Pc infecté

Résolu
Bonjour,
j'ai fait un scan avec panda et cde dernier me ressort 3 virus et 98 vulnerabikités; que je n'ai pu desinfecter ; c'est payant ;et en tant quétydiant , grrr pas de tune.
merci de m'aider joint log hajickLogfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:19:41, on 22/09/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\PC Tools Firewall Plus\FWService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Mobile Connect\HUAWEIDataCard.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=10168&gct=&gc=1&q=
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=10168&gct=&gc=1&q=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.bing.com/spresults.aspx
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://toolbar.ask.com/toolbarv/askRedirect?o=10168&gct=&gc=1&q=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [00PCTFW] "C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s
O8 - Extra context menu item: Télécharger avec IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: Télécharger le contenu de video FLV avec IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Télécharger tous les liens avec IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {6e32070a-766d-4ee6-879c-dc1fa91d2fc3} (MUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://fichiers.touslesdrivers.com/maconfig/MaConfig_3_5_2_1.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D3D63528-CF8C-4001-93FB-A8818A2F034A}: NameServer = 192.168.50.58 196.12.230.202
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - PC Tools - C:\Program Files\PC Tools Firewall Plus\FWService.exe

--
End of file - 4804 bytes
Configuration: Windows XP
Firefox 3.5.3

15 réponses

  1. Modérateur
    Salut,

    Télécharge ToolBar S&D ( de Eric_71 )
    = = = = >>> En cliquant ici <<< = = = =

    /!\ Déconnectes toi et fermes toute tes applications en cours le temps de la manipulation /!\
    * Double-cliques sur l’exécutable pour lancer l’outil
    * Une fois fait, tape F pour sélectionner le Français
    * Choisis l’option 1 (Recherche) et tape sur Entrée.
    * Une fois le scan finit, un rapport va apparaître au format .txt.
    * Copie-colle l’intégralité de son contenu dans ta prochaine réponse ...
    Note :
    Le rapport est sauvegardé ici : C:\TB.txt
    Tuto si besoin ICI
    1
    1. -----------\\ ToolBar S&D 1.2.9 XP/Vista

      Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
      X86-based PC ( Uniprocessor Free : Intel(R) Pentium(R) 4 CPU 2.40GHz )
      BIOS : 686O2 v3.18
      USER : ADMIN ( Administrator )
      BOOT : Normal boot
      Antivirus : AntiVir Desktop 9.0.1.32 (Activated)
      Firewall : PC Tools Firewall Plus 4.0.0 (Not Activated)
      A:\ (USB)
      C:\ (Local Disk) - FAT32 - Total:37 Go (Free:25 Go)
      D:\ (CD or DVD)

      "C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
      Option : [1] ( 22/09/2009|19:45 )

      -----------\\ Recherche de Fichiers / Dossiers ...

      -----------\\ Extensions

      (ADMIN) - {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} => adblockplus

      -----------\\ [..\Internet Explorer\Main]

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
      "Start Page"="https://www.google.fr/?gws_rd=ssl"
      "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
      "Search Bar"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
      "Default_Search_URL"="http://toolbar.ask.com/toolbarv/askRedirect?o=10168&gct=&gc=1&q="
      "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home"

      --------------------\\ Recherche d'autres infections

      Aucune autre infection trouvée !

      1 - "C:\ToolBar SD\TB_1.txt" - 22/09/2009|19:45 - Option : [1]

      -----------\\ Fin du rapport a 19:45:55,51
      0
  2. Modérateur
    Etrange qu'il n'ait rien détecté.

    On va tenter une autre méthode :

    Télécharge Malwarebytes’ Anti-Malware
    = = = = >>> En cliquant ici <<< = = = =

    - Enregistre le sur le bureau
    - Double clique sur le fichier téléchargé pour lancer le processus d’installation
    - Lorsqu’il te le sera demandé, mets à jour Malwarebytes anti malware
    - Si le pare-feu demande l’autorisation de se connecter pour malwarebytes, acceptes
    - Une fois la mise à jour terminée, ferme Malwarebytes
    - Double-clique sur l’icône de malwarebytes pour le relancer
    - Dans l’onglet, Recherche, probablement ouvert par défaut,
    - Sélectionne Exécuter un examen complet
    - Clique sur Rechercher
    - Le scan démarre
    - A la fin de l’analyse, un message s’affiche : L’examen s’est terminé normalement. Cliquez sur ‘Afficher les résultats’ pour afficher tous les objets trouvés.
    - Clique sur Ok pour poursuivre.
    - Si des malwares ont été détectés, cliques sur Afficher les résultats
    - Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
    - Malwarebytes va ouvrir le bloc-notes et y copier le rapport d’analyse.
    - Rends toi dans l’onglet rapport/log
    - Tu clique dessus pour l’afficher.
    - Une fois affiché, cliques sur édition en haut du bloc notes, et puis sur sélectionner tout
    - Tu recliques sur édition et puis sur copier et tu reviens sur le forum et dans ta réponse
    - Tu clique droit dans le cadre de la réponse et coller

    Si tu as besoin d’aide regarde ce tutorial ICI
    0
    1. au faite avant de scané par hijack j'ai fait scan malwarbites et avira free; rien trouvé???????

      JE DOUTE QUE PANDA RACONTE DES HISTOIRE . MAIS TJRS PROBLEME OUVERTURES FENETRES,,
      0
  3. Modérateur
    Qu'appelles-tu OUVERTURES FENETRES,,
    Poste moi le rapport de MBAM que tu avais lancé stp.
    Avais-tu mis MBAM à jour ?
    0
    1. le probelm c que : exemple je suis sue CCM et tout a coup la page disparais et moteur bing s'affiche et dés fois c'est la page :impossible ouvrir verifiez conection ou parametre réseau ect; alors que je suis conecté
      pour rapport mbam je l'ai pas gardé ,au faite toolbar ne ma pas donné rapport a la fin du scan je l'ai eu sur c: tb:txt
      0
      1. j'ai trouver le rapport /log mbam mais kan je klic pour ouvrir et le coller ici, rien ne se passe :s'ouvre pas et je l'ai pas trouver sur c:log txt
        0
        1. Modérateur
          On va procéder autrement :

          Pour une analyse plus en profondeur de ton PC :
          Télécharge Random’s System Information Tool (RSIT) de random/random et enregistre l’exécutable sur le Bureau.
          = = = = >>> En cliquant ici <<< = = = =

          * Double clique sur RSIT.exe pour le lancer.
          * Une première fenêtre s’ouvre, clique alors sur Continue (Disclaimer).
          * Si la dernière version de HijackThis n’est pas détectée sur ton PC, RSIT le téléchargera et te demandera d’accepter la licence.
          * Lorsque l’analyse sera terminée, deux fichiers texte s’ouvriront (probablement avec le bloc-notes).
          0
          1. j'ai telecharger rsit.exe et quand je clik sur continuer ,ptite fenetre s'ouvre disant hijack driver ect ;comme c en anglais je pige pas, et charge puis se ferme !!!et rien ne se passe????
            0
        2. Logfile of random's system information tool 1.06 (written by random/random)
          Run by ADMIN at 2009-09-22 22:00:53
          Microsoft Windows XP Professionnel Service Pack 2
          System drive C: has 26 GB (69%) free of 38 GB
          Total RAM: 247 MB (26% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 22:00:55, on 22/09/2009
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Avira\AntiVir Desktop\sched.exe
          C:\Program Files\Avira\AntiVir Desktop\avguard.exe
          C:\Program Files\Java\jre6\bin\jqs.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
          C:\Program Files\PC Tools Firewall Plus\FWService.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
          C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
          C:\WINDOWS\system32\wscntfy.exe
          C:\WINDOWS\system32\wbem\wmiapsrv.exe
          C:\Program Files\Mobile Connect\HUAWEIDataCard.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\Internet Download Manager\IEMonitor.exe
          C:\WINDOWS\system32\drwtsn32.exe
          C:\WINDOWS\system32\drwtsn32.exe
          C:\WINDOWS\explorer.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\Documents and Settings\ADMIN\Bureau\RSIT.exe
          C:\Program Files\trend micro\ADMIN.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=10168&gct=&gc=1&q=
          R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=10168&gct=&gc=1&q=
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.bing.com/spresults.aspx
          R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://toolbar.ask.com/toolbarv/askRedirect?o=10168&gct=&gc=1&q=%s
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
          R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll (file missing)
          O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
          O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
          O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
          O4 - HKLM\..\Run: [00PCTFW] "C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s
          O8 - Extra context menu item: Télécharger avec IDM - C:\Program Files\Internet Download Manager\IEExt.htm
          O8 - Extra context menu item: Télécharger le contenu de video FLV avec IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
          O8 - Extra context menu item: Télécharger tous les liens avec IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
          O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
          O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
          O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
          O16 - DPF: {6e32070a-766d-4ee6-879c-dc1fa91d2fc3} (MUWebControl Class) - http://update.microsoft.com/...
          O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://fichiers.touslesdrivers.com/maconfig/MaConfig_3_5_2_1.cab
          O17 - HKLM\System\CCS\Services\Tcpip\..\{D3D63528-CF8C-4001-93FB-A8818A2F034A}: NameServer = 192.168.50.58 196.12.230.202
          O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
          O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
          O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
          O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - PC Tools - C:\Program Files\PC Tools Firewall Plus\FWService.exe
          0
          1. Modérateur
            Quel est ton disque E ? Lecteur CD ?

            *********

            /!\ Procédure réservée à khaldcasa. Ne tentez pas de la reproduire si vous avez un problème similaire sous peine de planter votre machine /!\
            Télécharge OTM (de Old_Timer) sur ton Bureau.
            = = = = >>> En cliquant ici <<< = = = =
            Une fois installé sur le bureau, double-clique sur OTMoveIt.exe pour le lancer.
            Assure toi que la case Unregister Dll’s and Ocx’s soit bien cochée
            Copie la liste qui se trouve en gras ci-dessous, et colle-la dans le cadre de gauche de OTMoveIt :
            Paste Instructions for Items to be moved.

            Procedure is

            :Files
            C:\Program Files\AskSearch
            C:\WINDOWS\IE4 Error Log.txt

            :reg
            [HKLM\Software\Microsoft\Internet Explorer\Main]
            Default_Search_URL="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
            [HKEY_CLASSES_ROOT\CLSID]
            C94E154B-1459-4A47-966B-4B843BEFC7DB=-
            [HKEY LOCAL MACHINE\SOFTWARE\Classes\CLSID]
            C94E154B-1459-4A47-966B-4B843BEFC7DB=-

            :Commands
            [purity]
            [emptytemp]
            [Reboot]


            Clique sur MoveIt! pour lancer la suppression.
            Après avoir fait Moveit!, une fenêtre s’affiche :
            "The system requires a reboot to finish removing files. Do you want to reboot now ?"
            Réponds Yes.
            Le résultat apparaîtra dans le cadre "Results".
            Clique sur Exit pour fermer.
            Poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

            *******

            Analyse ce fichier :
            C:\WINDOWS\PEV.exe

            Sur le site de virustotal :
            https://www.virustotal.com/gui/

            Parcourir > Sélectionne ton fichier > Analyser, patiente que l’analyse soit terminée.

            Poste bien le rapport.

            (Si VirusTotal indique que le fichier a déjà été analysé, clique sur le bouton Ré-analyse le fichier maintenant).

            Crapoulou.
            0
            1. J4AI PAS E j'ai c=dd et d = cd dvd
              dois je telecherger OTM ???
              0
          2. Modérateur
            Oui, tu as OTM à télécharger et suivre la procédure (me donner un rapport à la fin) et analyser le fichier en ligne et me poster le rapport.
            Cela fait 2 rapports à me poster.
            0
            1. bonjour
              voila 1er rapport pour fichier windons pev.ese le second suivra
              Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español | English
              Virus Total
              Virustotal est un service qui analyse les fichiers suspects et facilite la détection rapide des virus, vers, chevaux de Troie et toutes sortes de malwares détectés par les moteurs antivirus. Plus d'informations...
              Fichier PEV.exe reçu le 2009.09.18 18:47:17 (UTC)
              Situation actuelle: terminé
              Résultat: 4/41 (9.76%)
              Formaté Formaté
              Impression des résultats Impression des résultats
              Antivirus Version Dernière mise à jour Résultat
              a-squared 4.5.0.24 2009.09.18 -
              AhnLab-V3 5.0.0.2 2009.09.18 -
              AntiVir 7.9.1.19 2009.09.18 -
              Antiy-AVL 2.0.3.7 2009.09.18 -
              Authentium 5.1.2.4 2009.09.18 -
              Avast 4.8.1351.0 2009.09.18 -
              AVG 8.5.0.412 2009.09.18 -
              BitDefender 7.2 2009.09.18 -
              CAT-QuickHeal 10.00 2009.09.18 (Suspicious) - DNAScan
              ClamAV 0.94.1 2009.09.18 -
              Comodo 2359 2009.09.18 -
              DrWeb 5.0.0.12182 2009.09.18 -
              eSafe 7.0.17.0 2009.09.17 Suspicious File
              eTrust-Vet 31.6.6745 2009.09.18 -
              F-Prot 4.5.1.85 2009.09.18 -
              F-Secure 8.0.14470.0 2009.09.18 -
              Fortinet 3.120.0.0 2009.09.18 PossibleThreat
              GData 19 2009.09.18 -
              Ikarus T3.1.1.72.0 2009.09.18 -
              Jiangmin 11.0.800 2009.09.18 -
              K7AntiVirus 7.10.848 2009.09.18 -
              Kaspersky 7.0.0.125 2009.09.18 -
              McAfee 5745 2009.09.18 -
              McAfee+Artemis 5745 2009.09.18 -
              McAfee-GW-Edition 6.8.5 2009.09.18 -
              Microsoft 1.5005 2009.09.18 -
              NOD32 4438 2009.09.18 -
              Norman 6.01.09 2009.09.18 -
              nProtect 2009.1.8.0 2009.09.18 -
              Panda 10.0.2.2 2009.09.18 -
              PCTools 4.4.2.0 2009.09.18 -
              Prevx 3.0 2009.09.18 Medium Risk Malware
              Rising 21.47.42.00 2009.09.18 -
              Sophos 4.45.0 2009.09.18 -
              Sunbelt 3.2.1858.2 2009.09.18 -
              Symantec 1.4.4.12 2009.09.18 -
              TheHacker 6.5.0.2.011 2009.09.18 -
              TrendMicro 8.950.0.1094 2009.09.18 -
              VBA32 3.12.10.10 2009.09.18 -
              ViRobot 2009.9.18.1943 2009.09.18 -
              VirusBuster 4.6.5.0 2009.09.18 -
              Information additionnelle
              File size: 229376 bytes
              MD5 : 91354a529c35836de367b36bf9d17362
              SHA1 : b3e87fab255b837cd1271041fd92f3cf7d5bf467
              SHA256: 552e1d6141e575f798c5cc5f1eaa484401c9d3b337c6d088394a93b12b5ccc06
              PEInfo: PE Structure information

              ( base data )
              entrypointaddress.: 0x1000
              timedatestamp.....: 0x4A8FE2B7 (Sat Aug 22 14:21:11 2009)
              machinetype.......: 0x14C (Intel I386)

              ( 3 sections )
              name viradd virsiz rawdsiz ntrpy md5
              .text 0x1000 0xB9000 0x36800 8.00 a8a5f1105dfaf83a8c976bb2ac7f1830
              .rsrc 0xBA000 0x2000 0x1200 7.29 15d12a274a884826802b1f201d9eaed0
              .reloc 0xBC000 0x200 0x200 0.22 b12d439e1c3e13121f2118218c5151ca

              ( 1 imports )

              > kernel32.dll: LoadLibraryA, GetProcAddress, VirtualAlloc, VirtualFree

              ( 0 exports )
              TrID : File type identification
              Win32 EXE PECompact compressed (v2.x) (48.9%)
              Win32 EXE PECompact compressed (generic) (34.4%)
              Win32 Executable Generic (7.0%)
              Win32 Dynamic Link Library (generic) (6.2%)
              Generic Win/DOS Executable (1.6%)
              ThreatExpert: https://www.symantec.com?md5=91354a529c35836de367b36bf9d17362
              ssdeep: 6144:s34fSYdtUkXwb8Siuth5JzeeOX6A6MQ5wznaVN:so685XMHze9qFMFO
              Prevx Info: http://info.prevx.com/aboutprogramtext.asp?PX5=E2596559006750EF80B703A84C45CD00627AE039
              PEiD : PECompact 2.xx --> BitSum Technologies
              packers (Kaspersky): PE_Patch.PECompact, PecBundle, PECompact
              packers (F-Prot): PecBundle, PECompact
              RDS : NSRL Reference Data Set
              -

              ATENTION ATTENTION: VirusTotal est un service gratuit offert par Hispasec Sistemas. Il n'y a aucune garantie quant à la disponibilité et la continuité de ce service. Bien que le taux de détection permis par l'utilisation de multiples moteurs antivirus soit bien supérieur à celui offert par seulement un produit, ces résultats NE garantissent PAS qu'un fichier est sans danger. Il n'y a actuellement aucune solution qui offre un taux d'efficacité de 100% pour la détection des virus et malwares.

              Autre fichier
              VirusTotal © Hispasec Sistemas - Blog - Contact: info@virustotal.com - Terms of Service & Privacy Policy
              0
            2. voila 2em j'espere avoir bien fait
              merci de ton aide

              All processes killed
              ========== FILES ==========
              File/Folder C:\Program Files\AskSearch not found.
              C:\WINDOWS\IE4 Error Log.txt moved successfully.
              ========== REGISTRY ==========
              HKLM\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar|iesearch" /E : value set successfully!
              Registry value HKEY_CLASSES_ROOT\CLSID\\C94E154B-1459-4A47-966B-4B843BEFC7DB not found.
              Registry value HKEY LOCAL MACHINE\SOFTWARE\Classes\CLSID\\C94E154B-1459-4A47-966B-4B843BEFC7DB not found.
              ========== COMMANDS ==========

              [EMPTYTEMP]

              User: Default User
              ->Temp folder emptied: 0 bytes
              ->Temporary Internet Files folder emptied: 0 bytes

              User: All Users

              User: NetworkService
              ->Temp folder emptied: 0 bytes
              ->Temporary Internet Files folder emptied: 0 bytes

              User: LocalService
              ->Temp folder emptied: 0 bytes
              ->Temporary Internet Files folder emptied: 33170 bytes

              User: ADMIN
              ->Temp folder emptied: 109040676 bytes
              ->Temporary Internet Files folder emptied: 1221489 bytes
              ->Java cache emptied: 0 bytes
              ->FireFox cache emptied: 72574951 bytes
              ->Google Chrome cache emptied: 9006056 bytes

              User: Administrateur
              ->Temp folder emptied: 0 bytes
              ->Temporary Internet Files folder emptied: 33170 bytes

              %systemdrive% .tmp files removed: 0 bytes
              C:\WINDOWS\msdownld.tmp folder deleted successfully.
              %systemroot% .tmp files removed: 2114937 bytes
              %systemroot%\System32 .tmp files removed: 0 bytes
              Windows Temp folder emptied: 32768 bytes
              RecycleBin emptied: 0 bytes

              Total Files Cleaned = 185,07 mb

              OTM by OldTimer - Version 3.0.0.6 log created on 09232009_150242

              Files moved on Reboot...

              Registry entries deleted on Reboot...
              0
          3. Modérateur
            Comment semble aller le PC ?
            Poste un nouveau rapport RSIT.
            0
            1. bonsoir;il y a bcp d'ameliorations quand a l'ouverture fenetres ;merci encore pour ton aide
              joint les 2 logs.
              Logfile of random's system information tool 1.06 (written by random/random)
              Run by ADMIN at 2009-09-23 23:50:41
              Microsoft Windows XP Professionnel Service Pack 2
              System drive C: has 26 GB (69%) free of 38 GB
              Total RAM: 247 MB (26% free)

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 23:50:43, on 23/09/2009
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\WINDOWS\Explorer.EXE
              C:\Program Files\Avira\AntiVir Desktop\sched.exe
              C:\Program Files\Avira\AntiVir Desktop\avguard.exe
              C:\Program Files\Java\jre6\bin\jqs.exe
              C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
              C:\Program Files\PC Tools Firewall Plus\FWService.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
              C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
              C:\Documents and Settings\ADMIN\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
              C:\WINDOWS\system32\wscntfy.exe
              C:\WINDOWS\system32\wbem\wmiapsrv.exe
              C:\Program Files\Mobile Connect\HUAWEIDataCard.exe
              C:\Program Files\Mozilla Firefox\firefox.exe
              C:\Program Files\Internet Download Manager\IDMan.exe
              C:\Program Files\Internet Download Manager\IEMonitor.exe
              C:\Documents and Settings\ADMIN\Bureau\RSIT.exe
              C:\Program Files\trend micro\ADMIN.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=10168&gct=&gc=1&q=
              R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=10168&gct=&gc=1&q=
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.bing.com/spresults.aspx
              R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://toolbar.ask.com/toolbarv/askRedirect?o=10168&gct=&gc=1&q=%s
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
              R3 - URLSearchHook: (no name) - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - (no file)
              O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
              O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
              O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
              O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
              O4 - HKLM\..\Run: [00PCTFW] "C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s
              O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\ADMIN\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
              O8 - Extra context menu item: Télécharger avec IDM - C:\Program Files\Internet Download Manager\IEExt.htm
              O8 - Extra context menu item: Télécharger le contenu de video FLV avec IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
              O8 - Extra context menu item: Télécharger tous les liens avec IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
              O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
              O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
              O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
              O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
              O16 - DPF: {6e32070a-766d-4ee6-879c-dc1fa91d2fc3} (MUWebControl Class) - http://update.microsoft.com/...
              O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://fichiers.touslesdrivers.com/maconfig/MaConfig_3_5_2_1.cab
              O17 - HKLM\System\CCS\Services\Tcpip\..\{D3D63528-CF8C-4001-93FB-A8818A2F034A}: NameServer = 192.168.50.58 196.12.230.202
              O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
              O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
              O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
              O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - PC Tools - C:\Program Files\PC Tools Firewall Plus\FWService.exe
              0
              1. Modérateur
                Relance Hijackthis.
                Clique sur "Do a system scan only".
                Coche ces lignes :
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=10168&gct=&gc=1&q=
                R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=10168&gct=&gc=1&q=
                R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://toolbar.ask.com/toolbarv/askRedirect?o=10168&gct=&gc=1&q=%s
                R3 - URLSearchHook: (no name) - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - (no file)

                Clique ensuite sur fix checked.
                Ferme Hijackthis.

                ********

                Mets à jour Internet Explorer en téléchargeant la version 8 (même si tu ne l’utilises pas, sinon c’est une faille de sécurité de ne pas le tenir à jour…)
                = = = =>>> En cliquant ici <<<= = = =

                ********

                Pour supprimer toutes les traces des logiciels qui ont servi à traiter les infections spécifiques :

                Télécharge Toolscleaner sur ton Bureau
                = = = =>>> En cliquant ici <<<= = = =
                * Double-clique sur ToolsCleaner2.exe et laisse le travailler
                * Clique sur Recherche et laisse le scan se terminer.
                * Clique sur Suppression pour finaliser.
                * Tu peux, si tu le souhaites, te servir des Options facultatives.
                * Clique sur Quitter, pour que le rapport puisse se créer.
                * Le rapport (TCleaner.txt) se trouve à la racine de votre disque dur (C:\)...colle le dans ta réponse.

                *********

                Tu peux garder Malwarebytes anti malware en tant qu’anti malware, il est très efficace. (Même s’il ne résout pas tous les problèmes, bien entendu … !)
                Par contre, il n’a pas de scan résident en mode gratuit ! Il faut donc pour l’utiliser le lancer, faire les mises à jour et faire un scan complet après.

                *******

                Mets à jour XP en installant le SP3 :
                http://www.microsoft.com/downloads/details.aspx?familyid=2FCDE6CE-B5FB-4488-8C50-FE22559D164E&displaylang=fr

                ********

                Je vois que tu disposes de Ccleaner.
                Utilise le en suivant cette procédure :

                - Exécute le.
                * Choisis l’onglet Nettoyeur

                Quitte ton navigateur Internet avant de le lancer, décoche la dernière case (Avancé si elle est cochée) puis clique sur "lancer le nettoyage" quand il aura terminé le scan cliques en bas à droite sur "lancer le nettoyage" et accepte par oui.
                Attention, il risque de vider ta corbeille : si tu veux récupérer des fichiers effacés par erreur, mieux vaut le faire maintenant.

                * Choisis l’onglet Registre

                - Clique sur Chercher des erreurs
                - Une fois la recherche terminée, clic sur Réparer les erreurs sélectionnées (par défaut, tout est sélectionné, laisse comme ça)
                - Au message Voulez-vous sauvegarder les changements faits dans le registre, réponds Oui et enregistre le fichier au format « .reg » en le nommant par la date par exemple en le mettant sur le bureau. Puis continue.
                - A la fenêtre qui s’ouvre ensuite, clique sur Corriger toutes les erreurs sélectionnées puis OK
                - Recommence jusqu’à ce qu’aucune erreur n’apparaisse (ou une seule récurrente).
                - Ferme Ccleaner.

                * Tutoriel en images ICI si besoin.

                Note : La sauvegarde utilisée permet de remettre tel que la base était avant la manipulation au cas où il y aurait des soucis mais cela ne m’est jamais arrivé ! Il vaut mieux prendre des précautions, c’est tout. ;-)

                Crapoulou.
                0
                1. j'ai refait analyse hijack Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 18:46:40, on 25/09/2009
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Avira\AntiVir Desktop\sched.exe
                  C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                  C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                  C:\Program Files\PC Tools Firewall Plus\FWService.exe
                  C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                  C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\wscntfy.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  C:\Program Files\Internet Download Manager\IEMonitor.exe
                  C:\Program Files\Internet Mobile\Internet Mobile.exe
                  C:\WINDOWS\explorer.exe
                  C:\Program Files\Windows NT\Accessoires\WORDPAD.EXE
                  C:\Program Files\trend micro\ADMIN.exe
                  C:\Program Files\trend micro\ADMIN.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                  O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
                  O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                  O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                  O4 - HKLM\..\Run: [00PCTFW] "C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s
                  O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_803138DCE93649E4.dll/cmsidewiki.html
                  O8 - Extra context menu item: Télécharger avec IDM - C:\Program Files\Internet Download Manager\IEExt.htm
                  O8 - Extra context menu item: Télécharger le contenu de video FLV avec IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
                  O8 - Extra context menu item: Télécharger tous les liens avec IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
                  O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                  O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                  O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
                  O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
                  O16 - DPF: {6e32070a-766d-4ee6-879c-dc1fa91d2fc3} (MUWebControl Class) - http://update.microsoft.com/...
                  O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://fichiers.touslesdrivers.com/maconfig/MaConfig_3_5_2_1.cab
                  O17 - HKLM\System\CCS\Services\Tcpip\..\{D3D63528-CF8C-4001-93FB-A8818A2F034A}: NameServer = 212.217.0.1 212.217.0.12
                  O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                  O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                  O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - PC Tools - C:\Program Files\PC Tools Firewall Plus\FWService.exe
                  0
              2. bonsoir
                j'ai suivi té conseil sauf que je n'ai pu telecharger sp3 et pour hijack j'ai fixer r0 mais les r1 n'existent pas ou deja supprimée , tool cleaner aussi c fait [ Rapport ToolsCleaner version 2.3.10 (par A.Rothstein & dj QUIOU) ]

                --> Recherche:

                ---------------------------------
                --> Suppression:

                Corbeille vidée!
                Fichiers te

                mporaires nettoyés !

                merci encore pc va bcp mieux
                doit je faire autyre manip.
                0
                1. Modérateur
                  Supprime tous les outils que je t'ai fait utilisés avec Toolscleaner (sauf Ccleaner et Malwarebytes' Anti Malware)..

                  S'il ne le fait pas, fais le manuellement.

                  Tu peux supprimer Hijackthis, c'est tout OK.
                  Et ce dossier :
                  C:\Program files\Trend micro.
                  0
                  1. ok cher pote ;merci bcp a +
                    0
                2. Modérateur
                  Tu peux passer le statut de la discussion sur Résolu.
                  Bonne continuation.
                  Crapoulou.
                  0