Pc infecté

Bonjour,
mon PC est infecté impossible d'effectuer un scanner jusqu'au bout l'ordi redemarre et d'aller dans certains programmes
merci de m'aider
Anne
Configuration: Windows XP
Firefox 3.0.14

54 réponses

Résumé de la discussion

Le problème central est une infection qui empêche d’effectuer un scanner jusqu’au bout, provoque des redémarrages et empêche l’ouverture de certains programmes sur Windows XP. Plusieurs méthodes et outils ont été évoqués, comme HijackThis pour nettoyer les entrées, RSIT ou ToolsCleaner pour supprimer des traces, et des conseils sur les mises à jour, la restauration et le défragmentage. En cas d’impossibilité de démarrer en mode sans échec, certains participants évoquent le formatage comme solution extrême, tandis que d’autres insistent sur la nécessité d’un nettoyage approfondi et d’un contrôle des programmes au démarrage.

Bobot (l’IA à votre service)
  1. bonjour,
    pimprenelle j'ai essayer rsit mais elle ne pouvait pas l'ouvrir lis ce que j'ai poster avant de poster
    1. Contributeur sécurité
      tu c'est comment faire pour revenir à configuration d'usine avec ton pc.
      1. Contributeur sécurité
        je pense que tu vas devoir formater l'ordi et le remettre en config d'usine.
        1. bonjour,
          oui j'ai pensé le faire pour être plus sûre
          en tout cas merci mille fois de ton aide !
          passe de bonnes fêtes
          Anne
      2. Contributeur sécurité
        As tu réessayé le mode sans échec?
        1. bonjour,
          non toujours pas
        2. je veux dire ça ne marche pas....
      3. Contributeur sécurité
        désolé de mettre autant de temps mais je cherche à résoudre ton problème, voici ce que tu vas essayer de faire :

        désactiver toutes les protections résidentes

        télécharge ceci : https://download.bleepingcomputer.com/sUBs/SafeBootKeyRepair.exe et regarde bien ce qu'il t'ai demandé de faire.
        1. bonjour,

          ci joint le rapport
          Reg export of SafeBoot key after repair:
          ========================

          Windows Registry Editor Version 5.00

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot]
          "AlternateShell"="cmd.exe"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal]

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\AppMgmt]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\AVG Anti-Spyware Driver]
          @="Driver"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\AVG Anti-Spyware Guard]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Base]
          @="Driver Group"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Boot Bus Extender]
          @="Driver Group"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Boot file system]
          @="Driver Group"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\CryptSvc]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\DcomLaunch]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmadmin]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmboot.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmio.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmload.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmserver]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\EventLog]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\File system]
          @="Driver Group"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Filter]
          @="Driver Group"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\HelpSvc]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Netlogon]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\PCI Configuration]
          @="Driver Group"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\PlugPlay]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\PNP Filter]
          @="Driver Group"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Primary disk]
          @="Driver Group"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\RpcSs]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\SCSI Class]
          @="Driver Group"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\sermouse.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\sr.sys]
          @="FSFilter System Recovery"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\SRService]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\System Bus Extender]
          @="Driver Group"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\vds]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\vga.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\vgasave.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\WinMgmt]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}]
          @="Universal Serial Bus controllers"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}]
          @="CD-ROM Drive"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
          @="DiskDrive"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}]
          @="Standard floppy disk controller"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
          @="Hdc"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
          @="Keyboard"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
          @="Mouse"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}]
          @="PCMCIA Adapters"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
          @="SCSIAdapter"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
          @="System"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}]
          @="Floppy disk drive"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
          @="Volume shadow copy"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
          @="Volume"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
          @="Human Interface Devices"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network]

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\AFD]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\AppMgmt]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\AVG Anti-Spyware Driver]
          @="Driver"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\AVG Anti-Spyware Guard]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Base]
          @="Driver Group"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Boot Bus Extender]
          @="Driver Group"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Boot file system]
          @="Driver Group"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Browser]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\CryptSvc]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\DcomLaunch]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Dhcp]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmadmin]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmboot.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmio.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmload.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmserver]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\DnsCache]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\EventLog]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\File system]
          @="Driver Group"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Filter]
          @="Driver Group"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\HelpSvc]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\ip6fw.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\ipnat.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\LanmanServer]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\LanmanWorkstation]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\LmHosts]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Messenger]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NDIS]
          @="Driver Group"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NDIS Wrapper]
          @="Driver Group"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Ndisuio]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetBIOS]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetBIOSGroup]
          @="Driver Group"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetBT]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetDDEGroup]
          @="Driver Group"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Netlogon]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetMan]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Network]
          @="Driver Group"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetworkProvider]
          @="Driver Group"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\nm]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\nm.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NtLmSsp]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PCI Configuration]
          @="Driver Group"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PlugPlay]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PNP Filter]
          @="Driver Group"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PNP_TDI]
          @="Driver Group"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Primary disk]
          @="Driver Group"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdpcdd.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdpdd.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdpwd.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdsessmgr]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\RpcSs]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\SCSI Class]
          @="Driver Group"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\sermouse.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\SharedAccess]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\sr.sys]
          @="FSFilter System Recovery"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\SRService]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Streams Drivers]
          @="Driver Group"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\System Bus Extender]
          @="Driver Group"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Tcpip]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\TDI]
          @="Driver Group"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\tdpipe.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\tdtcp.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\termservice]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\vga.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\vgasave.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\WinMgmt]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\WZCSVC]
          @="Service"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{36FC9E60-C465-11CF-8056-444553540000}]
          @="Universal Serial Bus controllers"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E965-E325-11CE-BFC1-08002BE10318}]
          @="CD-ROM Drive"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}]
          @="DiskDrive"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E969-E325-11CE-BFC1-08002BE10318}]
          @="Standard floppy disk controller"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
          @="Hdc"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
          @="Keyboard"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
          @="Mouse"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}]
          @="Net"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E973-E325-11CE-BFC1-08002BE10318}]
          @="NetClient"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E974-E325-11CE-BFC1-08002BE10318}]
          @="NetService"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}]
          @="NetTrans"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E977-E325-11CE-BFC1-08002BE10318}]
          @="PCMCIA Adapters"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
          @="SCSIAdapter"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
          @="System"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E980-E325-11CE-BFC1-08002BE10318}]
          @="Floppy disk drive"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
          @="Volume"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
          @="Human Interface Devices"

          ========================

          HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver
          HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard
      4. Contributeur sécurité
        et le reste tu là fait?
        1. alors j'ai
          lancer hijackthis
          trace de symantec comment et où regarder ?
          tollscleaner c'est fait
          update checker ok
          ccleaner c'est fait
          restauration ok
          nettoyage ok
          pour la defragmentation je ne peux toujours pas démarrer en mode ss echec
          firefox ok plus les extensions

          j'ai toujours des problèmes pour démarrer
      5. Contributeur sécurité
        On va passer au nettoyage et mise à jour de l’ordinateur :

        Lance Hijackthis , (= C:\Program Files\trend micro\ANNE.exe) , ensuite clique sur do a system scan only puis tu sélectionne les lignes suivante ,

        O20 - Winlogon Notify: cbssreg - C:\Documents and Settings\All Users\Documents\Settings\cbss.dll (file missing)

        O23 - Service: LiveUpdate - Unknown owner - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE (file missing) => Symantec®Norton LiveUpdate

        R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
        O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
        O4 - Global Startup: McAfee Security Scan.lnk = ?

        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\K-Lite Codec Pack\QuickTime\QTTask.exe" -atboottime => Apple®Quick Time
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe => Microsoft®Windows NT
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL') => Microsoft®Windows NT
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU') => Microsoft®Windows NT
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') => Microsoft®Windows NT
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') => Microsoft®Windows NT

        Tu cliques en bas sur le bouton FIX CHECKED et valides .

        Redémarres l'ordi . ( important pour que certaines modifs faites avec hijakthis soient prises en compte )

        Si vous n'arrivé pas à lancer Hijackthis à partir du lien plus haut, téléchargez le fichier d'installation d'HijackThis.

        Tutoriaux Hijackthis

        Regarde aussi dans ton ordi et supprime toute les traces qui resteraient de symantec.


        Pour supprimer toutes les traces des logiciels qui ont servi à traiter les infections spécifiques :

        ▶ Télécharge Toolscleaner sur ton Bureau

        ▶ Sous XP : Double-clique sur ToolsCleaner2.exe
        ▶ Clique sur Recherche et laisse le scan se terminer.
        ▶ Clique sur Suppression pour finaliser.
        ▶ Tu peux, si tu le souhaites, te servir des Options facultatives.
        ▶ Clique sur Quitter, pour que le rapport puisse se créer.
        ▶ Le rapport (TCleaner.txt) se trouve à la racine de votre disque dur (C:\)...colle le dans ta réponse

        Pour mettre à jour les logiciels sur ton PC :

        Les Mises A Jour sont très importantes pour votre PC, afin d'éviter certaines failles de sécurité

        Voici un excellent petit logiciel très utile qui te permettra de savoir les nouvelles mises à jour disponibles pour les différents logiciels installés sur ton PC :

        ▶ Télécharge Update Checker

        ▶ Installe le avec les paramètres par défaut en cliquant chaques fois sur Suivant.

        ▶ Une fois installé, patiente quelques secondes et tu verras apparaître une icône verte dans ta barre des tâches te signalant qu'il y a des mises à jour disponibles.

        ▶ Double-cliques sur l'icône pour être redirrigé sur le site de téléchargement des mises à jour.

        ▶ Un conseil : n'installe pas les BETA qui sont listées en dessous.

        ▶ Tu installes les mises à jour que tu désires, les plus importantes sont :

        ● Java

        ● Adobe Reader

        ● Adobe Flash Player

        ● Navigateur Internet

        (attention certain logiciels mis en lien pour les mises à jour peuvent être en anglais, rechercher celui en français)

        Voici un tuto

        Enfin un petit nettoyage de l'ordi :

        Télécharge Ccleaner

        Tutoriel pour l'installer et l'utiliser correctement CCleaner

        Fais le nettoyage et recherche les erreurs du registre comme expliqué en bas du tutoriel.

        Enfin Purge de la restauration système :

        Désactivation de la restauration :

        ▶ Cliquez droit sur poste de travail
        ▶ Ensuite aller sur propriétés
        ▶ Puis restauration système
        ▶ Et cochez la case désactiver la restauration
        ▶ Cliquez ensuite sur appliquez, puis OK
        ▶ Et redémarrez votre PC

        Réactivation de la restauration :

        ▶ Cliquez droit sur poste de travail
        ▶ Ensuite aller sur propriétés
        ▶ Puis restauration système
        ▶ Et décochez la case désactiver la restauration
        ▶ Cliquez ensuite sur appliquez, puis OK
        ▶ Et redémarrez votre PC

        Et ensuite création d'un nouveau point de restauration comme ce qui suit :

        ▶ Allez dans le Menu Démarrer
        ▶ Puis dans Programmes
        ▶ Ensuite dans Accessoires
        ▶ Et enfin dans Outils système
        ▶ Choisir Restauration du système
        ▶ Sélectionnez créer un point de restauration
        ▶ Cliquez sur Suivant
        ▶ Entrez un nom pour le point de restauration
        ▶ Cliquez sur créer et le point de restauration se créé automatiquement.

        Enfin vous devez garder les logiciels suivant qui ont été téléchargés pour la désinfection et le nettoyage::

        ▶ Ccleaner à garder absolument et faire le nettoyage souvent

        ▶ Malware à garder absolument (faire scan de temps en temps)

        ▶ Update checker à garder absolument et faire un scan pour vérifier les mises à jour disponible

        Les autres sont à supprimer, dans ajout et suppression de programmes pour certains et pour d'autres manuellement

        Pour finir, penser à faire après tout ça, une défragmentation du PC afin de regrouper les fragments de fichiers éparpillés sur le disque pour optimiser les temps d'accès du disque dur lors de la lecture de fichiers de taille importante.

        Voici la procédure :

        Méthode 1 :

        Ainsi pour défragmenter de manière optimale, il est fortement recommandé de démarrer Windows en mode sans échec, puis de lancer la défragmentation !

        Pour lancer la défragmentation :

        ▶ Pour Windows XP et pour les autres versions, la procédure est quasiment la même

        ▶ Double-cliquez sur Poste de Travail, clic droit sur le disque à défragmenter puis sur Propriétés.

        ▶ Choisissez l'onglet Outils puis cliquez sur Défragmenter maintenant

        Méthode 2 :

        Aussi pour défragmenter le disque dur (plus efficace que l'utilitaire de défragmentation de Windows).

        Télacharge MyDefrag

        Voir le tuto pour bien l'installer et l'utiliser

        Un peu de prévention, je te conseille :

        D'installer un parefeu autre que celui de windows, car celui de windows ne filtre que les flux entrants mais laisse tout sortir ! Donc cela permet :
        ▶ de se faire voler des informations (vols de fichiers),
        ▶ de se faire voler les mots de passe et login (keyloggers),
        ▶ de laisser n'importe-qui prendre une totale possession de la machine (troyens) !
        ▶ de laisser plus de pouvoir à certains programmes malveillants (les malwares). Par exemple certains virus tentent de se connecter sur internet pour communiquer avec l'extérieur. Ceci peut leur permettre de télécharger des fichiers nuisibles, d'attaquer des ordinateurs distants (votre responsabilité peut être engagée dans ce genre de cas), etc....

        Utilisez donc un véritable pare-feu, comme :

        ▶ FireWall

        ▶ Online Armor Personal Firewall

        Ensuite tu as Avast comme antivirus, ce que je te propose, c'est de le désinstaller pour mettre à la place AVIRA/ANTIVIR, car AVIRA/ANTIVR détecte plus de virus qu'Avast donc plus performant. Voici un petit comparatif avec AVAST et AVIRA/ANTIVIR

        Ce que tu vas faire :

        [*] Aller dans ajout et suppression de programme,
        [*] Désinstaller Avast
        [*] Ensuite, passer ceci pour bien supprimer Avast entièrement
        [*] Puis Installer AVIRA/ANTIVIR
        [*] Tuto de configuration en vidéo

        De remplacer IE par Firefox :

        ▶ Télécharge Firefox, car il est plus sûr et plus rapide que IE. Ensuite installe les extensions suivantes afin de bien sécurisé ta navigation sur Internet. :

        ▶ IE Tab

        IE Tab est une extension pour Mozilla Firefox, et uniquement pour les systèmes d'exploitation Windows. Elle permet à une page Web ou à un lien d'être ouvert dans un onglet de Firefox avec le moteur d'Internet Explorer.

        ▶ AdBlockPlus

        AdblockPlus est une extension de firefox permettant de bloquer les publicités et les pop-ups des sites visités par l'utilisateur.

        ▶ Web Of Trust

        WOT est un module complémentaire de sécurité Internet gratuit pour votre navigateur. Il vous protège des fraudes en ligne, de l'usurpation d'identité, des logiciels espions, du courrier indésirable, des virus et des sites de vente en ligne non fiables.

        ▶NoScript

        Protection supplémentaire pour votre Firefox : NoScript ne permet l'exécution de scripts JavaScript que sur les domaines de confiance de votre choix (p.ex. le site de votre banque). Ce système de blocage préventif de scripts basé sur une liste blanche empêche l'exploitation de failles de sécurité (connues et même inconnues) sans perte de fonctionnalités…

        ▶PhishTank SiteChecker

        Vous informe en temps réel des menaces de phishing durant votre navigation sur Internet./list

        Et pour finir, un peu de lecture :

        Prévention & Sécurité sur internet
        1. bonjour,
          j'étais absente je m'en occupe dès que possible
          merci
        2. bonjour,
          voilà j'ai à peu près suivi tout le processus j'ai encore un problème au démarrage :
          "windows n'a pas démarré normalement...."
          ensuite une vérification du disque est faite...

          ci joint le rapport tcleaner
          [ Rapport ToolsCleaner version 2.3.11 (par A.Rothstein & dj QUIOU) ]

          --> Recherche:

          C:\cleannavi.txt: trouvé !
          C:\FindyKill.txt: trouvé !
          C:\UsbFix.txt: trouvé !
          C:\_OTM: trouvé !
          C:\UsbFix: trouvé !
          C:\FindyKill: trouvé !
          C:\Rsit: trouvé !
          C:\Documents and Settings\ANNE\Mes documents\dossiers ordi\hijackthis.log: trouvé !
          C:\Documents and Settings\ANNE\Mes documents\dossiers ordi\cleannavi.txt: trouvé !
          C:\Documents and Settings\ANNE\Bureau\antiviral\OTM.exe: trouvé !
          C:\Documents and Settings\ANNE\Bureau\antiviral\Ad-R.exe: trouvé !
          C:\Documents and Settings\ANNE\Bureau\antiviral\UsbFix.exe: trouvé !
          C:\Documents and Settings\ANNE\Bureau\antiviral\UsbFix.txt: trouvé !
          C:\Documents and Settings\ANNE\Bureau\Raccourcis Bureau non utilisés\Rsit.exe: trouvé !
          C:\Program Files\Navilog1: trouvé !
          C:\Program Files\Ad-remover: trouvé !
          C:\Program Files\ZHPDiag: trouvé !
          C:\Program Files\Hijackthis Version Française\hijackthis.log: trouvé !
          C:\Program Files\trend micro\HijackThis.exe: trouvé !
          C:\Program Files\trend micro\hijackthis.log: trouvé !
          C:\Program Files\ZHPDiag\ZHPdiag.exe: trouvé !
          C:\Program Files\Ad-Remover\BACKUP\Ad-R.exe: trouvé !
          C:\BFU\toolbar.bfu: trouvé !
          C:\BFU\Bfu.exe: trouvé !

          ---------------------------------
          --> Suppression:

          C:\Documents and Settings\ANNE\Bureau\antiviral\OTM.exe: supprimé !
          C:\Documents and Settings\ANNE\Bureau\antiviral\Ad-R.exe: supprimé !
          C:\Program Files\trend micro\HijackThis.exe: supprimé !
          C:\Program Files\ZHPDiag\ZHPdiag.exe: supprimé !
          C:\Program Files\Ad-Remover\BACKUP\Ad-R.exe: supprimé !
          C:\BFU\toolbar.bfu: supprimé !
          C:\BFU\Bfu.exe: supprimé !
          C:\cleannavi.txt: supprimé !
          C:\FindyKill.txt: supprimé !
          C:\UsbFix.txt: supprimé !
          C:\Documents and Settings\ANNE\Mes documents\dossiers ordi\hijackthis.log: supprimé !
          C:\Documents and Settings\ANNE\Mes documents\dossiers ordi\cleannavi.txt: supprimé !
          C:\Documents and Settings\ANNE\Bureau\antiviral\UsbFix.exe: supprimé !
          C:\Documents and Settings\ANNE\Bureau\antiviral\UsbFix.txt: supprimé !
          C:\Documents and Settings\ANNE\Bureau\Raccourcis Bureau non utilisés\Rsit.exe: supprimé !
          C:\Program Files\Hijackthis Version Française\hijackthis.log: supprimé !
          C:\Program Files\trend micro\hijackthis.log: supprimé !
          C:\_OTM: supprimé !
          C:\UsbFix: supprimé !
          C:\FindyKill: supprimé !
          C:\Rsit: supprimé !
          C:\Program Files\Navilog1: supprimé !
          C:\Program Files\Ad-remover: supprimé !
          C:\Program Files\ZHPDiag: supprimé !
      6. Contributeur sécurité
        Je regarde ça et te tiens au courant demain car il est tard.
        1. Contributeur sécurité
          Parfais pourrais tu me refaire un RSIt.
          1. http://www.cijoint.fr/cjlink.php?file=cj200911/cijqbNtrSR.txt
        2. Contributeur sécurité
          ▶ Télécharge OTM (de Old_Timer) sur ton Bureau

          ▶ Double-clique sur OTM.exe pour le lancer.

          ▶ Assure toi que la case Unregister Dll's and Ocx's soit bien cochée.

          ▶ Copie la liste qui se trouve en gras dans la citation ci-dessous et colle-la dans le cadre de gauche de OTM sous "Paste instructions for item to be moved".

          -----------------------------------------------------------------------------

          :reg
          [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cbssreg]

          :files
          C:\Documents and Settings\All Users\Documents\Settings\cbss.dll

          :commands
          [emptytemp]
          [reboot]


          -----------------------------------------------------------------------------

          ▶ clique sur MoveIt! pour lancer la suppression.

          ▶ Le résultat apparaitra dans le cadre "Results".

          ▶ Clique sur Exit pour fermer.

          ▶ Poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

          ▶ Il te sera peut-être demandé de redémarrer le pc pour achever la suppression. Si c'est le cas accepte par Yes.
          1. All processes killed
            ========== REGISTRY ==========
            Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cbssreg\ deleted successfully.
            ========== FILES ==========
            LoadLibrary failed for C:\Documents and Settings\All Users\Documents\Settings\cbss.dll
            File move failed. C:\Documents and Settings\All Users\Documents\Settings\cbss.dll scheduled to be moved on reboot.
            ========== COMMANDS ==========

            [EMPTYTEMP]

            User: Default User
            ->Temp folder emptied: 0 bytes
            ->Temporary Internet Files folder emptied: 0 bytes

            User: All Users

            User: NetworkService
            ->Temp folder emptied: 0 bytes
            ->Temporary Internet Files folder emptied: 0 bytes

            User: LocalService
            ->Temp folder emptied: 0 bytes
            ->Temporary Internet Files folder emptied: 33170 bytes

            User: ANNE
            ->Temp folder emptied: 24623524 bytes
            ->Temporary Internet Files folder emptied: 14883488 bytes
            ->Java cache emptied: 0 bytes
            ->FireFox cache emptied: 97167286 bytes

            User: Administrateur
            ->Temp folder emptied: 0 bytes
            ->Temporary Internet Files folder emptied: 0 bytes

            %systemdrive% .tmp files removed: 0 bytes
            %systemroot% .tmp files removed: 0 bytes
            %systemroot%\System32 .tmp files removed: 0 bytes
            Windows Temp folder emptied: 182795 bytes
            %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 56323296 bytes
            %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
            RecycleBin emptied: 809805 bytes

            Total Files Cleaned = 185,07 mb

            OTM by OldTimer - Version 3.1.2.0 log created on 11192009_172043

            Files moved on Reboot...
            File move failed. C:\Documents and Settings\All Users\Documents\Settings\cbss.dll scheduled to be moved on reboot.
            File C:\WINDOWS\temp\_avast4_\Webshlock.txt not found!
            C:\WINDOWS\temp\Perflib_Perfdata_548.dat moved successfully.

            Registry entries deleted on Reboot...
        3. Contributeur sécurité
          Essaye de faire ceci et réessaye :

          Démarches à faire pour afficher les fichiers et dossiers cachés :

          * Double cliquez sur l'Icône Poste de travail qui se trouve sur votre bureau
          * Votre Poste de travail s'affichera alors comme sur cette image
          * Ensuite dans la barre des menus en haut,vous cliquez sur "Outils"
          * Puis vous cliquez sur "Options des dossiers" comme sur cette image
          * Une fois l'option "Options des dossiers" sélectionnée vous verrez apparaître une fenêtre intitulée Options des dossiers
          * Cliquez donc sur l'onglet Affichage et vous obtiendrez cette fenêtre ci
          * Dans les options qui vous sont proposées, sélectionnez " Afficher les dossiers et fichiers cachés" comme sur cette image
          * Masquer les extensions des fichiers dont le type est connu
          * Masquer les fichiers protégés du système d'exploitation
          * Voir comme sur cette image
          * Cliquez ensuite sur "Appliquer" et validez par "Ok"
          1. des fichiers ont réapparu mais je n'ai pas trouvé celui ci
            désolé
        4. Contributeur sécurité
          Parfais,

          Maintenant, analyse moi ce fichier : C:\Documents and Settings\All Users\Documents\Settings\cbss.dll avec virus total :

          Ce service se trouve ici :
          ==> https://www.virustotal.com/gui/

          1) La fenêtre principale comporte plusieurs points qu'il faut comprendre :

          # La Charge du service est l'élément qui détermine si le site VirusTotal est peu ou fortement sollicité, vert le site est peu utilisé, rouge vous allez devoir attendre.

          # Parcourir, permettra de rechercher le fichier à analyser. Envoyer, commencera l'analyse du fichier que vous avez au préalable recherché voir cette cette image

          2) Cliquez sur " Parcourir " afin de rechercher le fichier à tester qui peut se trouver sur votre bureau, vos documents, un dossier de Windows, etc. :
          Une fois sélectionné , cliquez sur " Ouvrir " voir cette cette image

          3) La page principale revient mais vous voyez maintenant précisément l'emplacement de ce fichier .
          Cliquez sur " Envoyer " voir cette image

          4) L'envoi du fichier est en cours, patientez pendant quelques secondes. Le temps d'attente peut être plus ou moins long selon la charge du service VirusTotal et de la taille du fichier à analyser voir cette cette image

          5) Cependant si le site VirusTotal est trop sollicité , cette fenêtre apparaitra et donc vous aurez pour choix, soit d'attendre tranquillement, soit de revenir à un autre moment de la journée quand le site sera moins utilisé.

          6) Votre fichier a été envoyé avec succès donc l'analyse va débuter dans quelques secondes et durer quelques minutes.
          Les 32 anti-virus vont analyser chacun à leur tour le fichier envoyé.

          7) Une fois le fichier totalement analysé vous verrez apparaitre dans le haut de la fenêtre le statut de l'analyse.
          Le chiffre en rouge est le nombre d'anti-virus considérant le fichier comme infecté.
          Cliquez sur " Formaté " afin d'avoir un rapport détaillé .

          Il ne vous reste qu'à faire un copier-coller du résultat ou de recopier l'url présente sur la barre d'adresse et de l'envoyer à la personne qui vous a demandé de faire cette analyse.
          1. bonjour,
            je ne trouve pas ce fichier...
        5. Contributeur sécurité
          ▶ tutoriel nettoyage

          ▶ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d avoir été infectés sans les ouvrir

          ▶ Double clic sur le raccourci UsbFix présent sur ton bureau

          ▶ choisi l'option 2 ( Suppression )

          ▶ Ton bureau disparaîtra et le pc redémarrera .

          ▶ Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.

          ▶ Ensuite post le rapport UsbFix.txt qui apparaîtra avec le bureau .

          ▶ Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

          ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

          ▶ /!\ UsbFix te proposera d'uploader un dossier compressé à cette adresse : https://www.androidworld.fr/

          ▶ Ce dossier a été créé par UsbFix et est enregistré sur ton bureau.

          ▶ Merci de l'envoyer à l'adresse indiquée afin d'aider l'auteur de UsbFix dans ses recherches.

          ▶ Merci d'avance pour ta contribution !!
          1. ############################## | UsbFix V6.053 |

            User : ANNE (Administrateurs) # R2-D2
            Update on 14/11/2009 by Chiquitine29, C_XX & Chimay8
            Start at: 17:27:01 | 17/11/2009
            Website : http://pagesperso-orange.fr/NosTools/index.html
            Contact : FindyKill.Contact@gmail.com

            AMD Sempron(tm) 2800+
            Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
            Internet Explorer 8.0.6001.18702
            Windows Firewall Status : Enabled
            AV : avast! antivirus 4.8.1356 [VPS 091117-0] 4.8.1356 [ Enabled | Updated ]

            C:\ -> Disque fixe local # 149,01 Go (54,25 Go free) [ACER] # FAT32
            D:\ -> Disque CD-ROM
            E:\ -> Disque amovible
            F:\ -> Disque amovible # 3,74 Go (3,74 Go free) # FAT32
            G:\ -> Disque amovible
            H:\ -> Disque amovible
            I:\ -> Disque amovible

            ############################## | Processus actifs |

            C:\WINDOWS\System32\smss.exe 484
            C:\WINDOWS\system32\csrss.exe 568
            C:\WINDOWS\system32\winlogon.exe 592
            C:\WINDOWS\system32\services.exe 636
            C:\WINDOWS\system32\lsass.exe 648
            C:\WINDOWS\system32\svchost.exe 800
            C:\WINDOWS\system32\svchost.exe 872
            C:\WINDOWS\System32\svchost.exe 940
            C:\WINDOWS\system32\svchost.exe 1028
            C:\Program Files\Internet Explorer\IEXPLORE.EXE 1128
            C:\WINDOWS\system32\svchost.exe 1164
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe 1256
            C:\Program Files\Alwil Software\Avast4\ashServ.exe 1356
            C:\WINDOWS\Explorer.EXE 1496
            C:\WINDOWS\system32\spoolsv.exe 1804
            C:\Program Files\Google\Update\GoogleUpdate.exe 2020
            C:\WINDOWS\system32\svchost.exe 560
            C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 756
            C:\Program Files\Bonjour\mDNSResponder.exe 912
            C:\WINDOWS\System32\svchost.exe 932
            C:\Program Files\Google\Update\GoogleUpdate.exe 1048
            C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe 1056
            C:\Program Files\Google\Update\GoogleUpdate.exe 744
            C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE 1444
            C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe 1572
            C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe 1588
            C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 1904
            C:\WINDOWS\system32\svchost.exe 1996
            C:\WINDOWS\system32\wuauclt.exe 260
            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe 400
            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe 468
            C:\Program Files\Alwil Software\Avast4\setup\avast.setup 1552
            C:\WINDOWS\system32\wbem\wmiprvse.exe 2076

            ################## | Fichiers # Dossiers infectieux |

            ################## | Registre # Clés Run infectieuses |

            ################## | Registre # Mountpoints2 |

            Supprimé ! HKCU\...\Explorer\MountPoints2\{5552cd95-a9f0-11de-95c0-000feadaf275}\Shell\AutoRun\Command
            Supprimé ! HKCU\...\Explorer\MountPoints2\{83249108-d75d-11dd-9490-000feadaf275}\Shell\AutoRun\Command
            Supprimé ! HKCU\...\Explorer\MountPoints2\{c466e84c-3a18-11dd-93ad-000feadaf275}\Shell\verb1\Command

            ################## | Listing des fichiers présent |

            [20/04/2004 11:31|--a------|5] C:\xpsp2.id
            [20/04/2004 11:31|--a------|5] C:\fr.id
            [16/06/2005 02:51|---hs----|78] C:\BOOTLOG.TXT
            [22/02/2007 18:21|--a------|186] C:\setup.log
            [16/06/2005 02:51|---hs----|512] C:\BOOTSECT.DOS
            [?|?|?] C:\pagefile.sys
            [?|?|?] C:\hiberfil.sys
            [05/08/2004 05:00|-rahs----|4952] C:\Bootfont.bin
            [04/09/2008 18:49|-rahs----|252240] C:\ntldr
            [05/08/2004 05:00|-rahs----|47564] C:\NTDETECT.COM
            [28/08/2007 09:41|--a------|8156] C:\resultat.txt
            [04/08/2005 19:00|-rahs----|216] C:\boot.ini
            [12/11/2009 22:38|--a------|4] C:\AUTOEXEC.BAT
            [09/04/2004 01:22|--a------|0] C:\CONFIG.SYS
            [23/04/1999 22:22|-r-hs----|0] C:\IO.SYS
            [16/06/2005 02:29|-r-hs----|0] C:\MSDOS.SYS
            [01/09/2007 12:34|--a------|1718] C:\cleannavi.txt
            [25/02/2008 17:45|--a------|1370] C:\crashAddress.txt
            [01/11/2009 09:04|--a------|4326] C:\Ad-Report-CLEAN[1].log
            [17/11/2009 17:28|--a------|3945] C:\UsbFix.txt
            [12/11/2009 22:37|--a------|4106] C:\Kill'em.txt
            [15/11/2009 09:35|--a------|3775] C:\FindyKill.txt
            [24/05/2001 12:59|--a------|162304] C:\UNWISE.EXE
            [06/11/2005 16:44|--a------|1091] C:\INSTALL.LOG
            [16/02/2006 09:33|--a------|192] C:\persist.dbs

            ################## | Vaccination |

            # C:\autorun.inf -> Dossier créé par UsbFix.

            ################## | Suspect | https://www.virustotal.com/gui/ |

            ################## | Cracks / Keygens / Serials |

            ################## | ! Fin du rapport # UsbFix V6.053 ! |
        6. Contributeur sécurité
          je te met le nouveau lien pour télécharger usb fix car il à changé : https://www.ionos.fr/?affiliate_id=77097
          1. ############################## | UsbFix V6.053 |

            User : ANNE (Administrateurs) # R2-D2
            Update on 14/11/2009 by Chiquitine29, C_XX & Chimay8
            Start at: 20:22:24 | 16/11/2009
            Website : http://pagesperso-orange.fr/NosTools/index.html
            Contact : FindyKill.Contact@gmail.com

            AMD Sempron(tm) 2800+
            Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
            Internet Explorer 8.0.6001.18702
            Windows Firewall Status : Enabled
            AV : avast! antivirus 4.8.1356 [VPS 091116-0] 4.8.1356 [ Enabled | Updated ]

            C:\ -> Disque fixe local # 149,01 Go (54,29 Go free) [ACER] # FAT32
            D:\ -> Disque CD-ROM
            F:\ -> Disque amovible # 3,74 Go (3,74 Go free) # FAT32

            ############################## | Processus actifs |

            C:\WINDOWS\System32\smss.exe 484
            C:\WINDOWS\system32\csrss.exe 568
            C:\WINDOWS\system32\winlogon.exe 592
            C:\WINDOWS\system32\services.exe 636
            C:\WINDOWS\system32\lsass.exe 648
            C:\WINDOWS\system32\svchost.exe 804
            C:\WINDOWS\system32\svchost.exe 872
            C:\WINDOWS\System32\svchost.exe 972
            C:\WINDOWS\system32\svchost.exe 1060
            C:\WINDOWS\system32\svchost.exe 1192
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe 1252
            C:\Program Files\Alwil Software\Avast4\ashServ.exe 1352
            C:\WINDOWS\Explorer.EXE 1492
            C:\Program Files\iTunes\iTunesHelper.exe 1632
            C:\WINDOWS\system32\ctfmon.exe 1648
            C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe 1696
            C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe 1704
            C:\Documents and Settings\ANNE\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe 1904
            C:\WINDOWS\system32\spoolsv.exe 1948
            C:\WINDOWS\system32\svchost.exe 1404
            C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 1460
            C:\Program Files\Bonjour\mDNSResponder.exe 1540
            C:\WINDOWS\System32\svchost.exe 856
            C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE 252
            C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe 408
            C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe 448
            C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 2020
            C:\WINDOWS\system32\svchost.exe 992
            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe 2184
            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe 2216
            C:\Program Files\iPod\bin\iPodService.exe 2352
            C:\Program Files\Windows Live\Contacts\wlcomm.exe 1208
            C:\Program Files\Mozilla Firefox\firefox.exe 3576
            C:\Program Files\Internet Explorer\IEXPLORE.EXE 2928
            C:\WINDOWS\system32\wbem\wmiprvse.exe 3716

            ################## | Fichiers # Dossiers infectieux |

            ################## | Registre # Clés Run infectieuses |

            ################## | Registre # Mountpoints2 |

            HKCU\..\..\Explorer\MountPoints2\{5552cd95-a9f0-11de-95c0-000feadaf275}
            Shell\AutoRun\command =F:\EmDesk.exe
            Shell\EmDesk\command =F:\EmDesk.exe

            HKCU\..\..\Explorer\MountPoints2\{83249108-d75d-11dd-9490-000feadaf275}
            Shell\AutoRun\command =E:\WDSetup.exe

            HKCU\..\..\Explorer\MountPoints2\{c466e84c-3a18-11dd-93ad-000feadaf275}
            shell\verb1\command =E:\desktop.exe

            ################## | Suspect | https://www.virustotal.com/gui/ |

            ################## | Cracks / Keygens / Serials |

            ################## | ! Fin du rapport # UsbFix V6.053 ! |
        7. Contributeur sécurité
          je te met le nouveau lien pour télécharger usb fix car il à changé : https://www.ionos.fr/?affiliate_id=77097
          1. ############################## | UsbFix V6.045 |

            User : ANNE (Administrateurs) # R2-D2
            Update on 24/10/2009 by Chiquitine29, C_XX & Chimay8
            Start at: 17:20:05 | 16/11/2009
            Website : http://pagesperso-orange.fr/NosTools/index.html
            Contact : FindyKill.Contact@gmail.com

            AMD Sempron(tm) 2800+
            Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
            Internet Explorer 8.0.6001.18702
            Windows Firewall Status : Enabled
            AV : avast! antivirus 4.8.1356 [VPS 091116-0] 4.8.1356 [ Enabled | Updated ]

            C:\ -> Disque fixe local # 149,01 Go (54,31 Go free) [ACER] # FAT32
            D:\ -> Disque CD-ROM
            E:\ -> Disque amovible
            F:\ -> Disque amovible # 3,74 Go (3,74 Go free) # FAT32
            G:\ -> Disque amovible
            H:\ -> Disque amovible
            I:\ -> Disque amovible

            ############################## | Processus actifs |

            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\csrss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\Program Files\Alwil Software\Avast4\ashServ.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\iTunes\iTunesHelper.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
            C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
            C:\Documents and Settings\ANNE\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            C:\Program Files\Bonjour\mDNSResponder.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
            C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
            C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe
            C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            C:\Program Files\iPod\bin\iPodService.exe
            C:\Program Files\Windows Live\Contacts\wlcomm.exe
            C:\Program Files\Internet Explorer\IEXPLORE.EXE
            C:\WINDOWS\system32\wbem\wmiprvse.exe

            ################## | Fichiers # Dossiers infectieux |

            ################## | Registre # Clés Run infectieuses |

            ################## | Registre # Mountpoints2 |

            HKCU\..\..\Explorer\MountPoints2\{5552cd95-a9f0-11de-95c0-000feadaf275}
            Shell\AutoRun\command =F:\EmDesk.exe
            Shell\EmDesk\command =F:\EmDesk.exe

            HKCU\..\..\Explorer\MountPoints2\{83249108-d75d-11dd-9490-000feadaf275}
            Shell\AutoRun\command =E:\WDSetup.exe

            HKCU\..\..\Explorer\MountPoints2\{c466e84c-3a18-11dd-93ad-000feadaf275}
            shell\verb1\command =E:\desktop.exe

            ################## | Suspect | https://www.virustotal.com/gui/ |

            ################## | Cracks / Keygens / Serials |

            ################## | ! Fin du rapport # UsbFix V6.045 ! |
        8. Contributeur sécurité
          Ensuite tu va me faire ceci :

          ▶ Rends-toi à cette adresse afin de télécharger UsbFix (créé par Chiquitine29 & C_XX) :

          ▶ https://www.androidworld.fr/

          ▶ Clique sur TÉLÉCHARGER et enregistre-le sur ton bureau.

          ▶ tutoriel recherche

          ▶ Double-clique sur UsbFix présent sur ton bureau, l'installation se fera automatiquement

          ▶ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

          ▶ Choisi l'option 1 (recherche)

          ▶ Laisse travailler l'outil

          ▶ Ensuite post le rapport UsbFix.txt qui apparaîtra

          * Note : le rapport UsbFix.txt est sauvegardé a la racine du disque

          * Note : Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides

          * Note : "SniffC.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
          Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
          Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
          1. Contributeur sécurité
            bonjour,

            Tu peux réessayer le mode sans échec pour voir si ça remarche. Merci.
            1. ça ne marche toujours pas
          2. Contributeur sécurité
            ah oui excuse pour le lien il à changé,

            ▶ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

            ▶ Double clic sur le raccourci FindyKill sur ton bureau

            ▶ Au menu principal,choisi l option 2 (Suppression)

            /!\ il y aura un redémarrage, laisse travailler l outils jusqu a l apparition du message "nettoyage effectué"

            /!\ Ne te sert pas du pc durant la suppression , ton bureau ne sera pas accessible c est normal !

            ▶ ensuite post le rapport FindyKill.txt

            * Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
            * Note : Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides

            A lire :

            le danger des cracks

            bagle/beagle
            1. ############################## | FindyKill V5.017 |

              # User : ANNE (Administrateurs) # R2-D2
              # Update on 01/11/2009 by Chiquitine29
              # Start at: 09:23:44 | 15/11/2009
              # Website : http://pagesperso-orange.fr/NosTools/index.html
              # Contact : FindyKill.Contact@gmail.com

              # AMD Sempron(tm) 2800+
              # Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
              # Internet Explorer 8.0.6001.18702
              # Windows Firewall Status : Enabled
              # AV : avast! antivirus 4.8.1356 [VPS 091114-1] 4.8.1356 [ Enabled | Updated ]

              # C:\ # Disque fixe local # 149,01 Go (54,38 Go free) [ACER] # FAT32
              # D:\ # Disque CD-ROM
              # E:\ # Disque amovible
              # G:\ # Disque amovible
              # H:\ # Disque amovible
              # I:\ # Disque amovible

              ############################## | Processus actifs |

              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\csrss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Internet Explorer\IEXPLORE.EXE
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Google\Update\GoogleUpdate.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              C:\Program Files\Bonjour\mDNSResponder.exe
              C:\Program Files\Google\Update\GoogleUpdate.exe
              C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              C:\Program Files\Google\Update\GoogleUpdate.exe
              C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
              C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
              C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe
              C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              C:\WINDOWS\system32\wbem\wmiprvse.exe
              C:\Program Files\Alwil Software\Avast4\setup\avast.setup

              ################## | C: |

              ################## | C:\WINDOWS |

              Supprimé ! C:\WINDOWS\Prefetch\WINUPGRO.EXE-17681AA8.pf

              ################## | C:\WINDOWS\system32 |

              ################## | C:\WINDOWS\system32\drivers |

              ################## | C:\Documents and Settings\ANNE\Application Data |

              ################## | Autres suppressions ... |

              ################## | Temporary Internet Files |

              ################## | Registre / Clés infectieuses |

              Supprimé ! [HKLM\software\microsoft\security center] "AntiVirusDisableNotify"
              Supprimé ! [HKLM\software\microsoft\security center] "AntiVirusOverride"
              Supprimé ! [HKLM\software\microsoft\security center] "FirewallDisableNotify"
              Supprimé ! [HKLM\software\microsoft\security center] "FirewallOverride"
              Supprimé ! [HKLM\software\microsoft\security center] "UpdatesDisableNotify"
              Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableTaskMgr"

              ################## | Etat / Services / Informations |

              # Mode sans echec : OK

              # Affichage des fichiers cachés : OK

              # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
              # EapHost -> Start = 2 ( Good = 2 | Bad = 4 )
              # Ip6Fw -> Start = 2 ( Good = 2 | Bad = 4 )
              # SharedAccess -> Start = "Start" ( Good = 2 | Bad = 4 )
              # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )

              ################## | PEH ... |

              ################## | Cracks / Keygens / Serials |

              ################## | ! Fin du rapport # FindyKill V5.017 ! |
          3. Contributeur sécurité
            désactiver toutes les protections résidentes, ensuite me faire ceci :

            ▶ Rends-toi à cette adresse afin de télécharger FindyKill (créé par Chiquitine29) :

            ▶ https://www.androidworld.fr/

            ▶ Clique sur TÉLÉCHARGER et enregistre-le sur ton bureau.

            ▶ Double clic sur le raccourci FindyKill sur ton bureau, l'installation se fera automatiquement

            ▶ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

            ▶ Au menu principal,choisi l option 1 (Recherche)

            ▶ Patiente un peu, l'analyse peut durer quelques minutes

            ▶ Post le rapport FindyKill.txt

            * Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
            1. le lien ne fonctionne pas
            2. me suis débrouillée...

              ############################## | FindyKill V5.017 |

              # User : ANNE (Administrateurs) # R2-D2
              # Update on 01/11/2009 by Chiquitine29
              # Start at: 15:08:04 | 14/11/2009
              # Website : http://pagesperso-orange.fr/NosTools/index.html
              # Contact : FindyKill.Contact@gmail.com

              # AMD Sempron(tm) 2800+
              # Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
              # Internet Explorer 8.0.6001.18702
              # Windows Firewall Status : Enabled
              # AV : avast! antivirus 4.8.1356 [VPS 091114-0] 4.8.1356 [ (!) Disabled | Updated ]

              # C:\ # Disque fixe local # 149,01 Go (54,37 Go free) [ACER] # FAT32
              # D:\ # Disque CD-ROM
              # E:\ # Disque amovible
              # G:\ # Disque amovible
              # H:\ # Disque amovible
              # I:\ # Disque amovible

              ############################## | Processus actifs |

              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\csrss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\WINDOWS\Explorer.EXE
              C:\Program Files\iTunes\iTunesHelper.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
              C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Documents and Settings\ANNE\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              C:\Program Files\Bonjour\mDNSResponder.exe
              C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
              C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
              C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe
              C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\iPod\bin\iPodService.exe
              C:\Program Files\Windows Live\Contacts\wlcomm.exe
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              C:\Program Files\Internet Explorer\IEXPLORE.EXE
              C:\Program Files\Mozilla Firefox\firefox.exe
              C:\WINDOWS\system32\wbem\wmiprvse.exe

              ################## | C: |

              ################## | C:\WINDOWS |

              ################## | C:\WINDOWS\system32 |

              ################## | C:\WINDOWS\system32\drivers |

              ################## | C:\Documents and Settings\ANNE\Application Data |

              ################## | Autres detections ... |

              ################## | Temporary Internet Files |

              ################## | Registre / Clés infectieuses |

              Présent ! [HKLM\software\microsoft\security center] "AntiVirusDisableNotify"
              Présent ! [HKLM\software\microsoft\security center] "AntiVirusOverride"
              Présent ! [HKLM\software\microsoft\security center] "FirewallDisableNotify"
              Présent ! [HKLM\software\microsoft\security center] "FirewallOverride"
              Présent ! [HKLM\software\microsoft\security center] "UpdatesDisableNotify"
              Présent ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableTaskMgr"

              ################## | Etat / Services / Informations |

              # Affichage des fichiers cachés : OK

              # Mode sans echec : OK

              # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
              # EapHost -> Start = 3 ( Good = 2 | Bad = 4 )
              # Ip6Fw -> Start = 3 ( Good = 2 | Bad = 4 )
              # SharedAccess -> Start = "Start" ( Good = 2 | Bad = 4 )
              # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )

              ################## | Cracks / Keygens / Serials |

              ################## | ! Fin du rapport # FindyKill V5.017 ! |
          4. Contributeur sécurité
            Fait moi alors une dernier RSIT pour voir.

            1. http://www.cijoint.fr/cjlink.php?file=cj200911/cijCehsYsU.txt
          • 1
          • 2
          • 3