Je suis infecte par personal security center

Résolu
bonjour . je ne sais pas comment j ai eu sa il me demande systemati quement "d acheter "le logiciel appeler "personal security center" en plus j ai toujours "systemdoctor 2006" qui vient tout le temp sur l ecran je ne suis pas un as de lordi comment se debarasser de ces sale bete d avance merci
Configuration: Windows XP
professoinnel 5 1 2600       pack 2

27 réponses

Résumé de la discussion

Plusieurs utilisateurs rencontrent une infection affichant Personal Security Center et System Doctor 2006 sur Windows XP, signalant que des programmes indésirables bloquent l'accès et simulent des alertes de sécurité. Pour s'en défaire, désactiver le démarrage automatique de Personal Security Center (par ex via CCleaner), redémarrer en mode sans échec et supprimer les fichiers malveillants listés dans le dossier système. Ensuite, exécuter des analyses complètes avec Malwarebytes' Anti-Malware ou alternatives comme AVG Anti-Spyware et Avast, puis supprimer les éléments détectés et nettoyer les points de restauration si possible. D'autres conseils recommandent des outils spécialisés et des nettoyages approfondis, et partagent des rapports d'analyse pour traquer les composants indésirables.

Bobot (l’IA à votre service)
  1. Hello !

    Clic sur démarrer, rechercher, tous les fichiers et dossiers, cherche et supprime :

    C:\WINDOWS\system32\ocguruft.dll
    C:\WINDOWS\system32\stcheck32.exe
    C:\WINDOWS\system32\swxrkxow.dll
    C:\WINDOWS\system32\wbypatod.exe

    **Si un fichier/dossier persiste lors de la suppression fait ceci:
    - Redémarre ton PC. Dès l'allumage de celui-ci tapote la touche F8 (ou F5 si F8 ne fonctionne pas), à l'écran qui va apparaître choisis "mode sans echec" attends un peu..
    Puis va supprimer les fichiers/dossiers, vide ta corbeille et redémarre ton PC normalement.

    Dis moi tous les antispywares que tu as stp
    4
    1. j'ai fait la manip mais je ne retrouve nulle part
      C:\WINDOWS\system32\ocguruft.dll
      C:\WINDOWS\system32\stcheck32.exe
      C:\WINDOWS\system32\swxrkxow.dll
      C:\WINDOWS\system32\wbypatod.exe
      comment faire?
      0
  2. Logfile of HijackThis v1.99.1
    Scan saved at 22:38:10, on 18/04/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\WINDOWS\System32\atievxx.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Fichiers communs\AOL\1168514836\ee\AOLSoftware.exe
    C:\WINDOWS\system32\wbypatod.exe
    C:\WINDOWS\system32\stcheck32.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    c:\program files\fichiers communs\aol\1168514836\ee\services\antiSpywareApp\ver2_0_28_1\AOLSP Scheduler.exe
    c:\program files\fichiers communs\aol\1168514836\ee\aolsoftware.exe
    c:\program files\fichiers communs\aol\1168514836\ee\ComputerCheckup.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://acrobat.adobe.com/us/en/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\swxrkxow.dll
    O2 - BHO: (no name) - {68218620-3D65-43F6-AD47-D38D84B5412A} - (no file)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: (no name) - {BB3A85F2-4CFD-47D9-A4DD-5A1A94DB5E85} - C:\WINDOWS\system32\jkhed.dll
    O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\qioihjvf.dll",setvm
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Fichiers communs\AOL\1168514836\ee\AOLSoftware.exe
    O4 - HKLM\..\Run: [wbypatod.exe] C:\WINDOWS\system32\wbypatod.exe
    O4 - HKLM\..\Run: [Privacy tools] C:\WINDOWS\system32\stcheck32.exe
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\WINDOWS\System32\shdocvw.dll
    O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\WINDOWS\System32\shdocvw.dll
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
    O20 - Winlogon Notify: jkhed - C:\WINDOWS\system32\jkhed.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

    2
    1. bonjour j ai reussi la suppression en passent par sans echec alor j ai aol spyware et a g v antispyware por 20 jour . merci beaucoup de m avoir aide
      2
      1. Salut,

        Télécharge SmitfraudFix et enregistre le sur le bureau. Si ton anti-virus t'alerte d'un virus, désactive-le.
        http://siri.urz.free.fr/Fix/SmitfraudFix.zip

        décompresse SmitfraudFix
        Lance le fichier SmitfraudFix ou SmitfraudFix.cmd et choisit l option 1 copie le rapport ici stp
        1
        1. SmitFraudFix v2.164

          Rapport fait à 11:22:31,57, 19/04/2007
          Executé à partir de C:\Documents and Settings\DUJARRIER ALAIN\Bureau\SmitfraudFix
          OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
          Le type du système de fichiers est NTFS
          Fix executé en mode normal

          »»»»»»»»»»»»»»»»»»»»»»»» Process

          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\Program Files\QuickTime\qttask.exe
          C:\Program Files\Fichiers communs\AOL\1168514836\ee\AOLSoftware.exe
          C:\WINDOWS\system32\wbypatod.exe
          C:\WINDOWS\system32\stcheck32.exe
          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
          C:\WINDOWS\system32\LEXBCES.EXE
          C:\WINDOWS\system32\LEXPPS.EXE
          C:\WINDOWS\system32\spoolsv.exe
          C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
          C:\WINDOWS\System32\atievxx.exe
          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
          C:\Program Files\Fichiers communs\AOL\Loader\aolload.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
          C:\WINDOWS\wanmpsvc.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          c:\program files\fichiers communs\aol\1168514836\ee\services\antiSpywareApp\ver2_0_28_1\AOLSP Scheduler.exe
          c:\program files\fichiers communs\aol\1168514836\ee\aolsoftware.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\WINDOWS\system32\cmd.exe

          »»»»»»»»»»»»»»»»»»»»»»»» hosts

          »»»»»»»»»»»»»»»»»»»»»»»» C:\

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\DUJARRIER ALAIN

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\DUJARRIER ALAIN\Application Data

          »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

          »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\DUJARR~1\Favoris

          »»»»»»»»»»»»»»»»»»»»»»»» Bureau

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

          »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

          »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

          »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          SrchSTS.exe by S!Ri
          Search SharedTaskScheduler's .dll

          »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
          "AppInit_DLLs"=""

          »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
          "System"=""

          »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32-huy32

          »»»»»»»»»»»»»»»»»»»»»»»» DNS

          Description: D-Link DFE-530TX PCI Fast Ethernet Adapter (rev.C) - Miniport d'ordonnancement de paquets
          DNS Server Search Order: 10.0.0.138

          HKLM\SYSTEM\CCS\Services\Tcpip\..\{41739C2C-6CF4-45F0-87B7-E0C70BDA6256}: DhcpNameServer=10.0.0.138

          »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

          »»»»»»»»»»»»»»»»»»»»»»»» Fin
          0
        2. bonjour l antivirus ne le trouve pas par conte j ai un alerte embat de l ecran et une fenetre qui s ouvre tout le temps merci pour lede
          0
      2. Tu peux le jeter.

        Mets à jour AVG antispyware et fais un scan complet de ton système puis colle le rapport ici stp

        Fais ce scan anti-virus en ligne avec Internet Explorer, accepte l'active X; la barre anti-popup du SP2(en haut) va se mettre à clignoter, clique dessus et choisit "accepter l'active X" pour faire fonctionner le scan anti-virus.
        Une fois qu'il a terminé colle le rapport ici stp

        ---> https://www.kaspersky.fr/downloads

        - Kaspersky Online Scanner
        - Accept
        0
        1. ---------------------------------------------------------
          AVG Anti-Spyware - Rapport d'analyse
          ---------------------------------------------------------

          + Créé à: 02:54:11 20/04/2007

          + Résultat de l'analyse:

          C:\System Volume Information\_restore{2A21CFED-D728-4C61-AEFC-1F306E72490F}\RP116\A0029185.exe -> Adware.UltimateDefender : Aucune action entreprise.
          C:\System Volume Information\_restore{2A21CFED-D728-4C61-AEFC-1F306E72490F}\RP116\A0029186.exe -> Adware.UltimateDefender : Aucune action entreprise.
          C:\WINDOWS\system32\qnmejqur\qnmejqur1.exe -> Adware.UltimateDefender : Aucune action entreprise.
          C:\WINDOWS\system32\qnmejqur\qnmejqur3.exe -> Adware.UltimateDefender : Aucune action entreprise.
          :mozilla.8:C:\Documents and Settings\DUJARRIER ALAIN\Application Data\Mozilla\Firefox\Profiles\xhn9v2j8.default\cookies.txt -> TrackingCookie.247realmedia : Aucune action entreprise.

          Fin du rapport
          0
        2. je n ai plus internet tout passe par Mozilla FireFox ou aol comme tu me demande labarre anti-popup du s p2 es que je peux le faire avec Mozilla a+
          0
      3. KASPERSKY ONLINE SCANNER REPORT
        Friday, April 20, 2007 5:43:56 PM
        Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
        Kaspersky Online Scanner version: 5.0.83.0
        Kaspersky Anti-Virus database last update: 20/04/2007
        Kaspersky Anti-Virus database records: 282503
        Scan Settings
        Scan using the following antivirus database standard
        Scan Archives true
        Scan Mail Bases true
        Scan Target Critical Areas
        C:\WINDOWS
        C:\DOCUME~1\DUJARR~1\LOCALS~1\Temp\
        Scan Statistics
        Total number of scanned objects 15943
        Number of viruses found 2
        Number of infected objects 4 / 0
        Number of suspicious objects 0
        Duration of the scan process 00:21:15

        Infected Object Name Virus Name Last Action
        C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
        C:\WINDOWS\SchedLgU.Txt Object is locked skipped
        C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
        C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
        C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
        C:\WINDOWS\system32\config\default Object is locked skipped
        C:\WINDOWS\system32\config\default.LOG Object is locked skipped
        C:\WINDOWS\system32\config\SAM Object is locked skipped
        C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
        C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
        C:\WINDOWS\system32\config\SECURITY Object is locked skipped
        C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
        C:\WINDOWS\system32\config\software Object is locked skipped
        C:\WINDOWS\system32\config\software.LOG Object is locked skipped
        C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
        C:\WINDOWS\system32\config\system Object is locked skipped
        C:\WINDOWS\system32\config\system.LOG Object is locked skipped
        C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat Object is locked skipped
        C:\WINDOWS\system32\config\systemprofile\Local Settings\Historique\History.IE5\index.dat Object is locked skipped
        C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
        C:\WINDOWS\system32\h323log.txt Object is locked skipped
        C:\WINDOWS\system32\ocguruft.dll Infected: Trojan.Win32.BHO.g skipped
        C:\WINDOWS\system32\stcheck32.exe Infected: Trojan.Win32.Obfuscated.ev skipped
        C:\WINDOWS\system32\swxrkxow.dll Infected: Trojan.Win32.BHO.g skipped
        C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
        C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
        C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
        C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
        C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
        C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
        C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
        C:\WINDOWS\system32\wbypatod.exe Infected: Trojan.Win32.Obfuscated.ev skipped
        C:\WINDOWS\Temp\Perflib_Perfdata_610.dat Object is locked skipped
        C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped
        C:\WINDOWS\WindowsUpdate.log Object is locked skipped
        C:\DOCUME~1\DUJARR~1\LOCALS~1\Temp\~DF9BCA.tmp Object is locked skipped
        Scan process completed.
        0
        1. bonjour après avoir eseillier Mozilla le housecall je n ai pas reussi a enleve le viruse "this trojan vundo.xq et this trojan usually "dont j ai fait des recherche pour retrouve internet je suis content j ai reussi dont j ai fais kaspersky je trouve qu il y a boucous de salte dans mon ordi j ai un nouveau " driveclene + doctor +alureon cf +nuvens " je n ai rien ouvert pour ses dernier merci d avance a +
          0
          1. ps quand tu dit " Tu peux le jeter " je jette l ordi ou l antiviruse deja pour l ordi je les achete d occasion car je suis en retraite et je me suis aperçu que windows n ai pas d'origine je ne peux pas faire les mise a jours alor tu vois l ordi que j ai mes ça me suffit a +
            0
            1. rebonjour j ai oublier de te dire que la bete et parti tu ma fait comprendre un peu plus l ordinateur je nave jame ete ci loin dans windows je remerci pour ce tu ma fais faire merci pour la bete a +
              0
              1. Bonjour

                Je pense pas que ton PC soit totalement propre.
                Concernant AVG antispyware il reste gratuit après la période d'essai, tu devras juste faire manuellement les mises à jours.

                Je te conseille d'ajouter ces anti-spywares et ce pare-feu :

                SpyBot-Search & Destroy : gratuit en français
                ----> http://www.infos-du-net.com/telecharger/Destroy-Search-Spybot,0301-324.html

                Si tu as besoin d'aide avec Sybot regarde ce tutoriel :
                --> http://www.tutoriaux-excalibur.com/spybot.htm

                A² squared : gratuit en français (fait un scan rusé et colle le rapport ici stp)
                ----> http://www.infos-du-net.com/telecharger/a-squared,0301-1233.html

                Si tu as besoin d'aide avec A-squared regarde ce tutoriel :
                --> https://kerio.probb.fr/t223-tuto-pour-a-squared-free

                Ad-Aware SE Personal : gratuit en anglais disponible en français voir tutoriel
                ----> http://www.infos-du-net.com/telecharger/Ad-aware-Personal,0301-244.html

                Si tu as besoin d'aide pour Ad-aware regarde ce tutoriel :
                --> https://kerio.probb.fr/t207-tutoriel-pour-ad-aware-anti-spyware

                Télécharge Spywareblaster
                ----> spyware blaster

                Puis exécute le logiciel pour lui appliquer les protections.
                Si tu as besoin d'aide, regarde ce tutoriel pour Spywareblaster
                https://kerio.probb.fr/t241-tuto-spywareblaster

                Désactive le pare-feu de Windows(SP2) il ne sert à rien puis installe celui ci pour plus de sécurité

                Kerio (pare-feu) : reste gratuit après la période d'essai en français
                ----> http://www.infos-du-net.com/telecharger/Firewall-Kerio-Personal,0301-390.html

                Regarde ce tutoriel si tu as besoin d'aide pour l'installation et la configuration de Kerio
                --> https://kerio.probb.fr/t250-tuto-sunbelt-personal-firewall-4-6

                Plus d'info :
                ->https://kerio.probb.fr/

                A plus tard ++
                0
                1. Version - a-squared Free 2.1

                  Réglages Scan:

                  Objets: Mémoire, Traces, Cookies, C:\WINDOWS\, C:\Program Files
                  Scan archives: Marche
                  Heuristiques: Marche
                  Scan ADS: Marche

                  Début du scan: 22/04/2007 09:23:00

                  Value: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser --> {5CBE2611-C31B-401F-89BC-4CBB25E853D7} Détecter: Trace.Registry.Zango Toolbar
                  C:\Program Files\ultimate fixer Détecter: Trace.Directory.Ultimate Fixer
                  C:\Documents and Settings\DUJARRIER ALAIN\Cookies\dujarrier alain@adserver.aol[2].txt Détecter: Trace.TrackingCookie
                  C:\Documents and Settings\DUJARRIER ALAIN\Cookies\dujarrier alain@link[1].txt Détecter: Trace.TrackingCookie
                  C:\Documents and Settings\DUJARRIER ALAIN\Application Data\Mozilla\Firefox\Profiles\xhn9v2j8.default\cookies.txt:10 Détecter: Trace.TrackingCookie
                  C:\Documents and Settings\DUJARRIER ALAIN\Application Data\Mozilla\Firefox\Profiles\xhn9v2j8.default\cookies.txt:36 Détecter: Trace.TrackingCookie
                  C:\Documents and Settings\DUJARRIER ALAIN\Application Data\Mozilla\Firefox\Profiles\xhn9v2j8.default\cookies.txt:37 Détecter: Trace.TrackingCookie
                  C:\Documents and Settings\DUJARRIER ALAIN\Application Data\Mozilla\Firefox\Profiles\xhn9v2j8.default\cookies.txt:38 Détecter: Trace.TrackingCookie
                  C:\Documents and Settings\DUJARRIER ALAIN\Application Data\Mozilla\Firefox\Profiles\xhn9v2j8.default\cookies.txt:39 Détecter: Trace.TrackingCookie
                  C:\Program Files\Mozilla Firefox\SmitfraudFix\Process.exe Détecter: Riskware.RiskTool.Win32.Processor.20
                  C:\Program Files\Mozilla Firefox\SmitfraudFix\Reboot.exe Détecter: Riskware.RiskTool.Win32.Reboot.f

                  Scanné

                  Fichiers: 47843
                  Traces: 110343
                  Cookies: 53
                  Processus: 33

                  Trouver

                  Fichiers: 2
                  Traces: 2
                  Cookies: 7
                  Processus: 0
                  Clés de Registre: 0

                  Fin du Scan: 22/04/2007 09:56:15
                  Temps du Scan: 00:33:15
                  0
                  1. N'hésite pas à tout supprimer.
                    Dès que tu as tout fait fais moi signe ;-)

                    A++
                    0
                    1. bonjour petit problème j ai du mal a allai sur le cite j ai comme aussi j ai presque tout fait sauf spywareblaster je n ai pas encore compris le site mais je vais arriver il n ai pas en France. j ai enlever windows le par feu il n arrête pas de venire sur l écran il avais beaucoup de saletés la j ai vue une parti de se qu ont peu faire avec l ordi je temps remercie a +
                      0
                      1. j ai été sur le cite kerio aide informatique il et superbe je vais avoir de la lecture j ai pu rentre spywareblaster un page internet explorer me marque " Ad blocked here by KPF." je vai voire avec windows pour la copie qui dans l ordi franchement merci pour tout a ++
                        0
                        1. tout fonconne a merveille . MILLE MERCI ALAINMARINE A+
                          0
                          1. Coucou !

                            Si tu as des questions ou problème n'hésite pas ;-)
                            0
                            1. bonjour une petite question peu tu me donne quelle que antivirus car avast que j ai il me reste 20 jours mille merci pour tout ps comment te contacte par cette page ou par kerio
                              0
                              1. Pur Avast fais une demande de licence gratuite, ici : tu auras juste à entrer les chiffres qui vont t'envoyer dans l'espace réservé à cet effet dans le logiciel.
                                https://www.avast.com/fr-fr/registration-free-antivirus

                                Tu peux me contacter ou tu souhaites pas de souci ;-)
                                0
                                1. SmitFraudFix v2.424

                                  Rapport fait à 19:21:55,87, 12/01/2010
                                  Executé à partir de C:\Documents and Settings\CLERY\Mes documents\T‚l‚chargements\SmitfraudFix\SmitfraudFix
                                  OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                                  Le type du système de fichiers est NTFS
                                  Fix executé en mode normal

                                  »»»»»»»»»»»»»»»»»»»»»»»» Process

                                  C:\WINDOWS\System32\smss.exe
                                  C:\WINDOWS\system32\winlogon.exe
                                  C:\WINDOWS\system32\services.exe
                                  C:\WINDOWS\system32\lsass.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\WINDOWS\Explorer.EXE
                                  C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                  C:\WINDOWS\system32\spoolsv.exe
                                  C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                  C:\Acer\Empowering Technology\admServ.exe
                                  C:\Program Files\Bonjour\mDNSResponder.exe
                                  C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
                                  C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
                                  C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe
                                  C:\Program Files\Java\jre6\bin\jqs.exe
                                  C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                  C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                                  C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                                  C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
                                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                  C:\WINDOWS\system32\igfxtray.exe
                                  C:\WINDOWS\system32\hkcmd.exe
                                  C:\WINDOWS\system32\igfxpers.exe
                                  C:\WINDOWS\system32\rundll32.exe
                                  C:\Acer\Empowering Technology\eRecovery\Monitor.exe
                                  C:\WINDOWS\system32\wbem\wmiapsrv.exe
                                  C:\WINDOWS\RTHDCPL.EXE
                                  C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                  C:\Acer\Empowering Technology\admtray.exe
                                  C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
                                  C:\Program Files\Acer\Acer Arcade\PCMService.exe
                                  C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
                                  C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                  C:\DOCUME~1\CLERY\LOCALS~1\Temp\RtkBtMnt.exe
                                  C:\WINDOWS\system32\wbem\unsecapp.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\Program Files\Java\jre6\bin\jusched.exe
                                  C:\WINDOWS\system32\ctfmon.exe
                                  C:\Program Files\Microsoft ActiveSync\wcescomm.exe
                                  C:\Program Files\PersonalSec\psecurity.exe
                                  C:\Documents and Settings\CLERY\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
                                  C:\PROGRA~1\MICROS~4\rapimgr.exe
                                  C:\Documents and Settings\CLERY\Application Data\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
                                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                  C:\Program Files\Java\jre6\bin\jucheck.exe
                                  C:\Program Files\Mozilla Firefox\firefox.exe
                                  C:\WINDOWS\system32\cmd.exe

                                  »»»»»»»»»»»»»»»»»»»»»»»» hosts

                                  »»»»»»»»»»»»»»»»»»»»»»»» C:\

                                  »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                                  »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                                  »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                                  »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                                  »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

                                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\CLERY

                                  »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\CLERY\LOCALS~1\Temp

                                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\CLERY\Application Data

                                  »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                                  »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\CLERY\Favoris

                                  »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                                  »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                                  »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                                  "Source"="About:Home"
                                  "SubscribedURL"="About:Home"
                                  "FriendlyName"="Ma page d'accueil"

                                  »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
                                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                  o4Patch
                                  Credits: Malware Analysis & Diagnostic
                                  Code: S!Ri

                                  »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                  IEDFix
                                  Credits: Malware Analysis & Diagnostic
                                  Code: S!Ri

                                  »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
                                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                  Agent.OMZ.Fix
                                  Credits: Malware Analysis & Diagnostic
                                  Code: S!Ri

                                  »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                  VACFix
                                  Credits: Malware Analysis & Diagnostic
                                  Code: S!Ri

                                  »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                  404Fix
                                  Credits: Malware Analysis & Diagnostic
                                  Code: S!Ri

                                  »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                  SrchSTS.exe by S!Ri
                                  Search SharedTaskScheduler's .dll

                                  »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                                  "AppInit_DLLs"=""

                                  »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                                  "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"

                                  »»»»»»»»»»»»»»»»»»»»»»»» RK

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                                  "System"=""

                                  »»»»»»»»»»»»»»»»»»»»»»»» DNS

                                  Description: Atheros AR5005G Wireless Network Adapter - Miniport d'ordonnancement de paquets
                                  DNS Server Search Order: 192.168.1.1

                                  HKLM\SYSTEM\CCS\Services\Tcpip\..\{1D4845FE-B96E-45E7-84E9-00C1F82D7EC2}: DhcpNameServer=192.168.1.1
                                  HKLM\SYSTEM\CS1\Services\Tcpip\..\{1D4845FE-B96E-45E7-84E9-00C1F82D7EC2}: DhcpNameServer=192.168.1.1
                                  HKLM\SYSTEM\CS2\Services\Tcpip\..\{1D4845FE-B96E-45E7-84E9-00C1F82D7EC2}: DhcpNameServer=192.168.1.1
                                  HKLM\SYSTEM\CS3\Services\Tcpip\..\{1D4845FE-B96E-45E7-84E9-00C1F82D7EC2}: DhcpNameServer=192.168.1.1
                                  HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                                  HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                                  HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                                  HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                                  »»»»»»»»»»»»»»»»»»»»»»»» Fin
                                  0
                              2. salu help jai le meme probleme que toi dit moi comment m en debarrassé de perso.security center merci
                                0
                                • 1
                                • 2