Antimalware doctore + gotnewupdate.exe

Résolu
Bonjour,

Mon pc récent est infecté par semble-t-il l'antimalware doctor : des fenêtres d'alertes de mon antivirus ne cessent de s'ouvrir et mon pc est bloqué.

Quelle manip me conseillez-vous, que faire ? Je m'en remet à votre sage expérience dont j'ai déjà pu, à mon grand soulagement, bénéficier.

Merci par avance à toute personne qui voudra bien me consacrer un peu de temps, et qui pourra m'aider.

J'espère que ce post ne fait pas doublon, j'ai cru tout à l'heure avoir mis un message mais je ne le vois plus...

Encore merci

61 réponses

Résumé de la discussion

Une infection par l'antimalware doctor provoque des fenêtres d'alerte et le blocage du PC, observée sur un système Windows XP avec Internet Explorer 8. Plusieurs réponses préconisent des outils de nettoyage comme Malwarebytes et ZHPDiag, avec des consignes d'installation, de mise à jour et d'exécution d’un scan complet. Certaines manipulations techniques évoquent lancer sigcheck.exe et décocher l’option O65 dans ZHPDiag, puis redémarrer le système pour finaliser le nettoyage. En cas d’absence d’accès Internet sur l’ordinateur infecté, il est recommandé d’imprimer les instructions ou d’utiliser un autre ordinateur pour télécharger et transférer les outils.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Hello, Bonsoir à tous les deux

    Je viens à peine de lire le message de gen.

    ZHPDiag utilise l'outil SygCheck de SysInternal, et au premier lancement de cet outil il peut y avoir demande d'agréement du logiciel.

    Visiblement tu as un problème avec cet outil !

    Recherche dans le dossier d'installation de ZHPDiag le fichier "sigcheck.exe" et essayes de le lancer directement (en tant qu'admin bien sûr)

    Si le problème persiste, c'est qu'il y a une imcompatibilité avec ton système, peut-être au niveau des logiciels de protection ?

    Dans ce cas tu décoches l'option O65 (Clique sur le bouton tournevis) et ZHPDiag terminera normalement sont scan.

    Bonne nuit.

    Amicalement Nicolas Coolman
    1. Oups, j'ai oublié de préciser : windows XP, antivirus Avira, il me semblait avoir Malwarbyte's mais j'ai un gros doute vu que j'ai pas vu l'icone et pas eu le temps de regarder dans programme, et j'ai pas spybot SD...
      1. Bonjour,

        Personne de disponible pour m'aider ? Je ne sais par quoi commencer, ni comment... en mode sans échec ? Un scan avira ?...

        Merci pour toute réponse...
        1. bonjour je viens de lire ton mail , commencons par le commencement ^^

          DESACTIVE TON ANTIVIRUS ET TON PAREFEU SI PRESENTS !!!!!(car il est detecté a tort comme infection)

          ▶ Télécharge List_Kill'em

          et enregistre le sur ton bureau

          double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

          Laisse coché :

          ♦ Executer Shortcut
          ♦ Executer List_Kill'em

          une fois terminée , clic sur "terminer" et le programme se lancera seul

          choisis l'option Search

          ▶ laisse travailler l'outil

          à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

          ▶ Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"
          1. Bon, il m'est impossible d'accéder à internet sur mon pc, alors je le telecharge sur cet ordi et le copie sur l'autre... et je crois que je vais devoir le faire en mode sans échec... parce que je ne peux strictement rien faire, même pas éteindre le pc normalement !
            1. voilà, j'espère que tu y trouves ce qu'on cherche, fait donc en mode sans échec...
              ¤¤¤¤¤¤¤¤¤¤ List'em by g3n-h@ckm@n 2.0.0.1 ¤¤¤¤¤¤¤¤¤¤

              User : Administrateur ()
              Update on 09/05/2010 by g3n-h@ckm@n ::::: 09.15
              Start at: 14:04:57 | 09/05/2010

              Processeur Intel Pentium III Xeon
              Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 2
              Internet Explorer 8.0.6001.18702
              Windows Firewall Status : Enabled
              AV : AntiVir Desktop 9.0.1.32 [ Enabled | (!) Outdated ]

              A:\ -> Lecteur de disquettes 3 ½ pouces
              C:\ -> Disque fixe local | 931,5 Go (880,19 Go free) | NTFS
              D:\ -> Disque CD-ROM | 4,32 Go (0 Mo free) [9467] | CDFS
              E:\ -> Disque CD-ROM
              F:\ -> Disque fixe local | 465,76 Go (202,45 Go free) [Expansion Drive] | NTFS
              G:\ -> Disque amovible | 955,72 Mo (941,86 Mo free) [UDISK] | FAT

              Boot: Safeboot
              ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\csrss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\Explorer.EXE
              C:\Program Files\List_Kill'em\List_Kill'em.exe
              C:\WINDOWS\system32\cmd.exe
              C:\WINDOWS\system32\wbem\wmiprvse.exe
              C:\Program Files\List_Kill'em\pv.exe

              ======================
              Keys "Run"
              ======================

              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              CTFMON.EXE REG_SZ C:\WINDOWS\system32\CTFMON.EXE

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              RTHDCPL REG_SZ RTHDCPL.EXE
              Alcmtr REG_SZ ALCMTR.EXE
              SystrayORAHSS REG_SZ "C:\Program Files\Orange\Systray\SystrayApp.exe"
              ORAHSSSessionManager REG_SZ C:\Program Files\Orange\SessionManager\SessionManager.exe
              Google Quick Search Box REG_SZ "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
              avgnt REG_SZ "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
              ArcSoft Connection Service REG_SZ C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
              QuickTime Task REG_SZ "C:\Program Files\QuickTime\qttask.exe" -atboottime
              Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
              Adobe ARM REG_SZ "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
              LVCOMSX REG_SZ C:\WINDOWS\system32\LVCOMSX.EXE

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

              =====================
              Other Keys
              =====================

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
              dontdisplaylastusername REG_DWORD 0 (0x0)
              legalnoticecaption REG_SZ
              legalnoticetext REG_SZ
              shutdownwithoutlogon REG_DWORD 1 (0x1)
              undockwithoutlogon REG_DWORD 1 (0x1)

              ===============

              [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
              NoDriveTypeAutoRun REG_DWORD 145 (0x91)

              ===============

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
              HonorAutoRunSetting REG_DWORD 1 (0x1)

              ===============

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
              AppInit_DLLS REG_SZ

              ===============

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
              AutoRestartShell REG_DWORD 1 (0x1)
              DefaultDomainName REG_SZ MYRIAM
              DefaultUserName REG_SZ Propriétaire
              LegalNoticeCaption REG_SZ
              LegalNoticeText REG_SZ
              PowerdownAfterShutdown REG_SZ 0
              ReportBootOk REG_SZ 1
              Shell REG_SZ Explorer.exe
              ShutdownWithoutLogon REG_SZ 0
              System REG_SZ
              Userinit REG_SZ C:\WINDOWS\system32\userinit.exe,
              VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
              SfcQuota REG_DWORD -1 (0xffffffff)
              allocatecdroms REG_SZ 0
              allocatedasd REG_SZ 0
              allocatefloppies REG_SZ 0
              cachedlogonscount REG_SZ 10
              forceunlocklogon REG_DWORD 0 (0x0)
              passwordexpirywarning REG_DWORD 14 (0xe)
              scremoveoption REG_SZ 0
              AllowMultipleTSSessions REG_DWORD 1 (0x1)
              UIHost REG_EXPAND_SZ logonui.exe
              LogonType REG_DWORD 1 (0x1)
              Background REG_SZ 0 0 0
              DebugServerCommand REG_SZ no
              SFCDisable REG_DWORD 0 (0x0)
              WinStationsDisabled REG_SZ 0
              HibernationPreviouslyEnabled REG_DWORD 1 (0x1)
              ShowLogonOptions REG_DWORD 0 (0x0)
              AltDefaultUserName REG_SZ Administrateur
              AltDefaultDomainName REG_SZ MYRIAM

              ===============

              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]

              ===============

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
              {AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ

              ===============

              [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
              %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
              C:\Program Files\Orange\Connectivity\ConnectivityManager.exe REG_SZ C:\Program Files\Orange\Connectivity\ConnectivityManager.exe:*:enabled:CSS
              C:\Program Files\Messenger\msmsgs.exe REG_SZ C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger
              C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
              C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
              C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare
              C:\Program Files\Electronic Arts\EADM\Core.exe REG_SZ C:\Program Files\Electronic Arts\EADM\Core.exe:*:Enabled:EA Download Manager
              C:\Program Files\e frontier\Poser 7\Poser.exe REG_SZ C:\Program Files\e frontier\Poser 7\Poser.exe:*:Enabled:Poser executable file
              C:\Program Files\Java\jre6\bin\javaw.exe REG_SZ C:\Program Files\Java\jre6\bin\javaw.exe:*:Disabled:Java(TM) Platform SE binary

              [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
              %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
              C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
              C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
              C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare

              ===============
              ActivX controls
              ===============

              [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{5D637FAD-E202-48D1-8F18-5B9C459BD1E3}]
              [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}]
              [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}]
              [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}]

              ===============
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{DFB17AA8-042A-429D-987C-26CE244A4189}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{283807B5-2C60-11D0-A31D-00AA00B92C03}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4278c270-a269-11d1-b5bf-0000f8051515}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f216970-c90c-11d1-b5c7-0000f8051515}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5A8D6EE0-3E18-11D0-821E-444553540000}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{73FA19D0-2D75-11D2-995D-00C04F98BBC9}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{ACC563BC-4266-43f0-B6ED-9D38C4202C7E}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CC2A9BA0-3BDD-11D0-821E-444553540000}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}]

              ==============
              BHO :
              ======

              [<NO NAME> REG_SZ ]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{24cc1362-11c6-4918-a2c0-b9ee5a563185}]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6}]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{F0626A63-410B-45E2-99A1-3F2475B2D695}]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}]

              ===
              DNS
              ===

              HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
              HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
              HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

              ================
              Internet Explorer :
              ================

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
              Start Page REG_SZ https://www.msn.com/fr-fr/?ocid=iehp
              Local Page REG_SZ C:\WINDOWS\system32\blank.htm
              Default_Search_URL REG_SZ https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              Default_Page_URL REG_SZ https://www.msn.com/fr-fr/?ocid=iehp
              Search Page REG_SZ https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF

              [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

              ========
              Services
              ========

              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

              Ndisuio : 0x3 ( OK = 3 )
              SharedAccess : 0x2 ( OK = 2 )
              wuauserv : 0x2 ( OK = 2 )

              ========
              Safemode
              ========

              HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot : OK !!
              HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal : OK !!
              HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network : OK !!

              =========
              Atapi.sys
              =========

              C:\WINDOWS\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\atapi.sys :
              MD5 :: [9f3a2f5aa6875c72bf062c712cfa2674]
              SHA256 :: [b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9]

              C:\WINDOWS\system32\drivers\atapi.sys :
              MD5 :: [cdfe4411a69c224bd1d11b2da92dac51]
              SHA256 :: [0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d]

              Référence :
              ==========

              Win 2000_SP2 : ff953a8f08ca3f822127654375786bbe
              Win 2000_SP4 : 8c718aa8c77041b3285d55a0ce980867
              Win XP_32b : a64013e98426e1877cb653685c5c0009
              Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
              Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
              Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
              Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
              Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
              Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
              Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
              Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C
              Windows 7_32b_Ultimate : 338c86357871c167a96ab976519bf59e

              =======
              Drive :
              =======

              D'fragmenteur de disque Windows
              Copyright (c) 2001 Microsoft Corp. et Executive Software International Inc.

              Rapport d'analyse
              932 Go total, 880 Go libre (94%), 27% fragment' (fragmentation du fichier 55%)

              Vous devriez d'fragmenter ce volume.

              ¤¤¤¤¤¤¤¤¤¤ Files/folders :

              Present !! : C:\Program Files\Fast Browser Search
              Present !! : C:\Program Files\SGPSA
              Present !! : C:\Program Files\WindowsUpdate
              Present !! : C:\WINDOWS\SET25.tmp
              Present !! : C:\WINDOWS\SET3.tmp
              Present !! : C:\WINDOWS\SET4.tmp
              Present !! : C:\WINDOWS\SET8.tmp
              Present !! : C:\WINDOWS\_delis32.ini
              Present !! : C:\WINDOWS\System32\DRIVERS\aksfridge.sys
              Present !! : C:\WINDOWS\System32\sshnas21.dll
              Present !! : C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
              Present !! : C:\WINDOWS\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
              Present !! : C:\WINDOWS\Temp\scs8.tmp
              Present !! : C:\WINDOWS\Temp\scs9.tmp
              Present !! : C:\WINDOWS\TEMP\scs8.tmp
              Present !! : C:\WINDOWS\TEMP\scs9.tmp

              ¤¤¤¤¤¤¤¤¤¤ Keys :

              Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
              Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
              Present !! : "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F0626A63-410B-45E2-99A1-3F2475B2D695}"
              Present !! : "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}"
              Present !! : HKCR\CLSID\{ca3eb689-8f09-4026-aa10-b9534c691ce0}
              Present !! : HKCR\Interface\{4897bba6-48d9-468c-8efa-846275d7701b}
              Present !! : HKCR\TypeLib\{4509d3cc-b642-4745-b030-645b79522c6d}
              Present !! : HKCR\urlsearchhook.toolbarurlsearchhook
              Present !! : HKCR\urlsearchhook.toolbarurlsearchhook.1
              Present !! : HKLM\Software\Conduit
              Present !! : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TBSB07183.TBSB07183Toolbar
              Present !! : HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SSHNAS
              Present !! : HKLM\SYSTEM\CurrentControlSet\Services\SSHNAS
              Present !! : HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_SSHNAS
              Present !! : HKLM\SYSTEM\ControlSet001\Services\SSHNAS
              Present !! : HKLM\SYSTEM\ControlSet002\Enum\Root\LEGACY_SSHNAS
              Present !! : HKLM\SYSTEM\ControlSet002\Services\SSHNAS

              ============

              catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
              Rootkit scan 2010-05-09 14:13:35
              Windows 5.1.2600 Service Pack 2 FAT NTAPI

              scanning hidden processes ...

              scanning hidden services ...

              scanning hidden autostart entries ...

              scanning hidden files ...

              scan completed successfully
              hidden processes: 0
              hidden services: 0
              hidden files: 0

              Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

              device: opened successfully
              user: MBR read successfully
              called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys
              kernel: MBR read successfully
              user & kernel MBR OK
              copy of MBR has been found in sector 0x074701B00
              malicious code @ sector 0x074701B03 !
              PE file found in sector at 0x074701B19 !

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
              FirstRunDisabled REG_DWORD 1 (0x1)
              AntiVirusDisableNotify REG_DWORD 0 (0x0)
              FirewallDisableNotify REG_DWORD 0 (0x0)
              UpdatesDisableNotify REG_DWORD 0 (0x0)
              AntiVirusOverride REG_DWORD 0 (0x0)
              FirewallOverride REG_DWORD 0 (0x0)

              ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

              End of scan : 14:13:36,92
              1. je peux me connecter sur mon pc, je recommence en mode normal pour voir
                1. non tu peux faire ceci d'entrée de jeu :

                  ▶ Relance List_Kill'em(soit en clic droit pour vista/7),avec le raccourci sur ton bureau.
                  mais cette fois-ci :

                  ▶ choisis l'Option Clean

                  ton PC va redemarrer,

                  laisse travailler l'outil.

                  en fin de scan la fenetre se ferme , et tu as un rapport du nom de Kill'em.txt sur ton bureau ,

                  ▶ colle le contenu dans ta reponse
                  1. Je réalise la même recherche (j'ai pu me connecter en mode normal) mais il est à 90 % depuis plusieurs minutes - le pc n'a pas l'air planté non plus...
                    C'est normal ? Oups, je viens de relire ton post... désolée...
                    1. Nos messages se croisent, désolée !

                      Ca fait plus de 40 mn qu'il est bloqué à 90 %.... et l'horloge est sur 14h32 bien qu'il soit 15h10 passé... La souris est active mais je n'ose toucher à rien...

                      Que me conseilles-tu ?
                      1. Rien depuis 14h36 précise... la souris bouge, je viens d'essayer ne serait-ce que de réduire la case blanche qui indique "searching, patience..." sans succès

                        Je clique sans plus de succès sur la page internet que j'ai réduite aussi... je peux donc dire, aucun signe de vie !

                        Heureusement que j'ai le pc de secours pour te joindre !

                        Qu"est-ce qu'on fait ?
                        1. Finalement, il est planté...
                          Je relance et si je peux, je suis la procédure 2
                          1. Je crois que ça va pas du tout... la manip 2 à planté l'ordi après le nettoyage... écran bleu avec un message d'erreur et des instructio si cela recommence...
                            je redémarre, ça replante après quelques minutes, à peine le temps d'afficher le rapport sur le bureau.
                            D'ailleurs, un message d'affiche à chaque fois que je redémarre :
                            Sous-système msdos 16 bits
                            c:\progr~1\expert~1\UI_BIOSCTL.EXE
                            NTDVM rencontré une erreur système
                            NTDVM rencontré une erreur système coh choisissez fermer ou ignorer

                            il semble que j'ai accès à internet dès que je désactive dès l'ouverture du pc mon antivirus

                            voici le dernier rapport, celui qui a fait planter :

                            ¤¤¤¤¤¤¤¤¤¤ Kill'em by g3n-h@ckm@n 2.0.0.1 ¤¤¤¤¤¤¤¤¤¤

                            User : Propriétaire (Administrateurs)
                            Update on 09/05/2010 by g3n-h@ckm@n ::::: 09.15
                            Start at: 15:33:06 | 09/05/2010

                            Processeur Intel Pentium III Xeon
                            Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 2
                            Internet Explorer 8.0.6001.18702
                            Windows Firewall Status : Enabled
                            AV : AntiVir Desktop 9.0.1.32 [ (!) Disabled | Updated ]

                            A:\ -> Lecteur de disquettes 3 ½ pouces
                            C:\ -> Disque fixe local | 931,5 Go (880,18 Go free) | NTFS
                            D:\ -> Disque CD-ROM | 4,32 Go (0 Mo free) [9467] | CDFS
                            E:\ -> Disque CD-ROM
                            F:\ -> Disque fixe local | 465,76 Go (202,45 Go free) [Expansion Drive] | NTFS

                            ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\csrss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\WINDOWS\Explorer.EXE
                            C:\Program Files\Avira\AntiVir Desktop\sched.exe
                            C:\WINDOWS\system32\cmd.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\Rxh.exe
                            C:\WINDOWS\Rqarya.exe
                            C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
                            C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                            C:\WINDOWS\system32\bgsvcgen.exe
                            C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                            C:\WINDOWS\system32\hasplms.exe
                            C:\Program Files\Java\jre6\bin\jqs.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\system32\wuauclt.exe
                            C:\WINDOWS\system32\wbem\wmiapsrv.exe
                            C:\WINDOWS\system32\wbem\wmiprvse.exe
                            C:\WINDOWS\System32\alg.exe
                            C:\WINDOWS\system32\wbem\wmiprvse.exe
                            C:\Program Files\List_Kill'em\pv.exe

                            ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                            Quarantined & Deleted !! : C:\Program Files\Fast Browser Search
                            Quarantined & Deleted !! : C:\Program Files\SGPSA
                            Quarantined & Deleted !! : C:\Program Files\WindowsUpdate
                            Quarantined & Deleted !! : C:\WINDOWS\SET25.tmp
                            Quarantined & Deleted !! : C:\WINDOWS\SET3.tmp
                            Quarantined & Deleted !! : C:\WINDOWS\SET4.tmp
                            Quarantined & Deleted !! : C:\WINDOWS\SET8.tmp
                            Quarantined & Deleted !! : C:\WINDOWS\_delis32.ini

                            Quarantined & Deleted !! : C:\WINDOWS\System32\DRIVERS\aksfridge.sys
                            Quarantined & Deleted !! : C:\WINDOWS\System32\sshnas21.dll
                            Quarantined & Deleted !! : C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
                            Quarantined & Deleted !! : C:\WINDOWS\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
                            Quarantined & Deleted !! : C:\WINDOWS\Temp\scs8.tmp
                            Quarantined & Deleted !! : C:\WINDOWS\Temp\scs9.tmp
                            Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\Local Settings\Temp\a.dat
                            Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\Local Settings\Temp\acD.tmp
                            Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\Local Settings\Temp\Rxf.exe
                            Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\Local Settings\Temp\Rxg.exe
                            Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\Local Settings\Temp\Rxh.exe
                            Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\Badaboom_Setup_1.2.0.87_TMP.EXE
                            Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\EAD2.exe
                            Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\EAD3.exe
                            Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\EAD4.exe
                            Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\EAD5.exe
                            Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\EAD6.exe
                            Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\EADM6AirComponents-installer.exe
                            Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\IE8-Setup-Full-MSN-XP.exe
                            Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\IE8-Setup-Full-XP.exe
                            Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\_is4.exe
                            Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\_is51.exe
                            Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\_is8C.exe
                            Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\_is90.exe
                            Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\_isAD.exe
                            Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\GLF93.tmp.tbArch.dll
                            Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\twapi-2.0a2.dll
                            Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\twapi-2.0a7.dll
                            Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\twapi-be29e7f1-71ae-4703-50cb-1d52be512f51.dll
                            Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\UninstallEACore.dll
                            Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\UninstallEADM.dll
                            Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\tmp2E.tmp
                            Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\tmp92.tmp

                            =======
                            Hosts :
                            =======

                            127.0.0.1 localhost

                            ========
                            Registry
                            ========

                            Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run : gotnewupdate.exe
                            Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run : M5T8QL3YW3
                            Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser : {0E5CBF21-D15F-11D0-8301-00AA005B4383}
                            Deleted : "HKCU\Software\Antimalware Doctor Inc"
                            Deleted : "HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Antimalware Doctor"
                            Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
                            Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
                            Deleted : "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F0626A63-410B-45E2-99A1-3F2475B2D695}"
                            Deleted : "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}"
                            Deleted : HKCR\CLSID\{ca3eb689-8f09-4026-aa10-b9534c691ce0}
                            Deleted : HKCR\Interface\{4897bba6-48d9-468c-8efa-846275d7701b}
                            Deleted : HKCR\TypeLib\{4509d3cc-b642-4745-b030-645b79522c6d}
                            Deleted : HKCR\urlsearchhook.toolbarurlsearchhook
                            Deleted : HKCR\urlsearchhook.toolbarurlsearchhook.1
                            Deleted : HKCU\Software\Conduit
                            Deleted : HKCU\SOFTWARE\Microsoft\Handle
                            Deleted : HKCU\SOFTWARE\QZAIB7KITK
                            Deleted : HKCU\SOFTWARE\XML
                            Deleted : HKLM\Software\Conduit
                            Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TBSB07183.TBSB07183Toolbar
                            Deleted : HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SSHNAS
                            Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SSHNAS
                            Deleted : HKLM\SYSTEM\ControlSet002\Enum\Root\LEGACY_SSHNAS
                            Deleted : HKLM\SYSTEM\ControlSet002\Services\SSHNAS
                            =================
                            Internet Explorer
                            =================

                            [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                            Start Page REG_SZ https://www.msn.com/fr-fr/?ocid=iehp
                            Local Page REG_SZ C:\WINDOWS\system32\blank.htm
                            Default_Search_URL REG_SZ https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            Default_Page_URL REG_SZ https://www.msn.com/fr-fr/?ocid=iehp
                            Search Page REG_SZ https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF

                            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                            Start Page REG_SZ https://www.google.com/?gws_rd=ssl
                            Local Page REG_SZ C:\WINDOWS\system32\blank.htm
                            Search Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

                            ===============
                            Security Center
                            ===============

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
                            FirstRunDisabled REG_DWORD 1 (0x1)
                            AntiVirusDisableNotify REG_DWORD 0 (0x0)
                            FirewallDisableNotify REG_DWORD 0 (0x0)
                            UpdatesDisableNotify REG_DWORD 0 (0x0)
                            AntiVirusOverride REG_DWORD 1 (0x1)
                            FirewallOverride REG_DWORD 1 (0x1)

                            ========
                            Services
                            =========

                            Ndisuio : Start = 3
                            Ip6Fw : Start = 2
                            SharedAccess : Start = 2
                            wuauserv : Start = 2
                            wscsvc : Start = 2

                            ============
                            Disk Cleaned
                            anti-ver blaster : OK
                            Prefetch cleaned
                            ================

                            ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                            1. ▶ Télécharge ZHPDiag (de Nicolas Coolman)

                              ou :ZHPDiag

                              ▶ Enregistre le sur ton Bureau.

                              Une fois le téléchargement achevé,

                              ▶ lance ZHPDiag.exe et clique sur Unzip dans la fenêtre qui s'ouvre.

                              ▶ Clique sur le tournevis puis sur Tous pour cocher toutes les cases des options.

                              ▶ Clique sur la loupe pour lancer l'analyse.

                              A la fin de l'analyse,

                              ▶ clique sur l'appareil photo et enregistre le rapport sur ton Bureau.

                              Pour me le transmettre clique sur ce lien :

                              http://www.cijoint.fr/

                              ▶ Clique sur Parcourir et cherche le fichier C:\Documents and settings\le_nom_de_ta_session\.ZHPDiag.txt

                              ▶ Clique sur Ouvrir.

                              ▶ Clique sur "Cliquez ici pour déposer le fichier".

                              Un lien de cette forme :

                              http://www.cijoint.fr/cjlink.php?file=cj200905/cib7SU.txt

                              est ajouté dans la page.

                              ▶ Copie ce lien dans ta réponse.

                              --
                              ?G3?-?@¢??@?(TM)©®?
                              1. Ok

                                Je fais cela demain en fin de journée, sans faute !

                                Pour info, ce virus prend le dessus sur mon anti virus apparement !

                                Bonne soirée !
                                1. Puréééee ! c'est la galère !
                                  Pour le moment, impossible de me connecter, je tente de passer en mode sans échec puis une nouvelle tentative de rédémarrage...
                                  1. Bon, je vais entamer la 3ème tentative... quel bonheur !

                                    petite question : à un moment donné du scan, on me demande (2 fois de suite je crois) d'accepter ou pas quelque chose (formulaire en anglais puis français, genre d'instruction) que je fasse oui ou non, cela me bloque, est-ce normal ?
                                • 1
                                • 2
                                • 3
                                • 4