Wcs.exe

Résolu
Salut , j'ai un probléme , mon resident spybot bloque toutes les 10 sec "wcs.exe " et sa rame a mort puis j'ai des pages internet qui s'affiche tout le temps en disant de telecharger ultimate antivirus , Jai essayé des scans avec avast , norton , mais rien a faire ils trouve 0 infections .Que faire ?
Jai lu un truc dans le forum sur hijackthis et Malwarebytes mais je connais rien en informatique et sa parait quand méme compliqué donc si quelqu'un a une solution a me faire part je suis preneur .
un grand merci d'avance
Configuration: Windows Vista
Firefox 3.0.3

47 réponses

Résumé de la discussion

Le problème porte sur une infection supposée qui déclenche des blocages système et des pages web affichant des invites de téléchargement antivirus, avec wcs.exe et d'autres processus suspects bloquant Windows. Pour éliminer l’infection, redémarrer en mode sans échec et relancer SmitFraudFix en choisissant l’option de nettoyage, puis sauvegarder le rapport et redémarrer en mode normal. Ensuite, analyser un nouveau rapport HijackThis pour repérer les entrées indésirables et, si nécessaire, compléter le nettoyage avec Malwarebytes et des antivirus, puis envisager l’installation d’un pare-feu pour prévenir les réinfections. Dernier élément utile: certains composants peuvent persister après le nettoyage, nécessitant une vérification manuelle des chemins d’exécution et des tâches planifiées.

Bobot (l’IA à votre service)
  1. ok ces plus clair au moins :) ben merci je crois que sans ton aide j'aurais formaté est perdre toute mes données par la méme occasions , encore merci pour ton aide et ta patience :) je classe le topic résolu et je te souhaite une bonne continuation :)

    cordialement adkuate :)
    -1
    1. Contributeur sécurité
      Pourquoi ne pas garder ces outils ?
      Certains mal utilisés peuvent au contraire endommager ta machine.

      garde malwarebytes que tu pourras lancer régulièrement pour vérifier que ton PC n'est pas infecté.

      Avec les protections que tu as sur ton PC, maintenant, tu devrais être plus tranquille.

      Si tu as le moindre problème, reposte un message dans la discussion.

      Peux-tu mettre le sujet comme résolu ? Merci.

      Bon surf et bonne continuation.

      Salut.
      -1
      1. moi ossi g pareil g kaspersky mais impossible de le suprimer c'est un petite iconne attenntion il veut pas partire et il ouvre plein d page et g ossi un otre truc bizzard c'est virus response 2009 jarrive pas a le suprimer g toute essayer aider moi!!!!!!!!!!!!!!!! deplus g pas de cd windows xp o cas ou il marrivera un trucc
        -1
        1. Contributeur sécurité
          Lyako,

          il est préférable d'ouvrir son propre sujet --> Posez votre question.
          Une personne de CCM se fera un plaisir de te répondre et de te dépanner.

          Salut.
          -1
        2. @verni29j'ai deja poser ma question venez m'aider svp
          -1
        3. @verni29j'ai deja poser ma question venez m'aider svp
          -1
      2. Voila le rapport toolscleaner , mais pourquoi ne pas gardé ces logiciels au cas ou ? cela m'intrigue :)
        Enfin en tout cas merci , je sens ma Machine revivre lol

        [ Rapport ToolsCleaner version 2.2.3 (par A.Rothstein & dj QUIOU) ]

        -->- Recherche:

        C:\TB.txt: trouvé !
        C:\Toolbar SD: trouvé !
        C:\Program Files\_OtMoveIt: trouvé !
        C:\Program Files\Trend Micro\HijackThis: trouvé !
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
        C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !
        C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
        C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
        C:\Users\user\Documents\AntiSpyware et securités\HijackThis.lnk: trouvé !
        C:\Users\user\Documents\AntiSpyware et securités\LopSD.exe: trouvé !
        C:\Users\user\Documents\AntiSpyware et securités\OtMoveIt2.exe: trouvé !
        C:\Users\user\Documents\AntiSpyware et securités\SmitFraudFix.exe: trouvé !
        C:\Users\user\Documents\AntiSpyware et securités\ToolBarSD.exe: trouvé !
        C:\Users\user\Documents\AntiSpyware et securités\SmitFraudfix: trouvé !
        C:\Users\user\Documents\Installers\HJTInstall.exe: trouvé !

        ---------------------------------
        -->- Suppression:

        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
        C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: supprimé !
        C:\Users\user\Documents\AntiSpyware et securités\HijackThis.lnk: supprimé !
        C:\Users\user\Documents\AntiSpyware et securités\LopSD.exe: supprimé !
        C:\Users\user\Documents\AntiSpyware et securités\OtMoveIt2.exe: supprimé !
        C:\Users\user\Documents\AntiSpyware et securités\SmitFraudFix.exe: supprimé !
        C:\Users\user\Documents\AntiSpyware et securités\ToolBarSD.exe: supprimé !
        C:\Users\user\Documents\Installers\HJTInstall.exe: supprimé !
        C:\TB.txt: supprimé !
        C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
        C:\Toolbar SD: ERREUR DE SUPPRESSION !!
        C:\Program Files\_OtMoveIt: supprimé !
        C:\Program Files\Trend Micro\HijackThis: supprimé !
        C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: supprimé !
        C:\Users\user\Documents\AntiSpyware et securités\SmitFraudfix: supprimé !

        Fichiers temporaires nettoyés !
        -1
        1. Contributeur sécurité
          Ca y est.On l'a eu.
          Bizarre que la première fois, l'outil ne l'ai pas supprimé.

          1) On va enlever les logiciels qui ont été utilisés..
          Télécharge ToolsCleaner .sur le bureau
          http://pc-system.fr/
          Double-clique sur ToolsCleaner2.exe --> Recherche --> Suppression.
          Il est possible que ton bureau disparaisse.

          Fais un copier/coller du rapport qui se trouve dans C:\TCleaner.txt

          2) Tu vas utiliser CCleaner.
          http://www.commentcamarche.net/telecharger/telecharger 168 ccleaner

          utilise les fonctions nettoyeur et registre.

          3) Les points de restauration :

          - Désactivation de la restauration système :
          Dans le Panneau de configuration choisis l’affichage classique :
          Système --> dans la liste des taches, à gauche, choisis propriétés du système
          Décoche les disques durs sélectionnés.
          Ceci va t'avertir que la restauration système va être désactivée. Accepte.

          Ceci va supprimer les points de restauration existants.

          - Dans la même fenêtre, resélectionner le disque c: puis choisis appliquer.
          Clique ensuite sur créer pour la création d’un point de restauration.
          Suis les invites.

          A+
          -1
          1. -----------\\ ToolBar S&D 1.2.1 XP/Vista

            Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6000 )
            X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU T5550 @ 1.83GHz )
            BIOS : Default System BIOS
            USER : user ( Administrator )
            BOOT : Normal boot
            Antivirus : Avira AntiVir PersonalEdition 8.0.1.27 (Activated)
            Firewall : Sunbelt Personal Firewall 4.6.1845 T (Activated)
            C:\ (Local Disk) - NTFS - Total : 149 Go Free : 110 Go
            D:\ (Local Disk) - NTFS - Total : 141 Go Free : 23 Go
            E:\ (CD or DVD)

            "C:\ToolBar SD" ( MAJ : 24-09-2008|21:50 )
            Option : [2] ( 04/10/2008|17:50 )

            [ UAC => 0 ]

            -----------\\ SUPPRESSION

            Supprime! - C:\Program Files\AskSBar\bar
            Supprime! - C:\Program Files\AskSBar

            -----------\\ Recherche de Fichiers / Dossiers ...

            -----------\\ [..\Internet Explorer\Main]

            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
            "Local Page"="C:\\Windows\\system32\\blank.htm"
            "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
            "Start Page"="about:blank"
            "Url"="https://www.msn.com/fr-fr/actualite/"

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
            "Start Page"="https://www.msn.com/fr-fr/"
            "Default_Page_URL"="https://www.asus.com/fr/"
            "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
            "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
            "Local Page"="%SystemRoot%\\system32\\blank.htm"

            --------------------\\ Recherche d'autres infections

            --------------------\\ Cracks & Keygens ..

            C:\Users\user\Documents\Azureus Downloads\Tracktor DJ Studio 3 + Key\TRAKTOR_DJ_STUDIO_3_KEYGEN.EXE

            [ UAC => 1 ]

            1 - "C:\ToolBar SD\TB_1.txt" - 03/10/2008| 0:47 - Option : [1]
            2 - "C:\ToolBar SD\TB_2.txt" - 03/10/2008|10:47 - Option : [1]
            3 - "C:\ToolBar SD\TB_3.txt" - 03/10/2008|11:04 - Option : [2]
            4 - "C:\ToolBar SD\TB_4.txt" - 03/10/2008|11:09 - Option : [2]
            5 - "C:\ToolBar SD\TB_5.txt" - 04/10/2008|16:36 - Option : [1]
            6 - "C:\ToolBar SD\TB_6.txt" - 04/10/2008|17:54 - Option : [2]

            -----------\\ Fin du rapport a 17:54:05,01
            -1
            1. Contributeur sécurité
              Pour la suite, il faut absolument que tu désactives l4UAC.
              Sinon, l'outil ne nettoiera pas l'infection.

              relance ensuite TollBarS&d ( click droit -> ... )
              Choisis l'option 2 et poste le rapport.

              A+
              -1
              1. hé hop ci joint le rapport toolbar

                -----------\\ ToolBar S&D 1.2.1 XP/Vista

                Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6000 )
                X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU T5550 @ 1.83GHz )
                BIOS : Default System BIOS
                USER : user ( Administrator )
                BOOT : Normal boot
                Antivirus : Avira AntiVir PersonalEdition 8.0.1.27 (Activated)
                Firewall : Sunbelt Personal Firewall 4.6.1845 T (Activated)
                C:\ (Local Disk) - NTFS - Total : 149 Go Free : 111 Go
                D:\ (Local Disk) - NTFS - Total : 141 Go Free : 23 Go
                E:\ (CD or DVD)

                "C:\ToolBar SD" ( MAJ : 24-09-2008|21:50 )
                Option : [1] ( 04/10/2008|16:33 )

                [ UAC => 1 ]

                -----------\\ Recherche de Fichiers / Dossiers ...

                C:\Program Files\AskSBar
                C:\Program Files\AskSBar\bar

                -----------\\ [..\Internet Explorer\Main]

                [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                "Local Page"="C:\\Windows\\system32\\blank.htm"
                "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                "Start Page"="about:blank"
                "Url"="https://www.msn.com/fr-fr/actualite/"

                [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                "Start Page"="https://www.msn.com/fr-fr/"
                "Default_Page_URL"="https://www.asus.com/fr/"
                "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                "Local Page"="%SystemRoot%\\system32\\blank.htm"

                --------------------\\ Recherche d'autres infections

                --------------------\\ Cracks & Keygens ..

                C:\Users\user\Documents\Azureus Downloads\Tracktor DJ Studio 3 + Key\TRAKTOR_DJ_STUDIO_3_KEYGEN.EXE

                [ UAC => 1 ]

                1 - "C:\ToolBar SD\TB_1.txt" - 03/10/2008| 0:47 - Option : [1]
                2 - "C:\ToolBar SD\TB_2.txt" - 03/10/2008|10:47 - Option : [1]
                3 - "C:\ToolBar SD\TB_3.txt" - 03/10/2008|11:04 - Option : [2]
                4 - "C:\ToolBar SD\TB_4.txt" - 03/10/2008|11:09 - Option : [2]
                5 - "C:\ToolBar SD\TB_5.txt" - 04/10/2008|16:36 - Option : [1]
                -1
                1. Contributeur sécurité
                  Oups, je me suis trompé d'outil, c'est ToolbarS&D et non LpoS&D.

                  Désinstalle LopS&D : panneau de configuration --> choisir affichage classique ( en haut à gauche ) --> programmes et fonctionnalités.
                  LopS&D devrait apparaitre dans la liste.

                  1) Vérifie que l'UAC est bien désactivée.

                  2) Télécharge Toolbar-S&D sur ton Bureau ( si tu l'as supprimé )
                  https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

                  * Lance l'installation du programme en exécutant le fichier téléchargé.
                  * click droit --> exécuter en tant qu'administrateur sur le raccourci de Toolbar-S&D.
                  * Sélectionne la langue puis valide.
                  * Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
                  * Copie/colle le contenu du rapport situé dans C:\TB.txt .

                  A+
                  0
                  1. voila le rapport lopsd

                    --------------------\\ Lop S&D 4.2.4-5 XP/Vista

                    Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6000 )
                    X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU T5550 @ 1.83GHz )
                    BIOS : Default System BIOS
                    USER : user ( Administrator )
                    BOOT : Normal boot
                    Antivirus : Avira AntiVir PersonalEdition 8.0.1.27 (Activated)
                    Firewall : Sunbelt Personal Firewall 4.6.1845 T (Activated)
                    C:\ (Local Disk) - NTFS - Total : 149 Go Free : 111 Go
                    D:\ (Local Disk) - NTFS - Total : 141 Go Free : 23 Go
                    E:\ (CD or DVD)

                    "C:\Lop SD" ( MAJ : 02-10-2008|23:42 )
                    Option : [1] ( 04/10/2008|16:24 )

                    [ UAC => 0 ]

                    --------------------\\ Listing des dossiers dans Local

                    [25/09/2008|12:13] C:\Users\user\AppData\Local\Adobe
                    [25/09/2008|12:02] C:\Users\user\AppData\Local\Ahead
                    [25/09/2008|11:59] C:\Users\user\AppData\Local\Application Data
                    [04/10/2008|00:20] C:\Users\user\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
                    [01/10/2008|23:37] C:\Users\user\AppData\Local\GDIPFONTCACHEV1.DAT
                    [25/09/2008|11:59] C:\Users\user\AppData\Local\Historique
                    [04/10/2008|14:13] C:\Users\user\AppData\Local\IconCache.db
                    [03/10/2008|20:59] C:\Users\user\AppData\Local\Microsoft
                    [01/10/2008|23:34] C:\Users\user\AppData\Local\Mozilla
                    [01/10/2008|22:30] C:\Users\user\AppData\Local\Seven Zip
                    [04/10/2008|16:23] C:\Users\user\AppData\Local\Temp
                    [25/09/2008|11:59] C:\Users\user\AppData\Local\Temporary Internet Files
                    [03/10/2008|21:03] C:\Users\user\AppData\Local\VirtualStore

                    --------------------\\ Tâches planifiées dans C:\Windows\tasks

                    [04/10/2008 16:17][--a------] C:\Windows\tasks\Uniblue SpyEraser Nag.job
                    [04/10/2008 13:55][--a------] C:\Windows\tasks\Uniblue SpyEraser.job
                    [04/10/2008 16:21][--a------] C:\Windows\tasks\Maintenance en 1 clic.job
                    [04/10/2008 16:17][--ah-----] C:\Windows\tasks\SA.DAT
                    [04/10/2008 14:13][--a------] C:\Windows\tasks\SCHEDLGU.TXT

                    --------------------\\ Listing des dossiers dans C:\ProgramData

                    [25/09/2008|12:13] C:\ProgramData\Adobe
                    [25/09/2008|12:02] C:\ProgramData\Ahead
                    [02/11/2006|15:02] C:\ProgramData\Application Data
                    [29/09/2008|09:01] C:\ProgramData\ASUS
                    [03/10/2008|14:38] C:\ProgramData\Avira
                    [02/10/2008|14:51] C:\ProgramData\Azureus
                    [02/11/2006|15:02] C:\ProgramData\Desktop
                    [02/11/2006|15:02] C:\ProgramData\Documents
                    [02/11/2006|15:02] C:\ProgramData\Favorites
                    [22/03/2008|03:55] C:\ProgramData\Intel
                    [02/10/2008|22:16] C:\ProgramData\Malwarebytes
                    [01/10/2008|23:34] C:\ProgramData\Microsoft
                    [01/10/2008|23:34] C:\ProgramData\Microsoft Help
                    [25/09/2008|12:01] C:\ProgramData\Nero
                    [22/03/2008|04:16] C:\ProgramData\NVIDIA
                    [22/03/2008|04:01] C:\ProgramData\P4G
                    [02/10/2008|00:05] C:\ProgramData\Soulseek
                    [03/10/2008|14:49] C:\ProgramData\Spybot - Search & Destroy
                    [02/11/2006|15:02] C:\ProgramData\Start Menu
                    [02/10/2008|00:29] C:\ProgramData\Symantec
                    [02/11/2006|15:02] C:\ProgramData\Templates
                    [02/10/2008|00:15] C:\ProgramData\TuneUp Software
                    [04/10/2008|13:54] C:\ProgramData\Uniblue
                    [03/10/2008|20:48] C:\ProgramData\WLInstaller

                    --------------------\\ Listing des dossiers dans C:\Program Files

                    [25/09/2008|12:12] C:\Program Files\Adobe
                    [01/10/2008|23:17] C:\Program Files\Alwil Software
                    [03/10/2008|15:01] C:\Program Files\AskSBar
                    [01/10/2008|23:44] C:\Program Files\ASUS
                    [22/03/2008|03:43] C:\Program Files\ATK Hotkey
                    [22/03/2008|03:43] C:\Program Files\ATKGFNEX
                    [22/03/2008|03:44] C:\Program Files\ATKOSD2
                    [22/03/2008|03:52] C:\Program Files\Attansic
                    [03/10/2008|14:38] C:\Program Files\Avira
                    [01/10/2008|23:28] C:\Program Files\CCleaner
                    [03/10/2008|20:49] C:\Program Files\Common Files
                    [22/03/2008|04:03] C:\Program Files\DIFX
                    [01/10/2008|23:52] C:\Program Files\Free Audio Pack
                    [01/10/2008|23:54] C:\Program Files\InstallShield Installation Information
                    [22/03/2008|03:54] C:\Program Files\Intel
                    [03/10/2008|10:35] C:\Program Files\Internet Explorer
                    [02/10/2008|00:22] C:\Program Files\Java
                    [25/09/2008|12:56] C:\Program Files\K-Lite Codec Pack
                    [02/10/2008|23:55] C:\Program Files\Malwarebytes' Anti-Malware
                    [04/10/2008|02:19] C:\Program Files\Microsoft CAPICOM 2.1.0.2
                    [02/11/2006|14:37] C:\Program Files\Microsoft Games
                    [18/04/2007|11:24] C:\Program Files\Movie Maker
                    [04/10/2008|16:21] C:\Program Files\Mozilla Firefox
                    [02/11/2006|14:37] C:\Program Files\MSBuild
                    [02/11/2006|14:37] C:\Program Files\MSN
                    [18/04/2007|10:43] C:\Program Files\MSXML 4.0
                    [25/09/2008|12:01] C:\Program Files\Nero
                    [22/03/2008|04:01] C:\Program Files\P4G
                    [22/03/2008|04:01] C:\Program Files\Power4Gear eXtreme
                    [22/03/2008|03:50] C:\Program Files\Realtek
                    [02/11/2006|14:37] C:\Program Files\Reference Assemblies
                    [02/10/2008|00:04] C:\Program Files\SoulseekNS
                    [02/10/2008|17:51] C:\Program Files\Spybot - Search & Destroy
                    [03/10/2008|17:49] C:\Program Files\Sunbelt Software
                    [22/03/2008|04:07] C:\Program Files\Synaptics
                    [02/10/2008|22:29] C:\Program Files\Trend Micro
                    [02/10/2008|00:16] C:\Program Files\TuneUp Utilities 2008
                    [02/11/2006|15:01] C:\Program Files\Uninstall Information
                    [01/10/2008|23:25] C:\Program Files\VideoLAN
                    [03/10/2008|15:01] C:\Program Files\Vuze
                    [22/03/2008|03:28] C:\Program Files\Windows Calendar
                    [18/04/2007|11:24] C:\Program Files\Windows Collaboration
                    [22/03/2008|03:28] C:\Program Files\Windows Defender
                    [18/04/2007|11:24] C:\Program Files\Windows Journal
                    [03/10/2008|20:59] C:\Program Files\Windows Live
                    [03/10/2008|10:35] C:\Program Files\Windows Mail
                    [22/03/2008|03:28] C:\Program Files\Windows Media Player
                    [02/11/2006|14:37] C:\Program Files\Windows NT
                    [18/04/2007|11:24] C:\Program Files\Windows Photo Gallery
                    [03/10/2008|10:35] C:\Program Files\Windows Sidebar
                    [02/10/2008|14:48] C:\Program Files\WinRAR
                    [22/03/2008|03:56] C:\Program Files\Wireless Console 2

                    --------------------\\ Listing des dossiers dans C:\Program Files\Common Files

                    [25/09/2008|12:12] C:\Program Files\Common Files\Adobe
                    [25/09/2008|12:02] C:\Program Files\Common Files\Ahead
                    [22/03/2008|04:08] C:\Program Files\Common Files\InstallShield
                    [02/10/2008|00:20] C:\Program Files\Common Files\Java
                    [25/09/2008|12:03] C:\Program Files\Common Files\LightScribe
                    [03/10/2008|20:49] C:\Program Files\Common Files\microsoft shared
                    [02/11/2006|13:18] C:\Program Files\Common Files\Services
                    [02/11/2006|13:18] C:\Program Files\Common Files\SpeechEngines
                    [01/10/2008|23:51] C:\Program Files\Common Files\Symantec Shared
                    [01/10/2008|23:31] C:\Program Files\Common Files\System
                    [03/10/2008|20:58] C:\Program Files\Common Files\WindowsLiveInstaller
                    [02/10/2008|00:15] C:\Program Files\Common Files\Wise Installation Wizard

                    --------------------\\ Process

                    ( 72 Processes )

                    ... OK !

                    --------------------\\ Recherche avec S_Lop

                    Aucun fichier / dossier Lop trouvé !

                    --------------------\\ Recherche de Fichiers / Dossiers Lop

                    Aucun fichier / dossier Lop trouvé !

                    --------------------\\ Verification du Registre

                    ..... OK !

                    --------------------\\ Verification du fichier Hosts

                    Fichier Hosts PROPRE

                    --------------------\\ Recherche de fichiers avec Catchme

                    catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                    Rootkit scan 2008-10-04 16:25:18
                    Windows 6.0.6000 NTFS
                    scanning hidden processes ...
                    scanning hidden files ...
                    scan completed successfully
                    hidden processes: 0
                    hidden files: 0

                    --------------------\\ Recherche d'autres infections

                    --------------------\\ Cracks & Keygens ..

                    C:\Users\user\Documents\Azureus Downloads\Tracktor DJ Studio 3 + Key\TRAKTOR_DJ_STUDIO_3_KEYGEN.EXE

                    [F:63][D:10]-> C:\Users\user\AppData\Local\Temp
                    [F:4][D:0]-> C:\Users\user\AppData\Roaming\MICROS~1\Windows\Cookies
                    [F:401][D:4]-> C:\Users\user\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
                    [F:1][D:1]-> C:\$Recycle.Bin

                    1 - "C:\Lop SD\LopR_1.txt" - 04/10/2008|16:28 - Option : [1]

                    --------------------\\ Fin du rapport a 16:28:39
                    [ UAC => 1 ]
                    0
                    1. Contributeur sécurité
                      On va réessayer ToolBarS&D. Il doit sorcément la supprimer.

                      1) Vérifie que l'UAC est bien désactivée.
                      Je te remets la manip.

                      Dans le panneau de configuration, choisir l’affichage classique.

                      Dans Comptes d’Utilisateurs --> activer ou désactiver le contrôle des comptes d’utilisateurs
                      Puis décoche la ligne "Utiliser le controle .. "
                      Il te sera demandé de redémarrer l’ordinateur. Accepte.

                      2) Télécharge LopS&D si tu l'as supprimé.
                      https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/LopSD.exe?attachauth=ANoY7co3ntqUavpZ3q1BG-h4pc13vqDZmhcNeEPChtsyrgAykRbhE8bZzhk979EfQD4AgwtQUHCaQ7ZQwNYMo3_0kA8htAspckDJtu2K5t6J9z6dLW4fpZyH4FpFL1tVMBZ8H-KnN7afZ5vt-WxZRpnynk-a0XmV_Y0C0q6DxGEDKie1TnPT7gFoZnoCnspzBmbW6ZzxA4fNr3oEDlbelNZON-LjF8nOmQ%3D%3D&attredirects=2

                      Installe le logiciel. Une icône va apparaitre sur le bureau.
                      Lance le logiciel en tant qu’administrateur. ( click droit --> Exécuter en tant qu’administrateur )
                      Tu choisis la langue et valide puis l'option 1 pour effectuer la recherche.
                      A la fin de la recherche, un rapport LopR.txt apparait. Il se trouve en C:\LopR.txt.
                      Si il y a plusieurs rapports, choisis celui avec le chiffre le plus élevé.
                      Tu posteras ce rapport dans le prochain message.

                      A+
                      0
                      1. ok merci !

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 11:44:57, on 04/10/2008
                        Platform: Windows Vista (WinNT 6.00.1904)
                        MSIE: Internet Explorer v7.00 (7.00.6000.16711)
                        Boot mode: Normal

                        Running processes:
                        C:\Windows\system32\taskeng.exe
                        C:\Program Files\ASUS\ASUS Live Update\ALU.exe
                        C:\Windows\system32\Dwm.exe
                        C:\Windows\Explorer.EXE
                        C:\Program Files\Windows Defender\MSASCui.exe
                        C:\Windows\System32\rundll32.exe
                        C:\Windows\System32\rundll32.exe
                        C:\Windows\RtHDVCpl.exe
                        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                        C:\Program Files\ASUS\ATK Media\DMedia.exe
                        C:\Windows\ASScrPro.exe
                        C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                        C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
                        C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
                        C:\Program Files\Mozilla Firefox\firefox.exe
                        C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
                        C:\Windows\system32\wuauclt.exe
                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.asus.com/fr/
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                        O1 - Hosts: ::1 localhost
                        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                        O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\2.bin\ASKSBAR.DLL
                        O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\2.bin\ASKSBAR.DLL
                        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                        O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                        O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                        O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
                        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                        O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
                        O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe
                        O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe
                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                        O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
                        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
                        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
                        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                        O20 - AppInit_DLLs:
                        O23 - Service: ADSM Service (ADSMService) - Unknown owner - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
                        O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                        O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                        O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
                        O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
                        O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                        O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
                        O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
                        O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                        O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
                        O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
                        O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
                        O23 - Service: Syntek AVStream USB2.0 WebCam Service (StkSSrv) - Syntek America Inc. - C:\Windows\System32\StkCSrv.exe
                        O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
                        0
                        1. Contributeur sécurité
                          Poste moi un rapport Hijackthis.

                          A+
                          0
                          1. Salut verni ! voila le rapport otmoveit e que j'ai effectué hier soir

                            Folder move failed. C:\Program Files\AskSBar\bar\2.bin scheduled to be moved on reboot.
                            Folder move failed. C:\Program Files\AskSBar\bar scheduled to be moved on reboot.
                            Folder move failed. C:\Program Files\AskSBar scheduled to be moved on reboot.

                            OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 10042008_005942

                            Les askbars son toujours la , ils ont dans C:/Otmoveit/Askbar , il ya 2 dossiers askbar maintenant + 1 dans mes programs files....
                            0
                            1. Contributeur sécurité
                              Ton PC est propre. Il n'y aucune trace de virus.

                              poste moi le rapport OTMoveIT et après je te donne les dernières consignes.

                              A+
                              0
                              1. voila jai eu le temps de faire le rapport antivir , joint ci dessous.
                                J'attend ta réponse avec impatience !!

                                cordialement adkuate

                                eport file date: samedi 4 octobre 2008 01:54

                                Scanning for 1657543 virus strains and unwanted programs.

                                Licensed to: Avira AntiVir PersonalEdition Classic
                                Serial number: 0000149996-ADJIE-0001
                                Platform: Windows Vista
                                Windows version: (plain) [6.0.6000]
                                Boot mode: Normally booted
                                Username: SYSTEM
                                Computer name: PC-DE-USER

                                Version information:
                                BUILD.DAT : 8.1.0.331 16934 Bytes 12/08/2008 11:46:00
                                AVSCAN.EXE : 8.1.4.7 315649 Bytes 26/06/2008 08:57:53
                                AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 07:56:40
                                LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 12:44:19
                                LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 07:58:52
                                ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 10:33:34
                                ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 24/06/2008 13:54:15
                                ANTIVIR2.VDF : 7.0.6.217 3773440 Bytes 26/09/2008 12:40:11
                                ANTIVIR3.VDF : 7.0.6.241 167936 Bytes 02/10/2008 12:40:14
                                Engineversion : 8.1.1.35
                                AEVDF.DLL : 8.1.0.5 102772 Bytes 25/02/2008 09:58:21
                                AESCRIPT.DLL : 8.1.0.76 319867 Bytes 03/10/2008 12:40:33
                                AESCN.DLL : 8.1.0.23 119156 Bytes 10/07/2008 12:44:49
                                AERDL.DLL : 8.1.1.2 438644 Bytes 03/10/2008 12:40:31
                                AEPACK.DLL : 8.1.2.3 364918 Bytes 03/10/2008 12:40:29
                                AEOFFICE.DLL : 8.1.0.25 196986 Bytes 03/10/2008 12:40:25
                                AEHEUR.DLL : 8.1.0.59 1438071 Bytes 03/10/2008 12:40:24
                                AEHELP.DLL : 8.1.0.15 115063 Bytes 10/07/2008 12:44:48
                                AEGEN.DLL : 8.1.0.36 315764 Bytes 03/10/2008 12:40:18
                                AEEMU.DLL : 8.1.0.7 430452 Bytes 31/07/2008 08:33:21
                                AECORE.DLL : 8.1.1.11 172406 Bytes 03/10/2008 12:40:15
                                AEBB.DLL : 8.1.0.1 53617 Bytes 10/07/2008 12:44:48
                                AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 08:40:05
                                AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 09:28:01
                                AVREP.DLL : 8.0.0.2 98344 Bytes 03/10/2008 12:40:14
                                AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 11:26:40
                                AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
                                AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 12:27:49
                                SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
                                SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 12:49:40
                                NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
                                RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 13:48:07
                                RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 13:34:37

                                Configuration settings for the scan:
                                Jobname..........................: Complete system scan
                                Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
                                Logging..........................: low
                                Primary action...................: interactive
                                Secondary action.................: ignore
                                Scan master boot sector..........: on
                                Scan boot sector.................: on
                                Boot sectors.....................: C:, D:,
                                Process scan.....................: on
                                Scan registry....................: on
                                Search for rootkits..............: off
                                Scan all files...................: All files
                                Scan archives....................: on
                                Recursion depth..................: 20
                                Smart extensions.................: on
                                Macro heuristic..................: on
                                File heuristic...................: medium

                                Start of the scan: samedi 4 octobre 2008 01:54

                                The scan of running processes will be started
                                Scan process 'avscan.exe' - '1' Module(s) have been scanned
                                Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                                Scan process 'firefox.exe' - '1' Module(s) have been scanned
                                Scan process 'conime.exe' - '1' Module(s) have been scanned
                                Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
                                Scan process 'SynTPHelper.exe' - '1' Module(s) have been scanned
                                Scan process 'KBFiltr.exe' - '1' Module(s) have been scanned
                                Scan process 'ATKOSD.exe' - '1' Module(s) have been scanned
                                Scan process 'LightScribeControlPanel.exe' - '1' Module(s) have been scanned
                                Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                                Scan process 'ACEngSvr.exe' - '1' Module(s) have been scanned
                                Scan process 'jusched.exe' - '1' Module(s) have been scanned
                                Scan process 'ASScrPro.exe' - '1' Module(s) have been scanned
                                Scan process 'DMedia.exe' - '1' Module(s) have been scanned
                                Scan process 'SynTPEnh.exe' - '1' Module(s) have been scanned
                                Scan process 'SbPFCl.exe' - '1' Module(s) have been scanned
                                Scan process 'ACMON.exe' - '1' Module(s) have been scanned
                                Scan process 'BatteryLife.exe' - '1' Module(s) have been scanned
                                Scan process 'wcourier.exe' - '1' Module(s) have been scanned
                                Scan process 'ATKOSD2.exe' - '1' Module(s) have been scanned
                                Scan process 'HControl.exe' - '1' Module(s) have been scanned
                                Scan process 'RtHDVCpl.exe' - '1' Module(s) have been scanned
                                Scan process 'rundll32.exe' - '1' Module(s) have been scanned
                                Scan process 'rundll32.exe' - '1' Module(s) have been scanned
                                Scan process 'MSASCui.exe' - '1' Module(s) have been scanned
                                Scan process 'explorer.exe' - '1' Module(s) have been scanned
                                Scan process 'ALU.exe' - '1' Module(s) have been scanned
                                Scan process 'dwm.exe' - '1' Module(s) have been scanned
                                Scan process 'taskeng.exe' - '1' Module(s) have been scanned
                                Scan process 'WmiPrvSE.exe' - '1' Module(s) have been scanned
                                Scan process 'taskeng.exe' - '1' Module(s) have been scanned
                                Scan process 'SearchIndexer.exe' - '1' Module(s) have been scanned
                                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                Scan process 'StkCSrv.exe' - '1' Module(s) have been scanned
                                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                Scan process 'spmgr.exe' - '1' Module(s) have been scanned
                                Scan process 'SbPFSvc.exe' - '1' Module(s) have been scanned
                                Scan process 'SbPFLnch.exe' - '1' Module(s) have been scanned
                                Scan process 'RegSrvc.exe' - '1' Module(s) have been scanned
                                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                Scan process 'LSSrvc.exe' - '1' Module(s) have been scanned
                                Scan process 'EvtEng.exe' - '1' Module(s) have been scanned
                                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                Scan process 'avguard.exe' - '1' Module(s) have been scanned
                                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                Scan process 'sched.exe' - '1' Module(s) have been scanned
                                Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                                Scan process 'GFNEXSrv.exe' - '1' Module(s) have been scanned
                                Scan process 'wlanext.exe' - '1' Module(s) have been scanned
                                Scan process 'ASLDRSrv.exe' - '1' Module(s) have been scanned
                                Scan process 'ADSMSrv.exe' - '1' Module(s) have been scanned
                                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                Scan process 'SLsvc.exe' - '1' Module(s) have been scanned
                                Scan process 'audiodg.exe' - '0' Module(s) have been scanned
                                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                Scan process 'lsm.exe' - '1' Module(s) have been scanned
                                Scan process 'lsass.exe' - '1' Module(s) have been scanned
                                Scan process 'services.exe' - '1' Module(s) have been scanned
                                Scan process 'csrss.exe' - '1' Module(s) have been scanned
                                Scan process 'wininit.exe' - '1' Module(s) have been scanned
                                Scan process 'csrss.exe' - '1' Module(s) have been scanned
                                Scan process 'smss.exe' - '1' Module(s) have been scanned
                                68 processes with 68 modules were scanned

                                Starting master boot sector scan:
                                Master boot sector HD0
                                [INFO] No virus was found!

                                Start scanning boot sectors:
                                Boot sector 'C:\'
                                [INFO] No virus was found!
                                Boot sector 'D:\'
                                [INFO] No virus was found!

                                Starting to scan the registry.
                                The registry was scanned ( '42' files ).

                                Starting the file scan:

                                Begin scan in 'C:\' <VistaOS>
                                C:\pagefile.sys
                                [WARNING] The file could not be opened!
                                Begin scan in 'D:\' <DATA>

                                End of the scan: samedi 4 octobre 2008 02:07
                                Used time: 13:25 Minute(s)

                                The scan has been done completely.

                                10521 Scanning directories
                                143504 Files were scanned
                                0 viruses and/or unwanted programs were found
                                0 Files were classified as suspicious:
                                0 files were deleted
                                0 files were repaired
                                0 files were moved to quarantine
                                0 files were renamed
                                1 Files cannot be scanned
                                143503 Files not concerned
                                1112 Archives were scanned
                                1 Warnings
                                0 Notes
                                0
                                1. effectivement ASKbar ce trouve dans programs file , jai refait la manipe 18 comme tu me la dit , je te met quand même le rapport bitdefender ci dessus (Au cas ou ) .
                                  Pour antivir je post tout sa demain ou ce soir si j'ai le temps , merci ^^

                                  cordialement adkuate
                                  0
                                  1. voila ci joint le rapport bitdefender

                                    General]
                                    App = "BitDefender Online Scanner v8"
                                    Date = 04:10:2008
                                    Time = 01:28:51
                                    Scan Path = C:\;D:\;E:\;

                                    [Engines Info]
                                    Virus Definitions = 1833437
                                    Engine build = "AVCORE v1.7 (build 8314.19) (i386) (Sep 10 2008 19:37:42)"
                                    Scan plugins = 16
                                    Archive plugins = 43
                                    Unpack plugins = 7
                                    E-mail plugins = 6
                                    System plugins = 4

                                    [Scan Statistics]
                                    Folders = 10476
                                    Files = 51562
                                    Archives = 758
                                    Packed files = 5287
                                    Identified viruses = 0
                                    Infected files = 0
                                    Warnings = 0
                                    Suspect files = 0
                                    Disinfected files = 0
                                    Deleted files = 0
                                    Copied files = 0
                                    Moved files = 0
                                    Renamed files = 0
                                    I/O Errors = 7

                                    [Scan Settings]
                                    SecondAction = Delete
                                    FirstAction = Disinfect
                                    Heuristics = 1
                                    Enable Warnings = 1
                                    Exclude Ext =
                                    Extensions = exe;com;dll;ocx;scr;bin;dat;386;vxd;sys;wdm;cla;class;ovl;ole;hlp;doc;dot;xls;ppt;wbk;wiz;pot;ppa;xla;xlt;vbs;vbe;mdb;rtf;htm;hta;html;xml;xtp;php;asp;js;shs;chm;lnk;pif;prc;url;smm;pfd;msi;ini;csc;cmd;bas;
                                    Scan Emails = 1
                                    Scan Archives = 1
                                    Scan Packed = 1
                                    Scan Files = 1
                                    Scan Boot = 1
                                    Verify Memory = 0

                                    [Scan Results]
                                    Line00000000 = "No problems found."
                                    0
                                    1. Contributeur sécurité
                                      Tout va pour le mieux ?
                                      Pour les protections sur ton PC, Oui !!

                                      - Antivir se met à jour très régulièrement. C'est le plus réactif et le meilleur antivirus gratuit.
                                      - Windows defender est très bien. Je l'ai sur ma machine.
                                      Lance Spybot de temps en temps pour vérifier la présence de spywares ou de mouchards. Il ne te trouvera à priori que des cookies, qui ne sont pas dangereux.
                                      - Kerio est un bon parefeu. Tout dépend du niveau de protection que tu as choisi, mais tu auras sans doute au départ des alertes sur des programmes qui veulent accéder au net. Ce sont des règles à créer au debut de l'utilisation d'un parefeu.
                                      Peut-être que je ne t'apprends rien sur ce sujet.

                                      1) J'aimerais que tu me postes le rapport d'antivir.
                                      lance un scan.
                                      Lorsque le scan est terminé, tu as la possibilité de générer un rapport en cliquant sur le bouton report

                                      2) La barre infectieuse AskBar est revenue. Mystère.
                                      refais la manip du message 18
                                      http://www.commentcamarche.net/forum/affich 8705666 wcs exe#18

                                      A+
                                      0
                                      1. voila mon dernier rapport hijack

                                        Logfile of Trend Micro HijackThis v2.0.2
                                        Scan saved at 18:16:58, on 03/10/2008
                                        Platform: Windows Vista (WinNT 6.00.1904)
                                        MSIE: Internet Explorer v7.00 (7.00.6000.16711)
                                        Boot mode: Normal

                                        Running processes:
                                        C:\Windows\system32\taskeng.exe
                                        C:\Windows\system32\Dwm.exe
                                        C:\Windows\system32\taskeng.exe
                                        C:\Windows\Explorer.EXE
                                        C:\Program Files\ASUS\ASUS Live Update\ALU.exe
                                        C:\Program Files\Windows Defender\MSASCui.exe
                                        C:\Windows\System32\rundll32.exe
                                        C:\Windows\RtHDVCpl.exe
                                        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                        C:\Program Files\ASUS\ATK Media\DMedia.exe
                                        C:\Windows\ASScrPro.exe
                                        C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                                        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                                        C:\Windows\System32\rundll32.exe
                                        C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
                                        C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
                                        C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
                                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.asus.com/fr/
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                        O1 - Hosts: ::1 localhost
                                        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                                        O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\2.bin\ASKSBAR.DLL
                                        O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\2.bin\ASKSBAR.DLL
                                        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                        O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                                        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                                        O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                                        O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
                                        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                        O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
                                        O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe
                                        O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe
                                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                                        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                                        O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
                                        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                                        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
                                        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
                                        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                                        O20 - AppInit_DLLs:
                                        O23 - Service: ADSM Service (ADSMService) - Unknown owner - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
                                        O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                        O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                        O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
                                        O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
                                        O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                                        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                        O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
                                        O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
                                        O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                                        O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
                                        O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
                                        O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
                                        O23 - Service: Syntek AVStream USB2.0 WebCam Service (StkSSrv) - Syntek America Inc. - C:\Windows\System32\StkCSrv.exe
                                        O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
                                        0
                                        • 1
                                        • 2
                                        • 3