Virus sur facebook

Bonjour,

Apparemment, j'ai virus sur facebook depuis que j'ai cliqué sur lien nous mettant en garde sur la logiciel sur facebook, fan check photos. Depuis, j'ai régulièrement de problèmes de connexin et les actualités disparaissent.
Pouvez m'aider sur les procédures à entamer pour réparer ce problème.
Merci d'avance
Configuration: Windows Vista Internet Explorer 7.0

6 réponses

  1. Contributeur sécurité
    j'ai dit de faire l'OPTION 2 avec USBfix et aprés l'option 3

    recommence stp
    0
    1. RAPP############################## | UsbFix V6.033 |

      User : Mériem (Administrateurs) # PC-DE-MÉRIEM
      Update on 14/09/2009 by Chiquitine29, C_XX & Chimay8
      Start at: 23:19:40 | 15/09/2009
      Website : http://pagesperso-orange.fr/NosTools/index.html

      Intel(R) Core(TM)2 Duo CPU T5800 @ 2.00GHz
      Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
      Internet Explorer 8.0.6001.18813
      Windows Firewall Status : Enabled

      C:\ -> Disque fixe local # 285,48 Go (222,49 Go free) [OS] # NTFS
      D:\ -> Disque fixe local # 10 Go (724,46 Mo free) [RECOVERY] # NTFS
      E:\ -> Disque CD-ROM # 0 Mo (0 Mo free) [Audio CD] # CDFS
      F:\ -> Disque amovible
      G:\ -> Disque CD-ROM # 10,72 Mo (0 Mo free) [Mobile Partner] # CDFS

      ############################## | Processus actifs |

      C:\Windows\System32\smss.exe
      C:\Windows\system32\csrss.exe
      C:\Windows\system32\wininit.exe
      C:\Windows\system32\csrss.exe
      C:\Windows\system32\services.exe
      C:\Windows\system32\lsass.exe
      C:\Windows\system32\lsm.exe
      C:\Windows\system32\winlogon.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\SLsvc.exe
      C:\Windows\system32\svchost.exe
      C:\Program Files\Dell\DellDock\DockLogin.exe
      C:\Windows\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\Windows\system32\WLANExt.exe
      C:\Windows\System32\spoolsv.exe
      C:\Program Files\Avira\AntiVir Desktop\sched.exe
      C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\aestsrv.exe
      C:\Windows\system32\svchost.exe
      C:\Program Files\Windows Live\Family Safety\fsssvc.exe
      C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
      C:\Windows\system32\svchost.exe
      C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
      C:\Program Files\Dell Support Center\bin\sprtsvc.exe
      C:\Windows\system32\STacSV.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\System32\TUProgSt.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\system32\SearchIndexer.exe
      C:\Windows\system32\DRIVERS\xaudio.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\Windows\system32\Dwm.exe
      C:\Windows\system32\taskeng.exe
      C:\Windows\Explorer.EXE
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Program Files\DellTPad\Apoint.exe
      C:\Windows\OEM02Mon.exe
      C:\Program Files\Dell\DellDock\DellDock.exe
      C:\Windows\System32\igfxpers.exe
      C:\Windows\System32\ico.exe
      C:\Windows\system32\igfxsrvc.exe
      C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
      C:\Windows\System32\WLTRAY.EXE
      C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      C:\Program Files\Dell\MediaDirect\PCMService.exe
      C:\Program Files\Windows Live\Family Safety\fsui.exe
      C:\Program Files\Alwil Software\Avast4\ashDisp.exe
      C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
      C:\Windows\ehome\ehtray.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\DellTPad\ApMsgFwd.exe
      C:\Program Files\DellTPad\HidFind.exe
      C:\Program Files\DellTPad\Apntex.exe
      C:\Windows\system32\wbem\unsecapp.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Program Files\Windows Media Player\wmpnetwk.exe
      C:\Windows\system32\wbem\wmiprvse.exe
      C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
      C:\Program Files\Digital Line Detect\DLG.exe
      C:\Program Files\Dell\QuickSet\quickset.exe
      C:\Program Files\OpenOffice.org 3\program\soffice.exe
      C:\Windows\ehome\ehmsas.exe
      c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
      C:\Windows\system32\conime.exe
      C:\Program Files\OpenOffice.org 3\program\soffice.bin
      C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      C:\Program Files\Windows Live\Contacts\wlcomm.exe
      C:\Windows\system32\WUDFHost.exe
      C:\Program Files\Kit Internet Mobile Bouygues Telecom\Kit Internet Mobile Bouygues Telecom.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Windows\system32\SearchProtocolHost.exe
      C:\Windows\system32\SearchFilterHost.exe
      C:\Windows\system32\wbem\wmiprvse.exe

      ################## | Fichiers # Dossiers infectieux |

      C:\autorun.inf
      D:\autorun.inf
      G:\autorun.inf

      ################## | Registre # Clés Run infectieuses |

      [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe]
      [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableRegedit"
      [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableTaskMgr"
      [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableRegedit"
      [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableRegistryTools"

      ################## | Registre # Mountpoints2 |

      HKCU\..\..\Explorer\MountPoints2\{1f966dfe-5210-11de-8970-002269bff6e1}
      shell\AutoRun\command =F:\AutoRun.exe

      HKCU\..\..\Explorer\MountPoints2\{30cc0ce6-8aa1-11de-880e-002269bff6e1}
      shell\AutoRun\command =F:\AutoRun.exe

      HKCU\..\..\Explorer\MountPoints2\{fedf1e44-52ca-11de-b6de-002269bff6e1}
      shell\AutoRun\command =G:\AutoRun.exe

      ################## | ! Fin du rapport # UsbFix V6.033 ! |

      ORT 1:
      0
      1. RAPP############################## | UsbFix V6.033 |

        User : Mériem (Administrateurs) # PC-DE-MÉRIEM
        Update on 14/09/2009 by Chiquitine29, C_XX & Chimay8
        Start at: 23:19:40 | 15/09/2009
        Website : http://pagesperso-orange.fr/NosTools/index.html

        Intel(R) Core(TM)2 Duo CPU T5800 @ 2.00GHz
        Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
        Internet Explorer 8.0.6001.18813
        Windows Firewall Status : Enabled

        C:\ -> Disque fixe local # 285,48 Go (222,49 Go free) [OS] # NTFS
        D:\ -> Disque fixe local # 10 Go (724,46 Mo free) [RECOVERY] # NTFS
        E:\ -> Disque CD-ROM # 0 Mo (0 Mo free) [Audio CD] # CDFS
        F:\ -> Disque amovible
        G:\ -> Disque CD-ROM # 10,72 Mo (0 Mo free) [Mobile Partner] # CDFS

        ############################## | Processus actifs |

        C:\Windows\System32\smss.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\wininit.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\services.exe
        C:\Windows\system32\lsass.exe
        C:\Windows\system32\lsm.exe
        C:\Windows\system32\winlogon.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\SLsvc.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\Dell\DellDock\DockLogin.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\Windows\system32\WLANExt.exe
        C:\Windows\System32\spoolsv.exe
        C:\Program Files\Avira\AntiVir Desktop\sched.exe
        C:\Program Files\Avira\AntiVir Desktop\avguard.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\aestsrv.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\Windows Live\Family Safety\fsssvc.exe
        C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
        C:\Program Files\Dell Support Center\bin\sprtsvc.exe
        C:\Windows\system32\STacSV.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\TUProgSt.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\SearchIndexer.exe
        C:\Windows\system32\DRIVERS\xaudio.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\Windows\system32\Dwm.exe
        C:\Windows\system32\taskeng.exe
        C:\Windows\Explorer.EXE
        C:\Program Files\Windows Defender\MSASCui.exe
        C:\Program Files\DellTPad\Apoint.exe
        C:\Windows\OEM02Mon.exe
        C:\Program Files\Dell\DellDock\DellDock.exe
        C:\Windows\System32\igfxpers.exe
        C:\Windows\System32\ico.exe
        C:\Windows\system32\igfxsrvc.exe
        C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
        C:\Windows\System32\WLTRAY.EXE
        C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
        C:\Program Files\Dell\MediaDirect\PCMService.exe
        C:\Program Files\Windows Live\Family Safety\fsui.exe
        C:\Program Files\Alwil Software\Avast4\ashDisp.exe
        C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
        C:\Windows\ehome\ehtray.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\DellTPad\ApMsgFwd.exe
        C:\Program Files\DellTPad\HidFind.exe
        C:\Program Files\DellTPad\Apntex.exe
        C:\Windows\system32\wbem\unsecapp.exe
        C:\Program Files\Windows Media Player\wmpnscfg.exe
        C:\Program Files\Windows Media Player\wmpnetwk.exe
        C:\Windows\system32\wbem\wmiprvse.exe
        C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
        C:\Program Files\Digital Line Detect\DLG.exe
        C:\Program Files\Dell\QuickSet\quickset.exe
        C:\Program Files\OpenOffice.org 3\program\soffice.exe
        C:\Windows\ehome\ehmsas.exe
        c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
        C:\Windows\system32\conime.exe
        C:\Program Files\OpenOffice.org 3\program\soffice.bin
        C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
        C:\Program Files\Windows Live\Contacts\wlcomm.exe
        C:\Windows\system32\WUDFHost.exe
        C:\Program Files\Kit Internet Mobile Bouygues Telecom\Kit Internet Mobile Bouygues Telecom.exe
        C:\Program Files\Internet Explorer\IEXPLORE.EXE
        C:\Program Files\Internet Explorer\IEXPLORE.EXE
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
        C:\Program Files\Internet Explorer\IEXPLORE.EXE
        C:\Program Files\Internet Explorer\IEXPLORE.EXE
        C:\Program Files\Internet Explorer\IEXPLORE.EXE
        C:\Windows\system32\SearchProtocolHost.exe
        C:\Windows\system32\SearchFilterHost.exe
        C:\Windows\system32\wbem\wmiprvse.exe

        ################## | Fichiers # Dossiers infectieux |

        C:\autorun.inf
        D:\autorun.inf
        G:\autorun.inf

        ################## | Registre # Clés Run infectieuses |

        [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe]
        [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableRegedit"
        [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableTaskMgr"
        [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableRegedit"
        [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableRegistryTools"

        ################## | Registre # Mountpoints2 |

        HKCU\..\..\Explorer\MountPoints2\{1f966dfe-5210-11de-8970-002269bff6e1}
        shell\AutoRun\command =F:\AutoRun.exe

        HKCU\..\..\Explorer\MountPoints2\{30cc0ce6-8aa1-11de-880e-002269bff6e1}
        shell\AutoRun\command =F:\AutoRun.exe

        HKCU\..\..\Explorer\MountPoints2\{fedf1e44-52ca-11de-b6de-002269bff6e1}
        shell\AutoRun\command =G:\AutoRun.exe

        ################## | ! Fin du rapport # UsbFix V6.033 ! |

        ORT 1:
        0
        1. Contributeur sécurité
          Bonsoir

          desinstalle registryDoktor par le panneau de configuration c'est une arnaque est installe CCleaner a la place
          https://www.malekal.com/tutoriel-ccleaner/
          va dans option/avancé et decoche la 1er case et nettoie plusieurs fois juqu' atrouver 0erreur meme dans le registre

          puis

          * Telecharge UsbFix (de C_XX & Chiquitine29) sur ton bureau
          http://sd-1.archive-host.com/membres/up/127028005715545653/UsbFix.exe
          * Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d'avoir été infectés sans les ouvrir
          * Double clic sur le raccourci UsbFix sur ton bureau, l'installation se fera automatiquement
          * Choisi l'option 2 SUPPRESSION
          * Laisse travailler l'outil
          * Ensuite post le rapport UsbFix.txt qui apparaîtra
          * Note : le rapport UsbFix.txt est sauvegardé a la racine du disque

          * Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
          Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
          Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus

          # :!: UsbFix te proposera d'uploader un dossier compressé à cette adresse : https://www.androidworld.fr/
          # Ce dossier a été créé par UsbFix et est enregistré sur ton bureau.
          # Merci de l'envoyer à l'adresse indiquée afin d'aider l'auteur de UsbFix dans ses recherches.
          # Merci d'avance pour ta contribution !!

          puis

          * Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptibles d'avoir été infectées sans les ouvrir
          * Double clique sur le raccourci UsbFix présent sur ton bureau .
          * Choisis l'option 3 ( Vaccination )
          * Laisse travailler l'outil.
          * Ensuite poste le rapport UsbFix.txt qui apparaîtra.

          * Note : Le rapport UsbFix.txt est sauvegardé à la racine du disque. ( C:\UsbFix.txt )

          ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

          puis

          * Télécharge Malwarebytes
          http://www.malwarebytes.org/mbam/program/mbam-setup.exe
          * Fais la mise à jour du logiciel (elle se fait normalement à l'installation)
          * Lance une analyse complète en cliquant sur "Exécuter un examen complet"
          * Sélectionnes les disques que tu veux analyser et cliques sur "Lancer l'examen"
          * L'analyse peut durer un bon moment.....
          * Une fois l'analyse terminée, cliques sur "OK" puis sur "Afficher les résultats"
          * Vérifies que tout est bien coché et cliques sur "Supprimer la sélection" => et ensuite sur "OK"
          * Un rapport va s'ouvrir dans le bloc note... Fais un copié/collé du rapport dans ta prochaine réponse sur le forum

          * Il se pourrait que certains fichiers devront être supprimés au redémarrage du PC... Faites le en cliquant sur "oui" à la question posée

          POSTE LES RAPPORTS AU FUR ET A MESURE, pas dans un seul message
          0
          1. Logfile of random's system information tool 1.06 (written by random/random)
            Run by Mériem at 2009-09-15 21:53:25
            Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
            System drive C: has 228 GB (78%) free of 292 GB
            Total RAM: 3061 MB (54% free)

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 21:53:49, on 15/09/2009
            Platform: Windows Vista SP1 (WinNT 6.00.1905)
            MSIE: Internet Explorer v8.00 (8.00.6001.18813)
            Boot mode: Normal

            Running processes:
            C:\Windows\system32\Dwm.exe
            C:\Windows\system32\taskeng.exe
            C:\Windows\Explorer.EXE
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\Program Files\DellTPad\Apoint.exe
            C:\Windows\OEM02Mon.exe
            C:\Program Files\Dell\DellDock\DellDock.exe
            C:\Windows\System32\hkcmd.exe
            C:\Windows\System32\igfxpers.exe
            C:\Windows\System32\ico.exe
            C:\Windows\system32\igfxsrvc.exe
            C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
            C:\Windows\System32\WLTRAY.EXE
            C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
            C:\Program Files\Dell\MediaDirect\PCMService.exe
            C:\Program Files\Dell Support Center\bin\sprtcmd.exe
            C:\Program Files\Windows Live\Family Safety\fsui.exe
            C:\Program Files\Alwil Software\Avast4\ashDisp.exe
            C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
            C:\Windows\ehome\ehtray.exe
            C:\Program Files\Windows Live\Messenger\msnmsgr.exe
            C:\Program Files\DellTPad\ApMsgFwd.exe
            C:\Program Files\DellTPad\HidFind.exe
            C:\Program Files\DellTPad\Apntex.exe
            C:\Windows\system32\wbem\unsecapp.exe
            C:\Program Files\Windows Media Player\wmpnscfg.exe
            C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
            C:\Program Files\Digital Line Detect\DLG.exe
            C:\Program Files\Dell\QuickSet\quickset.exe
            C:\Program Files\OpenOffice.org 3\program\soffice.exe
            C:\Windows\ehome\ehmsas.exe
            c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
            C:\Windows\system32\conime.exe
            C:\Program Files\OpenOffice.org 3\program\soffice.bin
            C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
            C:\Program Files\Windows Live\Contacts\wlcomm.exe
            C:\Program Files\Kit Internet Mobile Bouygues Telecom\Kit Internet Mobile Bouygues Telecom.exe
            C:\Program Files\Internet Explorer\IEXPLORE.EXE
            C:\Program Files\Internet Explorer\IEXPLORE.EXE
            C:\Program Files\Internet Explorer\IEXPLORE.EXE
            C:\Program Files\Internet Explorer\IEXPLORE.EXE
            C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
            C:\Program Files\Internet Explorer\IEXPLORE.EXE
            C:\Users\Mériem\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HWBB65KW\RSIT[1].exe
            C:\Program Files\trend micro\Mériem.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
            O1 - Hosts: ::1 localhost
            O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
            O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
            O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
            O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
            O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
            O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
            O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
            O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
            O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
            O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
            O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
            O4 - HKLM\..\Run: [PMX Daemon] ICO.EXE
            O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
            O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
            O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
            O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
            O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
            O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
            O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
            O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
            O4 - HKCU\..\Run: [AROReminder] C:\Program Files\Advanced Registry Optimizer\ARO.exe -rem
            O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
            O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
            O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
            O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
            O4 - Global Startup: BTTray.lnk = ?
            O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
            O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
            O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
            O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
            O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
            O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
            O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
            O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
            O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
            O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
            O13 - Gopher Prefix:
            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
            O17 - HKLM\System\CCS\Services\Tcpip\..\{6E3455B5-7F29-410E-9538-2F496F663C69}: NameServer = 62.201.129.99 62.201.159.99
            O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
            O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
            O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
            O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
            O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
            O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
            O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
            O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
            O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
            O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
            O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
            O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
            O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe
            O23 - Service: @%SystemRoot%\System32\TUProgSt.exe,-1 (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\Windows\System32\TUProgSt.exe
            O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
            0
            1. Contributeur sécurité
              bonjour

              oui on peut t'aider mais "fan check photos" (bon maintenanat tu le sais) c'est un virus alors fait passer le message dans facebook

              Télécharge Random's System Information Tool (RSIT) de Random/Random, et enregistre le sur ton Bureau.
              http://images.malwareremoval.com/random/RSIT.exe
              • Double clique sur RSIT.exe pour lancer l'outil.
              • Clique sur "Continue" à l'écran Disclaimer.
              • Si l'outil HijackThis n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu s'il te le demande) et tu devras accepter la licence.
              • Une fois le scan terminé, deux rapports vont apparaître : poste les dans deux messages séparés stp
              0