Big virus ,coriace ,au secours

Résolu
Bonjour,
J'ai été victime d'une infection de virus et je ne sais vraiment pas comment le supprimé ni de quels sortes de virus il s'agit.
Une fois connecter a internet des photos se téléchargent son mon bureau ,ensuite des trentaine de fenêtres s'ouvrent, après je reçois des centaines de message d'erreurs ou de probabilité d'infection de mon ordinateur et quand je clique dessus il me redirige vers une page de scan mais quand je clique pour lancer le scan ...Rien a part une autre image que apparait...Des messages d'erreurs ne stoppent pas d'apparaitre m'informant d'un état critique de mon ordi me disant que la ram est saturée et indisponible,qu aucune appli ne peut etre lancer etc etc...Mon ordi surchauffe alors ,et je ne sait plus quoi faire de ces centaine de fenêtre qui s ouvrent a l'infini,je ne peux plus rien faire ma ram est saturé,des que je lance une application elle prends des heures a s'éxecuter même en mode hors ligne mon ordi est lent,internet devient un enfer pour moi,besoin d'aide svp,si quelqu'un a une idée ou un bon programme je prends direct^^.
D'avance merci.

Memoire vive: 1024Mo
DD:250Go
Configuration: Windows Vista Ultimate Edition
Firefox 3.0.1

30 réponses

Résumé de la discussion

Une infection virale provoque des popups intempestifs, des milliers de fenêtres qui s'ouvrent et un ralentissement majeur du système Windows Vista, avec messages d'erreur et surchauffe empêchant toute utilisation normale. Plusieurs conseils essentiels suggèrent de redémarrer, vider la quarantaine et exécuter CCleaner avec des réglages spécifiques, puis de redémarrer et d'obtenir un rapport HijackThis pour identifier les éléments indésirables et démarrer leur suppression. D'autres réponses utiles mentionnent l'analyse des logs avec Malwarebytes Anti-Malware et l'identification d'éléments malveillants tels que Trojan.Vundo et des entrées de démarrage à supprimer pour restaurer les performances. En dernier lieu, certains éléments détectés apparaissent sous forme de services et de DLL autorisés, nécessitant une suppression manuelle et parfois une réinstallation de logiciels sécurisés pour stabiliser l'ordinateur.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    bonjour, pourrais tu mettre un rapport hijackthis merci

    postes un rapport hijackthis

    HijackThis est un outil développé par merijn, capable de détecter les composants ajoutés à votre navigateur, les programmes lancés au démarrage du système, etc. Le programme vous permet de consulter tous les éléments et éventuellement de les retirer de l'ordinateur. HijackThis est, par exemple, en mesure de forcer le changement de la page d'accueil. Cette fonction est particulièrement utile lorsque votre navigateur ne vous permet plus de modifier la page d'accueil car un site se l'est appropriée ! Le logiciel peut également enregistrer des paramètres par défaut et ignorer certains éléments définis.

    télécharge Hijackthis http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis

    .cliques sur download
    .cliques sur download Hijackthis installer
    .enregistres le sur le bureau
    .Tu fermes tout les programmes ouverts y compris le navigateur. sauf ton anti-virus et pare-feux
    .installes le , il va s'installer par défaut dans C:\Program Files\Trend Micro\HijackThis
    .Cliques sur "Do a system scan and save the logfile"
    .Cela va t'ouvrir un bloc note à la fin du scan.
    .Copie son contenu et poste le dans ton prochain message. sinon le rapport est dans C:\Program Files\Trend Micro\HijackThis\ hijackthis "document texte"

    des expliquations en images : http://pagesperso-orange.fr/rginformatique/section%20virus/demohijack.htm
    0
    1. Je telecharge la version1.99 ?Et j'ai lancer un scan en ligne sur panda active scan,je vais donc attendre qu il se termine puis je lance hijickthis^^En esperant que ca marche
      0
      1. Contributeur sécurité
        bonjour, pour hijackthis la vresion 1.99 n'est pas la dernière version prend la version sur le lien que je t'ai mis
        0
        1. quand je vais sur ton lien la page me mets ce-ci : The URI you submitted has disallowed characters.
          0
          1. Contributeur sécurité
            bonjour, désolé j'ai pas remarqué que le lien n'était pas cliquable normalement pas de problème http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis

            le principal c'est d'avoir réussi poste le rapport de malwarbytes
            0
        2. voici un des message tres enervant que je recois :ATTENTION! If your computer is infected, you could suffer data loss, erratic PC behaviour, PC freezes and creahes.

          Detect and remove viruses before they damage your computer!
          Antivirus 2009 will perform a quick and 100% FREE scan of your computer for Viruses, Spyware and Adware.

          Do you want to install Antivirus 2009 to scan your computer for malware now? (Recommended)
          0
          1. Bonjour,est ce que la v la plus recentes est la 2.02 ?
            Merci
            0
            1. Voici le rapport :
              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 13:56:49, on 2/08/2008
              Platform: Windows Vista (WinNT 6.00.1904)
              MSIE: Internet Explorer v7.00 (7.00.6000.16386)
              Boot mode: Normal

              Running processes:
              C:\Windows\system32\Dwm.exe
              D:\Program Files\Alwil Software\Avast4\ashDisp.exe
              D:\Program Files\iTunes\iTunesHelper.exe
              C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
              D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
              C:\Windows\system32\wbem\unsecapp.exe
              D:\Programme\Internet Download Manager\IEMonitor.exe
              D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
              C:\Windows\system32\rundll32.exe
              C:\Windows\system32\rundll32.exe
              C:\Windows\explorer.exe
              C:\Users\J-lian\Desktop\HiJackThis.exe

              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
              R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
              O1 - Hosts: ::1 localhost
              O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - D:\Programme\Internet Download Manager\IDMIECC.dll
              O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
              O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~2\SPYBOT~1\SDHelper.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
              O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
              O4 - HKLM\..\Run: [avast!] D:\PROGRA~2\ALWILS~1\Avast4\ashDisp.exe
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
              O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
              O4 - HKLM\..\Run: [\Win666A.exe] C:\Windows\system32\Win666A.exe
              O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
              O4 - HKCU\..\Run: [StartCCC] D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
              O4 - HKCU\..\Run: [\Win666A.exe] C:\Windows\system32\Win666A.exe
              O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\J-lian\AppData\Local\Temp\qoMfdbyV.dll,#1
              O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\J-lian\AppData\Local\Temp\ddcDwxvW.dll,c
              O4 - HKCU\..\Run: [50a5917f] rundll32.exe "C:\Users\J-lian\AppData\Local\Temp\mjshhfjg.dll",b
              O4 - HKCU\..\Run: [IDMan] D:\Programme\Internet Download Manager\IDMan.exe /onboot
              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
              O8 - Extra context menu item: Download all links with IDM - D:\Programme\Internet Download Manager\IEGetAll.htm
              O8 - Extra context menu item: Download FLV video content with IDM - D:\Programme\Internet Download Manager\IEGetVL.htm
              O8 - Extra context menu item: Download with IDM - D:\Programme\Internet Download Manager\IEExt.htm
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~2\MICROS~2\OFFICE11\EXCEL.EXE/3000
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~2\Java\JRE16~2.0_0\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~2\Java\JRE16~2.0_0\bin\ssv.dll
              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
              O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~2\SPYBOT~1\SDHelper.dll
              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~2\SPYBOT~1\SDHelper.dll
              O10 - Broken Internet access because of LSP provider 'c:\windows\system32\pnrpnsp.dll' missing
              O13 - Gopher Prefix:
              O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
              O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
              O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - D:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
              O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
              O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
              O23 - Service: avast! Antivirus - ALWIL Software - D:\Program Files\Alwil Software\Avast4\ashServ.exe
              O23 - Service: avast! Mail Scanner - ALWIL Software - D:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              O23 - Service: avast! Web Scanner - ALWIL Software - D:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
              O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
              O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
              O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
              O23 - Service: SmartLinkService (SLService) - Unknown owner - slserv.exe (file missing)
              O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
              O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
              0
              1. Aidez moi plz,le scan en ligne a dtecté 10 virus,32 fichiers suspect,7fichier vulnerable,mais je ne peut rien faire car il faut payer pour les suprimmer,et je ne comprend rien a ce rapport besoin d aide plz
                0
                1. Contributeur sécurité
                  bonjour, passes malwarebytes en mode sans echec et cliques bien sur supprimer la sélection en fin de scan et poste le rapport, avecun nouveau hijackthis merci

                  Télécharge Malwarebytes' Anti-Malware: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

                  . sur la page cliques sur Télécharger Malwarebyte's Anti-Malware
                  . enregistres le sur le bureau
                  . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
                  . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
                  . si le pare-feu demande l'autorisation de se connecter pour malwarebytes, acceptes
                  . Une fois la mise à jour terminée,fermes Malwarebytes
                  . redemarres en mode sans échec pour savoir comment au cas ou tu ne saurrais pas regarde plus bas
                  . une fois en mode sans echec tu double-cliques sur l'icône de malwarebytes
                  . une fois ouvert rend-toi dans l'onglet, Recherche
                  . Sélectionnes Exécuter un examen complet
                  . Cliques sur Rechercher
                  . Le scan démarre.
                  . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
                  . Cliques sur Ok pour poursuivre.
                  . Si des malwares ont été détectés, cliques sur Afficher les résultats
                  . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
                  . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
                  . redemarre le pc
                  . une fois redémarré en mode normal double-cliques sur malwarebytes
                  . rends toi dans l'onglet rapport/log
                  . tu cliques dessus pour l'afficher une fois affiché
                  . tu cliques sur edition en haut du boc notes,et puis sur sélectionner tous
                  . tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
                  . tu cliques droit dans le cadre de la reponse et coller

                  Si tu as besoin d'aide regarde ce tutoriel :
                  https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

                  (attention : pas de connexion possible en mode sans échec , donc copies ou imprimes bien la manipe pour éviter les erreurs ...)

                  pour redémarrer en mode sans échec : /!\ Ne jamais démarrer en mode sans échec via MSCONFIG /!\

                  demarrer sans echec sous vista

                  .cliques sur démarrer
                  .sur panneau de configuration
                  .sur outils d'administration
                  .sur configuration système
                  .sur le message cliques sur continuer
                  .sur la nouvel fenêtre choisir démarrage en mode diagnostic
                  .puis cliques sur appliquer et OK
                  .sur la demande sur redémarrer

                  une fois redémarrer en mode diagnostic fais ce que tu as à faire et puis pour revenir au mode normal tu refais la même chose

                  démarrer/panneau de configuration/ outils d'administration
                  et faire le chois démarrage normal/ appliquer et OK /redémarrer

                  tutoriel en images si tu as un problème:

                  http://bibou0007.com/windows-vista-f102/tutorial-mode-sans-echec-vista-methode-automatique-t1396.htm

                  ======================================================================

                  postes un nouveau hijackthis

                  .
                  0
                  1. >Bonjours,merci de ton aide,hélas il m'est apparut un message d'erreur me disant que certains virus n'avait pas pu etre supprimé et maitenant quand mon ordi demarre des message apparaissent me mettant :error run application dll. application manquante. Voici le rapport
                    Malwarebytes' Anti-Malware 1.24
                    Version de la base de données: 1017
                    Windows 6.0.6000

                    21:23:46 2/08/2008
                    mbam-log-8-2-2008 (21-23-46).txt

                    Type de recherche: Examen complet (C:\|D:\|)
                    Eléments examinés: 121169
                    Temps écoulé: 40 minute(s), 57 second(s)

                    Processus mémoire infecté(s): 0
                    Module(s) mémoire infecté(s): 1
                    Clé(s) du Registre infectée(s): 3
                    Valeur(s) du Registre infectée(s): 2
                    Elément(s) de données du Registre infecté(s): 0
                    Dossier(s) infecté(s): 3
                    Fichier(s) infecté(s): 34

                    Processus mémoire infecté(s):
                    (Aucun élément nuisible détecté)

                    Module(s) mémoire infecté(s):
                    C:\Users\J-lian\AppData\Local\Temp\ddcDwxvW.dll (Trojan.Vundo) -> Delete on reboot.

                    Clé(s) du Registre infectée(s):
                    HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
                    HKEY_CURRENT_USER\SOFTWARE\Microsoft\MS Juan (Trojan.Vundo) -> Quarantined and deleted successfully.
                    HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.

                    Valeur(s) du Registre infectée(s):
                    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cmds (Trojan.Vundo) -> Delete on reboot.
                    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MSServer (Malware.Trace) -> Delete on reboot.

                    Elément(s) de données du Registre infecté(s):
                    (Aucun élément nuisible détecté)

                    Dossier(s) infecté(s):
                    C:\Program Files\PCHealthCenter (Trojan.Fakealert) -> Quarantined and deleted successfully.
                    C:\Program Files\VAV (Rogue.VistaAntivirus2008) -> Quarantined and deleted successfully.
                    C:\Program Files\AVM (Rogue.AntivirusMaster) -> Quarantined and deleted successfully.

                    Fichier(s) infecté(s):
                    C:\Users\J-lian\AppData\Local\Temp\ddcDwxvW.dll (Trojan.Vundo) -> Delete on reboot.
                    C:\Program Files\PCHealthCenter\5.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
                    C:\Users\J-lian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2DE5C14J\kb456456[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\Users\J-lian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AJWHWUC2\ico[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\Users\J-lian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E6YE3WJM\kb767887[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\Users\J-lian\AppData\Local\Temp\nucxmyqv.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\Users\J-lian\AppData\Local\Temp\lnmrmkjq.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\Users\J-lian\AppData\Local\Temp\mjshhfjg.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\Users\J-lian\AppData\Local\Temp\ymupsgvx.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\Program Files\PCHealthCenter\0.exe (Trojan.Fakealert) -> Quarantined and deleted successfully.
                    C:\Program Files\PCHealthCenter\0.gif (Trojan.Fakealert) -> Quarantined and deleted successfully.
                    C:\Program Files\PCHealthCenter\1.exe (Trojan.Fakealert) -> Quarantined and deleted successfully.
                    C:\Program Files\PCHealthCenter\1.gif (Trojan.Fakealert) -> Quarantined and deleted successfully.
                    C:\Program Files\PCHealthCenter\2.exe (Trojan.Fakealert) -> Quarantined and deleted successfully.
                    C:\Program Files\PCHealthCenter\2.gif (Trojan.Fakealert) -> Quarantined and deleted successfully.
                    C:\Program Files\PCHealthCenter\3.exe (Trojan.Fakealert) -> Quarantined and deleted successfully.
                    C:\Program Files\PCHealthCenter\3.gif (Trojan.Fakealert) -> Quarantined and deleted successfully.
                    C:\Program Files\PCHealthCenter\4.exe (Trojan.Fakealert) -> Quarantined and deleted successfully.
                    C:\Program Files\PCHealthCenter\7.exe (Trojan.Fakealert) -> Quarantined and deleted successfully.
                    C:\Program Files\PCHealthCenter\sc.html (Trojan.Fakealert) -> Quarantined and deleted successfully.
                    C:\Program Files\PCHealthCenter\sex1.ico (Trojan.Fakealert) -> Quarantined and deleted successfully.
                    C:\Program Files\PCHealthCenter\sex2.ico (Trojan.Fakealert) -> Quarantined and deleted successfully.
                    C:\Program Files\VAV\vav.cpl (Rogue.VistaAntivirus2008) -> Quarantined and deleted successfully.
                    C:\Program Files\VAV\vav.exe (Rogue.VistaAntivirus2008) -> Quarantined and deleted successfully.
                    C:\Program Files\VAV\vav.ooo (Rogue.VistaAntivirus2008) -> Quarantined and deleted successfully.
                    C:\Program Files\VAV\vav1.dat (Rogue.VistaAntivirus2008) -> Quarantined and deleted successfully.
                    C:\Program Files\AVM\avm.cpl (Rogue.AntivirusMaster) -> Quarantined and deleted successfully.
                    C:\Program Files\AVM\avm.exe (Rogue.AntivirusMaster) -> Quarantined and deleted successfully.
                    C:\Program Files\AVM\avm.ooo (Rogue.AntivirusMaster) -> Quarantined and deleted successfully.
                    C:\Program Files\AVM\avm1.dat (Rogue.AntivirusMaster) -> Quarantined and deleted successfully.
                    C:\Windows\System32\sex1.ico (Malware.Trace) -> Quarantined and deleted successfully.
                    C:\Windows\System32\sex2.ico (Malware.Trace) -> Quarantined and deleted successfully.
                    C:\Users\J-lian\AppData\Local\Temp\byxXnooN.dll (Malware.Trace) -> Delete on reboot.
                    C:\Users\J-lian\AppData\Local\Temp\s1265.php (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                    0
                    1. Contributeur sécurité
                      bonjour, tu redémarres ton pc si tu ne l'as pas encore fais depuis la fin de l'analyse de malwarebytes, tu vides la quarantaine, et tu passes Ccleaner avec ces réglages la , tu redémarres tu postes un nouveau hijackthis et tu nous dis comment est le pc

                      télécharge Ccleaner à partir de cette adresses

                      https://www.01net.com/outils/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/tele32599.html

                      .enregistres le sur le bureau
                      .double-cliques sur le fichier pour lancer l'installation
                      .sur la fenêtre de l'installation langage bien choisir français et OK
                      .cliques sur suivant
                      .lis la licence et j'accepte
                      .cliques sur suivant
                      .la tu ne gardes de coché que mettre un raccourci sur le bureau et puis contrôler automatiquement les mises à jour de Ccleaner
                      .cliques sur intaller
                      .cliques sur fermer
                      .double-cliques sur l'icône de Ccleaner pour l'ouvrir
                      .une fois ouvert tu cliques sur option et puis avancé
                      .tu décoches effacer uniquement les fichiers, du dossier temp de windows plus vieux que 48 heures
                      .cliques sur nettoyeur
                      .cliques sur windows et dans la colonne avancé
                      .cochesla première case vieilles données du perfetch que celle-la
                      .cliques sur analyse une fois l'analyse terminé
                      .cliques sur lancer le nettoyage et sur la demande de confirmation OK il vas falloir que tu le refasses une autre fois une fois fini vériffis en appuiant de nouveau sur analyse pour être sur qu'il n'y est plus rien
                      .cliques maintenant sur registre et puis sur rechercher les erreurs
                      .laisses tout cochées et cliques sur réparrer les erreurs sélectionnées
                      .il te demande de sauvegarder OUI
                      .tu lui donnes un nom pour pouvoir la retrouver et enregitre
                      .cliques sur corriger toutes les erreurs sélectionnées et sur la demande de confirmation OK
                      .il supprime et fermer tu vériffis en relancant rechercher les erreurs
                      .tu retournes dans option et tu recoches la case effacer uniquement les fichiers, du dossier temp de windows plus vieux que 48 heures et sur nettoyeur, windows sous avancé tu décoches la première case vieilles données du perfetch
                      .tu peux fermer Ccleaner
                      =======================================================================
                      redémarres et fais un nouveau hijackthis
                      0
                      1. Contributeur sécurité
                        bon je croix que c'est pas la peinne que je continu tu as déja suffisament de renseignement sur ton autre sujet si tu est sur plusieurs sujet pour le même problème ne soit pas surpris si tu utilise les outils de l'un et de l'autre d'avoir des problème après car chacun te donne des outils et des procédures propres et pas toujours compatible entre elle alors si d'un coté tu appliques une chose et de l'autre une autre on risque de créer des problèmes @+
                        http://www.commentcamarche.net/forum/affich 7707426 analyse hijackthis j ai des virus
                        0
                        1. Non desolé mais je pensais que tu m'avait abandonné,de plus je n'ai suivit que tes procedure car j'ai voulu suprimer l'autres sujet mais je ne sais pas comment faire alors ne m'en veux pas je suis nouveau,et merci de ton aide car tu explique très bien,alors je te demanderai de ne pas m'en vouloir et de bien vouloir continuer a m expliquer et de m expliquer comment suprimmé l autre sujet.Merci
                          0
                          1. Bonsoir,
                            je fait quoi du fichier de sauvegarde de registre de cccleaner,je l'ai enregistrer sur mon bureai,je te l'envoie ou je peux le supprimer ?
                            Et avec hijickthis est ce que je te renvoie a nouveau le nouveau rapport aussi ?
                            Merci
                            0
                            1. Voici le nouveau rapport,j'ai la possibilité de cocher des case a la fin du scan,dois je ignorer cela,car je ne m'en suis pas occuper ,j'au juste scaner et envoyer le rapport que voici:
                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 22:18:48, on 2/08/2008
                              Platform: Windows Vista (WinNT 6.00.1904)
                              MSIE: Internet Explorer v7.00 (7.00.6000.16386)
                              Boot mode: Normal

                              Running processes:
                              C:\Windows\system32\Dwm.exe
                              C:\Windows\Explorer.EXE
                              D:\Program Files\Alwil Software\Avast4\ashDisp.exe
                              C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                              D:\Program Files\iTunes\iTunesHelper.exe
                              D:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
                              C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                              D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
                              C:\Windows\system32\wbem\unsecapp.exe
                              C:\Program Files\Mozilla Firefox\firefox.exe
                              D:\Programme\Internet Download Manager\IEMonitor.exe
                              D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
                              C:\Users\J-lian\Desktop\HiJackThis.exe

                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                              R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                              O1 - Hosts: ::1 localhost
                              O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - D:\Programme\Internet Download Manager\IDMIECC.dll
                              O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                              O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~2\SPYBOT~1\SDHelper.dll
                              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                              O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                              O4 - HKLM\..\Run: [avast!] D:\PROGRA~2\ALWILS~1\Avast4\ashDisp.exe
                              O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                              O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "D:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                              O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                              O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
                              O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
                              O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
                              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                              O4 - HKCU\..\Run: [StartCCC] D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
                              O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                              O4 - HKCU\..\Run: [IDMan] D:\Programme\Internet Download Manager\IDMan.exe /onboot
                              O4 - HKCU\..\Run: [E06FXLRD_22276578] "D:\Program Files\Microsoft Encarta\Collection Microsoft Encarta 2006 DVD\EDICT.EXE" -m
                              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                              O8 - Extra context menu item: Download all links with IDM - D:\Programme\Internet Download Manager\IEGetAll.htm
                              O8 - Extra context menu item: Download FLV video content with IDM - D:\Programme\Internet Download Manager\IEGetVL.htm
                              O8 - Extra context menu item: Download with IDM - D:\Programme\Internet Download Manager\IEExt.htm
                              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
                              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~2\Java\JRE16~2.0_0\bin\ssv.dll
                              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~2\Java\JRE16~2.0_0\bin\ssv.dll
                              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
                              O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
                              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~2\SPYBOT~1\SDHelper.dll
                              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~2\SPYBOT~1\SDHelper.dll
                              O10 - Broken Internet access because of LSP provider 'c:\windows\system32\pnrpnsp.dll' missing
                              O13 - Gopher Prefix:
                              O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
                              O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                              O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - D:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
                              O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                              O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
                              O23 - Service: avast! Antivirus - ALWIL Software - D:\Program Files\Alwil Software\Avast4\ashServ.exe
                              O23 - Service: avast! Mail Scanner - ALWIL Software - D:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                              O23 - Service: avast! Web Scanner - ALWIL Software - D:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                              O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                              O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                              O23 - Service: JMAN - Unknown owner - C:\Users\J-lian\AppData\Local\Temp\JMAN.exe (file missing)
                              O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                              O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
                              O23 - Service: SmartLinkService (SLService) - Unknown owner - slserv.exe (file missing)
                              O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
                              O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
                              O23 - Service: XEZTTHXJGJKI - Unknown owner - C:\Users\J-lian\AppData\Local\Temp\XEZTTHXJGJKI.exe (file missing)
                              0
                              1. Contributeur sécurité
                                bon consernant la sauvegarde tu la conserves un peut le temps "2 à 3 jours" de voir si il n'y as pas de disfonctionnement suite au passage de ccleaner " perso depuis plus d'un an ça m'est jamais arrivé, mais bon toujours prudence" tu poste le nouveau hijackthis et surtout tu dis comment est le pc

                                SURTOUT NE COCHES aucune case de toi même tu risque de planter le pc
                                0
                                1. J'ai poste le nouveau hijickthis au dessus,j'ai l'impression de ne plus avoir de probleme mais l'ordi me semble tres tres lent,genre 2min juste pour lancer mozilla firefox
                                  0
                                  1. Logfile of Trend Micro HijackThis v2.0.2
                                    Scan saved at 22:32:05, on 2/08/2008
                                    Platform: Windows Vista (WinNT 6.00.1904)
                                    MSIE: Internet Explorer v7.00 (7.00.6000.16386)
                                    Boot mode: Normal

                                    Running processes:
                                    C:\Windows\system32\Dwm.exe
                                    C:\Windows\Explorer.EXE
                                    D:\Program Files\Alwil Software\Avast4\ashDisp.exe
                                    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                                    D:\Program Files\iTunes\iTunesHelper.exe
                                    C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                                    D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
                                    C:\Windows\system32\wbem\unsecapp.exe
                                    C:\Program Files\Mozilla Firefox\firefox.exe
                                    D:\Programme\Internet Download Manager\IEMonitor.exe
                                    D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
                                    C:\Users\J-lian\Desktop\HiJackThis.exe

                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                    O1 - Hosts: ::1 localhost
                                    O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - D:\Programme\Internet Download Manager\IDMIECC.dll
                                    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~2\SPYBOT~1\SDHelper.dll
                                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                                    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                                    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                    O4 - HKLM\..\Run: [avast!] D:\PROGRA~2\ALWILS~1\Avast4\ashDisp.exe
                                    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                                    O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "D:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
                                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                                    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                                    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
                                    O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
                                    O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
                                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                                    O4 - HKCU\..\Run: [StartCCC] D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
                                    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                                    O4 - HKCU\..\Run: [IDMan] D:\Programme\Internet Download Manager\IDMan.exe /onboot
                                    O4 - HKCU\..\Run: [E06FXLRD_22276578] "D:\Program Files\Microsoft Encarta\Collection Microsoft Encarta 2006 DVD\EDICT.EXE" -m
                                    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                                    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                    O8 - Extra context menu item: Download all links with IDM - D:\Programme\Internet Download Manager\IEGetAll.htm
                                    O8 - Extra context menu item: Download FLV video content with IDM - D:\Programme\Internet Download Manager\IEGetVL.htm
                                    O8 - Extra context menu item: Download with IDM - D:\Programme\Internet Download Manager\IEExt.htm
                                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
                                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~2\Java\JRE16~2.0_0\bin\ssv.dll
                                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~2\Java\JRE16~2.0_0\bin\ssv.dll
                                    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                                    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                                    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
                                    O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
                                    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~2\SPYBOT~1\SDHelper.dll
                                    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~2\SPYBOT~1\SDHelper.dll
                                    O10 - Broken Internet access because of LSP provider 'c:\windows\system32\pnrpnsp.dll' missing
                                    O13 - Gopher Prefix:
                                    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
                                    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                                    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - D:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
                                    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
                                    O23 - Service: avast! Antivirus - ALWIL Software - D:\Program Files\Alwil Software\Avast4\ashServ.exe
                                    O23 - Service: avast! Mail Scanner - ALWIL Software - D:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                    O23 - Service: avast! Web Scanner - ALWIL Software - D:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                    O23 - Service: JMAN - Unknown owner - C:\Users\J-lian\AppData\Local\Temp\JMAN.exe (file missing)
                                    O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                                    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
                                    O23 - Service: SmartLinkService (SLService) - Unknown owner - slserv.exe (file missing)
                                    O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
                                    O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
                                    O23 - Service: XEZTTHXJGJKI - Unknown owner - C:\Users\J-lian\AppData\Local\Temp\XEZTTHXJGJKI.exe (file missing)
                                    0
                                    1. Contributeur sécurité
                                      tu relances hijackthis comme expliqué et tu vas Fixer les lignes

                                      .Tu fermes tout les programmes ouverts y compris le navigateur. sauf ton anti-virus et pare-feux
                                      .Lances HijackThis
                                      .Cliques sur "Do a system scan only"
                                      .Tu coches les lignes suivantes :
                                      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                                      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
                                      O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - D:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

                                      .Tu cliques sur "Fixe Checked"
                                      .Tu fermes HijackThis

                                      des expliquations en images : http://pagesperso-orange.fr/rginformatique/section%20virus/demohijack.htm
                                      ======================================================================
                                      Sinon tu as trois anti-spyware " spybot, AVG, ad-aware" c'est deux de trop car un seul anti-spyware en résident sur le même pc, car ça ralenti le pc pour rien c'est pas parce que tu en as plusieurs que tu es mieux protégé par contre tu peux en utiliser un autre à la demande comme malwarebytes qui lui n'est actif que quand tu le lances "toujours faire la mise à jour avant"
                                      0
                                      1. J'ai suprimé avg,spybot et adaware,et j'ai fait la manip de hijackthis il m'a demander confirmation j'ai cliquer sur ok mais apres un message est apparut j'ai cliqué sur ok et un fichier nommé backup est apparut sur mon bureau est ce normal ?
                                        0
                                        • 1
                                        • 2