Fenetre IE en cascades... Virus ????

Bonjour,

Je surfais sur le site de l'equipe (a priori pas un site louche) et d'un coup, des fenetres IE se sont ouvertes sans s'arreter. Impossible de les arreter. Elles avaient apparemment un lien avec Facebook, mais impossible de voir car elles s'ouvraient trop vite.

J'ai du eteindre le PC car meme le gestionnaire des taches ne me permettait pas d'arreter le processus.

Ja'i passe l'antivirus (antivir. A jour) qui ne me signale rien.

Pouvez vous me dire comment trouver la cause du probleme...

Merci d'avance d'excuser le delai de reponse car je suis a l'etranger (decallage horaire).

Comme ce PC me sert aussi a travailler, c'est vraiment important...

17 réponses

  1. Contributeur sécurité
    salut

    fais ceci

    ● Télécharges Random's System Information Tool (RSIT) de Random/Random, et enregistres le sur ton Bureau.

    ● Double clique sur RSIT.exe pour lancer l'outil.

    ● Cliques sur "Continue" à l'écran Disclaimer.

    ● Si l'outil HijackThis n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu s'il te le demande) et tu devras accepter la licence.

    ● Une fois le scan terminé, deux rapports vont apparaître : poste les dans deux messages séparés stp

    * Tutoriel illustré pour t'aider

    * pour héberger les rapports trop longs de RSIT

    0
    1. Bonjour,

      Voici le contenu du fichier log :

      Logfile of random's system information tool 1.07 (written by random/random)
      Run by d at 2010-05-29 06:45:37
      Microsoft® Windows Vista(TM) Home Premium Service Pack 1
      System drive C: has 129 GB (57%) free of 226 GB
      Total RAM: 3061 MB (50% free)

      HijackThis download failed

      ======Scheduled tasks folder======

      C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
      C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
      C:\Windows\tasks\User_Feed_Synchronization-{9394A470-025D-4B40-B3E3-8240A911E9D5}.job

      ======Registry dump======

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
      Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2009-12-18 61888]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
      Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2009-05-26 1088296]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
      Spybot-S&D IE Protection - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2009-01-26 1879896]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
      SSVHelper Class - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll [2008-02-22 509328]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
      Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-05-28 278128]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
      Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll [2010-05-28 814648]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
      {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-05-28 278128]

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
      "Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
      "Apoint"=C:\Program Files\DellTPad\Apoint.exe [2008-05-04 167936]
      "OEM02Mon.exe"=C:\Windows\OEM02Mon.exe [2007-08-28 36864]
      "IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-03-06 141848]
      "HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2008-03-06 166424]
      "Persistence"=C:\Windows\system32\igfxpers.exe [2008-03-06 133656]
      "IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [2007-03-22 174872]
      "Broadcom Wireless Manager UI"=C:\Windows\system32\WLTRAY.exe [2008-10-27 3563520]
      "dscactivate"=C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe [2008-03-12 16384]
      "PCMService"=C:\Program Files\Dell\MediaDirect\PCMService.exe [2007-12-21 184320]
      "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2009-12-18 40368]
      "RemoteControl"=C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe [2003-10-31 32768]
      "avgnt"=C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe [2008-06-12 266497]
      "Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-12-11 948672]

      [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
      "Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-01-21 1233920]
      "UniKey"=C:\Program Files\UniKey\UniKeyNT.exe [2006-04-19 217088]
      "Skype"=C:\Program Files\Skype\Phone\Skype.exe [2009-05-26 24264488]
      "swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-07-05 39408]
      "WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240]

      C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
      AutoCAD Startup Accelerator.lnk - C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
      Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe

      C:\Users\d\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
      Dell Dock.lnk - C:\Program Files\Dell\DellDock\DellDock.exe

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\GoToAssist]
      C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll [2009-01-17 10536]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
      C:\Windows\system32\igfxdev.dll [2008-03-06 200704]

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\GoToAssist]

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
      "dontdisplaylastusername"=0
      "legalnoticecaption"=
      "legalnoticetext"=
      "shutdownwithoutlogon"=1
      "undockwithoutlogon"=1
      "EnableUIADesktopToggle"=0

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

      ======File associations======

      .scr - open - "C:\Windows\notepad.exe" "%1"
      .scr - install -
      .scr - config -

      ======List of files/folders created in the last 1 months======

      2010-05-29 06:43:57 ----D---- C:\rsit
      2010-05-29 06:43:57 ----D---- C:\Program Files\trend micro
      2010-05-26 06:47:23 ----A---- C:\Windows\system32\tzres.dll
      2010-05-12 07:02:28 ----A---- C:\Windows\system32\inetcomm.dll

      ======List of files/folders modified in the last 1 months======

      2010-05-29 06:45:38 ----D---- C:\Windows\Temp
      2010-05-29 06:43:58 ----D---- C:\Windows\Prefetch
      2010-05-29 06:43:57 ----RD---- C:\Program Files
      2010-05-28 17:14:15 ----D---- C:\COMMUN
      2010-05-28 15:50:20 ----D---- C:\Windows\System32
      2010-05-28 15:50:20 ----D---- C:\Windows\inf
      2010-05-28 15:50:20 ----A---- C:\Windows\system32\PerfStringBackup.INI
      2010-05-28 11:28:59 ----D---- C:\Windows
      2010-05-28 11:28:59 ----D---- C:\ProgramData\Spybot - Search & Destroy
      2010-05-28 11:20:39 ----SHD---- C:\Windows\Installer
      2010-05-28 08:47:57 ----SHD---- C:\System Volume Information
      2010-05-27 07:21:56 ----D---- C:\Windows\rescache
      2010-05-27 07:06:40 ----D---- C:\Windows\system32\catroot2
      2010-05-27 03:01:12 ----D---- C:\Windows\winsxs
      2010-05-27 03:01:11 ----D---- C:\Windows\system32\en-US
      2010-05-26 06:45:52 ----D---- C:\Windows\system32\catroot
      2010-05-20 18:53:27 ----D---- C:\Users\d\AppData\Roaming\Skype
      2010-05-19 16:00:41 ----D---- C:\Users\d\AppData\Roaming\skypePM
      2010-05-13 08:29:13 ----D---- C:\ProgramData\Adobe
      2010-05-13 08:21:19 ----HD---- C:\ProgramData
      2010-05-13 08:10:05 ----D---- C:\Program Files\Common Files\Adobe
      2010-05-13 03:16:32 ----D---- C:\Program Files\Windows Mail
      2010-05-12 11:21:16 ----N---- C:\Windows\system32\MpSigStub.exe

      ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

      R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys [2009-05-28 11608]
      R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2009-05-28 75096]
      R1 ssmdrv;ssmdrv; C:\Windows\system32\DRIVERS\ssmdrv.sys [2007-03-01 28352]
      R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2008-06-23 12672]
      R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2007-09-06 39936]
      R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2007-09-06 42496]
      R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2007-09-06 37376]
      R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\xaudio.sys [2008-06-23 8704]
      R3 ApfiltrService;Alps Touch Pad Filter Driver for Windows 2000/XP/Vista; C:\Windows\system32\DRIVERS\Apfiltr.sys [2008-05-04 164400]
      R3 avgntflt;avgntflt; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys [2009-05-28 52056]
      R3 BCM42RLY;BCM42RLY; C:\Windows\system32\drivers\BCM42RLY.sys [2008-10-27 18424]
      R3 BCM43XX;Dell Wireless WLAN Card Driver; C:\Windows\system32\DRIVERS\bcmwl6.sys [2008-10-27 1207288]
      R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-21 14208]
      R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2008-06-23 980992]
      R3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HSXHWAZL.sys [2008-06-23 208384]
      R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-03-06 2016256]
      R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service; C:\Windows\system32\drivers\IntcHdmi.sys [2008-03-06 111616]
      R3 OEM02Dev;Creative Camera OEM002 Driver; C:\Windows\system32\DRIVERS\OEM02Dev.sys [2007-08-28 235520]
      R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver; C:\Windows\system32\DRIVERS\OEM02Vfx.sys [2007-08-28 7424]
      R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-21 88576]
      R3 STHDA;SigmaTel High Definition Audio CODEC; C:\Windows\system32\drivers\stwrt.sys [2007-11-12 330240]
      R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2008-06-23 661504]
      R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264]
      R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2007-09-29 278528]
      S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
      S3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\Windows\system32\DRIVERS\e1e6032.sys [2008-01-21 220672]
      S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
      S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
      S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
      S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
      S3 R300;R300; C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-02 2028032]
      S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
      S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
      S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
      S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

      ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

      R2 AESTFilters;Andrea ST Filters Service; C:\Windows\system32\aestsrv.exe [2007-11-12 73728]
      R2 AntiVirScheduler;Avira AntiVir Personal - Free Antivirus Scheduler; C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe [2008-10-15 68865]
      R2 AntiVirService;Avira AntiVir Personal - Free Antivirus Guard; C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe [2008-10-15 151297]
      R2 DockLoginService;Dock Login Service; C:\Program Files\Dell\DellDock\DockLogin.exe [2008-09-24 155648]
      R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe [2007-03-22 355096]
      R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
      R2 STacSV;SigmaTel Audio Service; C:\Windows\system32\STacSV.exe [2007-11-12 102400]
      R2 wltrysvc;Dell Wireless WLAN Tray Service; C:\Windows\System32\WLTRYSVC.EXE [2008-10-27 24064]
      R2 XAudioService;XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [2008-06-23 386560]
      S2 gupdate;Google Update Service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-29 135664]
      S3 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2010-04-24 74360]
      S3 GoToAssist;GoToAssist; C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe [2009-01-17 16680]
      S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-07-05 182768]
      S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
      S3 stllssvr;stllssvr; C:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2008-03-24 74384]

      -----------------EOF-----------------
      0
      1. Et voici le fichier info :

        info.txt logfile of random's system information tool 1.06 2010-05-29 06:45:42

        ======Uninstall list======

        -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88564CEF-20A5-4EF2-A05F-309F2EBA9B06}\setup.exe" -l0x9
        -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A1A5BA3E-9ABF-4037-820B-6151022B8ACB}\setup.exe" -l0x9
        -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A82F10CB-18B5-4EAC-AEF2-FA49CD565626}\setup.exe" -l0x9
        -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D5BA7C09-E523-478C-9C37-A1D86C76383E}\setup.exe" -l0x9
        -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F6366726-BA44-4D6A-8ECE-476E2E616AD1}\setup.exe" -l0x9
        Adobe Flash Player ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
        Adobe Reader 8.1.1-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81100000003}
        Adobe Reader 8.2.0-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A82000000003}
        Advanced Audio FX Engine-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88564CEF-20A5-4EF2-A05F-309F2EBA9B06}\setup.exe" -l0x9 /remove
        Advanced Video FX Engine-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D5BA7C09-E523-478C-9C37-A1D86C76383E}\setup.exe" -l0x9 /remove
        ASUSDVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\Setup.exe" -uninstall
        AutoCAD 2005 - English-->MsiExec.exe /I{5783F2D7-0301-0409-0002-0060B0CE6BBA}
        Autodesk DWF Viewer-->C:\PROGRA~1\Autodesk\AUTODE~1\Setup.exe /remove
        Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
        CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
        Chinese Traditional Fonts Support For Adobe Reader 8-->MsiExec.exe /I{AC76BA86-7AD7-2448-0000-800000000003}
        Cisco EAP-FAST Module-->MsiExec.exe /I{6D3963B0-E13B-4FC3-B0FF-506A304BB043}
        Cisco LEAP Module-->MsiExec.exe /I{83770D14-21B9-44B3-8689-F7B523F94560}
        Cisco PEAP Module-->MsiExec.exe /I{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}
        Compatibility Pack for the 2007 Office system-->MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
        Conexant HDA D330 MDC V.92 Modem-->C:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2C06&SUBSYS_14F1000F\UIU32m.exe -U -Idel000fz.INF
        Dell Best of Web-->MsiExec.exe /I{C39A4E1F-9AF1-4FE1-A80E-A5B867FABB42}
        Dell Dock-->MsiExec.exe /I{F6CB42B9-F033-4152-8813-FF11DA8E6A78}
        Dell Getting Started Guide-->MsiExec.exe /I{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}
        Dell Support Center-->MsiExec.exe /X{E3BFEE55-39E2-4BE0-B966-89FE583822C1}
        Dell Touchpad-->C:\Program Files\DellTPad\Uninstap.exe ADDREMOVE
        Dell Webcam Center-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A1A5BA3E-9ABF-4037-820B-6151022B8ACB}\setup.exe" -l0x9 /remove
        Dell Webcam Manager-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F6366726-BA44-4D6A-8ECE-476E2E616AD1}\setup.exe" -l0x9 /remove
        Dell Wireless WLAN Card Utility-->"C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwlu00.exe" verbose /rootkey="Software\Broadcom\802.11\UninstallInfo" /rootdir="C:\Program Files\Dell\Dell Wireless WLAN Card"
        Digital Line Detect-->C:\Program Files\InstallShield Installation Information\{E646DCF0-5A68-11D5-B229-002078017FBF}\setup.exe -runfromtemp -l0x0009 -removeonly
        EDocs-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6B7B6D4D-8F9B-4CB3-8CA4-BCA9CC4C1A22}\setup.exe"
        Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_A22A7357696681C5.exe" /uninstall
        Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
        Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
        GoToAssist 8.0.0.514-->C:\Program Files\Citrix\GoToAssist\514\G2AUninstaller.exe /uninstall
        Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
        Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
        Intel(R) Matrix Storage Manager-->C:\Windows\System32\Imsmudlg.exe
        Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
        K-Lite Mega Codec Pack 4.3.1-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
        Laptop Integrated Webcam Driver (1.03.02.0719) -->C:\Windows\CtDrvIns.exe -uninstall -script OEM002.uns -plugin OEM02Pin.dll -pluginres OEM02Pin.crl -nodisconprompt -langid 0x0409
        Live! Cam Avatar Creator-->C:\Program Files\InstallShield Installation Information\{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}\setup.exe -runfromtemp -l0x0009 -removeonly /remove
        Live! Cam Avatar v1.0-->C:\Program Files\InstallShield Installation Information\{1D5E29AD-39A9-4D0A-A8B6-46A6FCD8C995}\setup.exe -runfromtemp -l0x0009 -removeonly /remove
        Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
        MediaDirect-->C:\Program Files\InstallShield Installation Information\{9C6978E8-B6D0-4AB7-A7A0-D81A74FBF745}\setup.exe -runfromtemp -l0x0009 -cluninstall
        Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
        Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
        Microsoft Office Professional Edition 2003-->MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
        Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
        Microsoft Works-->MsiExec.exe /I{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}
        Modem Diagnostic Tool-->MsiExec.exe /I{294EAADF-E50F-4DD8-AD8D-19587EA10512}
        MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
        MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
        NetWaiting-->C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\setup.exe -runfromtemp -l0x0009 -removeonly
        OutlookAddinSetup-->MsiExec.exe /I{9BDEF074-020E-458D-ADC5-8FF68E0C9B56}
        QuickSet-->MsiExec.exe /I{4B6AD248-D3BF-426A-8D64-847288154F13}
        Roxio Creator Audio-->MsiExec.exe /I{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}
        Roxio Creator Copy-->MsiExec.exe /I{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}
        Roxio Creator Data-->MsiExec.exe /I{08E81ABD-79F7-49C2-881F-FD6CB0975693}
        Roxio Creator DE-->C:\ProgramData\Uninstall\{09760D42-E223-42AD-8C3E-55B47D0DDAC3}\setup.exe /x {09760D42-E223-42AD-8C3E-55B47D0DDAC3}
        Roxio Creator DE-->MsiExec.exe /I{ED439A64-F018-4DD4-8BA5-328D85AB09AB}
        Roxio Creator Tools-->MsiExec.exe /I{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}
        Roxio Express Labeler 3-->MsiExec.exe /I{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
        Roxio Update Manager-->MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
        Skype(TM) 4.0-->MsiExec.exe /X{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}
        Spelling Dictionaries Support For Adobe Reader 8-->MsiExec.exe /I{AC76BA86-7AD7-5464-3428-800000000003}
        Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
        UniKey 4.0 NT-->C:\Program Files\UniKey\uninst.exe
        Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""

        ======Security center information======

        AS: Windows Defender

        ======System event log======

        Computer Name: d-PC
        Event Code: 134
        Message: NtpClient was unable to set a manual peer to use as a time source because of DNS resolution error on 'time.windows.com,0x9'. NtpClient will try again in 15 minutes and double the reattempt interval thereafter. The error was: No such host is known. (0x80072AF9)
        Record Number: 102209
        Source Name: Microsoft-Windows-Time-Service
        Time Written: 20100528234342.000000-000
        Event Type: Warning
        User:

        Computer Name: d-PC
        Event Code: 134
        Message: NtpClient was unable to set a manual peer to use as a time source because of DNS resolution error on 'time.windows.com,0x9'. NtpClient will try again in 15 minutes and double the reattempt interval thereafter. The error was: No such host is known. (0x80072AF9)
        Record Number: 102210
        Source Name: Microsoft-Windows-Time-Service
        Time Written: 20100528234352.000000-000
        Event Type: Warning
        User:

        Computer Name: d-PC
        Event Code: 134
        Message: NtpClient was unable to set a manual peer to use as a time source because of DNS resolution error on 'time.windows.com,0x9'. NtpClient will try again in 15 minutes and double the reattempt interval thereafter. The error was: No such host is known. (0x80072AF9)
        Record Number: 102212
        Source Name: Microsoft-Windows-Time-Service
        Time Written: 20100528234437.000000-000
        Event Type: Warning
        User:

        Computer Name: d-PC
        Event Code: 134
        Message: NtpClient was unable to set a manual peer to use as a time source because of DNS resolution error on 'time.windows.com,0x9'. NtpClient will try again in 15 minutes and double the reattempt interval thereafter. The error was: No such host is known. (0x80072AF9)
        Record Number: 102213
        Source Name: Microsoft-Windows-Time-Service
        Time Written: 20100528234439.000000-000
        Event Type: Warning
        User:

        Computer Name: d-PC
        Event Code: 134
        Message: NtpClient was unable to set a manual peer to use as a time source because of DNS resolution error on 'time.windows.com,0x9'. NtpClient will try again in 15 minutes and double the reattempt interval thereafter. The error was: No such host is known. (0x80072AF9)
        Record Number: 102216
        Source Name: Microsoft-Windows-Time-Service
        Time Written: 20100528234441.000000-000
        Event Type: Warning
        User:

        =====Application event log=====

        Computer Name: d-PC
        Event Code: 3013
        Message: The entry <MAPI://{S-1-5-21-2445960749-1516840855-336234774-1000}/PERSONAL FOLDERS($CFA48716)/X/OUTBOX/????????????????????????> in the hash map cannot be updated.

        Context: Application, SystemIndex Catalog

        Details:
        A device attached to the system is not functioning. (0x8007001f)

        Record Number: 9522
        Source Name: Microsoft-Windows-Search
        Time Written: 20100528090232.000000-000
        Event Type: Error
        User:

        Computer Name: d-PC
        Event Code: 3013
        Message: The entry <MAPI://{S-1-5-21-2445960749-1516840855-336234774-1000}/PERSONAL FOLDERS($CFA48716)/X/OUTBOX/????????????????????????> in the hash map cannot be updated.

        Context: Application, SystemIndex Catalog

        Details:
        A device attached to the system is not functioning. (0x8007001f)

        Record Number: 9523
        Source Name: Microsoft-Windows-Search
        Time Written: 20100528090232.000000-000
        Event Type: Error
        User:

        Computer Name: d-PC
        Event Code: 508
        Message: Windows (2336) Windows: A request to write to the file "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb" at offset 545005568 (0x00000000207c2000) for 8192 (0x00002000) bytes succeeded, but took an abnormally long time (2837 seconds) to be serviced by the OS. This problem is likely due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem.
        Record Number: 9524
        Source Name: ESENT
        Time Written: 20100528131901.000000-000
        Event Type: Warning
        User:

        Computer Name: d-PC
        Event Code: 3013
        Message: The entry <MAPI://{S-1-5-21-2445960749-1516840855-336234774-1000}/PERSONAL FOLDERS($CFA48716)/X/OUTBOX/????????????????????????> in the hash map cannot be updated.

        Context: Application, SystemIndex Catalog

        Details:
        A device attached to the system is not functioning. (0x8007001f)

        Record Number: 9525
        Source Name: Microsoft-Windows-Search
        Time Written: 20100528131932.000000-000
        Event Type: Error
        User:

        Computer Name: d-PC
        Event Code: 3013
        Message: The entry <MAPI://{S-1-5-21-2445960749-1516840855-336234774-1000}/PERSONAL FOLDERS($CFA48716)/X/OUTBOX/????????????????????????> in the hash map cannot be updated.

        Context: Application, SystemIndex Catalog

        Details:
        A device attached to the system is not functioning. (0x8007001f)

        Record Number: 9526
        Source Name: Microsoft-Windows-Search
        Time Written: 20100528131932.000000-000
        Event Type: Error
        User:

        =====Security event log=====

        Computer Name: d-PC
        Event Code: 4624
        Message: An account was successfully logged on.

        Subject:
        Security ID: S-1-0-0
        Account Name: -
        Account Domain: -
        Logon ID: 0x0

        Logon Type: 3

        New Logon:
        Security ID: S-1-5-7
        Account Name: ANONYMOUS LOGON
        Account Domain: NT AUTHORITY
        Logon ID: 0x665e85e
        Logon GUID: {00000000-0000-0000-0000-000000000000}

        Process Information:
        Process ID: 0x0
        Process Name: -

        Network Information:
        Workstation Name: DARA
        Source Network Address: 192.168.1.100
        Source Port: 1796

        Detailed Authentication Information:
        Logon Process: NtLmSsp
        Authentication Package: NTLM
        Transited Services: -
        Package Name (NTLM only): NTLM V1
        Key Length: 0

        This event is generated when a logon session is created. It is generated on the computer that was accessed.

        The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

        The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).

        The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.

        The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.

        The authentication information fields provide detailed information about this specific logon request.
        - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
        - Transited services indicate which intermediate services have participated in this logon request.
        - Package name indicates which sub-protocol was used among the NTLM protocols.
        - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
        Record Number: 74793
        Source Name: Microsoft-Windows-Security-Auditing
        Time Written: 20100506030001.430000-000
        Event Type: Audit Success
        User:

        Computer Name: d-PC
        Event Code: 4634
        Message: An account was logged off.

        Subject:
        Security ID: S-1-5-7
        Account Name: ANONYMOUS LOGON
        Account Domain: NT AUTHORITY
        Logon ID: 0x665e85e

        Logon Type: 3

        This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
        Record Number: 74794
        Source Name: Microsoft-Windows-Security-Auditing
        Time Written: 20100506030001.534000-000
        Event Type: Audit Success
        User:

        Computer Name: d-PC
        Event Code: 4624
        Message: An account was successfully logged on.

        Subject:
        Security ID: S-1-0-0
        Account Name: -
        Account Domain: -
        Logon ID: 0x0

        Logon Type: 3

        New Logon:
        Security ID: S-1-5-7
        Account Name: ANONYMOUS LOGON
        Account Domain: NT AUTHORITY
        Logon ID: 0x665e8c2
        Logon GUID: {00000000-0000-0000-0000-000000000000}

        Process Information:
        Process ID: 0x0
        Process Name: -

        Network Information:
        Workstation Name: DARA
        Source Network Address: 192.168.1.100
        Source Port: 1796

        Detailed Authentication Information:
        Logon Process: NtLmSsp
        Authentication Package: NTLM
        Transited Services: -
        Package Name (NTLM only): NTLM V1
        Key Length: 0

        This event is generated when a logon session is created. It is generated on the computer that was accessed.

        The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

        The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).

        The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.

        The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.

        The authentication information fields provide detailed information about this specific logon request.
        - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
        - Transited services indicate which intermediate services have participated in this logon request.
        - Package name indicates which sub-protocol was used among the NTLM protocols.
        - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
        Record Number: 74795
        Source Name: Microsoft-Windows-Security-Auditing
        Time Written: 20100506030001.594000-000
        Event Type: Audit Success
        User:

        Computer Name: d-PC
        Event Code: 4634
        Message: An account was logged off.

        Subject:
        Security ID: S-1-5-7
        Account Name: ANONYMOUS LOGON
        Account Domain: NT AUTHORITY
        Logon ID: 0x665e8c2

        Logon Type: 3

        This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
        Record Number: 74796
        Source Name: Microsoft-Windows-Security-Auditing
        Time Written: 20100506030001.608000-000
        Event Type: Audit Success
        User:

        Computer Name: d-PC
        Event Code: 4624
        Message: An account was successfully logged on.

        Subject:
        Security ID: S-1-0-0
        Account Name: -
        Account Domain: -
        Logon ID: 0x0

        Logon Type: 3

        New Logon:
        Security ID: S-1-5-7
        Account Name: ANONYMOUS LOGON
        Account Domain: NT AUTHORITY
        Logon ID: 0x666f4a7
        Logon GUID: {00000000-0000-0000-0000-000000000000}

        Process Information:
        Process ID: 0x0
        Process Name: -

        Network Information:
        Workstation Name: DARA
        Source Network Address: 192.168.1.100
        Source Port: 1796

        Detailed Authentication Information:
        Logon Process: NtLmSsp
        Authentication Package: NTLM
        Transited Services: -
        Package Name (NTLM only): NTLM V1
        Key Length: 0

        This event is generated when a logon session is created. It is generated on the computer that was accessed.

        The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

        The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).

        The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.

        The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.

        The authentication information fields provide detailed information about this specific logon request.
        - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
        - Transited services indicate which intermediate services have participated in this logon request.
        - Package name indicates which sub-protocol was used among the NTLM protocols.
        - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
        Record Number: 74797
        Source Name: Microsoft-Windows-Security-Auditing
        Time Written: 20100506030608.459000-000
        Event Type: Audit Success
        User:

        ======Environment variables======

        "ComSpec"=%SystemRoot%\system32\cmd.exe
        "FP_NO_HOST_CHECK"=NO
        "OS"=Windows_NT
        "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\10.0\DLLShared\;C:\Program Files\Common Files\Autodesk Shared\
        "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
        "PROCESSOR_ARCHITECTURE"=x86
        "TEMP"=%SystemRoot%\TEMP
        "TMP"=%SystemRoot%\TEMP
        "USERNAME"=SYSTEM
        "windir"=%SystemRoot%
        "PROCESSOR_LEVEL"=6
        "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
        "PROCESSOR_REVISION"=0f0d
        "NUMBER_OF_PROCESSORS"=2
        "TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
        "DFSTRACINGON"=FALSE
        "RoxioCentral"=C:\Program Files\Common Files\Roxio Shared\10.0\Roxio Central36\

        -----------------EOF-----------------
        0
        1. Et pour info, voici le lien

          http://www.cijoint.fr/cjlink.php?file=cj201005/cijueOZ8Sd.txt
          0
          1. Contributeur sécurité
            salut

            le rapport log.txt est incomplet . Remets le via ci-joint.

            C'est bon pour info.txt

            Les 2 fichiers sont sauvegardés dans le dossier C:\rsit
            Chaque difficulté rencontrée doit être l'occasion d'un nouveau progrès.

            [Pierre de Coubertin]
            0
            1. voila le lien :

              http://www.cijoint.fr/cjlink.php?file=cj201005/cijH5anAxi.txt
              0
              1. Contributeur sécurité
                Télécharge maintenant FindyKill sur ton bureau :

                http://pagesperso-orange.fr/NosTools/Chiquitine29/Setup.exe

                --> Lance l installation avec les paramètres par défaut

                --> Fais un clic droit sur le raccourci FindyKill sur ton bureau

                --> Choisi exécuter en tant qu administrateur

                --> Au menu principal,choisi l option 1 (Recherche)

                --> Post le rapport FindyKill.txt

                Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
                0
                1. Voila:

                  ############################## | FindyKill V5.043 |

                  # User : d (Administrators) # D-PC
                  # Update on 12/05/2010 by El Desaparecido
                  # Start at: 7:55:23 PM | 5/30/2010
                  # Website : http://pagesperso-orange.fr/NosTools/index.html
                  # Contact : FindyKill.Contact@gmail.com

                  # Intel(R) Core(TM)2 Duo CPU T5800 @ 2.00GHz
                  # Microsoft® Windows Vista(TM) Home Premium (6.0.6001 32-bit) # Service Pack 1
                  # Internet Explorer 7.0.6001.18000
                  # Windows Firewall Status : Disabled

                  # C:\ # Local Fixed Disk # 220.32 Go (126.15 Go free) [OS] # NTFS
                  # D:\ # Local Fixed Disk # 10 Go (4.81 Go free) [RECOVERY] # NTFS
                  # E:\ # CD-ROM Disc

                  ################## | Eléments infectieux |

                  ################## | Registre |

                  ################## | Etat |

                  # Affichage des fichiers cachés : OK

                  # Mode sans echec : OK

                  # Uac : OK

                  # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
                  # EapHost -> Start = 3 ( Good = 2 | Bad = 4 )
                  # Wlansvc -> Start = 2 ( Good = 2 | Bad = 4 )
                  # SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
                  # windefend -> Start = 2 ( Good = 2 | Bad = 4 )
                  # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
                  # wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

                  ################## | ! Fin du rapport # FindyKill V5.043 ! |
                  0
                  1. Contributeur sécurité
                    ● Télécharges Malwarebytes

                    ● Tu auras un tutoriel à ta disposition pour l'installer et l'utiliser correctement.

                    ● Fais la mise à jour du logiciel (elle se fait normalement à l'installation)

                    ● Lance une analyse complète en cliquant sur "Exécuter un examen complet"

                    ● Sélectionnes les disques que tu veux analyser et cliques sur "Lancer l'examen"

                    ● L'analyse peut durer un bon moment.....

                    ● Une fois l'analyse terminée, cliques sur "OK" puis sur "Afficher les résultats"

                    ● Vérifies que tout est bien coché et cliques sur "Supprimer la sélection" => et ensuite sur "OK"

                    ● Un rapport va s'ouvrir dans le bloc note... Fais un copié/collé du rapport dans ta prochaine réponse sur le forum

                    ● Il se pourrait que certains fichiers devront être supprimés au redémarrage du PC... Faites le en cliquant sur "oui" à la question posée

                    Les créateurs d'infections utilisent les emplacements des fichiers système pour hébérger les infections, d'où les fichiers . dll ou exe dans ces series d'infections.
                    MABM est très régulièrement mis à jour pour ne pas supprimer les fichiers légitimes de windows, donc pas de craintes de ce côté là.

                    0
                    1. Apparemment rien...

                      Malwarebytes' Anti-Malware 1.46
                      www.malwarebytes.org

                      Version de la base de données: 4052

                      Windows 6.0.6001 Service Pack 1
                      Internet Explorer 7.0.6001.18000

                      5/31/2010 3:25:36 PM
                      mbam-log-2010-05-31 (15-25-36).txt

                      Type d'examen: Examen complet (C:\|D:\|)
                      Elément(s) analysé(s): 245538
                      Temps écoulé: 1 heure(s), 23 minute(s), 55 seconde(s)

                      Processus mémoire infecté(s): 0
                      Module(s) mémoire infecté(s): 0
                      Clé(s) du Registre infectée(s): 0
                      Valeur(s) du Registre infectée(s): 0
                      Elément(s) de données du Registre infecté(s): 0
                      Dossier(s) infecté(s): 0
                      Fichier(s) infecté(s): 0

                      Processus mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Module(s) mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Clé(s) du Registre infectée(s):
                      (Aucun élément nuisible détecté)

                      Valeur(s) du Registre infectée(s):
                      (Aucun élément nuisible détecté)

                      Elément(s) de données du Registre infecté(s):
                      (Aucun élément nuisible détecté)

                      Dossier(s) infecté(s):
                      (Aucun élément nuisible détecté)

                      Fichier(s) infecté(s):
                      (Aucun élément nuisible détecté)
                      0
                      1. Contributeur sécurité
                        re

                        on va passer un autre outils de diagnostique

                        ● Télécharges ZHPDiag ( de Nicolas coolman ).

                        ● Double clique sur le fichier d'installation, puis installes le avec les paramètres par défaut ( N'oublies pas de cocher " Créer une icône sur le bureau " )

                        ● Lances ZHPDiag en double cliquant sur l'icône présente sur ton bureau

                        ● Cliques sur la loupe en haut à gauche, puis laisse l'outil scanner.

                        ● Une fois le scan terminé, cliques sur l'icône en forme de disquette et enregistres le fichier sur ton bureau.

                        ● Rends toi sur www.cjoint.com

                        ● Cliques sur " Parcourir " dans la partie " Joindre un fichier[...] "

                        ● Séléctionnes le rapport ZHPdiag.txt qui se trouve sur ton bureau

                        ● Cliques ensuite sur " Créer le lien cjoint " et copie/colle le dans ton prochain message
                        0
                        1. Voila : http://www.cijoint.fr/cjlink.php?file=cj201006/cij1fmfVAl.txt
                          0
                          1. Contributeur sécurité
                            bonjour

                            rien ne montre une infection dans tes rapports et c'est là le problème .

                            As-tu toujours ces pubs avec IE ?
                            0
                            1. Non.

                              Ce n'est arrive qu'une fois.

                              Est-ce que cela peut etre du aux serveurs vietnamiens ou a des relais divers ????

                              Et si c'est le cas, y a t il un risque pour le PC ??
                              0
                              1. Contributeur sécurité
                                bonjour

                                j'attends une réponse à ta question . pour l'instant , on va mettre à jour ton pc.

                                1) Java , adobe raider et internet explorer ne sont pas jour pas à jour , c'est une faille de sécurité importante.
                                Supprimes ces versions de java et adobe raider de "programmes et fonctionnalité " et réinstaller ces versions

                                java
                                adobe reader

                                IE 8

                                2) Utilises firefox au lieu de Internet Explorer . Et mettre à firefox ces deux extentions:

                                adblocks pour stopper les pubs
                                wot pour contrôler la fiabilité des sites
                                0
                                1. Contributeur sécurité
                                  bonjour

                                  et merci à Electricien69

                                  ==> J'ai besoin de savoir si le PC est un pc perso ou un pc d'entreprise ?

                                  ensuite , télécharges et exécutes ceci :

                                  hijackthis et suis le tutoriel proposé

                                  post ensuite le rapport
                                  0