HELP ^^Marie^^

Résolu
Bonjour,^^Marie^^
depuis qu'on a enlever le virus d'msn mon ordi rame enormement! j'ai relancé avast il m'a trouvé un virus sur je c pas quoi... volume information que j'ai mis en quarantaine! depuis l'ordi rame toujours et il s'eteint tout seul et redemarre chaque fois que je lance avast et qu'il scan!
il scan un moment et apres il redemarre tout seul, du coup je n'arrive plus a arriver jusqu'au bout

peut tu m'aider?? merci d'avance
Configuration: Windows XP
Internet Explorer 7.0

240 réponses

Résumé de la discussion

Le problème principal est un PC sous Windows XP qui devient très lent et s’éteint puis redémarre lors du scan Avast après la suppression supposée d’un virus lié à MSN, malgré la quarantaine. Plusieurs réponses recommandent des nettoyages plus profonds et des mises à jour, notamment l’application de correctifs Windows et l’utilisation d’outils comme ComboFix, Antivir et DiagHelp pour identifier et neutraliser des composants malveillants persistants. Des avertissements portent sur des infections anciennes et des failles de sécurité non corrigées (MSN6, logiciels obsolètes) et proposent, en alternative à Avast, des solutions comme Kerio et Antivir, avec installation hors ligne et redémarrage en mode sans échec. Des rapports et journaux d’outils (par exemple ComboFix, DiagHelp) apparaissent comme éléments de diagnostic, indiquant des traces de fichiers système modifiés et de programmes potentiellement malveillants.

Bobot (l’IA à votre service)
  1. Re

    Fais moi un log hijackthis

    Faut que je relise tout avant

    A demain
    Ce soir je sature

    0
    1. Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 21:28, on 2008-02-01
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16574)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\windows\system\hpsysdrv.exe
      C:\HP\KBD\KBD.EXE
      C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
      C:\WINDOWS\System32\hphmon05.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\WINDOWS\System32\nvsvc32.exe
      C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\System32\HPZipm12.exe
      C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
      C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
      C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe
      C:\Program Files\Softwin\BitDefender10\bdagent.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
      C:\Program Files\Softwin\BitDefender10\vsserv.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
      O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
      O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
      O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
      O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
      O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\hphupd05.exe
      O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
      O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
      O4 - HKLM\..\Run: [LaunchList] C:\Program Files\Pinnacle\Studio 9\LaunchList.exe
      O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
      O4 - HKLM\..\Run: [Sysmem32] C:\WINDOWS\system32\drivers\alg.exe
      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg
      O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
      O4 - .DEFAULT User Startup: ddrive.js (User 'Default user')
      O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
      O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
      O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe
      O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
      O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
      O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe
      O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
      0
      1. Tu dois avoir un soucis dans la rest-système je pense

        E - Scan online avec BitDefender

        Fais ce scan anti-virus en ligne avec Internet Explorer, accepte l'active X; la barre anti-popup du SP2 (en haut) va se mettre à clignoter, clic dessus et choisis "accepter l'active X" pour faire fonctionner le scan anti-virus.
        Une fois qu'il a terminé colle le rapport ici stp
        https://www.bitdefender.com/toolbox/
        Copie/Colle le rapport
        http://www.malekal.com/tutorial_BitDefender_AntiSpyware.php
        https://kerio.probb.fr/t673-bitdefender-antivirus-en-ligne?highlight=tutorial+bitdefender
        http://pageperso.aol.fr/rginformatique/mapage/defender.htm

        A demain

        Je tombe un peu

        A++

        0
        1. ca fait deux jours que j'essaie de le faire il se lance pas!!
          je c pas si c parce que l'ordi rame mais ya pas moyen
          bon je reeesaie ce soir je te tiens au courant demain
          by by et merci
          0
          1. Bonsoir choupie13 , bonsoir ^^marie^^ .
            choupie13 c'est normal que ton pc rame et plante tu as deux antivirus ca peu etre ca qui fait planter ton pc donc fait ceci :

            desinstal bitdefender a l'aide de l'utilitaire de desinstalation que tu trouveras sur cette page : http://www.bitdefender.fr/KB333-fr--Desinstaller-BitDefender.html

            télécharges et installes :
            KillBox de Option^Explicit:http://www.killbox.net/downloads/KillBox.exe
            Aide Killbox:https://jesses.pagesperso-orange.fr/Docs/Logiciels/KillBox.htm

            sélectionne entièrement la liste ci-dessous :

            C:\WINDOWS\system32\drivers\alg.exe


            ---> et tu fais clic droit / copier

            Ouvres killbox
            - Sélectionne "delete on reboot"
            - Clique sur le menu "File" -> "Past from clip board"
            - Clique sur All Files
            - Clique sur la croix rouge et et blanche
            - Répond yes et laisse redémarrer ton pc.
            N'hésite pas à consulter l'Aide killbox

            NOTE: Si tu reçois le message "PendingFileRenameOperations Registry Data has been removed by external process!" et que l'ordinateur ne redémarre pas, redémarre le manuellement ---> Menu Démarrer / arreter / redémarrer l'ordinateur

            Après redémarrage, relance Killbox puis clic sur le menu fichier -> Log -> Actions History Log
            Poste le rapport ici

            0
            1. Pocket Killbox version 2.0.0.881
              Running on Windows XP as Propriétaire(Administrator)
              was started @ vendredi, février 01, 2008, 10:48 PM

              # 1 [Delete on Reboot]
              Path = C:\WINDOWS\system32\drivers\alg.exe

              # 2 [Delete on Reboot]
              Path = C:\WINDOWS\system32\drivers\alg.exe

              PendingFileRenameOperations Registry Data has been Removed by External Process! @ 10:55:53 PM
              Killbox Closed(Exit) @ 10:56:06 PM
              __________________________________________________

              Pocket Killbox version 2.0.0.881
              Running on Windows XP as Propriétaire(Administrator)
              was started @ vendredi, février 01, 2008, 11:00 PM

              Killbox Closed(Exit) @ 11:01:03 PM
              __________________________________________________

              Pocket Killbox version 2.0.0.881
              Running on Windows XP as Propriétaire(Administrator)
              was started @ vendredi, février 01, 2008, 11:02 PM

              voila M.L King merci de ton aide
              0
              1. l'ordi rame tjrs autant c l'enfer!!!
                0
                1. poste un nouveau rapport hijackthis stp
                  0
                  1. Il serait temps de changer d'anti-virus aussi !!!
                    Si tout le monde préconisaient antivir au lien d'avast les désinfec serait plus simple...
                    0
                    1. bonsoir espion3004 j'allai y venir merci de ton appuie . lol

                      avast est bien depasse il serais mieu pour toi que tu installe antivir il est plus performant et moin lourd que avast !

                      utilitaire de desisntalation de avast :https://www.commentcamarche.net/telecharger/ 34055246 utilitaire de desinstallation de avast

                      telecharge antivir : https://www.commentcamarche.net/telecharger/ 55 antivir
                      aide pour configurer antivir :https://www.malekal.com/avira-free-security-antivirus-gratuit/

                      Nous serons capable de tailler la montagne du desepoir . En diamant de l'espoir . Fort de cette fois, nous serons capable de changer dans notre nation le son de la discorde en une merveilleuse symphonie de fraternite , ....!!
                      0
                      1. piouff, ok, salut Martin Luther King, je te rejoins sur ce faite !..
                        0
                        1. bon j'ai changé d'antivurus j'ai mis antivir
                          il a détécté c:/upaq.exe bos/medbot.gen

                          voila je lé misen quarantaine mais tjrs pareil en ce ki concerne les symptome de mon ordi!
                          et l'ordi c'est éteint et a redémaré avant a fin du scan
                          0
                          1. bonjour tout le monde

                            choupie,choupie

                            déjà de retour, ont te manquaient lol

                            tu as des trace de bitdefender tu ne l'aurais pas installer ???

                            utilise : ca

                            0
                            1. et poste un nouveau raport hijack, comme demander par : M.L king

                              0
                            2. @curagiooups

                              desoler, M.L king

                              j'ai pas bien relus ce topic

                              choupie ne fait pas se que je t'ai dit ne poste au poste 13 ne fais qu'un new hijackthis

                              toute mes excuse, M.L king
                              0
                          2. Bonjour a tous , tu n'a pas a t'excuser curagio , choupi13 peu regarder dans antivir et chercher aussi le rapport et nous en faire un copier coller stp .
                            poste nous le rapport antivir plus un nouveau rapport hijackthis .
                            0
                            1. Bonjour, M.L king, le rapport antivir de choupi13 est tombé là
                              http://www.commentcamarche.net/forum/affich 4880974 help marie#0
                              0
                          3. Coucou TLM

                            Suis pas loin en attendant un new HT

                            0
                            1. AntiVir PersonalEdition Classic
                              Report file date: 2008-02-02 11:35

                              Scanning for 740715 virus strains and unwanted programs.

                              Licensed to: Avira AntiVir PersonalEdition Classic
                              Serial number: 0000149996-ADJIE-0001
                              Platform: Windows XP
                              Windows version: (Service Pack 2) [5.1.2600]
                              Username: Propriétaire
                              Computer name: NOM-PGDCJLPCC3Z

                              Version information:
                              BUILD.DAT : 248 14437 Bytes 2007-05-31 16:59:00
                              AVSCAN.EXE : 7.0.4.15 282664 Bytes 2007-04-20 12:37:14
                              AVSCAN.DLL : 7.0.4.4 33832 Bytes 2007-03-27 12:31:54
                              LUKE.DLL : 7.0.4.11 143400 Bytes 2007-03-27 12:26:04
                              LUKERES.DLL : 7.0.4.0 10280 Bytes 2007-03-19 12:18:59
                              ANTIVIR0.VDF : 6.35.0.1 7371264 Bytes 2006-05-31 14:08:58
                              ANTIVIR1.VDF : 6.37.1.151 4303360 Bytes 2007-02-23 14:09:01
                              ANTIVIR2.VDF : 6.38.0.214 729600 Bytes 2007-04-12 14:09:02
                              ANTIVIR3.VDF : 6.38.0.225 50688 Bytes 2007-04-16 14:09:02
                              AVEWIN32.DLL : 7.4.0.12 2404864 Bytes 2007-04-13 14:04:24
                              AVWINLL.DLL : 1.0.0.7 14376 Bytes 2007-02-26 10:36:26
                              AVPREF.DLL : 7.0.2.1 24616 Bytes 2007-03-27 12:31:50
                              AVREP.DLL : 7.0.0.1 155688 Bytes 2007-04-16 13:16:24
                              AVPACK32.DLL : 7.3.0.8 360488 Bytes 2007-03-27 08:48:28
                              AVREG.DLL : 7.0.1.2 31784 Bytes 2007-03-15 09:05:08
                              AVEVTLOG.DLL : 7.0.0.18 86056 Bytes 2007-03-27 12:16:05
                              AVARKT.DLL : 1.0.0.17 278568 Bytes 2007-05-02 11:32:26
                              NETNT.DLL : 7.0.0.0 7720 Bytes 2007-03-08 11:09:42
                              RCIMAGE.DLL : 7.0.1.15 2228264 Bytes 2007-03-13 10:46:18
                              RCTEXT.DLL : 7.0.45.0 86056 Bytes 2007-03-19 12:42:42

                              Configuration settings for the scan:
                              Jobname..........................: Local Hard Disks
                              Configuration file...............: C:\Program Files\AntiVir PersonalEdition Classic\alldiscs.avp
                              Logging..........................: low
                              Primary action...................: interactive
                              Secondary action.................: ignore
                              Scan master boot sector..........: off
                              Scan boot sector.................: on
                              Boot sectors.....................: D:,
                              Scan memory......................: on
                              Process scan.....................: on
                              Scan registry....................: on
                              Search for rootkits..............: off
                              Scan all files...................: Intelligent file selection
                              Scan archives....................: on
                              Recursion depth..................: 20
                              Smart extensions.................: on
                              Macro heuristic..................: on
                              File heuristic...................: medium

                              Start of the scan: 2008-02-02 11:35

                              The scan of running processes will be started
                              Scan process 'avscan.exe' - '1' Module(s) have been scanned
                              Scan process 'msworks.exe' - '1' Module(s) have been scanned
                              Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                              Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
                              Scan process 'explorer.exe' - '1' Module(s) have been scanned
                              Scan process 'svchost.exe' - '1' Module(s) have been scanned
                              Scan process 'guard.exe' - '1' Module(s) have been scanned
                              Scan process 'svchost.exe' - '1' Module(s) have been scanned
                              Scan process 'svchost.exe' - '1' Module(s) have been scanned
                              Scan process 'lsass.exe' - '1' Module(s) have been scanned
                              Scan process 'services.exe' - '1' Module(s) have been scanned
                              Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                              Scan process 'csrss.exe' - '1' Module(s) have been scanned
                              Scan process 'smss.exe' - '1' Module(s) have been scanned
                              14 processes with 14 modules were scanned

                              Start scanning boot sectors:
                              Boot sector 'C:\'
                              [NOTE] No virus was found!
                              Boot sector 'D:\'
                              [NOTE] No virus was found!

                              Starting to scan the registry.
                              The registry was scanned ( '27' files ).

                              Starting the file scan:

                              Begin scan in 'C:\' <HP_PAVILION>
                              C:\pagefile.sys
                              [WARNING] The file could not be opened!
                              C:\WINDOWS\system32\nested.sys
                              [DETECTION] Is the Trojan horse TR/Rootkit.Gen
                              [INFO] The file was moved to '48175ef5.qua'!
                              Begin scan in 'D:\' <HP_RECOVERY>

                              End of the scan: 2008-02-02 13:35
                              Used time: 2:00:39 min

                              The scan has been done completely.

                              5072 Scanning directories
                              287724 Files were scanned
                              1 viruses and/or unwanted programs were found
                              0 classified as suspicious:
                              0 files were deleted
                              0 files were repaired
                              1 files were moved to quarantine
                              0 files were renamed
                              1 Files cannot be scanned
                              287723 Files not concerned
                              17771 Archives were scanned
                              1 Warnings
                              0 Notes
                              0 Hidden objects were found

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 14:29, on 2008-02-02
                              Platform: Windows XP SP2 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v7.00 (7.00.6000.16574)
                              Boot mode: Normal

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\windows\system\hpsysdrv.exe
                              C:\HP\KBD\KBD.EXE
                              C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
                              C:\WINDOWS\System32\hphmon05.exe
                              C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                              C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                              C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
                              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              C:\WINDOWS\system32\ctfmon.exe
                              C:\Program Files\Messenger\msmsgs.exe
                              C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
                              C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                              C:\WINDOWS\System32\nvsvc32.exe
                              C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
                              C:\WINDOWS\System32\HPZipm12.exe
                              C:\WINDOWS\system32\wscntfy.exe
                              C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
                              C:\Program Files\internet explorer\iexplore.exe
                              C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
                              C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
                              C:\WINDOWS\system32\NOTEPAD.EXE
                              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                              R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                              O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                              O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                              O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                              O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                              O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                              O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                              O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
                              O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                              O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
                              O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
                              O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                              O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
                              O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
                              O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\hphupd05.exe
                              O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
                              O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
                              O4 - HKLM\..\Run: [LaunchList] C:\Program Files\Pinnacle\Studio 9\LaunchList.exe
                              O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                              O4 - HKLM\..\Run: [Sysmem32] C:\WINDOWS\system32\drivers\alg.exe
                              O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                              O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
                              O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                              O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                              O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
                              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                              O4 - .DEFAULT User Startup: ddrive.js (User 'Default user')
                              O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
                              O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                              O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                              O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                              O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
                              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                              O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
                              O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
                              O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
                              O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
                              0
                              1. Ok

                                On commence à y voir un peu plus clair dans ton log

                                Fais un récapitulatif complet de tes symptômes

                                0
                                1. ok
                                  alors le pc rame enormement et deuxieme probleme quand je lance le scan de l'antivirus le pc redemare tout seul au bout d'un moment!
                                  le scan antivir a été jusqu'a la fin car je l'ai fait en mode sans echec

                                  voila
                                  a++
                                  0
                                  1. oui derniere chose aussi ce matin on m'a dit de changer d'antivirus donc j'ai désinstallé avast et j'ai mis antivir et maintenant la securité windows me dit que la protection antivirus est périmé!!

                                    a+
                                    0
                                    • 1
                                    • 2
                                    • 3
                                    • 4
                                    • 5
                                    • 7
                                    • 8
                                    • 12