Infection de mon pc par malware et new win32

Bonjour,
deuis quelques jours, je suis envahi par le malware et le new win32. Ca a commencé avec un fichier qui a aterri sur mon pc et qui a (très probablement) envoyé ces deux saloperies sur mon disque dur et que j'ai bien vite supprimé.
En gros, si je lance un scan, mc afee les repère et je suis parfaitement capable de les upprimer. Seulement dès que je reboot... rebelote le malware et le win32 sont relà a me faire la nique sous une autre forme.
Or j'ai un problème majeur, je pense que ces deux machins ont reussi d'une manière ou d'une autre à m'empêcher d'installer nimporte quel software freeware ou autre sur mon disque dur. Si je veux telecharger un autre antivirus, je suis le lien et paf soit la page n'existe pas, soit firefox (ou ie d'ailleurs) bug, ou bien même pour bêtement retelecharger windows live messenger ou de mettre a jour firefox ou ie, ca s'avere impossible. J'ai essayé de restaurer, mais sans résultat. Je deviens fou pitié aidez moi.
Configuration: Windows Vista
Firefox 3.0.10

11 réponses

  1. Contributeur
    Bonjour,

    télécharge GenProc http://www.genproc.com/GenProc.exe

    double-clique sur GenProc.exe et poste le contenu du rapport qui s'ouvre
    0
    1. Hum ca marche manifestement pas.
      En gros quand je lance genproc, la fenêtre s'ouvre, mais il me liste des erreurs à répétition qui se base surtout sur le fait qu'il ne trouve pas les fichiers.
      http://img3.imageshack.us/img3/842/problemeq.jpg
      http://img3.imageshack.us/img3/1760/probleme2.jpg
      http://img31.imageshack.us/img31/1172/probleme3.jpg
      0
      1. j'ai bien desactivé l'UAC, rien n y fait, ca me fait toujours le même problème. J'ai bien tenté de le retélécharger, mais sans résultat.
        0
        1. Contributeur
          démarrer => exécuter écrit cmd puis ok
          colle dans la fenêtre noir

          set > v.txt
          notepad v.txt


          valide par entrée
          poste le rapport.

          0
          1. ALLUSERSPROFILE=C:\ProgramData
            APPDATA=C:\Users\Aniss\AppData\Roaming
            CLASSPATH=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
            CommonProgramFiles=C:\Program Files\Common Files
            COMPUTERNAME=THE-SPARK
            ComSpec=C:\Windows\system32\cmd.exe
            DFSTRACINGON=FALSE
            FP_NO_HOST_CHECK=NO
            HOMEDRIVE=C:
            HOMEPATH=\Users\Aniss
            LOCALAPPDATA=C:\Users\Aniss\AppData\Local
            LOGONSERVER=\\THE-SPARK
            NTIPath=C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Program Files\Acer\Empowering Technology\eDataSecurity\;C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86;C:\Program Files\Acer\Empowering Technology\eDataSecurity\x64;C:\Program Files\NewTech Infosystems\NTI Backup Now 5\;
            NUMBER_OF_PROCESSORS=2
            OS=Windows_NT
            Path=C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Program Files\Acer\Empowering Technology\eDataSecurity\;C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86;C:\Program Files\Acer\Empowering Technology\eDataSecurity\x64;C:\Program Files\QuickTime\QTSystem\
            PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
            Pathtem=C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Program Files\Acer\Empowering Technology\eDataSecurity\;C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86;C:\Program Files\Acer\Empowering Technology\eDataSecurity\x64
            PROCESSOR_ARCHITECTURE=x86
            PROCESSOR_IDENTIFIER=x86 Family 6 Model 23 Stepping 6, GenuineIntel
            PROCESSOR_LEVEL=6
            PROCESSOR_REVISION=1706
            ProgramData=C:\ProgramData
            ProgramFiles=C:\Program Files
            PROMPT=$P$G
            PUBLIC=C:\Users\Public
            QTJAVA=C:\Program Files\QuickTime\QTSystem\QTJava.zip
            SESSIONNAME=Console
            SystemDrive=C:
            SystemRoot=C:\Windows
            TEMP=C:\Users\Aniss\AppData\Local\Temp
            TMP=C:\Users\Aniss\AppData\Local\Temp
            TRACE_FORMAT_SEARCH_PATH=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
            USERDOMAIN=The-Spark
            USERNAME=Aniss
            USERPROFILE=C:\Users\Aniss
            windir=C:\Windows
            0
            1. Contributeur
              tu est l'administrateur sur ce pc ?
              0
              1. Oui, il n ya même aucun autre compte utilisateur
                0
                1. Contributeur
                  Télécharge plutot la version zip dans ce cas : http://www.alt-shift-return.org/Info/Fichiers/GenProc.zip sur ton bureau

                  dézippe le dossier, double-clique sur GenProc.bat [img]http://forum.telecharger.01net.com/forum/­lies/jeanchretien1-3.gif/img et poste le contenu du rapport qui s'ouvre

                  Aide en images : http://www.alt-shift-return.org/Info/GenProc-HowTo.html
                  0
                  1. Ca en fonctionne pas...
                    Les fichiers qui sont dit manquants sont pourtant présents avant que je tente de lancer genproc, mais apres avoir essayé lorsque je verifie ils n'y sont plus (dont swreg.exe)
                    0
                    1. Contributeur
                      Poste un rapport HijackThis : http://forum.telecharger.01net.com/forum/high-tech/PRODUITS/Questions-techniques/hijackthis-version-install-sujet_199100_1.htm
                      0