Probleme avecc MBAM

Bonjour,
Ces jours cis, en voulant faire une analyse complete de mon pc grace à l'antivirus Malwarebyte entimalware, je ressens que mon pc devient lent, aucun de mes programmes ne s'execunte et il commence à buger jusqu'à ce qu'il m'affiche un ecran bleu
cependant quand je change de session sur le meme pc, le preobleme n'existe plus
Serai ce un virus ???
aidez moi
et merci

22 réponses

Résumé de la discussion

Une analyse complète du PC avec l'antivirus déclenche un ralentissement et des plantages, l'écran bleu survient, mais le problème n'apparaît plus lors d'un changement de session. Plusieurs éléments du fil évoquent une infection détectée par UsbFix et des suppressions de fichiers suspects, avec un rapport détaillant des éléments infectieux et des entrées registry modifiées. Des interventions recommandées incluent sauvegarder les données, puis réinstaller ou formater et vérifier l'existence d'un CD Windows ou d'un support de récupération compatible pour rétablir le fonctionnement. D'autres indications soulignent que le souci peut dissimuler une corruption des outils de détection ou des conflits logiciels, d'où l'importance de tester en mode sans échec et d'utiliser des outils complémentaires.

Bobot (l’IA à votre service)
  1. bonjour MBAM n'est pas un antivirus ces un antispyware en version gratuite il n'offre aucune protection

    pour cerner ton infection

    Télécharge ZHPDiag ( de Nicolas coolman ).
    https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html

    (outil de diagnostic)

    Double clique sur le fichier d'installation, puis installe le avec les paramètres par défaut ( N'oublie pas de cocher " Créer une icône sur le bureau " )

    Lance ZHPDiag en double cliquant sur l'icône présente sur ton bureau (Clique droit -> Executer en tant qu'admin pour vista )

    Clique sur la loupe en haut à gauche, puis laisse l'outil scanner.

    Une fois le scan terminé, clique sur l'icône en forme de disquette et enregistre le fichier sur ton bureau.

    Rend toi sur Cjoint : http://www.cijoint.fr/

    Clique sur "Parcourir " dans la partie " Joindre un fichier[...] "

    Sélectionne le rapport ZHPdiag.txt qui se trouve sur ton bureau

    Clique ensuite sur "Cliquez ici pour déposer le fichier " et copie/colle le lien dans ton prochain message

    si le message ne passe pas sur le forum utilise ceci https://www.cjoint.com/
    0
    1. Bonjour,
      voila le lien
      http://www.cijoint.fr/cjlink.php?file=cj201004/cij2hdGw5L.txt

      et merci
      que dois je faire ???
      0
      1. Imperatif sous vista ==> Désactiver l'UAC

        https://www.commentcamarche.net/informatique/windows/261-desactiver-le-controle-de-compte-d-utilisateur-uac-de-windows/

        --> Télécharge UsbFix (par El Desaparecido & C_XX) sur ton Bureau.

        --> Branche tes sources de données externes à ton PC (clé USB, disque dur externe, carte SD, etc...) sans les ouvrir.

        --> Double-clique sur le programme UsbFix situé sur ton Bureau.

        --> Choisis l'option 1 (Recherche).

        --> Laisse travailler l'outil.

        --> Poste le rapport UsbFix.txt.

        Note : le rapport UsbFix.txt est sauvegardé à la racine du disque (C:\UsbFix.txt).

        "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
        0
        1. Voila le rapport

          ############################## | UsbFix V6.108 |

          User : Abdelali (Administrateurs) # PC-DE-ABDELALI
          Update on 23/04/2010 by El Desaparecido , C_XX & Chimay8
          Start at: 14:30:36 | 24/04/2010
          Website : http://pagesperso-orange.fr/NosTools/index.html
          Contact : FindyKill.Contact@gmail.com

          Pentium(R) Dual-Core CPU T4200 @ 2.00GHz
          Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
          Internet Explorer 8.0.6001.18904
          Windows Firewall Status : Enabled
          AV : BitDefender Antivirus 12.0 [ Enabled | Updated ]
          FW : Pare-feu BitDefender [ Enabled ]12.0

          C:\ -> Disque fixe local # 222,26 Go (59,11 Go free) # NTFS
          D:\ -> Disque fixe local # 10,62 Go (1,79 Go free) [RECOVERY] # NTFS
          E:\ -> Disque CD-ROM
          F:\ -> Disque amovible # 3,74 Go (2,12 Go free) # FAT32

          ################## | Elements infectieux |

          ################## | Registre |

          [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\policies\System] "DisableRegistryTools"
          [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\policies\System] "DisableTaskMgr"
          [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\policies\System] "DisableRegistryTools"
          [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\policies\System] "DisableTaskMgr"
          [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"
          [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"

          ################## | Mountpoints2 |

          HKCU\..\..\Explorer\MountPoints2\{02e621b7-31b2-11df-870e-9d4c22ab4d0c}
          shell\AutoRun\command =

          HKCU\..\..\Explorer\MountPoints2\{12d2cde2-30b9-11df-b5a0-e25efe1e949e}
          shell\AutoRun\command =
          shell\open\command =

          HKCU\..\..\Explorer\MountPoints2\{489cb259-319c-11df-97b2-c56835c0340c}
          shell\AutoRun\command =

          HKCU\..\..\Explorer\MountPoints2\{489cb27b-319c-11df-97b2-c56835c0340c}
          shell\AutoRun\command =

          HKCU\..\..\Explorer\MountPoints2\{489cb27d-319c-11df-97b2-c56835c0340c}
          shell\AutoRun\command =

          HKCU\..\..\Explorer\MountPoints2\{489cb2a3-319c-11df-97b2-c56835c0340c}
          shell\AutoRun\command =

          HKCU\..\..\Explorer\MountPoints2\{7e937956-bd62-11de-bb8b-9ce66f434892}
          shell\AutoRun\command =

          HKCU\..\..\Explorer\MountPoints2\{bba67016-d999-11de-8477-b9524c43332c}
          shell\AutoRun\command =

          HKCU\..\..\Explorer\MountPoints2\{eac35c1b-31a0-11df-8c99-e28b92e6e50f}
          shell\AutoRun\command =

          HKCU\..\..\Explorer\MountPoints2\{eac35c49-31a0-11df-8c99-e28b92e6e50f}
          shell\AutoRun\command =

          ################## | Vaccin |

          # C:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
          # D:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
          # F:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).

          ################## | ! Fin du rapport # UsbFix V6.108 ! |
          0
          1. Suppression

            Branche tes sources de données externes à ton PC, (clé USB, disque dur externe......) susceptibles d'avoir été infectés sans les ouvrir

            (1) Double clic sur le raccourci UsbFix présent sur ton bureau

            (2) Choisi l option 2 ( Suppression )

            Ton bureau disparaitra et le pc redémarrera .

            Au redémarrage , UsbFix scannera ton pc , laisse travailler l outil.

            Ensuite poste le rapport UsbFix.txt qui apparaitra avec le bureau .

            Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

            ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
            0
            1. bonjour,
              voila le rapport de usbfix apres suppression
              ############################## | UsbFix V6.108 |

              User : Abdelali (Administrateurs) # PC-DE-ABDELALI
              Update on 23/04/2010 by El Desaparecido , C_XX & Chimay8
              Start at: 15:32:45 | 24/04/2010
              Website : http://pagesperso-orange.fr/NosTools/index.html
              Contact : FindyKill.Contact@gmail.com

              Pentium(R) Dual-Core CPU T4200 @ 2.00GHz
              Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
              Internet Explorer 8.0.6001.18904
              Windows Firewall Status : Enabled
              AV : BitDefender Antivirus 12.0 [ Enabled | Updated ]
              FW : Pare-feu BitDefender [ Enabled ]12.0

              C:\ -> Disque fixe local # 222,26 Go (58,95 Go free) # NTFS
              D:\ -> Disque fixe local # 10,62 Go (1,79 Go free) [RECOVERY] # NTFS
              E:\ -> Disque CD-ROM
              F:\ -> Disque amovible # 3,74 Go (2,12 Go free) # FAT32

              ################## | Elements infectieux |

              Supprimé ! C:\$Recycle.Bin\S-1-5-21-1053870860-4224898397-3916119968-1000
              Supprimé ! C:\$Recycle.Bin\S-1-5-21-1053870860-4224898397-3916119968-1005
              Supprimé ! C:\$Recycle.Bin\S-1-5-21-1053870860-4224898397-3916119968-501
              Supprimé ! D:\$Recycle.Bin\S-1-5-21-1053870860-4224898397-3916119968-1000
              Supprimé ! D:\$Recycle.Bin\S-1-5-21-1053870860-4224898397-3916119968-1005
              Supprimé ! D:\$Recycle.Bin\S-1-5-21-1053870860-4224898397-3916119968-501

              ################## | Registre |

              Supprimé ! [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\policies\System] "DisableRegistryTools"
              Supprimé ! [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\policies\System] "DisableTaskMgr"
              Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"
              Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"

              ################## | Mountpoints2 |

              Supprimé ! HKCU\...\Explorer\MountPoints2\{02e621b7-31b2-11df-870e-9d4c22ab4d0c}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{12d2cde2-30b9-11df-b5a0-e25efe1e949e}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{489cb259-319c-11df-97b2-c56835c0340c}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{489cb27b-319c-11df-97b2-c56835c0340c}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{489cb27d-319c-11df-97b2-c56835c0340c}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{489cb2a3-319c-11df-97b2-c56835c0340c}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{7e937956-bd62-11de-bb8b-9ce66f434892}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{bba67016-d999-11de-8477-b9524c43332c}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{eac35c1b-31a0-11df-8c99-e28b92e6e50f}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{eac35c49-31a0-11df-8c99-e28b92e6e50f}\Shell\AutoRun\Command

              ################## | Listing des fichiers présent |

              [15/03/2010 19:12|--a------|4] C:\autoexec.bat
              [16/03/2010 20:10|--a------|13406] C:\bdlog.txt
              [11/04/2009 06:36|-rahs----|333257] C:\bootmgr
              [18/09/2006 21:43|--a------|10] C:\config.sys
              [08/12/2009 22:09|-ra------|14139] C:\Degre2.zip
              [07/11/2007 08:00|--a------|17734] C:\eula.1028.txt
              [07/11/2007 08:00|--a------|17734] C:\eula.1031.txt
              [07/11/2007 08:00|--a------|10134] C:\eula.1033.txt
              [07/11/2007 08:00|--a------|17734] C:\eula.1036.txt
              [07/11/2007 08:00|--a------|17734] C:\eula.1040.txt
              [07/11/2007 08:00|--a------|118] C:\eula.1041.txt
              [07/11/2007 08:00|--a------|17734] C:\eula.1042.txt
              [07/11/2007 08:00|--a------|17734] C:\eula.2052.txt
              [07/11/2007 08:00|--a------|17734] C:\eula.3082.txt
              [14/03/2010 13:20|--a------|4557] C:\FyK.txt
              [07/11/2007 08:00|--a------|1110] C:\globdata.ini
              [?|?|?] C:\hiberfil.sys
              [08/01/2010 17:09|--a------|132] C:\httpdwl.dat
              [07/11/2007 08:00|--a------|843] C:\install.ini
              [07/11/2007 08:03|--a------|76304] C:\install.res.1028.dll
              [07/11/2007 08:03|--a------|96272] C:\install.res.1031.dll
              [07/11/2007 08:03|--a------|91152] C:\install.res.1033.dll
              [07/11/2007 08:03|--a------|97296] C:\install.res.1036.dll
              [07/11/2007 08:03|--a------|95248] C:\install.res.1040.dll
              [07/11/2007 08:03|--a------|81424] C:\install.res.1041.dll
              [07/11/2007 08:03|--a------|79888] C:\install.res.1042.dll
              [07/11/2007 08:03|--a------|75792] C:\install.res.2052.dll
              [07/11/2007 08:03|--a------|96272] C:\install.res.3082.dll
              [22/08/2009 16:15|-rahs----|0] C:\IO.SYS
              [14/03/2010 23:36|--a------|26505] C:\List'em.txt
              [27/06/2008 17:00|---h-----|8682] C:\MessengerStyleSheet.xsl
              [22/08/2009 16:15|-rahs----|0] C:\MSDOS.SYS
              [?|?|?] C:\pagefile.sys
              [26/02/2010 15:55|--a------|11] C:\trace.ini
              [24/04/2010 15:42|--a------|4685] C:\UsbFix.txt
              [31/03/2010 11:22|--a------|6611] C:\UsbFix_Upload_Me_PC-de-Abdelali.zip
              [07/11/2007 08:00|--a------|5686] C:\vcredist.bmp
              [07/11/2007 08:09|--a------|1442522] C:\VC_RED.cab
              [07/11/2007 08:12|--a------|232960] C:\VC_RED.MSI
              [19/08/2009 11:55|---hs----|13] D:\BLOCK.RIN
              [03/10/2006 21:02|---hs----|438328] D:\bootmgr
              [04/11/2008 15:37|---hs----|1199] D:\Desktop.ini
              [10/09/2002 14:14|---hs----|8134] D:\Folder.htt
              [24/04/2010 15:32|--ahs----|196] D:\MASTER.LOG
              [12/09/2008 15:17|---hs----|381873] D:\protect.arabic
              [15/09/2008 13:57|---hs----|182624] D:\protect.bulgarian
              [16/09/2002 12:37|---hs----|181898] D:\protect.chinese hong kong
              [16/09/2002 12:37|---hs----|181916] D:\protect.chinese simplified
              [16/09/2002 12:37|---hs----|181898] D:\protect.chinese traditional
              [27/04/2006 14:19|---hs----|181865] D:\protect.czech
              [03/11/2005 13:21|---hs----|181726] D:\protect.danish
              [10/09/2002 11:56|---hs----|181605] D:\protect.dutch
              [10/09/2002 11:50|---hs----|181651] D:\protect.ed
              [22/11/2004 13:28|---hs----|181648] D:\protect.english
              [03/11/2005 13:20|---hs----|181673] D:\protect.finnish
              [03/11/2005 13:19|---hs----|181736] D:\protect.french
              [03/11/2005 13:18|---hs----|181669] D:\protect.german
              [23/11/2005 13:56|---hs----|182689] D:\protect.greek
              [23/01/2006 07:18|---hs----|182605] D:\protect.hebrew
              [28/08/2007 12:58|---hs----|181696] D:\protect.hungarian
              [03/11/2005 13:17|---hs----|181554] D:\protect.italian
              [19/06/2007 13:22|---hs----|182351] D:\protect.japanese
              [24/11/2005 09:24|---hs----|218295] D:\protect.korean
              [03/11/2005 13:15|---hs----|181578] D:\protect.norwegian
              [25/04/2006 12:44|---hs----|181789] D:\protect.polish
              [03/11/2005 13:13|---hs----|181624] D:\protect.portuguese
              [27/10/2005 17:24|---hs----|181882] D:\protect.portuguese brazilian
              [15/09/2008 13:57|---hs----|181735] D:\protect.romanian
              [28/06/2004 06:52|---hs----|211936] D:\protect.russian
              [04/07/2007 09:46|---hs----|181954] D:\protect.slovak
              [03/11/2005 13:11|---hs----|181586] D:\protect.spanish
              [10/09/2002 12:15|---hs----|181602] D:\protect.swedish
              [12/08/2003 08:37|---hs----|181783] D:\protect.turkish
              [24/04/2010 15:26|--a------|1232] F:\EncFiltLog.menc
              [06/04/2010 21:50|--a------|4388711] F:\DSC01711.JPG
              [24/04/2010 10:58|--ah-----|1249280] F:\album.vol
              [01/09/2009 03:09|--a------|647168] F:\pim.vol
              [01/02/2010 01:06|--a------|15793] F:\Oreille.docx
              [05/10/2009 18:14|--a------|5207742] F:\02-celine_dion-alone.mp3
              [11/01/2010 03:20|--a------|6444] F:\aya.jpg
              [10/04/2010 19:06|--a------|88814627] F:\ppc_9.1.24(3).zip
              [ | | ] F:\
              [18/02/2010 10:03|--a------|784179] F:\_SynthSse.pdf
              [31/08/2009 06:34|--a------|102400] F:\fbmail.vol
              [20/03/2010 21:37|--a------|296] F:\WMPInfo.xml
              [15/01/2010 01:50|--ah-----|1016] F:\album.cache
              [20/08/2009 18:05|--a------|16613133] F:\Quand chaque photo.pptx
              [14/04/2010 22:57|--a------|2623920] F:\WindowsSideShowforWindowsMobile.exe
              [22/09/2009 14:35|--a------|296870] F:\sheduler.log
              [06/04/2010 22:04|--a------|3154605] F:\livre-micro-comp2.pdf
              [17/04/2010 19:03|--a------|9947] F:\EugSne Ionesco,Notes.docx
              [12/12/2009 11:10|--a------|5764896] F:\paco de lucia - cafe del mar guitar more spanish - entre dos aguas.mp3
              [30/10/2009 15:41|--a------|5369451] F:\inspiration.mp3
              [19/01/2010 12:16|--a------|5913043] F:\habla me81.mp3
              [22/09/2009 11:53|--a------|94801] F:\WorldMateLive.Log
              [27/12/2009 22:02|--a------|8037146] F:\01 mnin ana w mnin nta.wma
              [27/12/2009 22:01|--a------|11867762] F:\04 Mali.wma
              [21/01/2010 01:20|--a------|220856] F:\07112009033.jpg
              [20/07/2009 21:53|--a------|2681251] F:\14 - I Can't Stop Loving You.mp3
              [11/01/2010 03:21|--a------|5811] F:\Lui.jpg
              [01/03/2010 11:50|--a------|6822] F:\DeuxFormulaire.pdf
              [15/01/2010 00:06|--a------|35840] F:\Times New Roman.doc
              [06/01/2010 22:44|--a------|10008258] F:\1_02 Omar Faruk Tekbilek - I love you.mp3
              [31/12/2009 18:09|--a------|8733416] F:\Buddha-Bar 5 by David Visan - Dinner - 13 - Alihan Samedov 'Sen Gelmez Oldun'.mp3
              [19/01/2010 23:49|--a------|67386] F:\kenza-r@live.fr(1).html
              [19/01/2010 23:04|--a------|8218] F:\miss-brooke_davis@hotmail.fr.html
              [01/12/2009 23:18|--a------|5660672] F:\keane - somewhere only we know.mp3
              [09/03/2009 11:54|--a------|11463857] F:\Anesthesia_for_Congenital_Heart_Disease.pdf
              [28/01/2010 21:12|--a------|57804] F:\kenza-r@live.fr.html
              [25/01/2010 21:23|--a------|4231296] F:\Richard_Marx_-_Right_Here_Waiting.mp3
              [01/02/2010 06:41|--a------|51520] F:\kenza-r@live.fr3.html
              [18/11/2009 23:42|--a------|5073546] F:\Said Mosker madanit.mp3
              [01/02/2010 01:06|--a------|168310] F:\kenza-r@live.fr3(1).html
              [13/11/2009 01:06|--a------|24842535] F:\10 - happy ending + ring-ring203.mp3
              [10/03/2010 20:29|--a------|4822456] F:\groupe kelma - warda 3la warda.mp3
              [05/04/2009 14:17|--a------|8974464] F:\06 what goes around _ comes arou(2).mp3
              [02/03/2010 01:57|--a------|18012] F:\Approche m'caniste et psychosociologiques des organisations.docx
              [21/01/2010 22:22|--a------|11461] F:\conf'rence.docx
              [26/10/2009 23:01|--a------|4420441] F:\Istanbul Benden B y k.mp3
              [16/03/2010 19:45|--a------|382560] F:\france24-s60v3.sisx
              [18/03/2010 08:14|--a------|802352] F:\kmsecurity_8_0_0_75_fr.cab
              [17/01/2010 22:19|--a------|44295938] F:\Le Prince Bleu_1.avi
              [21/01/2010 22:09|--a------|11856] F:\textes projet conf'rence sur la r'gionalisation.docx
              [17/01/2010 22:18|--a------|50819042] F:\Je rǸvise (Je rǸalise).avi
              [05/02/2010 21:11|--a------|34625] F:\Doc1.docx
              [08/02/2010 11:52|--a------|24903] F:\Plan Word.docx
              [10/02/2010 09:59|--a------|13545] F:\Seuil et taux avec Excel.docx
              [12/03/2010 23:38|--a------|5408356] F:\nouri-lbare7.mp3
              [19/01/2010 17:11|--a------|10415] F:\La politique de r'gionalisation a 't' con#ue afin de lutter contre les in'galit's de d'veloppement des diverses parties du royaume.docx
              [23/01/2010 17:27|--a------|26624] F:\Une des difficult's principales de l.doc
              [23/01/2010 17:24|--a------|26624] F:\Plus de d'bats.doc
              [23/01/2010 21:53|--a------|6171690] F:\L'Envie D'Aimer - Les dix commandements.mp3
              [02/03/2010 23:37|--a------|6514939] F:\Med Ziani Ad Lewis Wake UP Morocco New Version 2009.mp3
              [19/10/2009 23:16|--a------|5415706] F:\Marc Lavoine - La semaine prochaine (clip officiel).mp3
              [05/11/2009 22:29|--a------|6044735] F:\PIERRE BACHELET _ MARIONNETTISTE _.mp3
              [17/01/2010 22:25|--a------|114821764] F:\I love you_Omer Faruk Tekbilek.avi
              [11/11/2009 00:25|--a------|33672280] F:\Les EnfoirǸs - Ici Les EnfoirǸs - une vidǸo Musique.avi
              [11/11/2009 21:48|--a------|58698534] F:\Sum 41 - With Me (Clip officiel) - une vidǸo Musique.avi
              [18/02/2010 20:10|--a------|71556992] F:\The Submarines - You_ Me_ and the Bourgeoisie (iPhone 3G ad song).avi
              [10/03/2010 22:33|--a------|9686727] F:\hazou bina laalam haja hamdaouia.mp3
              [31/12/2009 22:02|--a------|5319053] F:\Junesex - Are U gonna dance.mp3
              [30/12/2009 22:32|--a------|3717225] F:\Keren Rose - La Liste - une vidǸo Musique.mp3
              [28/08/2009 18:10|--a------|46861] F:\$REFZ41S.jpg
              [16/03/2010 19:46|--a------|237628] F:\france24-uiq3.sis
              [11/12/2007 14:39|--a------|297846] F:\kavmobile_ppc_50_6_0_0_62_fr.cab
              [02/11/2009 13:27|--a------|499489] F:\La Communication externe.pptx
              [23/10/2009 00:01|--a------|5742256] F:\copie de shayne ward - no promises.mp3
              [15/11/2009 23:49|--a------|6404096] F:\AlexUnder Base Feat. Frissco - Privacy (Radio Edit).mp3
              [14/12/2009 12:25|--a------|21017] F:\Les nouvelles technologies de communication regroupent un ensemble de ressources n'cessaires pour manipuler de l.docx
              [15/12/2009 22:14|--a------|71070] F:\Es-snoussi Abdelali GroupeD word.docx

              ################## | Vaccination |

              # C:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
              # D:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
              # F:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).

              s'il vous plais, que dois je faire mtn ????
              0
              1. Bon, voilà le rapport apres suppression:

                ############################## | UsbFix V6.108 |

                User : Abdelali (Administrateurs) # PC-DE-ABDELALI
                Update on 23/04/2010 by El Desaparecido , C_XX & Chimay8
                Start at: 15:32:45 | 24/04/2010
                Website : http://pagesperso-orange.fr/NosTools/index.html
                Contact : FindyKill.Contact@gmail.com

                Pentium(R) Dual-Core CPU T4200 @ 2.00GHz
                Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
                Internet Explorer 8.0.6001.18904
                Windows Firewall Status : Enabled
                AV : BitDefender Antivirus 12.0 [ Enabled | Updated ]
                FW : Pare-feu BitDefender [ Enabled ]12.0

                C:\ -> Disque fixe local # 222,26 Go (58,95 Go free) # NTFS
                D:\ -> Disque fixe local # 10,62 Go (1,79 Go free) [RECOVERY] # NTFS
                E:\ -> Disque CD-ROM
                F:\ -> Disque amovible # 3,74 Go (2,12 Go free) # FAT32

                ################## | Elements infectieux |

                Supprimé ! C:\$Recycle.Bin\S-1-5-21-1053870860-4224898397-3916119968-1000
                Supprimé ! C:\$Recycle.Bin\S-1-5-21-1053870860-4224898397-3916119968-1005
                Supprimé ! C:\$Recycle.Bin\S-1-5-21-1053870860-4224898397-3916119968-501
                Supprimé ! D:\$Recycle.Bin\S-1-5-21-1053870860-4224898397-3916119968-1000
                Supprimé ! D:\$Recycle.Bin\S-1-5-21-1053870860-4224898397-3916119968-1005
                Supprimé ! D:\$Recycle.Bin\S-1-5-21-1053870860-4224898397-3916119968-501

                ################## | Registre |

                Supprimé ! [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\policies\System] "DisableRegistryTools"
                Supprimé ! [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\policies\System] "DisableTaskMgr"
                Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"
                Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"

                ################## | Mountpoints2 |

                Supprimé ! HKCU\...\Explorer\MountPoints2\{02e621b7-31b2-11df-870e-9d4c22ab4d0c}\Shell\AutoRun\Command
                Supprimé ! HKCU\...\Explorer\MountPoints2\{12d2cde2-30b9-11df-b5a0-e25efe1e949e}\Shell\AutoRun\Command
                Supprimé ! HKCU\...\Explorer\MountPoints2\{489cb259-319c-11df-97b2-c56835c0340c}\Shell\AutoRun\Command
                Supprimé ! HKCU\...\Explorer\MountPoints2\{489cb27b-319c-11df-97b2-c56835c0340c}\Shell\AutoRun\Command
                Supprimé ! HKCU\...\Explorer\MountPoints2\{489cb27d-319c-11df-97b2-c56835c0340c}\Shell\AutoRun\Command
                Supprimé ! HKCU\...\Explorer\MountPoints2\{489cb2a3-319c-11df-97b2-c56835c0340c}\Shell\AutoRun\Command
                Supprimé ! HKCU\...\Explorer\MountPoints2\{7e937956-bd62-11de-bb8b-9ce66f434892}\Shell\AutoRun\Command
                Supprimé ! HKCU\...\Explorer\MountPoints2\{bba67016-d999-11de-8477-b9524c43332c}\Shell\AutoRun\Command
                Supprimé ! HKCU\...\Explorer\MountPoints2\{eac35c1b-31a0-11df-8c99-e28b92e6e50f}\Shell\AutoRun\Command
                Supprimé ! HKCU\...\Explorer\MountPoints2\{eac35c49-31a0-11df-8c99-e28b92e6e50f}\Shell\AutoRun\Command

                ################## | Listing des fichiers présent |

                [15/03/2010 19:12|--a------|4] C:\autoexec.bat
                [16/03/2010 20:10|--a------|13406] C:\bdlog.txt
                [11/04/2009 06:36|-rahs----|333257] C:\bootmgr
                [18/09/2006 21:43|--a------|10] C:\config.sys
                [08/12/2009 22:09|-ra------|14139] C:\Degre2.zip
                [07/11/2007 08:00|--a------|17734] C:\eula.1028.txt
                [07/11/2007 08:00|--a------|17734] C:\eula.1031.txt
                [07/11/2007 08:00|--a------|10134] C:\eula.1033.txt
                [07/11/2007 08:00|--a------|17734] C:\eula.1036.txt
                [07/11/2007 08:00|--a------|17734] C:\eula.1040.txt
                [07/11/2007 08:00|--a------|118] C:\eula.1041.txt
                [07/11/2007 08:00|--a------|17734] C:\eula.1042.txt
                [07/11/2007 08:00|--a------|17734] C:\eula.2052.txt
                [07/11/2007 08:00|--a------|17734] C:\eula.3082.txt
                [14/03/2010 13:20|--a------|4557] C:\FyK.txt
                [07/11/2007 08:00|--a------|1110] C:\globdata.ini
                [?|?|?] C:\hiberfil.sys
                [08/01/2010 17:09|--a------|132] C:\httpdwl.dat
                [07/11/2007 08:00|--a------|843] C:\install.ini
                [07/11/2007 08:03|--a------|76304] C:\install.res.1028.dll
                [07/11/2007 08:03|--a------|96272] C:\install.res.1031.dll
                [07/11/2007 08:03|--a------|91152] C:\install.res.1033.dll
                [07/11/2007 08:03|--a------|97296] C:\install.res.1036.dll
                [07/11/2007 08:03|--a------|95248] C:\install.res.1040.dll
                [07/11/2007 08:03|--a------|81424] C:\install.res.1041.dll
                [07/11/2007 08:03|--a------|79888] C:\install.res.1042.dll
                [07/11/2007 08:03|--a------|75792] C:\install.res.2052.dll
                [07/11/2007 08:03|--a------|96272] C:\install.res.3082.dll
                [22/08/2009 16:15|-rahs----|0] C:\IO.SYS
                [14/03/2010 23:36|--a------|26505] C:\List'em.txt
                [27/06/2008 17:00|---h-----|8682] C:\MessengerStyleSheet.xsl
                [22/08/2009 16:15|-rahs----|0] C:\MSDOS.SYS
                [?|?|?] C:\pagefile.sys
                [26/02/2010 15:55|--a------|11] C:\trace.ini
                [24/04/2010 15:42|--a------|4685] C:\UsbFix.txt
                [31/03/2010 11:22|--a------|6611] C:\UsbFix_Upload_Me_PC-de-Abdelali.zip
                [07/11/2007 08:00|--a------|5686] C:\vcredist.bmp
                [07/11/2007 08:09|--a------|1442522] C:\VC_RED.cab
                [07/11/2007 08:12|--a------|232960] C:\VC_RED.MSI
                [19/08/2009 11:55|---hs----|13] D:\BLOCK.RIN
                [03/10/2006 21:02|---hs----|438328] D:\bootmgr
                [04/11/2008 15:37|---hs----|1199] D:\Desktop.ini
                [10/09/2002 14:14|---hs----|8134] D:\Folder.htt
                [24/04/2010 15:32|--ahs----|196] D:\MASTER.LOG
                [12/09/2008 15:17|---hs----|381873] D:\protect.arabic
                [15/09/2008 13:57|---hs----|182624] D:\protect.bulgarian
                [16/09/2002 12:37|---hs----|181898] D:\protect.chinese hong kong
                [16/09/2002 12:37|---hs----|181916] D:\protect.chinese simplified
                [16/09/2002 12:37|---hs----|181898] D:\protect.chinese traditional
                [27/04/2006 14:19|---hs----|181865] D:\protect.czech
                [03/11/2005 13:21|---hs----|181726] D:\protect.danish
                [10/09/2002 11:56|---hs----|181605] D:\protect.dutch
                [10/09/2002 11:50|---hs----|181651] D:\protect.ed
                [22/11/2004 13:28|---hs----|181648] D:\protect.english
                [03/11/2005 13:20|---hs----|181673] D:\protect.finnish
                [03/11/2005 13:19|---hs----|181736] D:\protect.french
                [03/11/2005 13:18|---hs----|181669] D:\protect.german
                [23/11/2005 13:56|---hs----|182689] D:\protect.greek
                [23/01/2006 07:18|---hs----|182605] D:\protect.hebrew
                [28/08/2007 12:58|---hs----|181696] D:\protect.hungarian
                [03/11/2005 13:17|---hs----|181554] D:\protect.italian
                [19/06/2007 13:22|---hs----|182351] D:\protect.japanese
                [24/11/2005 09:24|---hs----|218295] D:\protect.korean
                [03/11/2005 13:15|---hs----|181578] D:\protect.norwegian
                [25/04/2006 12:44|---hs----|181789] D:\protect.polish
                [03/11/2005 13:13|---hs----|181624] D:\protect.portuguese
                [27/10/2005 17:24|---hs----|181882] D:\protect.portuguese brazilian
                [15/09/2008 13:57|---hs----|181735] D:\protect.romanian
                [28/06/2004 06:52|---hs----|211936] D:\protect.russian
                [04/07/2007 09:46|---hs----|181954] D:\protect.slovak
                [03/11/2005 13:11|---hs----|181586] D:\protect.spanish
                [10/09/2002 12:15|---hs----|181602] D:\protect.swedish
                [12/08/2003 08:37|---hs----|181783] D:\protect.turkish
                [24/04/2010 15:26|--a------|1232] F:\EncFiltLog.menc
                [06/04/2010 21:50|--a------|4388711] F:\DSC01711.JPG
                [24/04/2010 10:58|--ah-----|1249280] F:\album.vol
                [01/09/2009 03:09|--a------|647168] F:\pim.vol
                [01/02/2010 01:06|--a------|15793] F:\Oreille.docx
                [05/10/2009 18:14|--a------|5207742] F:\02-celine_dion-alone.mp3
                [11/01/2010 03:20|--a------|6444] F:\aya.jpg
                [10/04/2010 19:06|--a------|88814627] F:\ppc_9.1.24(3).zip
                [ | | ] F:\
                [18/02/2010 10:03|--a------|784179] F:\_SynthSse.pdf
                [31/08/2009 06:34|--a------|102400] F:\fbmail.vol
                [20/03/2010 21:37|--a------|296] F:\WMPInfo.xml
                [15/01/2010 01:50|--ah-----|1016] F:\album.cache
                [20/08/2009 18:05|--a------|16613133] F:\Quand chaque photo.pptx
                [14/04/2010 22:57|--a------|2623920] F:\WindowsSideShowforWindowsMobile.exe
                [22/09/2009 14:35|--a------|296870] F:\sheduler.log
                [06/04/2010 22:04|--a------|3154605] F:\livre-micro-comp2.pdf
                [17/04/2010 19:03|--a------|9947] F:\EugSne Ionesco,Notes.docx
                [12/12/2009 11:10|--a------|5764896] F:\paco de lucia - cafe del mar guitar more spanish - entre dos aguas.mp3
                [30/10/2009 15:41|--a------|5369451] F:\inspiration.mp3
                [19/01/2010 12:16|--a------|5913043] F:\habla me81.mp3
                [22/09/2009 11:53|--a------|94801] F:\WorldMateLive.Log
                [27/12/2009 22:02|--a------|8037146] F:\01 mnin ana w mnin nta.wma
                [27/12/2009 22:01|--a------|11867762] F:\04 Mali.wma
                [21/01/2010 01:20|--a------|220856] F:\07112009033.jpg
                [20/07/2009 21:53|--a------|2681251] F:\14 - I Can't Stop Loving You.mp3
                [11/01/2010 03:21|--a------|5811] F:\Lui.jpg
                [01/03/2010 11:50|--a------|6822] F:\DeuxFormulaire.pdf
                [15/01/2010 00:06|--a------|35840] F:\Times New Roman.doc
                [06/01/2010 22:44|--a------|10008258] F:\1_02 Omar Faruk Tekbilek - I love you.mp3
                [31/12/2009 18:09|--a------|8733416] F:\Buddha-Bar 5 by David Visan - Dinner - 13 - Alihan Samedov 'Sen Gelmez Oldun'.mp3
                [19/01/2010 23:49|--a------|67386] F:\kenza-r@live.fr(1).html
                [19/01/2010 23:04|--a------|8218] F:\miss-brooke_davis@hotmail.fr.html
                [01/12/2009 23:18|--a------|5660672] F:\keane - somewhere only we know.mp3
                [09/03/2009 11:54|--a------|11463857] F:\Anesthesia_for_Congenital_Heart_Disease.pdf
                [28/01/2010 21:12|--a------|57804] F:\kenza-r@live.fr.html
                [25/01/2010 21:23|--a------|4231296] F:\Richard_Marx_-_Right_Here_Waiting.mp3
                [01/02/2010 06:41|--a------|51520] F:\kenza-r@live.fr3.html
                [18/11/2009 23:42|--a------|5073546] F:\Said Mosker madanit.mp3
                [01/02/2010 01:06|--a------|168310] F:\kenza-r@live.fr3(1).html
                [13/11/2009 01:06|--a------|24842535] F:\10 - happy ending + ring-ring203.mp3
                [10/03/2010 20:29|--a------|4822456] F:\groupe kelma - warda 3la warda.mp3
                [05/04/2009 14:17|--a------|8974464] F:\06 what goes around _ comes arou(2).mp3
                [02/03/2010 01:57|--a------|18012] F:\Approche m'caniste et psychosociologiques des organisations.docx
                [21/01/2010 22:22|--a------|11461] F:\conf'rence.docx
                [26/10/2009 23:01|--a------|4420441] F:\Istanbul Benden B y k.mp3
                [16/03/2010 19:45|--a------|382560] F:\france24-s60v3.sisx
                [18/03/2010 08:14|--a------|802352] F:\kmsecurity_8_0_0_75_fr.cab
                [17/01/2010 22:19|--a------|44295938] F:\Le Prince Bleu_1.avi
                [21/01/2010 22:09|--a------|11856] F:\textes projet conf'rence sur la r'gionalisation.docx
                [17/01/2010 22:18|--a------|50819042] F:\Je rǸvise (Je rǸalise).avi
                [05/02/2010 21:11|--a------|34625] F:\Doc1.docx
                [08/02/2010 11:52|--a------|24903] F:\Plan Word.docx
                [10/02/2010 09:59|--a------|13545] F:\Seuil et taux avec Excel.docx
                [12/03/2010 23:38|--a------|5408356] F:\nouri-lbare7.mp3
                [19/01/2010 17:11|--a------|10415] F:\La politique de r'gionalisation a 't' con#ue afin de lutter contre les in'galit's de d'veloppement des diverses parties du royaume.docx
                [23/01/2010 17:27|--a------|26624] F:\Une des difficult's principales de l.doc
                [23/01/2010 17:24|--a------|26624] F:\Plus de d'bats.doc
                [23/01/2010 21:53|--a------|6171690] F:\L'Envie D'Aimer - Les dix commandements.mp3
                [02/03/2010 23:37|--a------|6514939] F:\Med Ziani Ad Lewis Wake UP Morocco New Version 2009.mp3
                [19/10/2009 23:16|--a------|5415706] F:\Marc Lavoine - La semaine prochaine (clip officiel).mp3
                [05/11/2009 22:29|--a------|6044735] F:\PIERRE BACHELET _ MARIONNETTISTE _.mp3
                [17/01/2010 22:25|--a------|114821764] F:\I love you_Omer Faruk Tekbilek.avi
                [11/11/2009 00:25|--a------|33672280] F:\Les EnfoirǸs - Ici Les EnfoirǸs - une vidǸo Musique.avi
                [11/11/2009 21:48|--a------|58698534] F:\Sum 41 - With Me (Clip officiel) - une vidǸo Musique.avi
                [18/02/2010 20:10|--a------|71556992] F:\The Submarines - You_ Me_ and the Bourgeoisie (iPhone 3G ad song).avi
                [10/03/2010 22:33|--a------|9686727] F:\hazou bina laalam haja hamdaouia.mp3
                [31/12/2009 22:02|--a------|5319053] F:\Junesex - Are U gonna dance.mp3
                [30/12/2009 22:32|--a------|3717225] F:\Keren Rose - La Liste - une vidǸo Musique.mp3
                [28/08/2009 18:10|--a------|46861] F:\$REFZ41S.jpg
                [16/03/2010 19:46|--a------|237628] F:\france24-uiq3.sis
                [11/12/2007 14:39|--a------|297846] F:\kavmobile_ppc_50_6_0_0_62_fr.cab
                [02/11/2009 13:27|--a------|499489] F:\La Communication externe.pptx
                [23/10/2009 00:01|--a------|5742256] F:\copie de shayne ward - no promises.mp3
                [15/11/2009 23:49|--a------|6404096] F:\AlexUnder Base Feat. Frissco - Privacy (Radio Edit).mp3
                [14/12/2009 12:25|--a------|21017] F:\Les nouvelles technologies de communication regroupent un ensemble de ressources n'cessaires pour manipuler de l.docx
                [15/12/2009 22:14|--a------|71070] F:\Es-snoussi Abdelali GroupeD word.docx

                ################## | Vaccination |

                # C:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
                # D:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
                # F:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).

                Que dois je faire svp???
                0
                1. du mieux ?
                  0
              2. Comment ca ?????????
                0
                1. je veux dire toujours aussi lents ?
                  0
              3. Oui, il cause toujours le meme prebleme,
                des que je commence le scan, le pc devient hyper lent, et les programmes comencent a bugger
                0
                1. désinstalle malwarebyts que tu a sur ton PC puis

                  Téléchargez MalwareByte's Anti-Malware ( dernière version )

                  http://www.malwarebytes.org/mbam/program/mbam-setup.exe

                  . Enregistres le sur le bureau
                  . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
                  . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
                  . Si le pare-feu demande l'autorisation de se connecter pour malwarebytes, accepte
                  . Une fois la mise à jour terminé
                  . Rend-toi dans l'onglet, Recherche
                  . Sélectionnes Exécuter un examen complet (examen assez long)
                  . Cliques sur Rechercher
                  . Le scan démarre.
                  . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
                  . Cliques sur Ok pour poursuivre.
                  . Si des malwares ont été détectés, clique sur Afficher les résultats
                  . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
                  . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
                  . Rends toi dans l'onglet rapport/log
                  . Tu cliques dessus pour l'afficher, une fois affiché
                  . Tu cliques sur edition en haut du boc notes, et puis sur sélectionner tous
                  . Tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
                  . tu cliques droit dans le cadre de la reponse et coller

                  Si tu as besoin d'aide regarde ces tutoriels :
                  Aide: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
                  http://www.infos-du-net.com/forum/278396-11-tuto-malwarebytes-anti-malware-mbam
                  0
                  1. Le pc m'affiche encore un ecran bleu,
                    voila les informations données par windows si ca pourrait t'aider

                    Signature du problème :
                    Nom d'événement de problème: BlueScreen
                    Version du système: 6.0.6002.2.2.0.768.3
                    Identificateur de paramètres régionaux: 1036

                    Informations supplémentaires sur le problème :
                    BCCode: 7a
                    BCP1: C06000E0
                    BCP2: C0000185
                    BCP3: 16BB7884
                    BCP4: C001C000
                    OS Version: 6_0_6002
                    Service Pack: 2_0
                    Product: 768_1

                    Fichiers aidant à décrire le problème :
                    C:\Windows\Minidump\Mini042510-01.dmp
                    C:\Users\Abdelali\AppData\Local\Temp\WER-73367-0.sysdata.xml
                    C:\Users\Abdelali\AppData\Local\Temp\WERFD22.tmp.version.txt

                    Lire notre déclaration de confidentialité :
                    https://privacy.microsoft.com/fr-fr/microsoft-error-reporting-privacy-statement
                    0
                    1. ta version de windows est légale ?

                      peut tu faire MBAM en mode sans échec
                      0
                      1. Contributeur sécurité
                        => usbfix
                        0
                        1. rebonjour

                          usbfix ?

                          le rapport ?
                          0
                        2. Contributeur sécurité
                          oublies

                          j'ai lu en diagonal...
                          0
                      2. Oui ma version windows est légale
                        mais j'essaye en mode sans echec ca pourrait solutionner le probleme ???
                        0
                        1. oui essaye en mode sans echec
                          0
                      3. Pour l'instant, je viens de demarrer le scan, et le pc et MBAM s'executent normallement

                        Je vous tiendrai au courrant des que le scann sera fini
                        ou y a t'il qqch à faire ???

                        et merci
                        0
                        1. non

                          attendre ces tout
                          0
                      4. :D

                        bon, il s'est executé normallement, aucune ifection

                        voilà le rapport

                        Malwarebytes' Anti-Malware 1.45
                        www.malwarebytes.org

                        Version de la base de données: 4033

                        Windows 6.0.6002 Service Pack 2 (Safe Mode)
                        Internet Explorer 8.0.6001.18904

                        25/04/2010 14:10:45
                        mbam-log-2010-04-25 (14-10-45).txt

                        Type d'examen: Examen complet (C:\|)
                        Elément(s) analysé(s): 408098
                        Temps écoulé: 1 heure(s), 30 minute(s), 58 seconde(s)

                        Processus mémoire infecté(s): 0
                        Module(s) mémoire infecté(s): 0
                        Clé(s) du Registre infectée(s): 0
                        Valeur(s) du Registre infectée(s): 0
                        Elément(s) de données du Registre infecté(s): 0
                        Dossier(s) infecté(s): 0
                        Fichier(s) infecté(s): 0

                        Processus mémoire infecté(s):
                        (Aucun élément nuisible détecté)

                        Module(s) mémoire infecté(s):
                        (Aucun élément nuisible détecté)

                        Clé(s) du Registre infectée(s):
                        (Aucun élément nuisible détecté)

                        Valeur(s) du Registre infectée(s):
                        (Aucun élément nuisible détecté)

                        Elément(s) de données du Registre infecté(s):
                        (Aucun élément nuisible détecté)

                        Dossier(s) infecté(s):
                        (Aucun élément nuisible détecté)

                        Fichier(s) infecté(s):
                        (Aucun élément nuisible détecté)
                        0
                        1. ? Télécharge Ad-remover ( de C_XX ) sur ton bureau :

                          ? Déconnecte toi et ferme toutes applications en cours !

                          ? Double clique sur "Ad-R.exe" pour lancer l'installation et laisse les paramètres d'installation par défaut .

                          ? Double-clique sur le raccourci Ad-remover qui est sur ton bureau pour lancer l'outil .

                          ? Au menu principal choisis "option clean " et tape sur [entrée] .

                          ? Laisse travailler l'outil et ne touche à rien ...

                          ? Poste le rapport qui apparait à la fin , sur le forum ...

                          ( Le rapport est sauvegardé aussi sous C:\Ad-report.log )
                          ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

                          ? Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                          Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                          Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
                          0
                          1. Voilà le rapport

                            .
                            ======= RAPPORT D'AD-REMOVER 2.0.0.0,C | UNIQUEMENT XP/VISTA/7 =======
                            .
                            Mis à jour par C_XX le 24/04/10 à 20:50
                            Contact: AdRemover.contact@gmail.com
                            Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
                            .
                            Lancé à: 18:07:08 le 25/04/2010 | Mode normal | Option: CLEAN
                            Exécuté de: C:\Ad-Remover\ADR.exe
                            SE: Microsoft® Windows Vista(TM) HomePremium Service Pack 2 - X86
                            Nom du PC: PC-DE-ABDELALI (Hewlett-Packard HP Pavilion dv6 Notebook PC)
                            Utilisateur actuel: Abdelali (Administrateur)
                            .
                            ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
                            .
                            .
                            C:\Users\Abdelali\AppData\Roaming\Mozilla\FireFox\Profiles\ejkp3174.default\extensions\toolbar@ask.com
                            C:\Users\Abdelali\AppData\Roaming\Mozilla\FireFox\Profiles\ejkp3174.default\searchplugins\askcom.xml
                            C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
                            C:\Windows\system32\Tasks\Scheduled Update for Ask Toolbar

                            (!) -- Fichiers temporaires supprimés.
                            .
                            HKCU\Software\AppDataLow\AskToolbarInfo
                            HKCU\Software\AppDataLow\Software\AskToolbar
                            HKCU\Software\Ask.com
                            HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
                            HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}
                            HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
                            HKLM\Software\bandoo
                            HKLM\Software\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
                            HKLM\Software\Classes\AppID\GenericAskToolbar.DLL
                            HKLM\Software\Classes\GenericAskToolbar.ToolbarWnd
                            HKLM\Software\Classes\GenericAskToolbar.ToolbarWnd.1
                            HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
                            HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
                            HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
                            HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Scheduled Update for Ask Toolbar
                            HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
                            HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
                            HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
                            HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks|{00000000-6E41-4FD3-8538-502F5495E5FC}
                            HKLM\Software\Microsoft\Internet Explorer\Toolbar|{D4027C7F-154A-4066-A1AD-4243D8127440}
                            .
                            (Orpheline) HKLM,Run - UpdateLBPShortCut - C:\Program Files\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" (Fichier manquant)
                            (Orpheline) HKLM,Run - UpdateP2GoShortCut - C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" (Fichier manquant)
                            .
                            ============== SCAN ADDITIONNEL ==============
                            .
                            * Mozilla FireFox Version 3.6.3 (fr) *
                            .
                            C:\Users\Abdelali\..\ejkp3174.default\prefs.js - browser.download.lastDir: C:\\Users\\Abdelali\\Desktop
                            C:\Users\Abdelali\..\ejkp3174.default\prefs.js - browser.startup.homepage: hxxp://fr.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:fr:official
                            C:\Users\Abdelali\..\ejkp3174.default\prefs.js - browser.startup.homepage_override.mstone: rv:1.9.2.3
                            C:\Users\Invité\..\hv6pzvom.default\prefs.js - browser.startup.homepage_override.mstone: rv:1.9.2.3
                            .
                            .
                            * Internet Explorer Version 8.0.6001.18904 *
                            .
                            [HKCU\Software\Microsoft\Internet Explorer\Main]
                            .
                            AutoHide: yes
                            Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                            Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                            Do404Search: 0x01000000
                            Enable Browser Extensions: yes
                            Local Page: C:\Windows\system32\blank.htm
                            Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                            Show_ToolBar: yes
                            Start Page: hxxp://fr.msn.com/
                            .
                            [HKLM\Software\Microsoft\Internet Explorer\Main]
                            .
                            AutoHide: yes
                            Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                            Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                            Delete_Temp_Files_On_Exit: yes
                            Local Page: C:\Windows\System32\blank.htm
                            Search bar: hxxp://search.msn.com/spbasic.htm
                            Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                            Start Page: hxxp://fr.msn.com/
                            .
                            [HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
                            .
                            Tabs: res://ieframe.dll/tabswelcome.htm
                            Blank: res://mshtml.dll/blank.htm
                            .
                            ============== SUSPECT(S) ==============
                            .
                            C:\Users\Abdelali\Desktop\clé\ali\Phylogene-Lycee-Base\Phylogene-Lycee-Base\Collections\Vertebres_Lycee\Carac-Images\Thon\serials.rar
                            C:\Users\Abdelali\Desktop\clé\ali\Phylogene-Lycee-Base\Phylogene-Lycee-Base\Collections\Vertebres_Lycee\Carac-Images\Tiktaalik\office_crack.rar
                            C:\Users\Abdelali\Desktop\Paperasse du Reste De La Famille\bureau2\Tune up utilities\Cracks\NFZ.nfo
                            C:\Users\Abdelali\Downloads\excel_cracker_setup.exe
                            C:\Users\Abdelali\Downloads\keygen ndrive 3.5.27.rar
                            .
                            ========================================
                            .
                            C:\Users\Abdelali\AppData\Local\Temp: 5 Fichier(s), 8 Dossier(s)
                            C:\Windows\temp: 2 Fichier(s), 5 Dossier(s)
                            C:\Users\Abdelali\AppData\Roaming\Microsoft\Windows\Cookies: 2 Fichier(s), 2 Dossier(s)
                            Temporary Internet Files: 4 Fichier(s), 8 Dossier(s)
                            .
                            C:\Ad-Remover\Quarantine: 91 Fichier(s)
                            C:\Ad-Remover\Backup: 16 Fichier(s)
                            .
                            C:\Ad-Report-CLEAN[1].txt - 571 Octet(s)
                            C:\Ad-Report-CLEAN[2].txt - 571 Octet(s)
                            C:\Ad-Report-CLEAN[3].txt - 571 Octet(s)
                            C:\Ad-Report-CLEAN[4].txt - 5537 Octet(s)
                            .
                            Fin à: 18:26:50, 25/04/2010
                            .
                            ============== E.O.F - CLEAN[4] ==============

                            Que faire mtn,????
                            0
                            1. bien comment va ton PC ?
                              0
                          2. Mal puisqu'il m'a refait l'ecran bleu ac les mm donnée des que j ai commencé le scann

                            Signature du problème :
                            Nom d'événement de problème: BlueScreen
                            Version du système: 6.0.6002.2.2.0.768.3
                            Identificateur de paramètres régionaux: 1036

                            Informations supplémentaires sur le problème :
                            BCCode: 7a
                            BCP1: C045A740
                            BCP2: C0000185
                            BCP3: 8D8F7860
                            BCP4: 8B4E8A9A
                            OS Version: 6_0_6002
                            Service Pack: 2_0
                            Product: 768_1

                            Fichiers aidant à décrire le problème :
                            C:\Windows\Minidump\Mini042510-02.dmp
                            C:\Users\Abdelali\AppData\Local\Temp\WER-50481-0.sysdata.xml
                            C:\Users\Abdelali\AppData\Local\Temp\WERFB20.tmp.version.txt

                            Lire notre déclaration de confidentialité :
                            http://go.microsoft.com/fwlink/?linkid=50163&clcid=0x040c
                            0
                            1. tu a le cd de windows ?
                              0
                              • 1
                              • 2