Antivirus soft est il un virus???

Résolu
Bonjour,

J'utilise le Mac de mon fils pour vous contacter au sujet d'un problème apparu sur mon PC depuis quelques minutes: un message d'alerte de "antivirus soft" s'affiche, lance un scan et détecte des trojans, malwares et autres choses de ce genre. J' ai esasyé de tout stopper et de lancer mon antivirus Antivir, mais il se bloque. Pouvez vous m'aider?
D'avance, je vous remercie pour votre aide
Bien cordialement
Helene
Configuration: PC Windows

23 réponses

Résumé de la discussion

Une alerte antivirus affichant 'antivirus soft' apparaît sur un PC Windows, lance un scan et signale des trojans et malwares, ce qui bloque l'antivirus et complique le nettoyage. Plusieurs réponses suggèrent d'attaquer en mode sans échec, d'exécuter des outils comme Malwarebytes, Ad-Remover ou List & Kill'em, puis de supprimer les fichiers infectés et de nettoyer le registre. Des guides proposent aussi de restaurer le MBR et de surveiller le démarrage, avec des scans répétés en mode sûr, et de copier les rapports pour poursuivre l’analyse. Des complications majeures sont évoquées lorsque l’alerte signale Malwarebytes comme infecté, bloquant son lancement et poussant à envisager des mesures hors du système pour vérifier l’authenticité des outils.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    bonjour

    regarde ceci

    http://www.commentcamarche.net/faq/26898-supprimer-antivirus-soft
    0
    1. Bonjour Benuur,

      Merci pour ta réponse, je suis perdue...j'ai regardé le lien que tu m'envoies, concrêtement, je dois faire quoi?? Pour l'instant, j'ai coupé ma connexion, dois je l remettre?
      Merci
      A tout de suite
      0
  2. Contributeur sécurité
    si ta toujours ta connexion

    télécharge

    http://www.malwarebytes.org/mbam/program/mbam-setup.exe

    a l'installation vérifie que mise a jour et lancer programme et scan complet sont bien cocher

    Une fois a jour, le programme va se lancer; clic sur l´onglet paramètre, et coche la case : "Arrêter internet explorer pendant la suppression".

    A la fin du scan clique sur Afficher les résultats

    Vérifier si tout est coché et clic Supprimer la sélection

    S'il t'es demandé de redémarrer >>> clique sur "Yes"

    Et tu poste le rapport générer
    0
    1. j'ai téléchargé malware, impossible de l'ouvrir, une alarte me dit qu'il est infecté
      0
  3. Contributeur sécurité
    une alerte de qui ?

    normalement le lien est sur peut-être faux positive ignore l'alerte

    chez moi aucune alerte pourtant sécurité je suis au taquet
    0
    1. je veux bien l'ignorer mais malwareb ne s'ouvre pas
      L'alerte dit:
      "Security warning Application cannot be executed. The file mbam exe is infected. Do you want to active your antivirus software now?"
      Et c'est ce soit disant anti virus qui est le virus!!!!
      Que faire alors?
      0
  4. Contributeur sécurité
    démarre le en mode sans échec

    Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter.
    0
    1. Voilà, j'ai lancé le mode sans échec et malware qui est en train de scanner, il a déjà trouvé un problème
      Dites moi s'il vous plait ce que je devrai faire quand le scan sera terminé
      Merci d'avance
      0
  5. Contributeur sécurité
    A la fin du scan clique sur Afficher les résultats

    Vérifier si tout est coché et clic Supprimer la sélection

    S'il t'es demandé de redémarrer >>> clique sur "Yes"
    0
    1. ok, et ensuite je redémarre en mode normal?
      0
  6. Contributeur sécurité
    oui
    0
    1. Malwarebytes' Anti-Malware 1.44
      Version de la base de données: 3510
      Windows 5.1.2600 Service Pack 3 (Safe Mode)
      Internet Explorer 6.0.2900.5512

      02/26/2010 18:54:11
      mbam-log-2010-02-26 (18-54-05).txt

      Type de recherche: Examen complet (C:\|)
      Eléments examinés: 227331
      Temps écoulé: 1 hour(s), 16 minute(s), 11 second(s)

      Processus mémoire infecté(s): 0
      Module(s) mémoire infecté(s): 0
      Clé(s) du Registre infectée(s): 0
      Valeur(s) du Registre infectée(s): 0
      Elément(s) de données du Registre infecté(s): 0
      Dossier(s) infecté(s): 0
      Fichier(s) infecté(s): 1

      Processus mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Module(s) mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Clé(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Valeur(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Elément(s) de données du Registre infecté(s):
      (Aucun élément nuisible détecté)

      Dossier(s) infecté(s):
      (Aucun élément nuisible détecté)

      Fichier(s) infecté(s):
      C:\327882R2FWJFW\Combo-Fix.sys (Malware.Trace) -> No action taken.

      j'ai supprimé le fichier infecté, mais j'ai toujours la même alerte de Windows Security alert

      Et maintenant, que dois-je faire?
      D'avance merci
      0
  7. Contributeur sécurité
    Télécharge UsbFix de C_XX & Chiquitine29

    http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe

    (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

    • Double clic sur "UsbFix.exe" présent sur ton bureau ( clic droit "exécuter en tant qu'administrateur" pour Vista & 7 )

    • Choisis l'option F pour français et tape sur [entrée] .

    Choisis l'option 1 ( Recherche ) et tape sur [entrée] .

    • Laisse travailler l'outil.

    • Ensuite poste le rapport UsbFix.txt qui apparaitra.

    • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

    ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

    • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
    Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
    Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
    0
    1. j'ai téléchargé usbfix, mais comme précédemment, je ne peux pas l'ouvrir, toujours ce Security Warning!
      0
    2. Voici le rapport, j'ai fait le scan en mode sans échec
      Qu'en pensez-vous??

      User : Hélène (Utilisateurs) # BUREAU
      Update on 20/02/2010 by El Desaparecido , C_XX & Chimay8
      Start at: 19:40:22 | 02/26/2010
      Website : http://pagesperso-orange.fr/NosTools/index.html
      Contact : FindyKill.Contact@gmail.com

      Intel(R) Pentium(R) 4 CPU 2.80GHz
      Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
      Internet Explorer 6.0.2900.5512
      Windows Firewall Status : Disabled
      AV : AntiVir Desktop 9.0.1.32 [ Enabled | (!) Outdated ]
      FW : Sunbelt Personal Firewall[ Enabled ]4.6.1861 T

      C:\ -> Disque fixe local # 149,01 Go (82,97 Go free) # NTFS
      D:\ -> Disque amovible
      E:\ -> Disque amovible
      F:\ -> Disque CD-ROM

      ############################## | Processus actifs |

      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\savedump.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\wbem\wmiprvse.exe

      ################## | Elements infectieux |

      ################## | Registre |

      [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"
      [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"

      ################## | Mountpoints2 |

      ################## | Vaccin |

      (!) Cet ordinateur n'est pas vacciné !

      ################## | ! Fin du rapport # UsbFix V6.097 ! |
      0
    3. ça, c'est un rapport hijac fait au tout début et que je e parvenais pas à ouvrir en mode normal, là en mode sans échec avec la connexion, j'arrive

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 17:20:10, on 02/26/2010
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Avira\AntiVir Desktop\sched.exe
      C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
      C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\MsPMSPSv.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
      C:\ATI-CPanel\atiptaxx.exe
      C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\Program Files\Skype\Phone\Skype.exe
      C:\Documents and Settings\Hélène\Local Settings\Application Data\dtgeqs\ukfhsftav.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\WINDOWS\system32\wscntfy.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.news/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
      O2 - BHO: DealioBHO Class - {6A87B991-A31F-4130-AE72-6D0C294BF082} - C:\Program Files\Dealio\kb127\Dealio.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
      O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
      O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O3 - Toolbar: Dealio - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - C:\Program Files\Dealio\kb127\Dealio.dll
      O4 - HKLM\..\Run: [ATIPTA] C:\ATI-CPanel\atiptaxx.exe
      O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
      O4 - HKLM\..\Run: [au] C:\Program Files\Dealio\DealioAU.exe
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [eggqoudn] C:\Documents and Settings\Hélène\Local Settings\Application Data\dtgeqs\ukfhsftav.exe
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
      O4 - HKCU\..\Run: [eggqoudn] C:\Documents and Settings\Hélène\Local Settings\Application Data\dtgeqs\ukfhsftav.exe
      O4 - Startup: stardock objectdock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
      O4 - Startup: TransBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe
      O8 - Extra context menu item: &Download with TrueDownloader! - C:\Program Files\TrueDownloader\TrueDownloader.htm
      O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
      O8 - Extra context menu item: Compare Prices with &Dealio - C:\Documents and Settings\Hélène\Application Data\Dealio\kb127\res\DealioSearch.html
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
      O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb127\Dealio.dll
      O9 - Extra 'Tools' menuitem: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb127\Dealio.dll
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
      O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
      O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Google Desktop Manager 5.8.811.4345 (GoogleDesktopManager-110408-113106) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      O23 - Service: Google Update Service (gupdate1c985864032915c) (gupdate1c985864032915c) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
      O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
      O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
      O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
      0
  8. fais le en mode sans échec

    tu a essaye de renommer usbfix ?
    0
    1. Voilà le rapport, le scan a été fait en mode sans échec

      User : Hélène (Utilisateurs) # BUREAU
      Update on 20/02/2010 by El Desaparecido , C_XX & Chimay8
      Start at: 19:40:22 | 02/26/2010
      Website : http://pagesperso-orange.fr/NosTools/index.html
      Contact : FindyKill.Contact@gmail.com

      Intel(R) Pentium(R) 4 CPU 2.80GHz
      Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
      Internet Explorer 6.0.2900.5512
      Windows Firewall Status : Disabled
      AV : AntiVir Desktop 9.0.1.32 [ Enabled | (!) Outdated ]
      FW : Sunbelt Personal Firewall[ Enabled ]4.6.1861 T

      C:\ -> Disque fixe local # 149,01 Go (82,97 Go free) # NTFS
      D:\ -> Disque amovible
      E:\ -> Disque amovible
      F:\ -> Disque CD-ROM

      ############################## | Processus actifs |

      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\savedump.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\wbem\wmiprvse.exe

      ################## | Elements infectieux |

      ################## | Registre |

      [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"
      [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"

      ################## | Mountpoints2 |

      ################## | Vaccin |

      (!) Cet ordinateur n'est pas vacciné !

      ################## | ! Fin du rapport # UsbFix V6.097 ! |
      0
  9. tu na pas de clé usb de portable ou autre a branché ?
    0
    1. Contributeur sécurité
      Suppression

      Branche tes sources de données externes à ton PC, (clé USB, disque dur externe......) susceptibles d'avoir été infectés sans les ouvrir

      (1) Double clic sur le raccourci UsbFix présent sur ton bureau

      (2) Choisi l option 2 ( Suppression )

      Ton bureau disparaitra et le pc redémarrera .

      Au redémarrage , UsbFix scannera ton pc , laisse travailler l outil.

      Ensuite poste le rapport UsbFix.txt qui apparaitra avec le bureau .

      Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

      ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
      0
      1. En attendant ta réponse, j'ai mis à jour malware, je n'arrivai pas en mode normal, j'ai refait un scan et voici ce qu'il a trouvé...
        On avance non??
        je fais maintenant ce que tu me dis pour usbfix

        Malwarebytes' Anti-Malware 1.44
        Version de la base de données: 3796
        Windows 5.1.2600 Service Pack 3 (Safe Mode)
        Internet Explorer 6.0.2900.5512

        02/26/2010 20:12:20
        mbam-log-2010-02-26 (20-12-20).txt

        Type de recherche: Examen rapide
        Eléments examinés: 144214
        Temps écoulé: 6 minute(s), 5 second(s)

        Processus mémoire infecté(s): 0
        Module(s) mémoire infecté(s): 0
        Clé(s) du Registre infectée(s): 2
        Valeur(s) du Registre infectée(s): 2
        Elément(s) de données du Registre infecté(s): 0
        Dossier(s) infecté(s): 0
        Fichier(s) infecté(s): 2

        Processus mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Module(s) mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Clé(s) du Registre infectée(s):
        HKEY_LOCAL_MACHINE\SOFTWARE\avsoft (Trojan.Fraudpack) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\Software\avsoft (Trojan.Fraudpack) -> Quarantined and deleted successfully.

        Valeur(s) du Registre infectée(s):
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\eggqoudn (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\eggqoudn (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.

        Elément(s) de données du Registre infecté(s):
        (Aucun élément nuisible détecté)

        Dossier(s) infecté(s):
        (Aucun élément nuisible détecté)

        Fichier(s) infecté(s):
        C:\Documents and Settings\Hélène\Local Settings\temp\VbMV.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Hélène\Local Settings\Temporary Internet Files\Content.IE5\74QEA867\eH4b9b1f77V0100f036002R2397d2b8102T001ca1fbQ000002fc901801F002d000aJ0f000601l000cK6d544b653180[1] (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        0
    2. Contributeur sécurité
      oui ouisa avance
      0
      1. super, ça remarche, je suis en mode normal et plus rien!!!
        merci mille fois, à toi et à tous ceux qui sont intervenus sur mon problème
        Je suis vraiment contente
        Merci à toute l'équipe de Comment ça marche, vous êtes tous dévoués, patients et pédagogues, sans oublier experts
        A bientôt
        Bises à tous
        helene

        Par contre, je ne vois plus mon antivirus???? ou dois-je le chercher??

        PS enfin j'espère être débarassée de ce virus!

        ############################# | UsbFix V6.097 |

        User : Hélène (Utilisateurs) # BUREAU
        Update on 20/02/2010 by El Desaparecido , C_XX & Chimay8
        Start at: 20:21:27 | 02/26/2010
        Website : http://pagesperso-orange.fr/NosTools/index.html
        Contact : FindyKill.Contact@gmail.com

        Intel(R) Pentium(R) 4 CPU 2.80GHz
        Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
        Internet Explorer 6.0.2900.5512
        Windows Firewall Status : Disabled
        AV : AntiVir Desktop 9.0.1.32 [ Enabled | (!) Outdated ]
        FW : Sunbelt Personal Firewall[ Enabled ]4.6.1861 T

        C:\ -> Disque fixe local # 149,01 Go (82,81 Go free) # NTFS
        D:\ -> Disque amovible
        E:\ -> Disque amovible
        F:\ -> Disque CD-ROM

        ############################## | Processus actifs |

        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\csrss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\savedump.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
        C:\WINDOWS\system32\logonui.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Avira\AntiVir Desktop\sched.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Avira\AntiVir Desktop\avguard.exe
        C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\Program Files\Google\Update\GoogleUpdate.exe
        C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        C:\Program Files\Java\jre6\bin\jqs.exe
        C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
        C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\MsPMSPSv.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\WINDOWS\System32\alg.exe
        C:\WINDOWS\system32\wbem\wmiprvse.exe
        C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
        C:\WINDOWS\system32\wscntfy.exe

        ################## | Elements infectieux |

        Supprimé ! C:\Recycler\S-1-5-21-1454471165-688789844-839522115-1005
        Supprimé ! C:\Recycler\S-1-5-21-1454471165-688789844-839522115-1006

        ################## | Registre |

        Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"
        Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"

        ################## | Mountpoints2 |

        ################## | Listing des fichiers présent |

        [01/31/2008 04:25|--a------|3328] C:\bitdefenden1201749835_1_02.xml
        [02/20/2006 11:21|-rahs----|216] C:\boot.ini
        [04/24/2003 13:00|-rahs----|4952] C:\Bootfont.bin
        [04/07/2005 13:34|--a------|0] C:\CONFIG.SYS
        [04/07/2005 13:58|--a------|39] C:\CTJINI.INI
        [02/03/2009 09:53|--a------|399] C:\DealioAu.log
        [06/23/2005 21:29|--a------|199] C:\hellbot.exe
        [02/24/2010 22:56|--a------|523] C:\hpfr3420.xml
        [02/24/2010 22:56|--a------|125502] C:\hpfr3425.log
        [10/08/2006 11:53|--ah-----|1594] C:\hpothb07.dat
        [10/08/2006 11:53|--ah-----|2985] C:\hpothb07.tif
        [10/14/2005 23:31|--a------|46] C:\hWaitEventRetryInstall
        [04/07/2005 13:34|-rahs----|0] C:\IO.SYS
        [04/07/2005 13:34|-rahs----|0] C:\MSDOS.SYS
        [09/20/2006 19:35|--a------|4158709] C:\myskin.pcb
        [02/20/2006 11:13|-rahs----|47564] C:\NTDETECT.COM
        [09/01/2008 11:46|-rahs----|252240] C:\ntldr
        [?|?|?] C:\pagefile.sys
        [04/07/2005 13:58|--a------|593] C:\pnpID.dat
        [03/08/2008 10:16|--a------|97680236] C:\Sauv.reg
        [01/10/2008 12:40|--a------|45] C:\TEST.XML
        [02/06/2006 00:19|--a------|1010] C:\tmpFile.dat
        [02/26/2010 20:27|--a------|3749] C:\UsbFix.txt

        ################## | Vaccination |

        # C:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).

        ################## | Upload |

        Veuillez envoyer le fichier : C:\UsbFix_Upload_Me_BUREAU.zip : https://www.ionos.fr/?affiliate_id=77097
        Merci pour votre contribution .
        0
    3. Contributeur sécurité
      encore quelque reste pour verifier

      pour l'antivirus t'inquiète la il tourne après un redémarrage ou un scan l'icône reapparaitra

      Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
      http://pagesperso-orange.fr/NosTools/C_XX/AD-R.exe
      * Lance l'installation du programme en exécutant le fichier téléchargé.( clic droit "exécuter en tant qu'administrateur" pour Vista/7 )
      * Double-clique ( clic droit "exécuter en tant qu'administrateur" pour Vista/7 ) maintenant sur le raccourci de Toolbar-S&D.
      * Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
      * Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
      * Poste le rapport généré. (C:\TB.txt)
      0
      1. on ne se quitte pas encore alors...
        c'est ad remover le truc que je dois lancer?
        0
    4. Contributeur sécurité
      oui
      0
      1. Voilà.
        ======= RAPPORT D'AD-REMOVER 1.1.4.6_J | UNIQUEMENT XP/VISTA/7 =======
        .
        Mis à jour par C_XX le 05.02.2010 à 17:34
        Contact: AdRemover.contact@gmail.com
        Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
        .
        Lancé à: 20:43:05, 02/26/2010 | Mode Normal | Option: SCAN
        Exécuté de: C:\Ad-Remover\
        Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
        Nom du PC: BUREAU | Utilisateur actuel: H‚lŠne
        .
        ============== ÉLÉMENT(S) TROUVÉ(S) ==============
        .

        C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\Dealio
        C:\Program Files\Dealio
        C:\Program Files\Search Settings
        C:\DOCUME~1\HLNE~1\APPLIC~1\Dealio
        C:\DOCUME~1\HLNE~1\APPLIC~1\Search Settings
        C:\Windows\Installer\424a7b.msi
        C:\Windows\Installer\424a82.msi
        C:\Documents and Settings\Serge\Application Data\Dealio
        C:\Documents and Settings\Serge\Application Data\EoRezo
        C:\Documents and Settings\Geoffroy\Application Data\EoRezo
        C:\Documents and Settings\Camille\Application Data\EoRezo
        C:\Documents and Settings\Camille\Camille.BUREAU\Application Data\EoRezo
        C:\Documents and Settings\Serge\Application Data\Search Settings
        .
        HKCU\software\Dealio
        HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F}
        HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F}
        HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
        HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F}
        HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F}
        HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
        HKCU\software\Search Settings
        HKLM\Software\Classes\CLSID\{6A87B991-A31F-4130-AE72-6D0C294BF082}
        HKLM\Software\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
        HKLM\Software\Classes\Interface\{D5A1EF9A-7948-435D-8B87-D6A598317288}
        HKLM\software\classes\SearchSettings.BHO
        HKLM\software\classes\SearchSettings.BHO.1
        HKLM\Software\Classes\TypeLib\{CD082CCA-086F-4FD8-8FD7-247A0DBBD1CC}
        HKLM\software\Dealio
        HKLM\Software\Microsoft\Internet Explorer\Extensions\{E908B145-C847-4e85-B315-07E2E70DECF8}
        HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F}
        HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F}
        HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6A87B991-A31F-4130-AE72-6D0C294BF082}
        HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\0292226F570267D459357AF78015E534
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\03285961954D5824C85975D955031EE8
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\6AC3985F4D64C2245A96D31569D1BF40
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\855847FA0E25FBA46B8516389DFDD4B3
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\9DC2844D0E3E8924C8973C3B3BAE1F58
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\AFEB575AA30ACB243B748619F62F0782
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\F461B8DD96FF5AA41A52D14E1D7B69C7
        HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\au
        HKLM\software\Search Settings
        HKU\s-1-5-21-1454471165-688789844-839522115-1005\software\Dealio
        HKU\s-1-5-21-1454471165-688789844-839522115-1005\software\Search Settings
        .
        ============== Scan additionnel ==============
        .
        .
        * Mozilla FireFox Version 3.6 [fr] *
        .
        Nom du profil: npj0mbfw.default (H‚lŠne)
        .
        (HLNE~1, prefs.js) Browser.download.lastDir, C:\Documents and Settings\Hélène\Mes documents
        (HLNE~1, prefs.js) Browser.search.defaultenginename, Google
        (HLNE~1, prefs.js) Browser.search.defaulturl, hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
        (HLNE~1, prefs.js) Browser.search.selectedEngine, Google
        (HLNE~1, prefs.js) Browser.startup.homepage, hxxp://news.google.fr
        (HLNE~1, prefs.js) Extensions.enabledItems, en-GB@dictionaries.addons.mozilla.org:1.19,{3112ca9c-de6d-4884-a869-9855de68056c}:6.1.20091119W,{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03,{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05,{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}:6.0.04,{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07,{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11,{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13,{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15,jqs@sun.com:1.0,{20a82645-c095-46ed-80e3-08825760534b}:1.1,{635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.2.20080910,{ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6
        .
        .
        * Internet Explorer Version 6.0.2900.5512 *
        .
        [HKEY_CURRENT_USER\..\Internet Explorer\Main]
        .
        Do404Search: 01000000
        Show_ToolBar: yes
        Start Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
        Search Page: hxxp://www.google.com
        Enable Browser Extensions: yes
        Local Page: C:\WINDOWS\system32\blank.htm
        Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
        Use Custom Search URL: 1 (0x1)
        Use Search Asst: no
        Search Bar: hxxp://www.google.com/ie
        First Home Page: hxxp://www.microsoft.com/isapi/redir.dll?Prd=ie&Pver=5.0&Ar=ie5update&O1=b1
        .
        [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
        .
        Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=69157
        Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
        Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
        Delete_Temp_Files_On_Exit: yes
        Local Page: C:\windows\system32\blank.htm
        Start Page: hxxp://fr.msn.com/
        Search Bar: hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
        .
        [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
        .
        Tabs: res://ieframe.dll/tabswelcome.htm
        .
        ===================================
        .
        6133 Octet(s) - C:\Ad-Report-SCAN[1].log
        .
        6 Fichier(s) - C:\DOCUME~1\HLNE~1\LOCALS~1\Temp
        10 Fichier(s) - C:\WINDOWS\Temp
        29 Fichier(s) - C:\WINDOWS\Prefetch
        .
        2 Fichier(s) - C:\Ad-Remover\BACKUP
        0 Fichier(s) - C:\Ad-Remover\QUARANTINE
        .
        Fin à: 21:26:41 | 02/26/2010 - SCAN[1]
        .
        ============== E.O.F ==============
        0
    5. Contributeur sécurité
      Nettoyage avec Ad-Remover :
      /!\ Déconnectes toi et fermes toutes applications en cours, désactive ton antivirus le temps de la manipulation/!\
      Double clique ( clic droit "exécuter en tant qu'administrateur" pour Vista/7 ) sur l’exécutable pour le lancer.
      Au message d’avertissement qui s’affiche, sélectionne ‘Oui’.
      Au menu principal choisi l’option "L" et tape ensuite sur la touche Entrée.Poste le rapport qui apparaît à la fin de l’analyse qui peut prendre du temps.
      (Le rapport est sauvegardé aussi sous C:\Ad-report(date).log)
      (CTRL+A Pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)
      0
      1. Le nettoyage est terminé
        Voici le rapport
        Je vais me coucher
        Je verrai demain la suite
        Déjà merci
        Bonne nuit
        helene
        ======= RAPPORT D'AD-REMOVER 1.1.4.6_J | UNIQUEMENT XP/VISTA/7 =======
        .
        Mis à jour par C_XX le 05.02.2010 à 17:34
        Contact: AdRemover.contact@gmail.com
        Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
        .
        Lancé à: 22:22:42, 02/26/2010 | Mode Normal | Option: CLEAN
        Exécuté de: C:\Ad-Remover\
        Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
        Nom du PC: BUREAU | Utilisateur actuel: H‚lŠne
        .
        ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
        .

        C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\Dealio
        C:\Program Files\Dealio
        C:\Program Files\Search Settings
        C:\DOCUME~1\HLNE~1\APPLIC~1\Dealio
        C:\DOCUME~1\HLNE~1\APPLIC~1\Search Settings
        C:\Windows\Installer\424a7b.msi
        C:\Windows\Installer\424a82.msi
        C:\Documents and Settings\Serge\Application Data\Dealio
        C:\Documents and Settings\Serge\Application Data\EoRezo
        C:\Documents and Settings\Geoffroy\Application Data\EoRezo
        C:\Documents and Settings\Camille\Application Data\EoRezo
        C:\Documents and Settings\Camille\Camille.BUREAU\Application Data\EoRezo
        C:\Documents and Settings\Serge\Application Data\Search Settings

        (!) -- Fichiers temporaires supprimés.

        .
        HKCU\software\Dealio
        HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F}
        HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
        HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F}
        HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
        HKCU\software\Search Settings
        HKLM\Software\Classes\CLSID\{6A87B991-A31F-4130-AE72-6D0C294BF082}
        HKLM\Software\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
        HKLM\Software\Classes\Interface\{D5A1EF9A-7948-435D-8B87-D6A598317288}
        HKLM\software\classes\SearchSettings.BHO
        HKLM\software\classes\SearchSettings.BHO.1
        HKLM\Software\Classes\TypeLib\{CD082CCA-086F-4FD8-8FD7-247A0DBBD1CC}
        HKLM\software\Dealio
        HKLM\Software\Microsoft\Internet Explorer\Extensions\{E908B145-C847-4e85-B315-07E2E70DECF8}
        HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F}
        HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6A87B991-A31F-4130-AE72-6D0C294BF082}
        HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\0292226F570267D459357AF78015E534
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\03285961954D5824C85975D955031EE8
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\6AC3985F4D64C2245A96D31569D1BF40
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\855847FA0E25FBA46B8516389DFDD4B3
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\9DC2844D0E3E8924C8973C3B3BAE1F58
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\AFEB575AA30ACB243B748619F62F0782
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\F461B8DD96FF5AA41A52D14E1D7B69C7
        HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\au
        HKLM\software\Search Settings
        .
        ============== Scan additionnel ==============
        .
        .
        * Mozilla FireFox Version 3.6 [fr] *
        .
        Nom du profil: npj0mbfw.default (H‚lŠne)
        .
        (HLNE~1, prefs.js) Browser.download.lastDir, C:\Documents and Settings\Hélène\Mes documents
        (HLNE~1, prefs.js) Browser.search.defaultenginename, Google
        (HLNE~1, prefs.js) Browser.search.defaulturl, hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
        (HLNE~1, prefs.js) Browser.search.selectedEngine, Google
        (HLNE~1, prefs.js) Browser.startup.homepage, hxxp://news.google.fr
        (HLNE~1, prefs.js) Extensions.enabledItems, en-GB@dictionaries.addons.mozilla.org:1.19,{3112ca9c-de6d-4884-a869-9855de68056c}:6.1.20091119W,{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03,{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05,{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}:6.0.04,{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07,{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11,{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13,{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15,jqs@sun.com:1.0,{20a82645-c095-46ed-80e3-08825760534b}:1.1,{635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.2.20080910,{ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6
        .
        .
        * Internet Explorer Version 6.0.2900.5512 *
        .
        [HKEY_CURRENT_USER\..\Internet Explorer\Main]
        .
        Do404Search: 01000000
        Show_ToolBar: yes
        Start Page: hxxp://fr.msn.com/
        Enable Browser Extensions: yes
        Local Page: C:\WINDOWS\system32\blank.htm
        Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
        Use Custom Search URL: 1 (0x1)
        Use Search Asst: no
        Search Bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
        Default_page_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
        .
        [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
        .
        Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
        Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
        Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
        Delete_Temp_Files_On_Exit: yes
        Local Page: C:\windows\system32\blank.htm
        Start Page: hxxp://fr.msn.com/
        Search Bar: hxxp://search.msn.com/spbasic.htm
        .
        [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
        .
        Tabs: res://ieframe.dll/tabswelcome.htm
        .
        ===================================
        .
        5703 Octet(s) - C:\Ad-Report-CLEAN[1].log
        6468 Octet(s) - C:\Ad-Report-SCAN[1].log
        .
        6 Fichier(s) - C:\DOCUME~1\HLNE~1\LOCALS~1\Temp
        9 Fichier(s) - C:\WINDOWS\Temp
        10 Fichier(s) - C:\WINDOWS\Prefetch
        .
        19 Fichier(s) - C:\Ad-Remover\BACKUP
        1476 Fichier(s) - C:\Ad-Remover\QUARANTINE
        .
        Fin à: 23:19:53 | 02/26/2010 - CLEAN[1]
        .
        ============== E.O.F ==============
        .
        0
    6. Contributeur sécurité
      excellent

      Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent(car il est detecté a tort comme infection)

      Télécharge et installe List&Kill'em et enregistre le sur ton bureau

      http://sd-1.archive-host.com/membres/up/829108531491024/List_Killem_Install.exe

      Branche clés usb , disques durs externes , mp3 , mp4 , etc..

      double clique ( clic droit "exécuter en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

      coche la case "créer une icône sur le bureau"

      une fois terminée , clic sur "terminer" et le programme se lancera seul

      choisis la langue puis choisis l'option 1 = Mode Recherche

      laisse travailler l'outil

      à l'apparition de la fenêtre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

      un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , mais ne le supprime pas pour l instant, le scan n'est pas fini.

      Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'écran "COMPLETED"
      0
      1. voici le dernier rapport
        merci pour tes commentaires

        List'em by g3n-h@ckm@n 1.2.8.1

        User : Hélène (Utilisateurs)
        Update on 26/02/2010 by g3n-h@ckm@n ::::: 14.30
        Start at: 11:09:39 | 02/27/2010
        Contact : https://forums.commentcamarche.net/forum/virus-securite-7

        Intel(R) Pentium(R) 4 CPU 2.80GHz
        Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
        Internet Explorer 6.0.2900.5512
        Windows Firewall Status : Disabled
        AV : AntiVir Desktop 9.0.1.32 [ (!) Disabled | Updated ]
        FW : Sunbelt Personal Firewall[ (!) Disabled ]4.6.1861 T

        C:\ -> Disque fixe local | 149,01 Go (82,73 Go free) | NTFS
        D:\ -> Disque amovible
        E:\ -> Disque amovible
        F:\ -> Disque CD-ROM

        Boot: Normal

        ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\csrss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Avira\AntiVir Desktop\sched.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Avira\AntiVir Desktop\avguard.exe
        C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\Program Files\Java\jre6\bin\jqs.exe
        C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
        C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\MsPMSPSv.exe
        C:\WINDOWS\System32\alg.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
        C:\ATI-CPanel\atiptaxx.exe
        C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
        C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
        C:\Program Files\Skype\Phone\Skype.exe
        C:\Program Files\Skype\Plugin Manager\skypePM.exe
        C:\WINDOWS\system32\wscntfy.exe
        C:\Program Files\List_Kill'em\List_Kill'em.scr
        C:\WINDOWS\system32\cmd.exe
        C:\WINDOWS\system32\wbem\wmiprvse.exe
        C:\Documents and Settings\Hélène\Local Settings\temp\93.tmp\pv.exe

        ======================
        Keys "Run"
        ======================
        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        swg REG_SZ C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        Skype REG_SZ "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        ATIPTA REG_SZ C:\ATI-CPanel\atiptaxx.exe
        UserFaultCheck REG_EXPAND_SZ %systemroot%\system32\dumprep 0 -u
        avgnt REG_SZ "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
        TkBellExe REG_SZ "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

        =====================
        Other Keys
        =====================
        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
        dontdisplaylastusername REG_DWORD 0 (0x0)
        legalnoticecaption REG_SZ
        legalnoticetext REG_SZ
        shutdownwithoutlogon REG_DWORD 1 (0x1)
        undockwithoutlogon REG_DWORD 1 (0x1)
        HideLegacyLogonScripts REG_DWORD 0 (0x0)
        HideLogoffScripts REG_DWORD 0 (0x0)
        RunLogonScriptSync REG_DWORD 1 (0x1)
        RunStartupScriptSync REG_DWORD 0 (0x0)
        HideStartupScripts REG_DWORD 0 (0x0)

        ===============
        [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
        NoDriveAutoRun REG_DWORD 255 (0xff)
        NoDriveTypeAutoRun REG_DWORD 255 (0xff)
        HonorAutoRunSetting REG_DWORD 0 (0x0)

        ===============
        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
        AllowLegacyWebView REG_DWORD 1 (0x1)
        AllowUnhashedWebView REG_DWORD 1 (0x1)
        NoDriveTypeAutoRun REG_DWORD 255 (0xff)
        NoDriveAutoRun REG_DWORD 255 (0xff)
        HonorAutoRunSetting REG_DWORD 0 (0x0)

        ===============
        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

        ===============
        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
        AutoRestartShell REG_DWORD 1 (0x1)
        DefaultDomainName REG_SZ BUREAU
        DefaultUserName REG_SZ Hélène
        LegalNoticeCaption REG_SZ
        LegalNoticeText REG_SZ
        PowerdownAfterShutdown REG_SZ 0
        ReportBootOk REG_SZ 1
        Shell REG_SZ explorer.exe
        ShutdownWithoutLogon REG_SZ 0
        System REG_SZ
        Userinit REG_SZ C:\WINDOWS\system32\userinit.exe,
        VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
        SfcQuota REG_DWORD -1 (0xffffffff)
        allocatecdroms REG_SZ 0
        allocatedasd REG_SZ 0
        allocatefloppies REG_SZ 0
        cachedlogonscount REG_SZ 10
        forceunlocklogon REG_DWORD 0 (0x0)
        passwordexpirywarning REG_DWORD 14 (0xe)
        scremoveoption REG_SZ 0
        AllowMultipleTSSessions REG_DWORD 1 (0x1)
        UIHost REG_EXPAND_SZ logonui.exe
        LogonType REG_DWORD 1 (0x1)
        Background REG_SZ 0 0 0
        DebugServerCommand REG_SZ no
        SFCDisable REG_DWORD 0 (0x0)
        WinStationsDisabled REG_SZ 0
        HibernationPreviouslyEnabled REG_DWORD 1 (0x1)
        ShowLogonOptions REG_DWORD 0 (0x0)
        AltDefaultUserName REG_SZ Hélène
        AltDefaultDomainName REG_SZ BUREAU
        ChangePasswordUseKerberos REG_DWORD 1 (0x1)
        SfcScan REG_DWORD 0 (0x0)

        ===============
        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WgaLogon]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]

        ===============
        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
        {AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ

        ===============
        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
        %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
        %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
        C:\Program Files\iTunes\iTunes.exe REG_SZ C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes
        C:\Program Files\Bonjour\mDNSResponder.exe REG_SZ C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour
        C:\Program Files\Skype\Plugin Manager\skypePM.exe REG_SZ C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager
        C:\Program Files\Skype\Phone\Skype.exe REG_SZ C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype

        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
        C:\Program Files\Windows Live\Messenger\livecall.exe REG_SZ C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)
        %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
        %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019

        ===============
        ActivX controls
        ===============
        HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{17492023-C23A-453E-A040-C7C580BBF700}
        HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{5D86DDB5-BDF9-441B-9E9E-D4730F4EE499}
        HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}
        HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}
        HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
        HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}
        HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
        HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
        HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
        HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
        HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{D27CDB6E-AE6D-11CF-96B8-444553540000}

        ===============
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{A34BA01E-226F-4702-AD75-AF5FBF21EB9F}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{0291E591-EA41-4c82-8106-3DC6CE7F7664}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{04d6265d-6b5d-41c3-9e7c-48be15919643}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{0fde1f56-0d59-4fd7-9624-e3df6b419d0e}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{0fde1f56-0d59-4fd7-9624-e3df6b419d0f}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{166B1BCA-3F9C-11CF-8075-444553540000}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{233C1507-6A77-46A4-9443-F871F945D258}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{283807B5-2C60-11D0-A31D-00AA00B92C03}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2A202491-F00D-11cf-87CC-0020AFEECF20}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{30528230-99F7-4BB4-88D8-FA1D4F56A2AB}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{347B0667-C7ED-429B-BDE3-CC8D3BACAA31}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{411EDCF7-755D-414E-A74B-3DCD6583F589}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4278c270-a269-11d1-b5bf-0000f8051515}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f216970-c90c-11d1-b5c7-0000f8051515}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5A8D6EE0-3E18-11D0-821E-444553540000}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5c9ff2bf-938d-47fe-85d9-9dbab4f65018}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5f3c70b3-ac2f-432c-8f9c-1624df61f54f}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{689e5762-8d75-4346-90cf-bc1902c32d63}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{79844cfb-ac65-4e10-a06a-c974234f40d0}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{82ced0ff-a00d-4405-ba5f-ef4699159333}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9A394342-4A68-4EBA-85A6-55B559F4E700}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{ae594d5e-dd07-4e54-8252-daa5aebbd4ec}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B508B3F1-A24A-32C0-B310-85786919EF28}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CC2A9BA0-3BDD-11D0-821E-444553540000}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11cf-96B8-444553540000}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{DAA94A2A-2A8D-4D3B-9DB8-56FBECED082D}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{eddbec60-89cb-44ef-8291-0850fd28ff6a}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{f5173cf0-1dfb-4978-8e50-a90169ee7ca9}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{F5776D81-AE53-4935-8E84-B0B283D8BCEF}

        ==============
        BHO :
        ======
        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{C333CF63-767F-4831-94AC-E683D962C63C}]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]

        ===
        DNS
        ===

        HKLM\SYSTEM\CCS\Services\Tcpip\..\{26E83445-8728-4A15-909A-73B41F7C0892}: DhcpNameServer=89.2.0.1 89.2.0.2
        HKLM\SYSTEM\CS1\Services\Tcpip\..\{26E83445-8728-4A15-909A-73B41F7C0892}: DhcpNameServer=89.2.0.1 89.2.0.2
        HKLM\SYSTEM\CS2\Services\Tcpip\..\{26E83445-8728-4A15-909A-73B41F7C0892}: DhcpNameServer=89.2.0.1 89.2.0.2
        HKLM\SYSTEM\CS3\Services\Tcpip\..\{26E83445-8728-4A15-909A-73B41F7C0892}: DhcpNameServer=82.216.111.121 192.168.0.1
        HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=89.2.0.1 89.2.0.2
        HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=89.2.0.1 89.2.0.2
        HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=89.2.0.1 89.2.0.2
        HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=82.216.111.121 192.168.0.1

        ================
        Internet Explorer :
        ================
        [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
        Start Page REG_SZ https://www.msn.com/fr-fr

        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
        Start Page REG_SZ https://www.msn.com/fr-fr

        ========
        Services
        ========
        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

        Ndisuio : 0x3 ( OK = 3 )
        EapHost : 0x3 ( OK = 2 )
        SharedAccess : 0x2 ( OK = 2 )
        wuauserv : 0x2 ( OK = 2 )

        =========
        Atapi.sys
        =========

        %%%% HASHDEEP-1.0
        %%%% size,md5,sha256,filename
        ## Invoked from: C:\Documents and Settings\Hélène\Local Settings\temp\93.tmp
        ## C:\> hashdeep.exe C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
        ##
        95360,cdfe4411a69c224bd1d11b2da92dac51,0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d,C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
        %%%% HASHDEEP-1.0
        %%%% size,md5,sha256,filename
        ## Invoked from: C:\Documents and Settings\Hélène\Local Settings\temp\93.tmp
        ## C:\> hashdeep.exe C:\WINDOWS\ServicePackFiles\i386\atapi.sys
        ##
        96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\ServicePackFiles\i386\atapi.sys
        %%%% HASHDEEP-1.0
        %%%% size,md5,sha256,filename
        ## Invoked from: C:\Documents and Settings\Hélène\Local Settings\temp\93.tmp
        ## C:\> hashdeep.exe C:\WINDOWS\system32\drivers\atapi.sys
        ##
        96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\system32\drivers\atapi.sys

        Référence :
        ==========

        Win 2000_SP2 : ff953a8f08ca3f822127654375786bbe
        Win XP_32b : a64013e98426e1877cb653685c5c0009
        Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
        Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
        Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
        Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
        Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
        Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
        Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
        Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C

        =======
        Drive :
        =======

        D‚fragmenteur de disque Windows
        Copyright (c) 2001 Microsoft Corp. et Executive Software International Inc.

        Rapport d'analyse
        149 Go total, 82,73 Go libre (55%), 25% fragment‚ (fragmentation du fichier 50%)

        Vous devriez d‚fragmenter ce volume.

        ¤¤¤¤¤¤¤¤¤¤ Files/folders :

        Present !! : C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
        Present !! : C:\WINDOWS\System32\_*.dll
        Present !! : C:\WINDOWS\System32\drivers\Cdaudio.sys
        Present !! : C:\WINDOWS\System32\rnaph.dll
        Present !! : C:\WINDOWS\System32\tmp.reg"
        Present !! : C:\Documents and Settings\H‚lŠne\LOCAL Settings\Temp\Perflib_Perfdata_990.dat

        ¤¤¤¤¤¤¤¤¤¤ Keys :

        Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
        Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"

        ============

        catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2010-02-27 12:02:48
        Windows 5.1.2600 Service Pack 3 NTFS

        scanning hidden processes ...

        scanning hidden services & system hive ...

        scanning hidden registry entries ...

        scanning hidden files ...

        scan completed successfully
        hidden processes: 0
        hidden services: 0
        hidden files: 0

        Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

        device: opened successfully
        user: MBR read successfully
        called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
        kernel: MBR read successfully
        user & kernel MBR OK

        ==========
        Programs
        ==========

        7-Zip
        a-squared Free
        aawsepersonal.exe
        Ad-remover
        Adobe
        Ahead
        Alwil Software
        AM-DeadLink
        APDFR
        Apple Software Update
        ArcSoft
        Autoruns
        Autoruns.zip
        Avira
        BitDefender
        BitZipper
        blank.gif
        Bonjour
        CleanUp!
        Common Files
        ComPlus Applications
        cqwydcgt.exe
        directx
        DivX
        eChanblard
        fdminst.exe
        Fichiers communs
        Foxit Software
        FrRefFra
        FrReform.exe
        GalleryPlayer Images
        GenuineCheck.exe
        GeoGebra(2)
        Ghostgum
        Google
        GoogleDesktopSetup.exe
        GoogleEarthWin.exe
        Hewlett-Packard
        Hip Interactive
        IE6
        IncrediMail
        Ink.msi
        InstallShield Installation Information
        instmsia.exe
        instmsiw.exe
        Internet Explorer
        Internet Usage Monitor Lite Edition
        InterVideo
        Intuwave Ltd
        iPod
        iTunes
        IZArc
        Java
        jv16 PowerTools
        licenses
        List_Kill'em
        Malwarebytes' Anti-Malware
        Messenger
        Microsoft
        microsoft frontpage
        Microsoft Office
        Microsoft Office(2)
        Microsoft Silverlight
        Microsoft SQL Server Compact Edition
        Microsoft Works
        Movie Maker
        Mozilla Firefox
        MSBuild
        MSECache
        MSN
        MSN Gaming Zone
        mst software
        MSXML 4.0
        NDP1.1sp1-KB867460-X86.exe
        NetMeeting
        OpenOffice.org 2.3
        OpenOffice.org 2.4
        openofficeorg1.cab
        openofficeorg2.cab
        openofficeorg21.msi
        openofficeorg22.msi
        openofficeorg3.cab
        openofficeorg4.cab
        OSCILLO
        Outlook Express
        Panasonic
        Philips
        Philips ToUcam Camera
        PhotoFiltre
        QuickTime
        rd2005trial.exe
        readmes
        Real
        Reference Assemblies
        serial.tde
        serial2
        Services en ligne
        setup.ini
        setupfre.exe
        SetupTrueDownloader.exe
        Sibelius Software
        SiSoftware
        Skype
        SopCast
        soref_regclean.exe
        Spybot - Search & Destroy
        spybotsd14.exe
        StartupList.exe
        startuplist.txt
        Startup_manager_2.0
        Startup_manager_2.0.zip
        stubinstaller.ini
        Sunbelt Software
        Symbian
        TGTSoft
        ThumbClic
        ThumbClic.zip
        Thumbs.db
        TI Education
        Trend Micro
        TVUPlayer
        Uninstall Information
        VideoLink Pro
        Virtools Web Player 3.5
        vista-inspirat-pack_vista_inspirat_pack_1.1_francais_15013.exe
        vLite
        WebLog Expert
        Windows Live
        Windows Live SkyDrive
        Windows Media Connect 2
        Windows Media Player
        Windows NT
        WindowsUpdate
        winMd5Sum
        WinRAR
        xerox
        Zero G Registry
        ZiPhone
        zlsSetup_65_725_000_fr.exe

        ============
        Drive C:
        ============

        $CTJTMP
        2095233f51f7db964e
        2e09703565345c472926bb9a700fb7
        327882R2FWJFW
        95893364180037fbbb81925e7a87
        Accessories
        Ad-Remover
        Ad-Report-CLEAN[1].log
        Ad-Report-SCAN[1].log
        ad9c5363644f768a6a557a96dbb0
        AddOn
        ATI-CPanel
        autorun.inf
        Backups
        bitdefenden1201749835_1_02.xml
        boot.ini
        Bootfont.bin c1d9505b5f8e2b9fd8e1
        cf742f19fc19ecaa7f1cfe1c9def860b
        Config.Msi
        CONFIG.SYS
        CTJINI.INI
        d257cd5ea34e60699cd442
        DealioAu.log
        Documentation en ligne
        Documents and Settings
        Downloads
        f65ea00c2824c2b36179b458fe0477
        hellbot.exe
        hijack
        hpfr3420.xml
        hpfr3425.log
        hpothb07.dat
        hpothb07.tif
        hWaitEventRetryInstall
        IO.SYS
        Kill'em
        List'em.txt
        Mes t‚l‚chargements
        MSDOS.SYS
        MSOCache
        myskin.pcb
        NTDETECT.COM
        ntldr
        pagefile.sys
        Panasonic
        pnpID.dat
        Program Files
        RECYCLER
        Sauv.reg
        System Volume Information
        teleir
        TEST.XML
        tmpFile.dat
        UsbFix
        UsbFix.txt
        UsbFix_Upload_Me_BUREAU.zip
        WINDOWS

        ¤¤¤¤¤¤¤¤¤¤ Cracks | Keygens | Serials

        ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

        End of scan : 12:23:15,79
        0
    7. Contributeur sécurité
      bonjour

      en arrive au bout du tunnel

      ▶ Relance List&Kill'em(soit en clic droit pour vista),avec le raccourci sur ton bureau.
      mais cette fois-ci :

      ▶ choisis l'option 2 = Mode Suppression

      laisse travailler l'outil.

      en fin de scan un rapport s'ouvre

      ▶ colle le contenu dans ta réponse

      ensuite :

      ▶ Relance List&Kill'em(soit en clic droit pour vista),avec le raccourci sur ton bureau.
      mais cette fois-ci :

      ▶ choisis l'option 6 = Restore MBR

      laisse travailler l'outil.

      en fin de scan un rapport s'ouvre

      ▶ colle le contenu dans ta réponse
      0
      1. Bonjour Benurr,

        Merci d'être encore là
        Est ce que je dois faire le mode suppression de List and Kill après avoir désactiver mon pare feu et mon antivirus comme pour la recherche???
        0
    8. Contributeur sécurité
      oui
      0
      1. ok
        0
      2. Me revoilà avec les 2 rapports
        Moi qui croyais que c'était fini depuis un moment!
        Est ce que maintenant on y voit plus clair??
        Merci
        Kill'em by g3n-h@ckm@n 1.2.8.1

        User : Hélène (Utilisateurs)
        Update on 26/02/2010 by g3n-h@ckm@n ::::: 14.30
        Start at: 17:29:23 | 02/27/2010
        Contact : https://forums.commentcamarche.net/forum/virus-securite-7

        Intel(R) Pentium(R) 4 CPU 2.80GHz
        Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
        Internet Explorer 6.0.2900.5512
        Windows Firewall Status : Disabled
        AV : AntiVir Desktop 9.0.1.32 [ (!) Disabled | Updated ]
        FW : Sunbelt Personal Firewall[ (!) Disabled ]4.6.1861 T

        C:\ -> Disque fixe local | 149,01 Go (84,08 Go free) | NTFS
        D:\ -> Disque amovible
        E:\ -> Disque amovible
        F:\ -> Disque CD-ROM

        ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\csrss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Avira\AntiVir Desktop\sched.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Avira\AntiVir Desktop\avguard.exe
        C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Java\jre6\bin\jqs.exe
        C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
        C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\MsPMSPSv.exe
        C:\ATI-CPanel\atiptaxx.exe
        C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
        C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
        C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
        C:\Program Files\Skype\Phone\Skype.exe
        C:\WINDOWS\System32\alg.exe
        C:\Program Files\Skype\Plugin Manager\skypePM.exe
        C:\WINDOWS\system32\wscntfy.exe
        C:\Program Files\List_Kill'em\List_Kill'em.scr
        C:\WINDOWS\system32\cmd.exe
        C:\WINDOWS\system32\wbem\wmiprvse.exe
        C:\Documents and Settings\Hélène\Local Settings\temp\5A.tmp\ERUNT.EXE
        C:\Documents and Settings\Hélène\Local Settings\temp\5A.tmp\pv.exe

        Detections :
        ==========

        ¤¤¤¤¤¤¤¤¤¤ Files/folders :

        Quarantined & Deleted !! : C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache

        Quarantined & Deleted !! : C:\WINDOWS\System32\_Source21.Dll
        Quarantined & Deleted !! : C:\WINDOWS\System32\drivers\Cdaudio.sys
        Quarantined & Deleted !! : C:\WINDOWS\System32\rnaph.dll
        Quarantined & Deleted !! : C:\WINDOWS\System32\tmp.reg
        Quarantined & Deleted !! : C:\Documents and Settings\Hélène\LOCAL Settings\Temp\Perflib_Perfdata_460.dat

        ==============
        host file OK !
        ==============

        ========
        Registry
        ========

        Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
        Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
        ========
        Services
        =========

        Ndisuio : Start = 3
        EapHost : Start = 2
        Ip6Fw : Start = 2
        SharedAccess : Start = 2
        wuauserv : Start = 2
        wscsvc : Start = 2

        ============
        Disk Cleaned
        ============

        =================
        anti-ver blaster : OK !!
        =================

        ================
        Prefetch cleaned
        ================

        ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

        Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

        device: opened successfully
        user: MBR read successfully
        kernel: MBR read successfully
        user & kernel MBR OK
        0
    9. Contributeur sécurité
      cool

      relance usbfix
      Double clic sur le raccourci UsbFix présent sur ton bureau

      Choisi l option 5 ( Désinstaller ) ....

      relance List&Kill'em.

      et choisie l'option 3 désinstallation

      ensuite

      pour nettoyer les fix qui ont servit

      Ferme toutes les applications en cours, puis télécharge ToolsCleaner2 sur ton Bureau.
      http://pc-system.fr/

      Double clique sur ToolsCleaner2.exe >
      puis Recherche
      et sur Suppression
      Note : ton bureau va disparaître, c'est normal. S'il n'apparaît pas à la fin du scan, fais la manip suivante :

      CTRL+ALT+SUPP pour ouvrir le Gestionnaire des tâches.
      Puis rends toi à l'onglet "Processus". Clique en haut à gauche sur Fichiers et choisis "Exécuter"

      Tape explorer.exe et valide. Cela fera re-apparaître le Bureau

      tu poste le rapport générer après suppression

      Par Manque De Curiosité On Risque De Mourir Ignorant;Tu es libre de penser que tu es C..,
      Mais C.. de penser que ­tu es libre...Merci a australe13
      0
      1. le bureau n' aps disparu
        est ce que c'est bon??

        [ Rapport ToolsCleaner version 2.3.11 (par A.Rothstein & dj QUIOU) ]

        --> Recherche:

        C:\UsbFix: trouvé !
        C:\Ad-remover: trouvé !
        C:\Ad-Remover\BACKUP\Ad-R.exe: trouvé !
        C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
        C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
        C:\Documents and Settings\Hélène\Bureau\HJTInstall.exe: trouvé !
        C:\Documents and Settings\Hélène\Bureau\Ad-R.exe: trouvé !
        C:\Documents and Settings\Hélène\Bureau\hijackthis.log: trouvé !
        C:\Documents and Settings\Hélène\Local Settings\temp\5A.tmp\catchme.exe: trouvé !
        C:\Documents and Settings\Hélène\Local Settings\temp\5A.tmp\mbr.exe: trouvé !
        C:\Documents and Settings\Hélène\Local Settings\temp\5D.tmp\catchme.exe: trouvé !
        C:\Documents and Settings\Hélène\Local Settings\temp\5D.tmp\mbr.log: trouvé !
        C:\Documents and Settings\Hélène\Local Settings\temp\5D.tmp\mbr.exe: trouvé !
        C:\Documents and Settings\Hélène\Menu Démarrer\Programmes\Ad-remover: trouvé !
        C:\Documents and Settings\Hélène\Menu Démarrer\Programmes\Ad-remover\Ad-remover.lnk: trouvé !
        C:\Program Files\Ad-remover: trouvé !
        C:\Program Files\Trend Micro\HijackThis: trouvé !
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
        C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !

        ---------------------------------
        --> Suppression:

        C:\Ad-Remover\BACKUP\Ad-R.exe: supprimé !
        C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
        C:\Documents and Settings\Hélène\Bureau\HJTInstall.exe: supprimé !
        C:\Documents and Settings\Hélène\Bureau\Ad-R.exe: supprimé !
        C:\Documents and Settings\Hélène\Local Settings\temp\5A.tmp\catchme.exe: supprimé !
        C:\Documents and Settings\Hélène\Local Settings\temp\5D.tmp\catchme.exe: supprimé !
        C:\Documents and Settings\Hélène\Menu Démarrer\Programmes\Ad-remover\Ad-remover.lnk: supprimé !
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
        C:\Documents and Settings\Hélène\Bureau\hijackthis.log: supprimé !
        C:\Documents and Settings\Hélène\Local Settings\temp\5A.tmp\mbr.exe: supprimé !
        C:\Documents and Settings\Hélène\Local Settings\temp\5D.tmp\mbr.log: supprimé !
        C:\Documents and Settings\Hélène\Local Settings\temp\5D.tmp\mbr.exe: supprimé !
        C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
        C:\UsbFix: supprimé !
        C:\Ad-remover: supprimé !
        C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
        C:\Documents and Settings\Hélène\Menu Démarrer\Programmes\Ad-remover: supprimé !
        C:\Program Files\Ad-remover: supprimé !
        C:\Program Files\Trend Micro\HijackThis: supprimé !
        0
    10. Contributeur sécurité
      Ok ,c'est bon malawarbyte et ccleaner tu les garde et sert toi s'en souvent

      tu va télécharger Ccleaner http://dl.commentcamarche.net/www.commentcamarche.net/download/files/ccsetup227_slim.exe

      ouvre "Ccleaner" vas dans l'onglet "Option" puis "Avancé" puis décoches "Effacer uniquement les fichiers, du dossier temp de Windows, plus vieux que 48 heures."

      . Puis vas dans l'onglet "Nettoyeur" fais "Analyse" puis "Lancer le nettoyage".
      Puis vas dans l'onglet "Registre" puis fait "Chercher des erreurs" puis "Réparer les erreurs sélectionnée"
      . Tu refais tous ca 4-5 fois (le nettoyage et le registre).

      Puis reste dans "Ccleaner" puis va dans "Option" puis "Propriété" puis coches "Nettoyer automatiquement l'ordinateur au démarrage".

      içi mode d'emploi pour ccleaner

      https://www.malekal.com/tutoriel-ccleaner/
      0
      1. Bonjour Benurr,

        Tout est fait, mon PC est-il propre maintenant??
        Encore merci pour tout
        Bonne continuation
        Et bon dimanche
        0
    11. Contributeur sécurité
      bonjour

      oui bon surf
      0
      1. Encore merci Benurr
        Deux dernières questions pour ne pas rester idiote: pourquoi alors que tout semblait être rentré dans l'ordre a-t-us continué à chercher? et pourquoi en mode sans échec avec la connexion, n'étais-je pas embêté par le virus?
        Bonne fin de journée
        Helene

        Comment je fais pour cloturer la discussion sur le forum en la marquant résolue??
        0
    • 1
    • 2