Advanced system protector

Résolu
Bonjour, voila j'ai un petit soucis,en allumant mon ordi aujourd'hui,il me demande de faire une mise a jour de oovoo,ok je le laisse faire puis j'ai une panne de courant,je le rallume donc et la j'ai 2 logiciel qui ce sont installer et impossible de les désinstaller,c'est "advanced system protector" et "regclean pro",je ne sais pas du tout ce que c'est ces 2logiciel mais il me bloque mon ordi,et impossible de les desinstaller,si quelqu'un peut m'aider,je vous remercie d'avance,cordialement.....

85 réponses

Résumé de la discussion

Suite à une mise à jour d’Oovoo déclenchée par le système, l’ordinateur sous Windows Vista est revenu avec deux logiciels indésirables (rogue), Advanced System Protector et RegClean Pro, qui bloquent le fonctionnement et restent réinstallables. Des réponses recommandent des outils de détection/désinfection comme RogueKiller ou MBAM, et des méthodes manuelles via OTLPE et USBFix pour nettoyer les éléments infectieux et le registre. Des utilisateurs indiquent l’importance d’éteindre l’antivirus temporairement si nécessaire, d’éviter d’ouvrir les éléments suspects et de vérifier les exécutions suspectes dans le gestionnaire de tâches et le registre. En dernier, la situation se termine par une remise à zéro d’usine sur les machines, solution radicale mais efficace lorsque les outils de nettoyage ne suffisent pas.

Bobot (l’IA à votre service)
  1. Bonjour

    En lisant ce poste " que de déboire " vous avez eu, je poste juste pour info.

    Tous les sites dont le mot "Soft" est incorporé dans le nom,
    ( Softsonic/Softpédia/Ect...ainsi que 01.Net) sont a bannir, surtout ne téléchargez jamais sur ce genre de site car ils modifient les programmes en incorporant des nuisibles, j'ai constaté également ( (WajamUpdater) "danger" /Ask toolbar/PC-Doctor/RegClean Pro ) ne jamais réinstaller ces soft "" DANGER ""

    Ce qu'il faut pour pc propre et sécurisé MalwareByte /Ccleaner /et Anti-virus
    vous avez Norton pas très cool comme anti-virus, si vous l'avez eu gratuitement ou avec Orange, choisissez-en un autre plus compétant ( Bitdefender le plus sur actuellement ) en plus vous pouvez avoir la version 2/3 postes pour deux ans a prix très raisonnable. Bitdefender Internet Sécurity. En magasin 30/40 euros env. (ne pas acheter en téléchargement en ligne + cher)

    Ne pas installer le logiciel de chez Orange une vraie daube ralenti connexions (mon F.A.I c'est Orange).
    Evitez également Internet Explorer (aspirateur de virus certifier conforme à Microsoft) "LOL"

    Quand vous faite un scan avec Malwarebyte si il trouve des nuisibles il faut cliquer sur "Voir résultat" bas droite de fenêtre et ensuite dans nouvelles fenêtre cliquer sur supprimer.

    Pour Ccleaner >>> https://www.ccleaner.com/ccleaner/download télécharger uniquement sur ce lien.
    1. bonjour,excuse pour mon silence mais je voulais juste te dire que j'ai reussi a remettre mes 2 ordi a sortie d'usine donc voila plus de probleme maintenant
      je te remercie beaucoup pour ton aide.

      a++ sabrina..
      1. oki non je n'ai rien d'important,en faite si tu veux c'est un copain qui me l'avait donner quand j'etais tomber un panne avec le hp,et en plus il y a enormenent de chose dessus que je ne me sert pas,il est presque plein donc c'etait une opportunité de le remetre a zero..

        j'ai donc regarder un peu sur le site et pour le reformater ils disent "alt" "f10" au demarrage,c'est bien comme ca ?
        1. Contributeur sécurité
          En effet ce n'est pas normal. Si tu n'as rien d'important sur ce PC Acer, c'est bien de le remettre en configuration Usine

          Smart
          1. bonjour pas de souci,non il na toujours pas fini,ecran noir et toujours en train de nettoyer, un peu long non?
            sinon je pensais directement le remettre a zero comme ca plus rien,il serait propre,qu'en pense tu ?

            soigne toi bien!!
            1. Contributeur sécurité
              Désolé de te répondre si tard mais j'ai été malade tout le week-end et je commences à peine à émerger.

              Peux-tu me dire si USBFix a fait son boulot. Regarde s'il y a un rapport à la racine du disque C:

              Smart
              1. bonjour,voila juste pour te dire le l'ordi acer tourne toujours depuis 22h hier soir,mon ecran est tout noir et semble travailler,je le vois par rapport a ma clé usb qui est allumer..

                j'espere que c'est normal et qu'il n'a pas beuguer..

                je pars travailler,je serai dispo a 18h30..
                1. Contributeur sécurité
                  "ces cd je ne pourrait plus les utiliser? ils disent utilisable une seul fois."

                  Je pense qu'il faut comprendre que ces CD, on ne peut les graver qu'une seule fois, car il existe des CD réinscriptibles. Je serais étonne que tu ne puisses réutiliser tes CD de restauration.

                  Smart
                  "Si tu n'as pas d'ambitions, tu t'installes au bord de la chute" (Kundera)
                  1. oki ,pas de souci pour le cd j'en ai d'autre c'est pas un pbm,un peu triste pour le HP mais si il faut le restaurer on le fera

                    par contre juste une parenthese,javais eu un pbm avec le disue dur que j'avais donc changer,je l'avais remplacer par un nouveau disque dur et avait utiliser mes cd de reinstallation,ceux que j'avais graver une fois l'ordi neuf,ces cd je ne pourrait plus les utiliser? ils disent utilisable une seul fois... enfin tu me dira comment faire au moment voulu..

                    je continu donc ce que tu viens de m'envoyer..
                    1. Contributeur sécurité
                      Je ne pense qu'il soit nécessaire de faire une restauration usine du PC Acer. En revanche il est fort possible qu'on le fasse sur le PC HP.

                      Juste pour te tenir informer , la clé USB était bien infectée ainsi que le CD. Pour ce dernier on le voit ici ==>
                      Présent! E:\reatogoMenu.exe
                      Présent! E:\AUTORUN.INF

                      On va supprimer les infections sur le PC et la clé USB, malheureusement ce n'est pas possible sur le CD. ET on va vacciner le PC et la clé

                      Dans la procédure qui suit, n'insère pas le CD OTLPE dans le lecteur

                      - Branche tes sources de données externes à ton PC (clé USB, disque dur externe, etc...) sans les ouvrir
                      - Double clique sur le raccourci UsbFix sur ton Bureau
                      - Clique sur "Suppression"
                      - Laisse travailler l'outil
                      - Ton Bureau va disparaitre puis l'ordinateur va redémarrer : c'est normal
                      - A la fin, le rapport va s'afficher : poste le dans ta prochaine réponse (il est aussi sauvegardé a la racine du disque dur)

                      Smart
                      1. si tout fois tu prefere qu'on remettre l'ordi acer a zero,sorti d'usine,sa ne derange pas,je n'ai rien d'important dessus..

                        il faudra juste me guider pour le faire..
                        1. ############################## | UsbFix V 7.102 | [Recherche]

                          Utilisateur: Chris (Administrateur) # PC-DE-CHRIS
                          Mis à jour le 20/12/2012 par El Desaparecido
                          Lancé à 20:40:45 | 25/01/2013

                          Site Web: https://www.sosvirus.net/
                          Contact: contact@eldesaparecido.com

                          PC: Acer (Aspire 5315 ) (X86-based PC
                          CPU: Intel(R) Celeron(R) CPU 550 @ 2.00GHz (1995)
                          RAM -> [Total : 2037 | Free : 860]
                          BIOS: Default System BIOS
                          BOOT: Normal boot

                          OS: Microsoft® Windows Vista(TM) Édition Familiale Basique (6.0.6002 32-Bit) # Service Pack 2
                          WB: Windows Internet Explorer 9.0.8112.16421

                          SC: Security Center Service [Enabled]
                          WU: Windows Update Service [Enabled]
                          AS: Windows Defender [Enabled | Updated]
                          FW: Windows FireWall Service [Enabled]

                          C:\ (%systemdrive%) -> Disque fixe # 50 Go (4 Go libre(s) - 8%) [ACER] # NTFS
                          D:\ -> Disque fixe # 50 Go (25 Go libre(s) - 51%) [DATA] # NTFS
                          E:\ -> CD-ROM
                          F:\ -> Disque amovible # 488 Mo (390 Mo libre(s) - 80%) [] # FAT

                          ################## | Processus Actif |

                          C:\Windows\system32\csrss.exe (492)
                          C:\Windows\system32\wininit.exe (536)
                          C:\Windows\system32\csrss.exe (544)
                          C:\Windows\system32\services.exe (584)
                          C:\Windows\system32\lsass.exe (600)
                          C:\Windows\system32\lsm.exe (608)
                          C:\Windows\system32\winlogon.exe (632)
                          C:\Windows\system32\svchost.exe (804)
                          C:\Windows\system32\svchost.exe (868)
                          C:\Windows\System32\svchost.exe (900)
                          C:\Windows\System32\svchost.exe (1004)
                          C:\Windows\System32\svchost.exe (1056)
                          C:\Windows\system32\svchost.exe (1072)
                          C:\Windows\system32\svchost.exe (1168)
                          C:\Windows\system32\SLsvc.exe (1184)
                          C:\Windows\system32\svchost.exe (1208)
                          C:\Windows\system32\svchost.exe (1376)
                          C:\Windows\System32\spoolsv.exe (1552)
                          C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (1576)
                          C:\Windows\system32\svchost.exe (1768)
                          C:\Windows\system32\taskeng.exe (972)
                          C:\Windows\system32\Dwm.exe (1336)
                          C:\Windows\Explorer.EXE (1396)
                          C:\Windows\system32\agrsmsvc.exe (1240)
                          C:\Acer\ALaunch\ALaunchSvc.exe (1124)
                          C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (1024)
                          C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe (1808)
                          C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe (1860)
                          C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe (2088)
                          C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe (2136)
                          C:\Acer\Empowering Technology\eNet\eNet Service.exe (2232)
                          C:\Program Files\Common Files\LightScribe\LSSrvc.exe (2292)
                          C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (2348)
                          C:\Windows\system32\taskeng.exe (2400)
                          C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (2516)
                          C:\Acer\Mobility Center\MobilityService.exe (2528)
                          C:\Windows\system32\svchost.exe (2560)
                          C:\Program Files\SFR\Gestionnaire de Connexion\SFR.DashBoard.Service.exe (2588)
                          C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (2700)
                          C:\Windows\system32\svchost.exe (2744)
                          C:\Windows\System32\svchost.exe (2796)
                          C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (2852)
                          C:\Acer\Empowering Technology\ePower\ePowerSvc.exe (2888)
                          C:\Windows\system32\SearchIndexer.exe (2968)
                          C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (2984)
                          C:\Windows\system32\DRIVERS\xaudio.exe (3028)
                          C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (3060)
                          C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe (3096)
                          C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe (3148)
                          C:\Windows\system32\wbem\wmiprvse.exe (3236)
                          C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe (3268)
                          C:\Windows\system32\wbem\unsecapp.exe (3436)
                          C:\Windows\system32\wbem\wmiprvse.exe (3644)
                          C:\Program Files\Windows Defender\MSASCui.exe (3884)
                          C:\Windows\RtHDVCpl.exe (3896)
                          C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe (3940)
                          C:\Program Files\Acer\Acer Arcade\PCMService.exe (3964)
                          C:\Program Files\Launch Manager\LManager.exe (2508)
                          C:\Program Files\Apoint2K\Apoint.exe (2428)
                          C:\Program Files\SGPSA\ie3sh.exe (2584)
                          C:\Windows\System32\igfxtray.exe (2548)
                          C:\Windows\System32\hkcmd.exe (2784)
                          C:\Windows\System32\igfxpers.exe (1164)
                          C:\Program Files\Common Files\Java\Java Update\jusched.exe (1104)
                          C:\Program Files\uTorrent\uTorrent.exe (3052)
                          C:\Program Files\Windows Media Player\wmpnscfg.exe (3000)
                          C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (3528)
                          C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (3496)
                          C:\Windows\system32\igfxsrvc.exe (2484)
                          C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE (936)
                          C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE (3476)
                          C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE (1660)
                          C:\Windows\system32\igfxext.exe (2916)
                          C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE (2416)
                          C:\Users\Chris\AppData\Local\Apps\2.0\M9N1GTXW.2WO\QXJ4K010.36Z\curs..tion_eee711038731a406_0004.0000_2ad57791d5c42008\CurseClient.exe (2816)
                          C:\Program Files\Windows Media Player\wmpnetwk.exe (4032)
                          C:\Windows\system32\igfxsrvc.exe (3340)
                          C:\Program Files\Skype\Phone\Skype.exe (4280)
                          C:\Users\Chris\AppData\Local\Temp\RtkBtMnt.exe (4492)
                          C:\Windows\system32\svchost.exe (4588)
                          C:\Program Files\Apoint2K\ApMsgFwd.exe (676)
                          C:\Program Files\Apoint2K\Apntex.exe (5396)
                          C:\Windows\system32\conime.exe (5764)
                          C:\Users\Chris\AppData\Local\Google\Chrome\Application\chrome.exe (4192)
                          C:\Users\Chris\AppData\Local\Google\Chrome\Application\chrome.exe (4864)
                          C:\Users\Chris\AppData\Local\Google\Chrome\Application\chrome.exe (4816)
                          C:\Users\Chris\AppData\Local\Google\Chrome\Application\chrome.exe (5816)
                          C:\Users\Chris\AppData\Local\Google\Chrome\Application\chrome.exe (4900)
                          C:\Users\Chris\AppData\Local\Google\Chrome\Application\chrome.exe (5168)
                          C:\Users\Chris\AppData\Local\Google\Chrome\Application\chrome.exe (2280)
                          C:\Windows\system32\NOTEPAD.EXE (3984)
                          C:\Windows\System32\WUDFHost.exe (4812)
                          C:\Windows\system32\SearchProtocolHost.exe (4184)
                          C:\Windows\system32\SearchFilterHost.exe (4252)
                          C:\UsbFix\Go.exe (5012)
                          C:\Windows\system32\SearchProtocolHost.exe (4044)

                          ################## | Éléments infectieux |

                          Présent! C:\Users\Chris\AppData\Local\Temp\RtkBtMnt.exe
                          Présent! C:\Users\Chris\AppData\Local\Temp\symlcsv1.exe
                          Présent! F:\Malwarebytes Anti-Malware.lnk
                          Présent! C:\Users\Chris\AppData\Roaming\Temp
                          Présent! E:\reatogoMenu.exe
                          Présent! E:\AUTORUN.INF

                          ################## | Registre |

                          ################## | Mountpoints2 |

                          HKCU\.\.\.\.\Explorer\MountPoints2\{214d9c3e-649f-11df-bebf-001b38def77f}
                          Shell\AutoRun\Command = F:\Vodaphone_uninstaller.exe

                          HKCU\.\.\.\.\Explorer\MountPoints2\{3c4c5c0b-42f2-11df-a826-001b38def77f}
                          Shell\AutoRun\Command = H:\USBAutoRun.exe

                          HKCU\.\.\.\.\Explorer\MountPoints2\{4cd782a7-d456-11df-bd03-001b38def77f}
                          Shell\AutoRun\Command = F:\Vodaphone_uninstaller.exe

                          HKCU\.\.\.\.\Explorer\MountPoints2\{55bcd2ff-e4cd-11de-9183-001b38def77f}
                          Shell\AutoRun\Command = F:\Vodaphone_uninstaller.exe

                          HKCU\.\.\.\.\Explorer\MountPoints2\{55bcd31a-e4cd-11de-9183-001b38def77f}
                          Shell\AutoRun\Command = F:\Vodaphone_uninstaller.exe

                          HKCU\.\.\.\.\Explorer\MountPoints2\{70164463-6968-11de-9ac5-001b38def77f}
                          Shell\AutoRun\Command = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RECYCLER\S-2-8-46-100026314-100015168-100000009-6553.com e:\
                          Shell\Open\Command = RECYCLER\S-2-8-46-100026314-100015168-100000009-6553.com e:\

                          HKCU\.\.\.\.\Explorer\MountPoints2\{a245b4b9-fe50-11dc-97eb-806e6f6e6963}
                          Shell\AutoRun\Command = E:\reatogoMenu.exe

                          HKCU\.\.\.\.\Explorer\MountPoints2\{b28d06ee-ef31-11de-8fa9-001b38def77f}
                          Shell\AutoRun\Command = F:\Vodaphone_uninstaller.exe

                          HKCU\.\.\.\.\Explorer\MountPoints2\{e9f89b07-f22c-11de-99f6-001b38def77f}
                          Shell\AutoRun\Command = F:\Vodaphone_uninstaller.exe

                          ################## | Vaccin |

                          (!) Cet ordinateur n'est pas vacciné!

                          ################## | E.O.F |
                          1. je ne sais pas si c'est ca que tu voulais,mais je n'ai que ca... je continue le reste
                            1. 2013/01/25 00:11:30 +0100 PC-DE-CHRIS Chris IP-BLOCK 218.10.62.29 (Type: outgoing, Port: 11949, Process: utorrent.exe)
                              2013/01/25 00:11:54 +0100 PC-DE-CHRIS Chris IP-BLOCK 91.214.45.183 (Type: outgoing, Port: 11949, Process: utorrent.exe)
                              2013/01/25 00:12:26 +0100 PC-DE-CHRIS Chris IP-BLOCK 77.78.235.20 (Type: outgoing, Port: 11949, Process: utorrent.exe)
                              2013/01/25 00:40:47 +0100 PC-DE-CHRIS Chris IP-BLOCK 218.10.62.61 (Type: outgoing, Port: 11949, Process: utorrent.exe)
                              2013/01/25 00:40:47 +0100 PC-DE-CHRIS Chris IP-BLOCK 218.10.62.132 (Type: outgoing, Port: 11949, Process: utorrent.exe)
                              2013/01/25 00:40:47 +0100 PC-DE-CHRIS Chris IP-BLOCK 218.10.51.32 (Type: outgoing, Port: 11949, Process: utorrent.exe)
                              2013/01/25 00:48:57 +0100 PC-DE-CHRIS Chris IP-BLOCK 77.78.209.114 (Type: incoming, Port: 11949, Process: utorrent.exe)
                              2013/01/25 01:11:32 +0100 PC-DE-CHRIS Chris IP-BLOCK 218.10.62.88 (Type: outgoing, Port: 11949, Process: utorrent.exe)
                              2013/01/25 01:11:32 +0100 PC-DE-CHRIS Chris IP-BLOCK 218.10.62.22 (Type: outgoing, Port: 11949, Process: utorrent.exe)
                              2013/01/25 09:16:17 +0100 PC-DE-CHRIS Chris MESSAGE Starting protection
                              2013/01/25 09:16:17 +0100 PC-DE-CHRIS Chris MESSAGE Protection started successfully
                              2013/01/25 09:16:17 +0100 PC-DE-CHRIS Chris MESSAGE Starting IP protection
                              2013/01/25 09:16:24 +0100 PC-DE-CHRIS Chris MESSAGE IP Protection started successfully
                              2013/01/25 09:27:47 +0100 PC-DE-CHRIS Chris IP-BLOCK 94.102.51.50 (Type: incoming, Port: 11949, Process: utorrent.exe)
                              2013/01/25 09:29:08 +0100 PC-DE-CHRIS Chris IP-BLOCK 94.102.51.50 (Type: incoming, Port: 11949, Process: utorrent.exe)
                              2013/01/25 09:34:13 +0100 PC-DE-CHRIS Chris IP-BLOCK 212.117.183.17 (Type: outgoing, Port: 11949, Process: utorrent.exe)
                              2013/01/25 09:41:58 +0100 PC-DE-CHRIS Chris IP-BLOCK 41.203.87.123 (Type: incoming, Port: 11949, Process: utorrent.exe)
                              2013/01/25 09:46:38 +0100 PC-DE-CHRIS Chris IP-BLOCK 94.102.51.50 (Type: incoming, Port: 11949, Process: utorrent.exe)
                              2013/01/25 09:59:46 +0100 PC-DE-CHRIS Chris IP-BLOCK 89.28.6.39 (Type: incoming, Port: 11949, Process: utorrent.exe)
                              2013/01/25 10:00:59 +0100 PC-DE-CHRIS Chris IP-BLOCK 178.152.9.198 (Type: incoming, Port: 11949, Process: utorrent.exe)
                              2013/01/25 10:02:56 +0100 PC-DE-CHRIS Chris IP-BLOCK 94.102.51.50 (Type: incoming, Port: 11949, Process: utorrent.exe)
                              2013/01/25 10:05:32 +0100 PC-DE-CHRIS Chris IP-BLOCK 94.102.51.50 (Type: outgoing, Port: 11949, Process: utorrent.exe)
                              2013/01/25 10:05:43 +0100 PC-DE-CHRIS Chris IP-BLOCK 94.102.51.50 (Type: outgoing, Port: 11949, Process: utorrent.exe)
                              2013/01/25 10:05:43 +0100 PC-DE-CHRIS Chris IP-BLOCK 94.102.51.50 (Type: outgoing, Port: 11949, Process: utorrent.exe)
                              2013/01/25 10:34:38 +0100 PC-DE-CHRIS Chris IP-BLOCK 94.102.51.50 (Type: outgoing, Port: 11949, Process: utorrent.exe)
                              2013/01/25 10:57:01 +0100 PC-DE-CHRIS Chris IP-BLOCK 89.28.100.72 (Type: incoming, Port: 11949, Process: utorrent.exe)
                              2013/01/25 11:07:58 +0100 PC-DE-CHRIS Chris IP-BLOCK 218.8.50.30 (Type: outgoing, Port: 11949, Process: utorrent.exe)
                              2013/01/25 11:11:03 +0100 PC-DE-CHRIS Chris IP-BLOCK 77.78.225.7 (Type: incoming, Port: 11949, Process: utorrent.exe)
                              2013/01/25 11:15:03 +0100 PC-DE-CHRIS Chris IP-BLOCK 222.69.123.159 (Type: incoming, Port: 11949, Process: utorrent.exe)
                              2013/01/25 11:39:47 +0100 PC-DE-CHRIS Chris IP-BLOCK 89.28.29.75 (Type: incoming, Port: 11949, Process: utorrent.exe)
                              2013/01/25 12:25:21 +0100 PC-DE-CHRIS Chris IP-BLOCK 218.7.209.46 (Type: outgoing, Port: 11949, Process: utorrent.exe)
                              2013/01/25 12:55:25 +0100 PC-DE-CHRIS Chris IP-BLOCK 89.28.22.134 (Type: outgoing, Port: 11949, Process: utorrent.exe)
                              2013/01/25 13:09:36 +0100 PC-DE-CHRIS Chris IP-BLOCK 89.28.42.38 (Type: outgoing, Port: 11949, Process: utorrent.exe)
                              2013/01/25 13:10:32 +0100 PC-DE-CHRIS Chris IP-BLOCK 178.90.88.16 (Type: outgoing, Port: 11949, Process: utorrent.exe)
                              2013/01/25 13:10:48 +0100 PC-DE-CHRIS Chris IP-BLOCK 212.117.167.250 (Type: outgoing, Port: 11949, Process: utorrent.exe)
                              2013/01/25 13:25:55 +0100 PC-DE-CHRIS Chris IP-BLOCK 212.117.177.77 (Type: outgoing, Port: 11949, Process: utorrent.exe)
                              2013/01/25 13:54:40 +0100 PC-DE-CHRIS Chris IP-BLOCK 212.113.33.150 (Type: outgoing, Port: 11949, Process: utorrent.exe)
                              2013/01/25 13:55:28 +0100 PC-DE-CHRIS Chris IP-BLOCK 31.133.34.93 (Type: outgoing, Port: 11949, Process: utorrent.exe)
                              2013/01/25 13:55:52 +0100 PC-DE-CHRIS Chris IP-BLOCK 89.28.120.21 (Type: outgoing, Port: 11949, Process: utorrent.exe)
                              2013/01/25 14:22:27 +0100 PC-DE-CHRIS Chris MESSAGE Executing scheduled update: Daily
                              2013/01/25 14:22:46 +0100 PC-DE-CHRIS Chris MESSAGE Scheduled update executed successfully: database updated from version v2013.01.24.07 to version v2013.01.25.05
                              2013/01/25 14:22:46 +0100 PC-DE-CHRIS Chris MESSAGE Starting database refresh
                              2013/01/25 14:22:46 +0100 PC-DE-CHRIS Chris MESSAGE Stopping IP protection
                              2013/01/25 14:22:48 +0100 PC-DE-CHRIS Chris MESSAGE IP Protection stopped successfully
                              2013/01/25 14:23:06 +0100 PC-DE-CHRIS Chris MESSAGE Database refreshed successfully
                              2013/01/25 14:23:06 +0100 PC-DE-CHRIS Chris MESSAGE Starting IP protection
                              2013/01/25 14:23:12 +0100 PC-DE-CHRIS Chris MESSAGE IP Protection started successfully
                              2013/01/25 14:39:17 +0100 PC-DE-CHRIS Chris IP-BLOCK 89.28.15.156 (Type: outgoing, Port: 11949, Process: utorrent.exe)
                              2013/01/25 16:48:59 +0100 PC-DE-CHRIS Chris MESSAGE Stopping IP protection
                              2013/01/25 16:49:03 +0100 PC-DE-CHRIS Chris MESSAGE IP Protection stopped successfully
                              2013/01/25 16:49:14 +0100 PC-DE-CHRIS Chris MESSAGE Protection stopped
                              2013/01/25 16:49:42 +0100 PC-DE-CHRIS Chris MESSAGE Starting protection
                              2013/01/25 16:49:42 +0100 PC-DE-CHRIS Chris MESSAGE Protection started successfully
                              2013/01/25 16:49:42 +0100 PC-DE-CHRIS Chris MESSAGE Starting IP protection
                              2013/01/25 16:49:53 +0100 PC-DE-CHRIS Chris MESSAGE IP Protection started successfully
                              2013/01/25 16:50:59 +0100 PC-DE-CHRIS Chris MESSAGE Starting database refresh
                              2013/01/25 16:50:59 +0100 PC-DE-CHRIS Chris MESSAGE Stopping IP protection
                              2013/01/25 16:50:59 +0100 PC-DE-CHRIS Chris MESSAGE IP Protection stopped successfully
                              2013/01/25 16:51:15 +0100 PC-DE-CHRIS Chris MESSAGE Database refreshed successfully
                              2013/01/25 16:51:15 +0100 PC-DE-CHRIS Chris MESSAGE Starting IP protection
                              2013/01/25 16:51:31 +0100 PC-DE-CHRIS Chris MESSAGE IP Protection started successfully
                              2013/01/25 17:02:34 +0100 PC-DE-CHRIS Chris IP-BLOCK 79.135.150.31 (Type: incoming, Port: 11949, Process: utorrent.exe)
                              2013/01/25 17:04:28 +0100 PC-DE-CHRIS Chris IP-BLOCK 85.234.189.127 (Type: incoming, Port: 11949, Process: utorrent.exe)
                              2013/01/25 17:17:31 +0100 PC-DE-CHRIS Chris IP-BLOCK 89.28.2.171 (Type: incoming, Port: 11949, Process: utorrent.exe)
                              2013/01/25 17:18:19 +0100 PC-DE-CHRIS Chris IP-BLOCK 188.130.176.8 (Type: incoming, Port: 11949, Process: utorrent.exe)
                              2013/01/25 17:19:24 +0100 PC-DE-CHRIS Chris IP-BLOCK 89.28.17.144 (Type: incoming, Port: 11949, Process: utorrent.exe)
                              2013/01/25 17:40:57 +0100 PC-DE-CHRIS Chris IP-BLOCK 89.28.18.134 (Type: incoming, Port: 11949, Process: utorrent.exe)
                              2013/01/25 19:47:05 +0100 PC-DE-CHRIS Chris MESSAGE Starting protection
                              2013/01/25 19:47:05 +0100 PC-DE-CHRIS Chris MESSAGE Protection started successfully
                              2013/01/25 19:47:05 +0100 PC-DE-CHRIS Chris MESSAGE Starting IP protection
                              2013/01/25 19:47:11 +0100 PC-DE-CHRIS Chris MESSAGE IP Protection started successfully
                              2013/01/25 19:50:22 +0100 PC-DE-CHRIS Chris IP-BLOCK 178.152.8.134 (Type: outgoing, Port: 11949, Process: utorrent.exe)
                              1. Malwarebytes Anti-Malware (Essai) 1.70.0.1100
                                www.malwarebytes.org

                                Version de la base de données: v2013.01.25.03

                                Windows Vista Service Pack 2 x86 NTFS
                                Internet Explorer 9.0.8112.16421
                                Chris :: PC-DE-CHRIS [administrateur]

                                Protection: Activé

                                25/01/2013 16:52:36
                                MBAM-log-2013-01-25 (19-41-36).txt

                                Type d'examen: Examen complet (C:\|D:\|)
                                Options d'examen activées: Mémoire | Démarrage | Registre | Système de fichiers | Heuristique/Extra | Heuristique/Shuriken | PUP | PUM
                                Options d'examen désactivées: P2P
                                Elément(s) analysé(s): 374033
                                Temps écoulé: 2 heure(s), 35 minute(s), 44 seconde(s)

                                Processus mémoire détecté(s): 0
                                (Aucun élément nuisible détecté)

                                Module(s) mémoire détecté(s): 0
                                (Aucun élément nuisible détecté)

                                Clé(s) du Registre détectée(s): 1
                                HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (PUP.MyWebSearch) -> Aucune action effectuée.

                                Valeur(s) du Registre détectée(s): 0
                                (Aucun élément nuisible détecté)

                                Elément(s) de données du Registre détecté(s): 0
                                (Aucun élément nuisible détecté)

                                Dossier(s) détecté(s): 0
                                (Aucun élément nuisible détecté)

                                Fichier(s) détecté(s): 3
                                C:\Program Files\Fast Browser Search\IE\SearchGuardPlus.exe (PUP.Fbsearch) -> Aucune action effectuée.
                                C:\Program Files\Fast Browser Search\IE\update.exe (PUP.Fbsearch) -> Aucune action effectuée.
                                C:\Users\Chris\Downloads\SoftonicDownloader_pour_curse-client.exe (PUP.OfferBundler.ST) -> Aucune action effectuée.

                                (fin)
                                1. Contributeur sécurité
                                  Lance MBAM va dans l'onglet Rapports/logs sélectionne le dernier rapport par rapport à la date et poste le dans la réponse.

                                  Ensuite je voudrais que tu fasses ceci:

                                  - Télécharge UsbFix (créé par El Desaparecido & C_XX) sur ton Bureau. Si ton antivirus affiche une alerte, ignore la et désactive l'antivirus temporairement.
                                  - Branche tes sources de données externes à ton PC (clé USB, disque dur externe, etc...) sans les ouvrir
                                  - Insères également le CD OTLPE
                                  - Double clique sur le raccourci UsbFix sur ton Bureau, l'installation se fera automatiquement
                                  -Clique sur "Recherche"
                                  - Laisse travailler l'outil
                                  - A la fin, le rapport va s'afficher : poste le dans ta prochaine réponse (il est aussi sauvegardé a la racine du disque dur)

                                  Smart
                                  "Si tu n'as pas d'ambitions, tu t'installes au bord de la chute" (Kundera)
                                  1. jai supprimer et les laisser s'eteindre mais il ne ma pas donner d'autre rapport quand il s'est rallumer...
                                    • 1
                                    • 2
                                    • 3
                                    • 4
                                    • 5