Supprimer virus TR/PWS.25600.8

Résolu
Bonjour,

Je suis sous windows XP , mon ordi est infecté par le virus TR/PWS.25600.8
depuis qqs jours

j'ai réussi à le nettoyer un peu en passant par navilog mais le virus persiste
il est détecté 1 fois sur deux (antivirus Antivir), je fais régulièrement des
nettoyages pour essayer de l'alléger

résultat à chaque démarrage plusieurs fenêtres error starting apparaissent +
une fenêtre de proposition pour prendre Notification Windows genuine advantage

Depuis peu quand j'utilise internet une fenêtre antivir avira apparait sans arrêt
pour m'alerter du virus mais je ne peux ni le mettre en quarantaine ni le supprimer ni
me débarrasser des fenêtres.

SVP COMMENT LE SUPPRIMER DEFINITIVEMENT SANS FORMATER MON PC?
Configuration: Windows XP
Firefox 3.0.11

14 réponses

  1. Contributeur sécurité
    slt
    as tu tenté de passer antivir en mode sans echec?

    _______________

    si tu peux colle un rapport avec antivir pour voir les fichiers infectés

    ____________________

    Télécharge ici :

    http://images.malwareremoval.com/random/RSIT.exe

    random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

    Double-clique sur RSIT.exe afin de lancer RSIT.

    Clique Continue à l'écran Disclaimer.

    Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

    Poste le contenu de log.txt (<<qui sera affiché)
    ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

    NB : Les rapports sont sauvegardés dans le dossier C:\rsit
    0
    1. merci de me répondre

      oui j'ai essayé en mode sans échec sans résultats

      je t'ai posté mon rapport antivir:

      Avira AntiVir Personal
      Report file date: mardi 21 juillet 2009 14:58

      Scanning for 1556791 virus strains and unwanted programs.

      Licensee : Avira AntiVir Personal - FREE Antivirus
      Serial number : 0000149996-ADJIE-0000001
      Platform : Windows XP
      Windows version : (Service Pack 2) [5.1.2600]
      Boot mode : Normally booted
      Username : SYSTEM
      Computer name : ABC-MJYVGFWC7Y1

      Version information:
      BUILD.DAT : 9.0.0.403 17961 Bytes 03/06/2009 17:05:00
      AVSCAN.EXE : 9.0.3.6 466689 Bytes 11/05/2009 08:14:47
      AVSCAN.DLL : 9.0.3.0 40705 Bytes 27/02/2009 09:58:24
      LUKE.DLL : 9.0.3.2 209665 Bytes 20/02/2009 10:35:49
      LUKERES.DLL : 9.0.2.0 12033 Bytes 27/02/2009 09:58:52
      ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 11:30:36
      ANTIVIR1.VDF : 7.1.4.132 5707264 Bytes 24/06/2009 09:47:53
      ANTIVIR2.VDF : 7.1.4.253 1779200 Bytes 19/07/2009 09:49:13
      ANTIVIR3.VDF : 7.1.5.5 30208 Bytes 20/07/2009 11:38:55
      Engineversion : 8.2.0.222
      AEVDF.DLL : 8.1.1.1 106868 Bytes 30/04/2009 10:52:04
      AESCRIPT.DLL : 8.1.2.18 442746 Bytes 20/07/2009 09:48:06
      AESCN.DLL : 8.1.2.3 127347 Bytes 14/05/2009 10:02:01
      AERDL.DLL : 8.1.2.4 430452 Bytes 20/07/2009 09:48:05
      AEPACK.DLL : 8.1.3.18 401783 Bytes 27/05/2009 15:07:20
      AEOFFICE.DLL : 8.1.0.38 196987 Bytes 20/07/2009 09:48:04
      AEHEUR.DLL : 8.1.0.143 1864055 Bytes 20/07/2009 09:48:04
      AEHELP.DLL : 8.1.4.5 229748 Bytes 20/07/2009 09:48:01
      AEGEN.DLL : 8.1.1.48 348532 Bytes 20/07/2009 09:48:00
      AEEMU.DLL : 8.1.0.9 393588 Bytes 09/10/2008 13:32:40
      AECORE.DLL : 8.1.7.5 180597 Bytes 20/07/2009 09:48:00
      AEBB.DLL : 8.1.0.3 53618 Bytes 09/10/2008 13:32:40
      AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 07:47:59
      AVPREF.DLL : 9.0.0.1 43777 Bytes 05/12/2008 09:32:15
      AVREP.DLL : 8.0.0.3 155905 Bytes 20/01/2009 13:34:28
      AVREG.DLL : 9.0.0.0 36609 Bytes 05/12/2008 09:32:09
      AVARKT.DLL : 9.0.0.3 292609 Bytes 24/03/2009 14:05:41
      AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 30/01/2009 09:37:08
      SQLITE3.DLL : 3.6.1.0 326401 Bytes 28/01/2009 14:03:49
      SMTPLIB.DLL : 9.2.0.25 28417 Bytes 02/02/2009 07:21:33
      NETNT.DLL : 9.0.0.0 11521 Bytes 05/12/2008 09:32:10
      RCIMAGE.DLL : 9.0.0.25 2438913 Bytes 15/05/2009 14:39:58
      RCTEXT.DLL : 9.0.37.0 86785 Bytes 17/04/2009 09:19:48

      Configuration settings for the scan:
      Jobname.............................: Complete system scan
      Configuration file..................: c:\program files\avira\antivir desktop\sysscan.avp
      Logging.............................: low
      Primary action......................: interactive
      Secondary action....................: ignore
      Scan master boot sector.............: on
      Scan boot sector....................: on
      Boot sectors........................: C:, E:, F:,
      Process scan........................: on
      Scan registry.......................: on
      Search for rootkits.................: on
      Integrity checking of system files..: off
      Scan all files......................: All files
      Scan archives.......................: on
      Recursion depth.....................: 20
      Smart extensions....................: on
      Macro heuristic.....................: on
      File heuristic......................: medium
      Deviating risk categories...........: +APPL,+GAME,+JOKE,+PCK,+SPR,

      Start of the scan: mardi 21 juillet 2009 14:58

      Starting search for hidden objects.
      HKEY_LOCAL_MACHINE\System\ControlSet002\Services\geyekrpohyidqg\main
      [INFO] The registry entry is invisible.
      HKEY_LOCAL_MACHINE\System\ControlSet002\Services\geyekrpohyidqg\modules
      [INFO] The registry entry is invisible.
      HKEY_LOCAL_MACHINE\System\ControlSet002\Services\geyekrpohyidqg\start
      [INFO] The registry entry is invisible.
      HKEY_LOCAL_MACHINE\System\ControlSet002\Services\geyekrpohyidqg\type
      [INFO] The registry entry is invisible.
      HKEY_LOCAL_MACHINE\System\ControlSet002\Services\geyekrpohyidqg\group
      [INFO] The registry entry is invisible.
      HKEY_LOCAL_MACHINE\System\ControlSet002\Services\geyekrpohyidqg\imagepath
      [INFO] The registry entry is invisible.
      '41083' objects were checked, '6' hidden objects were found.

      The scan of running processes will be started
      Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
      Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
      Scan process 'avscan.exe' - '1' Module(s) have been scanned
      Scan process 'avcenter.exe' - '1' Module(s) have been scanned
      Scan process 'alg.exe' - '1' Module(s) have been scanned
      Scan process 'devldr32.exe' - '1' Module(s) have been scanned
      Scan process 'SPUVolumeWatcher.exe' - '1' Module(s) have been scanned
      Scan process 'avgnt.exe' - '1' Module(s) have been scanned
      Scan process 'realsched.exe' - '1' Module(s) have been scanned
      Scan process 'jusched.exe' - '1' Module(s) have been scanned
      Scan process 'rundll32.exe' - '1' Module(s) have been scanned
      Scan process 'avgcsrvx.exe' - '1' Module(s) have been scanned
      Scan process 'avgnsx.exe' - '1' Module(s) have been scanned
      Scan process 'avgrsx.exe' - '1' Module(s) have been scanned
      Scan process 'avgemc.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'PAStiSvc.exe' - '1' Module(s) have been scanned
      Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
      Scan process 'explorer.exe' - '1' Module(s) have been scanned
      Scan process 'jqs.exe' - '1' Module(s) have been scanned
      Scan process 'avgwdsvc.exe' - '1' Module(s) have been scanned
      Scan process 'ATKKBService.exe' - '1' Module(s) have been scanned
      Scan process 'avguard.exe' - '1' Module(s) have been scanned
      Scan process 'ANIWZCSdS.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'sched.exe' - '1' Module(s) have been scanned
      Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'lsass.exe' - '1' Module(s) have been scanned
      Scan process 'services.exe' - '1' Module(s) have been scanned
      Scan process 'winlogon.exe' - '1' Module(s) have been scanned
      Scan process 'csrss.exe' - '1' Module(s) have been scanned
      Scan process 'smss.exe' - '1' Module(s) have been scanned
      37 processes with 37 modules were scanned

      Starting master boot sector scan:
      Master boot sector HD0
      [INFO] No virus was found!

      Start scanning boot sectors:
      Boot sector 'C:\'
      [INFO] No virus was found!
      Boot sector 'E:\'
      [INFO] No virus was found!
      Boot sector 'F:\'
      [INFO] No virus was found!

      Starting to scan executable files (registry).
      The registry was scanned ( '50' files ).

      Starting the file scan:

      Begin scan in 'C:\'
      C:\pagefile.sys
      [WARNING] The file could not be opened!
      [NOTE] This file is a Windows system file.
      [NOTE] This file cannot be opened for scanning.
      C:\System Volume Information\_restore{6DFF39B0-8240-470C-8D48-DA908D8F6B80}\RP740\A0086018.exe
      [DETECTION] Is the TR/PWS.25600.8 Trojan
      C:\System Volume Information\_restore{6DFF39B0-8240-470C-8D48-DA908D8F6B80}\RP740\A0086019.exe
      [DETECTION] Is the TR/PWS.25600.8 Trojan
      C:\System Volume Information\_restore{6DFF39B0-8240-470C-8D48-DA908D8F6B80}\RP740\A0086020.exe
      [DETECTION] Is the TR/PWS.25600.8 Trojan
      C:\System Volume Information\_restore{6DFF39B0-8240-470C-8D48-DA908D8F6B80}\RP740\A0086021.exe
      [DETECTION] Is the TR/PWS.25600.8 Trojan
      C:\System Volume Information\_restore{6DFF39B0-8240-470C-8D48-DA908D8F6B80}\RP740\A0086022.exe
      [DETECTION] Is the TR/PWS.25600.8 Trojan
      C:\System Volume Information\_restore{6DFF39B0-8240-470C-8D48-DA908D8F6B80}\RP740\A0086023.exe
      [DETECTION] Is the TR/PWS.25600.8 Trojan
      Begin scan in 'E:\'
      Begin scan in 'F:\'

      Beginning disinfection:
      C:\System Volume Information\_restore{6DFF39B0-8240-470C-8D48-DA908D8F6B80}\RP740\A0086018.exe
      [DETECTION] Is the TR/PWS.25600.8 Trojan
      [NOTE] The file was moved to '4a95c791.qua'!
      C:\System Volume Information\_restore{6DFF39B0-8240-470C-8D48-DA908D8F6B80}\RP740\A0086019.exe
      [DETECTION] Is the TR/PWS.25600.8 Trojan
      [NOTE] The file was moved to '49c09c42.qua'!
      C:\System Volume Information\_restore{6DFF39B0-8240-470C-8D48-DA908D8F6B80}\RP740\A0086020.exe
      [DETECTION] Is the TR/PWS.25600.8 Trojan
      [NOTE] The file was moved to '4b1155aa.qua'!
      C:\System Volume Information\_restore{6DFF39B0-8240-470C-8D48-DA908D8F6B80}\RP740\A0086021.exe
      [DETECTION] Is the TR/PWS.25600.8 Trojan
      [NOTE] The file was moved to '4b105d92.qua'!
      C:\System Volume Information\_restore{6DFF39B0-8240-470C-8D48-DA908D8F6B80}\RP740\A0086022.exe
      [DETECTION] Is the TR/PWS.25600.8 Trojan
      [NOTE] The file was moved to '49c68bd2.qua'!
      C:\System Volume Information\_restore{6DFF39B0-8240-470C-8D48-DA908D8F6B80}\RP740\A0086023.exe
      [DETECTION] Is the TR/PWS.25600.8 Trojan
      [NOTE] The file was moved to '4a95c792.qua'!

      End of the scan: mardi 21 juillet 2009 15:49
      Used time: 50:15 Minute(s)

      The scan has been done completely.

      9301 Scanned directories
      332571 Files were scanned
      6 Viruses and/or unwanted programs were found
      0 Files were classified as suspicious
      0 files were deleted
      0 Viruses and unwanted programs were repaired
      6 Files were moved to quarantine
      0 Files were renamed
      1 Files cannot be scanned
      332564 Files not concerned
      1291 Archives were scanned
      1 Warnings
      7 Notes
      41083 Objects were scanned with rootkit scan
      6 Hidden objects were found
      0
      1. Voilà les fichiers texte:

        Logfile of random's system information tool 1.06 (written by random/random)
        Run by LYLY at 2009-07-21 16:03:05
        Microsoft Windows XP Professionnel Service Pack 2
        System drive C: has 6 GB (31%) free of 20 GB
        Total RAM: 2046 MB (73% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 16:03:16, on 21/07/2009
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Avira\AntiVir Desktop\sched.exe
        C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
        C:\Program Files\Avira\AntiVir Desktop\avguard.exe
        C:\WINDOWS\ATKKBService.exe
        C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
        C:\Program Files\Java\jre6\bin\jqs.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\System32\nvsvc32.exe
        C:\WINDOWS\System32\PAStiSvc.exe
        C:\WINDOWS\System32\svchost.exe
        C:\PROGRA~1\AVG\AVG8\avgemc.exe
        C:\PROGRA~1\AVG\AVG8\avgrsx.exe
        C:\PROGRA~1\AVG\AVG8\avgnsx.exe
        C:\Program Files\AVG\AVG8\avgcsrvx.exe
        C:\WINDOWS\system32\RUNDLL32.EXE
        C:\Program Files\Java\jre6\bin\jusched.exe
        C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
        C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
        C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
        C:\WINDOWS\system32\devldr32.exe
        C:\Documents and Settings\LYLY\Bureau\RSIT.exe
        C:\Program Files\Trend Micro\HijackThis\LYLY.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
        R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
        R3 - URLSearchHook: (no name) - *{C94E154B-1459-4A47-966B-4B843BEFC7DB} - (no file)
        R3 - URLSearchHook: (no name) - *{fe37be35-b028-49f9-bb0c-6a38c4e55b97} - (no file)
        O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
        O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
        O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\fr\msntb.dll (file missing)
        O3 - Toolbar: P2P Max France Toolbar - {fe37be35-b028-49f9-bb0c-6a38c4e55b97} - C:\Program Files\P2P_Max_France\tbP2P_.dll (file missing)
        O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
        O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
        O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
        O4 - HKLM\..\Run: [D-Link D-Link Wireless G DWA-110] C:\Program Files\D-Link\D-Link Wireless G DWA-110\AirGCFG.exe
        O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
        O4 - HKCU\..\Run: [] C:\DOCUME~1\LYLY\LOCALS~1\Temp\pqk7ddzzl .exe
        O4 - HKCU\..\Run: [RegistryDoktorFrNET] C:\Program Files\Registry Doktor 4.1\RegistryDoktor.exe
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
        O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
        O4 - Startup: Outil de détection de support de Cyber-shot Viewer.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
        O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
        O20 - AppInit_DLLs: C:\DOCUME~1\LYLY\LOCALS~1\Temp\302967501724mmx.dll
        O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
        O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
        O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
        O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Wireless Service - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
        O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
        O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
        O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
        O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
        O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
        O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
        O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
        0
        1. Contributeur sécurité
          ok les infections sont simplement dans ta restauration!

          1/ vire AVG8 car sur un ordi ne mettre qu'un seul antivirus et garde antivir

          2/tu avais registry doctor qui est un espion ! fais gaffe à ce que tu mets!!!

          Télécharge OTM
          http://www.geekstogo.com/forum/files/file/402-otm-oldtimers-move-it/
          http://oldtimer.geekstogo.com/OTMoveIt3.exe (de Old_Timer) sur ton Bureau.

          double-clique sur OTM.exe pour le lancer.
          copie la liste qui se trouve en citation ci-dessous,
          et colle-la dans le cadre de gauche de OTM :Paste instruction for items to be moved.
          (attention bien mettre :files)

          :processes
          explorer.exe
          :files
          C:\Program Files\Registry Doktor 4.1\RegistryDoktor.exe
          C:\DOCUME~1\LYLY\LOCALS~1\Temp\pqk7ddzzl .exe
          C:\DOCUME~1\LYLY\LOCALS~1\Temp\302967501724mmx.dll
          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
          {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}-
          {fe37be35-b028-49f9-bb0c-6a38c4e55b97}-
          [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
          ""=-
          "RegistryDoktorFrNET"=-
          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
          "AppInit_DLLS"=-
          :commands
          [purity]
          [emptytemp]
          [start explorer]

          clique sur MoveIt! pour lancer la suppression.
          le résultat apparaitra dans le cadre "Results".
          clique sur Exit pour fermer.
          poste le rapport situé dans C:\_OTM\MovedFiles.

          il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

          ___________________

          scan avec malwarebyte , fais un scan rapide et colle le rapport obtenu et vire ce qui est trouvé:

          https://www.malekal.com/tutoriel-malwarebyte-anti-malware/­

          ______________________

          lance glary utilities et nettoie le pc (ne pas mettre l'askbar)

          http://www.commentcamarche.net/telecharger/telecharger 34055557 glary utilities

          ________________________
          désactive ta restauration puis redemarre ton pc puis réactive la
          https://www.informatruc.com

          _________________________

          remets un rapport rsit et dis si encore des soucis et verifie avec antivir que les infections ne sont plus présentes

          a plus
          0
          1. rapport OTM:

            All processes killed
            ========== PROCESSES ==========
            No active process named explorer.exe was found!
            ========== FILES ==========
            File/Folder C:\Program Files\Registry Doktor 4.1\RegistryDoktor.exe not found.
            File/Folder C:\DOCUME~1\LYLY\LOCALS~1\Temp\pqk7ddzzl .exe not found.
            File/Folder C:\DOCUME~1\LYLY\LOCALS~1\Temp\302967501724mmx.dll not found.
            File/Folder [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] not found.
            File/Folder {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}- not found.
            File/Folder {fe37be35-b028-49f9-bb0c-6a38c4e55b97}- not found.
            File/Folder [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion­\Run] not found.
            File/Folder "= not found.
            File/Folder RegistryDoktorFrNET"= not found.
            File/Folder [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] not found.
            File/Folder AppInit_DLLS"= not found.
            ========== COMMANDS ==========

            [EMPTYTEMP]

            User: All Users

            User: Default User
            ->Temp folder emptied: 0 bytes
            ->Temporary Internet Files folder emptied: 33170 bytes

            User: LocalService
            ->Temp folder emptied: 0 bytes
            File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
            ->Temporary Internet Files folder emptied: 725798 bytes

            User: LYLY
            ->Temp folder emptied: 1644360 bytes
            ->Temporary Internet Files folder emptied: 33170 bytes
            ->Java cache emptied: 0 bytes
            ->FireFox cache emptied: 46757476 bytes

            User: NetworkService
            ->Temp folder emptied: 0 bytes
            ->Temporary Internet Files folder emptied: 1077767 bytes

            %systemdrive% .tmp files removed: 0 bytes
            %systemroot% .tmp files removed: 1119633 bytes
            %systemroot%\System32 .tmp files removed: 3072 bytes
            File delete failed. C:\WINDOWS\temp\hlktmp scheduled to be deleted on reboot.
            Windows Temp folder emptied: 361381 bytes
            RecycleBin emptied: 0 bytes

            Total Files Cleaned = 49,36 mb

            OTM by OldTimer - Version 3.0.0.5 log created on 07202009_171614

            Files moved on Reboot...
            File move failed. C:\WINDOWS\temp\hlktmp scheduled to be moved on reboot.

            Registry entries deleted on Reboot...
            0
            1. Contributeur sécurité
              ok fais la suite

              a plus
              0
              1. désolée d'avoir mis autant de tps pour répondre

                Malwarebytes' Anti-Malware 1.39
                Version de la base de données: 2467
                Windows 5.1.2600 Service Pack 2

                20/07/2009 18:09:28
                mbam-log-2009-07-20 (18-09-28).txt

                Type de recherche: Examen complet (A:\|C:\|D:\|E:\|F:\|)
                Eléments examinés: 201905
                Temps écoulé: 35 minute(s), 11 second(s)

                Processus mémoire infecté(s): 0
                Module(s) mémoire infecté(s): 0
                Clé(s) du Registre infectée(s): 0
                Valeur(s) du Registre infectée(s): 0
                Elément(s) de données du Registre infecté(s): 0
                Dossier(s) infecté(s): 0
                Fichier(s) infecté(s): 0

                Processus mémoire infecté(s):
                (Aucun élément nuisible détecté)

                Module(s) mémoire infecté(s):
                (Aucun élément nuisible détecté)

                Clé(s) du Registre infectée(s):
                (Aucun élément nuisible détecté)

                Valeur(s) du Registre infectée(s):
                (Aucun élément nuisible détecté)

                Elément(s) de données du Registre infecté(s):
                (Aucun élément nuisible détecté)

                Dossier(s) infecté(s):
                (Aucun élément nuisible détecté)

                Fichier(s) infecté(s):
                (Aucun élément nuisible détecté)
                0
                1. Contributeur sécurité
                  ok poursuis encore :)
                  0
                  1. Tout a l'air OK
                    Plus de problèmes au démarrage et en
                    allant sur internet, mais toujours cette fenêtre Windows Genuine Advantage

                    merci

                    Apparemment çà peut être un message automatique de microsoft
                    qui se déclenche automatiquement

                    Tu sais comment la supprimer?

                    Logfile of random's system information tool 1.06 (written by random/random)
                    Run by LYLY at 2009-07-20 19:32:33
                    Microsoft Windows XP Professionnel Service Pack 2
                    System drive C: has 6 GB (32%) free of 20 GB
                    Total RAM: 2046 MB (82% free)

                    Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 19:32:33, on 20/07/2009
                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                    Boot mode: Normal

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\Program Files\Avira\AntiVir Desktop\sched.exe
                    C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
                    C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                    C:\WINDOWS\ATKKBService.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\Program Files\Java\jre6\bin\jqs.exe
                    C:\WINDOWS\System32\nvsvc32.exe
                    C:\WINDOWS\System32\PAStiSvc.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\RUNDLL32.EXE
                    C:\Program Files\Java\jre6\bin\jusched.exe
                    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                    C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
                    C:\WINDOWS\system32\wuauclt.exe
                    C:\WINDOWS\system32\devldr32.exe
                    C:\Documents and Settings\LYLY\Bureau\RSIT.exe
                    C:\Program Files\Trend Micro\HijackThis\LYLY.exe

                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                    R3 - URLSearchHook: (no name) - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - (no file)
                    R3 - URLSearchHook: (no name) - {fe37be35-b028-49f9-bb0c-6a38c4e55b97} - (no file)
                    O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
                    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
                    O3 - Toolbar: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
                    O3 - Toolbar: (no name) - {fe37be35-b028-49f9-bb0c-6a38c4e55b97} - (no file)
                    O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
                    O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                    O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                    O4 - Startup: Outil de détection de support de Cyber-shot Viewer.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
                    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                    O20 - AppInit_DLLs: C:\DOCUME~1\LYLY\LOCALS~1\Temp\302967501724mmx.dll
                    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                    O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
                    O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Wireless Service - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
                    O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                    O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
                    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                    O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
                    0
                    1. Contributeur sécurité
                      si ton windows est légal mets le Windows Genuine Advantage

                      sinon vire cette tache plannifiée WGASetup.job

                      C:\WINDOWS\tasks\WGASetup.job

                      ________________________

                      colle un rapport hijackthis
                      http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download

                      Relance HijackThis, choisis "do a scan only" coche la case devant les lignes ci-dessous et clic en bas sur "fix checked".

                      R3 - URLSearchHook: (no name) - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - (no file)
                      R3 - URLSearchHook: (no name) - {fe37be35-b028-49f9-bb0c-6a38c4e55b97} - (no file)
                      O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
                      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
                      O3 - Toolbar: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
                      O3 - Toolbar: (no name) - {fe37be35-b028-49f9-bb0c-6a38c4e55b97} - (no file)
                      O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
                      O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll

                      O20 - AppInit_DLLs: C:\DOCUME~1\LYLY\LOCALS~1\Temp\302967501724mmx.dll

                      _______________________

                      Télécharge OTM
                      http://www.geekstogo.com/forum/files/file/402-otm-oldtimers-move-it/
                      (de Old_Timer) sur ton Bureau.

                      double-clique sur OTM.exe pour le lancer.
                      copie la liste qui se trouve en citation ci-dessous,
                      et colle-la dans le cadre de gauche de OTM :Paste instruction for items to be moved.
                      (attention bien mettre :files)

                      :processes
                      explorer.exe
                      :files
                      C:\DOCUME~1\LYLY\LOCALS~1\Temp\302967501724mmx.dll
                      :reg
                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                      "AppInit_DLLS"=-
                      :commands
                      [purity]
                      [emptytemp]
                      [start explorer]

                      clique sur MoveIt! pour lancer la suppression.
                      le résultat apparaitra dans le cadre "Results".
                      clique sur Exit pour fermer.
                      poste le rapport situé dans C:\_OTM\MovedFiles.

                      il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

                      _______________________

                      alors dis moi ton windows est légal ?
                      0
                      1. Pas vraiment...
                        Tout est impec

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 21:10:13, on 20/07/2009
                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                        Boot mode: Normal

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\Program Files\Avira\AntiVir Desktop\sched.exe
                        C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
                        C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                        C:\WINDOWS\ATKKBService.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\Program Files\Java\jre6\bin\jqs.exe
                        C:\WINDOWS\System32\nvsvc32.exe
                        C:\WINDOWS\System32\PAStiSvc.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\RUNDLL32.EXE
                        C:\Program Files\Java\jre6\bin\jusched.exe
                        C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                        C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
                        C:\WINDOWS\system32\devldr32.exe
                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                        R3 - URLSearchHook: (no name) - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - (no file)
                        R3 - URLSearchHook: (no name) - {fe37be35-b028-49f9-bb0c-6a38c4e55b97} - (no file)
                        O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
                        O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
                        O3 - Toolbar: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
                        O3 - Toolbar: (no name) - {fe37be35-b028-49f9-bb0c-6a38c4e55b97} - (no file)
                        O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
                        O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                        O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                        O4 - Startup: Outil de détection de support de Cyber-shot Viewer.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
                        O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                        O20 - AppInit_DLLs: C:\DOCUME~1\LYLY\LOCALS~1\Temp\302967501724mmx.dll
                        O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                        O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
                        O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Wireless Service - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
                        O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                        O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                        O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
                        O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                        O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
                        0
                        1. Contributeur sécurité
                          ok va dans le panneau de configuration puis centre de sécurité et désactive les mise a jour de windows surtout!!! car si non légal ...

                          ______________

                          remets un rapport RSIt pour vérifier

                          _______________

                          pour virer ce qui a été utilisé:

                          Télécharge ToolsCleaner sur ton bureau.
                          --> http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner

                          # Clique sur Recherche et laisse le scan agir ...
                          # Clique sur Suppression pour finaliser.
                          # Tu peux, si tu le souhaites, te servir des Options facultatives.
                          # Clique sur Quitter pour obtenir le rapport.
                          # Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

                          ________________

                          rq:
                          pour protéger gratos ton ordi

                          http://www.commentcamarche.net/telecharger/logiciel 4 securite

                          vacciner son ordi après avoir branché toutes ses clés usb avec usbfix ou flash disinfector ou rav antivirus car beaucoup actuellement transitent par les supports externes :
                          http://ww25.evosla.com/compteur.php?soft=rav_antivirus
                          http://www.techsupportforum.com/sectools/sUBs/Flash_Disinfector.exe
                          http://sd-1.archive-host.com/membres/up/127028005715545653/UsbFix.exe

                          ---------
                          mettre un antivirus

                          ANTIVIR ou AVG8 ou (AVAST )
                          https://www.malekal.com/avira-free-security-antivirus-gratuit/ (merci Malekal)
                          https://www.avira.com/fr/free-antivirus-windows
                          -------------
                          des anti-espions :
                          MalwareByte's Anti-Malware + SPYBOT +/- si tea timer non active de spybot:
                          WINDOWS DEFENDER ou SPYWARE TERMINATOR ou SPYWARE GUARD
                          +
                          SPYWAREBLASTER pour immuniser le système contre vundo notamment mais en anglais (mais facile d'utilisation : il suffit de faire "update" pour mettre à jour tous les mois et ensuite" enable all protection" pour immuniser)...

                          Rq : spybot … sortent de nouvelles versions régulièrement, vérifiez que vous avez la dernière version
                          --------
                          un pare feu :
                          celui de (Windows) ou mieux Online armor ou KERIO ou JETICO ou ZONE ALARM (mettre que le parefeu gratuit) ou COMODO

                          http://www.commentcamarche.net/telecharger/telecharger 34055356 online armor personal firewall
                          https://www.01net.com/telecharger/windows/Securite/firewall/fiches/39911.html
                          https://forum.pcastuces.com/sujet.asp?f=25&s=35606
                          https://www.clubic.com/telecharger-fiche11071-sunbelt-personal-firewall-ex-kerio.html
                          https://manuelsdaide.com/contact/
                          http://www.open-files.com/forum/index.php?showtopic=29277
                          https://www.01net.com/telecharger/windows/Securite/firewall/fiches/18128.html
                          https://www.zonealarm.com/software/free-firewall

                          -----------
                          CCLEANER pour effacer les traces de surf
                          ---------
                          naviguer avec firefox ou safari ou opera et non internet explorer plus touché par les virus
                          http://www.mozilla-europe.org/fr
                          0
                          1. Rapport RsIt

                            Logfile of random's system information tool 1.06 (written by random/random)
                            Run by LYLY at 2009-07-20 22:44:30
                            Microsoft Windows XP Professionnel Service Pack 2
                            System drive C: has 6 GB (32%) free of 20 GB
                            Total RAM: 2046 MB (79% free)

                            Logfile of Trend Micro HijackThis v2.0.2
                            Scan saved at 22:44:33, on 20/07/2009
                            Platform: Windows XP SP2 (WinNT 5.01.2600)
                            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                            Boot mode: Normal

                            Running processes:
                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\Program Files\Avira\AntiVir Desktop\sched.exe
                            C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
                            C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                            C:\WINDOWS\ATKKBService.exe
                            C:\WINDOWS\Explorer.EXE
                            C:\Program Files\Java\jre6\bin\jqs.exe
                            C:\WINDOWS\System32\nvsvc32.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\system32\devldr32.exe
                            C:\Program Files\Mozilla Firefox\firefox.exe
                            C:\WINDOWS\system32\wuauclt.exe
                            C:\Documents and Settings\LYLY\Bureau\RSIT.exe
                            C:\Program Files\Trend Micro\HijackThis\LYLY.exe

                            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                            O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Wireless Service - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
                            O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                            O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                            O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
                            O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                            O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                            0
                            1. Contributeur sécurité
                              ok c'est bon!
                              0