Antivirus soft est il un virus???

Résolu
helene -  
 helene -
Bonjour,

J'utilise le Mac de mon fils pour vous contacter au sujet d'un problème apparu sur mon PC depuis quelques minutes: un message d'alerte de "antivirus soft" s'affiche, lance un scan et détecte des trojans, malwares et autres choses de ce genre. J' ai esasyé de tout stopper et de lancer mon antivirus Antivir, mais il se bloque. Pouvez vous m'aider?
D'avance, je vous remercie pour votre aide
Bien cordialement
Helene
Configuration: PC Windows

23 réponses

  • 1
  • 2
Résumé de la discussion

Une alerte antivirus affichant 'antivirus soft' apparaît sur un PC Windows, lance un scan et signale des trojans et malwares, ce qui bloque l'antivirus et complique le nettoyage. Plusieurs réponses suggèrent d'attaquer en mode sans échec, d'exécuter des outils comme Malwarebytes, Ad-Remover ou List & Kill'em, puis de supprimer les fichiers infectés et de nettoyer le registre. Des guides proposent aussi de restaurer le MBR et de surveiller le démarrage, avec des scans répétés en mode sûr, et de copier les rapports pour poursuivre l’analyse. Des complications majeures sont évoquées lorsque l’alerte signale Malwarebytes comme infecté, bloquant son lancement et poussant à envisager des mesures hors du système pour vérifier l’authenticité des outils.

Bobot (l'IA à votre service)
  1. benurrr Messages postés 9766 Statut Contributeur sécurité 107
     
    bonjour

    regarde ceci

    http://www.commentcamarche.net/faq/26898-supprimer-antivirus-soft
    0
    1. helene
       
      Bonjour Benuur,

      Merci pour ta réponse, je suis perdue...j'ai regardé le lien que tu m'envoies, concrêtement, je dois faire quoi?? Pour l'instant, j'ai coupé ma connexion, dois je l remettre?
      Merci
      A tout de suite
      0
  2. benurrr Messages postés 9766 Statut Contributeur sécurité 107
     
    si ta toujours ta connexion

    télécharge

    http://www.malwarebytes.org/mbam/program/mbam-setup.exe

    a l'installation vérifie que mise a jour et lancer programme et scan complet sont bien cocher

    Une fois a jour, le programme va se lancer; clic sur l´onglet paramètre, et coche la case : "Arrêter internet explorer pendant la suppression".

    A la fin du scan clique sur Afficher les résultats

    Vérifier si tout est coché et clic Supprimer la sélection

    S'il t'es demandé de redémarrer >>> clique sur "Yes"

    Et tu poste le rapport générer
    0
    1. helene
       
      j'ai téléchargé malware, impossible de l'ouvrir, une alarte me dit qu'il est infecté
      0
  3. benurrr Messages postés 9766 Statut Contributeur sécurité 107
     
    une alerte de qui ?

    normalement le lien est sur peut-être faux positive ignore l'alerte

    chez moi aucune alerte pourtant sécurité je suis au taquet
    0
    1. helene
       
      je veux bien l'ignorer mais malwareb ne s'ouvre pas
      L'alerte dit:
      "Security warning Application cannot be executed. The file mbam exe is infected. Do you want to active your antivirus software now?"
      Et c'est ce soit disant anti virus qui est le virus!!!!
      Que faire alors?
      0
  4. benurrr Messages postés 9766 Statut Contributeur sécurité 107
     
    démarre le en mode sans échec

    Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter.
    0
    1. helene
       
      Voilà, j'ai lancé le mode sans échec et malware qui est en train de scanner, il a déjà trouvé un problème
      Dites moi s'il vous plait ce que je devrai faire quand le scan sera terminé
      Merci d'avance
      0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. benurrr Messages postés 9766 Statut Contributeur sécurité 107
     
    A la fin du scan clique sur Afficher les résultats

    Vérifier si tout est coché et clic Supprimer la sélection

    S'il t'es demandé de redémarrer >>> clique sur "Yes"
    0
    1. helene
       
      ok, et ensuite je redémarre en mode normal?
      0
  7. benurrr Messages postés 9766 Statut Contributeur sécurité 107
     
    oui
    0
    1. helene
       
      Malwarebytes' Anti-Malware 1.44
      Version de la base de données: 3510
      Windows 5.1.2600 Service Pack 3 (Safe Mode)
      Internet Explorer 6.0.2900.5512

      02/26/2010 18:54:11
      mbam-log-2010-02-26 (18-54-05).txt

      Type de recherche: Examen complet (C:\|)
      Eléments examinés: 227331
      Temps écoulé: 1 hour(s), 16 minute(s), 11 second(s)

      Processus mémoire infecté(s): 0
      Module(s) mémoire infecté(s): 0
      Clé(s) du Registre infectée(s): 0
      Valeur(s) du Registre infectée(s): 0
      Elément(s) de données du Registre infecté(s): 0
      Dossier(s) infecté(s): 0
      Fichier(s) infecté(s): 1

      Processus mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Module(s) mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Clé(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Valeur(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Elément(s) de données du Registre infecté(s):
      (Aucun élément nuisible détecté)

      Dossier(s) infecté(s):
      (Aucun élément nuisible détecté)

      Fichier(s) infecté(s):
      C:\327882R2FWJFW\Combo-Fix.sys (Malware.Trace) -> No action taken.

      j'ai supprimé le fichier infecté, mais j'ai toujours la même alerte de Windows Security alert

      Et maintenant, que dois-je faire?
      D'avance merci
      0
  8. benurrr Messages postés 9766 Statut Contributeur sécurité 107
     
    Télécharge UsbFix de C_XX & Chiquitine29

    http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe

    (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

    • Double clic sur "UsbFix.exe" présent sur ton bureau ( clic droit "exécuter en tant qu'administrateur" pour Vista & 7 )

    • Choisis l'option F pour français et tape sur [entrée] .

    Choisis l'option 1 ( Recherche ) et tape sur [entrée] .

    • Laisse travailler l'outil.

    • Ensuite poste le rapport UsbFix.txt qui apparaitra.

    • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

    ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

    • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
    Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
    Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
    0
    1. helene
       
      j'ai téléchargé usbfix, mais comme précédemment, je ne peux pas l'ouvrir, toujours ce Security Warning!
      0
    2. helene
       
      Voici le rapport, j'ai fait le scan en mode sans échec
      Qu'en pensez-vous??


      User : Hélène (Utilisateurs) # BUREAU
      Update on 20/02/2010 by El Desaparecido , C_XX & Chimay8
      Start at: 19:40:22 | 02/26/2010
      Website : http://pagesperso-orange.fr/NosTools/index.html
      Contact : FindyKill.Contact@gmail.com

      Intel(R) Pentium(R) 4 CPU 2.80GHz
      Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
      Internet Explorer 6.0.2900.5512
      Windows Firewall Status : Disabled
      AV : AntiVir Desktop 9.0.1.32 [ Enabled | (!) Outdated ]
      FW : Sunbelt Personal Firewall[ Enabled ]4.6.1861 T

      C:\ -> Disque fixe local # 149,01 Go (82,97 Go free) # NTFS
      D:\ -> Disque amovible
      E:\ -> Disque amovible
      F:\ -> Disque CD-ROM

      ############################## | Processus actifs |

      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\savedump.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\wbem\wmiprvse.exe

      ################## | Elements infectieux |


      ################## | Registre |

      [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"
      [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"

      ################## | Mountpoints2 |


      ################## | Vaccin |

      (!) Cet ordinateur n'est pas vacciné !

      ################## | ! Fin du rapport # UsbFix V6.097 ! |
      0
    3. helene
       
      ça, c'est un rapport hijac fait au tout début et que je e parvenais pas à ouvrir en mode normal, là en mode sans échec avec la connexion, j'arrive

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 17:20:10, on 02/26/2010
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Avira\AntiVir Desktop\sched.exe
      C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
      C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\MsPMSPSv.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
      C:\ATI-CPanel\atiptaxx.exe
      C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\Program Files\Skype\Phone\Skype.exe
      C:\Documents and Settings\Hélène\Local Settings\Application Data\dtgeqs\ukfhsftav.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\WINDOWS\system32\wscntfy.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.news/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
      O2 - BHO: DealioBHO Class - {6A87B991-A31F-4130-AE72-6D0C294BF082} - C:\Program Files\Dealio\kb127\Dealio.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
      O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
      O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O3 - Toolbar: Dealio - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - C:\Program Files\Dealio\kb127\Dealio.dll
      O4 - HKLM\..\Run: [ATIPTA] C:\ATI-CPanel\atiptaxx.exe
      O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
      O4 - HKLM\..\Run: [au] C:\Program Files\Dealio\DealioAU.exe
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [eggqoudn] C:\Documents and Settings\Hélène\Local Settings\Application Data\dtgeqs\ukfhsftav.exe
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
      O4 - HKCU\..\Run: [eggqoudn] C:\Documents and Settings\Hélène\Local Settings\Application Data\dtgeqs\ukfhsftav.exe
      O4 - Startup: stardock objectdock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
      O4 - Startup: TransBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe
      O8 - Extra context menu item: &Download with TrueDownloader! - C:\Program Files\TrueDownloader\TrueDownloader.htm
      O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
      O8 - Extra context menu item: Compare Prices with &Dealio - C:\Documents and Settings\Hélène\Application Data\Dealio\kb127\res\DealioSearch.html
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
      O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb127\Dealio.dll
      O9 - Extra 'Tools' menuitem: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb127\Dealio.dll
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
      O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
      O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Google Desktop Manager 5.8.811.4345 (GoogleDesktopManager-110408-113106) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      O23 - Service: Google Update Service (gupdate1c985864032915c) (gupdate1c985864032915c) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
      O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
      O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
      O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
      0
  9. hacker13
     
    fais le en mode sans échec

    tu a essaye de renommer usbfix ?
    0
    1. helene
       
      Voilà le rapport, le scan a été fait en mode sans échec

      User : Hélène (Utilisateurs) # BUREAU
      Update on 20/02/2010 by El Desaparecido , C_XX & Chimay8
      Start at: 19:40:22 | 02/26/2010
      Website : http://pagesperso-orange.fr/NosTools/index.html
      Contact : FindyKill.Contact@gmail.com

      Intel(R) Pentium(R) 4 CPU 2.80GHz
      Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
      Internet Explorer 6.0.2900.5512
      Windows Firewall Status : Disabled
      AV : AntiVir Desktop 9.0.1.32 [ Enabled | (!) Outdated ]
      FW : Sunbelt Personal Firewall[ Enabled ]4.6.1861 T

      C:\ -> Disque fixe local # 149,01 Go (82,97 Go free) # NTFS
      D:\ -> Disque amovible
      E:\ -> Disque amovible
      F:\ -> Disque CD-ROM

      ############################## | Processus actifs |

      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\savedump.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\wbem\wmiprvse.exe

      ################## | Elements infectieux |


      ################## | Registre |

      [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"
      [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"

      ################## | Mountpoints2 |


      ################## | Vaccin |

      (!) Cet ordinateur n'est pas vacciné !

      ################## | ! Fin du rapport # UsbFix V6.097 ! |
      0
  10. hacker13
     
    tu na pas de clé usb de portable ou autre a branché ?
    0
  11. benurrr Messages postés 9766 Statut Contributeur sécurité 107
     
    Suppression

    Branche tes sources de données externes à ton PC, (clé USB, disque dur externe......) susceptibles d'avoir été infectés sans les ouvrir

    (1) Double clic sur le raccourci UsbFix présent sur ton bureau

    (2) Choisi l option 2 ( Suppression )

    Ton bureau disparaitra et le pc redémarrera .

    Au redémarrage , UsbFix scannera ton pc , laisse travailler l outil.

    Ensuite poste le rapport UsbFix.txt qui apparaitra avec le bureau .

    Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

    ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
    0
    1. helene
       
      En attendant ta réponse, j'ai mis à jour malware, je n'arrivai pas en mode normal, j'ai refait un scan et voici ce qu'il a trouvé...
      On avance non??
      je fais maintenant ce que tu me dis pour usbfix

      Malwarebytes' Anti-Malware 1.44
      Version de la base de données: 3796
      Windows 5.1.2600 Service Pack 3 (Safe Mode)
      Internet Explorer 6.0.2900.5512

      02/26/2010 20:12:20
      mbam-log-2010-02-26 (20-12-20).txt

      Type de recherche: Examen rapide
      Eléments examinés: 144214
      Temps écoulé: 6 minute(s), 5 second(s)

      Processus mémoire infecté(s): 0
      Module(s) mémoire infecté(s): 0
      Clé(s) du Registre infectée(s): 2
      Valeur(s) du Registre infectée(s): 2
      Elément(s) de données du Registre infecté(s): 0
      Dossier(s) infecté(s): 0
      Fichier(s) infecté(s): 2

      Processus mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Module(s) mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Clé(s) du Registre infectée(s):
      HKEY_LOCAL_MACHINE\SOFTWARE\avsoft (Trojan.Fraudpack) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\Software\avsoft (Trojan.Fraudpack) -> Quarantined and deleted successfully.

      Valeur(s) du Registre infectée(s):
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\eggqoudn (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\eggqoudn (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.

      Elément(s) de données du Registre infecté(s):
      (Aucun élément nuisible détecté)

      Dossier(s) infecté(s):
      (Aucun élément nuisible détecté)

      Fichier(s) infecté(s):
      C:\Documents and Settings\Hélène\Local Settings\temp\VbMV.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Hélène\Local Settings\Temporary Internet Files\Content.IE5\74QEA867\eH4b9b1f77V0100f036002R2397d2b8102T001ca1fbQ000002fc901801F002d000aJ0f000601l000cK6d544b653180[1] (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      0
  12. benurrr Messages postés 9766 Statut Contributeur sécurité 107
     
    oui ouisa avance
    0
    1. helene
       
      super, ça remarche, je suis en mode normal et plus rien!!!
      merci mille fois, à toi et à tous ceux qui sont intervenus sur mon problème
      Je suis vraiment contente
      Merci à toute l'équipe de Comment ça marche, vous êtes tous dévoués, patients et pédagogues, sans oublier experts
      A bientôt
      Bises à tous
      helene

      Par contre, je ne vois plus mon antivirus???? ou dois-je le chercher??

      PS enfin j'espère être débarassée de ce virus!

      ############################# | UsbFix V6.097 |

      User : Hélène (Utilisateurs) # BUREAU
      Update on 20/02/2010 by El Desaparecido , C_XX & Chimay8
      Start at: 20:21:27 | 02/26/2010
      Website : http://pagesperso-orange.fr/NosTools/index.html
      Contact : FindyKill.Contact@gmail.com

      Intel(R) Pentium(R) 4 CPU 2.80GHz
      Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
      Internet Explorer 6.0.2900.5512
      Windows Firewall Status : Disabled
      AV : AntiVir Desktop 9.0.1.32 [ Enabled | (!) Outdated ]
      FW : Sunbelt Personal Firewall[ Enabled ]4.6.1861 T

      C:\ -> Disque fixe local # 149,01 Go (82,81 Go free) # NTFS
      D:\ -> Disque amovible
      E:\ -> Disque amovible
      F:\ -> Disque CD-ROM

      ############################## | Processus actifs |

      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\savedump.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
      C:\WINDOWS\system32\logonui.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Avira\AntiVir Desktop\sched.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\Program Files\Google\Update\GoogleUpdate.exe
      C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
      C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\MsPMSPSv.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\WINDOWS\System32\alg.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe
      C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
      C:\WINDOWS\system32\wscntfy.exe

      ################## | Elements infectieux |

      Supprimé ! C:\Recycler\S-1-5-21-1454471165-688789844-839522115-1005
      Supprimé ! C:\Recycler\S-1-5-21-1454471165-688789844-839522115-1006

      ################## | Registre |

      Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"
      Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"

      ################## | Mountpoints2 |


      ################## | Listing des fichiers présent |

      [01/31/2008 04:25|--a------|3328] C:\bitdefenden1201749835_1_02.xml
      [02/20/2006 11:21|-rahs----|216] C:\boot.ini
      [04/24/2003 13:00|-rahs----|4952] C:\Bootfont.bin
      [04/07/2005 13:34|--a------|0] C:\CONFIG.SYS
      [04/07/2005 13:58|--a------|39] C:\CTJINI.INI
      [02/03/2009 09:53|--a------|399] C:\DealioAu.log
      [06/23/2005 21:29|--a------|199] C:\hellbot.exe
      [02/24/2010 22:56|--a------|523] C:\hpfr3420.xml
      [02/24/2010 22:56|--a------|125502] C:\hpfr3425.log
      [10/08/2006 11:53|--ah-----|1594] C:\hpothb07.dat
      [10/08/2006 11:53|--ah-----|2985] C:\hpothb07.tif
      [10/14/2005 23:31|--a------|46] C:\hWaitEventRetryInstall
      [04/07/2005 13:34|-rahs----|0] C:\IO.SYS
      [04/07/2005 13:34|-rahs----|0] C:\MSDOS.SYS
      [09/20/2006 19:35|--a------|4158709] C:\myskin.pcb
      [02/20/2006 11:13|-rahs----|47564] C:\NTDETECT.COM
      [09/01/2008 11:46|-rahs----|252240] C:\ntldr
      [?|?|?] C:\pagefile.sys
      [04/07/2005 13:58|--a------|593] C:\pnpID.dat
      [03/08/2008 10:16|--a------|97680236] C:\Sauv.reg
      [01/10/2008 12:40|--a------|45] C:\TEST.XML
      [02/06/2006 00:19|--a------|1010] C:\tmpFile.dat
      [02/26/2010 20:27|--a------|3749] C:\UsbFix.txt

      ################## | Vaccination |

      # C:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).

      ################## | Upload |

      Veuillez envoyer le fichier : C:\UsbFix_Upload_Me_BUREAU.zip : https://www.ionos.fr/?affiliate_id=77097
      Merci pour votre contribution .
      0
  13. benurrr Messages postés 9766 Statut Contributeur sécurité 107
     
    encore quelque reste pour verifier

    pour l'antivirus t'inquiète la il tourne après un redémarrage ou un scan l'icône reapparaitra

    Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
    http://pagesperso-orange.fr/NosTools/C_XX/AD-R.exe
    * Lance l'installation du programme en exécutant le fichier téléchargé.( clic droit "exécuter en tant qu'administrateur" pour Vista/7 )
    * Double-clique ( clic droit "exécuter en tant qu'administrateur" pour Vista/7 ) maintenant sur le raccourci de Toolbar-S&D.
    * Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
    * Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
    * Poste le rapport généré. (C:\TB.txt)
    0
    1. helene
       
      on ne se quitte pas encore alors...
      c'est ad remover le truc que je dois lancer?
      0
  14. benurrr Messages postés 9766 Statut Contributeur sécurité 107
     
    oui
    0
    1. helene
       
      Voilà.
      ======= RAPPORT D'AD-REMOVER 1.1.4.6_J | UNIQUEMENT XP/VISTA/7 =======
      .
      Mis à jour par C_XX le 05.02.2010 à 17:34
      Contact: AdRemover.contact@gmail.com
      Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
      .
      Lancé à: 20:43:05, 02/26/2010 | Mode Normal | Option: SCAN
      Exécuté de: C:\Ad-Remover\
      Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
      Nom du PC: BUREAU | Utilisateur actuel: H‚lŠne
      .
      ============== ÉLÉMENT(S) TROUVÉ(S) ==============
      .

      C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\Dealio
      C:\Program Files\Dealio
      C:\Program Files\Search Settings
      C:\DOCUME~1\HLNE~1\APPLIC~1\Dealio
      C:\DOCUME~1\HLNE~1\APPLIC~1\Search Settings
      C:\Windows\Installer\424a7b.msi
      C:\Windows\Installer\424a82.msi
      C:\Documents and Settings\Serge\Application Data\Dealio
      C:\Documents and Settings\Serge\Application Data\EoRezo
      C:\Documents and Settings\Geoffroy\Application Data\EoRezo
      C:\Documents and Settings\Camille\Application Data\EoRezo
      C:\Documents and Settings\Camille\Camille.BUREAU\Application Data\EoRezo
      C:\Documents and Settings\Serge\Application Data\Search Settings
      .
      HKCU\software\Dealio
      HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F}
      HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F}
      HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
      HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F}
      HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F}
      HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
      HKCU\software\Search Settings
      HKLM\Software\Classes\CLSID\{6A87B991-A31F-4130-AE72-6D0C294BF082}
      HKLM\Software\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
      HKLM\Software\Classes\Interface\{D5A1EF9A-7948-435D-8B87-D6A598317288}
      HKLM\software\classes\SearchSettings.BHO
      HKLM\software\classes\SearchSettings.BHO.1
      HKLM\Software\Classes\TypeLib\{CD082CCA-086F-4FD8-8FD7-247A0DBBD1CC}
      HKLM\software\Dealio
      HKLM\Software\Microsoft\Internet Explorer\Extensions\{E908B145-C847-4e85-B315-07E2E70DECF8}
      HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F}
      HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F}
      HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6A87B991-A31F-4130-AE72-6D0C294BF082}
      HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\0292226F570267D459357AF78015E534
      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\03285961954D5824C85975D955031EE8
      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\6AC3985F4D64C2245A96D31569D1BF40
      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\855847FA0E25FBA46B8516389DFDD4B3
      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\9DC2844D0E3E8924C8973C3B3BAE1F58
      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\AFEB575AA30ACB243B748619F62F0782
      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\F461B8DD96FF5AA41A52D14E1D7B69C7
      HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\au
      HKLM\software\Search Settings
      HKU\s-1-5-21-1454471165-688789844-839522115-1005\software\Dealio
      HKU\s-1-5-21-1454471165-688789844-839522115-1005\software\Search Settings
      .
      ============== Scan additionnel ==============
      .
      .
      * Mozilla FireFox Version 3.6 [fr] *
      .
      Nom du profil: npj0mbfw.default (H‚lŠne)
      .
      (HLNE~1, prefs.js) Browser.download.lastDir, C:\Documents and Settings\Hélène\Mes documents
      (HLNE~1, prefs.js) Browser.search.defaultenginename, Google
      (HLNE~1, prefs.js) Browser.search.defaulturl, hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
      (HLNE~1, prefs.js) Browser.search.selectedEngine, Google
      (HLNE~1, prefs.js) Browser.startup.homepage, hxxp://news.google.fr
      (HLNE~1, prefs.js) Extensions.enabledItems, en-GB@dictionaries.addons.mozilla.org:1.19,{3112ca9c-de6d-4884-a869-9855de68056c}:6.1.20091119W,{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03,{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05,{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}:6.0.04,{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07,{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11,{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13,{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15,jqs@sun.com:1.0,{20a82645-c095-46ed-80e3-08825760534b}:1.1,{635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.2.20080910,{ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6
      .
      .
      * Internet Explorer Version 6.0.2900.5512 *
      .
      [HKEY_CURRENT_USER\..\Internet Explorer\Main]
      .
      Do404Search: 01000000
      Show_ToolBar: yes
      Start Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
      Search Page: hxxp://www.google.com
      Enable Browser Extensions: yes
      Local Page: C:\WINDOWS\system32\blank.htm
      Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
      Use Custom Search URL: 1 (0x1)
      Use Search Asst: no
      Search Bar: hxxp://www.google.com/ie
      First Home Page: hxxp://www.microsoft.com/isapi/redir.dll?Prd=ie&Pver=5.0&Ar=ie5update&O1=b1
      .
      [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
      .
      Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=69157
      Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
      Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
      Delete_Temp_Files_On_Exit: yes
      Local Page: C:\windows\system32\blank.htm
      Start Page: hxxp://fr.msn.com/
      Search Bar: hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
      .
      [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
      .
      Tabs: res://ieframe.dll/tabswelcome.htm
      .
      ===================================
      .
      6133 Octet(s) - C:\Ad-Report-SCAN[1].log
      .
      6 Fichier(s) - C:\DOCUME~1\HLNE~1\LOCALS~1\Temp
      10 Fichier(s) - C:\WINDOWS\Temp
      29 Fichier(s) - C:\WINDOWS\Prefetch
      .
      2 Fichier(s) - C:\Ad-Remover\BACKUP
      0 Fichier(s) - C:\Ad-Remover\QUARANTINE
      .
      Fin à: 21:26:41 | 02/26/2010 - SCAN[1]
      .
      ============== E.O.F ==============
      0
  15. benurrr Messages postés 9766 Statut Contributeur sécurité 107
     
    Nettoyage avec Ad-Remover :
    /!\ Déconnectes toi et fermes toutes applications en cours, désactive ton antivirus le temps de la manipulation/!\
    Double clique ( clic droit "exécuter en tant qu'administrateur" pour Vista/7 ) sur l’exécutable pour le lancer.
    Au message d’avertissement qui s’affiche, sélectionne ‘Oui’.
    Au menu principal choisi l’option "L" et tape ensuite sur la touche Entrée.Poste le rapport qui apparaît à la fin de l’analyse qui peut prendre du temps.
    (Le rapport est sauvegardé aussi sous C:\Ad-report(date).log)
    (CTRL+A Pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)
    0
    1. helene
       
      Le nettoyage est terminé
      Voici le rapport
      Je vais me coucher
      Je verrai demain la suite
      Déjà merci
      Bonne nuit
      helene
      ======= RAPPORT D'AD-REMOVER 1.1.4.6_J | UNIQUEMENT XP/VISTA/7 =======
      .
      Mis à jour par C_XX le 05.02.2010 à 17:34
      Contact: AdRemover.contact@gmail.com
      Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
      .
      Lancé à: 22:22:42, 02/26/2010 | Mode Normal | Option: CLEAN
      Exécuté de: C:\Ad-Remover\
      Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
      Nom du PC: BUREAU | Utilisateur actuel: H‚lŠne
      .
      ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
      .

      C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\Dealio
      C:\Program Files\Dealio
      C:\Program Files\Search Settings
      C:\DOCUME~1\HLNE~1\APPLIC~1\Dealio
      C:\DOCUME~1\HLNE~1\APPLIC~1\Search Settings
      C:\Windows\Installer\424a7b.msi
      C:\Windows\Installer\424a82.msi
      C:\Documents and Settings\Serge\Application Data\Dealio
      C:\Documents and Settings\Serge\Application Data\EoRezo
      C:\Documents and Settings\Geoffroy\Application Data\EoRezo
      C:\Documents and Settings\Camille\Application Data\EoRezo
      C:\Documents and Settings\Camille\Camille.BUREAU\Application Data\EoRezo
      C:\Documents and Settings\Serge\Application Data\Search Settings

      (!) -- Fichiers temporaires supprimés.

      .
      HKCU\software\Dealio
      HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F}
      HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
      HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F}
      HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
      HKCU\software\Search Settings
      HKLM\Software\Classes\CLSID\{6A87B991-A31F-4130-AE72-6D0C294BF082}
      HKLM\Software\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
      HKLM\Software\Classes\Interface\{D5A1EF9A-7948-435D-8B87-D6A598317288}
      HKLM\software\classes\SearchSettings.BHO
      HKLM\software\classes\SearchSettings.BHO.1
      HKLM\Software\Classes\TypeLib\{CD082CCA-086F-4FD8-8FD7-247A0DBBD1CC}
      HKLM\software\Dealio
      HKLM\Software\Microsoft\Internet Explorer\Extensions\{E908B145-C847-4e85-B315-07E2E70DECF8}
      HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F}
      HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6A87B991-A31F-4130-AE72-6D0C294BF082}
      HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\0292226F570267D459357AF78015E534
      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\03285961954D5824C85975D955031EE8
      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\6AC3985F4D64C2245A96D31569D1BF40
      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\855847FA0E25FBA46B8516389DFDD4B3
      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\9DC2844D0E3E8924C8973C3B3BAE1F58
      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\AFEB575AA30ACB243B748619F62F0782
      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\F461B8DD96FF5AA41A52D14E1D7B69C7
      HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\au
      HKLM\software\Search Settings
      .
      ============== Scan additionnel ==============
      .
      .
      * Mozilla FireFox Version 3.6 [fr] *
      .
      Nom du profil: npj0mbfw.default (H‚lŠne)
      .
      (HLNE~1, prefs.js) Browser.download.lastDir, C:\Documents and Settings\Hélène\Mes documents
      (HLNE~1, prefs.js) Browser.search.defaultenginename, Google
      (HLNE~1, prefs.js) Browser.search.defaulturl, hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
      (HLNE~1, prefs.js) Browser.search.selectedEngine, Google
      (HLNE~1, prefs.js) Browser.startup.homepage, hxxp://news.google.fr
      (HLNE~1, prefs.js) Extensions.enabledItems, en-GB@dictionaries.addons.mozilla.org:1.19,{3112ca9c-de6d-4884-a869-9855de68056c}:6.1.20091119W,{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03,{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05,{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}:6.0.04,{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07,{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11,{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13,{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15,jqs@sun.com:1.0,{20a82645-c095-46ed-80e3-08825760534b}:1.1,{635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.2.20080910,{ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6
      .
      .
      * Internet Explorer Version 6.0.2900.5512 *
      .
      [HKEY_CURRENT_USER\..\Internet Explorer\Main]
      .
      Do404Search: 01000000
      Show_ToolBar: yes
      Start Page: hxxp://fr.msn.com/
      Enable Browser Extensions: yes
      Local Page: C:\WINDOWS\system32\blank.htm
      Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
      Use Custom Search URL: 1 (0x1)
      Use Search Asst: no
      Search Bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
      Default_page_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
      .
      [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
      .
      Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
      Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
      Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
      Delete_Temp_Files_On_Exit: yes
      Local Page: C:\windows\system32\blank.htm
      Start Page: hxxp://fr.msn.com/
      Search Bar: hxxp://search.msn.com/spbasic.htm
      .
      [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
      .
      Tabs: res://ieframe.dll/tabswelcome.htm
      .
      ===================================
      .
      5703 Octet(s) - C:\Ad-Report-CLEAN[1].log
      6468 Octet(s) - C:\Ad-Report-SCAN[1].log
      .
      6 Fichier(s) - C:\DOCUME~1\HLNE~1\LOCALS~1\Temp
      9 Fichier(s) - C:\WINDOWS\Temp
      10 Fichier(s) - C:\WINDOWS\Prefetch
      .
      19 Fichier(s) - C:\Ad-Remover\BACKUP
      1476 Fichier(s) - C:\Ad-Remover\QUARANTINE
      .
      Fin à: 23:19:53 | 02/26/2010 - CLEAN[1]
      .
      ============== E.O.F ==============
      .
      0
  16. benurrr Messages postés 9766 Statut Contributeur sécurité 107
     
    excellent

    Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent(car il est detecté a tort comme infection)

    Télécharge et installe List&Kill'em et enregistre le sur ton bureau

    http://sd-1.archive-host.com/membres/up/829108531491024/List_Killem_Install.exe

    Branche clés usb , disques durs externes , mp3 , mp4 , etc..

    double clique ( clic droit "exécuter en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

    coche la case "créer une icône sur le bureau"

    une fois terminée , clic sur "terminer" et le programme se lancera seul

    choisis la langue puis choisis l'option 1 = Mode Recherche

    laisse travailler l'outil

    à l'apparition de la fenêtre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

    un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , mais ne le supprime pas pour l instant, le scan n'est pas fini.

    Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'écran "COMPLETED"
    0
    1. helene
       
      voici le dernier rapport
      merci pour tes commentaires

      List'em by g3n-h@ckm@n 1.2.8.1

      User : Hélène (Utilisateurs)
      Update on 26/02/2010 by g3n-h@ckm@n ::::: 14.30
      Start at: 11:09:39 | 02/27/2010
      Contact : https://forums.commentcamarche.net/forum/virus-securite-7

      Intel(R) Pentium(R) 4 CPU 2.80GHz
      Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
      Internet Explorer 6.0.2900.5512
      Windows Firewall Status : Disabled
      AV : AntiVir Desktop 9.0.1.32 [ (!) Disabled | Updated ]
      FW : Sunbelt Personal Firewall[ (!) Disabled ]4.6.1861 T

      C:\ -> Disque fixe local | 149,01 Go (82,73 Go free) | NTFS
      D:\ -> Disque amovible
      E:\ -> Disque amovible
      F:\ -> Disque CD-ROM

      Boot: Normal


      ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Avira\AntiVir Desktop\sched.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
      C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\MsPMSPSv.exe
      C:\WINDOWS\System32\alg.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
      C:\ATI-CPanel\atiptaxx.exe
      C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\Program Files\Skype\Phone\Skype.exe
      C:\Program Files\Skype\Plugin Manager\skypePM.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\Program Files\List_Kill'em\List_Kill'em.scr
      C:\WINDOWS\system32\cmd.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe
      C:\Documents and Settings\Hélène\Local Settings\temp\93.tmp\pv.exe

      ======================
      Keys "Run"
      ======================
      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      swg REG_SZ C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      Skype REG_SZ "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      ATIPTA REG_SZ C:\ATI-CPanel\atiptaxx.exe
      UserFaultCheck REG_EXPAND_SZ %systemroot%\system32\dumprep 0 -u
      avgnt REG_SZ "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
      TkBellExe REG_SZ "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

      =====================
      Other Keys
      =====================
      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
      dontdisplaylastusername REG_DWORD 0 (0x0)
      legalnoticecaption REG_SZ
      legalnoticetext REG_SZ
      shutdownwithoutlogon REG_DWORD 1 (0x1)
      undockwithoutlogon REG_DWORD 1 (0x1)
      HideLegacyLogonScripts REG_DWORD 0 (0x0)
      HideLogoffScripts REG_DWORD 0 (0x0)
      RunLogonScriptSync REG_DWORD 1 (0x1)
      RunStartupScriptSync REG_DWORD 0 (0x0)
      HideStartupScripts REG_DWORD 0 (0x0)

      ===============
      [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
      NoDriveAutoRun REG_DWORD 255 (0xff)
      NoDriveTypeAutoRun REG_DWORD 255 (0xff)
      HonorAutoRunSetting REG_DWORD 0 (0x0)

      ===============
      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
      AllowLegacyWebView REG_DWORD 1 (0x1)
      AllowUnhashedWebView REG_DWORD 1 (0x1)
      NoDriveTypeAutoRun REG_DWORD 255 (0xff)
      NoDriveAutoRun REG_DWORD 255 (0xff)
      HonorAutoRunSetting REG_DWORD 0 (0x0)

      ===============
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

      ===============
      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
      AutoRestartShell REG_DWORD 1 (0x1)
      DefaultDomainName REG_SZ BUREAU
      DefaultUserName REG_SZ Hélène
      LegalNoticeCaption REG_SZ
      LegalNoticeText REG_SZ
      PowerdownAfterShutdown REG_SZ 0
      ReportBootOk REG_SZ 1
      Shell REG_SZ explorer.exe
      ShutdownWithoutLogon REG_SZ 0
      System REG_SZ
      Userinit REG_SZ C:\WINDOWS\system32\userinit.exe,
      VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
      SfcQuota REG_DWORD -1 (0xffffffff)
      allocatecdroms REG_SZ 0
      allocatedasd REG_SZ 0
      allocatefloppies REG_SZ 0
      cachedlogonscount REG_SZ 10
      forceunlocklogon REG_DWORD 0 (0x0)
      passwordexpirywarning REG_DWORD 14 (0xe)
      scremoveoption REG_SZ 0
      AllowMultipleTSSessions REG_DWORD 1 (0x1)
      UIHost REG_EXPAND_SZ logonui.exe
      LogonType REG_DWORD 1 (0x1)
      Background REG_SZ 0 0 0
      DebugServerCommand REG_SZ no
      SFCDisable REG_DWORD 0 (0x0)
      WinStationsDisabled REG_SZ 0
      HibernationPreviouslyEnabled REG_DWORD 1 (0x1)
      ShowLogonOptions REG_DWORD 0 (0x0)
      AltDefaultUserName REG_SZ Hélène
      AltDefaultDomainName REG_SZ BUREAU
      ChangePasswordUseKerberos REG_DWORD 1 (0x1)
      SfcScan REG_DWORD 0 (0x0)

      ===============
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WgaLogon]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]

      ===============
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
      {AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ

      ===============
      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
      %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
      %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
      C:\Program Files\iTunes\iTunes.exe REG_SZ C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes
      C:\Program Files\Bonjour\mDNSResponder.exe REG_SZ C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour
      C:\Program Files\Skype\Plugin Manager\skypePM.exe REG_SZ C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager
      C:\Program Files\Skype\Phone\Skype.exe REG_SZ C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
      C:\Program Files\Windows Live\Messenger\livecall.exe REG_SZ C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)
      %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
      %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019

      ===============
      ActivX controls
      ===============
      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{17492023-C23A-453E-A040-C7C580BBF700}
      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{5D86DDB5-BDF9-441B-9E9E-D4730F4EE499}
      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}
      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}
      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}
      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{D27CDB6E-AE6D-11CF-96B8-444553540000}

      ===============
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{A34BA01E-226F-4702-AD75-AF5FBF21EB9F}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{0291E591-EA41-4c82-8106-3DC6CE7F7664}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{04d6265d-6b5d-41c3-9e7c-48be15919643}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{0fde1f56-0d59-4fd7-9624-e3df6b419d0e}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{0fde1f56-0d59-4fd7-9624-e3df6b419d0f}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{166B1BCA-3F9C-11CF-8075-444553540000}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{233C1507-6A77-46A4-9443-F871F945D258}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{283807B5-2C60-11D0-A31D-00AA00B92C03}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2A202491-F00D-11cf-87CC-0020AFEECF20}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{30528230-99F7-4BB4-88D8-FA1D4F56A2AB}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{347B0667-C7ED-429B-BDE3-CC8D3BACAA31}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{411EDCF7-755D-414E-A74B-3DCD6583F589}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4278c270-a269-11d1-b5bf-0000f8051515}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f216970-c90c-11d1-b5c7-0000f8051515}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5A8D6EE0-3E18-11D0-821E-444553540000}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5c9ff2bf-938d-47fe-85d9-9dbab4f65018}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5f3c70b3-ac2f-432c-8f9c-1624df61f54f}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{689e5762-8d75-4346-90cf-bc1902c32d63}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{79844cfb-ac65-4e10-a06a-c974234f40d0}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{82ced0ff-a00d-4405-ba5f-ef4699159333}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9A394342-4A68-4EBA-85A6-55B559F4E700}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{ae594d5e-dd07-4e54-8252-daa5aebbd4ec}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B508B3F1-A24A-32C0-B310-85786919EF28}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CC2A9BA0-3BDD-11D0-821E-444553540000}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11cf-96B8-444553540000}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{DAA94A2A-2A8D-4D3B-9DB8-56FBECED082D}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{eddbec60-89cb-44ef-8291-0850fd28ff6a}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{f5173cf0-1dfb-4978-8e50-a90169ee7ca9}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{F5776D81-AE53-4935-8E84-B0B283D8BCEF}

      ==============
      BHO :
      ======
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{C333CF63-767F-4831-94AC-E683D962C63C}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]

      ===
      DNS
      ===

      HKLM\SYSTEM\CCS\Services\Tcpip\..\{26E83445-8728-4A15-909A-73B41F7C0892}: DhcpNameServer=89.2.0.1 89.2.0.2
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{26E83445-8728-4A15-909A-73B41F7C0892}: DhcpNameServer=89.2.0.1 89.2.0.2
      HKLM\SYSTEM\CS2\Services\Tcpip\..\{26E83445-8728-4A15-909A-73B41F7C0892}: DhcpNameServer=89.2.0.1 89.2.0.2
      HKLM\SYSTEM\CS3\Services\Tcpip\..\{26E83445-8728-4A15-909A-73B41F7C0892}: DhcpNameServer=82.216.111.121 192.168.0.1
      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=89.2.0.1 89.2.0.2
      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=89.2.0.1 89.2.0.2
      HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=89.2.0.1 89.2.0.2
      HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=82.216.111.121 192.168.0.1

      ================
      Internet Explorer :
      ================
      [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
      Start Page REG_SZ https://www.msn.com/fr-fr

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
      Start Page REG_SZ https://www.msn.com/fr-fr

      ========
      Services
      ========
      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

      Ndisuio : 0x3 ( OK = 3 )
      EapHost : 0x3 ( OK = 2 )
      SharedAccess : 0x2 ( OK = 2 )
      wuauserv : 0x2 ( OK = 2 )

      =========
      Atapi.sys
      =========

      %%%% HASHDEEP-1.0
      %%%% size,md5,sha256,filename
      ## Invoked from: C:\Documents and Settings\Hélène\Local Settings\temp\93.tmp
      ## C:\> hashdeep.exe C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
      ##
      95360,cdfe4411a69c224bd1d11b2da92dac51,0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d,C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
      %%%% HASHDEEP-1.0
      %%%% size,md5,sha256,filename
      ## Invoked from: C:\Documents and Settings\Hélène\Local Settings\temp\93.tmp
      ## C:\> hashdeep.exe C:\WINDOWS\ServicePackFiles\i386\atapi.sys
      ##
      96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\ServicePackFiles\i386\atapi.sys
      %%%% HASHDEEP-1.0
      %%%% size,md5,sha256,filename
      ## Invoked from: C:\Documents and Settings\Hélène\Local Settings\temp\93.tmp
      ## C:\> hashdeep.exe C:\WINDOWS\system32\drivers\atapi.sys
      ##
      96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\system32\drivers\atapi.sys

      Référence :
      ==========

      Win 2000_SP2 : ff953a8f08ca3f822127654375786bbe
      Win XP_32b : a64013e98426e1877cb653685c5c0009
      Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
      Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
      Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
      Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
      Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
      Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
      Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
      Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C

      =======
      Drive :
      =======

      D‚fragmenteur de disque Windows
      Copyright (c) 2001 Microsoft Corp. et Executive Software International Inc.

      Rapport d'analyse
      149 Go total, 82,73 Go libre (55%), 25% fragment‚ (fragmentation du fichier 50%)

      Vous devriez d‚fragmenter ce volume.

      ¤¤¤¤¤¤¤¤¤¤ Files/folders :

      Present !! : C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
      Present !! : C:\WINDOWS\System32\_*.dll
      Present !! : C:\WINDOWS\System32\drivers\Cdaudio.sys
      Present !! : C:\WINDOWS\System32\rnaph.dll
      Present !! : C:\WINDOWS\System32\tmp.reg"
      Present !! : C:\Documents and Settings\H‚lŠne\LOCAL Settings\Temp\Perflib_Perfdata_990.dat

      ¤¤¤¤¤¤¤¤¤¤ Keys :

      Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
      Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"

      ============

      catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2010-02-27 12:02:48
      Windows 5.1.2600 Service Pack 3 NTFS

      scanning hidden processes ...

      scanning hidden services & system hive ...

      scanning hidden registry entries ...

      scanning hidden files ...

      scan completed successfully
      hidden processes: 0
      hidden services: 0
      hidden files: 0


      Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

      device: opened successfully
      user: MBR read successfully
      called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
      kernel: MBR read successfully
      user & kernel MBR OK

      ==========
      Programs
      ==========

      7-Zip
      a-squared Free
      aawsepersonal.exe
      Ad-remover
      Adobe
      Ahead
      Alwil Software
      AM-DeadLink
      APDFR
      Apple Software Update
      ArcSoft
      Autoruns
      Autoruns.zip
      Avira
      BitDefender
      BitZipper
      blank.gif
      Bonjour
      CleanUp!
      Common Files
      ComPlus Applications
      cqwydcgt.exe
      directx
      DivX
      eChanblard
      fdminst.exe
      Fichiers communs
      Foxit Software
      FrRefFra
      FrReform.exe
      GalleryPlayer Images
      GenuineCheck.exe
      GeoGebra(2)
      Ghostgum
      Google
      GoogleDesktopSetup.exe
      GoogleEarthWin.exe
      Hewlett-Packard
      Hip Interactive
      IE6
      IncrediMail
      Ink.msi
      InstallShield Installation Information
      instmsia.exe
      instmsiw.exe
      Internet Explorer
      Internet Usage Monitor Lite Edition
      InterVideo
      Intuwave Ltd
      iPod
      iTunes
      IZArc
      Java
      jv16 PowerTools
      licenses
      List_Kill'em
      Malwarebytes' Anti-Malware
      Messenger
      Microsoft
      microsoft frontpage
      Microsoft Office
      Microsoft Office(2)
      Microsoft Silverlight
      Microsoft SQL Server Compact Edition
      Microsoft Works
      Movie Maker
      Mozilla Firefox
      MSBuild
      MSECache
      MSN
      MSN Gaming Zone
      mst software
      MSXML 4.0
      NDP1.1sp1-KB867460-X86.exe
      NetMeeting
      OpenOffice.org 2.3
      OpenOffice.org 2.4
      openofficeorg1.cab
      openofficeorg2.cab
      openofficeorg21.msi
      openofficeorg22.msi
      openofficeorg3.cab
      openofficeorg4.cab
      OSCILLO
      Outlook Express
      Panasonic
      Philips
      Philips ToUcam Camera
      PhotoFiltre
      QuickTime
      rd2005trial.exe
      readmes
      Real
      Reference Assemblies
      serial.tde
      serial2
      Services en ligne
      setup.ini
      setupfre.exe
      SetupTrueDownloader.exe
      Sibelius Software
      SiSoftware
      Skype
      SopCast
      soref_regclean.exe
      Spybot - Search & Destroy
      spybotsd14.exe
      StartupList.exe
      startuplist.txt
      Startup_manager_2.0
      Startup_manager_2.0.zip
      stubinstaller.ini
      Sunbelt Software
      Symbian
      TGTSoft
      ThumbClic
      ThumbClic.zip
      Thumbs.db
      TI Education
      Trend Micro
      TVUPlayer
      Uninstall Information
      VideoLink Pro
      Virtools Web Player 3.5
      vista-inspirat-pack_vista_inspirat_pack_1.1_francais_15013.exe
      vLite
      WebLog Expert
      Windows Live
      Windows Live SkyDrive
      Windows Media Connect 2
      Windows Media Player
      Windows NT
      WindowsUpdate
      winMd5Sum
      WinRAR
      xerox
      Zero G Registry
      ZiPhone
      zlsSetup_65_725_000_fr.exe

      ============
      Drive C:
      ============

      $CTJTMP
      2095233f51f7db964e
      2e09703565345c472926bb9a700fb7
      327882R2FWJFW
      95893364180037fbbb81925e7a87
      Accessories
      Ad-Remover
      Ad-Report-CLEAN[1].log
      Ad-Report-SCAN[1].log
      ad9c5363644f768a6a557a96dbb0
      AddOn
      ATI-CPanel
      autorun.inf
      Backups
      bitdefenden1201749835_1_02.xml
      boot.ini
      Bootfont.bin c1d9505b5f8e2b9fd8e1
      cf742f19fc19ecaa7f1cfe1c9def860b
      Config.Msi
      CONFIG.SYS
      CTJINI.INI
      d257cd5ea34e60699cd442
      DealioAu.log
      Documentation en ligne
      Documents and Settings
      Downloads
      f65ea00c2824c2b36179b458fe0477
      hellbot.exe
      hijack
      hpfr3420.xml
      hpfr3425.log
      hpothb07.dat
      hpothb07.tif
      hWaitEventRetryInstall
      IO.SYS
      Kill'em
      List'em.txt
      Mes t‚l‚chargements
      MSDOS.SYS
      MSOCache
      myskin.pcb
      NTDETECT.COM
      ntldr
      pagefile.sys
      Panasonic
      pnpID.dat
      Program Files
      RECYCLER
      Sauv.reg
      System Volume Information
      teleir
      TEST.XML
      tmpFile.dat
      UsbFix
      UsbFix.txt
      UsbFix_Upload_Me_BUREAU.zip
      WINDOWS

      ¤¤¤¤¤¤¤¤¤¤ Cracks | Keygens | Serials





      ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

      End of scan : 12:23:15,79
      0
  17. benurrr Messages postés 9766 Statut Contributeur sécurité 107
     
    bonjour

    en arrive au bout du tunnel

    ▶ Relance List&Kill'em(soit en clic droit pour vista),avec le raccourci sur ton bureau.
    mais cette fois-ci :

    ▶ choisis l'option 2 = Mode Suppression

    laisse travailler l'outil.

    en fin de scan un rapport s'ouvre

    ▶ colle le contenu dans ta réponse

    ensuite :

    ▶ Relance List&Kill'em(soit en clic droit pour vista),avec le raccourci sur ton bureau.
    mais cette fois-ci :

    ▶ choisis l'option 6 = Restore MBR

    laisse travailler l'outil.

    en fin de scan un rapport s'ouvre

    ▶ colle le contenu dans ta réponse
    0
    1. helene
       
      Bonjour Benurr,

      Merci d'être encore là
      Est ce que je dois faire le mode suppression de List and Kill après avoir désactiver mon pare feu et mon antivirus comme pour la recherche???
      0
  18. benurrr Messages postés 9766 Statut Contributeur sécurité 107
     
    oui
    0
    1. helene
       
      ok
      0
    2. helene
       
      Me revoilà avec les 2 rapports
      Moi qui croyais que c'était fini depuis un moment!
      Est ce que maintenant on y voit plus clair??
      Merci
      Kill'em by g3n-h@ckm@n 1.2.8.1

      User : Hélène (Utilisateurs)
      Update on 26/02/2010 by g3n-h@ckm@n ::::: 14.30
      Start at: 17:29:23 | 02/27/2010
      Contact : https://forums.commentcamarche.net/forum/virus-securite-7

      Intel(R) Pentium(R) 4 CPU 2.80GHz
      Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
      Internet Explorer 6.0.2900.5512
      Windows Firewall Status : Disabled
      AV : AntiVir Desktop 9.0.1.32 [ (!) Disabled | Updated ]
      FW : Sunbelt Personal Firewall[ (!) Disabled ]4.6.1861 T

      C:\ -> Disque fixe local | 149,01 Go (84,08 Go free) | NTFS
      D:\ -> Disque amovible
      E:\ -> Disque amovible
      F:\ -> Disque CD-ROM


      ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Avira\AntiVir Desktop\sched.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
      C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\MsPMSPSv.exe
      C:\ATI-CPanel\atiptaxx.exe
      C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
      C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\Program Files\Skype\Phone\Skype.exe
      C:\WINDOWS\System32\alg.exe
      C:\Program Files\Skype\Plugin Manager\skypePM.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\Program Files\List_Kill'em\List_Kill'em.scr
      C:\WINDOWS\system32\cmd.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe
      C:\Documents and Settings\Hélène\Local Settings\temp\5A.tmp\ERUNT.EXE
      C:\Documents and Settings\Hélène\Local Settings\temp\5A.tmp\pv.exe

      Detections :
      ==========


      ¤¤¤¤¤¤¤¤¤¤ Files/folders :

      Quarantined & Deleted !! : C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache

      Quarantined & Deleted !! : C:\WINDOWS\System32\_Source21.Dll
      Quarantined & Deleted !! : C:\WINDOWS\System32\drivers\Cdaudio.sys
      Quarantined & Deleted !! : C:\WINDOWS\System32\rnaph.dll
      Quarantined & Deleted !! : C:\WINDOWS\System32\tmp.reg
      Quarantined & Deleted !! : C:\Documents and Settings\Hélène\LOCAL Settings\Temp\Perflib_Perfdata_460.dat

      ==============
      host file OK !
      ==============

      ========
      Registry
      ========

      Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
      Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
      ========
      Services
      =========

      Ndisuio : Start = 3
      EapHost : Start = 2
      Ip6Fw : Start = 2
      SharedAccess : Start = 2
      wuauserv : Start = 2
      wscsvc : Start = 2

      ============
      Disk Cleaned
      ============

      =================
      anti-ver blaster : OK !!
      =================

      ================
      Prefetch cleaned
      ================



      ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤






      Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

      device: opened successfully
      user: MBR read successfully
      kernel: MBR read successfully
      user & kernel MBR OK
      0
  19. benurrr Messages postés 9766 Statut Contributeur sécurité 107
     
    cool

    relance usbfix
    Double clic sur le raccourci UsbFix présent sur ton bureau

    Choisi l option 5 ( Désinstaller ) ....

    relance List&Kill'em.

    et choisie l'option 3 désinstallation

    ensuite

    pour nettoyer les fix qui ont servit

    Ferme toutes les applications en cours, puis télécharge ToolsCleaner2 sur ton Bureau.
    http://pc-system.fr/

    Double clique sur ToolsCleaner2.exe >
    puis Recherche
    et sur Suppression
    Note : ton bureau va disparaître, c'est normal. S'il n'apparaît pas à la fin du scan, fais la manip suivante :

    CTRL+ALT+SUPP pour ouvrir le Gestionnaire des tâches.
    Puis rends toi à l'onglet "Processus". Clique en haut à gauche sur Fichiers et choisis "Exécuter"

    Tape explorer.exe et valide. Cela fera re-apparaître le Bureau

    tu poste le rapport générer après suppression

    Par Manque De Curiosité On Risque De Mourir Ignorant;Tu es libre de penser que tu es C..,
    Mais C.. de penser que ­tu es libre...Merci a australe13
    0
    1. helene
       
      le bureau n' aps disparu
      est ce que c'est bon??

      [ Rapport ToolsCleaner version 2.3.11 (par A.Rothstein & dj QUIOU) ]

      --> Recherche:

      C:\UsbFix: trouvé !
      C:\Ad-remover: trouvé !
      C:\Ad-Remover\BACKUP\Ad-R.exe: trouvé !
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
      C:\Documents and Settings\Hélène\Bureau\HJTInstall.exe: trouvé !
      C:\Documents and Settings\Hélène\Bureau\Ad-R.exe: trouvé !
      C:\Documents and Settings\Hélène\Bureau\hijackthis.log: trouvé !
      C:\Documents and Settings\Hélène\Local Settings\temp\5A.tmp\catchme.exe: trouvé !
      C:\Documents and Settings\Hélène\Local Settings\temp\5A.tmp\mbr.exe: trouvé !
      C:\Documents and Settings\Hélène\Local Settings\temp\5D.tmp\catchme.exe: trouvé !
      C:\Documents and Settings\Hélène\Local Settings\temp\5D.tmp\mbr.log: trouvé !
      C:\Documents and Settings\Hélène\Local Settings\temp\5D.tmp\mbr.exe: trouvé !
      C:\Documents and Settings\Hélène\Menu Démarrer\Programmes\Ad-remover: trouvé !
      C:\Documents and Settings\Hélène\Menu Démarrer\Programmes\Ad-remover\Ad-remover.lnk: trouvé !
      C:\Program Files\Ad-remover: trouvé !
      C:\Program Files\Trend Micro\HijackThis: trouvé !
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
      C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !

      ---------------------------------
      --> Suppression:

      C:\Ad-Remover\BACKUP\Ad-R.exe: supprimé !
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
      C:\Documents and Settings\Hélène\Bureau\HJTInstall.exe: supprimé !
      C:\Documents and Settings\Hélène\Bureau\Ad-R.exe: supprimé !
      C:\Documents and Settings\Hélène\Local Settings\temp\5A.tmp\catchme.exe: supprimé !
      C:\Documents and Settings\Hélène\Local Settings\temp\5D.tmp\catchme.exe: supprimé !
      C:\Documents and Settings\Hélène\Menu Démarrer\Programmes\Ad-remover\Ad-remover.lnk: supprimé !
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
      C:\Documents and Settings\Hélène\Bureau\hijackthis.log: supprimé !
      C:\Documents and Settings\Hélène\Local Settings\temp\5A.tmp\mbr.exe: supprimé !
      C:\Documents and Settings\Hélène\Local Settings\temp\5D.tmp\mbr.log: supprimé !
      C:\Documents and Settings\Hélène\Local Settings\temp\5D.tmp\mbr.exe: supprimé !
      C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
      C:\UsbFix: supprimé !
      C:\Ad-remover: supprimé !
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
      C:\Documents and Settings\Hélène\Menu Démarrer\Programmes\Ad-remover: supprimé !
      C:\Program Files\Ad-remover: supprimé !
      C:\Program Files\Trend Micro\HijackThis: supprimé !
      0
  20. benurrr Messages postés 9766 Statut Contributeur sécurité 107
     
    Ok ,c'est bon malawarbyte et ccleaner tu les garde et sert toi s'en souvent

    tu va télécharger Ccleaner http://dl.commentcamarche.net/www.commentcamarche.net/download/files/ccsetup227_slim.exe

    ouvre "Ccleaner" vas dans l'onglet "Option" puis "Avancé" puis décoches "Effacer uniquement les fichiers, du dossier temp de Windows, plus vieux que 48 heures."

    . Puis vas dans l'onglet "Nettoyeur" fais "Analyse" puis "Lancer le nettoyage".
    Puis vas dans l'onglet "Registre" puis fait "Chercher des erreurs" puis "Réparer les erreurs sélectionnée"
    . Tu refais tous ca 4-5 fois (le nettoyage et le registre).

    Puis reste dans "Ccleaner" puis va dans "Option" puis "Propriété" puis coches "Nettoyer automatiquement l'ordinateur au démarrage".

    içi mode d'emploi pour ccleaner

    https://www.malekal.com/tutoriel-ccleaner/
    0
    1. helene
       
      Bonjour Benurr,

      Tout est fait, mon PC est-il propre maintenant??
      Encore merci pour tout
      Bonne continuation
      Et bon dimanche
      0
  21. benurrr Messages postés 9766 Statut Contributeur sécurité 107
     
    bonjour

    oui bon surf
    0
    1. helene
       
      Encore merci Benurr
      Deux dernières questions pour ne pas rester idiote: pourquoi alors que tout semblait être rentré dans l'ordre a-t-us continué à chercher? et pourquoi en mode sans échec avec la connexion, n'étais-je pas embêté par le virus?
      Bonne fin de journée
      Helene

      Comment je fais pour cloturer la discussion sur le forum en la marquant résolue??
      0
  • 1
  • 2