Pc infecté

Résolu
Bonjour,

j'ai un souci, j'ai des problème pour aller sur internet et de nombreuses fenetres souvrent en disant par exemple que mon pc a été infecté par un cheval de troie blablabla, voici le rapport navilog
merci d'avance pour votre aide

Search Navipromo version 3.6.0 commencé le 18/09/2008 à 19:46:30,71

!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

Outil exécuté depuis C:\Program Files\navilog1
Session actuelle : "amandine"

Mise à jour le 27.06.2008 à 23h00 par IL-MAFIOSO

Microsoft Windows Vista 6.0.6000
Internet Explorer : 7.0.6000.16711
Système de fichiers : NTFS

Recherche executé en mode normal

*** Recherche Programmes installés ***

*** Recherche dossiers dans "C:\Windows" ***

*** Recherche dossiers dans "C:\Program Files" ***

*** Recherche dossiers dans "C:\ProgramData" ***

*** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

*** Recherche dossiers dans "c:\users\amandine\appdata\roaming\micros~1\windows\startm~1\programs" ***

*** Recherche dossiers dans "C:\Users\amandine\AppData\Local\virtualstore\Program Files" ***

*** Recherche dossiers dans "C:\Users\amandine\AppData\Roaming" ***

*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net

Aucun Fichier trouvé

*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!

* Recherche dans "C:\Windows\system32" *

* Recherche dans "C:\Users\amandine\AppData\Local\Microsoft" *

* Recherche dans "C:\Users\amandine\AppData\Local" *

*** Recherche fichiers ***

*** Recherche clés spécifiques dans le Registre ***

*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)

1)Recherche nouveaux fichiers Instant Access :

2)Recherche Heuristique :

* Dans "C:\Windows\system32" :

* Dans "C:\Users\amandine\AppData\Local\Microsoft" :

* Dans "C:\Users\amandine\AppData\Local" :

3)Recherche Certificats :

Certificat Egroup absent !
Certificat Electronic-Group absent !
Certificat OOO-Favorit absent !
Certificat Sunny-Day-Design-Ltd absent !

4)Recherche fichiers connus :

*** Analyse terminée le 18/09/2008 à 20:03:29,51 ***
Configuration: Windows Vista
Internet Explorer 7.0

12 réponses

  1. c bizarre, voici l rapport hitjackthis
    merci d'avance

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 22:18:00, on 18/09/2008
    Platform: Windows Vista (WinNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.16711)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\ASUS\ASUS Live Update\ALU.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
    C:\Program Files\Nero\Nero 7\InCD\InCD.exe
    C:\Windows\RtHDVCpl.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Windows\ASScrPro.exe
    C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
    C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
    C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\Internet Explorer\ieuser.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Windows\system32\wuauclt.exe
    C:\Windows\system32\rundll32.exe
    C:\Windows\system32\NOTEPAD.EXE
    C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Windows\system32\SearchFilterHost.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://neufportail.fr/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: (no name) - {A73A976E-4A78-4694-BA1A-3002459E1919} - C:\Users\amandine\AppData\Local\Temp\nnNFvUml.dll
    O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
    O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe
    O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe
    O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
    O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
    O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
    O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\mljJdaby.dll,#1
    O4 - HKLM\..\Run: [BM47bf75e3] Rundll32.exe "C:\Users\amandine\AppData\Local\Temp\uptiahnn.dll",s
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\amandine\AppData\Local\Temp\nnNFvUml.dll,c
    O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\amandine\AppData\Local\Temp\mljgGXQI.dll,#1
    O4 - HKCU\..\Run: [BM47bf75e3] Rundll32.exe "C:\Users\amandine\AppData\Local\Temp\fkfwkopv.dll",s
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O13 - Gopher Prefix:
    O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
    O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
    O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
    O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
    O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
    0
    1. j'espère que c va donner quelquechose, un sit X vient de s'ouvrir seul !!!
      0
      1. voici le rapport combo fix

        ComboFix 08-09-16.05 - amandine 2008-09-18 22:33:15.1 - NTFSx86
        Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.1152 [GMT 2:00]
        Lancé depuis: C:\Users\amandine\Downloads\ComboFix.exe
        * Un nouveau point de restauration a été créé
        .

        (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
        .

        C:\Users\amandine\AppData\Local\Temp\fkfwkopv.dll
        C:\Users\amandine\AppData\Local\Temp\nnNFvUml.dll
        C:\Windows\system32\hgGwwtsR.dll
        C:\Windows\system32\mljJdaby.dll
        C:\Windows\system32\wvUnOEwv.dll

        .
        ((((((((((((((((((((((((((((( Fichiers cr‚‚s du 2008-08-18 au 2008-09-18 ))))))))))))))))))))))))))))))))))))
        .

        Pas de nouveau fichier cr‚‚ dans ce laps de temps

        .
        (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
        .
        2008-09-18 20:17 --------- d-----w C:\Program Files\Trend Micro
        2008-09-18 18:05 --------- d-----w C:\Program Files\Navilog1
        2008-09-17 22:29 --------- d-----w C:\Users\amandine\AppData\Roaming\LimeWire
        2008-09-12 11:04 --------- d-----w C:\ProgramData\Microsoft Help
        2008-09-09 12:51 --------- d-----w C:\Users\amandine\AppData\Roaming\vlc
        2008-09-09 12:42 --------- d-----w C:\Program Files\VideoLAN
        2008-09-09 12:31 --------- d-----w C:\Program Files\DivX
        2008-09-09 12:31 --------- d-----w C:\Program Files\Common Files\PX Storage Engine
        2008-09-09 12:30 --------- d-----w C:\Program Files\AVIcodec
        2008-09-09 12:22 --------- d-----w C:\Program Files\VistaCodecPack
        2008-09-09 12:20 --------- d-----w C:\ProgramData\VistaCodecs
        2008-09-09 12:08 --------- d-----w C:\Users\amandine\AppData\Roaming\DivX
        2008-08-23 11:23 --------- d-----w C:\ProgramData\NOS
        2008-08-23 11:23 --------- d-----w C:\Program Files\NOS
        2008-08-23 09:10 --------- d-----w C:\Program Files\Common Files\Adobe
        2008-08-18 10:51 --------- d-----w C:\Program Files\Windows Mail
        2008-08-06 20:02 --------- d-----w C:\Program Files\IKEA HomePlanner
        2008-08-06 20:01 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
        2008-07-31 03:34 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
        2008-07-31 03:34 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
        2008-07-31 03:34 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
        2008-07-31 03:34 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
        2008-07-30 23:32 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
        2008-07-18 22:31 --------- d-----w C:\Program Files\CCleaner
        2008-07-18 18:47 691 ----a-w C:\Users\amandine\AppData\Roaming\GetValue.vbs
        2008-07-18 18:47 35 ----a-w C:\Users\amandine\AppData\Roaming\SetValue.bat
        2008-07-09 21:08 174 --sha-w C:\Program Files\desktop.ini
        2008-06-27 03:54 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
        2008-03-21 13:51 99,864 ----a-w C:\Users\amandine\AppData\Roaming\GDIPFONTCACHEV1.DAT
        .

        ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
        .
        .
        *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
        REGEDIT4

        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-03-28 1232896]
        "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
        "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-11-22 630784]
        "NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-26 161328]
        "InCD"="C:\Program Files\Nero\Nero 7\InCD\InCD.exe" [2007-03-26 1057328]
        "StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
        "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-01 857648]
        "ASUS Screen Saver Protector"="C:\Windows\ASScrPro.exe" [2007-11-06 33136]
        "ASUS Camera ScreenSaver"="C:\Windows\ASScrProlog.exe" [2007-11-06 37232]
        "BitDefender Antiphishing Helper"="C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe" [2007-10-09 61440]
        "BDAgent"="C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe" [2008-09-16 368640]
        "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 144784]
        "SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-09-28 185896]
        "OpwareSE4"="C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-10-11 75304]
        "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
        "RtHDVCpl"="RtHDVCpl.exe" [2007-02-15 C:\Windows\RtHDVCpl.exe]

        C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
        Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]

        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
        "msacm.divxa32"= divxa32.acm

        [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
        "DisableMonitoring"=dword:00000001

        [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
        "DisableMonitoring"=dword:00000001

        [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
        "DisableMonitoring"=dword:00000001

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
        "EnableFirewall"= 0 (0x0)

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
        "{7D7C206B-263C-4CAE-B956-4B50DB853DD9}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
        "{CC1479EA-E4CB-40BA-ACC9-E15B51CBF07A}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
        "EnableFirewall"= 0 (0x0)

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
        "DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
        "EnableFirewall"= 0 (0x0)

        R0 AtiPcie;ATI PCI Express (3GIO) Filter;C:\Windows\system32\DRIVERS\AtiPcie.sys [2006-10-30 8192]
        R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-07-21 2920448]
        R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;C:\Windows\system32\DRIVERS\bdfndisf.sys [2008-06-26 86792]

        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
        bthsvcs REG_MULTI_SZ BthServ
        bdx REG_MULTI_SZ scan
        .
        Contenu du dossier 'Tƒches planifi‚es'
        .
        - - - - ORPHELINS SUPPRIMES - - - -

        BHO-{A73A976E-4A78-4694-BA1A-3002459E1919} - C:\Users\amandine\AppData\Local\Temp\nnNFvUml.dll
        HKLM-Run-MSServer - C:\Windows\system32\mljJdaby.dll
        ShellExecuteHooks-{07846E47-47CE-4C7C-989A-9A8380F3BD91} - C:\Windows\system32\mljJdaby.dll

        .
        ------- Examen suppl‚mentaire -------
        .
        R0 -: HKCU-Main,Start Page = hxxp://www.neufportail.fr/
        O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
        O8 -: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
        .

        **************************************************************************

        catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2008-09-18 22:40:45
        Windows 6.0.6000 NTFS

        Recherche de processus cach‚s ...

        Recherche d'‚l‚ments en d‚marrage automatique cach‚s ...

        Recherche de fichiers cach‚s ...

        C:\Users\amandine\AppData\Roaming\Microsoft\Windows\Cookies\amandine@live[1].txt 335 bytes

        Scan termin‚ avec succŠs
        Fichiers cach‚s: 1

        **************************************************************************
        .
        ------------------------ Autres processus actifs ------------------------
        .
        C:\Windows\System32\Ati2evxx.exe
        C:\Windows\System32\audiodg.exe
        C:\Windows\System32\Ati2evxx.exe
        C:\Program Files\ATK Hotkey\ASLDRSrv.exe
        C:\Program Files\ATK Hotkey\HControl.exe
        C:\Program Files\ATKOSD2\ATKOSD2.exe
        C:\Program Files\ASUS\Splendid\ACMON.exe
        C:\Program Files\P4G\BatteryLife.exe
        C:\Windows\System32\ACEngSvr.exe
        C:\Program Files\ATK Hotkey\ATKOSD.exe
        C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
        C:\Program Files\Common Files\LightScribe\LSSrvc.exe
        C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
        C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
        C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
        C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
        C:\Windows\System32\conime.exe
        C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
        C:\Program Files\Windows Media Player\wmpnetwk.exe
        C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
        C:\Windows\System32\wbem\WMIADAP.exe
        C:\Windows\servicing\TrustedInstaller.exe
        .
        **************************************************************************
        .
        Heure de fin: 2008-09-18 22:46:35 - La machine a red‚marr‚
        ComboFix-quarantined-files.txt 2008-09-18 20:46:09

        Avant-CF: Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
        AprŠs-CF: 30,373,568,512 octets libres

        157 --- E O F --- 2008-09-18 18:28:07

        j'espère que tout est réglé
        merci
        0
        1. voici le rapport log
          Logfile of random's system information tool 1.02 (written by random/random)
          Run by amandine at 2008-09-18 23:09:46
          Microsoft® Windows Vista™ Édition Familiale Premium
          System drive C: has 30 GB (43%) free of 69 GB
          Total RAM: 1919 MB (60% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 23:09:54, on 18/09/2008
          Platform: Windows Vista (WinNT 6.00.1904)
          MSIE: Internet Explorer v7.00 (7.00.6000.16711)
          Boot mode: Normal

          Running processes:
          C:\Windows\system32\Dwm.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\system32\conime.exe
          C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
          C:\Program Files\Nero\Nero 7\InCD\InCD.exe
          C:\Windows\RtHDVCpl.exe
          C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\Windows\ASScrPro.exe
          C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
          C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
          C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe
          C:\Program Files\Windows Sidebar\sidebar.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\Windows Media Player\wmpnscfg.exe
          C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
          C:\Windows\system32\wuauclt.exe
          C:\Windows\Explorer.exe
          C:\Windows\system32\notepad.exe
          C:\Program Files\Internet Explorer\ieuser.exe
          C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
          C:\Windows\system32\SearchFilterHost.exe
          C:\Users\amandine\Downloads\RSIT.exe
          C:\Program Files\Trend Micro\HijackThis\amandine.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://neufportail.fr/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
          O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
          O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
          O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe
          O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe
          O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
          O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
          O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
          O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
          O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
          O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
          O13 - Gopher Prefix:
          O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
          O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
          O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
          O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
          O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
          O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
          O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
          O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
          O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
          0
          1. voici le rapport malewarebytes

            Malwarebytes' Anti-Malware 1.28
            Version de la base de données: 1134
            Windows 6.0.6000

            18/09/2008 23:46:54
            mbam-log-2008-09-18 (23-46-54).txt

            Type de recherche: Examen complet (C:\|D:\|)
            Eléments examinés: 126912
            Temps écoulé: 22 minute(s), 53 second(s)

            Processus mémoire infecté(s): 0
            Module(s) mémoire infecté(s): 0
            Clé(s) du Registre infectée(s): 0
            Valeur(s) du Registre infectée(s): 0
            Elément(s) de données du Registre infecté(s): 0
            Dossier(s) infecté(s): 0
            Fichier(s) infecté(s): 1

            Processus mémoire infecté(s):
            (Aucun élément nuisible détecté)

            Module(s) mémoire infecté(s):
            (Aucun élément nuisible détecté)

            Clé(s) du Registre infectée(s):
            (Aucun élément nuisible détecté)

            Valeur(s) du Registre infectée(s):
            (Aucun élément nuisible détecté)

            Elément(s) de données du Registre infecté(s):
            (Aucun élément nuisible détecté)

            Dossier(s) infecté(s):
            (Aucun élément nuisible détecté)

            Fichier(s) infecté(s):
            C:\Users\amandine\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\644148W0\Codec[1].exe (Trojan.Dropper) -> Quarantined and deleted successfully.

            et voici le rapport hitjackthis

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 23:09:54, on 18/09/2008
            Platform: Windows Vista (WinNT 6.00.1904)
            MSIE: Internet Explorer v7.00 (7.00.6000.16711)
            Boot mode: Normal

            Running processes:
            C:\Windows\system32\Dwm.exe
            C:\Windows\system32\taskeng.exe
            C:\Windows\system32\conime.exe
            C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
            C:\Program Files\Nero\Nero 7\InCD\InCD.exe
            C:\Windows\RtHDVCpl.exe
            C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            C:\Windows\ASScrPro.exe
            C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
            C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
            C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe
            C:\Program Files\Windows Sidebar\sidebar.exe
            C:\Program Files\Windows Live\Messenger\msnmsgr.exe
            C:\Program Files\Windows Media Player\wmpnscfg.exe
            C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
            C:\Windows\system32\wuauclt.exe
            C:\Windows\Explorer.exe
            C:\Windows\system32\notepad.exe
            C:\Program Files\Internet Explorer\ieuser.exe
            C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
            C:\Windows\system32\SearchFilterHost.exe
            C:\Users\amandine\Downloads\RSIT.exe
            C:\Program Files\Trend Micro\HijackThis\amandine.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://neufportail.fr/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
            O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
            O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
            O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
            O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
            O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
            O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe
            O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe
            O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
            O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
            O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
            O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
            O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
            O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
            O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
            O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
            O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
            O13 - Gopher Prefix:
            O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
            O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
            O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
            O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
            O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
            O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
            O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
            O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
            O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
            O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
            0
            1. non aucun soucis
              en tout as merci a vous tous sur ce forume ca fait deux fois que vous me sauvez la mise lol
              merci s'il y a d'autre choses à faire dites moi sinon je met résolu
              encore merci
              0
              1. Contributeur
                Bonsoir
                ton rapport ne montre rien d'infectieux

                poste un rapport HijackThis

                Télécharge sur le Bureau HijackThis

                http://download.hijackthis.eu/HJTInstall.exe

                = Double-clique sur dessus pour l'installer
                = Clique sur Do a system scan and save the log
                = Colle le rapport
                si problème voir l'aide
                http://www.swl1f.net/viewtopic.php?f=14&t=153&p=1100#p1100
                http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm

                @+
                -1
                1. Contributeur
                  Pourquoi est-ce bizarre
                  vu ce que montre ton rapport je dirais que c'est normal

                  Ton rapport HijackThis montre plusieurs infections

                  Télécharge combofix.exe (par sUBs) et sauvegarde le sur ton bureau.
                  http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                  * Déconnecte toi d'internet et ferme toutes tes applications.
                  * Désactive tes protections (antivirus, parefeu,antispyware) provisoirement et seulement le temps de l'utilisation de ComboFix,
                  * Double-clic sur combofix.exe, il est possible que ton parefeu te demande si tu acceptes ou non l'accès de nircmd.cfexe à la zone sûre: accepte.
                  * /!\ Ne touche à rien tant que le scan n'est pas terminé.Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne /!\
                  * Attends que Combofix ait terminé, un rapport sera créé.
                  * réactive ton parefeu, ton antivirus, la garde de ton antispyware
                  * copie/colle le rapport, le rapport se trouve dans : C:Combofix.txt
                  * Réactive tes protections en temps réel, Antivirus, Antispywares, avant de te reconnecter à internet.

                  -1
                  1. Contributeur
                    Malheuresement quand on ce fait infecté ça ne ce rèpare pas en deux coup de baguette magique :(
                    Mais j'espère que ça ne sera pas trop long ;)

                    pour la suite

                    Télécharge Random's System Information Tool (RSIT) par random/random et sauvegarde-le sur ton Bureau.
                    http://images.malwareremoval.com/random/RSIT.exe
                    * Double-clique sur RSIT.exe afin de lancer RSIT.
                    * Clique sur Continue à l'écran Disclaimer.
                    * Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.
                    * Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

                    --> Poste le contenu de log.txt (<<qui sera affiché) ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

                    Note : Les deux rapports sont également sauvegardés %systemroot%\rsit
                    -1
                    1. Contributeur
                      très bien

                      Télécharge malwarebytes
                      http://www.malwarebytes.org/mbam/program/mbam-setup.exe
                      Une aide pour l'installation
                      http://www.swl1f.net/viewtopic.php?f=14&t=68

                      => Installe le
                      => Ensuite va en mode sans echec

                      Relance le Pc et tapote la touche F8 ( ou F5 pour certains) , jusqu’à l’apparition des inscriptions avec choix de démarrage
                      Avec les touches « flèches », sélectionne Mode sans échec ==> entrée ==>nom utilisateur habituel

                      => Lance malwarebytes
                      => Coche "Executer un examen complet"
                      => Si tu es en présence d'une infection à la fin de l'examen clique sur "ok"
                      => Clique sur Supprimer la sélection
                      => Pour poster le rapport Clique sur l'onglet Rapports/Logs, sélectionne celui t'intéresse et clique sur Ouvrir
                      => Fait copier coller et poste le rapport

                      --------------------------

                      ensuite

                      * Télécharge CCleaner
                      https://filehippo.com/download_ccleaner/
                      => Aide toi de ce tuto pour l'utiliser
                      http://www.swl1f.net/viewtopic.php?f=14&t=69

                      --------------------------

                      Ensuite refais un nouveau HijackThis

                      @+
                      -1
                      1. Contributeur
                        Bon très bien ton rapport est propre as tu encore des soucis ?
                        -1
                        1. Contributeur
                          oui autes choses :)

                          bonne lecture

                          Télécharge ATF Cleaner par Atribune. <== Tu pourras garder ce logiciel pour une utilisation régulière.
                          http://www.atribune.org/ccount/click.php?id=1

                          Double-clique ATF-Cleaner.exe afin de lancer le programme.
                          Sous l'onglet Main, choisis : Select All
                          Clique sur le bouton Empty Selected

                          Si tu utilises le navigateur Firefox :

                          Clique Firefox au haut et choisis : Select All
                          Clique le bouton Empty Selected
                          NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.

                          Si tu utilises le navigateur Opera :


                          Clique Opera au haut et choisis : Select All
                          Clique le bouton Empty Selected
                          NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.

                          Clique Exit, du menu principal, afin de fermer le programme.
                          Pour obtenir du Support technique, double-clique l'adresse électronique située au bas de chacun des menus.

                          ensuite ce logiciel va t'aider a supprimer les outils utiliser

                          Ferme toutes les applications en cours, puis télécharge ToolsCleaner2 sur ton Bureau.
                          http://pc-system.fr/

                          Double clique sur ToolsCleaner2.exe >
                          puis Recherche
                          et sur Suppression
                          Note : ton bureau va disparaître, c'est normal. S'il n'apparaît pas à la fin du scan, fais la manip suivante :

                          CTRL+ALT+SUPP
                          pour ouvrir le Gestionnaire des tâches.
                          Puis rends toi à l'onglet "Processus". Clique en haut à gauche sur Fichiers et choisis "Exécuter"

                          Tape explorer.exe et valide. Cela fera re-apparaître le Bureau

                          ensuite fait ceci (IMPORTANT)

                          * Désactivation :

                          Cliquer droit sur le "Poste de travail" > Propriétés > onglet "Restauration du système" > cocher la case "Désactiver la Restauration du système sur tous les lecteurs"
                          > Appliquer patiente jusqu a que cela soit marqué "désactivée" puis Ok.

                          * Activation :
                          Suivre le même chemin ; décocher la case "Désactiver la Restauration du système sur tous les lecteurs"
                          > Appliquer attends que cela soit a nouveau sur "surveillance" puis Ok. Redémarrer l'ordinateur..

                          Pense aussi à faire tes mises à jours régulièrement

                          Windows update : ==> ici =>http://www.update.microsoft.com/windowsupdate/v6/default.aspx
                          Java : ==> ici => https://www.java.com/fr/download/

                          Ces mises à jours sont très importantes pour la sécurité de ton PC.

                          N'installe qu'un seul parefeu !!
                          et bien sur qu'un antivirus

                          N'oublie pas de faire régulièrement les mises à jour de tes logiciels avant chaque scan.

                          * Tu peux aussi utiliser ces logiciels de sécurité

                          Malwarebytes => C'est un anti-malwares gratuit et en français, tu devras une fois installer le lancer périodiquement pour contrôler ton PC.
                          Un tuto pour le télécharger et son installation => Ici => http://www.swl1f.net/viewtopic.php?f=14&t=68

                          Spyware Terminator => C'est un anti-spyware gratuit et en français, Il travaillera automatiquement grâce à son module résident, tu pourras le programmer pour effectuer un scan journalier.
                          Un tuto pour le télécharger et son installation => Ici => http://www.swl1f.net/viewtopic.php?f=14&t=66

                          * Ensuite quelques conseils
                          L'infection de ton pc peut se faire de différente façon, voici en quelques lignes plusieurs points à éviter. ==> ici =>http://www.swl1f.net/viewtopic.php?f=14&t=67

                          * le navigateur

                          Essaye le navigateur Firefox plus sur/securisé qu IE
                          Firefox n'utilise pas le dangereux protocole ActiveX
                          * Téléchargement: ==> Firefox => http://www.mozilla-europe.org/fr/products/firefox/
                          * Tutorial pour le sécuriser: ==> ici =>https://forum.zebulon.fr/topic/69628-s%C3%A9curiser-un-peu-plus-firefox/

                          Important
                          Surfez avec les droits administrateurs sur le net te rend vulnérable, il faut donc utiliser un autre compte que celui de l'administrateur


                          * Pour que ton pc retrouve un peu de jeunesse
                          * Pense a lancer une petite défragmentation.
                          * Utilise CCleaner régulièrement.
                          * Gère tes services grâce a ces 2 liens
                          ==> ici => http://speedweb1.free.fr/frames2.php?page=service3 et ==> ici => http://speedweb1.free.fr/frames2.php?page=service4
                          * Utilise Zeb Utility
                          une application ne nécessitant pas d’installation, pour optimiser un poil ton pc. (merci a l ami Zebulon)
                          Téléchargement : ==> ici ==> https://www.zebulon.fr/telechargements/utilitaires/optimisation/zeb-utility.html
                          Tuto : ==> ici => https://www.zebulon.fr/dossiers/autres/58-zebutility.html

                          Et pour finir

                          Dénonce ton infection pour faire condamner les auteurs.

                          Crée un message pour faire avancer les choses sur Malware-Complaints, nous devons être les plus nombreux possibles, alors rends compte de ton infection

                          - Voir les règles du forum : ==> ici => https://malwarecomplaints.info/
                          - Après t'être enregistré à l'aide du bouton en haut se nommant "Register"
                          Si tu as plus de 13 ans, choisir : "I Agree to these terms and am over or exactly 13 years of age"
                          Si tu as moins, clique sur : "I Agree to these terms and am under 13 years of age"

                          Tu as alors sous forme de liste un sujet par type d'infection (Look2Me, Smitfraud, SpywareQuake etc..).

                          * malwarecomplaints => https://malwarecomplaints.info/

                          Si le malware que tu as eu n'apparaît pas dans la liste, ou si tu ne sais pas par quoi tu étais infecté(e), crée un message dans le sujet Autres infections
                          conforme au règle du forum (age, ville, département etc..)

                          Indique aussi le nom du Forum qui t'a aidé

                          * Tuto => http://www.malekal.com/malwarecomplaints.html

                          @+

                          -1