Supprimer pro antispyware 2009

Résolu
Bonjour,

Mon PC est infecté par pro antispyware 2009. Je n'arrive pas à m'en débarrasser, pourriez-vous m'aider ? Je pensais pourtant être bien sécurisé avec AVAST et AVG antispyware mais non. Aidez-moi.
Configuration: Windows XP

15 réponses

Résumé de la discussion

Un PC équipé de Windows XP est infecté par Pro Antispyware 2009 et les antivirus habituels (AVG et Avast) semblent insuffisants pour l’enlever. Plusieurs interventions techniques ont été tentées, notamment le mode sans échec, des outils comme ComboFix, SmitFraudFix et HijackThis, et une suppression des éléments malveillants dans les fichiers et le registre. Les rapports et scans révèlent des éléments suspects, dont des services et fichiers associés à TDSSserv et Catchme, des entrées de démarrage malicieuses et des restes dans le registre. En contexte, le fil illustre une approche progressive combinant outils de suppression et nettoyage des traces, avec une relance du système de restauration à vérifier et des rapports qui guident les étapes suivantes.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Salut !!

    commence par faire ceci stp :

    Option 1 - Recherche :

    ▶ télécharge smitfraudfix et enregistre le sur le bureau

    ▶ Ensuite double clique sur smitfraudfix puis exécuter

    ▶ Sélectionner 1 pour créer un rapport des fichiers responsables de l'infection.

    (attention : N utilises pas l option 2 si je ne te l ai pas demandé !!)

    ▶ copier/coller le rapport dans la réponse.

    Voici un tutoriel sonore et animé en cas de problème d'utilisation

    (Attention : "process.exe", un composant de l'outil, est détecté par certains antivirus comme étant un "RiskTool".
    Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains,
    cet utilitaire pourrait arrêter des logiciels de sécurité.)
    0
    1. Salut,

      Voici une copie du rapport que vous m'avez demandé :

      SmitFraudFix v2.374

      Rapport fait à 17:19:05,25, 11/11/2008
      Executé à partir de C:\Documents and Settings\Compaq_Propri‚taire\Bureau\SmitfraudFix
      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
      Le type du système de fichiers est
      Fix executé en mode normal

      »»»»»»»»»»»»»»»»»»»»»»»» Process

      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\a-squared Free\a2service.exe
      C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
      C:\windows\system\hpsysdrv.exe
      C:\HP\KBD\KBD.EXE
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\WINDOWS\AGRSMMSG.exe
      C:\WINDOWS\ALCXMNTR.EXE
      C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
      C:\Program Files\Hercules\Hercules DualPix HD Webcam\CamService.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\WINDOWS\System32\regsvr32.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\proas2009.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      C:\Program Files\ArcSoft\PhotoImpression 5\PI Monitor.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
      c:\documents and settings\compaq_propriétaire\local settings\application data\smgay.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\WINDOWS\system32\cmd.exe

      »»»»»»»»»»»»»»»»»»»»»»»» hosts

      »»»»»»»»»»»»»»»»»»»»»»»» C:\

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

      C:\WINDOWS\privacy_danger PRESENT !
      C:\WINDOWS\rvoelbxt.exe PRESENT !

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

      C:\WINDOWS\system32\tdssservers.dat détecté, utilisez un scanner de Rootkit
      C:\WINDOWS\system32\tdssadw.dll détecté, utilisez un scanner de Rootkit
      C:\WINDOWS\system32\tdssinit.dll détecté, utilisez un scanner de Rootkit
      C:\WINDOWS\system32\tdssl.dll détecté, utilisez un scanner de Rootkit
      C:\WINDOWS\system32\tdsslog.dll détecté, utilisez un scanner de Rootkit
      C:\WINDOWS\system32\tdssmain.dll détecté, utilisez un scanner de Rootkit
      C:\WINDOWS\system32\drivers\tdssserv.sys détecté, utilisez un scanner de Rootkit

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Compaq_Propri‚taire

      »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Compaq_Propri‚taire\Application Data

      »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

      »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\COMPAQ~1\Favoris

      »»»»»»»»»»»»»»»»»»»»»»»» Bureau

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

      »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

      »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
      "Source"="About:Home"
      "SubscribedURL"="About:Home"
      "FriendlyName"="Ma page d'accueil"

      »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      o4Patch
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      IEDFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» VACFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      VACFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      404Fix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      "AppInit_DLLs"=""

      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
      "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
      "System"=""

      »»»»»»»»»»»»»»»»»»»»»»»» RK

      »»»»»»»»»»»»»»»»»»»»»»»» DNS

      Description: SiS 900-Based PCI Fast Ethernet Adapter - Miniport d'ordonnancement de paquets
      DNS Server Search Order: 192.168.1.1

      HKLM\SYSTEM\CCS\Services\Tcpip\..\{61621FA0-7B3B-4FD1-97BB-D3CC189C56B0}: DhcpNameServer=192.168.1.1
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{61621FA0-7B3B-4FD1-97BB-D3CC189C56B0}: DhcpNameServer=192.168.1.1
      HKLM\SYSTEM\CS3\Services\Tcpip\..\{61621FA0-7B3B-4FD1-97BB-D3CC189C56B0}: DhcpNameServer=192.168.1.1
      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
      HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

      »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

      »»»»»»»»»»»»»»»»»»»»»»»» Fin

      J'espère que cela vous permettra de m'aider à supprimer Pro Antispyware 2009 qui envahit mon PC;

      Merci d'avance.

      A+
      0
  2. hello
    tu sais charger ça soit directement soit ici sur télécharcher
    fait un update scanne ton pc et corrige ce qu'il te propose
    http://www.malwarebytes.org/mbam/program/mbam-setup.exe
    0
    1. Contributeur sécurité
      non pas malwarebytes tout de suite !!!
      0
      1. Contributeur sécurité
        ok maintenant fais ceci stp :

        Option 2 - Nettoyage :

        ▶ redémarre le PC en mode sans échec

        ▶ Double cliquer sur smitfraudfix

        ▶ Sélectionner 2 pour supprimer les fichiers responsables de l'infection.

        ▶ A la question Voulez-vous nettoyer le registre ? répondre O (oui) afin de débloquer le fond d'écran et supprimer les clés de démarrage automatique de l'infection.

        Le fix déterminera si le fichier wininet.dll est infecté. A la question Corriger le fichier infecté ? répondre O (oui) pour remplacer le fichier corrompu.

        ▶ Enregistre le rapport sur ton bureau

        ▶ Redémarrer en mode normal et poster le rapport.
        0
        1. Salut c'est encore moi,

          J'ai sélectionné le "mode sans échec" mais mon pc redémarre windows XP normalement. J'ai refait la manip à plusieurs reprises et toujours la même chose. Alors j'ai procédé quand même à l'option 2 - Nettoyage mais je n'ai eu que la première question et non la seconde. L'alerte virus a disparu du bas de l'écran mais le vilain Pro Antispyware 2009 est toujours présent. Voici le rapport :

          SmitFraudFix v2.374

          Rapport fait à 22:01:36,03, 12/11/2008
          Executé à partir de C:\Documents and Settings\Compaq_Propri‚taire\Bureau\SmitfraudFix
          OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
          Le type du système de fichiers est
          Fix executé en mode normal

          »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          SrchSTS.exe by S!Ri
          Search SharedTaskScheduler's .dll

          »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

          »»»»»»»»»»»»»»»»»»»»»»»» hosts

          127.0.0.1 localhost

          »»»»»»»»»»»»»»»»»»»»»»»» VACFix

          VACFix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

          S!Ri's WS2Fix: LSP not Found.

          »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

          GenericRenosFix by S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

          »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

          IEDFix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

          404Fix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» RK

          »»»»»»»»»»»»»»»»»»»»»»»» DNS

          Description: SiS 900-Based PCI Fast Ethernet Adapter - Miniport d'ordonnancement de paquets
          DNS Server Search Order: 192.168.1.1

          HKLM\SYSTEM\CCS\Services\Tcpip\..\{61621FA0-7B3B-4FD1-97BB-D3CC189C56B0}: DhcpNameServer=192.168.1.1
          HKLM\SYSTEM\CS1\Services\Tcpip\..\{61621FA0-7B3B-4FD1-97BB-D3CC189C56B0}: DhcpNameServer=192.168.1.1
          HKLM\SYSTEM\CS3\Services\Tcpip\..\{61621FA0-7B3B-4FD1-97BB-D3CC189C56B0}: DhcpNameServer=192.168.1.1
          HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
          HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
          HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

          »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

          »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
          "System"=""

          »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

          Nettoyage terminé.

          »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          SrchSTS.exe by S!Ri
          Search SharedTaskScheduler's .dll

          »»»»»»»»»»»»»»»»»»»»»»»» Fin

          Je précise qu'après le redémarrage de mon PC un message d'erreur de microsoft est apparu.

          Je suis complètement dépassée... Y-a-t-il une solution à mon problème ?
          0
      2. Contributeur sécurité
        Salut !!

        ▶ Télécharge Combofix de sUBs

        ▶ et enregistre le sur le Bureau.

        ▶ désactive tes protections et ferme toutes tes applications(antivirus, parefeu, garde en temps réel de l'antispyware)

        Voici le tutoriel officiel de Bleeping Computer pour savoir l utiliser :

        https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

        ensuite envois le rapport et refais un nouveau rapport hijackthis stp
        0
        1. Désolé mais c'est quoi un rapport hijackthis stp.
          0
      3. Contributeur sécurité
        après avoir fait combofix, fais ceci stp : (dsl je pensais te l avoir déjà demandé)

        ▶ Fais un rapport hijackthis pour que je puisse vérifier les infections de ton pc stp

        ▶ Télécharge hijackthis et enregistre le fichier d'installation sur ton bureau.

        ▶ Ensuite double-cliques sur le fichier d'installation puis sur "exécuter".

        ▶ Cliques sur "Install" en vérifiant que le chemin d'installation est bien dans tes programmes et puis sur "I Accept".

        ▶ Cliques sur "Do a system scan and save a logfile".

        ▶ Laisse l'analyse se terminer jusqu'à l'apparition du rapport dans le bloc note.

        ▶ Ensuite fais un copié/collé du rapport dans ta prochaine réponse sur le forum

        Comment copier/coller le rapport :

        Quand tu as le rapport à l écran, tu fais ctrl A pour "sélectionner tout" puis ctrl C pour "copier".

        ensuite tu viens sur le forum pour me répondre et tu fais ctrl V pour "coller" le rapport.
        0
        1. J'ai un problème je n'arrive pas à ouvrir le lien pour télécharger combofix. Alors je suis allée le récupérer sur un site mais je n'ai pas le manuel d'utilisation. Qu'est ce que je fais ?
          0
      4. Contributeur sécurité
        Où l as tu téléchargé ??
        0
        1. J'espère que le lien est sure... je vais me coucher car je me lève tôt pour le taf. Bonne nuit A+
          0
      5. Contributeur sécurité
        je préfère être sure que tu ai la dernière version...

        Supprime celui que tu as téléchargé et télécharge celui ci sur le bureau :

        https://www.mediafire.com/?sharekey=424caed9c295f93dab1eab3e9fa335caa6e1b15c2cf8802a

        désactive ton antivirus en faisant un clic droit sur son icone dans la barre des tâches en bas à droite et sélectionne "désactiver" ou "quitter".

        Ensuite lance combofix et poste son rapport stp
        0
        1. Salut,

          J'ai passé combofix donc voici le rapport :

          ComboFix 08-11-11.01 - Compaq_Propriétaire 2008-11-13 13:22:15.1 - NTFSx86
          Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.233 [GMT 1:00]
          Commutateurs utilisés :: c:\documents and settings\Compaq_Propriétaire\Bureau\WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
          .

          (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
          .

          c:\documents and settings\Compaq_Propriétaire\Local Settings\Application Data\smgay.dat
          c:\documents and settings\Compaq_Propriétaire\Local Settings\Application Data\smgay.exe
          c:\documents and settings\Compaq_Propriétaire\Local Settings\Application Data\smgay_nav.dat
          c:\documents and settings\Compaq_Propriétaire\Local Settings\Application Data\smgay_navps.dat
          c:\windows\eskd.exe
          c:\windows\system32\drivers\TDSSserv.sys
          c:\windows\system32\nvs2.inf
          c:\windows\system32\TDSSadw.dll
          c:\windows\system32\TDSSerrors.log
          c:\windows\system32\tdssinit.dll
          c:\windows\system32\tdssl.dll
          c:\windows\system32\TDSSlog.dll
          c:\windows\system32\tdssmain.dll
          c:\windows\system32\tdssserf.dll
          c:\windows\system32\tdssserf1.dll
          c:\windows\system32\TDSSservers.dat
          c:\windows\system32\windows_update.exe
          D:\Autorun.inf

          .
          ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
          .

          -------\Service_TDSSSERV
          -------\Legacy_TDSSSERV

          ((((((((((((((((((((((((((((( Fichiers créés du 2008-10-13 au 2008-11-13 ))))))))))))))))))))))))))))))))))))
          .

          2008-11-12 22:01 . 2007-09-05 23:22 289,144 --a------ c:\windows\system32\VCCLSID.exe
          2008-11-12 22:01 . 2006-04-27 16:49 288,417 --a------ c:\windows\system32\SrchSTS.exe
          2008-11-12 22:01 . 2008-10-01 14:51 87,552 --a------ c:\windows\system32\VACFix.exe
          2008-11-12 22:01 . 2008-10-10 07:58 82,944 --a------ c:\windows\system32\o4Patch.exe
          2008-11-12 22:01 . 2008-05-18 20:40 82,944 --a------ c:\windows\system32\IEDFix.exe
          2008-11-12 22:01 . 2008-10-10 07:58 82,944 --a------ c:\windows\system32\IEDFix.C.exe
          2008-11-12 22:01 . 2008-08-18 11:19 82,432 --a------ c:\windows\system32\404Fix.exe
          2008-11-12 22:01 . 2003-06-05 20:13 53,248 --a------ c:\windows\system32\Process.exe
          2008-11-12 22:01 . 2004-07-31 17:50 51,200 --a------ c:\windows\system32\dumphive.exe
          2008-11-12 22:01 . 2007-10-03 23:36 25,600 --a------ c:\windows\system32\WS2Fix.exe
          2008-11-12 21:57 . 2008-11-12 22:20 90,112 --a------ c:\windows\DUMP2c40.tmp
          2008-11-12 21:57 . 2008-11-12 21:58 90,112 --a------ c:\windows\DUMP2c01.tmp
          2008-11-12 21:57 . 2008-11-12 22:20 90,112 --a------ c:\windows\DUMP1e55.tmp
          2008-11-11 17:19 . 2008-11-12 22:02 4,078 --a------ c:\windows\system32\tmp.reg
          2008-11-05 22:20 . 2008-11-05 22:20 <REP> d-------- c:\program files\Enigma Software Group
          2008-11-01 11:00 . 2008-11-01 11:00 178,176 --a------ c:\windows\system32\bjiacmuomz.dll
          2008-10-25 15:53 . 2008-10-25 16:50 <REP> d-------- c:\program files\a-squared Free
          2008-10-16 21:31 . 2008-10-16 21:31 127 --a------ c:\windows\system32\MRT.INI
          2008-10-16 21:08 . 2008-10-16 21:08 <REP> d-------- c:\documents and settings\All Users\Application Data\Solt Lake Software
          2008-10-16 21:08 . 2008-11-05 22:17 77,937 --a------ c:\windows\system32\itcerijbjkkynbjvd.exe

          .
          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          2008-10-25 16:14 --------- d-----w c:\program files\Services en ligne
          2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
          2008-09-29 17:39 --------- d-----w c:\program files\Easy Internet signup
          2008-09-15 15:39 1,846,144 ----a-w c:\windows\system32\win32k.sys
          2008-09-04 16:45 1,106,944 ----a-w c:\windows\system32\msxml3.dll
          2008-08-29 17:16 204,800 ----a-w c:\windows\rqbmvpso.dll
          2008-08-20 05:37 663,552 ----a-w c:\windows\system32\wininet.dll
          2008-08-14 13:44 2,182,400 ----a-w c:\windows\system32\ntoskrnl.exe
          2008-08-14 13:44 2,059,776 ----a-w c:\windows\system32\ntkrnlpa.exe
          2007-09-28 19:58 14,528 ----a-w c:\documents and settings\Compaq_Propriétaire\Application Data\GDIPFONTCACHEV1.DAT
          2006-11-18 19:27 784,568 ----a-w c:\program files\install_JPEG_compression.zip
          2006-11-02 17:00 894 ----a-w c:\documents and settings\Compaq_Propriétaire\Application Data\wklnhst.dat
          2006-10-02 13:55 1,493,848 ----a-w c:\program files\ccsetup133.exe
          2006-09-25 17:29 12,023,296 ----a-w c:\program files\setupfre.exe
          2005-12-29 17:57 3,188,836 ----a-w c:\program files\IZArc35.exe
          1995-09-20 13:16 456,976 ----a-w c:\program files\Fichiers communs\dao3032.dll
          2006-04-19 16:25 8,192 --sha-w c:\windows\o2cLicStore.bin
          .

          ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          .
          *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
          REGEDIT4

          [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7BA7DCCC-4F0B-DB30-0DA0-4EB8E4E12924}]
          2008-11-01 11:00 178176 --a------ c:\windows\system32\bjiacmuomz.dll

          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "Acme.PCHButton"="c:\progra~1\HELPAN~1\HPQ\XPXWWPP5\plugin\bin\PCHButton.exe" [2005-01-02 159744]
          "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-17 68856]
          "Pro Antispyware 2009"="c:\documents and settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\proas2009.exe" [2008-10-16 930816]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
          "hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
          "IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-08-20 155648]
          "KBD"="c:\hp\KBD\KBD.EXE" [2003-02-11 61440]
          "ISUSPM Startup"="c:\progra~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe" [2005-02-16 221184]
          "ISUSScheduler"="c:\program files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
          "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2004-06-08 286720]
          "Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-14 233472]
          "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-09-29 4603904]
          "PS2"="c:\windows\system32\ps2.exe" [2003-09-12 98304]
          "LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 253952]
          "HerculesCamService"="c:\program files\Hercules\Hercules DualPix HD Webcam\CamService.exe" [2007-01-17 102400]
          "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-08-10 282624]
          "OpwareSE2"="c:\program files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152]
          "!AVG Anti-Spyware"="c:\program files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 6731312]
          "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
          "fddmzvuzdpwkrke"="c:\windows\system32\bjiacmuomz.dll" [2008-11-01 178176]
          "nwiz"="nwiz.exe" [2004-09-29 c:\windows\system32\nwiz.exe]
          "SiSPower"="SiSPower.dll" [2004-09-24 c:\windows\system32\SiSPower.dll]
          "AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 c:\windows\AGRSMMSG.exe]
          "AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 c:\windows\ALCXMNTR.EXE]

          c:\documents and settings\Compaq_Propri‚taire\Menu D‚marrer\Programmes\D‚marrage\
          wkcalrem.LNK - c:\program files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe [2004-07-12 15360]

          c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
          Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
          Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
          PI Monitor.lnk - c:\program files\ArcSoft\PhotoImpression 5\PI Monitor.exe [2005-04-24 86016]

          [HKEY_LOCAL_MACHINE\software\microsoft\security center]
          "AntiVirusOverride"=dword:00000001

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
          "EnableFirewall"= 0 (0x0)

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
          "%windir%\\system32\\sessmgr.exe"=
          "c:\\Program Files\\iTunes\\iTunes.exe"=
          "c:\\WINDOWS\\system32\\dpvsetup.exe"=
          "c:\\Program Files\\Hercules\\Hercules DualPix HD Webcam\\Station2.exe"=
          "c:\\Program Files\\uTorrent\\uTorrent.exe"=

          R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-07-19 78416]
          R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
          R3 USBSTOR;Pilote de stockage de masse USB;c:\windows\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
          S3 APL531;Hercules Dualpix HD Webcam;c:\windows\system32\Drivers\HDvid.sys [2006-12-08 275072]
          S3 camfilt;camfilt;c:\windows\system32\Drivers\camfilt.sys [2006-11-16 24192]
          S3 usbscan;Pilote de scanneur USB;c:\windows\system32\DRIVERS\usbscan.sys [2004-08-03 15104]

          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1327d854-3913-11dc-9b0b-806d6172696f}]
          \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

          *Newly Created Service* - CATCHME
          *Newly Created Service* - PROCEXP90
          .
          Contenu du dossier 'Tâches planifiées'

          2008-11-13 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
          - c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]

          2008-11-13 c:\windows\Tasks\Symantec NetDetect.job
          - c:\program files\Symantec\LiveUpdate\NDetect.exe []

          2008-11-13 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
          - c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
          .
          - - - - ORPHELINS SUPPRIMES - - - -

          HKCU-Run-MsnMsgr - c:\program files\MSN Messenger\MsnMsgr.Exe
          HKCU-Run-smgay - c:\documents and settings\compaq_propriétaire\local settings\application data\smgay.exe
          HKLM-Run-IS CfgWiz - c:\program files\Fichiers communs\Symantec Shared\cfgwiz.exe
          HKLM-Run-VTTimer - VTTimer.exe

          .
          ------- Examen supplémentaire -------
          .
          R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
          O8 -: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
          O8 -: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
          O8 -: Easy-WebPrint Ajouter à la liste d'impressions - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
          O8 -: Easy-WebPrint Impression rapide - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
          O8 -: Easy-WebPrint Imprimer - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
          O8 -: Easy-WebPrint Prévisualiser - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
          O8 -: Ouvrir dans un nouvel onglet d'arrière-plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?d7a0d0bc48ab4d2d8eef156616907d1c
          O8 -: Ouvrir dans un nouvel onglet de premier plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?d7a0d0bc48ab4d2d8eef156616907d1c
          .

          **************************************************************************

          catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2008-11-13 13:24:16
          Windows 5.1.2600 Service Pack 2 NTFS

          Recherche de processus cachés ...

          Recherche d'éléments en démarrage automatique cachés ...

          Recherche de fichiers cachés ...

          Scan terminé avec succès
          Fichiers cachés: 0

          **************************************************************************

          [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\TDSSserv]
          "imagepath"="\systemroot\system32\drivers\TDSSserv.sys"
          .
          Heure de fin: 2008-11-13 13:24:46
          ComboFix-quarantined-files.txt 2008-11-13 12:24:44

          Avant-CF: 229,400,121,344 octets libres
          Après-CF: 229,413,781,504 octets libres

          175 --- E O F --- 2008-11-12 20:52:55

          J'ai l'impression que Pro Antispyware 2009 a disparu... j'ai réactivé mon anti-virus.
          A+
          0
      6. Contributeur sécurité
        Salut !!

        maintenant fais un rapport hijackthis comme expliqué au message 9 stp
        0
        1. Voici le rapport :

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 13:57:40, on 13/11/2008
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\a-squared Free\a2service.exe
          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
          c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
          C:\WINDOWS\system32\nvsvc32.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\explorer.exe
          C:\Program Files\internet explorer\iexplore.exe
          C:\WINDOWS\System32\regsvr32.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
          O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
          O2 - BHO: mxlivemedia browser enhancer - {7BA7DCCC-4F0B-DB30-0DA0-4EB8E4E12924} - C:\WINDOWS\system32\bjiacmuomz.dll
          O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
          O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
          O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
          O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
          O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
          O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
          O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
          O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
          O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
          O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
          O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
          O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
          O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
          O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
          O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
          O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
          O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
          O4 - HKLM\..\Run: [HerculesCamService] C:\Program Files\Hercules\Hercules DualPix HD Webcam\CamService.exe
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
          O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\Run: [fddmzvuzdpwkrke] C:\WINDOWS\System32\regsvr32.exe /s "C:\WINDOWS\system32\bjiacmuomz.dll"
          O4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\HELPAN~1\HPQ\XPXWWPP5\plugin\bin\PCHButton.exe
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [Pro Antispyware 2009] "C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\proas2009.exe" /autorun
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - Startup: wkcalrem.LNK = C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe
          O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
          O4 - Global Startup: PI Monitor.lnk = C:\Program Files\ArcSoft\PhotoImpression 5\PI Monitor.exe
          O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
          O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
          O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
          O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
          O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
          O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
          O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?d7a0d0bc48ab4d2d8eef156616907d1c
          O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?d7a0d0bc48ab4d2d8eef156616907d1c
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
          O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
          0
      7. Contributeur sécurité
        Je vois que tu as avast comme antivirus... Non ??

        maintenant fais ceci stp :

        ▶ Télécharge malwarebyte's anti-malware

        ▶ Voici un tutoriel pour t'aider à l'utiliser.

        ▶ Fais la mise à jour du logiciel (elle se fait normalement à l'installation)

        ▶ Lance une analyse complète en cliquant sur "Exécuter un examen complet"

        ▶ Sélectionnes les disques que tu veux analyser et cliques sur "Lancer l'examen"

        ▶ L'analyse peut durer un bon moment.....

        ▶ Une fois l'analyse terminée, cliques sur "OK" puis sur "Afficher les résultats"

        ▶ Vérifies que tout est bien coché et cliques sur "Supprimer la sélection" => et ensuite sur "OK"

        ▶ Un rapport va s'ouvrir dans le bloc note... Fais un copié/collé du rapport dans ta prochaine réponse sur le forum

        * Il se pourrait que certains fichiers devront être supprimés au redémarrage du PC... Faites le en cliquant sur "oui" à la question posée

        Et ensuite refais un nouveau rapport hijackthis stp
        0
        1. Help, help... je crois que j'ai fait une bêtise... j'ai réinstallé AVAST 4.8 par clubic et voilà que pro antispyware 2009 est revenu... j'ai de nouveau repassé combofix mais il est toujours là... qu'est-ce que je fais ? Désolée pour ma bêtise mais je ne sais plus comment faire.
          0
      8. Contributeur sécurité
        Fais malwarebytes comme je t ai demandé stp
        0
        1. Voici le rapport de malwarebytes :

          Malwarebytes' Anti-Malware 1.30
          Version de la base de données: 1306
          Windows 5.1.2600 Service Pack 2

          13/11/2008 15:41:33
          mbam-log-2008-11-13 (15-41-33).txt

          Type de recherche: Examen complet (C:\|D:\|)
          Eléments examinés: 110337
          Temps écoulé: 48 minute(s), 45 second(s)

          Processus mémoire infecté(s): 0
          Module(s) mémoire infecté(s): 0
          Clé(s) du Registre infectée(s): 4
          Valeur(s) du Registre infectée(s): 1
          Elément(s) de données du Registre infecté(s): 0
          Dossier(s) infecté(s): 6
          Fichier(s) infecté(s): 32

          Processus mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Module(s) mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Clé(s) du Registre infectée(s):
          HKEY_CLASSES_ROOT\CLSID\{c9c57833-caa6-4b82-ab0d-7256ec8eabe1} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
          HKEY_CLASSES_ROOT\qalkfxor.bpws (Trojan.FakeAlert) -> Quarantined and deleted successfully.
          HKEY_CLASSES_ROOT\qalkfxor.toolbar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
          HKEY_CURRENT_USER\SOFTWARE\Solt Lake Software (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.

          Valeur(s) du Registre infectée(s):
          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\pro antispyware 2009 (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.

          Elément(s) de données du Registre infecté(s):
          (Aucun élément nuisible détecté)

          Dossier(s) infecté(s):
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009 (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\BASE (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\DELETED (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\LOG (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\SAVED (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.

          Fichier(s) infecté(s):
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\proas2009.exe (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\LOG\20081016220847768.log (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\LOG\20081025145017046.log (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\LOG\20081025145457171.log (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\LOG\20081025165003015.log (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\LOG\20081025180332625.log (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\LOG\20081025183906046.log (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\LOG\20081025193114109.log (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\LOG\20081030204254171.log (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\LOG\20081105221615437.log (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\LOG\20081105223826046.log (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\LOG\20081110110406984.log (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\LOG\20081110161510812.log (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\LOG\20081111171626328.log (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\LOG\20081112083826718.log (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\LOG\20081112213020875.log (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\LOG\20081112213309453.log (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\LOG\20081112213452140.log (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\LOG\20081112213930781.log (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\LOG\20081112214859078.log (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\LOG\20081112215354546.log (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\LOG\20081112220002218.log (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\LOG\20081112220642265.log (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\LOG\20081112221242781.log (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\LOG\20081112221417046.log (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\LOG\20081112221604437.log (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\LOG\20081112221745781.log (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\LOG\20081112222330984.log (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\LOG\20081113122017296.log (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\LOG\20081113142348375.log (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\LOG\20081113144812515.log (Rogue.ProAntispyware2009) -> Quarantined and deleted successfully.
          C:\WINDOWS\rqbmvpso.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.

          et le rapport d'hijackthis :

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 15:48:00, on 13/11/2008
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\a-squared Free\a2service.exe
          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
          c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
          C:\WINDOWS\system32\nvsvc32.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
          C:\windows\system\hpsysdrv.exe
          C:\HP\KBD\KBD.EXE
          C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\WINDOWS\AGRSMMSG.exe
          C:\WINDOWS\system32\rundll32.exe
          C:\Program Files\iPod\bin\iPodService.exe
          C:\WINDOWS\ALCXMNTR.EXE
          C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
          C:\Program Files\Hercules\Hercules DualPix HD Webcam\CamService.exe
          C:\Program Files\QuickTime\qttask.exe
          C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
          C:\WINDOWS\System32\regsvr32.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
          C:\Program Files\ArcSoft\PhotoImpression 5\PI Monitor.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
          O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
          O2 - BHO: mxlivemedia browser enhancer - {7BA7DCCC-4F0B-DB30-0DA0-4EB8E4E12924} - C:\WINDOWS\system32\bjiacmuomz.dll
          O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
          O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
          O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
          O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
          O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
          O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
          O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
          O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
          O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
          O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
          O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
          O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
          O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
          O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
          O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
          O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
          O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
          O4 - HKLM\..\Run: [HerculesCamService] C:\Program Files\Hercules\Hercules DualPix HD Webcam\CamService.exe
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
          O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
          O4 - HKLM\..\Run: [fddmzvuzdpwkrke] C:\WINDOWS\System32\regsvr32.exe /s "C:\WINDOWS\system32\bjiacmuomz.dll"
          O4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\HELPAN~1\HPQ\XPXWWPP5\plugin\bin\PCHButton.exe
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - Startup: wkcalrem.LNK = C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe
          O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
          O4 - Global Startup: PI Monitor.lnk = C:\Program Files\ArcSoft\PhotoImpression 5\PI Monitor.exe
          O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
          O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
          O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
          O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
          O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
          O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
          O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?d7a0d0bc48ab4d2d8eef156616907d1c
          O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?d7a0d0bc48ab4d2d8eef156616907d1c
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
          O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
          O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
          0
      9. Contributeur sécurité
        Relance hijackthis en cliquant sur scan only et coches ces lignes stp :

        O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

        puis tu cliques sur fix checked.

        Comme antivirus, télécharge Antivir, il est très éfficace et gratuit.

        Voici un tutoriel pour l'installer et l'utiliser correctement.

        ensuite :

        ▶ Télécharge JavaRa.zip

        ▶ Décompresse le fichier sur ton bureau (clique droit > Extraire tout.)

        ▶ Double-clique sur le répertoire JavaRa obtenu.

        ▶ Puis double-clique sur le fichier JavaRa.exe (le .exe peut ne pas s'afficher)

        ▶ Clique sur Search For Updates.

        ▶ Sélectionne Update Using jucheck.exe puis clique sur Search.

        ▶ Autorise le processus à se connecter s'il te le demande, clique sur Install et suis les instructions d'installation. Cela prendra quelques minutes.

        ▶ Quand l'installation est terminée, revient à l'écran de JavaRa et clique sur Remove Older Versions.

        ▶ Clique sur Oui pour confirmer. L'outil va travailler, clique ensuite sur Ok, puis une deuxième fois sur Ok.

        ▶ Un rapport va s'ouvrir, copie-colle le dans ta prochaine réponse.

        * Note : le rapport se trouve aussi là : ( C:\JavaRa.log )

        ▶ Ferme l'application et dis moi si tu as encore des problèmes.
        0
        1. Voici le rapport de jAVA :

          JavaRa 1.11 Removal Log.

          Report follows after line.

          ------------------------------------

          The JavaRa removal process was started on Thu Nov 13 16:12:17 2008

          Found and removed: C:\Program Files\Java\j2re1.4.2_03

          Found and removed: C:\Program Files\Java\jre1.6.0_03

          Could not delete: C:\Program Files\Java\jre1.6.0_05

          Found and removed: C:\Windows\Installer\{7148F0A8-6813-11D6-A77B-00B0D0142030}

          Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.4

          Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}

          Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}

          Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBB}

          Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBB}

          Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC}

          Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC}

          Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610003

          Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610005

          Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610003

          Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610005

          Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610003

          Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610005

          Found and removed: SOFTWARE\Classes\JavaPlugin.160_03

          Found and removed: SOFTWARE\Classes\JavaPlugin.160_05

          Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_03

          Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_05

          Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_03

          Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_05

          Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}

          Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}

          Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610003

          Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610005

          Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610003

          Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610005

          Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610003

          Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610005

          Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160030}

          Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160050}

          Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7148F0A8-6813-11D6-A77B-00B0D0142030}

          Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}

          Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}

          Found and removed: SOFTWARE\Classes\Installer\Products\8A0F841731866D117AB7000B0D410203

          Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F841731866D117AB7000B0D410203

          Found and removed: SOFTWARE\Classes\JavaPlugin.142_03

          Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.4.2_03

          Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.4.2_03

          Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.4.2_03

          Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}

          Found and removed: Software\Classes\JavaPlugin.142_03

          Found and removed: Software\Classes\JavaPlugin.160_03

          Found and removed: Software\Classes\JavaPlugin.160_05

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

          Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_03\

          Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_05\

          Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_03\bin\

          Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_05\bin\

          Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

          Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

          Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

          Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

          Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

          Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

          Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_03

          Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_05

          Found and removed: Software\JavaSoft\Java2D\1.6.0_03

          Found and removed: Software\JavaSoft\Java Runtime Environment\1.6.0_03

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

          Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

          ------------------------------------

          Finished reporting.

          Apparement tout fonctionne. Si ce n'est l'ouverture de la page d'accueil internet qui est MSN au lieu de GOOGLE. Comment on change ? Merci beaucoup pour ton aide très précieuse. A+
          0
      10. Contributeur sécurité
        tu vas sur internet avec internet explorer ou firefox ??
        0
        1. je vais sur internet avec internet explorer
          0
      11. Contributeur sécurité
        ok...

        -ouvre internet explorer

        -dans la barre du menu, clique sur Outils puis sur Options internet

        -ensuite tu entres http://google.fr dans Page d'accueil

        -ensuite tu applique => OK

        ensuite si tu n as plus de problèmes tu peux faire ceci pour terminer stp :

        Pour supprimer toutes les traces des logiciels qui ont servi à traiter les infections spécifiques :

        ▶ Télécharge Toolscleaner sur ton Bureau

        ▶ Double-clique sur ToolsCleaner2.exe et laisse le travailler
        ▶ Clique sur Recherche et laisse le scan se terminer.
        ▶ Clique sur Suppression pour finaliser.
        ▶ Tu peux, si tu le souhaites, te servir des Options facultatives.
        ▶ Clique sur Quitter, pour que le rapport puisse se créer.
        ▶ Le rapport (TCleaner.txt) se trouve à la racine de votre disque dur (C:\)...colle le dans ta réponse

        Désactive et réactive la Restauration du système :

        Le fait de faire cette manipulation va supprimer tous les virus qui auraient pu se loger dans les
        points de restauration que tu avais créé auparavant.. Il est donc recommandé de la faire :

        1 Dans la barre des tâches de Windows, clique sur Démarrer.

        2 Clique avec le bouton droit de la souris sur Poste de travail puis clique sur Propriétés.

        3 Dans l'onglet Restauration du système, coche "Désactiver la Restauration du système"

        4 Clique sur Appliquer.

        5 Ensuite décoche "Désactiver la restauration du systeme"

        6 clique sur appliquer puis ok

        7 vas créer un point de restauration en cliquant sur démarrer => tous les programmes => accessoires =>

        outils systeme => restauration du systeme => créer un point de restauration => tu mets un nom

        (exemple : après désinfection sur CCM) puis tu valides.

        pour XP : Voici un tutoriel en cas de problèmes.

        Tu peux mettre ton problème résolu !! Comment mettre résolu ??
        0
        1. Voici le rapport Tcleaner :

          [ Rapport ToolsCleaner version 2.2.6 (par A.Rothstein & dj QUIOU) ]

          -->- Recherche:

          C:\Combofix.txt: trouvé !
          C:\Combofix: trouvé !
          C:\Qoobox: trouvé !
          C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
          C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
          C:\Documents and Settings\Compaq_Propriétaire\Bureau\HijackThis.lnk: trouvé !
          C:\Documents and Settings\Compaq_Propriétaire\Bureau\ComboFix.exe: trouvé !
          C:\Documents and Settings\Compaq_Propriétaire\Bureau\HJTInstall.exe: trouvé !
          C:\Documents and Settings\Compaq_Propriétaire\Bureau\SmitFraudFix.exe: trouvé !
          C:\Documents and Settings\Compaq_Propriétaire\Bureau\SmitFraudfix: trouvé !
          C:\Documents and Settings\Compaq_Propriétaire\Mes documents\hijackthis.log: trouvé !
          C:\Documents and Settings\Compaq_Propriétaire\Recent\HijackThis.lnk: trouvé !
          C:\Program Files\Trend Micro\HijackThis: trouvé !
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
          C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !

          ---------------------------------
          -->- Suppression:

          C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
          C:\Documents and Settings\Compaq_Propriétaire\Bureau\HijackThis.lnk: supprimé !
          C:\Documents and Settings\Compaq_Propriétaire\Bureau\ComboFix.exe: ERREUR DE SUPPRESSION !!
          C:\Documents and Settings\Compaq_Propriétaire\Bureau\HJTInstall.exe: supprimé !
          C:\Documents and Settings\Compaq_Propriétaire\Bureau\SmitFraudFix.exe: supprimé !
          C:\Documents and Settings\Compaq_Propriétaire\Recent\HijackThis.lnk: supprimé !
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
          C:\Combofix.txt: supprimé !
          C:\Documents and Settings\Compaq_Propriétaire\Mes documents\hijackthis.log: supprimé !
          C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
          C:\Combofix: supprimé !
          C:\Qoobox: supprimé !
          C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
          C:\Documents and Settings\Compaq_Propriétaire\Bureau\SmitFraudfix: supprimé !
          C:\Program Files\Trend Micro\HijackThis: supprimé !

          Merci beaucoup pour ton aide, c'est vraiment sympa d'aider les personnes comme moi qui ne maîtrise pas trop l'informatique. Encore un grand merci.... Bon courage pour la suite.
          0
      12. Contributeur sécurité
        Mais de rien, je t ai aidé avec plaisir ;-)

        Tu peux supprimer aussi combofix qui est sur ton bureau..

        Fais bien la suite car c est très important !!

        Bonne soirée @+
        0