/HELP\ PC qui rame !

Bonjour, des que j'arrive sur le bureau le voyant du disque dur se fige et le PC rame a mort donc impossible de faire quoi que ce soit il faut 1 minute pour ouvrir le menu demarrer... J'ai lancer le mode sans echec et effectuer le scan Avast(qui est mon antivirus d'ailleur)et il n'a rien trouver ... je fais le scan spybot puis je met un coup de CCleaner mais sa rame toujours autant.Je télécharge malwarebytes' qui me trouve 2 ad-aware mais sa n'a pas résolu mon problème.
C'est apparu d'un coup en plein milieu d'un jeu.

Merci de votre aide :)
Configuration: Windows Vista
Firefox 2.0.0.16

21 réponses

  1. je viens de faire une analyse BitDefender en ligne qui m'a trouver un trojan !
    0
    1. salut

      quand tu fais des scans, tu dois apprendre à coller les rapports ici, et par là même fournir un max de renseignements aux éventuels helpers. Peux-tu coller le rapport du scan avec Bitdefender? As-tu effacé le virus?

      1) Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

      2) Télécharge Malwarebytes' Anti-Malware (MBAM) et enregistre le sur ton Bureau à partir de ce lien :

      https://www.malwarebytes.com/

      3) A la fin du téléchargement, ferme toutes les fenêtres et programmes, y compris celui-ci.

      4) Double-clique sur l'icône Download_mbam-setup.exe sur ton bureau pour démarrer le programme d'installation.

      5) Pendant l'installation, suis les indications (en particulier le choix de la langue et l'autorisation d'accession à Internet). N'apporte aucune modification aux réglages par défaut et, en fin d'installation, vérifie que les options Update Malwarebytes' Anti-Malware et Launch Malwarebytes' Anti-Malware sont cochées.

      6) MBAM démarrera automatiquement et enverra un message demandant à mettre à jour le programme avant de lancer une analyse. Comme MBAM se met automatiquement à jour en fin d'installation, clique sur OK pour fermer la boîte de dialogue. La fenêtre principale de MBAM s'affiche :

      7) Dans l'onglet analyse, vérifie que "Exécuter un examen complet" est coché et clique sur le bouton Rechercher pour démarrer l'analyse.

      8) MBAM analyse ton ordinateur. L'analyse peut prendre un certain temps. Il suffit de vérifier de temps en temps son avancement.

      9) A la fin de l'analyse, un message s'affiche indiquant la fin de l'analyse. Clique sur OK pour poursuivre.

      10) Si des malwares ont été détectés, leur liste s'affiche.
      En cliquant sur Suppression (?) , MBAM va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.

      11) MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Ferme le Bloc-notes. (Le rapport peut être retrouvé sous l'onglet Rapports/logs)

      12) Ferme MBAM en cliquant sur Quitter.

      13) Poste le rapport dans ta réponse

      ------------------------------------------------------------------------------------------------------------------------------------------------------------

      Clique sur ce lien
      http://www.trendsecure.com/portal/en-US/threat_analytics/HJT­Install.exe
      pour télécharger le fichier d'installation d'HijackThis.

      Enregistre HJTInstall.exe sur ton bureau et RENOMME-LE selon ta convenance

      Double-clique sur HJTInstall.exe pour lancer le programme

      Par défaut, il s'installera là :
      C:\Program Files\Trend Micro\HijackThis

      Accepte la license en cliquant sur le bouton "I Accept"

      Choisis l'option "Do a system scan and save a log file"

      Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note

      Clique sur "Edition -> Sélectionner tout", puis sur "Edition -> Copier" pour copier tout le contenu du rapport

      Colle le rapport que tu viens de copier sur ce forum

      Ne fixe encore AUCUNE ligne, cela pourrait empêcher ton PC de fonctionner correctement

      Tutoriaux : http://pageperso.aol.fr/balltrap34/demohijack.htm (ne fixe rien pour le moment !!)
      http://cybersecurite.xooit.com/t138-HijackThis-2-0-2.htm

      A plus

      Zor
      0
      1. Pour MBAM je l'ai deja effectuer comme preciser ci-dessus mais je vais en refaire un et t'envoyer le rapport :)
        0
        1. Voici le rapport Hijackthis:
          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 19:44:55, on 30/07/2008
          Platform: Windows Vista SP1 (WinNT 6.00.1905)
          MSIE: Internet Explorer v7.00 (7.00.6001.18000)
          Boot mode: Safe mode with network support

          Running processes:
          C:\Windows\Explorer.EXE
          C:\Windows\system32\wbem\unsecapp.exe
          C:\PILOTE~1\FREEDO~1\FREEDO~1\fdm.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          R3 - URLSearchHook: (no name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - (no file)
          O1 - Hosts: ::1 localhost
          O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - (no file)
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PILOTE~1\Spybot\SPYBOT~1\SDHelper.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
          O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Pilotes et logiciels\Free Download Manager\Free Download Manager\iefdm2.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
          O3 - Toolbar: (no name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - (no file)
          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
          O4 - HKLM\..\Run: [Skytel] Skytel.exe
          O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\JM\JMInsIDE.exe
          O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
          O4 - HKLM\..\Run: [avast!] C:\PILOTE~1\ANTIVI~1\ashDisp.exe
          O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe /RegAll
          O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
          O4 - HKLM\..\Run: [HP Software Update] C:\Pilotes et logiciels\Imprimante HP\HP Software Update\HPWuSchd2.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
          O4 - HKLM\..\Run: [WinampAgent] "C:\Pilotes et logiciels\Winamp\winampa.exe"
          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
          O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [Steam] "c:\jeux\counte~1\steam.exe" -silent
          O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Pilotes et logiciels\Spybot\Spybot - Search & Destroy\TeaTimer.exe
          O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\Maxime\Program Files\DNA\btdna.exe"
          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Pilotes et logiciels\Imprimante HP\Digital Imaging\bin\hpqtra08.exe
          O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Pilotes et logiciels\Souris\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
          O4 - Global Startup: Logitech SetPoint.lnk = C:\Pilotes et logiciels\Souris\SetPoint\SetPoint.exe
          O8 - Extra context menu item: Tout télécharger avec Free Download Manager - file://C:\Pilotes et logiciels\Free Download Manager\Free Download Manager\dlall.htm
          O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Pilotes et logiciels\Free Download Manager\Free Download Manager\dllink.htm
          O8 - Extra context menu item: Télécharger la sélection avec Free Download Manager - file://C:\Pilotes et logiciels\Free Download Manager\Free Download Manager\dlselected.htm
          O8 - Extra context menu item: Télécharger la vidéo avec Free Download Manager - file://C:\Pilotes et logiciels\Free Download Manager\Free Download Manager\dlfvideo.htm
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PILOTE~1\Spybot\SPYBOT~1\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PILOTE~1\Spybot\SPYBOT~1\SDHelper.dll
          O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Pilotes et logiciels\ICQ\ICQ6\ICQ.exe
          O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Pilotes et logiciels\ICQ\ICQ6\ICQ.exe
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O13 - Gopher Prefix:
          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
          O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/webplayer/stage6/windows/AutoDLDivXWebPlayerInstaller.cab
          O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
          O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
          O16 - DPF: {DFB5BCF1-06AE-4ABB-BFA8-1E228F41C50A} (CamfrogWEB Advanced Unicode Control) - https://www.bobtv.fr/download/cfweb_www.bobtv.fr-download_instmodule.exe
          O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Pilotes et logiciels\Souris\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Pilotes et logiciels\Antivirus\aswUpdSv.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Pilotes et logiciels\Antivirus\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Pilotes et logiciels\Antivirus\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Pilotes et logiciels\Antivirus\ashWebSv.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
          O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
          O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
          O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe (file missing)
          0
          1. Et voici le rapport MBAM:

            Malwarebytes' Anti-Malware 1.23
            Version de la base de données: 1008
            Windows 6.0.6001 Service Pack 1

            20:25:50 30/07/2008
            mbam-log-7-30-2008 (20-25-50).txt

            Type de recherche: Examen complet (A:\|C:\|D:\|E:\|)
            Eléments examinés: 138325
            Temps écoulé: 26 minute(s), 34 second(s)

            Processus mémoire infecté(s): 0
            Module(s) mémoire infecté(s): 0
            Clé(s) du Registre infectée(s): 0
            Valeur(s) du Registre infectée(s): 0
            Elément(s) de données du Registre infecté(s): 0
            Dossier(s) infecté(s): 0
            Fichier(s) infecté(s): 0

            Processus mémoire infecté(s):
            (Aucun élément nuisible détecté)

            Module(s) mémoire infecté(s):
            (Aucun élément nuisible détecté)

            Clé(s) du Registre infectée(s):
            (Aucun élément nuisible détecté)

            Valeur(s) du Registre infectée(s):
            (Aucun élément nuisible détecté)

            Elément(s) de données du Registre infecté(s):
            (Aucun élément nuisible détecté)

            Dossier(s) infecté(s):
            (Aucun élément nuisible détecté)

            Fichier(s) infecté(s):
            (Aucun élément nuisible détecté)
            0
            1. Salut,

              Pas la peine d'aller en mode sans échec :
              Télécharge et lance LSPfix http://www.cexx.org/lspfix.htm
              Déconnecte-toi d'Internet et fermez toutes les fenêtres d'Internet Explorer.
              Coche la case "I know what I'm doing"
              Sélectionne toutes les instances des dll contenue dans 010 du rapport d'HijackThis
              Fais glisser du panneau de gauche "keep" au panneau de droite "Remove".
              Clique sur le bouton "Finish".

              A plus

              Zor

              Attention: comme tu es sous vista, pour lancer l'applicatication, tu devras peut-être cliquer bouton droit "exécuter en tant qu'administrateur"
              0
              1. Si je suis obliger pour le mode sans echec car il met 15 minutes pour ouvrir un programme en normal...
                0
                1. là, c'est in tout petit programme...

                  A toi de voir

                  A plus

                  Zor
                  0
                  1. Voila j'ai supprimmer ce dll avec ton logiciel c bon maintenant ?
                    0
                    1. Colle un nouveau rapport Hijackthis, please

                      A plus

                      Zor
                      0
                      1. J'ai refait un Hijackthis:

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 22:03:10, on 30/07/2008
                        Platform: Windows Vista SP1 (WinNT 6.00.1905)
                        MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                        Boot mode: Safe mode with network support

                        Running processes:
                        C:\Windows\Explorer.EXE
                        C:\Windows\system32\wbem\unsecapp.exe
                        C:\PILOTE~1\FREEDO~1\FREEDO~1\fdm.exe
                        C:\Pilotes et logiciels\Mozilla Firefox\firefox.exe
                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                        R3 - URLSearchHook: (no name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - (no file)
                        O1 - Hosts: ::1 localhost
                        O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - (no file)
                        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PILOTE~1\Spybot\SPYBOT~1\SDHelper.dll
                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                        O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Pilotes et logiciels\Free Download Manager\Free Download Manager\iefdm2.dll
                        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                        O3 - Toolbar: (no name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - (no file)
                        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                        O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                        O4 - HKLM\..\Run: [Skytel] Skytel.exe
                        O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\JM\JMInsIDE.exe
                        O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
                        O4 - HKLM\..\Run: [avast!] C:\PILOTE~1\ANTIVI~1\ashDisp.exe
                        O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe /RegAll
                        O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
                        O4 - HKLM\..\Run: [HP Software Update] C:\Pilotes et logiciels\Imprimante HP\HP Software Update\HPWuSchd2.exe
                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                        O4 - HKLM\..\Run: [WinampAgent] "C:\Pilotes et logiciels\Winamp\winampa.exe"
                        O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                        O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                        O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
                        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                        O4 - HKCU\..\Run: [Steam] "c:\jeux\counte~1\steam.exe" -silent
                        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Pilotes et logiciels\Spybot\Spybot - Search & Destroy\TeaTimer.exe
                        O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\Maxime\Program Files\DNA\btdna.exe"
                        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Pilotes et logiciels\Imprimante HP\Digital Imaging\bin\hpqtra08.exe
                        O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Pilotes et logiciels\Souris\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                        O4 - Global Startup: Logitech SetPoint.lnk = C:\Pilotes et logiciels\Souris\SetPoint\SetPoint.exe
                        O8 - Extra context menu item: Tout télécharger avec Free Download Manager - file://C:\Pilotes et logiciels\Free Download Manager\Free Download Manager\dlall.htm
                        O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Pilotes et logiciels\Free Download Manager\Free Download Manager\dllink.htm
                        O8 - Extra context menu item: Télécharger la sélection avec Free Download Manager - file://C:\Pilotes et logiciels\Free Download Manager\Free Download Manager\dlselected.htm
                        O8 - Extra context menu item: Télécharger la vidéo avec Free Download Manager - file://C:\Pilotes et logiciels\Free Download Manager\Free Download Manager\dlfvideo.htm
                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
                        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
                        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PILOTE~1\Spybot\SPYBOT~1\SDHelper.dll
                        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PILOTE~1\Spybot\SPYBOT~1\SDHelper.dll
                        O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Pilotes et logiciels\ICQ\ICQ6\ICQ.exe
                        O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Pilotes et logiciels\ICQ\ICQ6\ICQ.exe
                        O13 - Gopher Prefix:
                        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                        O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/webplayer/stage6/windows/AutoDLDivXWebPlayerInstaller.cab
                        O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
                        O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
                        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                        O16 - DPF: {DFB5BCF1-06AE-4ABB-BFA8-1E228F41C50A} (CamfrogWEB Advanced Unicode Control) - https://www.bobtv.fr/download/cfweb_www.bobtv.fr-download_instmodule.exe
                        O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Pilotes et logiciels\Souris\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
                        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Pilotes et logiciels\Antivirus\aswUpdSv.exe
                        O23 - Service: avast! Antivirus - ALWIL Software - C:\Pilotes et logiciels\Antivirus\ashServ.exe
                        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Pilotes et logiciels\Antivirus\ashMaiSv.exe
                        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Pilotes et logiciels\Antivirus\ashWebSv.exe
                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                        O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
                        O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
                        O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
                        O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe (file missing)
                        0
                        1. Salut,

                          1) lance hijackthis, scan only, coche les lignes suivantes:

                          R3 - URLSearchHook: (no name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - (no file)
                          O3 - Toolbar: (no name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - (no file)
                          O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Pilotes et logiciels\Souris\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

                          O4 - HKLM\..\Run: [HP Software Update] C:\Pilotes et logiciels\Imprimante HP\HP Software Update\HPWuSchd2.exe
                          O4 - HKCU\..\Run: [Steam] "c:\jeux\counte~1\steam.exe" -silent
                          O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe (file missing)

                          Fais ensuite "fix checked"

                          2) je te propose de désinstaller Avast https://www.avast.com/fr-fr/uninstall-utility

                          au profit d'antivir https://www.malekal.com/avira-free-security-antivirus-gratuit/

                          Fais un scan avec antivir et colle un rapport ici

                          Bonne nuit

                          Zor
                          0
                          1. Pour l'antivirus c'est ce que j'allais faire car je sais qu'avast est pas top :S
                            0
                            1. Voici le rapport antivir:

                              Avira AntiVir Personal
                              Report file date: mercredi 30 juillet 2008 23:15

                              Scanning for 1521174 virus strains and unwanted programs.

                              Licensed to: Avira AntiVir PersonalEdition Classic
                              Serial number: 0000149996-ADJIE-0001
                              Platform: Windows Vista
                              Windows version: (Service Pack 1) [6.0.6001]
                              Boot mode: Normally booted
                              Username: SYSTEM
                              Computer name: PC-DE-MAXIME

                              Version information:
                              BUILD.DAT : 8.1.0.326 16933 Bytes 11/07/2008 12:57:00
                              AVSCAN.EXE : 8.1.4.7 315649 Bytes 26/06/2008 08:57:53
                              AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 07:56:40
                              LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 12:44:19
                              LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 07:58:52
                              ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 10:33:34
                              ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 24/06/2008 13:54:15
                              ANTIVIR2.VDF : 7.0.5.174 2027008 Bytes 25/07/2008 21:13:55
                              ANTIVIR3.VDF : 7.0.5.194 174080 Bytes 30/07/2008 21:13:57
                              Engineversion : 8.1.1.12
                              AEVDF.DLL : 8.1.0.5 102772 Bytes 09/07/2008 08:46:50
                              AESCRIPT.DLL : 8.1.0.59 307579 Bytes 30/07/2008 21:14:11
                              AESCN.DLL : 8.1.0.23 119156 Bytes 30/07/2008 21:14:10
                              AERDL.DLL : 8.1.0.20 418165 Bytes 09/07/2008 08:46:50
                              AEPACK.DLL : 8.1.2.1 364917 Bytes 30/07/2008 21:14:09
                              AEOFFICE.DLL : 8.1.0.21 192891 Bytes 30/07/2008 21:14:07
                              AEHEUR.DLL : 8.1.0.44 1343863 Bytes 30/07/2008 21:14:05
                              AEHELP.DLL : 8.1.0.15 115063 Bytes 09/07/2008 08:46:50
                              AEGEN.DLL : 8.1.0.31 311669 Bytes 30/07/2008 21:14:00
                              AEEMU.DLL : 8.1.0.6 430451 Bytes 09/07/2008 08:46:50
                              AECORE.DLL : 8.1.1.7 172406 Bytes 30/07/2008 21:13:59
                              AEBB.DLL : 8.1.0.1 53617 Bytes 24/04/2008 08:50:42
                              AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 08:40:05
                              AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 09:28:01
                              AVREP.DLL : 8.0.0.2 98561 Bytes 30/07/2008 21:13:58
                              AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 11:26:40
                              AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
                              AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 12:27:49
                              SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
                              SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 12:49:40
                              NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
                              RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 13:48:07
                              RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 13:34:37

                              Configuration settings for the scan:
                              Jobname..........................: Complete system scan
                              Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
                              Logging..........................: low
                              Primary action...................: interactive
                              Secondary action.................: ignore
                              Scan master boot sector..........: on
                              Scan boot sector.................: on
                              Boot sectors.....................: C:,
                              Process scan.....................: on
                              Scan registry....................: on
                              Search for rootkits..............: off
                              Scan all files...................: Intelligent file selection
                              Scan archives....................: on
                              Recursion depth..................: 20
                              Smart extensions.................: on
                              Macro heuristic..................: on
                              File heuristic...................: medium

                              Start of the scan: mercredi 30 juillet 2008 23:15

                              The scan of running processes will be started
                              Scan process 'avscan.exe' - '1' Module(s) have been scanned
                              Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                              Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                              Scan process 'avguard.exe' - '1' Module(s) have been scanned
                              Scan process 'sched.exe' - '1' Module(s) have been scanned
                              Scan process 'svchost.exe' - '1' Module(s) have been scanned
                              Scan process 'VSSVC.exe' - '1' Module(s) have been scanned
                              Scan process 'SpybotSD.exe' - '1' Module(s) have been scanned
                              Scan process 'fdm.exe' - '1' Module(s) have been scanned
                              Scan process 'firefox.exe' - '1' Module(s) have been scanned
                              Scan process 'rundll32.exe' - '1' Module(s) have been scanned
                              Scan process 'hpqste08.exe' - '1' Module(s) have been scanned
                              Scan process 'WmiPrvSE.exe' - '1' Module(s) have been scanned
                              Scan process 'unsecapp.exe' - '1' Module(s) have been scanned
                              Scan process 'taskeng.exe' - '1' Module(s) have been scanned
                              Scan process 'WUDFHost.exe' - '1' Module(s) have been scanned
                              Scan process 'SearchIndexer.exe' - '1' Module(s) have been scanned
                              Scan process 'svchost.exe' - '1' Module(s) have been scanned
                              Scan process 'svchost.exe' - '1' Module(s) have been scanned
                              Scan process 'svchost.exe' - '1' Module(s) have been scanned
                              Scan process 'PnkBstrA.exe' - '1' Module(s) have been scanned
                              Scan process 'svchost.exe' - '1' Module(s) have been scanned
                              Scan process 'svchost.exe' - '1' Module(s) have been scanned
                              Scan process 'svchost.exe' - '1' Module(s) have been scanned
                              Scan process 'sidebar.exe' - '1' Module(s) have been scanned
                              Scan process 'KHALMNPR.exe' - '1' Module(s) have been scanned
                              Scan process 'ehmsas.exe' - '1' Module(s) have been scanned
                              Scan process 'SetPoint.exe' - '1' Module(s) have been scanned
                              Scan process 'LogitechDesktopMessenger.exe' - '1' Module(s) have been scanned
                              Scan process 'hpqtra08.exe' - '1' Module(s) have been scanned
                              Scan process 'btdna.exe' - '1' Module(s) have been scanned
                              Scan process 'TeaTimer.exe' - '1' Module(s) have been scanned
                              Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned
                              Scan process 'ehtray.exe' - '1' Module(s) have been scanned
                              Scan process 'sidebar.exe' - '1' Module(s) have been scanned
                              Scan process 'winampa.exe' - '1' Module(s) have been scanned
                              Scan process 'rundll32.exe' - '1' Module(s) have been scanned
                              Scan process 'jusched.exe' - '1' Module(s) have been scanned
                              Scan process 'LogiTray.exe' - '1' Module(s) have been scanned
                              Scan process 'RtHDVCpl.exe' - '1' Module(s) have been scanned
                              Scan process 'MSASCui.exe' - '1' Module(s) have been scanned
                              Scan process 'explorer.exe' - '1' Module(s) have been scanned
                              Scan process 'taskeng.exe' - '1' Module(s) have been scanned
                              Scan process 'dwm.exe' - '1' Module(s) have been scanned
                              Scan process 'svchost.exe' - '1' Module(s) have been scanned
                              Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                              Scan process 'svchost.exe' - '1' Module(s) have been scanned
                              Scan process 'svchost.exe' - '1' Module(s) have been scanned
                              Scan process 'rundll32.exe' - '1' Module(s) have been scanned
                              Scan process 'SLsvc.exe' - '1' Module(s) have been scanned
                              Scan process 'audiodg.exe' - '0' Module(s) have been scanned
                              Scan process 'svchost.exe' - '1' Module(s) have been scanned
                              Scan process 'svchost.exe' - '1' Module(s) have been scanned
                              Scan process 'svchost.exe' - '1' Module(s) have been scanned
                              Scan process 'svchost.exe' - '1' Module(s) have been scanned
                              Scan process 'svchost.exe' - '1' Module(s) have been scanned
                              Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                              Scan process 'nvvsvc.exe' - '1' Module(s) have been scanned
                              Scan process 'svchost.exe' - '1' Module(s) have been scanned
                              Scan process 'lsm.exe' - '1' Module(s) have been scanned
                              Scan process 'lsass.exe' - '1' Module(s) have been scanned
                              Scan process 'services.exe' - '1' Module(s) have been scanned
                              Scan process 'csrss.exe' - '1' Module(s) have been scanned
                              Scan process 'wininit.exe' - '1' Module(s) have been scanned
                              Scan process 'csrss.exe' - '1' Module(s) have been scanned
                              Scan process 'smss.exe' - '1' Module(s) have been scanned
                              65 processes with 65 modules were scanned

                              Starting master boot sector scan:
                              Master boot sector HD0
                              [INFO] No virus was found!
                              Master boot sector HD1
                              [INFO] No virus was found!
                              [WARNING] System error [21]: Le périphérique n'est pas prêt.
                              [INFO] Please restart the search with Administrator rights

                              Start scanning boot sectors:
                              Boot sector 'C:\'
                              [INFO] No virus was found!

                              Starting to scan the registry.
                              The registry was scanned ( '50' files ).

                              Starting the file scan:

                              Begin scan in 'C:\'
                              C:\hiberfil.sys
                              [WARNING] The file could not be opened!
                              C:\pagefile.sys
                              [WARNING] The file could not be opened!
                              C:\Downloads\Software\crysis_demo_jouable_1_anglais_77292.exe
                              [0] Archive type: RAR SFX (self extracting)
                              --> AllOth~1.cab
                              [1] Archive type: CAB (Microsoft)
                              --> shadercache.pak1
                              [WARNING] No further files can be extracted from this archive. The archive will be closed
                              --> English.cab
                              [1] Archive type: CAB (Microsoft)
                              --> trailer_rating.sfd
                              [WARNING] No further files can be extracted from this archive. The archive will be closed
                              [WARNING] No further files can be extracted from this archive. The archive will be closed

                              End of the scan: jeudi 31 juillet 2008 00:21
                              Used time: 1:06:07 Hour(s)

                              The scan has been done completely.

                              16779 Scanning directories
                              555871 Files were scanned
                              0 viruses and/or unwanted programs were found
                              0 Files were classified as suspicious:
                              0 files were deleted
                              0 files were repaired
                              0 files were moved to quarantine
                              0 files were renamed
                              3 Files cannot be scanned
                              555868 Files not concerned
                              3260 Archives were scanned
                              6 Warnings
                              0 Notes
                              0
                              1. Sinon sa a l'air de remarcher grand merci pour ton aide :)
                                0
                                1. Tant mieux. Cependant, je me demande quand même ce qui ralentissait ton ordi.
                                  D'après tes différents rapports, je n'ai pas vu d'infection.

                                  Ceci dit, avec antivir, tu peux planifier des scan via le "scheduler", ce qui est plus facile à mettre en oeuvre (pas de risque d'oubli et prévenir vaut mieux que guérir)

                                  Je te conseille de faire un scan périodique avec Malwarebytes antimalware (en mode sans échec), de vider ton ordi de temps à autres avec CCleaner, tu peux aussi corriger les erreurs de ta base de registres avec ce même logiciel dans l'onglet "erreurs" (très utile quand tu désinstalles un logiciel par ex)

                                  Je ne saurai jamais assez te conseiller de défragmenter ton disque dur.

                                  A plus

                                  Zor
                                  0
                                  1. Oki mais je fais asser regulierement des scans par moi meme avec spybot et maintenant antivir sinon a quoi sa sert de defragmenter le disque dur ?
                                    0
                                    • 1
                                    • 2