Pop-ups Antivirus 2009

Résolu
Bonjour,

J'a un problème de pop up qui me propsoent d'installer antivirus 2009 et que j'ai de soi-disant spyware...

vous pouvez m'aider a m'en débarasser?
Configuration: Windows XP
Firefox 3.0.3

16 réponses

  1. Salut,

    Télécharge HijackThis (outils de dignostic) ici :

    -> Fais un clic droit sur un des liens et choisi enregistrer la cible sous .... le bureau
    -> http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe
    -> ftp://ftp.commentcamarche.com/download/HJTInstall.exe

    -> Fais un double-clic sur HJTInstall.exe afin de lancer l'installation

    -> Clique sur Install ensuite sur I Accept

    -> Clique sur Do a scan system and save log file

    -> Le bloc-notes s'ouvrira, fais un copier-coller de tout son contenu ici dans ta prochaine réponse
    -1
    1. ça c'est une pub qui c'est installé sur ton ordi !!
      Retient le nom du logiciel et va dans
      panneau de configuration - programme et fonctionnalités
      tu retrouves le logiciel et tu le désinstalle.
      Comment s'appelle cet antivirus?
      -1
      1. Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 19:22:08, on 15.10.2008
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16735)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
        C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\WINDOWS\system32\IoctlSvc.exe
        C:\WINDOWS\system32\SearchIndexer.exe
        C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
        C:\WINDOWS\system32\wscntfy.exe
        C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Documents and Settings\Samira Sarah\Bureau\HiJackThis.exe

        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
        O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
        O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
        O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
        O9 - Extra button: Statistiques de la protection du trafic Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
        O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
        O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll jajahu.dll
        O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
        O23 - Service: Kaspersky Anti-Virus (avp) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
        O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
        O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
        -1
        1. Télécharge combofix : http://download.bleepingcomputer.com/sUBs/ComboFix.exe

          -> Double clique sur combofix.exe.
          -> Tape sur la touche 1 (Yes) pour démarrer le scan.
          -> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

          NOTE : Le rapport se trouve également ici : C:\Combofix.txt

          Avant d'utiliser ComboFix :

          -> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.

          -> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent géner fortement la procédure de recherche et de nettoyage de l'outil.

          Une fois fait, sur ton bureau double-clic sur Combofix.exe.

          - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

          /!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.

          - En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

          - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

          -> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

          -> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.
          -1
          1. ComboFix 08-10-15.01 - Samira Sarah 2008-10-15 19:30:24.1 - NTFSx86
            Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.190 [GMT 2:00]
            Lancé depuis: C:\Documents and Settings\Samira Sarah\Bureau\ComboFix.exe
            * Un nouveau point de restauration a été créé

            [COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B][/COLOR]
            .

            (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
            .

            C:\WINDOWS\system32\awtqpPfc.dll
            C:\WINDOWS\system32\bhfremjx.exe
            C:\WINDOWS\system32\iigxcupl.dll
            C:\WINDOWS\system32\jajahu.dll
            C:\WINDOWS\system32\ljJASigg.dll
            C:\WINDOWS\system32\lpucxgii.ini
            C:\WINDOWS\system32\nnnljjJa.dll
            C:\WINDOWS\system32\qwdesefo.dll
            C:\WINDOWS\system32\rBdfLRqr.ini
            C:\WINDOWS\system32\rBdfLRqr.ini2
            C:\WINDOWS\system32\rqRLfdBr.dll
            C:\WINDOWS\system32\wrwaqsyx.dll
            C:\WINDOWS\system32\xrscddju.dll
            C:\WINDOWS\system32\xysqawrw.ini

            .
            ((((((((((((((((((((((((((((( Fichiers créés du 2008-09-15 au 2008-10-15 ))))))))))))))))))))))))))))))))))))
            .

            2008-10-15 09:02 . 2008-09-08 12:41 333,824 -----c--- C:\WINDOWS\system32\dllcache\srv.sys
            2008-10-15 08:59 . 2008-09-15 17:26 1,846,528 -----c--- C:\WINDOWS\system32\dllcache\win32k.sys
            2008-10-15 08:58 . 2008-08-14 15:23 2,191,232 -----c--- C:\WINDOWS\system32\dllcache\ntoskrnl.exe
            2008-10-15 08:58 . 2008-08-14 15:23 2,147,328 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
            2008-10-15 08:58 . 2008-08-14 15:23 2,068,096 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
            2008-10-15 08:58 . 2008-08-14 15:23 2,025,984 -----c--- C:\WINDOWS\system32\dllcache\ntkrpamp.exe
            2008-10-11 12:11 . 2008-10-11 12:13 <REP> d-------- C:\Program Files\DivX
            2008-10-10 17:34 . 2008-10-10 17:34 <REP> d-------- C:\Program Files\CCleaner
            2008-10-09 12:37 . 2008-10-09 12:37 <REP> d-------- C:\Documents and Settings\Samira Sarah\Application Data\Youdagames
            2008-10-08 17:21 . 2008-10-10 12:09 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
            2008-10-05 10:35 . 2008-10-05 10:35 <REP> d-------- C:\Program Files\Intuisphere
            2008-10-05 10:16 . 2008-10-05 10:20 <REP> d-------- C:\904381116280ea1ad7
            2008-09-28 15:21 . 2008-09-28 15:21 <REP> d-------- C:\Documents and Settings\Samira Sarah\Application Data\Windows Search
            2008-09-25 12:12 . 2008-09-25 12:12 <REP> d-------- C:\Program Files\MSXML 4.0
            2008-09-24 19:26 . 2008-09-24 19:26 <REP> d-------- C:\Documents and Settings\Samira Sarah\Application Data\Nero
            2008-09-24 19:17 . 2008-09-24 19:17 <REP> d-------- C:\Program Files\Nero
            2008-09-24 19:17 . 2008-09-24 19:23 <REP> d-------- C:\Program Files\Fichiers communs\Nero
            2008-09-24 19:17 . 2008-09-24 19:17 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Nero
            2008-09-24 17:37 . 2008-09-24 17:37 <REP> d-------- C:\Program Files\Microsoft Silverlight
            2008-09-19 16:57 . 2008-09-19 16:57 <REP> d-------- C:\Documents and Settings\Samira Sarah\Application Data\Microsoft Web Folders
            2008-09-18 18:00 . 2008-09-19 16:59 379 --a------ C:\WINDOWS\ODBC.INI
            2008-09-18 17:16 . 2008-09-18 17:16 <REP> d-------- C:\Documents and Settings\Samira Sarah\Application Data\Windows Desktop Search
            2008-09-18 17:15 . 2008-09-18 17:15 <REP> d-------- C:\WINDOWS\system32\GroupPolicy
            2008-09-18 17:15 . 2008-09-18 17:15 <REP> d-------- C:\Program Files\Windows Desktop Search
            2008-09-18 17:13 . 2008-03-07 19:02 192,000 -----c--- C:\WINDOWS\system32\dllcache\offfilt.dll
            2008-09-18 17:13 . 2008-03-07 19:02 98,304 -----c--- C:\WINDOWS\system32\dllcache\nlhtml.dll
            2008-09-18 17:13 . 2008-03-07 19:02 29,696 -----c--- C:\WINDOWS\system32\dllcache\mimefilt.dll
            2008-09-18 16:50 . 2008-09-18 16:53 <REP> d-------- C:\WINDOWS\system32\URTTemp
            2008-09-17 14:58 . 2008-09-17 14:58 <REP> d-------- C:\Program Files\Windows Journal Viewer
            2008-09-16 02:14 . 2008-09-16 02:14 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
            2008-09-16 02:14 . 2008-09-16 02:14 524,288 --a------ C:\WINDOWS\system32\DivXsm.exe
            2008-09-16 02:14 . 2008-09-16 02:14 9,878 --a------ C:\WINDOWS\system32\dsm_fr.qm
            2008-09-16 02:14 . 2008-09-16 02:14 4,816 --a------ C:\WINDOWS\system32\divxsm.tlb
            2008-09-16 02:11 . 2008-09-16 02:11 823,296 --a------ C:\WINDOWS\system32\divx_xx0c.dll
            2008-09-16 02:11 . 2008-09-16 02:11 823,296 --a------ C:\WINDOWS\system32\divx_xx07.dll
            2008-09-16 02:11 . 2008-09-16 02:11 815,104 --a------ C:\WINDOWS\system32\divx_xx0a.dll
            2008-09-16 02:11 . 2008-09-16 02:11 802,816 --a------ C:\WINDOWS\system32\divx_xx11.dll
            2008-09-16 02:11 . 2008-09-16 02:11 683,520 --a------ C:\WINDOWS\system32\DivX.dll
            2008-09-16 02:11 . 2008-09-16 02:11 634,880 --a------ C:\WINDOWS\system32\divxdec.ax
            2008-09-16 02:11 . 2008-09-16 02:11 352,401 --a------ C:\WINDOWS\system32\DivXMedia.ax
            2008-09-16 02:11 . 2008-09-16 02:11 161,096 --a------ C:\WINDOWS\system32\DivXCodecVersionChecker.exe
            2008-09-16 02:11 . 2008-09-16 02:11 12,288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
            2008-09-15 12:43 . 2006-02-20 18:59 85,408 -ra------ C:\WINDOWS\system32\drivers\w810mgmt.sys
            2008-09-15 12:43 . 2006-02-20 18:59 83,344 -ra------ C:\WINDOWS\system32\drivers\w810obex.sys
            2008-09-15 12:42 . 2006-02-20 18:59 94,064 -ra------ C:\WINDOWS\system32\drivers\w810mdm.sys
            2008-09-15 12:42 . 2006-02-20 18:59 8,336 -ra------ C:\WINDOWS\system32\drivers\w810mdfl.sys
            2008-09-15 12:42 . 2006-02-20 18:59 6,176 -ra------ C:\WINDOWS\system32\drivers\w810cmnt.sys
            2008-09-15 12:42 . 2006-02-20 18:59 6,176 -ra------ C:\WINDOWS\system32\drivers\w810cm.sys

            .
            (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
            .
            2008-10-15 17:40 6,476 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
            2008-10-15 17:40 335,904 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
            2008-10-15 17:40 16,296 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
            2008-10-15 17:40 1,813,536 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
            2008-10-15 16:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
            2008-10-15 09:14 --------- d-----w C:\Documents and Settings\Samira Sarah\Application Data\uTorrent
            2008-10-10 15:30 --------- d-----w C:\Program Files\DynGate
            2008-09-23 10:29 --------- d-----w C:\Program Files\Dofus
            2008-09-18 16:02 --------- d-----w C:\Program Files\microsoft frontpage
            2008-09-16 00:14 9,464 ------w C:\WINDOWS\system32\drivers\cdralw2k.sys
            2008-09-16 00:14 9,336 ------w C:\WINDOWS\system32\drivers\cdr4_xp.sys
            2008-09-16 00:14 43,528 ------w C:\WINDOWS\system32\drivers\PxHelp20.sys
            2008-09-14 11:43 --------- d-----w C:\Program Files\uTorrent
            2008-09-14 10:33 --------- d-----w C:\Program Files\InstallShield Installation Information
            2008-09-14 10:23 --------- d-----w C:\Program Files\Veoh Networks
            2008-09-13 16:59 --------- d-----w C:\Program Files\TeamViewer3
            2008-09-13 16:59 --------- d-----w C:\Documents and Settings\Samira Sarah\Application Data\TeamViewer
            2008-09-13 13:47 96,976 ----a-w C:\WINDOWS\system32\drivers\klin.dat
            2008-09-13 13:37 --------- d-----w C:\Program Files\Kaspersky Lab
            2008-09-13 13:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
            2008-09-13 13:12 --------- d-----w C:\Program Files\Lavalys
            2008-09-13 11:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
            2008-09-13 11:23 --------- d-----w C:\Documents and Settings\Samira Sarah\Application Data\InstallShield
            2008-09-13 11:03 --------- d-----w C:\Documents and Settings\Samira Sarah\Application Data\Sony Ericsson
            2008-09-13 07:55 --------- d-----w C:\Program Files\Windows Media Connect 2
            2008-09-13 07:44 --------- d-----w C:\Program Files\Trend Micro
            2008-09-13 07:19 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
            2008-09-13 06:15 --------- d-----w C:\Program Files\Messenger Plus! Live
            2008-09-12 19:17 87,855 ----a-w C:\WINDOWS\system32\drivers\klick.dat
            2008-09-12 18:35 --------- d-----w C:\Program Files\Windows Live
            2008-09-12 18:34 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
            2008-09-12 18:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
            2008-09-12 17:31 --------- d-----w C:\Program Files\Ares
            2008-09-12 17:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\nView_Profiles
            2008-09-12 17:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\NVIDIA
            2008-09-08 10:41 333,824 ----a-w C:\WINDOWS\system32\drivers\srv.sys
            .

            ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
            .
            .
            *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
            REGEDIT4

            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
            "Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [2008-08-28 3660848]
            "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 7700480]
            "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-10-22 86016]
            "NeroFilterCheck"="C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe" [2008-06-19 570664]
            "NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-08 2221352]
            "AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2008-07-29 206088]
            "nwiz"="nwiz.exe" [2006-10-22 C:\WINDOWS\system32\nwiz.exe]

            [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
            "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]

            [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
            "nltide_3"="advpack.dll" [2008-08-26 C:\WINDOWS\system32\advpack.dll]

            C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
            Windows Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]

            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
            "NoDesktopCleanupWizard"= 1 (0x1)

            [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
            "ForceClassicControlPanel"= 1 (0x1)
            "NoSMConfigurePrograms"= 1 (0x1)
            "NoDesktopCleanupWizard"= 1 (0x1)

            [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
            "ForceClassicControlPanel"= 1 (0x1)
            "NoSMConfigurePrograms"= 1 (0x1)
            "NoDesktopCleanupWizard"= 1 (0x1)

            [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
            "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]

            [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
            "DisableMonitoring"=dword:00000001

            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
            "%windir%\\system32\\sessmgr.exe"=
            "C:\\Program Files\\Ares\\Ares.exe"=
            "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
            "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
            "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
            "C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.325\\French\\setup.exe"=
            "C:\\Program Files\\TeamViewer3\\TeamViewer.exe"=
            "C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
            "C:\\Program Files\\uTorrent\\uTorrent.exe"=

            R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [2008-01-29 32784]
            R3 FA312;Pilote de la carte Fast Ethernet FA330/FA312/FA311 NETGEAR;C:\WINDOWS\system32\DRIVERS\FA312nd5.sys [2001-08-17 16074]
            R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2008-04-30 24592]
            S3 MRVW225;802.11g/b Wireless LAN Dirver for Windows XP;C:\WINDOWS\system32\DRIVERS\MRVW225.sys [2007-05-11 299904]
            .
            - - - - ORPHELINS SUPPRIMES - - - -

            BHO-{1e17dc14-a585-4ada-bd64-d526a53c9372} - C:\WINDOWS\system32\jajahu.dll
            BHO-{31CDFCB9-37D6-4C1D-A31D-AA2DD56F637B} - (no file)
            BHO-{6B36C255-28D2-4397-8F9F-AF3505C6FE1F} - C:\WINDOWS\system32\rqRLfdBr.dll
            ShellExecuteHooks-{31CDFCB9-37D6-4C1D-A31D-AA2DD56F637B} - (no file)
            Notify-iifedbxu - iifedbxu.dll

            .
            ------- Examen supplémentaire -------
            .
            FireFox -: Profile - C:\Documents and Settings\Samira Sarah\Application Data\Mozilla\Firefox\Profiles\6qr8sbvf.default\
            FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1757867&SearchSource=3&q=
            FF -: plugin - C:\Program Files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
            .

            **************************************************************************

            catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
            Rootkit scan 2008-10-15 19:42:40
            Windows 5.1.2600 Service Pack 3 NTFS

            Recherche de processus cachés ...

            Recherche d'éléments en démarrage automatique cachés ...

            Recherche de fichiers cachés ...

            Scan terminé avec succès
            Fichiers cachés: 0

            **************************************************************************
            .
            ------------------------ Autres processus actifs ------------------------
            .
            C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
            C:\WINDOWS\system32\nvsvc32.exe
            C:\WINDOWS\system32\IoctlSvc.exe
            C:\WINDOWS\system32\searchindexer.exe
            C:\WINDOWS\system32\wscntfy.exe
            C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
            .
            **************************************************************************
            .
            Heure de fin: 2008-10-15 19:50:03 - La machine a redémarré
            ComboFix-quarantined-files.txt 2008-10-15 17:49:54

            Avant-CF: 35'860'832'256 octets libres
            Après-CF: 35,800,526,848 octets libres

            203 --- E O F --- 2008-10-15 07:30:40
            -1
            1. Telecharge malwarebytes

              Tu l´instale; le programme va se mettre automatiquement a jour.

              Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

              Click maintenant sur l´onglet recherche et coche la case : "executer un examen complet".

              Puis click sur "rechercher".

              Laisse le scanner le pc...

              Si des elements on ete trouvés > click sur supprimer la selection.

              si il t´es demandé de redemarrer > click sur "yes".

              A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.

              Copie et colle le rapport stp.

              PS : les rapport sont aussi rangé dans l onglet rapport/log
              -1
              1. la j'ai pas le temps de faire complète voila la rapide

                Malwarebytes' Anti-Malware 1.28
                Version de la base de données: 1274
                Windows 5.1.2600 Service Pack 3

                15.10.2008 20:33:07
                mbam-log-2008-10-15 (20-33-07).txt

                Type de recherche: Examen rapide
                Eléments examinés: 42524
                Temps écoulé: 7 minute(s), 33 second(s)

                Processus mémoire infecté(s): 0
                Module(s) mémoire infecté(s): 0
                Clé(s) du Registre infectée(s): 0
                Valeur(s) du Registre infectée(s): 0
                Elément(s) de données du Registre infecté(s): 0
                Dossier(s) infecté(s): 0
                Fichier(s) infecté(s): 1

                Processus mémoire infecté(s):
                (Aucun élément nuisible détecté)

                Module(s) mémoire infecté(s):
                (Aucun élément nuisible détecté)

                Clé(s) du Registre infectée(s):
                (Aucun élément nuisible détecté)

                Valeur(s) du Registre infectée(s):
                (Aucun élément nuisible détecté)

                Elément(s) de données du Registre infecté(s):
                (Aucun élément nuisible détecté)

                Dossier(s) infecté(s):
                (Aucun élément nuisible détecté)

                Fichier(s) infecté(s):
                C:\WINDOWS\system32\cmdow.exe (Malware.Tool) -> Quarantined and deleted successfully.
                -1
                1. réouvre malewarebyte
                  va sur quarantaine
                  supprime

                  refais un scan hijackthis , post le rapport et on termine
                  -1
                  1. Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 20:42:02, on 15.10.2008
                    Platform: Windows XP SP3 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v7.00 (7.00.6000.16735)
                    Boot mode: Normal

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
                    C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                    C:\WINDOWS\system32\nvsvc32.exe
                    C:\WINDOWS\system32\IoctlSvc.exe
                    C:\WINDOWS\system32\SearchIndexer.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
                    C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
                    C:\WINDOWS\explorer.exe
                    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
                    C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
                    C:\Program Files\Mozilla Firefox\firefox.exe
                    C:\Documents and Settings\Samira Sarah\Bureau\HiJackThis.exe

                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
                    O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
                    O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
                    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                    O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
                    O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
                    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                    O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE RÉSEAU')
                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                    O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                    O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
                    O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                    O9 - Extra button: Statistiques de la protection du trafic Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
                    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
                    O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
                    O23 - Service: Kaspersky Anti-Virus (avp) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                    O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
                    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                    O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
                    -1
                    1. Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 20:42:02, on 15.10.2008
                      Platform: Windows XP SP3 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v7.00 (7.00.6000.16735)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
                      C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                      C:\WINDOWS\system32\nvsvc32.exe
                      C:\WINDOWS\system32\IoctlSvc.exe
                      C:\WINDOWS\system32\SearchIndexer.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
                      C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
                      C:\WINDOWS\explorer.exe
                      C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
                      C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
                      C:\Program Files\Mozilla Firefox\firefox.exe
                      C:\Documents and Settings\Samira Sarah\Bureau\HiJackThis.exe

                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                      O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
                      O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
                      O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
                      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
                      O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
                      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                      O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE RÉSEAU')
                      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                      O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
                      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                      O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
                      O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                      O9 - Extra button: Statistiques de la protection du trafic Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
                      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
                      O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
                      O23 - Service: Kaspersky Anti-Virus (avp) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                      O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                      O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
                      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                      O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
                      -1
                      1. -> Télécharge Ccleaner (n'installe pas la barre d'outil Yahoo):

                        http://download.piriform.com/ccsetup210.exe

                        https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html

                        -> Tuto : https://www.malekal.com/tutoriel-ccleaner/

                        ensuite :

                        * pour supprimer les outils/fix utilisés :

                        Télécharge ToolsCleaner sur ton bureau.
                        -->
                        http://pc-system.fr/
                        http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner

                        # Clique sur Recherche et laisse le scan agir ...
                        # Clique sur Suppression pour finaliser.
                        # Tu peux, si tu le souhaites, te servir des Options facultatives.
                        # Clique sur Quitter pour obtenir le rapport.
                        # Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

                        Désactive et réactive ta restauration system :

                        (1) Désactiver la Restauration du système

                        cliques sur Démarrer
                        Cliques droit sur Poste de travail
                        cliques sur Propriétés
                        Cliques sur l'onglet Restauration du système
                        Coches Désactiver la Restauration du système sur tous les lecteurs
                        Cliques sur Appliquer, Lorsque le message de confirmation apparaît,
                        cliques sur Oui.
                        Cliques sur OK.

                        (2) Activer la Restauration du système

                        cliques sur Démarrer
                        Cliques droit sur Poste de travail
                        cliques sur Propriétés
                        Cliques sur l'onglet Restauration du système
                        Décoches Désactiver la Restauration du système sur tous les lecteurs
                        Cliques sur Appliquer, Lorsque le message de confirmation apparaît,
                        cliques sur Oui.
                        Cliques sur OK.

                        Tuto xp : http://service1.symantec.com/support/inter/tsgeninfointl.Nsf/fr_docid/20020830101856924

                        -1
                        1. Voila C'est fait.

                          J'ai Déja Ccleaner dans mon pc.

                          il est déja paramétré.
                          -1
                          1. DE rien pas de soucis

                            @++
                            -1