Pctutto, suis-je infecté ?

Bonjour,
L'autre jour croyant que c'était la notice explicative d'un logiciel (comme la légende l'indiquait), j'ai cliqué sur pctutto ou un truc comme ça, dans les deux jours qui ont suivi je me suis inquiété de voir autant de mises à jour automatiques avec le logo habituel en bas à droite des mises à jour de windows, j'ai immédiatement repéré dans le gestionnaire un autoupdate.exe nouveau, en le recherchant dans les registres j'ai vu qu'il était sous "agence-exclusive" que j'ai recherché sur le net et j'ai compris que je m'étais fait avoir. Il se trouve que j'avais une sauvegarde des registres qui datait justement de la veille du jour où j'ai cliqué sur pctutto, j'ai donc désinstallé firefox et internet explorer 8.0 et fait une restauration du système à la veille du jour fatidique puis j'ai tout réinstallé. Je n'ai pas de pub intempestive pour le moment et plus de programme inconnu dans le gestionnaire mais j'ai observé des trucs bizarres, par exemple quand j'ai désinstallé internet explorer, la désinstallation n'a pas supprimé tous les fichiers sous program files>IE, j'ai donc voulu les supprimer à la main et là surprenant: je les supprimais puis ils réapparaissaient automatiquement. De la même manière, j'ai trouvé sur un disque externe qui était allumé lorsque j'ai cliqué sur pctutto mais que j'ai malheureusement éteint pendant ma restauration, des fichiers bizarres écrits en langue arabe qui n'existaient pas auparavant, je les ai supprimés mais il y en a un qui reste dans la corbeille du disque externe, ne pouvant le supprimer de la corbeille, je l'ai renommé, le rename a été pris en compte puis quelques secondes après il a repris son nom d'origine...
Du coup, j'ai téléchargé ad-remover et j'ai fait un scan il me sort des trucs dans un fichier texte mais ne me dit pas si c'est embêtant ou pas, je ne sais pas trop si je dois relancer pour nettoyer, pouvez-vous svp me donner votre avis ? Merci
ci-dessous le résultat du scan:
======= RAPPORT D'AD-REMOVER 2.0.0.0,D | UNIQUEMENT XP/VISTA/7 =======
.
Mis à jour par C_XX le 19/05/10 à 19:20
Contact: AdRemover.contact@gmail.com
Site web: Orange
.
Lancé à: 16:36:04 le 05/07/2011 | Mode normal | Option: SCAN
Exécuté de: C:\Ad-Remover\ADR.exe
SE: Microsoft Windows XP Édition familiale (Service Pack 3 - X86)
Nom du PC: MAYA
Utilisateur actuel: Roger
.
============== ÉLÉMENT(S) TROUVÉ(S) ==============
.
.
C:\Documents and Settings\All Users\Application Data\Viewpoint
C:\Documents and Settings\Roger\Application Data\VMNTOOLBAR
C:\Program Files\Viewpoint
C:\Program Files\VMNTOOLBAR
.
HKCU\Software\fcn
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33}
HKCU\Software\vmntoolbar
HKLM\Software\Classes\AxMetaStream.MetaStreamCtl
HKLM\Software\Classes\AxMetaStream.MetaStreamCtl.1
HKLM\Software\Classes\AxMetaStream.MetaStreamCtlSecondary
HKLM\Software\Classes\AxMetaStream.MetaStreamCtlSecondary.1
HKLM\Software\Classes\CLSID\{03F998B2-0E00-11D3-A498-00104B6EB52E}
HKLM\Software\Classes\CLSID\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
HKLM\Software\Classes\CLSID\{4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33}
HKLM\Software\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
HKLM\Software\MetaStream
HKLM\Software\Microsoft\Active Setup\Installed Components\{03F998B2-0E00-11D3-A498-00104B6EB52E}
HKLM\Software\Microsoft\Active Setup\Installed Components\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\vmntoolbar
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\ViewpointMediaPlayer
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\vmntoolbar
HKLM\Software\Viewpoint
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33}
.
.
============== SCAN ADDITIONNEL ==============
.
* Mozilla FireFox Version 5.0 (fr) *
.
C:\Documents and Settings\Roger\..\7ity5h2g.default\prefs.js - browser.startup.homepage: hxxp://www.orange.fr
C:\Documents and Settings\Roger\..\7ity5h2g.default\prefs.js - browser.startup.homepage_override.buildID: 20110615151330
C:\Documents and Settings\Roger\..\7ity5h2g.default\prefs.js - browser.startup.homepage_override.mstone: rv:5.0
C:\Documents and Settings\Annie\..\8j63gj7h.default\prefs.js - browser.startup.homepage_override.mstone: rv:1.9.0.6
.
.
* Internet Explorer Version 8.0.6001.18702 *
.
[HKCU\Software\Microsoft\Internet Explorer\Main]
.
Default_Page_URL: hxxp://www.euro.dell.com/countries/fr/fra/gen/default.htm
Do404Search: 0x01000000
Enable Browser Extensions: yes
Local Page: C:\WINDOWS\system32\blank.htm
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Show_ToolBar: yes
Start Page: hxxp://www.orange.fr/
.
[HKLM\Software\Microsoft\Internet Explorer\Main]
.
Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=69157
Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Delete_Temp_Files_On_Exit: yes
Local Page: C:\WINDOWS\system32\blank.htm
Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Start Page: hxxp://go.microsoft.com/fwlink/?LinkId=69157
.
[HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
.
Tabs: res://ieframe.dll/tabswelcome.htm
Blank: res://mshtml.dll/blank.htm
.
========================================
.
C:\Ad-Remover\Quarantine: 0 Fichier(s)
C:\Ad-Remover\Backup: 0 Fichier(s)
.
C:\Ad-Report-SCAN[1].txt - 3513 Octet(s)
.
Fin à: 17:23:14, 05/07/2011
.
============== E.O.F - SCAN[1] ==============

54 réponses

Résumé de la discussion

Suspicion de malware survient après un clic sur un logiciel soi-disant explicatif, suivie de mises à jour automatiques et d'un autoupdate.exe détecté dans le gestionnaire, avec des entrées liées à agence-exclusive. Des mesures ont été prises rapidement pour la sécurité, avec restauration système à la veille et réinstallation, suppression d'Internet Explorer, puis analyse d'un disque externe présentant des fichiers suspects. Les rapports via Ad-Remover et ComboFix indiquent des composants potentiellement indésirables (Viewpoint, VMNTOOLBAR et diverses clés de registre), et les échanges restent hésitants sur l'interprétation des résultats. En cas de doute persistant, les contributeurs recommandent d'utiliser des sources fiables et de mener des analyses complémentaires, tout en restant prudent face à des outils non vérifiés et potentiellement risqués.

Bobot (l’IA à votre service)
  1. Bonjour,

    Lance Ad-remover, clique sur désinstaller (il n'est pas à jour), ensuite

    1/ * Télécharge de AD-Remover sur ton Bureau.
    http://www.teamxscript.org/adremoverTelechargement.html

    /!\ Ferme toutes applications en cours /!\

    - Double-clique sur l'icône Ad-remover située sur ton Bureau.
    - Sur la page, clique sur le bouton « Nettoyer »
    - Confirme lancement du scan
    - Laisse travailler l'outil.
    - Poste le rapport qui apparaît à la fin.

    (Le rapport est sauvegardé aussi sous C:\Ad-report(Scan/clean).Txt)

    (CTRL+A pour tout sélectionner, CTRL+C pour copier et CTRL+V pour c

    -*-*-*-*-*-*-*-*-*-*-*-*-*<<<<<<<<<<-*-*-*-*-*-*-*-*-*>>>>>>>>>>
    Membre, Contributeur //// Poisson66 ////

    Ne me donne pas le poisson mais apprends moi à le pêcher!

    -*-*-*-*-*-*-*-*-*-*-*-*-*<<<<<<<<<<-*-*-*-*-*-*-*-*-*>>>>>>>>>>
    0
    1. salut ad-remover pas à jour
      0
      1. Bojour,

        Oui, c'est vrai merci : g3n-h@ckm@n
        -*-*-*-*-*-*-*-*-*-*-*-*-*<<<<<<<<<<-*-*-*-*-*-*-*-*-*>>>>>>>>>>
        Membre, Contributeur //// Poisson66 ////

        Ne me donne pas le poisson mais apprends moi à le pêcher!

        -*-*-*-*-*-*-*-*-*-*-*-*-*<<<<<<<<<<-*-*-*-*-*-*-*-*-*>>>>>>>>>>
        0
        1. Merci pour la réponse, ci-dessous le rapport de ad-remover (bouton Nettoyer):
          .
          ======= RAPPORT D'AD-REMOVER 2.0.0.0,D | UNIQUEMENT XP/VISTA/7 =======
          .
          Mis à jour par C_XX le 19/05/10 à 19:20
          Contact: AdRemover.contact@gmail.com
          Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
          .
          Lancé à: 08:24:15 le 06/07/2011 | Mode normal | Option: CLEAN
          Exécuté de: C:\Ad-Remover\ADR.exe
          SE: Microsoft Windows XP Édition familiale (Service Pack 3 - X86)
          Nom du PC: MAYA
          Utilisateur actuel: Roger
          .
          ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
          .
          .
          C:\Documents and Settings\All Users\Application Data\Viewpoint
          C:\Documents and Settings\Roger\Application Data\VMNTOOLBAR
          C:\Program Files\Viewpoint
          C:\Program Files\VMNTOOLBAR

          (!) -- Fichiers temporaires supprimés.
          .
          HKCU\Software\fcn
          HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33}
          HKCU\Software\vmntoolbar
          HKLM\Software\Classes\AxMetaStream.MetaStreamCtl
          HKLM\Software\Classes\AxMetaStream.MetaStreamCtl.1
          HKLM\Software\Classes\AxMetaStream.MetaStreamCtlSecondary
          HKLM\Software\Classes\AxMetaStream.MetaStreamCtlSecondary.1
          HKLM\Software\Classes\CLSID\{03F998B2-0E00-11D3-A498-00104B6EB52E}
          HKLM\Software\Classes\CLSID\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
          HKLM\Software\Classes\CLSID\{4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33}
          HKLM\Software\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
          HKLM\Software\MetaStream
          HKLM\Software\Microsoft\Active Setup\Installed Components\{03F998B2-0E00-11D3-A498-00104B6EB52E}
          HKLM\Software\Microsoft\Active Setup\Installed Components\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
          HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\vmntoolbar
          HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\ViewpointMediaPlayer
          HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\vmntoolbar
          HKLM\Software\Viewpoint
          HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33}
          .
          .
          ============== SCAN ADDITIONNEL ==============
          .
          * Mozilla FireFox Version 5.0 (fr) *
          .
          C:\Documents and Settings\Roger\..\7ity5h2g.default\prefs.js - browser.startup.homepage: hxxp://www.orange.fr
          C:\Documents and Settings\Roger\..\7ity5h2g.default\prefs.js - browser.startup.homepage_override.buildID: 20110615151330
          C:\Documents and Settings\Roger\..\7ity5h2g.default\prefs.js - browser.startup.homepage_override.mstone: rv:5.0
          C:\Documents and Settings\Annie\..\8j63gj7h.default\prefs.js - browser.startup.homepage_override.mstone: rv:1.9.0.6
          .
          .
          * Internet Explorer Version 8.0.6001.18702 *
          .
          [HKCU\Software\Microsoft\Internet Explorer\Main]
          .
          Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
          Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
          Do404Search: 0x01000000
          Enable Browser Extensions: yes
          Local Page: C:\WINDOWS\system32\blank.htm
          Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
          Show_ToolBar: yes
          Start Page: hxxp://fr.msn.com/
          .
          [HKLM\Software\Microsoft\Internet Explorer\Main]
          .
          Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
          Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
          Delete_Temp_Files_On_Exit: yes
          Local Page: C:\WINDOWS\system32\blank.htm
          Search bar: hxxp://search.msn.com/spbasic.htm
          Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
          Start Page: hxxp://fr.msn.com/
          .
          [HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
          .
          Tabs: res://ieframe.dll/tabswelcome.htm
          Blank: res://mshtml.dll/blank.htm
          .
          ========================================
          .
          C:\Ad-Remover\Quarantine: 0 Fichier(s)
          C:\Ad-Remover\Backup: 13 Fichier(s)
          .
          C:\Ad-Report-CLEAN[1].txt - 3703 Octet(s)
          C:\Ad-Report-SCAN[1].txt - 3637 Octet(s)
          .
          Fin à: 08:53:09, 06/07/2011
          .
          ============== E.O.F - CLEAN[1] ==============
          0
          1. Re,

            Je t'ai demandé de désinstaller ta version D'Ad-remover qui n'est pas à jour !

            Fais ceci stp :

            Lance Ad-remover, clique sur désinstaller (il n'est pas à jour), ensuite

            1/ * Télécharge de AD-Remover sur ton Bureau.
            http://www.teamxscript.org/adremoverTelechargement.html

            /!\ Ferme toutes applications en cours /!\

            - Double-clique sur l'icône Ad-remover située sur ton Bureau.
            - Sur la page, clique sur le bouton « chercher »
            - Confirme lancement du scan
            - Laisse travailler l'outil.
            - Poste le rapport qui apparaît à la fin.

            (Le rapport est sauvegardé aussi sous C:\Ad-report(Scan/clean).Txt)

            (CTRL+A pour tout sélectionner, CTRL+C pour copier et CTRL+V pour c

            0
            1. Désolé, j'ai désinstallé l'ancien, ci-dessous le rapport du nouveau:
              fichier: Ad-Report-SCAN[1].txt
              ======= RAPPORT D'AD-REMOVER 2.0.0.2,G | UNIQUEMENT XP/VISTA/7 =======

              Mis à jour par TeamXscript le 12/04/11
              Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
              Site web: http://www.teamxscript.org

              C:\Program Files\Ad-Remover\main.exe (SCAN [1]) -> Lancé à 09:36:43 le 07/07/2011, Mode normal

              Microsoft Windows XP Édition familiale Service Pack 3 (X86)
              Roger@MAYA ( )

              ============== RECHERCHE ==============

              Fichier trouvé: C:\Documents and Settings\Roger\Local Settings\Application Data\igakyog_navpsold.dat

              Clé trouvée: HKLM\Software\MozillaPlugins\@viewpoint.com/VMP

              ============== SCAN ADDITIONNEL ==============

              **** Mozilla Firefox Version [5.0 (fr)] ****

              HKLM_MozillaPlugins\@viewpoint.com/VMP (x)
              Searchplugins\bing.xml ( hxxp://www.bing.com/search)
              Components\browsercomps.dll (Mozilla Foundation)
              Components\Scriptff.dll (McAfee, Inc.)

              -- C:\Documents and Settings\Roger\Application Data\Mozilla\FireFox\Profiles\7ity5h2g.default --
              Prefs.js - browser.startup.homepage, hxxp://www.orange.fr
              Prefs.js - browser.startup.homepage_override.buildID, 20110615151330
              Prefs.js - browser.startup.homepage_override.mstone, rv:5.0

              -- C:\Documents and Settings\Annie\Application Data\Mozilla\FireFox\Profiles\8j63gj7h.default --
              Prefs.js - browser.startup.homepage_override.mstone, rv:1.9.0.6

              ========================================

              **** Internet Explorer Version [8.0.6001.18702] ****

              HKCU_Main|Default_Page_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
              HKCU_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
              HKCU_Main|Search bar - hxxp://go.microsoft.com/fwlink/?linkid=54896
              HKCU_Main|Start Page - hxxp://fr.msn.com/
              HKLM_Main|Default_Page_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
              HKLM_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
              HKLM_Main|Search bar - hxxp://search.msn.com/spbasic.htm
              HKLM_Main|Search Page - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
              HKLM_Main|Start Page - hxxp://fr.msn.com/
              HKCU_URLSearchHooks|{08C06D61-F1F3-4799-86F8-BE1A89362C85} (x)
              HKCU_URLSearchHooks|{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - "McAfee SiteAdvisor Toolbar" (c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll)
              HKCU_SearchScopes\{e3dccd12-aa1a-48c5-a38b-518a9c35992f} - "iadah" (hxxp://www.iadah.com/web-B-8?search&q={searchTerms})
              HKCU_Toolbar\WebBrowser|{C55BBCD6-41AD-48AD-9953-3609C48EACC7} (C:\Program Files\Annexe\Orbit\Orbitdownloader\GrabPro.dll)
              HKLM_Toolbar|{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} (c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll)
              HKLM_Toolbar|{C55BBCD6-41AD-48AD-9953-3609C48EACC7} (C:\Program Files\Annexe\Orbit\Orbitdownloader\GrabPro.dll)
              HKCU_ElevationPolicy\{D3DE705E-0BB6-47E6-AB61-6FF78BE040A0} - C:\Program Files\Internet Explorer\minftnet.exe (x)
              HKLM_ElevationPolicy\{1FCCD250-A453-4348-86C1-E5EA9B76FADB} - C:\Program Files\McAfee\VirusScan\mcvsmap.exe (McAfee, Inc.)
              HKLM_ElevationPolicy\{4250488A-CB24-0893-C066-B1AEA57BCFF2} - C:\Program Files\Annexe\Orbit\Orbitdownloader\orbitdm.exe (Orbitdownloader.com)
              HKLM_ElevationPolicy\{A8F94DF3-F6C6-422a-8BFC-7EE0F60A8609} - C:\Program Files\McAfee\VirusScan\mcvsshld.exe (McAfee, Inc.)
              HKLM_Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - "?" (?)
              HKLM_Extensions\{9455301C-CF6B-11D3-A266-00C04F689C50} - "Organise-notes" (C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Researcher\EROPROJ.DLL,106)
              HKLM_Extensions\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - "Real.com" (C:\Program Files\Real\RealPlayer\eb_inact.ico)
              HKLM_Extensions\{e2e2dd38-d088-4134-82b7-f2ba38496583} - "?" (?)
              BHO\{000123B4-9B42-4900-B3F7-F4B073EFC214} - "Octh Class" (C:\Program Files\Annexe\Orbit\Orbitdownloader\orbitcth.dll)
              BHO\{5CA3D70E-1895-11CF-8E15-001234567890} - "DriveLetterAccess" (C:\WINDOWS\system32\dla\tfswshx.dll)
              BHO\{7DB2D5A0-7241-4E79-B68D-6309F01C5231} - "scriptproxy" (C:\Program Files\Fichiers communs\McAfee\SystemCore\ScriptSn.20110705125717.dll)
              BHO\{B164E929-A1B6-4A06-B104-2CD0E90A88FF} - "McAfee SiteAdvisor BHO" (c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll)

              ========================================

              C:\Program Files\Ad-Remover\Quarantine: 0 Fichier(s)
              C:\Program Files\Ad-Remover\Backup: 1 Fichier(s)

              C:\Ad-Report-SCAN[1].txt - 07/07/2011 09:37:10 (2884 Octet(s))

              Fin à: 09:38:51, 07/07/2011

              ============== E.O.F ==============
              0
              1. Bonjour,
                1/
                Relance Ad-remover puis clique sur "Nettoyer" puis poste le rapport

                2/
                Nous allons effectuer un diagnostic de ton PC:
                *Télécharge ZHPDiag sur ton bureau :

                https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html
                ou :
                http://www.premiumorange.com/zeb-help-process/zhpdiag.html

                * Laisse toi guider lors de l'installation,coche "Ajouter une icône sur le bureau" et décoche la case "Exécuter ZHPDiag"

                /!\Utilisateur de Vista et Seven : Clique droit sur le logo de ZHPdiag, « exécuter en tant qu'Administrateur »

                * Clique sur l'icône représentant une loupe (« Lancer le diagnostic »)
                * Enregistre le rapport sur ton Bureau à l'aide de l'icône représentant une disquette
                * Héberge le rapport ZHPDiag.txt sur un des sites ci dessous, puis copie/colle le lien fourni dans ta prochaine réponse sur le forum :
                http://pjjoint.malekal.com/

                Si indisponible:
                http://www.cijoint.fr/

                * Tuto zhpdiag :
                http://www.premiumorange.com/zeb-help-process/zhpdiag.html

                Hébergement de rapport sur pjjoint.malekal.com

                * Rends toi sur http://pjjoint.malekal.com/
                * Clique sur le bouton Parcourir
                * Sélectionne le fichier que tu veux heberger et clique sur Ouvrir
                *Clique sur le bouton Envoyer
                * Un message de confirmation s'affiche, copie le lien dans ta prochaine réponse.

                @+
                0
                1. Bonjour,
                  Ci-dessous le rapport de nettoyage de Ad-remover. Pour ce qui est de ZPHDiag, j'ai dû le désinstaller et le réinstaller car la première fois McAfee me l'avait sucré (détection cheval de Troie), pour la 2ème exécution j'avais stoppé McAfee, tout a eu l'air de se passer normalement, tu trouveras le rapport de ZPHDiag sur:
                  http://rwebeasy.free.fr/ZHPDiag.txt
                  *******************************************************
                  fichier: Ad-Report-CLEAN[1].txt
                  ======= RAPPORT D'AD-REMOVER 2.0.0.2,G | UNIQUEMENT XP/VISTA/7 =======

                  Mis à jour par TeamXscript le 12/04/11
                  Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
                  Site web: http://www.teamxscript.org

                  C:\Program Files\Ad-Remover\main.exe (CLEAN [1]) -> Lancé à 12:46:49 le 07/07/2011, Mode normal

                  Microsoft Windows XP Édition familiale Service Pack 3 (X86)
                  Roger@MAYA ( )

                  ============== ACTION(S) ==============

                  Fichier supprimé: C:\Documents and Settings\Roger\Local Settings\Application Data\igakyog_navpsold.dat

                  (!) -- Fichiers temporaires supprimés.

                  Clé supprimée: HKLM\Software\MozillaPlugins\@viewpoint.com/VMP

                  ============== SCAN ADDITIONNEL ==============

                  **** Mozilla Firefox Version [5.0 (fr)] ****

                  Searchplugins\bing.xml ( hxxp://www.bing.com/search)
                  Components\browsercomps.dll (Mozilla Foundation)
                  Components\Scriptff.dll (McAfee, Inc.)

                  -- C:\Documents and Settings\Roger\Application Data\Mozilla\FireFox\Profiles\7ity5h2g.default --
                  Prefs.js - browser.startup.homepage, hxxp://www.orange.fr
                  Prefs.js - browser.startup.homepage_override.buildID, 20110615151330
                  Prefs.js - browser.startup.homepage_override.mstone, rv:5.0

                  -- C:\Documents and Settings\Annie\Application Data\Mozilla\FireFox\Profiles\8j63gj7h.default --
                  Prefs.js - browser.startup.homepage_override.mstone, rv:1.9.0.6

                  ========================================

                  **** Internet Explorer Version [8.0.6001.18702] ****

                  HKCU_Main|Default_Page_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                  HKCU_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                  HKCU_Main|Search bar - hxxp://go.microsoft.com/fwlink/?linkid=54896
                  HKCU_Main|Start Page - hxxp://fr.msn.com/
                  HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink/?LinkId=54896
                  HKLM_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                  HKLM_Main|Search bar - hxxp://search.msn.com/spbasic.htm
                  HKLM_Main|Search Page - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                  HKLM_Main|Start Page - hxxp://fr.msn.com/
                  HKCU_URLSearchHooks|{08C06D61-F1F3-4799-86F8-BE1A89362C85} (x)
                  HKCU_URLSearchHooks|{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - "McAfee SiteAdvisor Toolbar" (c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll)
                  HKCU_SearchScopes\{e3dccd12-aa1a-48c5-a38b-518a9c35992f} - "iadah" (hxxp://www.iadah.com/web-B-8?search&q={searchTerms})
                  HKCU_Toolbar\WebBrowser|{C55BBCD6-41AD-48AD-9953-3609C48EACC7} (C:\Program Files\Annexe\Orbit\Orbitdownloader\GrabPro.dll)
                  HKLM_Toolbar|{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} (c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll)
                  HKLM_Toolbar|{C55BBCD6-41AD-48AD-9953-3609C48EACC7} (C:\Program Files\Annexe\Orbit\Orbitdownloader\GrabPro.dll)
                  HKCU_ElevationPolicy\{D3DE705E-0BB6-47E6-AB61-6FF78BE040A0} - C:\Program Files\Internet Explorer\minftnet.exe (x)
                  HKLM_ElevationPolicy\{1FCCD250-A453-4348-86C1-E5EA9B76FADB} - C:\Program Files\McAfee\VirusScan\mcvsmap.exe (McAfee, Inc.)
                  HKLM_ElevationPolicy\{4250488A-CB24-0893-C066-B1AEA57BCFF2} - C:\Program Files\Annexe\Orbit\Orbitdownloader\orbitdm.exe (Orbitdownloader.com)
                  HKLM_ElevationPolicy\{A8F94DF3-F6C6-422a-8BFC-7EE0F60A8609} - C:\Program Files\McAfee\VirusScan\mcvsshld.exe (McAfee, Inc.)
                  HKLM_Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - "?" (?)
                  HKLM_Extensions\{9455301C-CF6B-11D3-A266-00C04F689C50} - "Organise-notes" (C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Researcher\EROPROJ.DLL,106)
                  HKLM_Extensions\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - "Real.com" (C:\Program Files\Real\RealPlayer\eb_inact.ico)
                  HKLM_Extensions\{e2e2dd38-d088-4134-82b7-f2ba38496583} - "?" (?)
                  BHO\{000123B4-9B42-4900-B3F7-F4B073EFC214} - "Octh Class" (C:\Program Files\Annexe\Orbit\Orbitdownloader\orbitcth.dll)
                  BHO\{5CA3D70E-1895-11CF-8E15-001234567890} - "DriveLetterAccess" (C:\WINDOWS\system32\dla\tfswshx.dll)
                  BHO\{7DB2D5A0-7241-4E79-B68D-6309F01C5231} - "scriptproxy" (C:\Program Files\Fichiers communs\McAfee\SystemCore\ScriptSn.20110705125717.dll)
                  BHO\{B164E929-A1B6-4A06-B104-2CD0E90A88FF} - "McAfee SiteAdvisor BHO" (c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll)

                  ========================================

                  C:\Program Files\Ad-Remover\Quarantine: 1 Fichier(s)
                  C:\Program Files\Ad-Remover\Backup: 14 Fichier(s)

                  C:\Ad-Report-CLEAN[1].txt - 07/07/2011 12:46:55 (643 Octet(s))
                  C:\Ad-Report-SCAN[1].txt - 07/07/2011 09:37:10 (4457 Octet(s))

                  Fin à: 12:49:30, 07/07/2011

                  ============== E.O.F ==============
                  0
                  1. Re,
                    1/
                    Copie tout le texte présent en gras ci-dessous ( tu le selectionnes avec ta souris / Clique droit dessus et choisis "copier" ou fait Ctrl+C )

                    O42 - Logiciel: Registry Cleaner - (.RegistryOptimizer.com.) [HKLM]
                    [HKLM\Software\BrowserChoice]
                    O43 - CFD:Common File Directory ----D- C:\Program Files\Registry Cleaner
                    FirewallRAZ
                    EmptyTemp
                    EmptyFlash


                    Puis Lance ZHPFix depuis le raccourci du bureau .

                    * Une fois l'outil ZHPFix ouvert , clique sur le bouton [ H ] ( "coller les lignes Helper" ) .

                    * Dans l'encadré principal tu verras donc les lignes que tu as copié précédemment apparaitrent .

                    Vérifie que toutes les lignes que je t'ai demandé de copier (et seulement elles) sont dans la fenêtre.

                    Clique sur le bouton GO

                    Copie/Colle le rapport à l'écran dans ton prochain message.

                    2/
                    * Télécharge, sur le Bureau, MBRCheck (par a_d_13) en cliquant sur l'un de ces liens:

                    * http://www.geekstogo.com/forum/files/file/441-mbrcheck/
                    * https://download.bleepingcomputer.com/rootrepeal/MBRCheck.exe
                    * http://www.kernelmode.info/MBRCheck.exe

                    * Fermer tout et cliquer sur MBRCheck.exe

                    * S'il te demande de taper "Y or N", tapes Y puis valider en tapant sur la touche entrée de ton clavier,
                    * S'il te demande de taper sur la touche "entrée" seulement, fais le
                    * S'il te demande 1, 2 ou 3, Appuie sur 2

                    * Un rapport s'ouvre en fin de scan et sera automatiquement enregistré sur le Bureau. Il sera du type MBRCheck_AA.JJ.MM_hh.mm.ss.txt (i.e. MBRCheck_07.21.10_18.08.06.txt).

                    *************************************************************************
                    * Ensuite, vous verrez ceci :

                    Enter your choice: Enter the physical disk number to fix (0-99, -1 to cancel):

                    Tapez le chiffre 0 puis valide avec [Entrée]
                    * Vous aurez maintenant un choix à faire, avec des codes de MBR :

                    Available MBR codes:

                    [ 0] Default (Windows XP)

                    [ 1] Windows XP

                    [ 2] Windows Server 2003

                    [ 3] Windows Vista

                    [ 4] Windows 2008

                    [ 5] Windows 7

                    [-1] Cancel

                    Tapez le chiffre correspondant à votre système d'exploitation puis validez avec [Entrée]
                    * Ensuite, vous aurez ceci :

                    Do you want to fix the MBR code? Type 'YES' and hit ENTER to continue:

                    tapez YES puis valide avec [Entrée]
                    * En principe, vous devriez maintenant voir ceci (ajouté au bout de la ligne) :

                    Do you want to fix the MBR code? Type 'YES' and hit ENTER to continue: Successfully wrote new MBR code!
                    ...suivi de "Please reboot your computer to complete the fix."
                    * A la suite de ça, redémarrez votre ordinateur
                    * Postez le rapport obtenu si vous vous faîtes aider

                    0
                    1. Juste une petite précision, la ligne FirewallRAZ est-elle obligatoire étant donné que je n'utilise pas le pare-feu de Windows, mais celui de McAfee ?
                      Merci
                      0
                      1. Non c'est pas nécessaire :)
                        0
                    2. Bon j'ai essayé de faire ce que tu dis, mais ça n'a pas l'air de fonctionner comme tu t'y attends
                      Déjà ZHPFix il faut le prendre au vol, si on ne se dépêche pas suffisamment, il disparaît avant qu'on ait eu le temps de passer à la suite.
                      Et l'inconvénient quand il disparaît c'est que la seringue du raccourci reste sur le bureau mais le programme sensé être derrière elle n'est plus là.
                      Il faut donc à chaque fois désinstaller ZPHDiag et le réinstaller pour retrouver un programme derrière la seringue de ZHPFix.
                      Bon je passe et ne donne que le résultat de la dernière fois où je suis allé suffisamment vite pour arriver à peu de choses d'ailleurs.
                      1.- j'ai collé les fameuses lignes en cliquant sur l'icône H
                      2.- j'ai cliqué sur OK => les mêmes lignes se sont réaffichées avec devant chacune d'elles une case à cocher
                      3.- j'ai cliqué sur "Tous" => toutes les lignes ont été cochées
                      4.- j'ai cliqué sur "Nettoyer" => je reçois immédiatement le message suivant: "File: "c:\Program Files\Registry Cleaner\unins000.dat does not exist cannot uninstal !"
                      5.- j'ai cliqué sur OK pour acquitter le message
                      6.- Plus rien n'ayant l'air de se passer, j'ai re-cliqué sur "Nettoyer" => l'ascenseur d'exécution a démarré, mais le programme a disparu alors que l'ascenseur n'était qu'à 50%
                      J'ai récupéré sous Program Files\Annexe\ZHPDiag un fichier ZHPFixQuarantine.txt qui ne contient que la ligne ci-dessous:
                      //
                      C:\Program Files\Annexe\ZHPDiag\Quarantine\Registry Cleaner.DIR,C:\Program Files\Registry Cleaner
                      //
                      qui m'a l'air liée uniquement au message que j'ai reçu !
                      et un fichier: ZHPADSReport.txt qui était peut-être déjà là et qui contient seulement les 7 lignes ci-après:
                      //
                      LADS - Freeware version 4.10
                      (C) Copyright 1998-2007 Frank Heyne Software (http://www.heysoft.de)
                      This program lists files with alternate data streams (ADS)
                      Use LADS on your own risk!
                      Scanning directory C:\WINDOWS\System32\Drivers\
                      size ADS in file
                      ---------- ---------------------------------
                      0 bytes in 0 ADS listed
                      //
                      Mais pas de fichier: ZHPFixReport.txt
                      J'ai vérifié sous Program Files, j'ai bien Registry Cleaner avec son .exe et d'autres fichiers, par contre effectivement il n'y a pas le fichier .dat.
                      bizarre Registry Cleaner utilise la même icône que CCleaner que j'ai aussi.
                      enfin j'ai remarqué que tout ce qui est sous Registry Cleaner a été recopié 2 fois (sur 2 niveaux de répertoire) sous ZPHDiag\Quarantine sans pour autant être effacé sous Registry Cleaner

                      Suggestion: s'il s'agit simplement de désinstaller des programmes, il serait probablement plus simple de me demander de le faire manuellement
                      A+
                      0
                      1. Re,

                        Laisse passer ZHPfix, on va revenir

                        Tu peux désinstaller manuellement Registry Cleaner

                        Puis tu passes à l'étape suivante

                        0
                        1. Bien comme ZHPfix ne marchait pas, quelqu'un m'a passé un programme qui soi-disant doit tout trouver: ESET Online Scanner et que tu dois probablement connaître. J'ai passé ce programme d'où mon silence car il a mis presque 17h pour tout scanner. Il a fini par arriver au bout mais je l'ai bloqué sur l'écran, je ne suis pas encore passé à la dernière étape qui consiste à cocher la case "back" puis "Uninstall application on close" car je ne suis pas sûr que les programmes signalés soient réellement des programmes malveillants et je ne vois toujours pas le rapport avec mon problème du début c'est à dire le clic sur pctutto et "agence-exclusive". En effet le programme qu'on trouve le plus souvent c'est RegistryBooster or ça fait déjà deux fois que je paye pour avoir ce programme (une 1ère fois je l'avais désinstallé par mégarde) et il m'a déjà bien servi avec CCleaner pour réparer des erreurs dans les registres. Faut-il que je le désinstalle encore une fois ? on trouve aussi Orbit un programme gratuit mais dont je me sers souvent pour faire toutes sortes de transferts de fichiers. Ces deux programmes font de la pub sur des journaux informatiques sérieux et sont souvent conseillés par ces mêmes journaux...
                          Si je pouvais avoir ton avis avant d'aller plus loin, je t'en remercie par avance, ci-dessous le fichier: logESET.txt
                          C:\Program Files\Annexe\Orbit\Setup\OrbitSetup4.1.02.exe Win32/OpenCandy application deleted - quarantined
                          C:\Program Files\Annexe\RegistryBooster\Launcher.exe Win32/RegistryBooster application cleaned by deleting - quarantined
                          C:\Program Files\Annexe\RegistryBooster\rbmonitor.exe Win32/RegistryBooster application cleaned by deleting - quarantined
                          C:\Program Files\Annexe\RegistryBooster\rbnotifier.exe Win32/RegistryBooster application cleaned by deleting - quarantined
                          C:\Program Files\Annexe\RegistryBooster\rb_move_serial.exe Win32/RegistryBooster application cleaned by deleting - quarantined
                          C:\Program Files\Annexe\RegistryBooster\rb_track_install.exe Win32/RegistryBooster application cleaned by deleting - quarantined
                          C:\Program Files\Annexe\RegistryBooster\registrybooster.exe Win32/RegistryBooster application cleaned by deleting - quarantined
                          C:\Program Files\Annexe\RegistryBooster\Setup\registrybooster.exe Win32/RegistryBooster application deleted - quarantined
                          C:\Program Files\Annexe\SpeedUpMyPC\Launcher.exe Win32/SpeedUpMyPC application cleaned by deleting - quarantined
                          C:\Program Files\Annexe\SpeedUpMyPC\sp_move_serial.exe Win32/SpeedUpMyPC application cleaned by deleting - quarantined
                          C:\Program Files\Annexe\SpeedUpMyPC\sp_track_install.exe Win32/SpeedUpMyPC application cleaned by deleting - quarantined
                          C:\Program Files\Annexe\SpeedUpMyPC\sump.exe Win32/SpeedUpMyPC application cleaned by deleting - quarantined
                          C:\Program Files\Sony Corporation\Tiscali\Tiscali Internet\dlls\InstallDialer.exe a variant of Win32/Injector.AHE trojan deleted - quarantined
                          C:\Program Files\Uniblue\RegistryBooster\Launcher.exe Win32/RegistryBooster application cleaned by deleting - quarantined
                          C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe Win32/RegistryBooster application cleaned by deleting - quarantined
                          C:\Program Files\Uniblue\RegistryBooster\rbnotifier.exe Win32/RegistryBooster application cleaned by deleting - quarantined
                          C:\Program Files\Uniblue\RegistryBooster\rb_move_serial.exe Win32/RegistryBooster application cleaned by deleting - quarantined
                          C:\Program Files\Uniblue\RegistryBooster\rb_ubm.exe Win32/RegistryBooster application cleaned by deleting - quarantined
                          C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe Win32/RegistryBooster application cleaned by deleting - quarantined
                          C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP56\A0099879.exe Win32/RegistryBooster application deleted - quarantined
                          C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP71\A0103367.exe Win32/OpenCandy application deleted - quarantined
                          C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP71\A0103368.exe Win32/RegistryBooster application deleted - quarantined
                          C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP72\A0103369.exe Win32/RegistryBooster application deleted - quarantined
                          C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP72\A0103370.exe Win32/OpenCandy application deleted - quarantined
                          C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP84\A0108949.exe Win32/OpenCandy application deleted - quarantined
                          C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP84\A0108950.exe Win32/RegistryBooster application cleaned by deleting - quarantined
                          C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP84\A0108951.exe Win32/RegistryBooster application cleaned by deleting - quarantined
                          C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP84\A0108952.exe Win32/RegistryBooster application cleaned by deleting - quarantined
                          C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP84\A0108953.exe Win32/RegistryBooster application cleaned by deleting - quarantined
                          C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP84\A0108954.exe Win32/RegistryBooster application cleaned by deleting - quarantined
                          C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP84\A0108955.exe Win32/RegistryBooster application cleaned by deleting - quarantined
                          C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP84\A0108956.exe Win32/RegistryBooster application deleted - quarantined
                          C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP84\A0108957.exe Win32/SpeedUpMyPC application cleaned by deleting - quarantined
                          C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP84\A0108958.exe Win32/SpeedUpMyPC application cleaned by deleting - quarantined
                          C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP84\A0108959.exe Win32/SpeedUpMyPC application cleaned by deleting - quarantined
                          C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP84\A0108960.exe Win32/SpeedUpMyPC application cleaned by deleting - quarantined
                          C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP84\A0108961.exe a variant of Win32/Injector.AHE trojan deleted - quarantined
                          C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP84\A0108962.exe Win32/RegistryBooster application cleaned by deleting - quarantined
                          C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP84\A0108963.exe Win32/RegistryBooster application cleaned by deleting - quarantined
                          C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP84\A0108964.exe Win32/RegistryBooster application cleaned by deleting - quarantined
                          C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP84\A0108965.exe Win32/RegistryBooster application cleaned by deleting - quarantined
                          C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP84\A0108966.exe Win32/RegistryBooster application cleaned by deleting - quarantined
                          C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP84\A0108967.exe Win32/RegistryBooster application cleaned by deleting - quarantined
                          I:\encarta.premium.2009.by.huga.for.directstreet.iso probably a variant of Win32/StartPage.DXPJOP trojan deleted - quarantined
                          I:\Registrybooster_setup\registrybooster.exe Win32/RegistryBooster application deleted - quarantined
                          I:\Setup\OrbitSetup4.1.02.exe Win32/OpenCandy application deleted - quarantined
                          I:\Setup\registrybooster.exe Win32/RegistryBooster application deleted - quarantined
                          0
                          1. Merci pour ton avis. J'ai vu les critiques sur le site et quelques avis contradictoires, moi je l'utilisais car j'avais remarqué qu'une fois ccleaner passé registrybooster en trouvait encore (des erreurs).
                            Saurais-tu par hasard avant que je sucre tout s'il existe un logiciel gratuit qui pourrait remplacer orbit et qui ne sorte pas en objet malveillant (je l'ai depuis longtemps, je sais qu'à l'époque j'en avais testé d'autres et c'est celui là que j'avais trouvé le mieux, en plus il était conseillé par 01-informatique)? merci
                            Concernant le fonctionnement de ESET Online Scanner, saurais-tu si je peux choisir les programmes que je ne veux pas qu'il désinstalle par exemple tout simplement en supprimant les lignes que je ne veux pas désinstaller du fichier: logESET.txt ?
                            0
                            1. Bonjour et merci pour ta patience. Rien ne s'est passé comme prévu, plusieurs infos:
                              1.- concernant ESET Online Scanner j'avais finalement décidé de cliquer sur "back" puis "Uninstall application on close", mais quand j'ai cliqué sur back plus moyen de trouver la case à cocher ou le bouton Uninstall application on close", après divers essais infructueux j'ai finalement cliqué sur "finish", je pense donc qu'il n'a rien dû désinstaller du tout et puis relancer le scan pour 17h d'exécution ça fait hésiter !
                              2.- Concernant le site sur les quelques logiciels à voir sur lequel tu m'as renvoyé: ils conseillent justement Orbit le logiciel signalé par ESET que j'hésitais à faire désinstaller, mais vu comme le point 1 s'est passé, je l'ai toujours.
                              3. Concernant la désinstallation manuelle de Registry Cleaner je n'ai pas pu la faire car il ne figure pas dans la liste des programmes installés (fenêtre "Ajouter/Supprimer" du panneau de configuration, bien qu'il y soit probablement)
                              4.- J'ai téléchargé MBRCheck sur http://www.geekstogo.com/forum/files/file/441-mbrcheck/
                              j'ai cliqué dessus et surprise il s'est exécuté dans la fenêtre de commande (MSDOS) et m'a juste demandé de cliquer sur enter dans la fenêtre MSDOS et ça s'est arrêté là! je n'ai pas eu la question: enter your choice ... physical disk...!!!. L'exécution a été ultrarapide et a quand même fourni un rapport que tu trouveras ci-après:
                              MBRCheck, version 1.2.3
                              (c) 2010, AD

                              Command-line:
                              Windows Version: Windows XP Home Edition
                              Windows Information: Service Pack 3 (build 2600)
                              Logical Drives Mask: 0x0000017c

                              Kernel Drivers (total 146):
                              0x804D7000 \WINDOWS\system32\ntoskrnl.exe
                              0x80700000 \WINDOWS\system32\hal.dll
                              0xF8A76000 \WINDOWS\system32\KDCOM.DLL
                              0xF8986000 \WINDOWS\system32\BOOTVID.dll
                              0xF8526000 ACPI.sys
                              0xF8A78000 \WINDOWS\System32\DRIVERS\WMILIB.SYS
                              0xF8515000 pci.sys
                              0xF8576000 isapnp.sys
                              0xF84F7000 pnpshark.sys
                              0xF898A000 compbatt.sys
                              0xF898E000 \WINDOWS\System32\DRIVERS\BATTC.SYS
                              0xF8B3E000 pciide.sys
                              0xF87F6000 \WINDOWS\System32\DRIVERS\PCIIDEX.SYS
                              0xF84D9000 pcmcia.sys
                              0xF8586000 MountMgr.sys
                              0xF84BA000 ftdisk.sys
                              0xF87FE000 PartMgr.sys
                              0xF8596000 VolSnap.sys
                              0xF84A2000
                              0xF8A7A000 st3shark.sys
                              0xF848A000 \WINDOWS\System32\DRIVERS\SCSIPORT.SYS
                              0xF85A6000 disk.sys
                              0xF85B6000 \WINDOWS\System32\DRIVERS\CLASSPNP.SYS
                              0xF846A000 fltmgr.sys
                              0xF8458000 sr.sys
                              0xF83FB000 mfehidk.sys
                              0xF85C6000 PxHelp20.sys
                              0xF83E6000 drvmcdb.sys
                              0xF83CF000 KSecDD.sys
                              0xF83BC000 WudfPf.sys
                              0xF832F000 Ntfs.sys
                              0xF8302000 NDIS.sys
                              0xF85D6000 ohci1394.sys
                              0xF85E6000 \WINDOWS\System32\DRIVERS\1394BUS.SYS
                              0xF82E8000 Mup.sys
                              0xF85F6000 agp440.sys
                              0xF8616000 \SystemRoot\System32\DRIVERS\intelppm.sys
                              0xF8A32000 \SystemRoot\System32\DRIVERS\CmBatt.sys
                              0xF8199000 \SystemRoot\System32\DRIVERS\ati2mtag.sys
                              0xF8185000 \SystemRoot\System32\DRIVERS\VIDEOPRT.SYS
                              0xF8836000 \SystemRoot\System32\DRIVERS\usbuhci.sys
                              0xF8161000 \SystemRoot\System32\DRIVERS\USBPORT.SYS
                              0xF883E000 \SystemRoot\System32\DRIVERS\usbehci.sys
                              0xF80CB000 \SystemRoot\system32\DRIVERS\WPC54Gv3.SYS
                              0xF8626000 \SystemRoot\System32\DRIVERS\nic1394.sys
                              0xF8636000 \SystemRoot\System32\DRIVERS\i8042prt.sys
                              0xF80B4000 \SystemRoot\System32\DRIVERS\Apfiltr.sys
                              0xF8866000 \SystemRoot\System32\DRIVERS\mouclass.sys
                              0xF8876000 \SystemRoot\System32\DRIVERS\kbdclass.sys
                              0xF8646000 \SystemRoot\System32\DRIVERS\imapi.sys
                              0xF8656000 \SystemRoot\System32\Drivers\AFS2K.SYS
                              0xF8A42000 \SystemRoot\System32\Drivers\cdrbsdrv.SYS
                              0xF8A80000 \SystemRoot\system32\drivers\sscdbhk5.sys
                              0xF8666000 \SystemRoot\System32\DRIVERS\cdrom.sys
                              0xF8676000 \SystemRoot\System32\DRIVERS\redbook.sys
                              0xF8091000 \SystemRoot\System32\DRIVERS\ks.sys
                              0xF8051000 \SystemRoot\system32\drivers\stac97.sys
                              0xF802D000 \SystemRoot\system32\drivers\portcls.sys
                              0xF8686000 \SystemRoot\system32\drivers\drmk.sys
                              0xF7F20000 \SystemRoot\System32\DRIVERS\BCMSM.sys
                              0xF88AE000 \SystemRoot\System32\Drivers\Modem.SYS
                              0xF8C02000 \SystemRoot\System32\DRIVERS\audstub.sys
                              0xF7F0C000 \SystemRoot\system32\DRIVERS\mfendisk.sys
                              0xF8696000 \SystemRoot\System32\DRIVERS\rasl2tp.sys
                              0xF8A62000 \SystemRoot\System32\DRIVERS\ndistapi.sys
                              0xF7EF5000 \SystemRoot\System32\DRIVERS\ndiswan.sys
                              0xF86A6000 \SystemRoot\System32\DRIVERS\raspppoe.sys
                              0xF86B6000 \SystemRoot\System32\DRIVERS\raspptp.sys
                              0xF88D6000 \SystemRoot\System32\DRIVERS\TDI.SYS
                              0xF7E44000 \SystemRoot\System32\DRIVERS\psched.sys
                              0xF86C6000 \SystemRoot\System32\DRIVERS\msgpc.sys
                              0xF7E20000 \SystemRoot\system32\drivers\mfeavfk.sys
                              0xF7DAD000 \SystemRoot\system32\drivers\mfefirek.sys
                              0xF88F6000 \SystemRoot\System32\DRIVERS\ptilink.sys
                              0xF8906000 \SystemRoot\System32\DRIVERS\raspti.sys
                              0xF86D6000 \SystemRoot\System32\DRIVERS\termdd.sys
                              0xF8A88000 \SystemRoot\System32\DRIVERS\swenum.sys
                              0xF7D27000 \SystemRoot\System32\DRIVERS\update.sys
                              0xF891E000 \SystemRoot\System32\DRIVERS\omci.sys
                              0xF8283000 \SystemRoot\System32\DRIVERS\mssmbios.sys
                              0xF86F6000 \SystemRoot\System32\Drivers\NDProxy.SYS
                              0xF8726000 \SystemRoot\System32\DRIVERS\usbhub.sys
                              0xF8A8E000 \SystemRoot\System32\DRIVERS\USBD.SYS
                              0xF8A66000 \SystemRoot\System32\Drivers\i2omgmt.SYS
                              0xF8A94000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
                              0xF8C6C000 \SystemRoot\System32\Drivers\Null.SYS
                              0xF8A98000 \SystemRoot\System32\Drivers\Beep.SYS
                              0xF8946000 \SystemRoot\system32\drivers\ssrtln.sys
                              0xF894E000 \SystemRoot\System32\drivers\vga.sys
                              0xF8A9C000 \SystemRoot\System32\Drivers\mnmdd.SYS
                              0xF8AA0000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
                              0xF895E000 \SystemRoot\System32\Drivers\Msfs.SYS
                              0xF896E000 \SystemRoot\System32\Drivers\Npfs.SYS
                              0xF7E18000 \SystemRoot\System32\DRIVERS\rasacd.sys
                              0xA2785000 \SystemRoot\System32\DRIVERS\ipsec.sys
                              0xA272C000 \SystemRoot\System32\DRIVERS\tcpip.sys
                              0xA2706000 \SystemRoot\System32\DRIVERS\ipnat.sys
                              0xA26F3000 \SystemRoot\system32\drivers\mfetdi2k.sys
                              0xF8736000 \SystemRoot\System32\DRIVERS\wanarp.sys
                              0xA26A3000 \SystemRoot\System32\DRIVERS\netbt.sys
                              0xF8746000 \SystemRoot\System32\DRIVERS\arp1394.sys
                              0xA2681000 \SystemRoot\System32\drivers\afd.sys
                              0xF8756000 \SystemRoot\System32\DRIVERS\netbios.sys
                              0xF8786000 \SystemRoot\System32\Drivers\SCDEmu.SYS
                              0xA2566000 \SystemRoot\System32\DRIVERS\rdbss.sys
                              0xA24F6000 \SystemRoot\System32\DRIVERS\mrxsmb.sys
                              0xF8796000 \SystemRoot\System32\Drivers\Fips.SYS
                              0xF885E000 \SystemRoot\System32\DRIVERS\USBSTOR.SYS
                              0xA26D3000 \SystemRoot\System32\DRIVERS\usbscan.sys
                              0xF8886000 \SystemRoot\System32\DRIVERS\usbprint.sys
                              0xF87D6000 \SystemRoot\System32\Drivers\Cdfs.SYS
                              0xA24AA000 \SystemRoot\System32\Drivers\Fastfat.SYS
                              0xA2492000 \SystemRoot\System32\Drivers\dump_atapi.sys
                              0xF8AB8000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
                              0xBF800000 \SystemRoot\System32\win32k.sys
                              0xA25D1000 \SystemRoot\System32\drivers\Dxapi.sys
                              0xF88B6000 \SystemRoot\System32\watchdog.sys
                              0xBF000000 \SystemRoot\System32\drivers\dxg.sys
                              0xF8BB5000 \SystemRoot\System32\drivers\dxgthk.sys
                              0xBF012000 \SystemRoot\System32\ati2dvag.dll
                              0xBF049000 \SystemRoot\System32\ati2cqag.dll
                              0xBF083000 \SystemRoot\System32\ati3duag.dll
                              0xBF257000 \SystemRoot\System32\ativvaxx.dll
                              0xA2621000 \SystemRoot\system32\drivers\drvnddm.sys
                              0xF8B7D000 \SystemRoot\system32\dla\tfsndres.sys
                              0xA2365000 \SystemRoot\system32\dla\tfsnifs.sys
                              0xA247E000 \SystemRoot\system32\dla\tfsnopio.sys
                              0xF8AF4000 \SystemRoot\system32\dla\tfsnpool.sys
                              0xF8856000 \SystemRoot\system32\dla\tfsnboio.sys
                              0xA2601000 \SystemRoot\system32\dla\tfsncofs.sys
                              0xF8B88000 \SystemRoot\system32\dla\tfsndrct.sys
                              0xA2324000 \SystemRoot\system32\dla\tfsnudf.sys
                              0xA230B000 \SystemRoot\system32\dla\tfsnudfa.sys
                              0xA20D6000 \SystemRoot\System32\DRIVERS\mrxdav.sys
                              0xA209D000 \SystemRoot\System32\Drivers\adfs.SYS
                              0xF8A82000 \SystemRoot\System32\Drivers\ASCTRM.SYS
                              0xA1F7D000 \SystemRoot\System32\DRIVERS\srv.sys
                              0xA1BFC000 \SystemRoot\system32\drivers\wdmaud.sys
                              0xA1CB9000 \SystemRoot\system32\drivers\sysaudio.sys
                              0xF887E000 \SystemRoot\System32\Drivers\CBPSp50.sys
                              0xA1926000 \SystemRoot\system32\drivers\cfwids.sys
                              0xA1615000 \SystemRoot\System32\Drivers\HTTP.sys
                              0xA115B000 \SystemRoot\system32\drivers\mfeapfk.sys
                              0xA1B39000 \SystemRoot\system32\drivers\mfebopk.sys
                              0xA25B9000 \SystemRoot\System32\DRIVERS\ndisuio.sys
                              0x7C910000 \WINDOWS\SYSTEM32\ntdll.dll

                              Processes (total 36):
                              0 System Idle Process
                              4 System
                              1072 C:\WINDOWS\SYSTEM32\smss.exe
                              1136 csrss.exe
                              1164 C:\WINDOWS\SYSTEM32\winlogon.exe
                              1212 C:\WINDOWS\SYSTEM32\services.exe
                              1224 C:\WINDOWS\SYSTEM32\lsass.exe
                              1416 C:\WINDOWS\SYSTEM32\SVCHOST.EXE
                              1524 SVCHOST.EXE
                              1576 C:\WINDOWS\SYSTEM32\SVCHOST.EXE
                              1624 C:\WINDOWS\SYSTEM32\SVCHOST.EXE
                              1708 SVCHOST.EXE
                              1748 SVCHOST.EXE
                              1768 C:\WINDOWS\SYSTEM32\WLTRYSVC.EXE
                              1780 C:\WINDOWS\SYSTEM32\BCMWLTRY.EXE
                              1800 C:\WINDOWS\SYSTEM32\spoolsv.exe
                              1892 SVCHOST.EXE
                              1944 C:\WINDOWS\SYSTEM32\SVCHOST.EXE
                              1956 C:\WINDOWS\CBTWlanSrv.exe
                              1996 C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
                              2028 C:\Program Files\Fichiers communs\McAfee\McSvcHost\McSvHost.exe
                              220 C:\Program Files\Fichiers communs\McAfee\SystemCore\mfevtps.exe
                              280 C:\WINDOWS\SYSTEM32\SVCHOST.EXE
                              300 C:\WINDOWS\SYSTEM32\SVCHOST.EXE
                              332 C:\Program Files\Fichiers communs\McAfee\SystemCore\mcshield.exe
                              512 C:\Program Files\Fichiers communs\McAfee\SystemCore\mfefire.exe
                              2096 C:\WINDOWS\explorer.exe
                              2108 C:\WINDOWS\SYSTEM32\rundll32.exe
                              2688 alg.exe
                              2872 C:\Program Files\Apoint\Apoint.exe
                              2880 C:\Program Files\McAfee.com\Agent\mcagent.exe
                              2936 C:\Program Files\Hewlett-Packard\Digital Imaging\bin\HpqSRmon.exe
                              2960 C:\WINDOWS\SYSTEM32\ctfmon.exe
                              3520 C:\Program Files\Apoint\ApntEx.exe
                              3540 C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
                              3404 C:\Program Files\Annexe\MBRCheck\Setup\MBRCheck.exe

                              \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000'03ec1000 (NTFS)
                              \\.\I: --> \\.\PhysicalDrive1 at offset 0x00000000'00007e00 (NTFS)

                              PhysicalDrive0 Model Number: IC25N060ATMR04-0, Rev: MO3OAD0A
                              PhysicalDrive1 Model Number: SAMSUNGHM251JJ, Rev:

                              Size Device Name MBR Status
                              --------------------------------------------
                              55 GB \\.\PhysicalDrive0 Dell MBR code detected
                              SHA1: 84B95CE8A54B7C5C3AAF149934FC46FB70FF8365
                              232 GB \\.\PhysicalDrive1 RE: Windows XP MBR code detected
                              SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A

                              Done!
                              0
                              1. Re,

                                1/
                                * Télécharge sur le bureau RogueKiller (par tigzy)
                                https://www.luanagames.com/index.fr.html

                                *( Sous Vista/Seven,clique droit, lancer en tant qu'administrateur )

                                * Quitte tous tes programmes en cours
                                * Lance RogueKiller.exe.
                                * Lorsque demandé, tape 1 et valide
                                *Si le rogue empêche le lancement du programme, Renomme (RogueKiller) en "winlogon" ou "firefox". Sinon renomme le en winlogon.exe ou firefox.exe (rajouter l'extension .exe)
                                * Un rapport (RKreport.txt) a du se créer à côté de l'exécutable, colle son contenu dans la réponse
                                * Si le programme a été bloqué, ne pas hésiter a essayer plusieurs fois.

                                2/
                                * Telecharge et install UsbFix par El Desaparecido , C_XX & Chimay8
                                Ou à partir ce lien : http://teamxscript.changelog.fr/too/UsbFix.exe

                                (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

                                - Double clique sur le raccourci UsbFix sur ton Bureau (clique droit avec la souris

                                :exécuter en tant qu'administrateur pour vista/seven), l'installation se fera

                                automatiquement

                                -Clique sur "Recherche"

                                - Laisse travailler l'outil

                                - A la fin, le rapport va s'afficher : poste le dans ta prochaine réponse (il est aussi

                                sauvegardé a la racine du disque dur)

                                0
                                1. Je viens de passer RogueKiller, mais avant d'aller plus loin que j'arrête mon micro et que je ne puisse plus me connecter, pourrais-tu me dire comment on sort de quarantaine le programme que Roguekiller vient d'y mettre. Il vient de tuer le service (CBTWlanSrv.exe) qui gère ma carte PCMCIA (Linksys) avec laquelle je me connecte via le wifi. Et de plus je ne reviens pas chez moi avant le mois d'octobre donc où je suis je n'ai pas le logiciel pour réinstaller.
                                  Ci-dessous le rapport de Roguekiller:
                                  RogueKiller V5.2.7 [30/06/2011] par Tigzy
                                  contact sur https://www.luanagames.com/index.fr.html
                                  mail: tigzyRK<at>gmail<dot>com
                                  Remontees: https://www.luanagames.com/index.fr.html

                                  Systeme d'exploitation: Windows XP (5.1.2600 Service Pack 3) 32 bits version
                                  Demarrage : Mode normal
                                  Utilisateur: Roger [Droits d'admin]
                                  Mode: Recherche -- Date : 09/07/2011 19:02:57

                                  Processus malicieux: 1
                                  [SUSP PATH] CBTWlanSrv.exe -- c:\windows\cbtwlansrv.exe -> KILLED

                                  Entrees de registre: 1
                                  [HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

                                  Fichier HOSTS:
                                  127.0.0.1 localhost

                                  Termine : << RKreport[1].txt >>
                                  RKreport[1].txt
                                  0
                                  1. Finalement j'ai aussi passé USBFix, ci-dessous le rapport, mais n'oublie pas de répondre à ma question du message précédent, sinon dès que j'arrête le micro je ne pourrai plus me reconnecter!!! (est-ce qu'il suffit d'aller dans la directory quarantaine que Roguekiller a mise sur le bureau, récupérer CBTWlanSrv.exe en enlevant l'extension supplémentaire qu'il a rajouté et de le remettre à sa place ?? ou faut-il aussi recréer une clé du registre et où ?)
                                    ############################## | UsbFix 7.048 | [Recherche]

                                    Utilisateur: Roger (Administrateur) # MAYA [ ]
                                    Mis à jour le 11/06/2011 par TeamXscript
                                    Lancé à 19:22:38 | 09/07/2011
                                    Site Web: http://www.teamxscript.org
                                    Submit your sample: http://www.teamxscript.org/Upload.php
                                    Contact: TeamXscript.ElDesaparecido@gmail.com

                                    CPU: Intel(R) Pentium(R) 4 CPU 3.40GHz
                                    CPU 2: Intel(R) Pentium(R) 4 CPU 3.40GHz
                                    Microsoft Windows XP Édition familiale (5.1.2600 32-Bit) # Service Pack 3
                                    Internet Explorer 8.0.6001.18702

                                    Pare-feu Windows: Désactivé /!\
                                    Antivirus: McAfee AntiVirus et AntiSpyware [(!) Disabled | Updated]
                                    Firewall: McAfee Firewall [Enabled]
                                    RAM -> 511 Mo
                                    C:\ (%systemdrive%) -> Disque fixe # 52 Go (13 Go libre(s) - 26%) [Disque local] # NTFS
                                    D:\ -> CD-ROM
                                    E:\ -> CD-ROM
                                    F:\ -> CD-ROM
                                    G:\ -> Disque amovible # 4 Go (4 Go libre(s) - 100%) [KINGSTON] # FAT32
                                    I:\ -> Disque fixe # 233 Go (41 Go libre(s) - 18%) [USB drive] # NTFS

                                    ################## | Éléments infectieux |

                                    ################## | Registre |

                                    ################## | Mountpoints2 |

                                    HKCU\.\.\.\.\Explorer\MountPoints2\{1dc7ff4c-3578-11de-b704-b7c0add63e62}
                                    Shell\AutoRun\Command = G:\LaunchU3.exe -a

                                    ################## | Vaccin |

                                    (!) Cet ordinateur n'est pas vacciné!

                                    ################## | E.O.F |
                                    0
                                    • 1
                                    • 2
                                    • 3