Xp antispyware 2012 bloque l'accès internet

Résolu
Bonjour,

sur l'ordi de mon mari nous avons le mm problème, mais pas moyen d'accéder a internet, en mode sans échec, j'ai donc téléchargé le fichier roguekiller pour lui envoyer, mais sa messagerie lui bloque. pas moyen d'accéder non plus a internet explorer et en mode sans échec avec prise en charge réseau : il n'y a pas de connexion internet(en wifi) !
que faire ??

merci d'avance de votre aide précieuse !

41 réponses

Résumé de la discussion

Des utilisateurs rapportent un problème d’accès à Internet sur Windows, en mode normal et sans échec, lié à des paramètres proxy et à une infection potentielle nécessitant RogueKiller. Une réponse clé suggère de désactiver le Proxy via regedit (proxyserver et proxyenable), puis d’installer RogueKiller depuis le site officiel et d’en partager le rapport. Le fil discute aussi de l’utilisation des rapports RogueKiller (RKreport) pour identifier des processus malveillants, des entrées de registre et des modifications dans le fichier HOSTS. En cas de doute, plusieurs messages évoquent la nécessité d’analyser les rapports supplémentaires et de vérifier les fichiers système, car des éléments restants peuvent persister après l’étape initiale.

Bobot (l’IA à votre service)
  1. ok

    fais-lui faire ca :

    demarrer/executer puis taper regedit

    deplier l'arborescence :

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet settings

    clic gauche sur "internet settings"

    colonne de droite :

    clic droit/supprimer sur "ProxyServer"

    double-clic sur

    "ProxyEnable" et changer le "1" en "0"

    valider , fermer , internet explorer devrait refonctionner , il ne retera plus qu'à telecharger roguekiller sur le site officiel et venir poster le rapport ici
    1. COUCOU,
      il est sous XP professionnel
      1. bonjour, en fet j'ai fait une fausse manipulation et j'ai cliquer par erreur xp antispyware mais là il bloque internet!Le seul souci c'est que je ne l'ai pas installé jusqu'à la fin je ne sais même pas comment l'installer et comment faire pour accéder à internet parce que ça ne marche plus!aidez moi svp!merci merci
      2. salut faut t'ouvrir un nouveau sujet et exposer ton probleme pour une bonne prise en charge
    2. en suivant l'arborescence jusqu'a internet setting ok
      clic gauche internet setting, on ne trouve pas proxy (serveur a droite)
      par contre on trouve proxy enable déjà a 0

      et spyware bloc internet....
      1. fichier roguekiller transféré par cle USB après le scan on lance 2 pour suppression ?
        1. je ne sais comment te remercier....ca re marche,
          on était dessus depuis le matin, et en qq clics avec tes réponses c'était résolu

          1000 merci
          et bon WE
          1. ce n'est pas fini il te reste des fichiers systemes appartenant au rogue , poste les trois rapports
            1. ah ok, je posterai tout a l'heure,quand mon mari sera de nouveau dispo.... @+
              1. pas de soucis :)

                ne vous inquiétez pas je sais ou ils se trouvent ^^
                1. le re voilà !

                  je ne sais pas si c bien....j'ai copier/coller les rapports il y en a 6.....

                  RogueKiller V5.2.7 [30/06/2011] par Tigzy
                  contact sur https://www.luanagames.com/index.fr.html
                  mail: tigzyRK<at>gmail<dot>com
                  Remontees: https://www.luanagames.com/index.fr.html

                  Systeme d'exploitation: Windows XP (5.1.2600 Service Pack 3) 32 bits version
                  Demarrage : Mode normal
                  Utilisateur: pincemaille [Droits d'admin]
                  Mode: Recherche -- Date : 16/07/2011 14:34:18

                  Processus malicieux: 1
                  [SUSP PATH] dxm.exe -- c:\documents and settings\pincemaille.s2ea57.net\local settings\application data\dxm.exe -> KILLED

                  Entrees de registre: 13
                  [ROGUE ST] HKCU\[...]\Run : 1275360597 (C:\Documents and Settings\pincemaille.S2EA57.NET\Local Settings\Application Data\dxm.exe) -> FOUND
                  [ROGUE ST] HKUS\S-1-5-21-2888850211-2002387829-1167814658-2068[...]\Run : 1275360597 (C:\Documents and Settings\pincemaille.S2EA57.NET\Local Settings\Application Data\dxm.exe) -> FOUND
                  [HJ] HKLM\[...]\Security Center : AntiVirusDisableNotify (1) -> FOUND
                  [HJ] HKLM\[...]\Security Center : FirewallDisableNotify (1) -> FOUND
                  [HJ] HKLM\[...]\Security Center : UpdatesDisableNotify (1) -> FOUND
                  [HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
                  [FILEASSO] HKCU\[...]Software\Classes\.exe\shell\open\command : ("C:\Documents and Settings\pincemaille.S2EA57.NET\Local Settings\Application Data\dxm.exe" -a "%1" %*) -> FOUND
                  [FILEASSO] HKCU\[...]Software\Classes\exefile\shell\open\command : ("C:\Documents and Settings\pincemaille.S2EA57.NET\Local Settings\Application Data\dxm.exe" -a "%1" %*) -> FOUND
                  [FILEASSO] HKCR\[...]exefile\shell\open\command : ("C:\Documents and Settings\pincemaille.S2EA57.NET\Local Settings\Application Data\dxm.exe" -a "%1" %*) -> FOUND
                  [FILEASSO] HKCR\[...].exe\shell\open\command : ("C:\Documents and Settings\pincemaille.S2EA57.NET\Local Settings\Application Data\dxm.exe" -a "%1" %*) -> FOUND
                  [FILEASSO] HKLM\[...]Software\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command : ("C:\Documents and Settings\pincemaille.S2EA57.NET\Local Settings\Application Data\dxm.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe") -> FOUND
                  [FILEASSO] HKLM\[...]Software\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command : ("C:\Documents and Settings\pincemaille.S2EA57.NET\Local Settings\Application Data\dxm.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode) -> FOUND
                  [FILEASSO] HKLM\[...]Software\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command : ("C:\Documents and Settings\pincemaille.S2EA57.NET\Local Settings\Application Data\dxm.exe" -a "C:\Program Files\Internet Explorer\iexplore.exe") -> FOUND

                  Fichier HOSTS:
                  127.0.0.1 localhost
                  192.168.1.9 dell1.s2ea57.net dell1
                  192.168.1.11 poste11.s2ea57.net poste11
                  192.168.1.12 poste12.s2ea57.net poste12
                  192.168.1.13 poste13.s2ea57.net poste13
                  192.168.1.14 poste14.s2ea57.net poste14
                  192.168.1.15 poste15.s2ea57.net poste15
                  192.168.1.16 poste16.s2ea57.net poste16
                  192.168.1.17 poste17.s2ea57.net poste17
                  192.168.1.18 poste18.s2ea57.net poste18
                  192.168.1.19 poste19.s2ea57.net poste19
                  192.168.1.21 poste21.s2ea57.net poste21
                  192.168.1.22 poste22.s2ea57.net poste22
                  192.168.1.23 poste23.s2ea57.net poste23
                  192.168.1.24 poste24.s2ea57.net poste24
                  192.168.1.25 poste25.s2ea57.net poste25
                  192.168.1.31 poste31.s2ea57.net poste31
                  192.168.1.32 poste32.s2ea57.net poste32
                  192.168.1.33 poste33.s2ea57.net poste33
                  192.168.1.34 poste34.s2ea57.net poste34
                  [...]

                  Termine : << RKreport[1].txt >>
                  RKreport[1].txt

                  rapport 2
                  RogueKiller V5.2.7 [30/06/2011] par Tigzy
                  contact sur https://www.luanagames.com/index.fr.html
                  mail: tigzyRK<at>gmail<dot>com
                  Remontees: https://www.luanagames.com/index.fr.html

                  Systeme d'exploitation: Windows XP (5.1.2600 Service Pack 3) 32 bits version
                  Demarrage : Mode normal
                  Utilisateur: pincemaille [Droits d'admin]
                  Mode: Recherche -- Date : 16/07/2011 14:34:51

                  Processus malicieux: 0

                  Entrees de registre: 13
                  [ROGUE ST] HKCU\[...]\Run : 1275360597 (C:\Documents and Settings\pincemaille.S2EA57.NET\Local Settings\Application Data\dxm.exe) -> FOUND
                  [ROGUE ST] HKUS\S-1-5-21-2888850211-2002387829-1167814658-2068[...]\Run : 1275360597 (C:\Documents and Settings\pincemaille.S2EA57.NET\Local Settings\Application Data\dxm.exe) -> FOUND
                  [HJ] HKLM\[...]\Security Center : AntiVirusDisableNotify (1) -> FOUND
                  [HJ] HKLM\[...]\Security Center : FirewallDisableNotify (1) -> FOUND
                  [HJ] HKLM\[...]\Security Center : UpdatesDisableNotify (1) -> FOUND
                  [HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
                  [FILEASSO] HKCU\[...]Software\Classes\.exe\shell\open\command : ("C:\Documents and Settings\pincemaille.S2EA57.NET\Local Settings\Application Data\dxm.exe" -a "%1" %*) -> FOUND
                  [FILEASSO] HKCU\[...]Software\Classes\exefile\shell\open\command : ("C:\Documents and Settings\pincemaille.S2EA57.NET\Local Settings\Application Data\dxm.exe" -a "%1" %*) -> FOUND
                  [FILEASSO] HKCR\[...]exefile\shell\open\command : ("C:\Documents and Settings\pincemaille.S2EA57.NET\Local Settings\Application Data\dxm.exe" -a "%1" %*) -> FOUND
                  [FILEASSO] HKCR\[...].exe\shell\open\command : ("C:\Documents and Settings\pincemaille.S2EA57.NET\Local Settings\Application Data\dxm.exe" -a "%1" %*) -> FOUND
                  [FILEASSO] HKLM\[...]Software\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command : ("C:\Documents and Settings\pincemaille.S2EA57.NET\Local Settings\Application Data\dxm.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe") -> FOUND
                  [FILEASSO] HKLM\[...]Software\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command : ("C:\Documents and Settings\pincemaille.S2EA57.NET\Local Settings\Application Data\dxm.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode) -> FOUND
                  [FILEASSO] HKLM\[...]Software\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command : ("C:\Documents and Settings\pincemaille.S2EA57.NET\Local Settings\Application Data\dxm.exe" -a "C:\Program Files\Internet Explorer\iexplore.exe") -> FOUND

                  Fichier HOSTS:
                  127.0.0.1 localhost
                  192.168.1.9 dell1.s2ea57.net dell1
                  192.168.1.11 poste11.s2ea57.net poste11
                  192.168.1.12 poste12.s2ea57.net poste12
                  192.168.1.13 poste13.s2ea57.net poste13
                  192.168.1.14 poste14.s2ea57.net poste14
                  192.168.1.15 poste15.s2ea57.net poste15
                  192.168.1.16 poste16.s2ea57.net poste16
                  192.168.1.17 poste17.s2ea57.net poste17
                  192.168.1.18 poste18.s2ea57.net poste18
                  192.168.1.19 poste19.s2ea57.net poste19
                  192.168.1.21 poste21.s2ea57.net poste21
                  192.168.1.22 poste22.s2ea57.net poste22
                  192.168.1.23 poste23.s2ea57.net poste23
                  192.168.1.24 poste24.s2ea57.net poste24
                  192.168.1.25 poste25.s2ea57.net poste25
                  192.168.1.31 poste31.s2ea57.net poste31
                  192.168.1.32 poste32.s2ea57.net poste32
                  192.168.1.33 poste33.s2ea57.net poste33
                  192.168.1.34 poste34.s2ea57.net poste34
                  [...]

                  Termine : << RKreport[2].txt >>
                  RKreport[1].txt ; RKreport[2].txt

                  rapport 3
                  RogueKiller V5.2.7 [30/06/2011] par Tigzy
                  contact sur https://www.luanagames.com/index.fr.html
                  mail: tigzyRK<at>gmail<dot>com
                  Remontees: https://www.luanagames.com/index.fr.html

                  Systeme d'exploitation: Windows XP (5.1.2600 Service Pack 3) 32 bits version
                  Demarrage : Mode normal
                  Utilisateur: pincemaille [Droits d'admin]
                  Mode: Recherche -- Date : 16/07/2011 14:44:01

                  Processus malicieux: 0

                  Entrees de registre: 13
                  [ROGUE ST] HKCU\[...]\Run : 1275360597 (C:\Documents and Settings\pincemaille.S2EA57.NET\Local Settings\Application Data\dxm.exe) -> FOUND
                  [ROGUE ST] HKUS\S-1-5-21-2888850211-2002387829-1167814658-2068[...]\Run : 1275360597 (C:\Documents and Settings\pincemaille.S2EA57.NET\Local Settings\Application Data\dxm.exe) -> FOUND
                  [HJ] HKLM\[...]\Security Center : AntiVirusDisableNotify (1) -> FOUND
                  [HJ] HKLM\[...]\Security Center : FirewallDisableNotify (1) -> FOUND
                  [HJ] HKLM\[...]\Security Center : UpdatesDisableNotify (1) -> FOUND
                  [HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
                  [FILEASSO] HKCU\[...]Software\Classes\.exe\shell\open\command : ("C:\Documents and Settings\pincemaille.S2EA57.NET\Local Settings\Application Data\dxm.exe" -a "%1" %*) -> FOUND
                  [FILEASSO] HKCU\[...]Software\Classes\exefile\shell\open\command : ("C:\Documents and Settings\pincemaille.S2EA57.NET\Local Settings\Application Data\dxm.exe" -a "%1" %*) -> FOUND
                  [FILEASSO] HKCR\[...]exefile\shell\open\command : ("C:\Documents and Settings\pincemaille.S2EA57.NET\Local Settings\Application Data\dxm.exe" -a "%1" %*) -> FOUND
                  [FILEASSO] HKCR\[...].exe\shell\open\command : ("C:\Documents and Settings\pincemaille.S2EA57.NET\Local Settings\Application Data\dxm.exe" -a "%1" %*) -> FOUND
                  [FILEASSO] HKLM\[...]Software\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command : ("C:\Documents and Settings\pincemaille.S2EA57.NET\Local Settings\Application Data\dxm.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe") -> FOUND
                  [FILEASSO] HKLM\[...]Software\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command : ("C:\Documents and Settings\pincemaille.S2EA57.NET\Local Settings\Application Data\dxm.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode) -> FOUND
                  [FILEASSO] HKLM\[...]Software\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command : ("C:\Documents and Settings\pincemaille.S2EA57.NET\Local Settings\Application Data\dxm.exe" -a "C:\Program Files\Internet Explorer\iexplore.exe") -> FOUND

                  Fichier HOSTS:
                  127.0.0.1 localhost
                  192.168.1.9 dell1.s2ea57.net dell1
                  192.168.1.11 poste11.s2ea57.net poste11
                  192.168.1.12 poste12.s2ea57.net poste12
                  192.168.1.13 poste13.s2ea57.net poste13
                  192.168.1.14 poste14.s2ea57.net poste14
                  192.168.1.15 poste15.s2ea57.net poste15
                  192.168.1.16 poste16.s2ea57.net poste16
                  192.168.1.17 poste17.s2ea57.net poste17
                  192.168.1.18 poste18.s2ea57.net poste18
                  192.168.1.19 poste19.s2ea57.net poste19
                  192.168.1.21 poste21.s2ea57.net poste21
                  192.168.1.22 poste22.s2ea57.net poste22
                  192.168.1.23 poste23.s2ea57.net poste23
                  192.168.1.24 poste24.s2ea57.net poste24
                  192.168.1.25 poste25.s2ea57.net poste25
                  192.168.1.31 poste31.s2ea57.net poste31
                  192.168.1.32 poste32.s2ea57.net poste32
                  192.168.1.33 poste33.s2ea57.net poste33
                  192.168.1.34 poste34.s2ea57.net poste34
                  [...]

                  Termine : << RKreport[3].txt >>
                  RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt

                  rapport 4
                  RogueKiller V5.2.7 [30/06/2011] par Tigzy
                  contact sur https://www.luanagames.com/index.fr.html
                  mail: tigzyRK<at>gmail<dot>com
                  Remontees: https://www.luanagames.com/index.fr.html

                  Systeme d'exploitation: Windows XP (5.1.2600 Service Pack 3) 32 bits version
                  Demarrage : Mode normal
                  Utilisateur: pincemaille [Droits d'admin]
                  Mode: Suppression -- Date : 16/07/2011 14:44:48

                  Processus malicieux: 0

                  Entrees de registre: 10
                  [ROGUE ST] HKCU\[...]\Run : 1275360597 (C:\Documents and Settings\pincemaille.S2EA57.NET\Local Settings\Application Data\dxm.exe) -> DELETED
                  [HJ] HKLM\[...]\Security Center : AntiVirusDisableNotify (1) -> REPLACED (0)
                  [HJ] HKLM\[...]\Security Center : FirewallDisableNotify (1) -> REPLACED (0)
                  [HJ] HKLM\[...]\Security Center : UpdatesDisableNotify (1) -> REPLACED (0)
                  [HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
                  [FILE ASSO] HKCU\[...]Software\Classes\.exe\shell\open\command : ("C:\Documents and Settings\pincemaille.S2EA57.NET\Local Settings\Application Data\dxm.exe" -a "%1" %*) -> REPLACED : ("%1" %*)
                  [FILE ASSO] HKCU\[...]Software\Classes\exefile\shell\open\command : ("C:\Documents and Settings\pincemaille.S2EA57.NET\Local Settings\Application Data\dxm.exe" -a "%1" %*) -> REPLACED : ("%1" %*)
                  [FILE ASSO] HKLM\[...]Software\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command : ("C:\Documents and Settings\pincemaille.S2EA57.NET\Local Settings\Application Data\dxm.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe") -> REPLACED : ("C:\Program Files\mozilla firefox\firefox.exe")
                  [FILE ASSO] HKLM\[...]Software\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command : ("C:\Documents and Settings\pincemaille.S2EA57.NET\Local Settings\Application Data\dxm.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode) -> REPLACED : ("C:\Program Files\mozilla firefox\firefox.exe" -safe-mode)
                  [FILE ASSO] HKLM\[...]Software\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command : ("C:\Documents and Settings\pincemaille.S2EA57.NET\Local Settings\Application Data\dxm.exe" -a "C:\Program Files\Internet Explorer\iexplore.exe") -> REPLACED : ("C:\Program Files\internet explorer\iexplore.exe")

                  Fichier HOSTS:
                  127.0.0.1 localhost
                  192.168.1.9 dell1.s2ea57.net dell1
                  192.168.1.11 poste11.s2ea57.net poste11
                  192.168.1.12 poste12.s2ea57.net poste12
                  192.168.1.13 poste13.s2ea57.net poste13
                  192.168.1.14 poste14.s2ea57.net poste14
                  192.168.1.15 poste15.s2ea57.net poste15
                  192.168.1.16 poste16.s2ea57.net poste16
                  192.168.1.17 poste17.s2ea57.net poste17
                  192.168.1.18 poste18.s2ea57.net poste18
                  192.168.1.19 poste19.s2ea57.net poste19
                  192.168.1.21 poste21.s2ea57.net poste21
                  192.168.1.22 poste22.s2ea57.net poste22
                  192.168.1.23 poste23.s2ea57.net poste23
                  192.168.1.24 poste24.s2ea57.net poste24
                  192.168.1.25 poste25.s2ea57.net poste25
                  192.168.1.31 poste31.s2ea57.net poste31
                  192.168.1.32 poste32.s2ea57.net poste32
                  192.168.1.33 poste33.s2ea57.net poste33
                  192.168.1.34 poste34.s2ea57.net poste34
                  [...]

                  Termine : << RKreport[4].txt >>
                  RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt ; RKreport[4].txt

                  rapport 5
                  RogueKiller V5.2.7 [30/06/2011] par Tigzy
                  contact sur https://www.luanagames.com/index.fr.html
                  mail: tigzyRK<at>gmail<dot>com
                  Remontees: https://www.luanagames.com/index.fr.html

                  Systeme d'exploitation: Windows XP (5.1.2600 Service Pack 3) 32 bits version
                  Demarrage : Mode normal
                  Utilisateur: pincemaille [Droits d'admin]
                  Mode: Proxy RAZ -- Date : 16/07/2011 14:45:44

                  Processus malicieux: 0

                  Entrees de registre: 0

                  Termine : << RKreport[5].txt >>
                  RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt ; RKreport[4].txt ; RKreport[5].txt

                  rapport 6
                  RogueKiller V5.2.7 [30/06/2011] par Tigzy
                  contact sur https://www.luanagames.com/index.fr.html
                  mail: tigzyRK<at>gmail<dot>com
                  Remontees: https://www.luanagames.com/index.fr.html

                  Systeme d'exploitation: Windows XP (5.1.2600 Service Pack 3) 32 bits version
                  Demarrage : Mode normal
                  Utilisateur: pincemaille [Droits d'admin]
                  Mode: Raccourcis RAZ -- Date : 16/07/2011 14:51:06

                  Processus malicieux: 0

                  Attributs de fichiers restaures:
                  Bureau: Success 1 / Fail 0
                  Lancement rapide: Success 0 / Fail 0
                  Programmes: Success 6 / Fail 0
                  Menu demarrer: Success 0 / Fail 0
                  Dossier utilisateur: Success 85 / Fail 0
                  Mes documents: Success 8 / Fail 0
                  Mes favoris: Success 0 / Fail 0
                  Mes images: Success 0 / Fail 0
                  Ma musique: Success 0 / Fail 0
                  Mes videos: Success 0 / Fail 0
                  Disques locaux: Success 791 / Fail 0
                  Sauvegarde: [NOT FOUND]

                  Lecteurs:
                  [C:] \Device\HarddiskVolume2 -- 0x3 --> Restored
                  [D:] \Device\CdRom0 -- 0x5 --> Skipped

                  Termine : << RKreport[6].txt >>
                  RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt ; RKreport[4].txt ; RKreport[5].txt ;
                  RKreport[6].txt
                  1. ok

                    desactive ton antivirus
                    desactive Windows defender si présent
                    desactive ton pare-feu

                    Ferme toutes tes appilications en cours

                    telecharge et enregistre ceci sur ton bureau :

                    Pre_Scan

                    mirroir :

                    http://www.archive-host.com

                    s'il n'est pas sur ton bureau coupe-le de ton dossier telechargements et colle-le sur ton bureau

                    Avertissement: Il y aura une extinction du bureau pendant le scan --> pas de panique.

                    une fois telechargé lance-le , laisse faire le scan jusqu'à l'apparition de "Pre_scan.txt" sur le bureau.

                    si 'outil est bloqué par l'infection utilise cette version : Version .pif

                    si l'outil detecte un proxy et que tu n'en as pas installé clique sur "supprimer le proxy"

                    si l'outil semble ne pas avoir fonctionné renomme-le winlogon , ou change son extension en .com ou .scr

                    Il se peut qu'une multitude de fenêtres noires clignotent , laisse-le travailler

                    Poste Pre_Scan.txt qui apparaitra sur le bureau en fin de scan

                    ▶▶▶ NE LE POSTE PAS SUR LE FORUM (il est trop long)

                    clique sur ce lien : http://www.cijoint.fr/

                    ▶ Clique sur Parcourir et cherche le fichier ci-dessus.

                    ▶ Clique sur Ouvrir.

                    ▶ Clique sur "Cliquez ici pour déposer le fichier".

                    Un lien de cette forme :

                    http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

                    est ajouté dans la page.

                    ▶ Copie ce lien dans ta réponse.

                    si ton bureau ne reapparait pas => ctrl+alt+supp , gestionnaire des taches => onglet fichier => nouvelle tache puis tape explorer
                    1. on n'arrive pas désactiver l'antivirus, c un "F-prot antivirus pour windows "!!
                      1. je t'envoie le lien a partir de l'ordi infecté;.....

                        http://www.cijoint.fr/cjlink.php?file=cj201107/cijqrpU9ma.txt
                        1. mon dieu mais c'est horrible !! on a bien fait de continuer !!

                          ========================

                          desinstalle Adobe reader on mettra le dernier à la fin
                          desinstalle pddforge toolbar c'est un ramsse trojans

                          ================================

                          fais glisser une icone n'importe quel fichier sur Pre_scan , pre_script va apparaitre

                          ouvre Pre_script et colle ce qui suit en gras, à l'interieur du texte qui s'ouvre ,
                          sans les lignes , en une seule fois en le mettant en surbrillance :
                          ___________________________________________________
                          processes::
                          ApplicationUpdater.exe
                          SearchSettings.exe

                          Registry::
                          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "Sonic RecordNow!"=-
                          "ISUSPM"=-
                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "nwiz"=-
                          "Dell QuickSet"=-
                          "Adobe Reader Speed Launcher"=-
                          ""=-
                          "SearchSettings"=-
                          [-HKEY_CLASSES_ROOT\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
                          [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
                          [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ext\settings\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
                          [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ext\stats\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
                          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
                          "{B922D405-6D13-4A2B-AE89-08A030DA4402}"=-
                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\URLSearchHooks]
                          "{B922D405-6D13-4A2B-AE89-08A030DA4402}"=-
                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
                          "{B922D405-6D13-4A2B-AE89-08A030DA4402}"=-
                          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
                          "{B922D405-6D13-4A2B-AE89-08A030DA4402}"=-
                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
                          "{B922D405-6D13-4A2B-AE89-08A030DA4402}"=-
                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
                          "{B922D405-6D13-4A2B-AE89-08A030DA4402}"=-
                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
                          "{B922D405-6D13-4A2B-AE89-08A030DA4402}"=-
                          [-HKEY_LOCAL_MACHINE\Software\Application Updater]
                          [-HKEY_LOCAL_MACHINE\Software\pdfforge]
                          [-HKEY_LOCAL_MACHINE\Software\Search Settings]
                          [HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
                          "139:TCP"=-
                          "445:TCP"=-
                          "137:UDP"=-
                          "138:UDP"=-

                          file::
                          C:\Documents and Settings\All Users\Application Data\hw1bknq874beni6e51i228tag
                          C:\Documents and Settings\pincemaille.S2EA57.NET\Local Settings\Application Data\hw1bknq874beni6e51i228tag

                          folder::
                          C:\Program Files\Application Updater
                          C:\Program Files\Fichiers communs\Spigot
                          C:\Documents and Settings\pincemaille.S2EA57.NET\Application Data\pdfforge
                          C:\Documents and Settings\pincemaille.S2EA57.NET\Application Data\Search Settings
                          C:\Program Files\Application Updater
                          C:\Program Files\pdfforge Toolbar

                          Driver::
                          Application Updater

                          attrib::

                          ___________________________________________________

                          copie-le (ctrl+c ou clique droit sur la selection puis => copier)

                          puis onglet fichier => enregistrer (pas enregistrer sous...) , puis ferme le texte

                          des fenetres noires risquent de clignoter , c'est normal , c'est le programme qui travaille

                          poste Pre_Script.txt qui apparaitra sur le bureau en fin de travail

                          si ton bureau ne reapparait pas => ctrl+alt+supp , gestionnaire des taches => onglet fichier => nouvelle tache puis tape explorer
                          1. adobe reader 9.2 français ne peut pas être désinstallé !!
                            il y en a 2 autres : adobe flash player 10 active X
                            & adobe flash player plugin
                            ??
                            1. En fait ne peut pas être supprimé car des fichiers seraient en cours d'utilisation alors que les applications sont fermées. (fenêtre adobe reader 9)
                              • 1
                              • 2
                              • 3