PC BIZARRE!!

Résolu
Bonjour,
voila mon soucis il me semble que mon pc ne tourne pas rond a plusieurs reprise j ai du faire un boot pour reparer windows (clic sur disque dur et reparer) j ai fait une analyse avec avira : ras sauf warnings 2 que je ne trouve pas,spybot :ras ;malwarebytes:ras
alors j ai fait un hijackthis peut on me dire si le pc est atteint ou c'est moi lol

Scan saved at 18:35:52, on 03/11/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Windows\System32\drivers\Phibtn.exe
C:\Windows\System32\drivers\Tray900.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Windows\system32\conime.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.atcomet.com/b/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.medion.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [RtHDVCpl] "C:\Windows\RtHDVCpl.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\WordPerfect Office X3\Programs\QFSCHD130.EXE"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Windows Mobile Device Center] "C:\Windows\WindowsMobile\wmdc.exe"
O4 - HKLM\..\Run: [SynTPStart] "C:\Program Files\Synaptics\SynTP\SynTPStart.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [PhiBtn] "C:\Windows\System32\Drivers\PhiBtn.exe"
O4 - HKLM\..\Run: [TrayMin900] "C:\Windows\System32\Drivers\Tray900.exe"
O4 - HKCU\..\Run: [Sidebar] "C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Ouvrir dans WordPerfect - C:\Program Files\WordPerfect Office X3\Programs\WPLauncher.hta
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper200711281.dll
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: O2Micro Flash Memory (O2Flash) - O2Micro International - C:\Windows\system32\o2flash.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe
O23 - Service: XAudioService - Unknown owner - C:\Windows\system32\DRIVERS\xaudio.exe (file missing)

--
End of file - 7921 bytes
Configuration: Windows Vista
Firefox 3.0.3

33 réponses

Résumé de la discussion

Un PC fonctionnant sous Windows Vista présente des dysfonctionnements répétés et nécessite parfois une réparation automatique au démarrage, suscitant des doutes sur une infection par malware malgré des scans apparemment rassurants. Plusieurs outils de sécurité ont été utilisés, notamment Avira, Spybot et Malwarebytes, puis HijackThis; les résultats montrent des éléments suspects dans les pages de démarrage et des modules tiers. Les propositions de résolution privilégient l’analyse approfondie via RSIT et un rapport HijackThis, puis des scans en ligne comme Kaspersky pour confirmer l’absence d’infection et proposer des nettoyages ciblés. Certaines recommandations mentionnent aussi des outils de suppression de boîtes de Pandore et la vaccination Spybot, ainsi que de vérifier les extensions et barres d’outils potentiellement indésirables.

Bobot (l’IA à votre service)
  1. Salut Cireluz,

    Le rapport est propre. ;)
    De toutes façons le PC tourne bien, non ?

    Pour ce qui est des backup hosts tu peux les supprimer si tu veux.

    C'est moi qui te remercie pour ta confiance. :)
    Prends soin de toi et de ton PC.

    A+ !'@mi.
    1. bonsoir ok merci et porte toi bien (mon pc ronronne de nouveau c est fantastique!!!)
  2. Re,
    oui moi ça va, merci.

    Sous Vista pour les manip de desinfection il faut être en mode Admin.

    ;)

    alors je voudrais savoir ,il avait quoi ce PC et pourquoi tu m as dit que bitcomet c est de la daube !!utorrent c est pas mieux il parasitait le son de msn et les autres que dirent ils ne sont pas evident as tu un avis sur ce sujet!!(hormis la charte)

    Je n'y connais rien. Et c'est vrai. Pas de P2P épicétou.

    le fichier update checker est toujours bloque au demarrage par mon parefeux es ce normal !!!,

    alors débloque le !

    :-)

    Bonne continuation.

    @++

    Quelques conseils et recommandations pour l'avenir :

    > Passe un coup d'AGV et/ou de MalwareByte's Anti-Malware et de Ccleaner de temps en temps (1 fois par semaine à 1 fois par mois, suivant l'utilisation que tu fais de ton PC. Tu peux aussi décocher la casse dans l’onglet "Options" puis clique sur "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier temp de Windows, plus vieux que 48 heures").
    - Utilise aussi tes autres logiciels de protection (scannes antivirus, antispywares...). N'oublie pas de faire les mises à jour avant de les utiliser.
    - Pense aussi à faire une défragmentation de tes disques durs de temps en temps (garde suffisamment d'espace sur C:\ (1/3 de libre pour être à l'aise))

    > Pour bien protéger ton PC :
    [1 seul Antivirus] + [1 seul Pare feu (/!\ les routeurs et box en possèdent un)] + [Quelques Antispywares] + [Mises à Jour récentes Windows et Logiciels de Protection] + [Utilisation de Firefox -ou autres- (Internet Explorer présente des failles de sécurité qui mettent longtemps avant d'être corrigées mais il faut absolument le conserver pour les mises à jour Windows)] + [Utilisation du PC en mode Invité (= limité). Lors d'une infection en mode administrateur le PC est beaucoup plus vulnérable. Voir ICI]
    PS : En fait la meilleure des protections c'est toi même : ce que tu fais avec ton PC : où tu surfes, télécharges...ect....
    Les virus utilisent les failles de ton PC pour infecter un système. Info : http://assiste.com.free.fr/p/abc/a/zombies_et_botnets.html

    > Quelques liens utiles :
    - http://www.commentcamarche.net/faq/sujet 2432 securite proteger un ordinateur contre les malwares d internet
    - https://sebsauvage.net/safehex.html
    - https://www.zebulon.fr/telechargements/securite/protection-donnees-personnelles/spywareblaster.html (= petit logiciel qui bloque l'installation d'activ-X nuisibles au PC. Fonctionne en arrière plan)

    Tchouss
    1. bonsoir et encore merci de ta devotion il ne faut pas croire que je ne suis pas reconnaisant bien au contraire j admire ce que vous faites sur ce site car du boulot y en a (hein sarko)
      pour ton topic de proteger son pc sache que je le fait tres souvent voir trop souvent et que a force de surfer effectivement je suis amene a tomber sur des bizarreries (ho ho ) je vais souvent sur le site de zebulon et scanner mon pc mais voila des fois mon pc beuggue sans raison il est vrai que je l ai deja remis en configue d usine
      plusieurs fois et enfin pour le fichier host ou il y a des backup anciens je laisse tout come cela? ENCORE MERCI MERCI ET MERCI et je ne crie pas seulement je te remercie bon courage a toi , a toutes et a tous

      merci beaucoup ,merci encore beaucoup,que la force soit avec toi heu et avec moi aussi A+
    2. bonjour encore mouais oups si tu peux regarder cela j ai decouvert sur zebulon merci cela n est pas urgent prends ton temps pour repondre
      amicalement E... A+

      Rapport de ZHPDiag v1.1.3.7 par Nicolas Coolman
      Enregistré le 07/11/2008 10:40:29
      Platform : Windows Vista (TM) Home Premium (6.0.6001) Service Pack 1
      MSIE: Internet Explorer v7.0.6001.18000
      MFIE: Mozilla Firefox (3.0.3)

      ---\\ Processus lancés
      C:\Windows\RtHDVCpl.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe
      C:\Program Files\WordPerfect Office X3\Programs\QFSCHD130.EXE
      C:\Windows\WindowsMobile\wmdc.exe
      C:\Program Files\Synaptics\SynTP\SynTPStart.exe
      C:\Windows\System32\Drivers\PhiBtn.exe
      C:\Windows\System32\Drivers\Tray900.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Windows\ehome\ehTray.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

      ---\\ Modification d'une valeur System.ini (F2)
      F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,
      F2 - REG:system.ini: Shell=explorer.exe

      ---\\ Pages de démarrage d'Internet Explorer (R0)
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.medion.com/
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp

      ---\\ Pages de recherche d'Internet Explorer (R1)
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchasst.htm

      ---\\ Redirection du fichier Hosts (O1)
      O1 - Hosts: ::1 localhost

      ---\\ Browser Helper Objects de navigateur (O2)
      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - C:\Program Files\Java\jre6\bin\ssv.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live
      \WindowsLiveLogin.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

      ---\\ Internet Explorer Toolbars (O3)
      O3 - Toolbar: 1 - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

      ---\\ Applications démarrées automatiquement par le registre (O4)
      O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
      O4 - HKLM\..\Run: [RtHDVCpl] "C:\Windows\RtHDVCpl.exe"
      O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
      O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
      O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\WordPerfect Office X3\Programs\QFSCHD130.EXE"
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
      O4 - HKLM\..\Run: [Windows Mobile Device Center] "C:\Windows\WindowsMobile\wmdc.exe"
      O4 - HKLM\..\Run: [SynTPStart] "C:\Program Files\Synaptics\SynTP\SynTPStart.exe"
      O4 - HKLM\..\Run: [PhiBtn] "C:\Windows\System32\Drivers\PhiBtn.exe"
      O4 - HKLM\..\Run: [TrayMin900] "C:\Windows\System32\Drivers\Tray900.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKCU\..\Run: [Sidebar] "C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
      O4 - HKCU\..\Run: [filehippo.com] "C:\Program Files\filehippo.com\UpdateChecker.exe" /background
      O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray

      ---\\ Invisibilité de l'icône d'options IE dans le panneau de Configuration (O5)
      O5 - control.ini: inetcpl.cpl=no

      ---\\ Lignes supplémentaires dans le menu contextuel d'Internet Explorer (O8)
      O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
      O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
      O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
      O8 - Extra context menu item: Ouvrir dans WordPerfect - C:\Program Files\WordPerfect Office X3\Programs\WPLauncher.hta

      ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
      O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll,211
      O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll,203

      ---\\ Objets ActiveX (Downloaded Program Files)(O16)
      O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} () -
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper200711281.dll
      O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} () - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab

      ---\\ Protocole additionnel et piratage de protocole (O18)
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

      ---\\ Clé de Registre autorun SharedTaskScheduler (O22)
      O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030}

      ---\\ Composants installés (ActiveSetup Installed Components) (O40)
      O40 - ASIC: Microsoft Windows Media Player - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
      O40 - ASIC: Internet Explorer - {26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
      O40 - ASIC: Browser Customizations - {60B49E34-C7CC-11D0-8953-00A0C90347FF} - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
      O40 - ASIC: Installation Support - {0291E591-EA41-4c82-8106-3DC6CE7F7664} - C:\Program Files\Yahoo!\Common\Yinsthelper200711281.dll
      O40 - ASIC: Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - (not file)
      O40 - ASIC: (no name) - {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - (not file)
      O40 - ASIC: Microsoft Windows Media Player 11.0 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\System32\wmpdxm.dll
      O40 - ASIC: Themes Setup - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - C:\Windows\system32\regsvr32.exe /s /n /i:/UserInstall C:\Windows\system32\themeui.dll
      O40 - ASIC: Installation Support - {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - C:\Program Files\Yahoo!\Common\Yinsthelper200711281.dll
      O40 - ASIC: Installation Support - {347B0667-C7ED-429B-BDE3-CC8D3BACAA31} - C:\Program Files\Yahoo!\Common\Yinsthelper200711281.dll
      O40 - ASIC: Offline Browsing Pack - {3af36230-a269-11d1-b5bf-0000f8051515} - (not file)
      O40 - ASIC: Microsoft Windows Mail 7 - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
      O40 - ASIC: (no name) - {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - (not file)
      O40 - ASIC: DirectDrawEx - {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - (not file)
      O40 - ASIC: Internet Explorer Help - {45ea75a0-a269-11d1-b5bf-0000f8051515} - (not file)
      O40 - ASIC: Microsoft Windows Script 5.6 - {4f645220-306d-11d2-995d-00c04f98bbc9} - (not file)
      O40 - ASIC: Internet Explorer Setup Tools - {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - (not file)
      O40 - ASIC: Browsing Enhancements - {630b1da0-b465-11d1-9948-00c04f98bbc9} - (not file)
      O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} - C:\Windows\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI
      O40 - ASIC: MSN Site Access - {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - (not file)
      O40 - ASIC: Address Book 7 - {7790769C-0471-11d2-AF11-00C04FA35D02} - (not file)
      O40 - ASIC: .NET Framework - {7C028AF8-F614-47B3-82DA-BA94E41B1089} - (not file)
      O40 - ASIC: Windows Desktop Update - {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
      O40 - ASIC: Internet Explorer - {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
      O40 - ASIC: (no name) - {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
      O40 - ASIC: Dynamic HTML Data Binding - {9381D8F2-0288-11D0-9501-00AA00B911A5} - (not file)
      O40 - ASIC: .NET Framework - {C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD} - (not file)
      O40 - ASIC: Internet Explorer Core Fonts - {C9E9A340-D1F1-11D0-821E-444553540600} - (not file)
      O40 - ASIC: (no name) - {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - (not file)
      O40 - ASIC: Adobe Flash Player - {D27CDB6E-AE6D-11CF-96B8-444553540000} - C:\Windows\system32\Macromed\Flash\Flash10a.ocx
      O40 - ASIC: HTML Help - {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - (not file)
      O40 - ASIC: Active Directory Service Interface - {E92B03AB-B707-11d2-9CBD-0000F87A369E} - (not file)

      ---\\ Logiciels installés (O42)
      O42 - Logiciel: Adobe Flash Player 10 ActiveX
      O42 - Logiciel: Adobe Flash Player 10 Plugin
      O42 - Logiciel: Avira AntiVir Personal - Free Antivirus
      O42 - Logiciel: BitComet 1.05
      O42 - Logiciel: CCleaner (remove only)
      O42 - Logiciel: Defraggler (remove only)
      O42 - Logiciel: filehippo.com Update Checker
      O42 - Logiciel: O2Micro Flash Memory Card Windows Driver V3.00
      O42 - Logiciel: Malwarebytes' Anti-Malware
      O42 - Logiciel: Mozilla Firefox (3.0.3)
      O42 - Logiciel: MpcStar 3.2
      O42 - Logiciel: nCleaner second 2.3.4.0
      O42 - Logiciel: Intel(R) PRO Network Connections 11.2.0.69
      O42 - Logiciel: QuickTime Alternative 2.7.0
      O42 - Logiciel: SpywareBlaster 4.1
      O42 - Logiciel: Synaptics Pointing Device Driver
      O42 - Logiciel: VLC media player 0.9.4
      O42 - Logiciel: Yahoo! Toolbar avec bloqueur de fenêtres pop-up
      O42 - Logiciel: WordPerfect Office X3
      O42 - Logiciel: Java(TM) 6 Update 10
      O42 - Logiciel: ATI Catalyst Control Center Ex
      O42 - Logiciel: Philips SPC 900NC PC Camera
      O42 - Logiciel: neroxml
      O42 - Logiciel: Windows Media Player Firefox Plugin
      O42 - Logiciel: Analyseur et SDK MSXML 4.0 SP2
      O42 - Logiciel: Microsoft Silverlight
      O42 - Logiciel: Gestionnaire pour appareils Windows Mobile
      O42 - Logiciel: IZArc 3.81
      O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable
      O42 - Logiciel: Adobe Reader 9 - Français
      O42 - Logiciel: Spelling Dictionaries Support For Adobe Reader 9
      O42 - Logiciel: Assistant de connexion Windows Live
      O42 - Logiciel: Spybot - Search & Destroy
      O42 - Logiciel: Windows Live Messenger
      O42 - Logiciel: MSXML 4.0 SP2 (KB936181)
      O42 - Logiciel: MSXML 4.0 SP2 (KB941833)
      O42 - Logiciel: Realtek High Definition Audio Driver
      O42 - Logiciel: 32 Bit HP CIO Components Installer
      O42 - Logiciel: Nero 7 Essentials
      O42 - Logiciel: Vista Codec Package
      O42 - Logiciel: Windows Live installer

      ---\\ Déni du service Local Security Authority (LSA) (O48)
      O48 - LSA:Local Security Authority Authentication Packages -
      O48 - LSA:Local Security Authority Notification Packages -

      End of the scan:
  3. Ok parfait l'ami ;)

    Juste un truc : tu as fais tourner deux fois Toolscleaner, non ?
    Dis moi juste si tu as encore des programmes tels que :
    HijackT
    SmitfraudFix
    ect...

    A+
    1. non je n ai plus rien de cela et si j ai utilise 2 fois tool c est qu il a bloque et ne repondait plus par moment c est difficile : soit le logiciel se lance soit je doit me mettre en administrateur!!!!! bon je pense que mon pc va bien et toi???
    2. alors je voudrais savoir ,il avait quoi ce PC et pourquoi tu m as dit que bitcomet c est de la daube !!utorrent c est pas mieux il parasitait le son de msn et les autres que dirent ils ne sont pas evident as tu un avis sur ce sujet!!(hormis la charte)
      je suis alle voir les fichier hosts il y a des backup qui datent c normal!!!
      le fichier update checker est toujours bloque au demarrage par mon parefeux es ce normal !!!
  4. Salut Cireluz,
    ok parfait. C'est parce que tu as spybot.

    Peux-tu ouvrir Spybot, faire les mises à jour puis une vaccination comme indiqué sur cette image ? https://forums.cnetfrance.fr
    Ensuite si tu veux tu peux lancer un scan.
    https://forums.cnetfrance.fr

    Alors, si tu n'as plus de souci :
    > Télécharge ToolsCleaner : https://www.commentcamarche.net/telecharger/securite/22061-toolscleaner/ sur ton bureau pour supprimer les boîtes de Pandore.
    - Clique sur Recherche et laisse le scan agir ...
    - Clique sur Suppression pour finaliser (tu peux, si tu le souhaites, te servir des Options facultatives)
    - Clique sur Quitter pour obtenir le rapport et poste le dans ta réponse (TCleaner.txt se trouve à la racine de ton disque dur (C:\)).
    - Supprime ToolsCleaner ensuite (il n'est pas installé dans Ajout/suppression de programmes. C'est un fichier directement exécutable : pas d'installation).

    Ensuite,
    > Télécharge et installe Update Checker : https://filehippo.com/windows/tuning-utilities/
    - Lance le programme. Une page web de ce type va s'ouvrir.
    - Fais les mises à jour de tous les logiciels proposés pour Update. Je ne te conseille pas de faire celles pour les versions béta (elles peuvent être instables).
    - Fais un copier/coller de la liste de éléments "Updates". Puis poste la sur le forum.
    - Une fois les mises à jour effectuées, relance ton PC.
    Tuto si problèmes : http://www.commentcamarche.net/faq/sujet 9908 update checker vos logiciels sont ils a jour

    Puis on termine.
    Bon courage.
    1. chalut,et bon appetit voila les resultats et the winner is?
      [ Rapport ToolsCleaner version 2.2.5 (par A.Rothstein & dj QUIOU) ]

      -->- Recherche:

      ---------------------------------
      -->- Suppression:

      Corbeille vidée!
      Fichiers temporaires nettoyés !

      http://www.filehippo.com/download_nero_burning_rom/
      impossible a installe sans license!!!!!!(j ai la version 7 )
      j ai installe flash player 10(pas pris le lien avant desole)
  5. Ok super.

    Peux tu faire le SmitfraudFix option 1 (et uniquement) stp ?

    J'ai 13 ans, pourquoi ? Et toi ?
    1. merci pour tes encouragements je me sent moins casse MERCI..................

      SmitFraudFix v2.371

      Scan done at 19:25:21,40, 05/11/2008
      Run from C:\Users\ERIC\Downloads\SmitfraudFix
      OS: Microsoft Windows [version 6.0.6001] - Windows_NT
      The filesystem type is NTFS
      Fix run in normal mode

      »»»»»»»»»»»»»»»»»»»»»»»» Process

      C:\Windows\system32\csrss.exe
      C:\Windows\system32\wininit.exe
      C:\Windows\system32\csrss.exe
      C:\Windows\system32\services.exe
      C:\Windows\system32\lsass.exe
      C:\Windows\system32\lsm.exe
      C:\Windows\system32\winlogon.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\system32\Ati2evxx.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\SLsvc.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\Ati2evxx.exe
      C:\Windows\System32\spoolsv.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Windows\system32\taskeng.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      C:\Windows\system32\svchost.exe
      C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\system32\o2flash.exe
      C:\Windows\system32\IoctlSvc.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\PSIService.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\system32\SearchIndexer.exe
      C:\Windows\system32\taskeng.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Windows\RtHDVCpl.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
      C:\Windows\WindowsMobile\wmdc.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\System32\drivers\Phibtn.exe
      C:\Windows\System32\drivers\Tray900.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Windows\ehome\ehtray.exe
      C:\Windows\System32\mobsync.exe
      C:\Windows\ehome\ehmsas.exe
      C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
      C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
      C:\Program Files\Windows Live\Messenger\usnsvc.exe
      C:\Windows\system32\WUDFHost.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
      C:\Windows\ehome\ehsched.exe
      C:\Windows\ehome\ehRecvr.exe
      C:\Windows\system32\taskeng.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Windows\system32\SearchProtocolHost.exe
      C:\Windows\system32\conime.exe
      C:\Windows\system32\wbem\wmiprvse.exe
      C:\Windows\system32\SearchFilterHost.exe
      C:\Windows\system32\cmd.exe

      »»»»»»»»»»»»»»»»»»»»»»»» hosts

      hosts file corrupted !

      127.0.0.1 www.legal-at-spybot.info
      127.0.0.1 legal-at-spybot.info

      »»»»»»»»»»»»»»»»»»»»»»»» C:\

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\ERIC

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\ERIC\AppData\Local\Temp

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\ERIC\Application Data

      »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\ERIC\FAVORI~1

      »»»»»»»»»»»»»»»»»»»»»»»» Desktop

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

      »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

      »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

      »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
      !!!Attention, following keys are not inevitably infected!!!

      o4Patch
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
      !!!Attention, following keys are not inevitably infected!!!

      IEDFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» VACFix
      !!!Attention, following keys are not inevitably infected!!!

      VACFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
      !!!Attention, following keys are not inevitably infected!!!

      404Fix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix
      !!!Attention, following keys are not inevitably infected!!!

      AntiXPVSTFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
      !!!Attention, following keys are not inevitably infected!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
      !!!Attention, following keys are not inevitably infected!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      "AppInit_DLLs"=""
      "LoadAppInit_DLLs"=dword:00000000

      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
      !!!Attention, following keys are not inevitably infected!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
      "Userinit"="C:\\Windows\\system32\\userinit.exe,"

      »»»»»»»»»»»»»»»»»»»»»»»» RK

      »»»»»»»»»»»»»»»»»»»»»»»» DNS

      Description: Intel(R) PRO/Wireless 3945ABG Network Connection
      DNS Server Search Order: 192.168.1.1

      HKLM\SYSTEM\CCS\Services\Tcpip\..\{2A8E40E8-18C5-413D-96D7-DEA3F7D6EFD9}: DhcpNameServer=192.168.1.1
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{2A8E40E8-18C5-413D-96D7-DEA3F7D6EFD9}: DhcpNameServer=192.168.1.1
      HKLM\SYSTEM\CS2\Services\Tcpip\..\{2A8E40E8-18C5-413D-96D7-DEA3F7D6EFD9}: DhcpNameServer=192.168.1.1
      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
      HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

      »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

      »»»»»»»»»»»»»»»»»»»»»»»» End

      j ai un peu plus que toi ok mais je ne fait pas usage de ce droit lol
    2. bonjour a toi DLLD tu vas rire mais j ai choppe un virus non pas mon pc mais moi je suis courbature a mort (a force de piannoter sur mon pc lol) non sans rire je suis raplapla j espere que tu es en forme toi A+
  6. LOL

    T'arrête un peu de t'excuser, oui !?

    :DDD

    Bon essaye ce lien alors : http://siri.urz.free.fr/Fix/SmitfraudFix.exe

    PS :

    ......par contre les 2 autres antivir delete virus


    Ca ne veut rien dire ?!
    (En tous cas j'ai pas compris !)

    @:+)
    1. heu ex.... la page ne s ouvre pas non plus (ce n est pas moi qui est un probleme)
    2. @cireluzHeu ok désolé.

      http://www.cijoint.fr/cjlink.php?file=cj200811/cijdDHD9hC.zip

      Pardon & merci.
    3. dit j ai essaye de telecharge smitfraud sur zebulon et mon anti virus a alerte sur DR/tool.reboot f11 dropper
      je n ose pas desactiver antivir au vue du message ; d autres part je continue avec kapersky a analyser tous mes disque )) cela n a pas de cause direct??? merci Mr
    4. @Utilisateur anonymeecoute je ne sais pas ce qui ce passe ou je pense deviner(blague non) meme probleme avec ton fichier dr/tool.reboot f9 dropper je ne sais pas quoi faire et je ne rigole pas maitre
  7. loul

    Ok,
    heureusement que je suis en repos lol,

    alors remue toi un peu et arrête de faire le coq ! :-)

    Le dernier souvenir que j'ai de toi c'est un topique de plus de 300 postes pour en arriver au simple fait que tu es sous Vista que c'est lui qui plombe ta bécane.
    Certes, on a bien rigolé.
    Mais là on est pas au café ;)

    Alors,
    très cher Cireluz, je vais t'expliquer comment ça marche :
    1°/ Le gros vilain c'est toi car tu ne prends pas soin de ta machine. (je me marre :D)
    2°/ Tu uses du P2P comme c'est pas permis, non ?
    3°/ Ici, sur CCM, tu as affaire à des bénévoles qui consacre gentiment du temps à trouver une solution à ton problème. Donc il ne faut pas cracher dans la soupe.
    4°/ Pour les Hosts, oui j'avais bien lu ton message. C'est moi qui me suis trompé en te donnant le même programme. Toutes mes excuses.
    5°/ Pour me le faire remarquer PAS BESOIN DE CRIER !
    6°/ Tu vas bien gentiment faire ce qui suit, et sans faire le pitre stp, afin que ton problème soit entièrement résolu ;-)
    7°/ Une fois la bécane ronronnante on déconnera.

    Es-tu d'accord ?

    8°/ Merci.

    :)

    Bon parfait pour le Kasper.
    Tu vois pas besoin de s'affoler :)

    Maintenant,
    >Ouvre ce lien http://siri.urz.free.fr/Fix/SmitfraudFix.php et télécharge SmitfraudFix (de S!RI).
    - Regarde le tuto
    - Exécute le programme et choisi l’option 1 (et uniquement).
    NB : sous Vista : fais un clic-droit sur le programme et choisis "Exécuter en tant qu'administrateur"
    Le programme va générer un rapport, copie/colle le sur le forum.

    On a bientôt terminé.
    Plus de souci l'ami ?

    :)

    A+
    1. ho ho on hausse le thon lol desole je ne criais pas et sache que je respecte ton boulot comme celui de tous a ccm je suis un grand deconneur et pis c tout bon serieusement je te remercie pour ton humo......... heu serieux bon je travaille si si
    2. heu excuse moi mais le site pour smitfraux est corrompu tous les liens sont rejetes par avira
    3. @cireluzOk,
      Bah c'est pas un souci.

      Désactive Antivir le temps du Dl et du scan.

      A+ ;)
    4. @Utilisateur anonymeheu reexcuse mais le lien que tu me dit d ouvrir est rejete impossible d ouvir avec firefox page introuvable heu.....
      ......par contre les 2 autres antivir delete virus
  8. Re,
    Ok, parfait.

    Tu arrives à faire le scan en ligne ?

    Tu peux fixer cette ligne dans HJT :
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    Ensuite,
    pour ce qui est du fichier Hosts :
    > Télécharger Hoster : http://www.funkytoad.com/download/HostsXpert.zip
    - Dézippe le dossier sur le bureau.
    - Lance Hoster et cliquer sur <Restore Microsoft's Hosts File>.

    Alors ?

    ;@)
    1. TU N AS PAS LU MES MESSAGES HO HO LE VILAIN avec kapersky cela se complique fichier endommage !!! alors je reessaye en administrateur oups!!!!!
      fichier hoster: error cannot create file C:/windows/systeme32/drivers/etc/hosts

      heureusement que je suis en repos lol
    2. meme soucis avec hoster sur bureau ou c: error
    3. kapersky en administrateur fonctionne 1ere analyse
      KASPERSKY ON-LINE SCANNER REPORT
      Wednesday, November 05, 2008 5:31:01 PM
      Système d'exploitation : Home Edition, Service Pack 1 (Build 6001)
      Kaspersky On-line Scanner version : 5.0.84.2
      Dernière mise à jour de la base antivirus Kaspersky : 5/11/2008
      Enregistrements dans la base antivirus Kaspersky : 1228632
      Paramètres d'analyse
      Analyser avec la base antivirus suivante standard
      Analyser les archives vrai
      Analyser les bases de messagerie vrai
      Cible de l'analyse Zones critiques
      C:\Windows
      C:\Users\ERIC\AppData\Local\Temp\
      Statistiques de l'analyse
      Total d'objets analysés 54869
      Nombre de virus trouvés 0
      Nombre d'objets infectés 0 / 0
      Nombre d'objets suspects 0
      Durée de l'analyse 00:29:33

      Nom de l'objet infecté Nom du virus Dernière action
      C:\Windows\bthservsdp.dat L'objet est verrouillé ignoré
      C:\Windows\Debug\PASSWD.LOG L'objet est verrouillé ignoré
      C:\Windows\Debug\WIA\wiatrace.log L'objet est verrouillé ignoré
      C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat L'objet est verrouillé ignoré
      C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat L'objet est verrouillé ignoré
      C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\WindowsUpdate.log L'objet est verrouillé ignoré
      C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT L'objet est verrouillé ignoré
      C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1 L'objet est verrouillé ignoré
      C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG2 L'objet est verrouillé ignoré
      C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{fb36221e-a6ae-11dd-a0d5-806e6f6e6963}.TM.blf L'objet est verrouillé ignoré
      C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{fb36221e-a6ae-11dd-a0d5-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms L'objet est verrouillé ignoré
      C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{fb36221e-a6ae-11dd-a0d5-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms L'objet est verrouillé ignoré
      C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT L'objet est verrouillé ignoré
      C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1 L'objet est verrouillé ignoré
      C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG2 L'objet est verrouillé ignoré
      C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{fb362219-a6ae-11dd-a0d5-806e6f6e6963}.TM.blf L'objet est verrouillé ignoré
      C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{fb362219-a6ae-11dd-a0d5-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms L'objet est verrouillé ignoré
      C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{fb362219-a6ae-11dd-a0d5-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms L'objet est verrouillé ignoré
      C:\Windows\SoftwareDistribution\ReportingEvents.log L'objet est verrouillé ignoré
      C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 L'objet est verrouillé ignoré
      C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 L'objet est verrouillé ignoré
      C:\Windows\System32\catroot2\edb.log L'objet est verrouillé ignoré
      C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb L'objet est verrouillé ignoré
      C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb L'objet est verrouillé ignoré
      C:\Windows\System32\config\COMPONENTS L'objet est verrouillé ignoré
      C:\Windows\System32\config\COMPONENTS.LOG1 L'objet est verrouillé ignoré
      C:\Windows\System32\config\COMPONENTS.LOG2 L'objet est verrouillé ignoré
      C:\Windows\System32\config\DEFAULT L'objet est verrouillé ignoré
      C:\Windows\System32\config\DEFAULT.LOG1 L'objet est verrouillé ignoré
      C:\Windows\System32\config\DEFAULT.LOG2 L'objet est verrouillé ignoré
      C:\Windows\System32\config\RegBack\COMPONENTS L'objet est verrouillé ignoré
      C:\Windows\System32\config\RegBack\DEFAULT L'objet est verrouillé ignoré
      C:\Windows\System32\config\RegBack\SAM L'objet est verrouillé ignoré
      C:\Windows\System32\config\RegBack\SECURITY L'objet est verrouillé ignoré
      C:\Windows\System32\config\RegBack\SOFTWARE L'objet est verrouillé ignoré
      C:\Windows\System32\config\RegBack\SYSTEM L'objet est verrouillé ignoré
      C:\Windows\System32\config\SAM L'objet est verrouillé ignoré
      C:\Windows\System32\config\SAM.LOG1 L'objet est verrouillé ignoré
      C:\Windows\System32\config\SAM.LOG2 L'objet est verrouillé ignoré
      C:\Windows\System32\config\SECURITY L'objet est verrouillé ignoré
      C:\Windows\System32\config\SECURITY.LOG1 L'objet est verrouillé ignoré
      C:\Windows\System32\config\SECURITY.LOG2 L'objet est verrouillé ignoré
      C:\Windows\System32\config\SOFTWARE L'objet est verrouillé ignoré
      C:\Windows\System32\config\SOFTWARE.LOG1 L'objet est verrouillé ignoré
      C:\Windows\System32\config\SOFTWARE.LOG2 L'objet est verrouillé ignoré
      C:\Windows\System32\config\SYSTEM L'objet est verrouillé ignoré
      C:\Windows\System32\config\SYSTEM.LOG1 L'objet est verrouillé ignoré
      C:\Windows\System32\config\SYSTEM.LOG2 L'objet est verrouillé ignoré
      C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat L'objet est verrouillé ignoré
      C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
      C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat L'objet est verrouillé ignoré
      C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TM.blf L'objet est verrouillé ignoré
      C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000001.regtrans-ms L'objet est verrouillé ignoré
      C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000002.regtrans-ms L'objet est verrouillé ignoré
      C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000003.regtrans-ms L'objet est verrouillé ignoré
      C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000004.regtrans-ms L'objet est verrouillé ignoré
      C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000005.regtrans-ms L'objet est verrouillé ignoré
      C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000006.regtrans-ms L'objet est verrouillé ignoré
      C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000007.regtrans-ms L'objet est verrouillé ignoré
      C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000008.regtrans-ms L'objet est verrouillé ignoré
      C:\Windows\System32\config\TxR\{fb36220b-a6ae-11dd-a0d5-806e6f6e6963}.TxR.0.regtrans-ms L'objet est verrouillé ignoré
      C:\Windows\System32\config\TxR\{fb36220b-a6ae-11dd-a0d5-806e6f6e6963}.TxR.1.regtrans-ms L'objet est verrouillé ignoré
      C:\Windows\System32\config\TxR\{fb36220b-a6ae-11dd-a0d5-806e6f6e6963}.TxR.2.regtrans-ms L'objet est verrouillé ignoré
      C:\Windows\System32\config\TxR\{fb36220b-a6ae-11dd-a0d5-806e6f6e6963}.TxR.blf L'objet est verrouillé ignoré
      C:\Windows\System32\LogFiles\Scm\SCM.EVM L'objet est verrouillé ignoré
      C:\Windows\System32\LogFiles\WUDF\WUDFTrace.etl L'objet est verrouillé ignoré
      C:\Windows\System32\Msdtc\KtmRmTm.blf L'objet est verrouillé ignoré
      C:\Windows\System32\Msdtc\KtmRmTmContainer00000000000000000001 L'objet est verrouillé ignoré
      C:\Windows\System32\Msdtc\KtmRmTmContainer00000000000000000002 L'objet est verrouillé ignoré
      C:\Windows\System32\spool\SpoolerETW.etl L'objet est verrouillé ignoré
      C:\Windows\System32\wbem\repository\INDEX.BTR L'objet est verrouillé ignoré
      C:\Windows\System32\wbem\repository\MAPPING1.MAP L'objet est verrouillé ignoré
      C:\Windows\System32\wbem\repository\MAPPING2.MAP L'objet est verrouillé ignoré
      C:\Windows\System32\wbem\repository\OBJECTS.DATA L'objet est verrouillé ignoré
      C:\Windows\System32\WDI\LogFiles\WdiContextLog.etl.002 L'objet est verrouillé ignoré
      C:\Windows\System32\wfp\wfpdiag.etl L'objet est verrouillé ignoré
      C:\Windows\System32\winevt\Logs\ACEEventLog.evtx L'objet est verrouillé ignoré
      C:\Windows\System32\winevt\Logs\Application.evtx L'objet est verrouillé ignoré
      C:\Windows\System32\winevt\Logs\DFS Replication.evtx L'objet est verrouillé ignoré
      C:\Windows\System32\winevt\Logs\HardwareEvents.evtx L'objet est verrouillé ignoré
      C:\Windows\System32\winevt\Logs\Internet Explorer.evtx L'objet est verrouillé ignoré
      C:\Windows\System32\winevt\Logs\Key Management Service.evtx L'objet est verrouillé ignoré
      C:\Windows\System32\winevt\Logs\Media Center.evtx L'objet est verrouillé ignoré
      C:\Windows\System32\winevt\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx L'objet est verrouillé ignoré
      C:\Windows\System32\winevt\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx L'objet est verrouillé ignoré
      C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx L'objet est verrouillé ignoré
      C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx L'objet est verrouillé ignoré
      C:\Windows\System32\winevt\Logs\Microsoft-Windows-DriverFrameworks-UserMode%4Operational.evtx L'objet est verrouillé ignoré
      C:\Windows\System32\winevt\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx L'objet est verrouillé ignoré
      C:\Windows\System32\winevt\Logs\Microsoft-Windows-International%4Operational.evtx L'objet est verrouillé ignoré
      C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA.evtx L'objet est verrouillé ignoré
      C:\Windows\System32\winevt\Logs\Microsoft-Windows-LanguagePackSetup%4Operational.evtx L'objet est verrouillé ignoré
      C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4Operational.evtx L'objet est verrouillé ignoré
      C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx L'objet est verrouillé ignoré
      C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx L'objet est verrouillé ignoré
      C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx L'objet est verrouillé ignoré
      C:\Windows\System32\winevt\Logs\Microsoft-Windows-TaskScheduler%4Operational.evtx L'objet est verrouillé ignoré
      C:\Windows\System32\winevt\Logs\Microsoft-Windows-UAC-FileVirtualization%4Operational.evtx L'objet est verrouillé ignoré
      C:\Windows\System32\winevt\Logs\Microsoft-Windows-WindowsUpdateClient%4Operational.evtx L'objet est verrouillé ignoré
      C:\Windows\System32\winevt\Logs\Microsoft-Windows-WLAN-AutoConfig%4Operational.evtx L'objet est verrouillé ignoré
      C:\Windows\System32\winevt\Logs\Security.evtx L'objet est verrouillé ignoré
      C:\Windows\System32\winevt\Logs\System.evtx L'objet est verrouillé ignoré
      C:\Windows\Tasks\SCHEDLGU.TXT L'objet est verrouillé ignoré
      C:\Windows\WindowsUpdate.log L'objet est verrouillé ignoré
      C:\Users\ERIC\AppData\Local\Temp\etilqs_fbBXNkwTW5iyWHCK5yqZ L'objet est verrouillé ignoré
      Analyse terminée.
  9. Re,
    je me disais bien..... On se débarrasse pas facilement de toi :DDD

    Bon,
    à la place de Zebrestore :
    > télécharge Hostsxpert : https://www.clubic.com/telecharger-fiche185974-hostsxpert.html
    - Clique droit sur le ficher zip et decompresse le sur ton dique où il y a windows.
    - Lance le programme puis clique sur <restore ms host file>, puis sur < ok >
    - Click sur <Make Hosts Read Only> pour les sécuriser contre de futures infections.
    - Ferme le programme.

    Pour BitComet c'est TON problème ! (lol)
    Le programme est classé légitime mais à ta place je m'en séparerai.

    Poste ensuite un nouveau HiJackT stp.

    Puis on va faire un scanne en ligne. Tu es sous Vista mais il devrait passer.
    > Fais un scan en ligne avec Kaspersky : https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
    N.B. : Le scan ne marche que sous Internet Explorer.
    - Commence par connecter tout ton matériel de stockage à ton PC (clés USB, DD amovible...). Allume les si nécessaire.
    - Sous Démonstration en ligne, on t'explique la marche à suivre, et pour lancer le scan il faut sélectionner < Exécuter l'analyse en ligne >.
    - On va te demander de télécharger un contrôle active x, accepte .
    - Dans le menu < Choisissez la cible de l'analyse >, sélectionne < Poste de travail >. Le scan va commencer.
    - Poste le rapport qui sera généré stp. (clique sur <enregistrer le rapport> puis sauvegarde-le sur ton bureau en choisissant "fichier texte (*.txt)" pour l'extension).
    S'il y a un problème, assure toi que les contrôles active x sont bien configurés dans les options internet comme décrit sur ce lien : http://www.inoculer.com/activex.php3
    Rappel : le scan est à faire sous Internet Explorer
    Tuto ici si problème : http://www.vista-xp.fr/forum/topic109.html
    NOTE : Si tu reçois le message "La licence de Kaspersky On-line Scanner est périmée", va dans Ajout/Suppression de programmes puis désinstalle On-Line Scanner, reconnecte toi sur le site de Kaspersky pour retenter le scan en ligne.
    Pour le rapport Kaspersky il faut que tu choisisses "Afficher le rapport" puis que tu l'enregistres sur ton bureau sous forme de fichier texte (type de fichier "tous les fichiers").

    Tu ne m'as pas répondu : le PC est toujours aussi lent ? Même sur Internet ?

    A+ Cireluz

    ;)
    1. hello! ouais dur dur de se debarasser de moi mais je t aime bien lol ,le pc tourne beaucoup mieux et pour ton hostexpert c est pour xp moi j ai VISTA (desole lol) pour bitcomet je l ai retire et je fais quoi maintenant pour telecharger utorrent (je sais la charte aille aille lol)
    2. tu vas rire (pas moi) quand je clic sur restore ms host file j ai un message d erreur :cannot create file C:/windows/systeme32/drivers/etc/hosts
    3. Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 15:59:37, on 05/11/2008
      Platform: Windows Vista SP1 (WinNT 6.00.1905)
      MSIE: Internet Explorer v7.00 (7.00.6001.18000)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Windows\system32\taskeng.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Windows\RtHDVCpl.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
      C:\Windows\WindowsMobile\wmdc.exe
      C:\Windows\System32\drivers\Phibtn.exe
      C:\Windows\System32\drivers\Tray900.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Windows\ehome\ehtray.exe
      C:\Windows\System32\mobsync.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\Windows\ehome\ehmsas.exe
      C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
      C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Windows\system32\SearchFilterHost.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O1 - Hosts: ::1 localhost
      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
      O4 - HKLM\..\Run: [RtHDVCpl] "C:\Windows\RtHDVCpl.exe"
      O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
      O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
      O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\WordPerfect Office X3\Programs\QFSCHD130.EXE"
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
      O4 - HKLM\..\Run: [Windows Mobile Device Center] "C:\Windows\WindowsMobile\wmdc.exe"
      O4 - HKLM\..\Run: [SynTPStart] "C:\Program Files\Synaptics\SynTP\SynTPStart.exe"
      O4 - HKLM\..\Run: [PhiBtn] "C:\Windows\System32\Drivers\PhiBtn.exe"
      O4 - HKLM\..\Run: [TrayMin900] "C:\Windows\System32\Drivers\Tray900.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKCU\..\Run: [Sidebar] "C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
      O8 - Extra context menu item: Ouvrir dans WordPerfect - C:\Program Files\WordPerfect Office X3\Programs\WPLauncher.hta
      O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
      O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
      O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O13 - Gopher Prefix:
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper200711281.dll
      O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
      O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
      O23 - Service: O2Micro Flash Memory (O2Flash) - O2Micro International - C:\Windows\system32\o2flash.exe
      O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
      O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe
      O23 - Service: XAudioService - Unknown owner - C:\Windows\system32\DRIVERS\xaudio.exe (file missing)
  10. Salut vous deux,

    Cireluz ? On se connait non ? (lol)

    Bon,
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.atcomet.com/b/

    Et : http://www.siteadvisor.com/sitereport.html?url=atcomet.com

    Peux-tu faire ceci ?

    > Lance Hijackthis :
    - Puis sélectionne <Do a system scan only>
    - Coche les cases des lignes suivantes :

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.atcomet.com/b/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.medion.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)

    Ensuite,
    - Ferme toutes les autres fenêtres et applications (même internet)
    - Clic sur <Fixe checked>

    Puis,
    je te conseille de désinstaller Bitcomet qui est une grosse daube.

    Ensuite,
    > Télécharge Zeb-Restore : http://telechargement.zebulon.fr/telecharger-zeb-restore.html
    - Mets le dans un dossier, sur ton bureau par exemple.
    - Lance Zebrestore et coche la/les case(s) suivante(s) :

    Fichier Hosts

    - Ne coche que la/les case(s) indiquée(s).
    - Clique sur le bouton <Restaurer>.
    - Quitte le programme.

    Y a du changement ?
    Bonne journée.

    A+
    1. bonjour a toi grand ami belge et oui je suis revenu te hanter lol;bon jai fait ce que tu m as dit (obeissant non!)
      avc zebrestore j ai eu ce massage en cochant fichier host:run time error75 path/file access error mais j ai eu ses messages aussi:backup et dedans fichier host que doit je en faire ??????
    2. re et que mettre alors???????
      Puis,
      je te conseille de désinstaller Bitcomet qui est une grosse daube.
  11. Contributeur sécurité
    pour le parefeux effetivement celui de windows ne filtre que se qui rentre donc en mettre un autre est mieux: il faut parcontre désactiver celui de windows sinon tu auras un conflit entre les deux parefeux

    ____________

    pour windows defender pas grave si inactif car tu as mis le tea tiemr de spybot: si les deux sont actifs l'ordi va ramer!!!

    alors soit réactive windows defender et désactive le tea timer de spybot (lancer spybot puis allers dans MODE puis MODE AVANCE puis outils puis resident)

    soit laisse windows defender désactiver et laisse le tea timer de spybot (essaye de le désactiver pour voir si internet va plus vite)

    ensuite fais le message de DIID pour voir

    pour protéger gratos ton ordi
    http://www.commentcamarche.net/telecharger/logiciel 4 securite

    mettre un antivirus

    ANTIVIR
    https://www.malekal.com/avira-free-security-antivirus-gratuit/ (merci Malekal)
    -------------
    des anti-espions :
    MALWAREBYTE ANTIMALWARE + SPYBOT +/- windows defender si tea timer de spybot désactivé
    +
    SPYWAREBLASTER pour immuniser le système contre vundo notamment mais en anglais (mais facile d'utilisation : il suffit de faire "update" pour mettre à jour tous les mois et ensuite" enable all protection" pour immuniser)...

    --------
    un pare feu :
    (celui de Windows) ou mieux COMODO ou KERIO ou JETICO ou ZONE ALARM (mettre que le parefeu gratuit)

    http://www.clubic.com/telecharger-fiche11071-sunbelt-persona­l-firewall-e(...)
    https://manuelsdaide.com/contact/
    http://www.open-files.com/forum/index.php?showtopic=29277
    https://www.commentcamarche.net/telecharger/ 157 zonealarm

    -----------

    CCLEANER pour effacer les traces de surf
    1. Contributeur sécurité
      ok

      rien d'infectieux dans ton rapport ...

      si les soucis persistent et que malheureusement tu n'as pas de point de restauration il va falloir reparer:

      http://www.vista-xp.fr/forum/topic428.html
      1. bonjour, jlpjlp merci de ta reponse mn pc a l air de mieux tourner ; plusieurs defrrag ont ete necessaire et encore la connexion su firefox est lente !!! tu ne m as pas dit pour le parefeux(voir reponse 13a de anthonny5151) et windows defender (disabled)c est normal!!
    2. OK A DEMAIN je ferais tout cela tranquillement dit tous les messages se dedoubles sur le site c est bizarre non et des fois pas dans l ordre
      1. Contributeur sécurité
        cf message 10 :

        Télécharge ici :

        http://images.malwareremoval.com/random/RSIT.exe

        random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

        Double-clique sur RSIT.exe afin de lancer RSIT.

        Clique Continue à l'écran Disclaimer.

        Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

        Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

        Poste le contenu de log.txt (<<qui sera affiché)
        ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

        NB : Les rapports sont sauvegardés dans le dossier C:\rsit
        1. bonjour:jlpjlp enfin reveille a cette heure je t envoie les 2 rapports demandes ;en ce qu concerne la restauration plus de points de restauration sur mon systeme ! je l avais nettoye en gardant le plus recent mais apparemment il n y en a plus : sur mon post anthonny5151 avait dit de changer mon parefeux car selui de windows n est pas tres securise ??qu en pense tu!!!voir message n°13merci

          Logfile of random's system information tool 1.04 (written by random/random)
          Run by ERIC at 2008-11-04 15:27:22
          Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
          System drive C: has 111 GB (79%) free of 141 GB
          Total RAM: 2045 MB (63% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 15:27:45, on 04/11/2008
          Platform: Windows Vista SP1 (WinNT 6.00.1905)
          MSIE: Internet Explorer v7.00 (7.00.6001.18000)
          Boot mode: Normal

          Running processes:
          C:\Windows\system32\Dwm.exe
          C:\Windows\Explorer.EXE
          C:\Windows\system32\taskeng.exe
          C:\Program Files\Windows Defender\MSASCui.exe
          C:\Windows\RtHDVCpl.exe
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
          C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
          C:\Windows\WindowsMobile\wmdc.exe
          C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
          C:\Windows\System32\drivers\Phibtn.exe
          C:\Windows\System32\drivers\Tray900.exe
          C:\Program Files\Windows Sidebar\sidebar.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Windows\ehome\ehtray.exe
          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          C:\Windows\ehome\ehmsas.exe
          C:\Windows\System32\mobsync.exe
          C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
          C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\Windows\system32\conime.exe
          C:\Windows\system32\SearchFilterHost.exe
          C:\Users\ERIC\Desktop\RSIT.exe
          C:\Program Files\trend micro\ERIC.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.atcomet.com/b/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.medion.com/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O1 - Hosts: ::1 localhost
          O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
          O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
          O4 - HKLM\..\Run: [RtHDVCpl] "C:\Windows\RtHDVCpl.exe"
          O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
          O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
          O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\WordPerfect Office X3\Programs\QFSCHD130.EXE"
          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
          O4 - HKLM\..\Run: [Windows Mobile Device Center] "C:\Windows\WindowsMobile\wmdc.exe"
          O4 - HKLM\..\Run: [SynTPStart] "C:\Program Files\Synaptics\SynTP\SynTPStart.exe"
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
          O4 - HKLM\..\Run: [PhiBtn] "C:\Windows\System32\Drivers\PhiBtn.exe"
          O4 - HKLM\..\Run: [TrayMin900] "C:\Windows\System32\Drivers\Tray900.exe"
          O4 - HKCU\..\Run: [Sidebar] "C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
          O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
          O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
          O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
          O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
          O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
          O8 - Extra context menu item: Ouvrir dans WordPerfect - C:\Program Files\WordPerfect Office X3\Programs\WPLauncher.hta
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
          O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
          O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
          O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
          O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O13 - Gopher Prefix:
          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper200711281.dll
          O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
          O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
          O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
          O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
          O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
          O23 - Service: O2Micro Flash Memory (O2Flash) - O2Micro International - C:\Windows\system32\o2flash.exe
          O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
          O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe
          O23 - Service: XAudioService - Unknown owner - C:\Windows\system32\DRIVERS\xaudio.exe (file missing)
      2. Contributeur sécurité
        ok esaye de restaurer sinon passe a ceci

        colle un rapport RSIT pour verifier les infections quand même

        puis

        sinon
        en général disque dur ou memoire vive je pense mais je ne suis pas le gros specialiste, il faudrait que tu te mette dans la partie matereil/hardaware du site.

        pour vérifier la mémoire vive: si tu en as deux vire une des deux pour voir si l'ordi marche correctement ou alors utilise memtest:

        http://www.world-informatique.com/pasapas/faq/voir.html?qid=­48

        si ton disque dur fais du bruit cela dois provenir de lui

        mais cela peut venir d'autre chose au niveau materiel....
        1. ok j essaierai chez moi et ce que disait anthony5151 il faut le faire egalement car j ai un parefeux d origine et il n est pas bon d apres lui ainssi que quelque mise a jour
          1. non aucun nouveau materiel n a ete installe ho plutot si dernierement j ai installe le cd d instal pour une imprimante hp que j ai desinstalle par la suite il y aurait peut etre cause a effet?????
            1. Contributeur sécurité
              tu dois donc avoir un souci matériel :
              si tu as mis un nouveau materiel ou logiciel vire le pour voir

              sinon
              en général disque dur ou memoire vive je pense mais je ne suis pas le gros specialiste, il faudrait que tu te mette dans la partie matereil/hardaware du site.

              pour vérifier la mémoire vive: si tu en as deux vire une des deux pour voir si l'ordi marche correctement ou alors utilise memtest:

              http://www.world-informatique.com/pasapas/faq/voir.html?qid=48

              si ton disque dur fais du bruit cela dois provenir de lui

              mais cela peut venir d'autre chose au niveau materiel....
              • 1
              • 2