Problème avec un certain win32

Résolu
Bonjour,

Voila j'ai un gros problème avec le "win32" depuis a peu près deux semaine je l'ai et je n'ai rien fait je sens que comment pc n'est plus performent comme avant je n'ai plus d'antivirus a cause de ce win32.

J'avais avast il allé très bien et beau matin je le lance et je recoit un message d'erreur comme quoi win32 n'est pas valide.

En plus c'est mon ordinateur, je n'est que 15 ans donc je suis pas très doué dans ce qui est virus et tout et j'espere que ce n'est pas un virus.

J'en ai parlé a mon père il ne sait rien du tout ^^ il m'a proposer d'aller le formater et franchement j'en ai pas trop envie !

J'espere que vous allé m'aider merci.
Configuration: Windows XP
Internet Explorer 7.0

36 réponses

Résumé de la discussion

Win32 est signalé sur un PC Windows XP, provoquant des lenteurs et l’absence d’antivirus après un message d’erreur indiquant que Win32 n’est pas valide, et inquiète quant à une infection. Plusieurs réponses proposent des outils et méthodes de détection et de suppression, notamment FindyKill pour scanner et nettoyer, des procédures avec CCleaner et des modifications manuelles du registre via un fichier .reg. D'autres interventions évoquent des scans avec Malwarebytes et signalent des rapports sans éléments infectés, tout en mentionnant des conseils discutables autour de cracks logiciels et d’options de nettoyage contestables. En cas d’écran bleu ou de persistance des ralentissements, il est conseillé de vérifier les pilotes, de sauvegarder les données et d’envisager une réinstallation propre ou une restauration préalable.

Bobot (l’IA à votre service)
  1. non tu aurais eu un ecran bleu etc

    c ok ??
    0
    1. oui c'est ok c'est sur le virus n'est pas venu si je'ai de nouveau des problème je reviendrais poster je close la discussion
      0
  2. ???

    tu peux réessayer en le telechargeant ici :

    https://www.skype.com/fr/
    0
    1. ok le vius n'est pas revenu j'espere
      0
  3. c'est urgent il y a un problème j'ai voulu installer msn messenger et il me dit encore win 32 n'est pas valide cété le msn 9.0 béta
    0
    1. Une clé de registre mais rassure toi rien de nefaste
      0
      1. ok

        il te reste une clé mais t inkiete c est pas un soucis

        bonne soirée
        0
        1. c'est quoi une clé ? et après promis je te laisse lol et merci beaucoup
          0
      2. et je peux mettre avast a la place avira ou tu me le déconseille
        0
        1. je te le deconseil

          mais si tu te sent plus a l aise avec avast alors ...
          0
      3. tu peux virer : Antipub

        pour l ecran bleu surement un soucis de compatibilité materiel donc je ne peux rien faire
        0
        1. je ne l'ai plus antipub et ok je marche résoulu après ta réponse
          0
      4. * pour supprimer les outils/fix utilisés :

        Télécharge ToolsCleaner sur ton bureau.
        -->
        http://pc-system.fr/
        http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner

        # Clique sur Recherche et laisse le scan agir ...
        # Clique sur Suppression pour finaliser.
        # Tu peux, si tu le souhaites, te servir des Options facultatives.
        # Clique sur Quitter pour obtenir le rapport.
        # Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

        0
        1. [ Rapport ToolsCleaner version 2.2.6 (par A.Rothstein & dj QUIOU) ]

          -->- Recherche:

          C:\FindyKill.txt: trouvé !
          C:\_OtMoveIt: trouvé !
          C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
          C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
          C:\Documents and Settings\Eric\Bureau\HijackThis.lnk: trouvé !
          C:\Documents and Settings\Eric\Bureau\HJTInstall.exe: trouvé !
          C:\Documents and Settings\Eric\Menu Démarrer\Programmes\FindyKill: trouvé !
          C:\Program Files\FindyKill: trouvé !
          C:\Program Files\Trend Micro\HijackThis: trouvé !
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
          C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !

          ---------------------------------
          -->- Suppression:

          C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
          C:\Documents and Settings\Eric\Bureau\HijackThis.lnk: supprimé !
          C:\Documents and Settings\Eric\Bureau\HJTInstall.exe: supprimé !
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
          C:\FindyKill.txt: supprimé !
          C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
          C:\_OtMoveIt: supprimé !
          C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
          C:\Documents and Settings\Eric\Menu Démarrer\Programmes\FindyKill: supprimé !
          C:\Program Files\FindyKill: ERREUR DE SUPPRESSION !!
          C:\Program Files\Trend Micro\HijackThis: supprimé !
          0
      5. Oui c est cela

        refais un scan hijackthis et post le rapport stp et dis moi si t as encore des soucis
        0
        1. Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 19:05:23, on 24/11/2008
          Platform: Windows XP SP3 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16735)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\system32\cisvc.exe
          C:\WINDOWS\system32\inetsrv\inetinfo.exe
          C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
          C:\WINDOWS\system32\nvsvc32.exe
          C:\WINDOWS\system32\HPZipm12.exe
          C:\WINDOWS\System32\tcpsvcs.exe
          C:\WINDOWS\System32\snmp.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\mqsvc.exe
          C:\WINDOWS\system32\mqtgsvc.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\explorer.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\WINDOWS\system32\cidaemon.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
          C:\WINDOWS\system32\cidaemon.exe
          C:\WINDOWS\system32\msiexec.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://portail.free.fr/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          F2 - REG:system.ini: UserInit=userinit.exe
          O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IEPro\iepro.dll
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
          O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
          O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
          O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
          O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
          O4 - HKLM\..\Run: [Windl] C:\WINDOWS\Windl\mirc.exe
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
          O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
          O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe"
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [DriverUpdaterPro] C:\Program Files\XPC Tools\Driver Updater Pro\DriverUpdaterPro.exe -t
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
          O4 - S-1-5-18 Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe (User 'SYSTEM')
          O4 - S-1-5-18 Startup: Anti-Pub.lnk = C:\Program Files\Antipub\antipub.exe (User 'SYSTEM')
          O4 - .DEFAULT Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe (User 'Default user')
          O4 - .DEFAULT Startup: Anti-Pub.lnk = C:\Program Files\Antipub\antipub.exe (User 'Default user')
          O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
          O4 - Startup: Anti-Pub.lnk = C:\Program Files\Antipub\antipub.exe
          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
          O9 - Extra button: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll
          O9 - Extra 'Tools' menuitem: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll
          O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
          O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
          O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
          O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - https://www.touslesdrivers.com/index.php?v_page=29
          O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
          O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
          O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
          O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
          0
      6. c est quasi finit

        désinstal liveupdate de symantec

        Télécharge OTMoveIt3 de OldTimer sur ton Bureau en cliquant sur ce lien :

        http://oldtimer.geekstogo.com/OTMoveIt3.exe

        Double-clique sur OTMoveIt3.exe pour le lancer.

        Vérifie que la case devant "Unregister Dll's and Ocx's est bien cochée.

        Copie la liste qui se trouve en gras ci-dessous,

        et colle-la dans le cadre de gauche de OTMoveIt : "Paste instructions for item to be moved".

        :files
        C:\Documents and Settings\Eric\Local Settings\Temporary Internet Files\Content.IE5\I8SEJI0X\norton-antivirus_norton_antivirus_2009_anglais_10082[2].exe

        :reg
        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
        "NAV"=-


        Clique sur "MoveIt!" pour lancer la suppression.

        Le résultat apparaitra dans le cadre "Results".

        Clique sur "Exit" pour fermer.

        Poste le rapport situé dans C:\_OTMoveIt\MovedFiles sous le nom xxxxxx_xxxxxxxxxx.log
        0
        1. c'est bien ca ?

          ========== FILES ==========
          File/Folder C:\Documents and Settings\Eric\Local Settings\Temporary Internet Files\Content.IE5\I8SEJI0X\norton-antivirus_norton_antivirus_2009_anglais_10082[2].exe not found.
          ========== REGISTRY ==========
          Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\NAV deleted successfully.

          OTMoveIt3 by OldTimer - Version 1.0.7.1 log created on 11242008_190055
          0
        2. @arckaeusa la fin tu pourra me dire ce qu'il faut désinstaller pour que mon pc ne ram pas et va bien car avant je recever un ecran bleu et il seré possible que je le recoivent encore !! mais d'abord finissons notre travail lol
          0
      7. Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 18:52:19, on 24/11/2008
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16735)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\system32\cisvc.exe
        C:\WINDOWS\system32\inetsrv\inetinfo.exe
        C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\WINDOWS\system32\HPZipm12.exe
        C:\WINDOWS\System32\tcpsvcs.exe
        C:\WINDOWS\System32\snmp.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\mqsvc.exe
        C:\WINDOWS\system32\mqtgsvc.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\explorer.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\WINDOWS\system32\cidaemon.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
        C:\WINDOWS\system32\cidaemon.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://portail.free.fr/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        F2 - REG:system.ini: UserInit=userinit.exe
        O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IEPro\iepro.dll
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
        O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
        O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
        O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
        O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
        O4 - HKLM\..\Run: [Windl] C:\WINDOWS\Windl\mirc.exe
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [NAV] "C:\Documents and Settings\Eric\Local Settings\Temporary Internet Files\Content.IE5\I8SEJI0X\norton-antivirus_norton_antivirus_2009_anglais_10082[2].exe" /RELAUNCH /RUNONCE /NOPROMPT
        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
        O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
        O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe"
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [DriverUpdaterPro] C:\Program Files\XPC Tools\Driver Updater Pro\DriverUpdaterPro.exe -t
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
        O4 - S-1-5-18 Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe (User 'SYSTEM')
        O4 - S-1-5-18 Startup: Anti-Pub.lnk = C:\Program Files\Antipub\antipub.exe (User 'SYSTEM')
        O4 - .DEFAULT Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe (User 'Default user')
        O4 - .DEFAULT Startup: Anti-Pub.lnk = C:\Program Files\Antipub\antipub.exe (User 'Default user')
        O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
        O4 - Startup: Anti-Pub.lnk = C:\Program Files\Antipub\antipub.exe
        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
        O9 - Extra button: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll
        O9 - Extra 'Tools' menuitem: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll
        O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
        O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
        O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
        O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - https://www.touslesdrivers.com/index.php?v_page=29
        O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
        O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
        O23 - Service: Planificateur LiveUpdate automatique (Automatic LiveUpdate Scheduler) - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
        O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
        O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
        0
        1. ok

          fais ccleaner nettoyage plus registre

          ensuite refais un scan hijackthis et post le rapport stp
          0
          1. ok ca ne va rien changer si je ne fait pas fix reg

            et je le sens qu'il va plus vite pourtant ce pas fini ou biento ptete
            0
        2. -> Télécharge Ccleaner (n'installe pas la barre d'outil Yahoo):

          http://download.piriform.com/ccsetup210.exe

          https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html

          -> Tuto : https://www.malekal.com/tutoriel-ccleaner/

          ensuite :

          Fix.reg

          Ouvre le bloc-notes (click droit sur le bureau > dans l´arborescence choisie nouveau et nouveau fichier texte) et fais un copier coller de ce qui est en citation ci-dessous (copie tout d'un trait-sans les barres(x)) :

          XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
          Windows Registry Editor Version 5.00

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
          "NAV"=-

          XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
          Note : Windows Registry Editor Version 5.00 est sur la premiere ligne dans le bloc note et il y a une ligne blanche a la fin.
          Puis click sur "fichier"/"enregistrer sous" :
          dans : sur le bureau
          Nom du fichier : fix.reg
          Type de fichier : "tous les fichiers"
          clique sur "enregistrer"

          ca doit ressembler a ca une fois enrregistré :

          http://img520.imageshack.us/img520/4251/screenshot005ps2.png

          double clique sur fix.reg => tu dois obligatoirement avoir un message "voulez-vous vraiment ajouter les informations contenues dans ce fichier .reg au registre ?"
          Si c'est bien le cas, clique sur "oui"

          et dis moi comment va le pc ensuite
          0
          1. Désactive et réactive ta restauration system :

            (1) Désactiver la Restauration du système

            cliques sur Démarrer
            Cliques droit sur Poste de travail
            cliques sur Propriétés
            Cliques sur l'onglet Restauration du système
            Coches Désactiver la Restauration du système sur tous les lecteurs
            Cliques sur Appliquer, Lorsque le message de confirmation apparaît,
            cliques sur Oui.
            Cliques sur OK.

            (2) Activer la Restauration du système

            cliques sur Démarrer
            Cliques droit sur Poste de travail
            cliques sur Propriétés
            Cliques sur l'onglet Restauration du système
            Décoches Désactiver la Restauration du système sur tous les lecteurs
            Cliques sur Appliquer, Lorsque le message de confirmation apparaît,
            cliques sur Oui.
            Cliques sur OK.

            Tuto xp : http://service1.symantec.com/support/inter/tsgeninfointl.Nsf/fr_docid/20020830101856924

            refais un scan hijackthis et post le rapport stp
            0
            1. Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 18:10:05, on 24/11/2008
              Platform: Windows XP SP3 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16735)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\WINDOWS\system32\cisvc.exe
              C:\WINDOWS\system32\inetsrv\inetinfo.exe
              C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
              C:\WINDOWS\system32\nvsvc32.exe
              C:\WINDOWS\system32\HPZipm12.exe
              C:\WINDOWS\System32\tcpsvcs.exe
              C:\WINDOWS\System32\snmp.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\mqsvc.exe
              C:\WINDOWS\system32\mqtgsvc.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\explorer.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              C:\WINDOWS\system32\cidaemon.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
              C:\WINDOWS\system32\cidaemon.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://portail.free.fr/
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              F2 - REG:system.ini: UserInit=userinit.exe
              O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IEPro\iepro.dll
              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
              O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
              O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
              O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
              O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
              O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
              O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
              O4 - HKLM\..\Run: [Windl] C:\WINDOWS\Windl\mirc.exe
              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
              O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
              O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
              O4 - HKLM\..\Run: [NAV] "C:\Documents and Settings\Eric\Local Settings\Temporary Internet Files\Content.IE5\I8SEJI0X\norton-antivirus_norton_antivirus_2009_anglais_10082[2].exe" /RELAUNCH /RUNONCE /NOPROMPT
              O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
              O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
              O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe"
              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              O4 - HKCU\..\Run: [DriverUpdaterPro] C:\Program Files\XPC Tools\Driver Updater Pro\DriverUpdaterPro.exe -t
              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
              O4 - S-1-5-18 Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe (User 'SYSTEM')
              O4 - S-1-5-18 Startup: Anti-Pub.lnk = C:\Program Files\Antipub\antipub.exe (User 'SYSTEM')
              O4 - .DEFAULT Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe (User 'Default user')
              O4 - .DEFAULT Startup: Anti-Pub.lnk = C:\Program Files\Antipub\antipub.exe (User 'Default user')
              O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
              O4 - Startup: Anti-Pub.lnk = C:\Program Files\Antipub\antipub.exe
              O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
              O9 - Extra button: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll
              O9 - Extra 'Tools' menuitem: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll
              O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
              O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
              O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
              O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - https://www.touslesdrivers.com/index.php?v_page=29
              O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
              O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
              O23 - Service: Planificateur LiveUpdate automatique (Automatic LiveUpdate Scheduler) - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
              O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
              O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
              O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
              0
          2. ok

            @++
            0
            1. Avira AntiVir Personal
              Report file date: lundi 24 novembre 2008 12:39

              Scanning for 1047788 virus strains and unwanted programs.

              Licensed to: Avira AntiVir PersonalEdition Classic
              Serial number: 0000149996-ADJIE-0001
              Platform: Windows XP
              Windows version: (Service Pack 3) [5.1.2600]
              Boot mode: Normally booted
              Username: Eric
              Computer name: SYNDICUS-6K2NAE

              Version information:
              BUILD.DAT : 8.2.0.336 16933 Bytes 30/10/2008 11:40:00
              AVSCAN.EXE : 8.1.4.7 315649 Bytes 26/06/2008 09:57:53
              AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 08:56:40
              LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 13:44:19
              LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 08:58:52
              ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 10:33:28
              ANTIVIR1.VDF : 7.1.0.56 411136 Bytes 09/11/2008 10:33:29
              ANTIVIR2.VDF : 7.1.0.124 376832 Bytes 23/11/2008 10:33:30
              ANTIVIR3.VDF : 7.1.0.127 28672 Bytes 24/11/2008 11:07:21
              Engineversion : 8.2.0.35
              AEVDF.DLL : 8.1.0.6 102772 Bytes 14/10/2008 11:05:56
              AESCRIPT.DLL : 8.1.1.15 332156 Bytes 24/11/2008 10:33:37
              AESCN.DLL : 8.1.1.5 123251 Bytes 24/11/2008 10:33:36
              AERDL.DLL : 8.1.1.3 438645 Bytes 24/11/2008 10:33:35
              AEPACK.DLL : 8.1.3.4 393591 Bytes 24/11/2008 10:33:35
              AEOFFICE.DLL : 8.1.0.30 196986 Bytes 24/11/2008 10:33:34
              AEHEUR.DLL : 8.1.0.71 1487222 Bytes 24/11/2008 10:33:34
              AEHELP.DLL : 8.1.2.0 119159 Bytes 24/11/2008 10:33:33
              AEGEN.DLL : 8.1.1.5 323956 Bytes 24/11/2008 10:33:32
              AEEMU.DLL : 8.1.0.9 393588 Bytes 14/10/2008 11:05:56
              AECORE.DLL : 8.1.5.1 172406 Bytes 24/11/2008 10:33:32
              AEBB.DLL : 8.1.0.3 53618 Bytes 14/10/2008 11:05:56
              AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 09:40:05
              AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 10:28:01
              AVREP.DLL : 8.0.0.2 98344 Bytes 24/11/2008 10:33:31
              AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 12:26:40
              AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 09:29:23
              AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 13:27:49
              SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 18:28:02
              SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 13:49:40
              NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 13:05:10
              RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 14:48:07
              RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 14:34:37

              Configuration settings for the scan:
              Jobname..........................: Local Drives
              Configuration file...............: c:\program files\avira\antivir personaledition classic\alldrives.avp
              Logging..........................: low
              Primary action...................: interactive
              Secondary action.................: ignore
              Scan master boot sector..........: on
              Scan boot sector.................: on
              Boot sectors.....................: C:, D:, E:, F:, G:, I:,
              Process scan.....................: on
              Scan registry....................: on
              Search for rootkits..............: off
              Scan all files...................: Intelligent file selection
              Scan archives....................: on
              Recursion depth..................: 20
              Smart extensions.................: on
              Macro heuristic..................: on
              File heuristic...................: medium

              Start of the scan: lundi 24 novembre 2008 12:39

              The scan of running processes will be started
              Scan process 'avscan.exe' - '1' Module(s) have been scanned
              Scan process 'avcenter.exe' - '1' Module(s) have been scanned
              Scan process 'avgnt.exe' - '1' Module(s) have been scanned
              Scan process 'avguard.exe' - '1' Module(s) have been scanned
              Scan process 'sched.exe' - '1' Module(s) have been scanned
              Scan process 'cidaemon.exe' - '1' Module(s) have been scanned
              Scan process 'cidaemon.exe' - '1' Module(s) have been scanned
              Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned
              Scan process 'WLLoginProxy.exe' - '1' Module(s) have been scanned
              Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
              Scan process 'iexplore.exe' - '1' Module(s) have been scanned
              Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
              Scan process 'svchost.exe' - '1' Module(s) have been scanned
              Scan process 'explorer.exe' - '1' Module(s) have been scanned
              Scan process 'svchost.exe' - '1' Module(s) have been scanned
              Scan process 'alg.exe' - '1' Module(s) have been scanned
              Scan process 'mqtgsvc.exe' - '1' Module(s) have been scanned
              Scan process 'mqsvc.exe' - '1' Module(s) have been scanned
              Scan process 'wdfmgr.exe' - '1' Module(s) have been scanned
              Scan process 'svchost.exe' - '1' Module(s) have been scanned
              Scan process 'snmp.exe' - '1' Module(s) have been scanned
              Scan process 'tcpsvcs.exe' - '1' Module(s) have been scanned
              Scan process 'HPZipm12.exe' - '1' Module(s) have been scanned
              Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
              Scan process 'NBService.exe' - '1' Module(s) have been scanned
              Scan process 'msdtc.exe' - '1' Module(s) have been scanned
              Scan process 'inetinfo.exe' - '1' Module(s) have been scanned
              Scan process 'cisvc.exe' - '1' Module(s) have been scanned
              Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
              Scan process 'svchost.exe' - '1' Module(s) have been scanned
              Scan process 'svchost.exe' - '1' Module(s) have been scanned
              Scan process 'svchost.exe' - '1' Module(s) have been scanned
              Scan process 'svchost.exe' - '1' Module(s) have been scanned
              Scan process 'svchost.exe' - '1' Module(s) have been scanned
              Scan process 'lsass.exe' - '1' Module(s) have been scanned
              Scan process 'services.exe' - '1' Module(s) have been scanned
              Scan process 'winlogon.exe' - '1' Module(s) have been scanned
              Scan process 'csrss.exe' - '1' Module(s) have been scanned
              Scan process 'smss.exe' - '1' Module(s) have been scanned
              39 processes with 39 modules were scanned

              Starting master boot sector scan:
              Master boot sector HD0
              [INFO] No virus was found!
              Master boot sector HD1
              [INFO] No virus was found!
              [WARNING] System error [21]: Le périphérique n'est pas prêt.
              Master boot sector HD2
              [INFO] No virus was found!
              [WARNING] System error [21]: Le périphérique n'est pas prêt.
              Master boot sector HD3
              [INFO] No virus was found!
              [WARNING] System error [21]: Le périphérique n'est pas prêt.
              Master boot sector HD4
              [INFO] No virus was found!
              [WARNING] System error [21]: Le périphérique n'est pas prêt.

              Start scanning boot sectors:
              Boot sector 'C:\'
              [INFO] No virus was found!
              Boot sector 'D:\'
              [INFO] In the drive 'D:\' no data medium is inserted!
              Boot sector 'E:\'
              [INFO] In the drive 'E:\' no data medium is inserted!
              Boot sector 'F:\'
              [INFO] In the drive 'F:\' no data medium is inserted!
              Boot sector 'G:\'
              [INFO] In the drive 'G:\' no data medium is inserted!

              Starting to scan the registry.
              The registry was scanned ( '69' files ).

              Starting the file scan:

              Begin scan in 'C:\'
              C:\pagefile.sys
              [WARNING] The file could not be opened!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP10\A0002602.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '495a97f2.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP10\A0002603.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '495a97f4.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP10\A0002605.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '495a97f6.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP10\A0002607.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '495a97fb.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP10\A0002610.exe
              [DETECTION] Contains recognition pattern of the WORM/Bagle.Gen worm
              [NOTE] The file was moved to '495a9802.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP10\A0002612.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '495a9809.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP10\A0002614.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '495a980a.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP10\A0002615.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '48db6073.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP10\A0002616.exe
              [DETECTION] Contains recognition pattern of the WORM/Bagle.Gen worm
              [NOTE] The file was moved to '495a980b.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP10\A0002617.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '48db6074.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP10\A0002618.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '495a980d.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP2\A0000089.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '495a9811.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP2\A0000090.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '48db606a.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP2\A0000091.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '495a9812.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP2\A0000277.sys
              [DETECTION] Is the TR/Rootkit.Gen Trojan
              [NOTE] The file was moved to '495a9817.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP2\A0000278.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '48db6060.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP2\A0000279.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '495a9818.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP2\A0000329.sys
              [DETECTION] Is the TR/Rootkit.Gen Trojan
              [NOTE] The file was moved to '495a9819.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP2\A0000330.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '48db6062.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP2\A0000331.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '495a981b.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP3\A0000389.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '495a981c.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP3\A0000390.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '48db6065.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP3\A0000391.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '495a981d.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP3\A0000493.sys
              [DETECTION] Is the TR/Rootkit.Gen Trojan
              [NOTE] The file was moved to '495a9820.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP3\A0000494.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '495a9821.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP3\A0000495.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '48db605a.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP3\A0000498.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '495a9822.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP3\A0000510.sys
              [DETECTION] Is the TR/Rootkit.Gen Trojan
              [NOTE] The file was moved to '48db605b.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP3\A0000511.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '495a9823.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP6\A0000522.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '495a9829.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP6\A0000523.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '48db6052.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP6\A0000524.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '495a982a.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP7\A0000644.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '495a982f.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP7\A0000645.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '495a9830.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP7\A0000646.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '48db6049.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP7\A0000784.sys
              [DETECTION] Is the TR/Rootkit.Gen Trojan
              [NOTE] The file was moved to '495a9834.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP7\A0000785.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '48db604d.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP7\A0000786.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '495a9836.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP7\A0000787.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '495a9835.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP7\A0000812.sys
              [DETECTION] Is the TR/Rootkit.Gen Trojan
              [NOTE] The file was moved to '48db604f.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP7\A0000813.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '495a9828.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP7\A0000814.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '495a9837.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP7\A0000815.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '48db6040.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP8\A0000858.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '495a983a.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP8\A0000859.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '495a983b.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP8\A0000860.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '48db6044.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP9\A0000925.sys
              [DETECTION] Is the TR/Rootkit.Gen Trojan
              [NOTE] The file was moved to '495a983e.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP9\A0000926.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '495a983f.qua'!
              C:\System Volume Information\_restore{6267604A-6D3F-4734-8646-C0CA62C20F64}\RP9\A0000927.exe
              [DETECTION] Is the TR/Bagle.Gen.B Trojan
              [NOTE] The file was moved to '48db6038.qua'!
              C:\WINDOWS\system32\drivers\sptd.sys
              [WARNING] The file could not be opened!
              C:\WINDOWS\Windl\download.dll
              [DETECTION] Contains recognition pattern of the IRC/Flood.D IRC virus
              [NOTE] The file was moved to '49a19bab.qua'!
              Begin scan in 'D:\'
              Search path D:\ could not be opened!
              System error [21]: Le périphérique n'est pas prêt.
              Begin scan in 'E:\'
              Search path E:\ could not be opened!
              System error [21]: Le périphérique n'est pas prêt.
              Begin scan in 'F:\'
              Search path F:\ could not be opened!
              System error [21]: Le périphérique n'est pas prêt.
              Begin scan in 'G:\'
              Search path G:\ could not be opened!
              System error [21]: Le périphérique n'est pas prêt.
              Begin scan in 'I:\'
              Search path I:\ could not be opened!
              System error [21]: Le périphérique n'est pas prêt.

              End of the scan: lundi 24 novembre 2008 13:17
              Used time: 37:46 Minute(s)

              The scan has been done completely.

              3714 Scanning directories
              249016 Files were scanned
              50 viruses and/or unwanted programs were found
              0 Files were classified as suspicious:
              0 files were deleted
              0 files were repaired
              50 files were moved to quarantine
              0 files were renamed
              2 Files cannot be scanned
              248964 Files not concerned
              3928 Archives were scanned
              6 Warnings
              50 Notes
              0
          3. je vais a l'école je revien vers 17h
            0
            • 1
            • 2