vista (WinNT 6.00.1904)
                    MSIE: Internet Explorer v7.00 (7.00.6000.16643)
                    Boot mode: Normal

                    Running processes:
                    C:\WINDOWS\system32\taskeng.exe
                    C:\Windows\system32\Dwm.exe
                    C:\Windows\Explorer.EXE
                    C:\WINDOWS\system32\taskeng.exe
                    C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
                    C:\Program Files\Apoint\Apoint.exe
                    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                    D:\Program Files\SPAMfighter\SFAgent.exe
                    C:\Program Files\Windows Sidebar\sidebar.exe
                    C:\Program Files\Windows Media Player\wmpnscfg.exe
                    C:\Windows\ehome\ehtray.exe
                    C:\Program Files\Palm\Hotsync.exe
                    C:\Program Files\My Book\WD Backup\uBBMonitor.exe
                    C:\Windows\ehome\ehmsas.exe
                    C:\Windows\system32\wbem\unsecapp.exe
                    C:\Program Files\Windows Sidebar\sidebar.exe
                    C:\Program Files\Apoint\ApMsgFwd.exe
                    C:\Program Files\Apoint\Apntex.exe
                    C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
                    C:\Windows\System32\mobsync.exe
                    C:\Program Files\Windows Media Player\wmplayer.exe
                    C:\PROGRA~1\MICROS~4\Office12\OUTLOOK.EXE
                    C:\Windows\system32\SearchProtocolHost.exe
                    C:\Windows\system32\SearchFilterHost.exe
                    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.neuf.fr/
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://windowsxlive.net/
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                    O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
                    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
                    O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\GOOGLE~1.DLL
                    O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll
                    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                    O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
                    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
                    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                    O4 - HKLM\..\Run: [SPAMfighter Agent] "D:\Program Files\SPAMfighter\SFAgent.exe" update delay 60
                    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                    O4 - HKCU\..\Run: [Neuf Media Center] "C:\Program Files\Neuf\Media Center\MediaCenter.exe"
                    O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
                    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                    O4 - HKUS\S-1-5-18\..\Run: [Gestionnaire Antidote.exe] C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe (User 'SYSTEM')
                    O4 - HKUS\.DEFAULT\..\Run: [Gestionnaire Antidote.exe] C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe (User 'Default user')
                    O4 - Startup: BOINC Manager.lnk = D:\Program Files\BOINC\boincmgr.exe
                    O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\Palm\Hotsync.exe
                    O4 - Global Startup: My Ink Resident.lnk = ?
                    O4 - Global Startup: WD Backup Monitor.lnk = C:\Program Files\My Book\WD Backup\uBBMonitor.exe
                    O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                    O8 - Extra context menu item: Chercher avec Copernic Agent - res://C:\Program Files\Copernic Agent\CopernicAgentExt.rdl/INTEGRATION_MENU_SEARCHEXT
                    O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                    O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                    O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                    O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                    O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                    O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
                    O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
                    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE12\EXCEL.EXE/3000
                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
                    O8 - Extra context menu item: Transfert par Image Converter 2 Plus - C:\Program Files\Sony\Image Converter 2\menu.htm
                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                    O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                    O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                    O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
                    O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
                    O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
                    O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
                    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
                    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
                    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
                    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                    O13 - Gopher Prefix:
                    O15 - Trusted Zone: https://www.google.fr/?gws_rd=ssl
                    O15 - Trusted Zone: https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                    O15 - Trusted Zone: *.sony-europe.com
                    O15 - Trusted Zone: *.sonystyle-europe.com
                    O15 - Trusted Zone: *.vaio-link.com
                    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - http://update.microsoft.com/...
                    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
                    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
                    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
                    O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
                    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                    O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
                    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                    O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
                    O23 - Service: Diskeeper - Diskeeper Corporation - D:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
                    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                    O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
                    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
                    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
                    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
                    O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
                    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                    O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - D:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                    O23 - Service: SPAMfighter Update Service - SPAMfighter ApS - D:\Program Files\SPAMfighter\sfus.exe
                    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
                    O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
                    O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
                    O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
                    O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                    O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
                    O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
                    O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
                    O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
                    O23 - Service: VAIO Cooporated Initialisation (VCI) - Sony Corporation - C:\Program Files\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe
                    O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
                    O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
                    O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
                    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
                    O23 - Service: Service de lancement de WlanCfg (Wlancfg) - Unknown owner - C:\Program Files\AOLbox\Gateway\wlancfg.exe (file missing)
                    O24 - Desktop Component 1: (no name) - C:\Program Files\Mozilla Firefox\Wallpaper_dynamique_V4_1024x768\wallpaper.htm
                    0
                4. Contributeur sécurité
                  Coucou Marie,

                  J'ai demandé la suppression de ce post malsain où ludsfa proposait AVEUGLÉMENT et DANGEREUSEMENT ComboFix.
                  Merci à l'équipe. ;)

                  Pour Vista j'ai ceci dans mes tablettes:
                  Tuto ScanOnlineKasperky ici si problème :
                  < http://www.vista-xp.fr/forum/topic109.html >

                  Amitiés
                  Al.
                  0
                  1. J'ai vu Al.
                    Se sert un peu trop de ComboFix à profusion ;;)*
                    Merci pour le lien ;;))
                    0
                5. Contributeur sécurité
                  Bonjour Lyonnais,

                  Bientôt ludsfa sera mis lui-même en quarantaine; je préfèrerais direct à la poubelle !

                  Enkade59, pourrais-tu suivre à la lettre ce que te suggère Lyonnais ?
                  Tu as la chance d'être entre de bonnes mains.
                  Pour ton info, Online-Scanner-Kaspersky est compatible avec VISTA (il suffit de lire ce qui est proposé; et ne pas vouloir courir) ==> bonne chance.

                  Al.
                  0
                  1. COucou

                    VU ;;))

                    0
                  2. OK pas de soucis ;)
                    0
                6. la politesse tu as appris un peu .
                  je suivrai ton post jusqu'au bout et si ça marche je suivrai tes conseils mais je n'en suis pas convaincu .
                  De plus "barre toi "
                  ça c'est limite.
                  Si tu n'as pas confiance regarde mes post.
                  0
                  1. Contributeur sécurité
                    je suis poli quand on ne vient pas me chercher.

                    Ton n'importe quoi était de trop.

                    Je ne t'ais rien demandé.

                    Tu es venu t'incruster.

                    Tu fais une proposition dangereuse (par rapport à la manière dont on va éliminer bagle, qui s'enlève "à la main" en mode sans échec).

                    Et tu te plains de ma réaction !!

                    mdr.

                    Tu suis ce que tu veux.

                    Et je n'ai pas confiance.
                    0
                  2. Bonjour ludsfa

                    Concernant ComboFix

                    Combofix est un outil puissant, donc particulièrement risqué.
                    L'ordi peut avoir du mal à redémarrer
                    La connection Internet peut planter


                    Il vaut donc mieux ne l'utiliser qu'en dernier recours, quand les autres outils ont échoué.
                    Vundofix, Virtumundobegone, SDFix, Navilog, SmitfraudFix, Clean.zip peuvent faire
                    une grosse partie du travail. L'antivirus et les antispywares aussi.

                    Sers toi des autres outils AVANT d'utiliser cet artillerie lourde à profusion.
                    D'autre part, s'il est mal placé, tu risques à d'autres plantages.

                    A++

                    0
                • 1
                • 2