Vista antispyware 2010 pb

Bonjour,

J'ai été infecté par 1 virus : mon pare feu vista a été desactivé sans moyen de le réactiver car il me demande une clé d'activation que je dois payer (dont je n'ai jamis eu besoin depuis que j'utilise mon ordi). Je n'ai plus accès à Internet. Il me faut une solution svp ! j'ai vu que Lyonnais 92 avait aidé une personne dans mon cas alors si vous pouvait m'éclairer se serait super, je ne m'y connais pas beaucoup mais j'ai deja fait l' analyse avec ZHPDiag ! Merci d'avance
Configuration: Windows Vista / Internet Explorer 7.0

67 réponses

Résumé de la discussion

Une infection informatique désactive le pare-feu de Windows Vista et empêche l’accès à Internet, avec une demande de paiement pour une clé d’activation et une absence de connaissances techniques apparentes. Des éléments de réponse essentiels mentionnent l’utilisation d’outils de diagnostic comme ZHPDiag et OTL, la collecte et le partage des rapports texte suite à un scan et à une étape de suppression. D’autres échanges évoquent le recours à des modes spécifiques des outils (par exemple le mode suppression) et l’envoi des liens ou des fichiers de rapports via des services externes pour obtenir de l’aide technique.

Bobot (l’IA à votre service)
  1. voila le lien du rapport : http://www.cijoint.fr/cjlink.php?file=cj201002/cijyQzM4JJ.txt
    je ne comprends absolument rien de ce que ca veut dire, si tu peux m'aider stp ! merci
    1
    1. salut poste le rapport zhp diag :

      Pour le transmettre clique sur ce lien :

      http://www.cijoint.fr/

      ▶ Clique sur Parcourir et cherche le fichier C:\Documents and settings\le_nom_de_ta_session\.ZHPDiag.txt

      ▶ Clique sur Ouvrir.

      ▶ Clique sur "Cliquez ici pour déposer le fichier".

      Un lien de cette forme :

      http://www.cijoint.fr/cjlink.php?file=cj2043805/cib7SU.txt

      est ajouté dans la page.

      ▶ Copie ce lien dans ta réponse.
      0
      1. heu bizarre ton rapport....

        Télécharge OTL de OLDTimer

        ▶ enregistre le sur ton Bureau.

        ▶ Double clic ( pour vista / 7 => clic droit "executer en tant qu'administrateur") sur OTL.exe pour le lancer.

        ▶ Coche les 2 cases Lop et Purity

        ▶ Coche la case devant scan all users

        ▶ règle-le sur "60 Days"

        ▶ dans la colonne de gauche , mets tout sur "all"

        ne modifie pas ceci :

        "files created whithin" et "files modified whithin"


        ▶Clic sur Run Scan.

        A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).

        Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\OTL.txt)

        ▶▶▶ NE LE POSTE PAS SUR LE FORUM

        Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/

        ▶ Clique sur Parcourir et cherche le fichier ci-dessus.

        ▶ Clique sur Ouvrir.

        ▶ Clique sur "Cliquez ici pour déposer le fichier".

        Un lien de cette forme :

        http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

        est ajouté dans la page.

        ▶ Copie ce lien dans ta réponse.

        ▶▶ Tu feras la meme chose avec le "Extra.txt".
        0
        1. mon ordi bug vraiment, c'est pourquoi je mets du temps à te répondre !
          0
          1. http://www.cijoint.fr/cjlink.php?file=cj201002/cij2RPWA5T.txt : OTL.txt

            et

            http://www.cijoint.fr/cjlink.php?file=cj201002/cij7g7ec0s.txt : Extra.txt
            0
            1. Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent(car il est detecté a tort comme infection)

              ▶ Télécharge List&Kill'em et enregistre le sur ton bureau

              ▶ Branche clés usb , disques durs externes , mp3 , mp4 , etc..

              double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

              coche la case "creer une icone sur le bureau"

              une fois terminée , clic sur "terminer" et le programme se lancera seul

              choisis la langue puis choisis l'option 1 = Mode Recherche

              ▶ laisse travailler l'outil

              à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

              un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , mais ne le supprime pas pour l instant, le scan n'est pas fini.

              ▶ Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"

              tu peux supprimer le rapport catchme.log de ton bureau maintenant.

              0
              1. Bonjour, j'ai fait ce que tu m'as dit, il y a un rapport qui est apparu à la fin du scan (List'em - Bloc notes) et dois-je le poster dans ma réponse ? Car il est long !
                0
                1. List'em by g3n-h@ckm@n 1.2.5.3

                  User : Secours (Utilisateurs)
                  Update on 19/02/2010 by g3n-h@ckm@n ::::: 13.15
                  Start at: 12:33:20 | 20/02/2010
                  Contact : https://forums.commentcamarche.net/forum/virus-securite-7

                  AMD Athlon(tm) 64 X2 Dual Core Processor 4400+
                  Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
                  Internet Explorer 7.0.6001.18000
                  Windows Firewall Status : Disabled
                  AV : avast! antivirus 4.8.1229 [VPS 081118-0] 4.8.1229 [ (!) Disabled | (!) Outdated ]
                  FW : Norton AntiVirus[ (!) Disabled ]15.5.0.23

                  C:\ -> Disque fixe local | 69,78 Go (16,57 Go free) [ACER] | NTFS
                  D:\ -> Disque fixe local | 69,51 Go (35,59 Go free) [DATA] | NTFS
                  E:\ -> Disque CD-ROM
                  F:\ -> Disque amovible
                  G:\ -> Disque amovible
                  H:\ -> Disque amovible
                  I:\ -> Disque amovible
                  J:\ -> Disque amovible | 3,77 Go (1,8 Go free) [IPOD (ANGY)] | FAT32
                  K:\ -> Disque amovible | 970,12 Mo (967,94 Mo free) [TAK-242_301] | FAT
                  L:\ -> Disque amovible | 3,76 Go (3,26 Go free) | FAT32

                  ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                  C:\Windows\System32\smss.exe
                  C:\Windows\system32\csrss.exe
                  C:\Windows\system32\wininit.exe
                  C:\Windows\system32\services.exe
                  C:\Windows\system32\lsass.exe
                  C:\Windows\system32\lsm.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\system32\Ati2evxx.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\SLsvc.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
                  C:\Windows\System32\spoolsv.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
                  C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
                  C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  C:\Program Files\Bonjour\mDNSResponder.exe
                  C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
                  C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
                  C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                  C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe
                  C:\Windows\system32\svchost.exe
                  C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                  C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\system32\SearchIndexer.exe
                  C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
                  C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                  C:\Windows\system32\WUDFHost.exe
                  C:\Program Files\iPod\bin\iPodService.exe
                  C:\Windows\servicing\TrustedInstaller.exe
                  C:\Windows\system32\csrss.exe
                  C:\Windows\system32\winlogon.exe
                  C:\Windows\system32\Ati2evxx.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\Explorer.EXE
                  C:\Program Files\Windows Defender\MSASCui.exe
                  C:\Windows\RtHDVCpl.exe
                  C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                  C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
                  C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                  C:\Program Files\iTunes\iTunesHelper.exe
                  C:\Program Files\Alwil Software\Avast5\AvastUI.exe
                  C:\Program Files\Java\jre6\bin\jusched.exe
                  C:\Program Files\Windows Sidebar\sidebar.exe
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  C:\Windows\system32\wuauclt.exe
                  C:\Program Files\Windows Live\Contacts\wlcomm.exe
                  C:\Program Files\Internet Explorer\IEUser.exe
                  C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
                  C:\Program Files\Windows Live\Toolbar\wltuser.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Windows\system32\Macromed\Flash\FlashUtil10d.exe
                  C:\Windows\system32\wbem\wmiprvse.exe
                  C:\Windows\system32\SearchProtocolHost.exe
                  C:\Windows\system32\SearchFilterHost.exe
                  C:\Program Files\List_Kill'em\List_Kill'em.scr
                  C:\Windows\system32\conime.exe
                  C:\Windows\system32\cmd.exe
                  C:\Windows\system32\wbem\wmiprvse.exe
                  C:\Users\Secours\AppData\Local\Temp\4605.tmp\pv.exe

                  ======================
                  Keys "Run"
                  ======================
                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  Sidebar REG_SZ C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                  WindowsWelcomeCenter REG_SZ rundll32.exe oobefldr.dll,ShowWelcomeCenter
                  msnmsgr REG_SZ "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                  swg REG_SZ "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  Windows Defender REG_EXPAND_SZ %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                  RtHDVCpl REG_SZ RtHDVCpl.exe
                  Acer Tour REG_SZ
                  eRecoveryService REG_SZ
                  Skytel REG_SZ Skytel.exe
                  Symantec PIF AlertEng REG_SZ "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                  ArcSoft Connection Service REG_SZ C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
                  Google Desktop Search REG_SZ "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                  iTunesHelper REG_SZ "C:\Program Files\iTunes\iTunesHelper.exe"
                  avast5 REG_SZ C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
                  SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre6\bin\jusched.exe"

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
                  InstallShieldSetup REG_SZ C:\PROGRA~1\INSTAL~1\{78143~1\Setup.exe -rebootC:\PROGRA~1\INSTAL~1\{78143~1\reboot.ini -l0x40c
                  C:\PROGRA~1\Canon\MDL30\CANONM~1.DLL REG_SZ C:\Windows\system32\regsvr32.exe /s "C:\PROGRA~1\Canon\MDL30\CANONM~1.DLL"
                  C:\PROGRA~1\Canon\ZOOMBR~2\STIREG~1.DLL REG_SZ C:\Windows\system32\regsvr32.exe /s "C:\PROGRA~1\Canon\ZOOMBR~2\STIREG~1.DLL"
                  C:\PROGRA~1\Canon\CAMERA~1\CAMERA~1\STIREG~1.DLL REG_SZ C:\Windows\system32\regsvr32.exe /s "C:\PROGRA~1\Canon\CAMERA~1\CAMERA~1\STIREG~1.DLL"

                  =====================
                  Other Keys
                  =====================
                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                  ConsentPromptBehaviorAdmin REG_DWORD 2 (0x2)
                  ConsentPromptBehaviorUser REG_DWORD 1 (0x1)
                  EnableInstallerDetection REG_DWORD 1 (0x1)
                  EnableLUA REG_DWORD 1 (0x1)
                  EnableSecureUIAPaths REG_DWORD 1 (0x1)
                  EnableVirtualization REG_DWORD 1 (0x1)
                  PromptOnSecureDesktop REG_DWORD 1 (0x1)
                  ValidateAdminCodeSignatures REG_DWORD 0 (0x0)
                  dontdisplaylastusername REG_DWORD 0 (0x0)
                  legalnoticecaption REG_SZ
                  legalnoticetext REG_SZ
                  scforceoption REG_DWORD 0 (0x0)
                  shutdownwithoutlogon REG_DWORD 1 (0x1)
                  undockwithoutlogon REG_DWORD 1 (0x1)
                  FilterAdministratorToken REG_DWORD 0 (0x0)
                  EnableUIADesktopToggle REG_DWORD 0 (0x0)

                  ===============
                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

                  ===============
                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

                  ===============
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                  AppInit_DLLS REG_SZ C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL

                  ===============
                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
                  ReportBootOk REG_SZ 1
                  Shell REG_SZ explorer.exe
                  Userinit REG_SZ C:\Windows\system32\userinit.exe,
                  VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
                  AutoRestartShell REG_DWORD 1 (0x1)
                  LegalNoticeCaption REG_SZ
                  LegalNoticeText REG_SZ
                  PowerdownAfterShutdown REG_SZ 0
                  ShutdownWithoutLogon REG_SZ 0
                  cachedlogonscount REG_SZ 10
                  forceunlocklogon REG_DWORD 0 (0x0)
                  passwordexpirywarning REG_DWORD 14 (0xe)
                  Background REG_SZ 0 0 0
                  DebugServerCommand REG_SZ no
                  WinStationsDisabled REG_SZ 0
                  DisableCAD REG_DWORD 1 (0x1)
                  scremoveoption REG_SZ 0
                  ShutdownFlags REG_DWORD 43 (0x2b)

                  ===============

                  ===============
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

                  ===============
                  [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                  C:\Acer\Empowering Technology\eDataSecurity\eDSfsu.exe REG_SZ C:\Acer\Empowering Technology\eDataSecurity\eDSfsu.exe:*:Enabled:eDSfsu
                  C:\Acer\Empowering Technology\eDataSecurity\encryption.exe REG_SZ C:\Acer\Empowering Technology\eDataSecurity\encryption.exe:*:Enabled:encryption
                  C:\Acer\Empowering Technology\eDataSecurity\decryption.exe REG_SZ C:\Acer\Empowering Technology\eDataSecurity\decryption.exe:*:Enabled:decryption

                  [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

                  ===============
                  ActivX controls
                  ===============
                  HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{233C1507-6A77-46A4-9443-F871F945D258}
                  HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{4F1E5B1A-2A80-42CA-8532-2D05CB959537}
                  HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}
                  HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
                  HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{C3F79A2B-B9B4-4A66-B012-3EE46475B072}
                  HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
                  HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
                  HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}

                  ===============
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{233C1507-6A77-46A4-9443-F871F945D258}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2A202491-F00D-11cf-87CC-0020AFEECF20}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7C028AF8-F614-47B3-82DA-BA94E41B1089}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11CF-96B8-444553540000}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}

                  ==============
                  BHO :
                  ======
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8}]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]

                  ================
                  Internet Explorer :
                  ================
                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                  Start Page REG_SZ https://fr.yahoo.com/

                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                  Start Page REG_SZ https://www.google.com/?gws_rd=ssl

                  ========
                  Services
                  ========
                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

                  Ndisuio : 0x3 ( OK = 3 )
                  EapHost : 0x3 ( OK = 2 )
                  Wlansvc : 0x3 ( OK = 2 )
                  SharedAccess : 0x4 ( OK = 2 )
                  windefend : 0x2 ( OK = 2 )
                  wuauserv : 0x2 ( OK = 2 )
                  wscsvc : 0x2 ( OK = 2 )

                  =========
                  Atapi.sys
                  =========

                  %%%% HASHDEEP-1.0
                  %%%% size,md5,sha256,filename
                  ## Invoked from: C:\Users\Secours\AppData\Local\Temp\4605.tmp
                  ## C:\> hashdeep C:\Windows\System32\Drivers\atapi.sys
                  ##
                  21560,2d9c903dc76a66813d350a562de40ed9,82609f01a08c6842e4c17c077bb641c1429c0e6657964b7f2d114035e1bdcbf3,C:\Windows\System32\Drivers\atapi.sys

                  Sources
                  =======

                  C:\Windows\SoftwareDistribution\Download\cd2b15b1a90e884578188440a1660b12\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
                  C:\Windows\System32\drivers\atapi.sys
                  C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
                  C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
                  C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
                  C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
                  C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys
                  C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys

                  Référence :
                  ==========

                  Win XP_32b : a64013e98426e1877cb653685c5c0009
                  Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
                  Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
                  Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
                  Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
                  Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
                  Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
                  Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
                  Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C

                  K:\Autorun.inf :
                  ----------------
                  [autorun]
                  shellexecute=Wscript.exe winrun.vbs
                  =======
                  Drive :
                  =======

                  D‚fragmenteur de disque Windows
                  Copyright (c) 2006 Microsoft Corp.

                  Rapport d'analyse pour le volume C: ACER

                  Taille du volume = 69.78 Go
                  Espace libre = 16.58 Go
                  tendue d'espace libre la plus grande = 6.82 Go
                  Pourcentage de fragmentation des fichiers = 1 %

                  Remarqueÿ: sur les volumes NTFS, les fragments de fichiers de plus de 64ÿMo ne sont pas inclus dans les statistiques de fragmentation.

                  Il n'est pas n‚cessaire de d‚fragmenter ce volume.

                  ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                  Present !! : C:\Windows\Temp\Setup.exe

                  ¤¤¤¤¤¤¤¤¤¤ Keys :

                  ============

                  catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                  Rootkit scan 2010-02-20 12:43:39
                  Windows 6.0.6001 Service Pack 1 NTFS

                  scanning hidden processes ...

                  scanning hidden services & system hive ...

                  scanning hidden registry entries ...

                  scanning hidden files ...

                  scan completed successfully
                  hidden processes: 0
                  hidden services: 0
                  hidden files: 0

                  Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

                  device: opened successfully
                  user: MBR read successfully
                  called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll prosync1.sys ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
                  kernel: MBR read successfully
                  user & kernel MBR OK

                  ==========
                  Programs
                  ==========

                  ABBYY FineReader 6.0 Sprint
                  Acer Arcade Live
                  Acer Inc
                  Adobe
                  ALCATEL PC Suite
                  Alwil Software
                  Apple Software Update
                  ATI
                  ATI Technologies
                  Bonjour
                  Canon
                  Chat Republic Games
                  Cisco Systems
                  Codemasters
                  Common Files
                  CyberLink
                  desktop.ini
                  DivX
                  epson
                  Epson Software
                  eSobi
                  Fichiers communs
                  GameSpy Arcade
                  Google
                  InstallShield Installation Information
                  Internet Explorer
                  iPod
                  iTunes
                  Java
                  JRE
                  LG Electronics
                  LG PC Suite II
                  List_Kill'em
                  Microsoft
                  Microsoft Games
                  Microsoft Office
                  Microsoft Office Outlook Connector
                  Microsoft Silverlight
                  Microsoft SQL Server Compact Edition
                  Microsoft Sync Framework
                  Microsoft Visual Studio
                  Microsoft Works
                  Microsoft.NET
                  Movie Maker
                  MSBuild
                  MSECache
                  MSXML 4.0
                  Neuf
                  NewTech Infosystems
                  Norton Security Scan
                  NortonInstaller
                  OpenOffice.org 3
                  PokerStars
                  QuickTime
                  Realtek
                  Reference Assemblies
                  Samsung
                  Uninstall Information
                  VideoLAN
                  Webcam 1200
                  Windows Calendar
                  Windows Collaboration
                  Windows Defender
                  Windows Journal
                  Windows Live
                  Windows Live SkyDrive
                  Windows Mail
                  Windows Media Player
                  Windows NT
                  Windows Photo Gallery
                  Windows Sidebar
                  Yahoo!
                  ZHPDiag

                  ============
                  Drive C:
                  ============

                  $RECYCLE.BIN
                  -20070506.log
                  Acer
                  AcerSW
                  autoexec.bat
                  Book
                  Boot
                  bootmgr
                  BOOTSECT.BAK
                  config.sys
                  conmgr.log
                  Documents and Settings
                  DRV
                  found.000
                  hiberfil.sys
                  HiTRUSTDrive
                  INSTALL.LOG
                  Kill'em
                  List'em.txt
                  MDR.iss
                  MSOCache
                  PA207.DAT
                  pagefile.sys
                  PerfLogs
                  Program Files
                  ProgramData
                  RHDSetup.log
                  setup.log
                  Sounds
                  System Volume Information
                  UNWISE.EXE
                  Users
                  Windows
                  YServer.txt

                  ¤¤¤¤¤¤¤¤¤¤ Cracks | Keygens | Serials

                  C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\Install.exe

                  ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

                  End of scan : 12:53:42,66
                  0
                  1. ▶ Relance List&Kill'em(soit en clic droit pour vista),avec le raccourci sur ton bureau.
                    mais cette fois-ci :

                    ▶ choisis l'option 2 = Mode Suppression

                    laisse travailler l'outil.

                    en fin de scan un rapport s'ouvre

                    ▶ colle le contenu dans ta reponse
                    0
                    1. Le scan est en train de se faire (85%) mais j'ai juste d'autres questions à te poser sur ce problème :

                      - le virus a infecté mes 2 comptes d'utilisateurs et j'en ai donc ouvert un troisième pour continuer à avoir accès à internet et c'est celle là que j'utilise actuellement, ce que je suis en train de faire sous tes conseils va-t-il également marcher pour les deux autres comptes d'utilisateurs ?

                      - le virus a également infecté mon ordi portable, est ce que je peux refaire que ce que tu m'avais dit pour le "réparer" aussi ? et d'où vient ce virus vu qu'il a infecté mes deux ordis : ma connexion internet ou alors peut-être un site de streaming ?

                      désolée je te demande beaucoup de chose mais je n'y comprends rien. merci pour tout
                      0
                      1. Kill'em by g3n-h@ckm@n 1.2.5.3

                        User : Secours (Utilisateurs)
                        Update on 19/02/2010 by g3n-h@ckm@n ::::: 13.15
                        Start at: 13:09:00 | 20/02/2010
                        Contact : https://forums.commentcamarche.net/forum/virus-securite-7

                        AMD Athlon(tm) 64 X2 Dual Core Processor 4400+
                        Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
                        Internet Explorer 7.0.6001.18000
                        Windows Firewall Status : Disabled
                        AV : avast! antivirus 4.8.1229 [VPS 081118-0] 4.8.1229 [ (!) Disabled | (!) Outdated ]
                        FW : Norton AntiVirus[ (!) Disabled ]15.5.0.23

                        C:\ -> Disque fixe local | 69,78 Go (16,82 Go free) [ACER] | NTFS
                        D:\ -> Disque fixe local | 69,51 Go (35,59 Go free) [DATA] | NTFS
                        E:\ -> Disque CD-ROM
                        F:\ -> Disque amovible
                        G:\ -> Disque amovible
                        H:\ -> Disque amovible
                        I:\ -> Disque amovible
                        J:\ -> Disque amovible | 3,77 Go (1,8 Go free) [IPOD (ANGY)] | FAT32
                        K:\ -> Disque amovible | 970,12 Mo (967,94 Mo free) [TAK-242_301] | FAT
                        L:\ -> Disque amovible | 3,76 Go (3,26 Go free) | FAT32

                        ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                        C:\Windows\System32\smss.exe
                        C:\Windows\system32\csrss.exe
                        C:\Windows\system32\wininit.exe
                        C:\Windows\system32\services.exe
                        C:\Windows\system32\lsass.exe
                        C:\Windows\system32\lsm.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\system32\Ati2evxx.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\SLsvc.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
                        C:\Windows\System32\spoolsv.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\taskeng.exe
                        C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
                        C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
                        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                        C:\Program Files\Bonjour\mDNSResponder.exe
                        C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
                        C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
                        C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                        C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe
                        C:\Windows\system32\svchost.exe
                        C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                        C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\system32\SearchIndexer.exe
                        C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
                        C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                        C:\Windows\system32\WUDFHost.exe
                        C:\Program Files\iPod\bin\iPodService.exe
                        C:\Windows\servicing\TrustedInstaller.exe
                        C:\Windows\system32\csrss.exe
                        C:\Windows\system32\winlogon.exe
                        C:\Windows\system32\Ati2evxx.exe
                        C:\Windows\system32\taskeng.exe
                        C:\Windows\system32\Dwm.exe
                        C:\Program Files\Windows Defender\MSASCui.exe
                        C:\Windows\RtHDVCpl.exe
                        C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                        C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
                        C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                        C:\Program Files\iTunes\iTunesHelper.exe
                        C:\Program Files\Alwil Software\Avast5\AvastUI.exe
                        C:\Program Files\Java\jre6\bin\jusched.exe
                        C:\Program Files\Windows Sidebar\sidebar.exe
                        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                        C:\Windows\system32\wuauclt.exe
                        C:\Program Files\Internet Explorer\IEUser.exe
                        C:\Program Files\Windows Live\Toolbar\wltuser.exe
                        C:\Windows\system32\Macromed\Flash\FlashUtil10d.exe
                        C:\Windows\system32\conime.exe
                        C:\Windows\explorer.exe
                        C:\Program Files\List_Kill'em\List_Kill'em.scr
                        C:\Windows\system32\cmd.exe
                        C:\Windows\system32\SearchProtocolHost.exe
                        C:\Windows\system32\SearchFilterHost.exe
                        C:\Windows\system32\wbem\wmiprvse.exe
                        C:\Users\Secours\AppData\Local\Temp\B57.tmp\ERUNT.EXE
                        C:\Users\Secours\AppData\Local\Temp\B57.tmp\pv.exe

                        Detections :
                        ==========

                        ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                        Quarantined & Deleted !! : C:\Windows\Temp\Setup.exe

                        ==============
                        host file OK !
                        ==============

                        ========
                        Registry
                        ========

                        ========
                        Services
                        =========

                        Ndisuio : Start = 3
                        EapHost : Start = 2
                        Wlansvc : Start = 2
                        SharedAccess : Start = 2
                        windefend : Start = 2
                        wuauserv : Start = 2
                        wscsvc : Start = 2

                        ============
                        Disk Cleaned
                        ============

                        =================
                        anti-ver blaster : OK !!
                        =================

                        ================
                        Prefetch cleaned
                        ================

                        ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

                        voila le rapport
                        0
                        1. relance List_Kill'em , option desinstaller

                          ensuite :

                          Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

                          ▶ Télécharge :

                          Malwarebytes

                          ou :

                          Malwarebytes

                          ▶ Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

                          (NB : Si tu as un message d'erreur t'indiquant qu'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX

                          ▶ Potasses le Tuto pour te familiariser avec le prg :

                          ( cela dit, il est très simple d'utilisation ).

                          relance malwarebytes en suivant scrupuleusement ces consignes :

                          ! Déconnecte toi et ferme toutes applications en cours !

                          ▶ Lance Malwarebyte's .

                          Fais un examen dit "Complet" .

                          ▶ Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
                          ▶ à la fin tu cliques sur "résultat" .
                          ▶ Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

                          ▶ Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

                          ▶ Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)

                          0
                          1. Malwarebytes' Anti-Malware 1.44
                            Version de la base de données: 3766
                            Windows 6.0.6001 Service Pack 1
                            Internet Explorer 7.0.6001.18000

                            20/02/2010 15:21:33
                            mbam-log-2010-02-20 (15-21-33).txt

                            Type de recherche: Examen complet (C:\|D:\|E:\|F:\|G:\|H:\|I:\|J:\|K:\|L:\|)
                            Eléments examinés: 318104
                            Temps écoulé: 1 hour(s), 12 minute(s), 17 second(s)

                            Processus mémoire infecté(s): 0
                            Module(s) mémoire infecté(s): 0
                            Clé(s) du Registre infectée(s): 0
                            Valeur(s) du Registre infectée(s): 0
                            Elément(s) de données du Registre infecté(s): 0
                            Dossier(s) infecté(s): 0
                            Fichier(s) infecté(s): 4

                            Processus mémoire infecté(s):
                            (Aucun élément nuisible détecté)

                            Module(s) mémoire infecté(s):
                            (Aucun élément nuisible détecté)

                            Clé(s) du Registre infectée(s):
                            (Aucun élément nuisible détecté)

                            Valeur(s) du Registre infectée(s):
                            (Aucun élément nuisible détecté)

                            Elément(s) de données du Registre infecté(s):
                            (Aucun élément nuisible détecté)

                            Dossier(s) infecté(s):
                            (Aucun élément nuisible détecté)

                            Fichier(s) infecté(s):
                            C:\Users\Angy\AppData\Local\av.exe (Rogue.MultipleAV) -> Quarantined and deleted successfully.
                            C:\Users\habibou\AppData\Local\av.exe (Rogue.MultipleAV) -> Quarantined and deleted successfully.
                            C:\Users\Angy\Local Settings\Application Data\av.exe (ROGUE.Win7Antispyware2010) -> Quarantined and deleted successfully.
                            C:\Users\habibou\Local Settings\Application Data\av.exe (ROGUE.Win7Antispyware2010) -> Quarantined and deleted successfully.
                            0
                            1. vide la quarantaine de malwarebytes , et refais OTL stp
                              0
                              1. http://www.cijoint.fr/cjlink.php?file=cj201002/cijWCtG4o4.txt
                                0
                                1. http://www.cijoint.fr/cjlink.php?file=cj201002/cijq5PzxLf.txt
                                  0
                                  1. tu as encore des soucis qui persistent ?
                                    0
                                    1. Sur ce compte d'utilisateur que j'ai utilisé pour faire ces manips, tout va bien le pare feu s'est réactivé mais sur mes deux autres comptes d'utilisateur, ça cloche : j'ai voulu vérifer l'état de sécurité de l'ordi dans " Panneau de configuration" pour voir si le pare feu était activé et ça me demande quel programme je veux pour l'ouvrir et c'est pareil quand je veux aller sur internet explorer !!! c'est bizarre ca me le faisait pas auparavant !!
                                      0
                                      1. ▶ Télécharge Superantispyware (SAS)

                                        ▶ Choisis "enregistrer" et enregistre-le sur ton bureau.

                                        ▶ Double-clique sur l'icône d'installation qui vient de se créer et suis les instructions.

                                        ▶ Créé une icône sur le bureau.

                                        ▶ Double-clique sur l'icône de SAS (une tête dans un cercle rouge barré) pour le lancer.

                                        ▶- Si l'outil te demande de mettre à jour le programme ("update the program definitions", clique sur yes.
                                        ▶- Sous Configuration and Preferences, clique sur le bouton "Preferences"
                                        ▶- Clique sur l'onglet "Scanning Control "
                                        ▶- Dans "Scanner Options ", assure toi que la case devant lles lignes suivantes est cochée :

                                        ▶Close browsers before scanning
                                        ▶Scan for tracking cookies
                                        ▶Terminate memory threats before quarantining

                                        ▶ Laisse les autres lignes décochées.

                                        ▶ Clique sur le bouton "Close" pour quitter l'écran du centre de contrôle.

                                        ▶ Dans la fenêtre principale, clique, dans "Scan for Harmful Software", sur "Scan your computer".

                                        ▶ Dans la colonne de gauche, coche C:\Fixed Drive.

                                        ▶ Dans la colonne de droite, sous "Complete scan", clique sur "Perform Complete Scan"

                                        ▶ Clique sur "next" pour lancer le scan. Patiente pendant la durée du scan.

                                        ▶ A la fin du scan, une fenêtre de résultats s'ouvre . Clique sur OK.

                                        ▶ Assure toi que toutes les lignes de la fenêtre blanche sont cochées et clique sur "Next".

                                        ▶ Tout ce qui a été trouvé sera mis en quarantaine. S'il t'es demandé de redémarrer l'ordi ("reboot"), clique sur Yes.

                                        Pour recopier les informations sur le forum, fais ceci :

                                        ▶ - après le redémarrage de l'ordi, double-clique sur l'icône pour lancer SAS.
                                        ▶ - Clique sur "Preferences" puis sur l'onglet "Statistics/Logs ".
                                        ▶- Dans "scanners logs", double-clique sur SUPERAntiSpyware Scan Log.

                                        ▶ - Le rapport va s'ouvrir dans ton éditeur de texte par défaut.

                                        ▶ - Copie son contenu dans ta réponse.

                                        Regarde bien le tuto SUPERAntiSpyware il est très bien expliqué.
                                        0
                                        • 1
                                        • 2
                                        • 3
                                        • 4