Infecté par System tool 2011

Bonjour,

Mon ordinateur est infecté par System tool 2011, alors j'ai donc cherché sur le net comment régler le problème.
J'ai donc télécharge Malwarbytes' Anti-Malware et en mode sans échec j'ai lancé l'analyse et supprimé tout ce qu'il a trouvé.
Le truc c'est que sur les forums que j'ai trouver on demande aux personnes qui avait le problème de poster le rapport éditer par Malwarebytes, mais je ne comprends pas pourquoi? Il se peut que l'opération n'est pas fonctionner? En tout cas moi j'ai l'impression que ca a marché.

Donc si quelqu'un qui comprend plus que moi pouvait juste me dire si c'est bon ou pas ca serait sympa, par ce que pour moi c'est du petit chinois ...

Voila le rapport :

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Version de la base de données: 5608

Windows 6.1.7600 (Safe Mode)
Internet Explorer 8.0.7600.16385

26/01/2011 15:08:42
mbam-log-2011-01-26 (15-08-42).txt

Type d'examen: Examen complet (C:\|)
Elément(s) analysé(s): 430671
Temps écoulé: 45 minute(s), 46 seconde(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 98
Valeur(s) du Registre infectée(s): 4
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 10
Fichier(s) infecté(s): 17

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\CLSID\{100EB1FD-D03E-47fd-81F3-EE91287F9465} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{E343EDFC-1E6C-4cb5-AA29-E9C922641C80} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{D8560AC2-21B5-4C1A-BDD4-BD12BC83B082} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.RprtCtrl.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.RprtCtrl (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{100EB1FD-D03E-47FD-81F3-EE91287F9465} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{100EB1FD-D03E-47FD-81F3-EE91287F9465} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{100EB1FD-D03E-47FD-81F3-EE91287F9465} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{0D82ACD6-A652-4496-A298-2BDE705F4227} (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{7025E484-D4B0-441a-9F0B-69063BD679CE} (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{8258B35C-05B8-4c0e-9525-9BCCC70F8F2D} (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{A89256AD-EC17-4a83-BEF5-4B8BC4F39306} (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{09325003-167C-483d-A4BA-8B3122ABB432} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{F1A1892C-2A6C-4817-98B4-FF81443CBA20} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{E25DA6D6-C365-46CF-ABAF-DC5893135D7A} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.HbGuru.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.HbGuru (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{20EA9658-6BC3-4599-A87D-6371FE9295FC} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.HbAx.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.HbAx (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{2721A8E5-BFDB-4562-9912-9E0531CA616C} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{5FE0CEAE-CB69-40AF-A323-40F94257DACB} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{65A16874-2ED0-460E-A547-5FE2EC3A13A7} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.MozillaPSExecuter.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.MozillaPSExecuter (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{396CFC12-932D-496b-A0A8-5D7201E105E1} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{573F4ABB-A1A2-44ED-9BA9-A8DAD40AAC46} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{71E02280-5212-45C3-B174-4D5A35DA254F} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.MozillaNvgtnTrpr.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.MozillaNvgtnTrpr (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{60DA826C-B1C6-4358-BDEC-4837CED45470} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.KOPFF.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.KOPFF (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{6DD76B7B-6423-4df0-9A07-84A6CAD973A0} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.Dwnldr.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.Dwnldr (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{74C22317-5B90-471f-9AD2-FEC049870A16} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.Scopes.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.Scopes (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7F6CFB6A-9227-4bb8-B941-F2B067E76F51} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.TriggerImmidiateOrRandomTS.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.TriggerImmidiateOrRandomTS (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{A16AD1E9-F69A-45af-9462-B1C286708842} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.IEButtonA.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.IEButtonA (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{A7CDDCDC-BEEB-4685-A062-978F5E07CEEE} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.HbInfoBand.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.HbInfoBand (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{A7CDDCDC-BEEB-4685-A062-978F5E07CEEE} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7CDDCDC-BEEB-4685-A062-978F5E07CEEE} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{AB0EE208-DF60-4fa7-A617-C4269760033E} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.Reporter.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.Reporter (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{C1089F63-7AFC-4538-B0EB-BEA0F4225A57} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.Stock.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.Stock (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{C9CCBB35-D123-4a31-AFFC-9B2933132116} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.IEButton.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.IEButton (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{CC7BD6F1-565C-47ce-A5BB-9C935E77B59D} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{02AED140-2B62-4B49-8B3B-179020CC39B9} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{17BF1E05-C0E8-413C-BD1F-A481EEA3B8E9} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.CntntDic.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.CntntDic (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{CFC16189-8A92-4a29-A940-60248385F426} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.CntntDisp.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.CntntDisp (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{DEE758B4-C3FB-4a5b-9939-848B9C77A2FB} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{E12AEAB6-7D12-4c07-8E36-5892EFB4DAFB} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.TriggerImmidiate.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.TriggerImmidiate (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{E2F2C137-A782-4fb5-81AF-086156F5EB0A} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.AsyncReporter.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.AsyncReporter (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{F1D06C9F-51F0-4476-BEDE-5DDF91BE304E} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.ReportData.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.ReportData (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{F3A32DF2-7413-4fb1-B575-1AC920A17B76} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.TriggerOnceInDay.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.TriggerOnceInDay (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{ACC62306-9A63-4864-BD2F-C8825D2D7EA6} (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{21BA420E-161C-413A-B21E-4E42AE1F4226} (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{CDCA70D8-C6A6-49EE-9BED-7429D6C477A2} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{8AD9AD05-36BE-4E40-BA62-5422EB0D02FB} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{D136987F-E1C4-4CCC-A220-893DF03EC5DF} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C5428486-50A0-4A02-9D20-520B59A9F9B2} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{C5428486-50A0-4A02-9D20-520B59A9F9B2} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C5428486-50A0-4A02-9D20-520B59A9F9B3} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{C5428486-50A0-4A02-9D20-520B59A9F9B3} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{89F88394-3828-4d03-A0CF-8203604C3DA6} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D4233F04-1789-483c-A137-731E8F113DD5} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ShopperReportsSA (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\BRNstIE.DLL (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\CmndFF.DLL (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\mozillaps.dll (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\Pltfrm.DLL (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\ShopperReports3 (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\ShopperReports3 (Adware.ShopperReports) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\eLgAnHk06511 (Trojan.FakeAlert) -> Value: eLgAnHk06511 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform\ShopperReports 3.0.497.0 (Adware.HotBar) -> Value: ShopperReports 3.0.497.0 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform\SRS_IT_E8790572BC765F5430A097 (Malware.Trace) -> Value: SRS_IT_E8790572BC765F5430A097 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions\ShopperReports@ShopperReports.com (ShopperReports) -> Value: ShopperReports@ShopperReports.com -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
c:\Users\Julien\AppData\Roaming\shopperreports3 (Adware.ShopperReports) -> Quarantined and deleted successfully.
c:\program files (x86)\shopperreports3 (Adware.ShopperReports) -> Quarantined and deleted successfully.
c:\program files (x86)\shopperreports3\bin (Adware.ShopperReports) -> Quarantined and deleted successfully.
c:\program files (x86)\shopperreports3\bin\3.0.497.0 (Adware.ShopperReports) -> Quarantined and deleted successfully.
c:\program files (x86)\shopperreports3\bin\3.0.497.0\firefox (Adware.ShopperReports) -> Quarantined and deleted successfully.
c:\program files (x86)\shopperreports3\bin\3.0.497.0\firefox\firefoxtoolbar (Adware.ShopperReports) -> Quarantined and deleted successfully.
c:\program files (x86)\shopperreports3\bin\3.0.497.0\firefox\firefoxtoolbar\extensions (Adware.ShopperReports) -> Quarantined and deleted successfully.
c:\program files (x86)\shopperreports3\bin\3.0.497.0\firefox\firefoxtoolbar\extensions\chrome (Adware.ShopperReports) -> Quarantined and deleted successfully.
c:\program files (x86)\shopperreports3\bin\3.0.497.0\firefox\firefoxtoolbar\extensions\components (Adware.ShopperReports) -> Quarantined and deleted successfully.
c:\programdata\microsoft\Windows\start menu\Programs\shopperreports (Adware.ShopperReports) -> Quarantined and deleted successfully.

Fichier(s) infecté(s):
c:\programdata\elganhk06511\elganhk06511.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\program files (x86)\shopperreports3\bin\3.0.497.0\shopperreports.dll (Adware.ShopperReports) -> Quarantined and deleted successfully.
c:\program files (x86)\shopperreports3\bin\3.0.497.0\Pltfrm.dll (Adware.ShopperReports) -> Quarantined and deleted successfully.
c:\program files (x86)\shopperreports3\bin\3.0.497.0\mozillaps.dll (Adware.ShopperReports) -> Quarantined and deleted successfully.
c:\program files (x86)\shopperreports3\bin\3.0.497.0\CmndFF.dll (Adware.ShopperReports) -> Quarantined and deleted successfully.
c:\program files (x86)\shopperreports3\bin\3.0.497.0\cntntcntr.dll (Adware.ShopperReports) -> Quarantined and deleted successfully.
c:\program files (x86)\shopperreports3\bin\3.0.497.0\BRNstIE.dll (Adware.ShopperReports) -> Quarantined and deleted successfully.
c:\program files (x86)\shopperreports3\bin\3.0.497.0\shopperreportsuninstaller.exe (Adware.ShopperReports) -> Quarantined and deleted successfully.
c:\program files (x86)\shopperreports3\bin\3.0.497.0\firefox\firefoxtoolbar\extensions\components\BRNstFF.dll (Adware.ShopperReports) -> Quarantined and deleted successfully.
c:\program files (x86)\shopperreports3\bin\3.0.497.0\link.ico (Adware.ShopperReports) -> Quarantined and deleted successfully.
c:\program files (x86)\shopperreports3\bin\3.0.497.0\firefox\firefoxtoolbar\extensions\chrome.manifest (Adware.ShopperReports) -> Quarantined and deleted successfully.
c:\program files (x86)\shopperreports3\bin\3.0.497.0\firefox\firefoxtoolbar\extensions\install.rdf (Adware.ShopperReports) -> Quarantined and deleted successfully.
c:\program files (x86)\shopperreports3\bin\3.0.497.0\firefox\firefoxtoolbar\extensions\chrome\firefoxtoolbar.jar (Adware.ShopperReports) -> Quarantined and deleted successfully.
c:\program files (x86)\shopperreports3\bin\3.0.497.0\firefox\firefoxtoolbar\extensions\components\BRNstFF.xpt (Adware.ShopperReports) -> Quarantined and deleted successfully.
c:\programdata\microsoft\Windows\start menu\Programs\shopperreports\About Us.lnk (Adware.ShopperReports) -> Quarantined and deleted successfully.
c:\programdata\microsoft\Windows\start menu\Programs\shopperreports\customer support.lnk (Adware.ShopperReports) -> Quarantined and deleted successfully.
c:\programdata\microsoft\Windows\start menu\Programs\shopperreports\shopperreports uninstall instructions.lnk (Adware.ShopperReports) -> Quarantined and deleted successfully.

10 réponses

  1. salut
    tu es verrolé de chez verolé !!!!!!!

    c'est bien d'avoir fait malawarebytes,est ce que sytem tool est toujours actif???

    tu peux faire un scan gratuit en ligne avec bitdefender (il est très corrosif avec tous les nuisibles

    0
    1. Merci de ta réponse.

      Je ne crois pas que system tool soit toujours actif, quand je démarre mon pc j'ai mon fond d'écran normal et je n'ai plus les message qui s'affichaient en bas à droite de l'écran.

      Je viens de faire un scan en ligne avec bitdefender et il me dit : aucune infection détecté.

      C'est plutôt bon signe ça, non?

      Sinon est ce que les fichier que malwarebytes a trouvé ont été supprimé ou seulement déplacé en quarantaine ? Faut il que je les supprime manuellement ?
      0
      1. Modérateur
        Salut,

        Tu peux suivre les indications de cette page pour t'aider : https://www.malekal.com/tutorial-otl/

        * Télécharge http://www.geekstogo.com/forum/files/file/398-otl-oldtimers-list-it/ sur ton bureau.
        (Sous Vista/Win7, il faut cliquer droit sur OTL et choisir Exécuter en tant qu'administrateur)

        * Lance OTL
        * Sous Peronnalisation, copie-colle ce qu'il y a dans le cadre ci-dessous :
        netsvcs
        msconfig
        safebootminimal
        safebootnetwork
        activex
        drivers32
        %ALLUSERSPROFILE\%Application Data\*.
        %ALLUSERSPROFILE%\Application Data\*.exe /s
        %APPDATA%\*.
        %APPDATA%\*.exe /s
        %SYSTEMDRIVE%\*.exe
        %systemroot%\*. /mp /s
        %systemroot%\system32\*.dll /lockedfiles
        %systemroot%\Tasks\*.job /lockedfiles
        %systemroot%\system32drivers\*.sys /lockedfiles
        %systemroot%\System32config\*.sav
        /md5start
        explorer.exe
        winlogon.exe
        wininit.exe
        /md5stop
        CREATERESTOREPOINT

        * Clique sur le bouton Analyse.
        * Quand le scan est fini, utilise le site http://www.cijoint.fr/ pour me donner les deux rapports : OTL.Txt et Extras.Txt.

        0
        1. Merci de ta réponse ultra rapide !!!

          J'ai effectué le scan et voici les rapports :

          http://www.cijoint.fr/cjlink.php?file=cj201101/cijnUa8ajb.txt
          http://www.cijoint.fr/cjlink.php?file=cj201101/cijMnlBxJg.txt
          0
          1. Modérateur
            AVG Antispyware est dépassé, désinstalle le.

            Supprime ce dosser : C:\ProgramData\eLgAnHk06511

            Adware Search Settings venu avec Free PDF to Word Converter

            Sachant que Malwarebyte a viré Shopping Reports.
            Vas falloir que tu fasses plus attention à ce que tu installes

            [2011/01/27 12:08:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Free PDF to Word Converter
            [2011/01/27 11:54:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Spigot
            [2011/01/27 11:54:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\pdfforge Toolbar
            [2011/01/27 11:54:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Application Updater


            Passe ce programme : http://www.teamxscript.org/adremoverTelechargement.html
            Poste le rapport ici.
            0
            1. J'ai désinstalé AVG ANtispyware et Free PDF to Word Converter ( pourtant j'ai décoché la case d'instalation de la toolbar), puis j'ai effectué le scan et voici le rapport :

              ======= RAPPORT D'AD-REMOVER 2.0.0.2,D | UNIQUEMENT XP/VISTA/7 =======

              Mis à jour par TeamXscript le 20/01/11 à 19:00
              Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
              Site web: http://www.teamxscript.org

              C:\Program Files (x86)\Ad-Remover\main.exe (SCAN [1]) -> Lancé à 12:48:58 le 27/01/2011, Mode normal

              Microsoft Windows 7 Édition Familiale Premium (X64)
              Julien@JULIEN-PC (Gigabyte Technology Co., Ltd. GA-MA770T-UD3P)

              ============== RECHERCHE ==============

              Service: "Application Updater" Présent

              Dossier trouvé: C:\Program Files (x86)\Application Updater
              Dossier trouvé: C:\Users\Julien\AppData\LocalLow\pdfforge
              Dossier trouvé: C:\Program Files (x86)\pdfforge Toolbar
              Dossier trouvé: C:\Users\Julien\AppData\LocalLow\Search Settings
              Dossier trouvé: C:\Users\Julien\AppData\LocalLow\ShopperReports3
              Dossier trouvé: C:\Program Files (x86)\Common Files\Spigot

              Clé trouvée: HKLM\Software\Classes\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402}
              Clé trouvée: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}
              Clé trouvée: HKLM\Software\Classes\Interface\{453DB0C5-F41C-4D97-8DD6-CC72ECD5F699}
              Clé trouvée: HKLM\Software\Classes\Interface\{4AFC07D0-59BB-46B8-B097-1A46E88EEF71}
              Clé trouvée: HKLM\Software\Classes\Interface\{6511CE4C-4722-40D0-AD3D-4AFA2F50978A}
              Clé trouvée: HKLM\Software\Classes\Interface\{83B2FE06-BA20-4F7D-96C6-6FC3A4E877D3}
              Clé trouvée: HKLM\Software\Classes\Interface\{9BEC9B38-BF39-4899-806E-A1C5DFEB60A2}
              Clé trouvée: HKLM\Software\Classes\Interface\{AEBF09E2-0C15-43C8-99BF-928C645D98A0}
              Clé trouvée: HKLM\Software\Classes\Interface\{B32966A2-F7C2-4362-A6CF-399EC8B44110}
              Clé trouvée: HKLM\Software\Classes\Interface\{B86D82BF-D39F-439A-A07C-43EDDC6F6EA6}
              Clé trouvée: HKLM\Software\Classes\Interface\{DA6305B9-0869-4235-8C1D-533A65E639E5}
              Clé trouvée: HKLM\Software\Classes\Interface\{DB885111-F39F-4D88-9EE5-C88460B6DF7B}
              Clé trouvée: HKLM\Software\Classes\Interface\{E6961C59-CFCE-4CCD-B794-BC78DB98413A}
              Clé trouvée: HKLM\Software\Classes\Interface\{F8B4EC8A-2407-4BE0-AEE2-0F430D65A90D}
              Clé trouvée: HKLM\Software\Application Updater
              Clé trouvée: HKLM\Software\pdfforge
              Clé trouvée: HKLM\Software\Search Settings
              Clé trouvée: HKCU\Software\AppDataLow\Software\pdfforge
              Clé trouvée: HKCU\Software\AppDataLow\Software\Search Settings
              Clé trouvée: HKCU\Software\AppDataLow\Software\ShopperReports3
              Clé trouvée: HKLM\Software\Classes\Installer\Products\B6FDFB1B30C3ef645B7DABBB00368D0E
              Clé trouvée: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{B1BFDF6B-3C03-46fe-B5D7-BABB0063D8E0}

              Valeur trouvée: HKLM\Software\Microsoft\Internet Explorer\Toolbar|{B922D405-6D13-4A2B-AE89-08A030DA4402}

              ============== SCAN ADDITIONNEL ==============

              ** Mozilla Firefox Version [3.6.13 (fr)] **

              -- C:\Users\Julien\AppData\Roaming\Mozilla\FireFox\Profiles\ej7sosno.default\Prefs.js --
              browser.download.lastDir, C:\\Users\\Julien\\Desktop
              browser.search.defaultenginename, eSnips Search
              browser.search.selectedEngine, eSnips Search
              browser.startup.homepage, hxxp://www.google.fr/
              browser.startup.homepage_override.mstone, rv:1.9.2.13
              keyword.URL, hxxp://eis.esnips.com/page/search_provider/?client_uuid=bda82ac0-85c3-4b48-b0d2-41fde8d1391d&q=

              ========================================

              ** Internet Explorer Version [8.0.7600.16385] **

              [HKCU\Software\Microsoft\Internet Explorer\Main]
              Do404Search: 0x01000000
              Enable Browser Extensions: yes
              Local Page: C:\Windows\system32\blank.htm
              Search bar: Preserve
              Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
              Show_ToolBar: yes
              Start Page: hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage=hxxp://eis.esnips.com/page/search/?client_uuid=bda82ac0-85c3-4b48-b0d2-41fde8d1391d

              [HKLM\Software\Microsoft\Internet Explorer\Main]
              AutoHide: yes
              Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=69157
              Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
              Delete_Temp_Files_On_Exit: yes
              Local Page: C:\Windows\SysWOW64\blank.htm
              Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
              Start Page: hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage=hxxp://eis.esnips.com/page/search/?client_uuid=bda82ac0-85c3-4b48-b0d2-41fde8d1391d

              [HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
              Tabs: res://ieframe.dll/tabswelcome.htm
              Blank: $ActiveDomain/page/blank/?client_uuid=bda82ac0-85c3-4b48-b0d2-41fde8d1391d

              ========================================

              C:\Program Files (x86)\Ad-Remover\Quarantine: 0 Fichier(s)
              C:\Program Files (x86)\Ad-Remover\Backup: 1 Fichier(s)

              C:\Ad-Report-SCAN[1].txt - 27/01/2011 (4632 Octet(s))

              Fin à: 12:49:35, 27/01/2011

              ============== E.O.F ==============
              0
              1. Modérateur
                Passe en nettoyage sur AD-Remover.
                0
                1. Voila c'est fait : nettoyage + redémarrage.
                  Voici le rapport éditer :

                  ======= RAPPORT D'AD-REMOVER 2.0.0.2,D | UNIQUEMENT XP/VISTA/7 =======

                  Mis à jour par TeamXscript le 20/01/11 à 19:00
                  Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
                  Site web: http://www.teamxscript.org

                  C:\Program Files (x86)\Ad-Remover\main.exe (CLEAN [1]) -> Lancé à 13:30:30 le 27/01/2011, Mode normal

                  Microsoft Windows 7 Édition Familiale Premium (X64)
                  Julien@JULIEN-PC (Gigabyte Technology Co., Ltd. GA-MA770T-UD3P)

                  ============== ACTION(S) ==============

                  Dossier supprimé: C:\Users\Julien\AppData\LocalLow\ShopperReports3

                  (!) -- Fichiers temporaires supprimés.

                  Clé supprimée: HKLM\Software\Classes\Interface\{453DB0C5-F41C-4D97-8DD6-CC72ECD5F699}
                  Clé supprimée: HKLM\Software\Classes\Interface\{4AFC07D0-59BB-46B8-B097-1A46E88EEF71}
                  Clé supprimée: HKLM\Software\Classes\Interface\{6511CE4C-4722-40D0-AD3D-4AFA2F50978A}
                  Clé supprimée: HKLM\Software\Classes\Interface\{83B2FE06-BA20-4F7D-96C6-6FC3A4E877D3}
                  Clé supprimée: HKLM\Software\Classes\Interface\{9BEC9B38-BF39-4899-806E-A1C5DFEB60A2}
                  Clé supprimée: HKLM\Software\Classes\Interface\{AEBF09E2-0C15-43C8-99BF-928C645D98A0}
                  Clé supprimée: HKLM\Software\Classes\Interface\{B32966A2-F7C2-4362-A6CF-399EC8B44110}
                  Clé supprimée: HKLM\Software\Classes\Interface\{B86D82BF-D39F-439A-A07C-43EDDC6F6EA6}
                  Clé supprimée: HKLM\Software\Classes\Interface\{DA6305B9-0869-4235-8C1D-533A65E639E5}
                  Clé supprimée: HKLM\Software\Classes\Interface\{DB885111-F39F-4D88-9EE5-C88460B6DF7B}
                  Clé supprimée: HKLM\Software\Classes\Interface\{E6961C59-CFCE-4CCD-B794-BC78DB98413A}
                  Clé supprimée: HKLM\Software\Classes\Interface\{F8B4EC8A-2407-4BE0-AEE2-0F430D65A90D}
                  Clé supprimée: HKCU\Software\AppDataLow\Software\ShopperReports3

                  ============== SCAN ADDITIONNEL ==============

                  ** Mozilla Firefox Version [3.6.13 (fr)] **

                  -- C:\Users\Julien\AppData\Roaming\Mozilla\FireFox\Profiles\ej7sosno.default\Prefs.js --
                  browser.download.lastDir, C:\\Users\\Julien\\Desktop
                  browser.search.defaultenginename, eSnips Search
                  browser.search.selectedEngine, eSnips Search
                  browser.startup.homepage, hxxp://www.google.fr/
                  browser.startup.homepage_override.mstone, rv:1.9.2.13
                  keyword.URL, hxxp://eis.esnips.com/page/search_provider/?client_uuid=bda82ac0-85c3-4b48-b0d2-41fde8d1391d&q=

                  ========================================

                  ** Internet Explorer Version [8.0.7600.16385] **

                  [HKCU\Software\Microsoft\Internet Explorer\Main]
                  Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                  Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                  Do404Search: 0x01000000
                  Enable Browser Extensions: yes
                  Local Page: C:\Windows\system32\blank.htm
                  Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                  Show_ToolBar: yes
                  Start Page: hxxp://fr.msn.com/

                  [HKLM\Software\Microsoft\Internet Explorer\Main]
                  AutoHide: yes
                  Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
                  Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                  Delete_Temp_Files_On_Exit: yes
                  Local Page: C:\Windows\SysWOW64\blank.htm
                  Search bar: hxxp://search.msn.com/spbasic.htm
                  Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                  Start Page: hxxp://fr.msn.com/

                  [HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
                  Tabs: res://ieframe.dll/tabswelcome.htm
                  Blank: $ActiveDomain/page/blank/?client_uuid=bda82ac0-85c3-4b48-b0d2-41fde8d1391d

                  ========================================

                  C:\Program Files (x86)\Ad-Remover\Quarantine: 14 Fichier(s)
                  C:\Program Files (x86)\Ad-Remover\Backup: 15 Fichier(s)

                  C:\Ad-Report-CLEAN[1].txt - 27/01/2011 (3577 Octet(s))
                  C:\Ad-Report-SCAN[1].txt - 27/01/2011 (4761 Octet(s))

                  Fin à: 13:31:10, 27/01/2011

                  ============== E.O.F ==============
                  0
                  1. Modérateur
                    t'as cette version installée : Adobe Reader 8.2.5 - Français
                    vulnérable : https://www.flexera.com/products/operations/software-vulnerability-research/secunia-research.html

                    Adobe Reader est pas à jour et contient des vulnérabilités qui peuvent mettre l'infection de ton PC.
                    Lire explications : https://forum.malekal.com/viewtopic.php?t=13629&start=

                    Fais plus attention à l'avenir....

                    Maintiens tes logiciel à jour c'est important, utilise ce programme : /faq/13362-mettre-a-jour-son-pc-contre-les-failles-de-securite
                    Absolument à faire.

                    Les antivirus ne font pas tout en ce qui concerne la sécurité de ta machine (mettre à jour ses logiciels etc etc)
                    La meilleur protection reste de connaître les infections pour pouvoir les éviter et avoir de bonne habitude.
                    Donc faut se documenter.

                    Un peu de lecture pour éviter les infections :
                    - connaitre et éviter les infections : https://www.malekal.com/fichiers/projetantimalwares/ProjetAntiMalware-courte.pdf
                    - sécuriser son PC : http://forum.malekal.com/comment-securiser-son-ordinateur.html
                    - lire : http://www.commentcamarche.net/faq/27128-malwares-quels-enjeux-version-synthese

                    Ce qu'il ne faut pas faire :
                    Je télécharge n'importe quoi - je m'infecte :
                    https://forums.commentcamarche.net/forum/affich-19719198-onglets-pub-intempestifs#14
                    https://forums.commentcamarche.net/forum/affich-18347759-le-nouveau-avast-sonne-trop-souvent#9
                    Je télécharge depuis n'importe où - je m'infecte : https://forums.commentcamarche.net/forum/affich-19916973-clickpotato-vlc-virus#6
                    Recommandations sur la sécurité : https://forums.commentcamarche.net/forum/affich-18680013-windows-7-et-antispyware#1

                    Fonctionnement de quelques catégories de malwares :
                    https://forums.commentcamarche.net/forum/affich-17725521-virus-programme-troyen
                    https://forums.commentcamarche.net/forum/affich-17746390-concernant-la-propagation-des-virus

                    Si tu as des questions sur le fonctionement des malwares.
                    N'hésite pas.

                    0
                    1. Ok merci beaucoup pour ton aide!

                      Je vais lire attentivement tout ce que tu m'as envoyer et mettre à jour mes logiciels.

                      Encore Merci
                      0