Malware defense...

Résolu
Bonjour,

Comme beaucoup d'entre vous en ce moment, j'ai Malware defense qui s'est installé... j'ai beau le supprimer il revient tout le temps... et bloque mon antivirus (avira antivir) qui ne peut se lancer.
J'ai des messages de virus qui apparaissent sans cesse ainsi que des pubs... et mon ordi s'éteint régulièrement.

Je voulais tout d'abord attendre les réponses à d'autres posts.. vu que j'ai vu que certains avaient le même problème que moi mais vu que cela est personnalisé j'ai préféré écrire...

J'ai fait CCleaner mais ne peut lancer Mbam...

Le mode sans échec de mon ordi n'arrive également pas à se lancer...

Des solutions pour virer cette chose??

Merci de vos réponses
ps : je suis sous xp internet explorer
Configuration: Windows XP Internet Explorer 6.0

24 réponses

  1. également & bonnes fetes :)
    0
    1. Pas de soucis apparent, je les ai supprimés manuellement.
      Merci bien et bonne continuation!

      ;)
      0
      1. Ok

        j'ai toujours les logiciels, genre : killbagle, Ccleaner, toolscleaner, sur le bureau et Mbam et ccleaner dans un autre dossier que j'avais fait (en essayant tout seul de tout supprimer...)

        pas de soucis à tous les supprimer manuellement???
        0
        1. le bureau n'a pas disparu

          [ Rapport ToolsCleaner version 2.3.11 (par A.Rothstein & dj QUIOU) ]

          --> Recherche:

          C:\_OTM: trouvé !
          C:\Documents and Settings\Acer\Bureau\OTM.exe: trouvé !
          C:\Documents and Settings\Acer\Bureau\UsbFix.exe: trouvé !
          C:\Documents and Settings\Acer\Bureau\Rsit.exe: trouvé !
          C:\_OTM\MovedFiles\12272009_182921\C_\Combofix.txt: trouvé !
          C:\_OTM\MovedFiles\12272009_182921\C_\Qoobox: trouvé !
          C:\_OTM\MovedFiles\12272009_182921\C_\UsbFix: trouvé !
          C:\_OTM\MovedFiles\12272009_182921\C_\Rsit: trouvé !
          C:\_OTM\MovedFiles\12272009_182921\C_WINDOWS\mbr.exe: trouvé !
          C:\_OTM\MovedFiles\12272009_182921\C_Qoobox\Quarantine\catchme.log: trouvé !
          C:\_OTM\MovedFiles\12272009_182921\C_Program Files\trend micro\HijackThis.exe: trouvé !
          C:\_OTM\MovedFiles\12272009_182921\C_Program Files\trend micro\hijackthis.log: trouvé !

          ---------------------------------
          --> Suppression:

          C:\Documents and Settings\Acer\Bureau\OTM.exe: supprimé !
          C:\_OTM\MovedFiles\12272009_182921\C_Program Files\trend micro\HijackThis.exe: supprimé !
          C:\Documents and Settings\Acer\Bureau\UsbFix.exe: supprimé !
          C:\Documents and Settings\Acer\Bureau\Rsit.exe: supprimé !
          C:\_OTM\MovedFiles\12272009_182921\C_\Combofix.txt: supprimé !
          C:\_OTM\MovedFiles\12272009_182921\C_WINDOWS\mbr.exe: supprimé !
          C:\_OTM\MovedFiles\12272009_182921\C_Qoobox\Quarantine\catchme.log: supprimé !
          C:\_OTM\MovedFiles\12272009_182921\C_Program Files\trend micro\hijackthis.log: supprimé !
          C:\_OTM: supprimé !
          0
          1. All processes killed
            ========== PROCESSES ==========
            No active process named explorer.exe was found!
            ========== SERVICES/DRIVERS ==========
            Service catchme stopped successfully!
            Service catchme deleted successfully!
            Service Bonjour Service stopped successfully!
            Service Bonjour Service deleted successfully!
            ========== FILES ==========
            C:\ComboFix.txt moved successfully.
            C:\FOUND.001 folder moved successfully.
            C:\WINDOWS\zip.exe moved successfully.
            C:\WINDOWS\SWXCACLS.exe moved successfully.
            C:\WINDOWS\SWSC.exe moved successfully.
            C:\WINDOWS\SWREG.exe moved successfully.
            C:\WINDOWS\sed.exe moved successfully.
            C:\WINDOWS\PEV.exe moved successfully.
            C:\WINDOWS\NIRCMD.exe moved successfully.
            C:\WINDOWS\MBR.exe moved successfully.
            C:\WINDOWS\grep.exe moved successfully.
            C:\WINDOWS\ERDNT\cache folder moved successfully.
            C:\WINDOWS\ERDNT\Hiv-backup\Users\00000006 folder moved successfully.
            C:\WINDOWS\ERDNT\Hiv-backup\Users\00000005 folder moved successfully.
            C:\WINDOWS\ERDNT\Hiv-backup\Users\00000004 folder moved successfully.
            C:\WINDOWS\ERDNT\Hiv-backup\Users\00000003 folder moved successfully.
            C:\WINDOWS\ERDNT\Hiv-backup\Users\00000002 folder moved successfully.
            C:\WINDOWS\ERDNT\Hiv-backup\Users\00000001 folder moved successfully.
            C:\WINDOWS\ERDNT\Hiv-backup\Users folder moved successfully.
            C:\WINDOWS\ERDNT\Hiv-backup folder moved successfully.
            C:\WINDOWS\ERDNT folder moved successfully.
            C:\Qoobox\BackEnv folder moved successfully.
            C:\Qoobox\Quarantine\C\Program Files\ShoppingReport\Bin\2.6.56 folder moved successfully.
            C:\Qoobox\Quarantine\C\Program Files\ShoppingReport\Bin folder moved successfully.
            C:\Qoobox\Quarantine\C\Program Files\ShoppingReport folder moved successfully.
            C:\Qoobox\Quarantine\C\Program Files\Hotbar\bin\11.0.78.0 folder moved successfully.
            C:\Qoobox\Quarantine\C\Program Files\Hotbar\bin folder moved successfully.
            C:\Qoobox\Quarantine\C\Program Files\Hotbar folder moved successfully.
            C:\Qoobox\Quarantine\C\Program Files folder moved successfully.
            C:\Qoobox\Quarantine\C\Documents and Settings\Acer\Application Data\ShoppingReport\cs\res2 folder moved successfully.
            C:\Qoobox\Quarantine\C\Documents and Settings\Acer\Application Data\ShoppingReport\cs\report folder moved successfully.
            C:\Qoobox\Quarantine\C\Documents and Settings\Acer\Application Data\ShoppingReport\cs\dwld folder moved successfully.
            C:\Qoobox\Quarantine\C\Documents and Settings\Acer\Application Data\ShoppingReport\cs\db folder moved successfully.
            C:\Qoobox\Quarantine\C\Documents and Settings\Acer\Application Data\ShoppingReport\cs folder moved successfully.
            C:\Qoobox\Quarantine\C\Documents and Settings\Acer\Application Data\ShoppingReport folder moved successfully.
            C:\Qoobox\Quarantine\C\Documents and Settings\Acer\Application Data folder moved successfully.
            C:\Qoobox\Quarantine\C\Documents and Settings\Acer folder moved successfully.
            C:\Qoobox\Quarantine\C\Documents and Settings folder moved successfully.
            C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers folder moved successfully.
            C:\Qoobox\Quarantine\C\WINDOWS\system32 folder moved successfully.
            C:\Qoobox\Quarantine\C\WINDOWS folder moved successfully.
            C:\Qoobox\Quarantine\C folder moved successfully.
            C:\Qoobox\Quarantine\Registry_backups folder moved successfully.
            C:\Qoobox\Quarantine folder moved successfully.
            C:\Qoobox folder moved successfully.
            C:\UsbFix\Quarantine\D folder moved successfully.
            C:\UsbFix\Quarantine\C\WINDOWS folder moved successfully.
            C:\UsbFix\Quarantine\C\Documents and Settings\Acer folder moved successfully.
            C:\UsbFix\Quarantine\C\Documents and Settings folder moved successfully.
            C:\UsbFix\Quarantine\C folder moved successfully.
            C:\UsbFix\Quarantine folder moved successfully.
            C:\UsbFix\Backup\Registry 27-12-2009\Users\00000002 folder moved successfully.
            C:\UsbFix\Backup\Registry 27-12-2009\Users\00000001 folder moved successfully.
            C:\UsbFix\Backup\Registry 27-12-2009\Users folder moved successfully.
            C:\UsbFix\Backup\Registry 27-12-2009 folder moved successfully.
            C:\UsbFix\Backup folder moved successfully.
            C:\UsbFix\Tools\Erunt folder moved successfully.
            C:\UsbFix\Tools folder moved successfully.
            C:\UsbFix\Reg folder moved successfully.
            C:\UsbFix\Fich folder moved successfully.
            C:\UsbFix folder moved successfully.
            C:\Program Files\trend micro folder moved successfully.
            C:\rsit folder moved successfully.
            C:\Program Files\Alwil Software\Avast4\Setup folder moved successfully.
            C:\Program Files\Alwil Software\Avast4 folder moved successfully.
            C:\Program Files\Alwil Software folder moved successfully.
            C:\Documents and Settings\All Users\Application Data\sysReserve.ini moved successfully.
            ========== REGISTRY ==========
            Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
            Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
            ========== COMMANDS ==========

            [EMPTYTEMP]

            User: Default User
            ->Temp folder emptied: 0 bytes
            ->Temporary Internet Files folder emptied: 32902 bytes

            User: All Users

            User: NetworkService
            ->Temp folder emptied: 0 bytes
            ->Temporary Internet Files folder emptied: 67 bytes

            User: LocalService
            ->Temp folder emptied: 0 bytes
            ->Temporary Internet Files folder emptied: 65670 bytes

            User: Acer
            ->Temp folder emptied: 314766 bytes
            ->Temporary Internet Files folder emptied: 13767895 bytes

            %systemdrive% .tmp files removed: 0 bytes
            %systemroot% .tmp files removed: 90112 bytes
            %systemroot%\System32 .tmp files removed: 6674944 bytes
            Windows Temp folder emptied: 169 bytes
            %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
            %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 67 bytes
            RecycleBin emptied: 0 bytes

            Total Files Cleaned = 20,00 mb

            OTM by OldTimer - Version 3.1.4.0 log created on 12272009_182921

            Files moved on Reboot...

            Registry entries deleted on Reboot...
            0
            1. Oui ,

              On termine ::

              ▶ Télécharge OTM de OldTimer sur ton Bureau.

              • Double-clique sur OTM.exe afin de le lancer.

              • Copie (Ctrl+C) le texte suivant ci-dessous :

              :processes
              explorer.exe

              :services
              catchme
              Bonjour Service

              :files
              C:\ComboFix.txt
              C:\FOUND.001
              C:\WINDOWS\zip.exe
              C:\WINDOWS\SWXCACLS.exe
              C:\WINDOWS\SWSC.exe
              C:\WINDOWS\SWREG.exe
              C:\WINDOWS\sed.exe
              C:\WINDOWS\PEV.exe
              C:\WINDOWS\NIRCMD.exe
              C:\WINDOWS\MBR.exe
              C:\WINDOWS\grep.exe
              C:\WINDOWS\ERDNT
              C:\Qoobox
              C:\UsbFix
              C:\Program Files\trend micro
              C:\rsit
              C:\Program Files\Alwil Software
              C:\Documents and Settings\All Users\Application Data\sysReserve.ini

              :reg
              [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

              :commands
              [emptytemp]
              [reboot]


              • Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

              • Clique maintenant sur le bouton MoveIt! puis ferme OTM.

              ▶ Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
              ▶ Accepte en cliquant sur YES.

              • Poste le rapport situé dans ce dossier : C:\_OTM\MovedFiles\
              Le nom du rapport correspond au moment de sa création : date_heure.log


              ###########

              Maintenant , nous allons supprimer les logiciels de désinfection que je t'ai fait téléchargé.
              En effet , s'en servir est dangereux pour le pc si l'on ne s'y connais pas.
              De plus ils sont mis régulièrement à jours.

              → Ferme toutes les applications en cours, puis télécharge ToolsCleaner2 sur ton Bureau.

              → Double clique sur ToolsCleaner2.exe
              → Clique sur .Recherche
              → puis sur Suppression quand la liste est trouvée.
              → Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

              (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

              Note : ton bureau RISQUE de disparaître, c'est normal. S'il n'apparaît pas à la fin du scan, fais la manip suivante :

              CTRL+ALT+SUPP pour ouvrir le Gestionnaire des tâches.
              Puis rends toi à l'onglet "Processus". Clique en haut à gauche sur Fichiers et choisis "Exécuter"

              Tape explorer.exe et valide. Cela fera re-apparaître le Bureau

              #################

              *Désactive ta restauration :
              Clique droit sur poste de travail/propriétés/Restauration système/coche la case désactiver la restauration, appliquer, OK
              ---> Redémarre ton PC ...

              *Réactive ta restauration :
              Clique droit sur poste de travail/propriétés/Restauration système/décoche la case désactiver la restauration, appliquer, OK
              --->Redémarre ton PC ...

              ( Note : tu peux aussi y accéder via panneau de configuration->" système "->" restauration système " ).

              Tuto xp : http://service1.symantec.com/support/inter/tsgeninfointl.Nsf/fr_docid/20020830101856924
              0
              1. virus et tout le toin toin supprimé c'est bon?
                0
                1. rapport rsit log.txt

                  Logfile of random's system information tool 1.06 (written by random/random)
                  Run by Acer at 2009-12-27 17:43:25
                  Microsoft Windows XP Édition familiale Service Pack 2
                  System drive C: has 12 GB (27%) free of 46 GB
                  Total RAM: 1022 MB (57% free)

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 17:43:30, on 27/12/2009
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\wltrysvc.exe
                  C:\WINDOWS\System32\bcmwltry.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                  C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  C:\WINDOWS\system32\WLTRAY.exe
                  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                  C:\WINDOWS\SOUNDMAN.EXE
                  C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
                  C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
                  C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                  C:\Program Files\Bonjour\mDNSResponder.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\PixArt\PAC207\Monitor.exe
                  C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
                  C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ArcCon.ac
                  C:\Program Files\acer\eRecovery\Monitor.exe
                  C:\WINDOWS\system32\wuauclt.exe
                  C:\WINDOWS\system32\wscntfy.exe
                  C:\Program Files\internet explorer\iexplore.exe
                  C:\WINDOWS\system32\wuauclt.exe
                  C:\Documents and Settings\Acer\Mes documents\riposte antimalwar\Malwarebytes' Anti-Malware\mbam.exe
                  C:\Documents and Settings\Acer\Bureau\RSIT.exe
                  C:\Program Files\trend micro\Acer.exe

                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
                  O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                  O4 - HKLM\..\Run: [preload] C:\Windows\RUNXMLPL.exe
                  O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                  O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
                  O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                  O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                  O4 - HKLM\..\Run: [eRecoveryService] C:\Windows\System32\Check.exe
                  O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
                  O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
                  O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
                  O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
                  O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe
                  O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
                  O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                  O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                  O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
                  O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                  O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
                  O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                  O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
                  O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
                  O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
                  O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                  O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                  O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                  O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                  O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                  O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
                  0
                  1. Réouvre malewarebyte's , va sur quarantaine et supprime tout .

                    Refais un scan RSIT et post log.txt stp
                    1
                    1. au rapport chef!

                      Malwarebytes' Anti-Malware 1.42
                      Version de la base de données: 3439
                      Windows 5.1.2600 Service Pack 2
                      Internet Explorer 6.0.2900.2180

                      27/12/2009 17:18:57
                      mbam-log-2009-12-27 (17-18-57).txt

                      Type de recherche: Examen rapide
                      Eléments examinés: 104089
                      Temps écoulé: 3 minute(s), 43 second(s)

                      Processus mémoire infecté(s): 1
                      Module(s) mémoire infecté(s): 0
                      Clé(s) du Registre infectée(s): 0
                      Valeur(s) du Registre infectée(s): 1
                      Elément(s) de données du Registre infecté(s): 0
                      Dossier(s) infecté(s): 2
                      Fichier(s) infecté(s): 10

                      Processus mémoire infecté(s):
                      C:\Program Files\Malware Defense\mdefense.exe (Trojan.FakeAlert) -> Unloaded process successfully.

                      Module(s) mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Clé(s) du Registre infectée(s):
                      (Aucun élément nuisible détecté)

                      Valeur(s) du Registre infectée(s):
                      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\malware defense (Trojan.FakeAlert) -> Quarantined and deleted successfully.

                      Elément(s) de données du Registre infecté(s):
                      (Aucun élément nuisible détecté)

                      Dossier(s) infecté(s):
                      C:\Program Files\malware Defense (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Acer\Menu Démarrer\Programmes\malware Defense (Rogue.MalwareDefense) -> Quarantined and deleted successfully.

                      Fichier(s) infecté(s):
                      C:\Program Files\Malware Defense\mdefense.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      C:\Program Files\malware Defense\md.db (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
                      C:\Program Files\malware Defense\mdext.dll (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
                      C:\Program Files\malware Defense\help.ico (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Acer\Menu Démarrer\Programmes\malware Defense\Malware Defense.lnk (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Acer\Menu Démarrer\Programmes\malware Defense\Uninstall Malware Defense.lnk (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Acer\Menu Démarrer\Programmes\malware Defense\Malware Defense Support.lnk (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Acer\Bureau\Malware Defense.lnk (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Acer\Bureau\Malware Defense Support.lnk (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Acer\Application Data\Microsoft\Internet Explorer\Quick Launch\Malware Defense.lnk (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
                      0
                      1. Pas grave ..

                        • Telecharge malwarebytes

                        • Tu l´instale, le programme va se mettre automatiquement a jour.

                        • Une fois a jour, le programme va se lancer.

                        • Click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

                        • Click maintenant sur l´onglet recherche et coche la case : "executer un examen rapide".

                        • Puis click sur "rechercher".

                        • Laisse le scanner le pc...

                        • Si des elements on ete trouvés > click sur supprimer la selection.

                        • Si il t´es demandé de redemarrer > click sur "yes".

                        • A la fin un rapport va s´ouvrir, sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.

                        • Copie et colle le rapport stp.
                        0
                        1. cela m'a demmandé de me conecter parce que je n'ai pas "la console de récupération microsoft windows", mais puisque je ne pouvais pas je n'ai pas pu, donc cela m'a dit que cela ne pouvait pas supprimer correctement...

                          voici le rapport :

                          ComboFix 09-12-26.05 - Acer 27/12/2009 16:46:14.1.1 - FAT32x86
                          Lancé depuis: c:\documents and settings\Acer\Bureau\killbagle.exe
                          AV: Avira AntiVir PersonalEdition Classic *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}

                          AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
                          .

                          (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                          .

                          c:\docume~1\Acer\LOCALS~1\Temp\wscsvc32.exe
                          c:\documents and settings\Acer\Application Data\ShoppingReport
                          c:\documents and settings\Acer\Application Data\ShoppingReport\cs\Config.xml
                          c:\documents and settings\Acer\Application Data\ShoppingReport\cs\db\Aliases.dbs
                          c:\documents and settings\Acer\Application Data\ShoppingReport\cs\db\Sites.dbs
                          c:\documents and settings\Acer\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
                          c:\documents and settings\Acer\Application Data\ShoppingReport\cs\report\aggr_storage.xml
                          c:\documents and settings\Acer\Application Data\ShoppingReport\cs\report\send_storage.xml
                          c:\documents and settings\Acer\Application Data\ShoppingReport\cs\res2\WhiteList.dbs
                          c:\program files\Hotbar
                          c:\program files\Hotbar\bin\11.0.78.0\CntntCntr.dll
                          c:\program files\Hotbar\bin\11.0.78.0\HostIE.dll
                          c:\program files\Hotbar\bin\11.0.78.0\HostOL.dll
                          c:\program files\Hotbar\bin\11.0.78.0\Toolbar.dll
                          c:\program files\ShoppingReport
                          c:\program files\ShoppingReport\Bin\2.6.56\ShoppingReport.dll
                          c:\program files\ShoppingReport\Uninst.exe
                          c:\windows\system32\drivers\H8SRTutkqpmebwi.sys
                          c:\windows\system32\H8SRTfcyowpepsh.dll
                          c:\windows\system32\H8SRTgoqypltwrd.dat
                          c:\windows\system32\H8SRTpkxqhsmybx.dll
                          c:\windows\system32\krl32mainweq.dll
                          c:\windows\system32\srcr.dat

                          .
                          ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                          .

                          -------\Service_H8SRTd.sys
                          -------\Legacy_H8SRTd.sys

                          ((((((((((((((((((((((((((((( Fichiers créés du 2009-11-27 au 2009-12-27 ))))))))))))))))))))))))))))))))))))
                          .

                          2009-12-27 15:43 . 2009-12-27 15:43 -------- d-----w- C:\FOUND.001
                          2009-12-27 14:39 . 2009-12-27 14:40 -------- d-----w- C:\UsbFix
                          2009-12-27 14:26 . 2009-12-27 14:26 -------- d-----w- c:\program files\trend micro
                          2009-12-27 14:26 . 2009-12-27 14:26 -------- d-----w- C:\rsit
                          2009-12-27 12:43 . 2009-12-03 15:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
                          2009-12-27 12:43 . 2009-12-27 12:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
                          2009-12-27 12:43 . 2009-12-03 15:13 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
                          2009-12-27 12:22 . 2009-12-27 12:22 -------- d-----w- c:\program files\Malware Defense
                          2009-12-27 11:30 . 2008-10-30 09:21 75072 ----a-w- c:\windows\system32\drivers\avipbb.sys
                          2009-12-27 11:30 . 2008-05-09 11:15 45376 ----a-w- c:\windows\system32\drivers\avgntdd.sys
                          2009-12-27 11:30 . 2008-01-21 16:11 22336 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
                          2009-12-27 11:30 . 2009-12-27 11:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
                          2009-12-24 17:37 . 2009-12-24 17:37 -------- d-----w- c:\documents and settings\Acer\Local Settings\Application Data\Help
                          2009-12-24 16:37 . 2009-12-24 16:37 -------- d-----w- c:\program files\Avira
                          2009-12-24 12:10 . 2009-12-24 12:10 -------- d-----w- c:\program files\Alwil Software
                          2009-12-24 11:48 . 2009-03-24 15:08 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
                          2009-12-07 10:28 . 2009-12-07 10:28 -------- d-----w- c:\program files\Audacity
                          2009-12-04 09:55 . 2009-12-04 09:55 -------- d-----w- c:\program files\Microsoft Silverlight

                          .
                          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                          .
                          2009-12-27 11:48 . 2008-04-17 05:39 90112 ----a-w- c:\windows\DUMP613a.tmp
                          2009-12-24 17:54 . 1979-12-31 23:00 65800 ----a-w- c:\windows\system32\perfc00C.dat
                          2009-11-21 17:41 . 2009-11-21 17:41 -------- d-----w- c:\program files\GiveMeTac 1.1
                          2009-11-13 15:01 . 2009-11-13 15:01 -------- d-----w- c:\program files\Microsoft
                          2009-11-13 15:01 . 2009-11-13 15:01 -------- d-----w- c:\program files\Windows Live SkyDrive
                          2009-11-13 14:57 . 2009-11-13 14:57 -------- d-----w- c:\program files\Fichiers communs\Windows Live
                          2009-10-29 05:46 . 1979-12-31 23:00 666112 ----a-w- c:\windows\system32\wininet.dll
                          2009-10-21 18:27 . 2009-10-21 18:26 664 ----a-w- c:\windows\system32\d3d9caps.dat
                          2009-10-21 06:03 . 1979-12-31 23:00 75776 ----a-w- c:\windows\system32\strmfilt.dll
                          2009-10-21 06:03 . 1979-12-31 23:00 25088 ----a-w- c:\windows\system32\httpapi.dll
                          2009-10-20 14:58 . 2004-08-03 22:00 263552 ----a-w- c:\windows\system32\drivers\http.sys
                          2009-10-20 00:07 . 2009-10-20 00:07 3084288 ----a-w- c:\windows\system32\SET19.tmp
                          2009-10-14 17:28 . 2008-04-21 19:18 86472 ----a-w- c:\documents and settings\Acer\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
                          2009-10-13 10:52 . 1979-12-31 23:00 267776 ----a-w- c:\windows\system32\oakley.dll
                          2009-10-12 13:52 . 1979-12-31 23:00 69632 ----a-w- c:\windows\system32\raschap.dll
                          2009-10-12 13:52 . 1979-12-31 23:00 113152 ----a-w- c:\windows\system32\rastls.dll
                          .

                          ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                          .
                          .
                          *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                          REGEDIT4

                          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-14 39408]
                          "Malware Defense"="c:\program files\Malware Defense\mdefense.exe" [2009-12-27 1756088]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY" [X]
                          "preload"="c:\windows\RUNXMLPL.exe" [2004-04-20 40960]
                          "SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-05 98394]
                          "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-05 688218]
                          "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-04-05 339968]
                          "SoundMan"="SOUNDMAN.EXE" [2005-08-17 90112]
                          "eRecoveryService"="c:\windows\System32\Check.exe" [2005-03-23 245760]
                          "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe" [2005-06-23 57344]
                          "CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 644696]
                          "SSBkgdUpdate"="c:\program files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
                          "OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
                          "Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
                          "ArcSoft Connection Service"="c:\program files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2009-10-10 203264]
                          "avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]

                          [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                          "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-05 15360]

                          c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                          Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
                          Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]

                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
                          "HonorAutoRunSetting"= 0 (0x0)

                          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
                          "HonorAutoRunSetting"= 0 (0x0)

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
                          2007-04-03 17:50 1603152 ----a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malware Defense]
                          2009-12-27 14:35 1756088 ----a-w- c:\program files\Malware Defense\mdefense.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Profiler]
                          2005-06-14 14:23 159744 ----a-w- c:\program files\Saitek\Software\Profiler.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SaiMfd]
                          2005-06-17 18:02 126976 ----a-w- c:\program files\Saitek\Software\SaiMfd.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
                          2005-10-26 16:17 159744 ----a-r- c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe

                          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                          "EnableFirewall"= 0 (0x0)

                          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                          "%windir%\\system32\\sessmgr.exe"=
                          "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
                          "c:\\Program Files\\Messenger\\MSMSGS.EXE"=
                          "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
                          "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
                          "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

                          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
                          "17630:TCP"= 17630:TCP:NortonAV
                          "13314:TCP"= 13314:TCP:NortonAV
                          "14829:TCP"= 14829:TCP:NortonAV
                          "15910:TCP"= 15910:TCP:NortonAV
                          "12431:TCP"= 12431:TCP:NortonAV
                          "16427:TCP"= 16427:TCP:NortonAV
                          "13519:TCP"= 13519:TCP:NortonAV
                          "14274:TCP"= 14274:TCP:NortonAV
                          "14739:TCP"= 14739:TCP:NortonAV
                          "16794:TCP"= 16794:TCP:NortonAV
                          "17848:TCP"= 17848:TCP:NortonAV
                          "14118:TCP"= 14118:TCP:NortonAV
                          "15673:TCP"= 15673:TCP:NortonAV
                          "14168:TCP"= 14168:TCP:NortonAV
                          "13049:TCP"= 13049:TCP:NortonAV
                          "13837:TCP"= 13837:TCP:NortonAV
                          "16615:TCP"= 16615:TCP:NortonAV
                          "17744:TCP"= 17744:TCP:NortonAV
                          "15814:TCP"= 15814:TCP:NortonAV
                          "18322:TCP"= 18322:TCP:NortonAV
                          "15539:TCP"= 15539:TCP:NortonAV
                          "16926:TCP"= 16926:TCP:NortonAV
                          "13297:TCP"= 13297:TCP:NortonAV
                          "12531:TCP"= 12531:TCP:NortonAV
                          "15042:TCP"= 15042:TCP:NortonAV
                          "15441:TCP"= 15441:TCP:NortonAV
                          "16287:TCP"= 16287:TCP:NortonAV
                          "13395:TCP"= 13395:TCP:NortonAV
                          "16724:TCP"= 16724:TCP:NortonAV
                          "14611:TCP"= 14611:TCP:NortonAV
                          "12223:TCP"= 12223:TCP:NortonAV
                          "16470:TCP"= 16470:TCP:NortonAV

                          R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [01/01/1980 200192]
                          S3 PAC207;Webcam 1200;c:\windows\system32\drivers\PFC027.SYS [11/09/2009 18:57 611584]
                          S3 SI15CI;SI15CI;\??\c:\elements\1stboot\SI15CI.SYS --> c:\elements\1stboot\SI15CI.SYS [?]
                          .
                          ------- Examen supplémentaire -------
                          .
                          uSearch Page = hxxp://www.google.com
                          uSearch Bar = hxxp://www.google.com/ie
                          mDefault_Search_URL = hxxp://www.google.com/ie
                          uInternet Settings,ProxyOverride = *.local
                          uSearchAssistant = hxxp://www.google.com/ie
                          uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
                          mSearchAssistant = hxxp://www.google.com/ie
                          IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
                          IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
                          .
                          - - - - ORPHELINS SUPPRIMES - - - -

                          WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
                          AddRemove-Malware Defense - c:\program files\Malware Defense\Uninstall.exe

                          **************************************************************************

                          catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                          Rootkit scan 2009-12-27 16:52
                          Windows 5.1.2600 Service Pack 2 FAT NTAPI

                          Recherche de processus cachés ...

                          Recherche d'éléments en démarrage automatique cachés ...

                          Recherche de fichiers cachés ...

                          Scan terminé avec succès
                          Fichiers cachés: 0

                          **************************************************************************
                          .
                          --------------------- DLLs chargées dans les processus actifs ---------------------

                          - - - - - - - > 'winlogon.exe'(840)
                          c:\windows\system32\Ati2evxx.dll
                          c:\windows\System32\BCMLogon.dll

                          - - - - - - - > 'explorer.exe'(1248)
                          c:\program files\ScanSoft\OmniPageSE4\OpHookSE4.dll
                          c:\windows\system32\msi.dll
                          c:\windows\system32\WPDShServiceObj.dll
                          c:\windows\system32\PortableDeviceTypes.dll
                          c:\windows\system32\PortableDeviceApi.dll
                          .
                          ------------------------ Autres processus actifs ------------------------
                          .
                          c:\windows\system32\Ati2evxx.exe
                          c:\windows\system32\Ati2evxx.exe
                          c:\windows\System32\wltrysvc.exe
                          c:\windows\System32\bcmwltry.exe
                          c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
                          c:\program files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
                          c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                          c:\program files\Bonjour\mDNSResponder.exe
                          c:\windows\system32\WLTRAY.exe
                          c:\windows\SOUNDMAN.EXE
                          c:\program files\Fichiers communs\ArcSoft\Connection Service\Bin\ArcCon.ac
                          c:\program files\acer\eRecovery\Monitor.exe
                          c:\windows\system32\rundll32.exe
                          .
                          **************************************************************************
                          .
                          Heure de fin: 2009-12-27 16:57:32 - La machine a redémarré
                          ComboFix-quarantined-files.txt 2009-12-27 15:57

                          Avant-CF: 12 948 832 256 octets libres
                          Après-CF: 12 969 967 616 octets libres

                          - - End Of File - - E0DCCD8317FEAA6BD6666251DC7DBC25
                          0
                          1. Génial , oui il y a quelques bebetes en stock :) Cela sert pour test , pour améliorer les outils .

                            Télécharge combofix : http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                            Avant de telecharger clic sur enregistrer renome le en killbagle et enregistre le sur le bureau

                            -> Double clique sur killbagle.exe.
                            -> Tape sur la touche 1 (Yes) pour démarrer le scan.
                            -> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

                            NOTE : Le rapport se trouve également ici : C:\Combofix.txt

                            Avant d'utiliser ComboFix :

                            -> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.

                            Une fois fait, sur ton bureau double-clic sur killbagle.exe.

                            - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

                            /!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.

                            - En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

                            - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

                            -> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.
                            0
                            1. c'est fait

                              y a pas plein de virus la dedans??
                              0
                              1. Rend moi un service ,

                                J aimerais que tu me fasses parvenir 2 fichiers infectieux :

                                • Affiche tous les fichiers et dossiers :

                                • Clique sur démarrer/panneau de configuration/option des dossiers/affichage

                                • Cocher afficher les dossiers cacher

                                • Décocher la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

                                • Décocher masquer les extensions dont le type est connu

                                • Puis fais «appliquer» pour valider les changements.

                                • Et OK

                                Rend toi à ces fichiers :

                                C:\DOCUME~1\Acer\LOCALS~1\Temp\richtx64.exe
                                C:\DOCUME~1\Acer\LOCALS~1\Temp\wscsvc32.exe

                                fais les moi parvenir ici stp :

                                https://www.ionos.fr/?affiliate_id=77097

                                Dis moi quand c est fais .
                                0
                                1. C:\Rsit\Log.txt

                                  Logfile of random's system information tool 1.06 (written by random/random)
                                  Run by Acer at 2009-12-27 15:26:26
                                  Microsoft Windows XP Édition familiale Service Pack 2
                                  System drive C: has 12 GB (27%) free of 46 GB
                                  Total RAM: 1022 MB (53% free)

                                  Logfile of Trend Micro HijackThis v2.0.2
                                  Scan saved at 15:27:59, on 27/12/2009
                                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                                  MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                                  Boot mode: Normal

                                  Running processes:
                                  C:\WINDOWS\System32\smss.exe
                                  C:\WINDOWS\system32\winlogon.exe
                                  C:\WINDOWS\system32\services.exe
                                  C:\WINDOWS\system32\lsass.exe
                                  C:\WINDOWS\system32\Ati2evxx.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\system32\Ati2evxx.exe
                                  C:\WINDOWS\Explorer.EXE
                                  C:\WINDOWS\System32\wltrysvc.exe
                                  C:\WINDOWS\System32\bcmwltry.exe
                                  C:\WINDOWS\system32\spoolsv.exe
                                  C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
                                  C:\Program Files\Bonjour\mDNSResponder.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                                  C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                  C:\WINDOWS\system32\WLTRAY.exe
                                  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                                  C:\WINDOWS\SOUNDMAN.EXE
                                  C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
                                  C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
                                  C:\WINDOWS\PixArt\PAC207\Monitor.exe
                                  C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
                                  C:\WINDOWS\system32\ctfmon.exe
                                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                  C:\DOCUME~1\Acer\LOCALS~1\Temp\richtx64.exe
                                  C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ArcCon.ac
                                  C:\Program Files\acer\eRecovery\Monitor.exe
                                  C:\WINDOWS\system32\wuauclt.exe
                                  C:\Program Files\Internet Explorer\iexplore.exe
                                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                  C:\DOCUME~1\Acer\LOCALS~1\Temp\wscsvc32.exe
                                  C:\Documents and Settings\Acer\Bureau\RSIT.exe
                                  C:\Program Files\trend micro\Acer.exe
                                  C:\Program Files\Internet Explorer\Iexplore.exe

                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://uk.ask.com
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.acer.com/worldwide/selection.html
                                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                  O2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - C:\Program Files\ShoppingReport\Bin\2.6.56\ShoppingReport.dll
                                  O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
                                  O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                                  O4 - HKLM\..\Run: [preload] C:\Windows\RUNXMLPL.exe
                                  O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                                  O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                  O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
                                  O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                                  O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                                  O4 - HKLM\..\Run: [eRecoveryService] C:\Windows\System32\Check.exe
                                  O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
                                  O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
                                  O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
                                  O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
                                  O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe
                                  O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
                                  O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                                  O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Documents and Settings\Acer\Mes documents\riposte antimalwar\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
                                  O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                                  O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                                  O4 - HKCU\..\Run: [richtx64.exe] C:\DOCUME~1\Acer\LOCALS~1\Temp\richtx64.exe
                                  O4 - HKCU\..\Run: [Malware Defense] "C:\Program Files\Malware Defense\mdefense.exe" -noscan
                                  O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                  O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                  O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
                                  O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
                                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                                  O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
                                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                                  O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShoppingReport\Bin\2.6.56\ShoppingReport.dll
                                  O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShoppingReport\Bin\2.6.56\ShoppingReport.dll
                                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                  O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
                                  O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                                  O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
                                  O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
                                  O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
                                  O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                  O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                  O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                                  O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                  O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                                  O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
                                  0
                                  1. Oui c est ça :)

                                    post le rapport : C:\Rsit\Log.txt maintenant .
                                    0
                                    1. c'est ça?

                                      ############################## | UsbFix V6.067 |

                                      User : Acer (Administrateurs) # ACER-D18848DB56
                                      Update on 24/12/2009 by Chiquitine29, C_XX & Chimay8
                                      Start at: 15:43:31 | 27/12/2009
                                      Website : http://pagesperso-orange.fr/NosTools/index.html
                                      Contact : FindyKill.Contact@gmail.com

                                      AMD Turion(tm) 64 Mobile Technology ML-30
                                      Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 2
                                      Internet Explorer 6.0.2900.2180
                                      Windows Firewall Status : Disabled
                                      AV : Malware Defense 1.0 [ Enabled | (!) Outdated ]
                                      AV : Avira AntiVir PersonalEdition Classic 8.0.1.30 [ (!) Disabled | (!) Outdated ]

                                      C:\ -> Disque fixe local # 45,15 Go (12,13 Go free) [ACER] # FAT32
                                      D:\ -> Disque fixe local # 45,54 Go (16,75 Go free) [ACERDATA] # FAT32
                                      E:\ -> Disque CD-ROM

                                      ############################## | Processus actifs |

                                      C:\WINDOWS\System32\smss.exe 748
                                      C:\WINDOWS\system32\csrss.exe 820
                                      C:\WINDOWS\system32\winlogon.exe 844
                                      C:\WINDOWS\system32\services.exe 888
                                      C:\WINDOWS\system32\lsass.exe 900
                                      C:\WINDOWS\system32\Ati2evxx.exe 1056
                                      C:\WINDOWS\system32\svchost.exe 1068
                                      C:\WINDOWS\system32\svchost.exe 1436
                                      C:\WINDOWS\System32\svchost.exe 1612
                                      C:\WINDOWS\system32\svchost.exe 1644
                                      C:\WINDOWS\system32\logonui.exe 1676
                                      C:\WINDOWS\system32\svchost.exe 1872
                                      C:\WINDOWS\system32\Ati2evxx.exe 1892
                                      C:\WINDOWS\system32\svchost.exe 196
                                      C:\WINDOWS\Explorer.EXE 212
                                      C:\Program Files\Internet Explorer\Iexplore.exe 372
                                      C:\WINDOWS\System32\wltrysvc.exe 624
                                      C:\WINDOWS\System32\bcmwltry.exe 652
                                      C:\WINDOWS\system32\spoolsv.exe 780
                                      C:\WINDOWS\system32\svchost.exe 1996
                                      C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe 2024
                                      C:\Program Files\Bonjour\mDNSResponder.exe 2044
                                      C:\WINDOWS\system32\svchost.exe 432
                                      C:\WINDOWS\system32\wuauclt.exe 1372
                                      C:\WINDOWS\system32\wbem\wmiprvse.exe 532
                                      C:\WINDOWS\System32\alg.exe 352
                                      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe 2088
                                      C:\WINDOWS\system32\wbem\wmiprvse.exe 2096
                                      C:\WINDOWS\system32\rundll32.exe 2576

                                      ################## | Elements infectieux |

                                      Supprimé ! C:\Documents and Settings\Acer\RavMonLog
                                      Supprimé ! C:\WINDOWS\AhnRpta.exe
                                      C:\autorun.inf -> fichier appelé : "C:\xmor.exe" ( Absent ! )
                                      Supprimé ! C:\autorun.inf
                                      D:\autorun.inf -> fichier appelé : "D:\xmor.exe" ( Absent ! )
                                      Supprimé ! D:\autorun.inf

                                      ################## | Registre |

                                      Supprimé ! [HKLM\SOFTWARE\Classes\CLSID\MADOWN]
                                      Supprimé ! [HKCR\CLSID\{bb4c402f-882a-4526-8c08-51278ea437c1}]
                                      Supprimé ! [HKLM\SYSTEM\CurrentControlSet\Services\AVPsys]
                                      Supprimé ! [HKLM\SYSTEM\ControlSet003\Services\AVPsys]

                                      ################## | Mountpoints2 |

                                      Supprimé ! HKCU\...\Explorer\MountPoints2\{1817867c-35f5-11dd-ac8a-0014a45d33d7}\Shell\Auto\Command
                                      Supprimé ! HKCU\...\Explorer\MountPoints2\{1817867d-35f5-11dd-ac8a-0014a45d33d7}\Shell\Auto\Command
                                      Supprimé ! HKCU\...\Explorer\MountPoints2\{2a92ee3c-c284-11de-adde-000ae4e6bb89}\Shell\AutoRun\Command
                                      Supprimé ! HKCU\...\Explorer\MountPoints2\{2d348b76-a607-11de-adab-0014a45d33d7}\Shell\AutoRun\Command
                                      Supprimé ! HKCU\...\Explorer\MountPoints2\{36b0d930-db27-11dd-acbf-0014a45d33d7}\Shell\AutoRun\Command
                                      Supprimé ! HKCU\...\Explorer\MountPoints2\{37e47e6a-0c38-11dd-ac77-806d6172696f}\Shell\AutoRun\Command
                                      Supprimé ! HKCU\...\Explorer\MountPoints2\{37e47e6b-0c38-11dd-ac77-806d6172696f}\Shell\AutoRun\Command
                                      Supprimé ! HKCU\...\Explorer\MountPoints2\{3a671c9c-c677-11de-ade9-0014a45d33d7}\Shell\AutoRun\Command
                                      Supprimé ! HKCU\...\Explorer\MountPoints2\{3df5f954-c29f-11de-addf-000ae4e6bb89}\Shell\AutoRun\Command
                                      Supprimé ! HKCU\...\Explorer\MountPoints2\{3f2afff8-0c9d-11de-ace4-0014a45d33d7}\Shell\AutoRun\Command
                                      Supprimé ! HKCU\...\Explorer\MountPoints2\{3f2afff9-0c9d-11de-ace4-0014a45d33d7}\Shell\AutoRun\Command
                                      Supprimé ! HKCU\...\Explorer\MountPoints2\{4b55c71c-df70-11de-ae1c-0014a45d33d7}\Shell\AutoRun\Command
                                      Supprimé ! HKCU\...\Explorer\MountPoints2\{7f234438-4bb5-11de-ad47-0014a45d33d7}\Shell\AutoRun\Command
                                      Supprimé ! HKCU\...\Explorer\MountPoints2\{a00b202e-0eb4-11dd-ac7b-0014a45d33d7}\Shell\AutoRun\Command
                                      Supprimé ! HKCU\...\Explorer\MountPoints2\{a5e481a7-cb2e-11de-adf4-0014a45d33d7}\Shell\AutoRun\Command
                                      Supprimé ! HKCU\...\Explorer\MountPoints2\{ba9c9a07-0a4b-11de-ace3-0014a45d33d7}\Shell\AutoRun\Command
                                      Supprimé ! HKCU\...\Explorer\MountPoints2\{d5da7cfc-ab73-11dd-acaa-0014a45d33d7}\Shell\Auto\Command
                                      Supprimé ! HKCU\...\Explorer\MountPoints2\{eedfa2aa-5414-11de-ad50-0014a45d33d7}\Shell\AutoRun\Command
                                      Supprimé ! HKCU\...\Explorer\MountPoints2\{f44b549c-d8d4-11de-ae0f-0014a45d33d7}\Shell\AutoRun\Command

                                      ################## | Listing des fichiers présent |

                                      [?|?|?] C:\pagefile.sys
                                      [15/10/2004 11:41|---hs----|512] C:\BOOTSECT.DOS
                                      [05/08/2004 05:00|-rahs----|4952] C:\Bootfont.bin
                                      [05/08/2004 05:00|-rahs----|251712] C:\ntldr
                                      [05/08/2004 05:00|-rahs----|47564] C:\NTDETECT.COM
                                      [24/12/2009 18:03|-rahs----|194] C:\BOOT.INI
                                      [07/04/2005 14:13|--a------|4] C:\wps.dat
                                      [08/04/2005 15:11|-rahs----|65] C:\PRELOAD.AAA
                                      [07/04/2005 14:19|--a------|167] C:\bcmwl5.log
                                      [08/04/2005 15:11|-rahs----|65] C:\PRELOAD.REV
                                      [?|?|?] C:\hiberfil.sys
                                      [17/04/2008 06:53|-rahs----|0] C:\MSDOS.SYS
                                      [17/04/2008 06:53|-rahs----|0] C:\IO.SYS
                                      [27/12/2009 15:45|--a------|5315] C:\UsbFix.txt
                                      [28/09/2009 00:06|--a------|230432] C:\PA207.DAT
                                      [12/10/2008 18:15|--a------|2402832] C:\WLinstaller.exe
                                      [12/10/2008 18:19|--a------|14566424] C:\vlc-0.9.4-win32.exe
                                      [20/10/2008 16:24|--a------|59392] C:\windows installer 3.1 EULA.doc
                                      [20/10/2008 16:26|--a------|2585872] C:\WindowsInstaller-KB893803-v2-x86.exe
                                      [15/06/2008 13:27|--a------|4991480] D:\Un Ricard dans un verre … ballon.m4a
                                      [15/06/2008 16:33|--a------|3472765] D:\The World Is Mine.m4a
                                      [07/12/2009 11:27|--a------|2228534] D:\audacity-win-1.2.6.exe
                                      [10/12/2009 16:30|--a------|13617] D:\[MONOVA[1].ORG] Le Tombeau des lucioles FRENCH DVDRip CinefeeL avi mistery51.torrent

                                      ################## | Vaccination |

                                      # C:\autorun.inf -> Dossier créé par UsbFix.
                                      # D:\autorun.inf -> Dossier créé par UsbFix.

                                      ################## | Cracks / Keygens / Serials |
                                      0
                                      1. Fais ceci alors :

                                        • Télécharge UsbFix sur ton bureau .

                                        (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d avoir été infectés sans les ouvrir

                                        • Double clic sur "UsbFix.exe" présent sur ton bureau .

                                        • Choisis l' option F pour français et et tape sur [entrée] .

                                        • choisis l'option 2 ( Suppression ) et tape sur [entrée].

                                        • Ton bureau disparaitra et le pc redémarrera .

                                        • Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.

                                        • Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .

                                        • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

                                        ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                                        • Tuto : http://pagesperso-orange.fr/NosTools/usbfix.html
                                        0
                                        • 1
                                        • 2