Pb virus je pense

Résolu
Bonjour,
j'ai un pb, mon pc reviens toujours au bureau toute les 5 secondes.
je pense que j'ai un virus.
pouvez vous m'aider?
merci

24 réponses

Résumé de la discussion

Un problème récurrent est signalé: le PC revient systématiquement sur le bureau toutes les 5 secondes, et l'utilisateur soupçonne une infection par virus potentielle. Plusieurs réponses proposent des outils et des méthodes: restauration système antérieure, puis ZHPFix et d'autres utilitaires de nettoyage pour supprimer les éléments indésirables et les raccourcis malveillants. Le récit décrit des résultats partiels: suppression de composants comme BingBar, SeaPort et services associés, suppression de clés du registre et des fichiers temporaires, suivie d'un redémarrage et d'un nouveau diagnostic. D'autres interventions évoquent RogueKiller et des scans détaillés qui identifient des pages d'accueil et des pages de recherche modifiées, et recommandent d'importer des rapports pour poursuivre le nettoyage.

Bobot (l’IA à votre service)
  1. bonjour, windows ne me propose pas de restauration antérieure à l'apparition du probleme.
    0
    1. bon bah j'ai fait un reset d'usine du pc.
      tout est nikel maintenant.
      0
  2. Contributeur sécurité
    Bonsoir,
    Pas d'infections..
    --------------
    Tu vas restaurer ton windows à une date antérieure (avant l'apparition du problème)
    Aide : <<<ICI>>>

    Bonne soirée
    0
    1. RogueKiller V10.0.8.0 (x64) [Nov 20 2014] par Adlice Software
      email : https://www.adlice.com/contact/
      Remontées : https://forum.adlice.com/
      Site web : https://www.adlice.com/fr/roguekiller/
      Blog : https://www.adlice.com/

      Système d'exploitation : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
      Démarré en : Mode normal
      Utilisateur : Home [Administrateur]
      Mode : Scan -- Date : 12/04/2014 13:40:14

      ¤¤¤ Processus : 0 ¤¤¤

      ¤¤¤ Registre : 14 ¤¤¤
      [PUM.HomePage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Start Page : https://fr.yahoo.com?fr=hp-avast&type=avastbcl -> Trouvé(e)
      [PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-183619350-1722492827-1061441442-1001\Software\Microsoft\Internet Explorer\Main | Start Page : https://fr.yahoo.com?fr=hp-avast&type=avastbcl -> Trouvé(e)
      [PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-183619350-1722492827-1061441442-1001\Software\Microsoft\Internet Explorer\Main | Start Page : https://fr.yahoo.com?fr=hp-avast&type=avastbcl -> Trouvé(e)
      [PUM.SearchPage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Search Page : https://fr.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms} -> Trouvé(e)
      [PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-183619350-1722492827-1061441442-1001\Software\Microsoft\Internet Explorer\Main | Search Page : https://fr.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms} -> Trouvé(e)
      [PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-183619350-1722492827-1061441442-1001\Software\Microsoft\Internet Explorer\Main | Search Page : https://fr.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms} -> Trouvé(e)
      [PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-183619350-1722492827-1061441442-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1 -> Trouvé(e)
      [PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-183619350-1722492827-1061441442-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Trouvé(e)
      [PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-183619350-1722492827-1061441442-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1 -> Trouvé(e)
      [PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-183619350-1722492827-1061441442-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Trouvé(e)
      [PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-183619350-1722492827-1061441442-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1 -> Trouvé(e)
      [PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-183619350-1722492827-1061441442-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Trouvé(e)
      [PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-183619350-1722492827-1061441442-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1 -> Trouvé(e)
      [PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-183619350-1722492827-1061441442-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Trouvé(e)

      ¤¤¤ Tâches : 0 ¤¤¤

      ¤¤¤ Fichiers : 0 ¤¤¤

      ¤¤¤ Fichier Hosts : 0 ¤¤¤

      ¤¤¤ Antirootkit : 105 (Driver: Chargé) ¤¤¤
      [IAT:Inl] (explorer.exe) ntdll.dll - NtSetSystemInformation : Unknown @ 0x76f101f0 (jmp 0x15d850)
      [IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtWriteVirtualMemory : Unknown @ 0x76f103b0 (jmp 0x15ed60)
      [IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtDuplicateObject : Unknown @ 0x76f10390 (jmp 0x15ed20)
      [IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtCreateEvent : Unknown @ 0x76f102d0 (jmp 0x15eba0)
      [IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtNotifyChangeKey : Unknown @ 0x76f10490 (jmp 0x15e300)
      [IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtTerminateProcess : Unknown @ 0x76f103e0 (jmp 0x15ee70)
      [IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtOpenEvent : Unknown @ 0x76f102e0 (jmp 0x15ec30)
      [IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtAssignProcessToJobObject : Unknown @ 0x76f103a0 (jmp 0x15e870)
      [IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtSetContextThread : Unknown @ 0x76f10400 (jmp 0x15dc20)
      [IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtCreateSection : Unknown @ 0x76f10310 (jmp 0x15ebc0)
      [IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtOpenProcess : Unknown @ 0x76f10370 (jmp 0x15ee60)
      [IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtSetSystemInformation : Unknown @ 0x76f101f0 (jmp 0x15d850)
      [IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtNotifyChangeMultipleKeys : Unknown @ 0x76f104a0 (jmp 0x15e300)
      [IAT:Inl] (explorer.exe @ kernel32.dll) ntdll.dll - NtQueryObject : Unknown @ 0x76f10450 (jmp 0x15f0a0)
      [IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtCreateIoCompletion : Unknown @ 0x76f10350 (jmp 0x15e730)
      [IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtCreateEvent : Unknown @ 0x76f102d0 (jmp 0x15eba0)
      [IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtDuplicateObject : Unknown @ 0x76f10390 (jmp 0x15ed20)
      [IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtQueryObject : Unknown @ 0x76f10450 (jmp 0x15f0a0)
      [IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtCreateSection : Unknown @ 0x76f10310 (jmp 0x15ebc0)
      [IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtOpenSection : Unknown @ 0x76f10320 (jmp 0x15ed00)
      [IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtWriteVirtualMemory : Unknown @ 0x76f103b0 (jmp 0x15ed60)
      [IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtOpenProcess : Unknown @ 0x76f10370 (jmp 0x15ee60)
      [IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtTerminateProcess : Unknown @ 0x76f103e0 (jmp 0x15ee70)
      [IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtOpenEvent : Unknown @ 0x76f102e0 (jmp 0x15ec30)
      [IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtCreateSemaphore : Unknown @ 0x76f102b0 (jmp 0x15e5a0)
      [IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtOpenSemaphore : Unknown @ 0x76f102c0 (jmp 0x15e030)
      [IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtCreateMutant : Unknown @ 0x76f10290 (jmp 0x15e610)
      [IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtOpenMutant : Unknown @ 0x76f102a0 (jmp 0x15e060)
      [IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtCreateTimer : Unknown @ 0x76f10330 (jmp 0x15e5f0)
      [IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtOpenTimer : Unknown @ 0x76f10340 (jmp 0x15e070)
      [IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtCreateThreadEx : Unknown @ 0x76f103d0 (jmp 0x15e6a0)
      [IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtTerminateThread : Unknown @ 0x76f103f0 (jmp 0x15ec10)
      [IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtOpenThread : Unknown @ 0x76f10380 (jmp 0x15e0c0)
      [IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtSuspendThread : Unknown @ 0x76f10430 (jmp 0x15d9a0)
      [IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtNotifyChangeKey : Unknown @ 0x76f10490 (jmp 0x15e300)
      [IAT:Inl] (explorer.exe @ ADVAPI32.dll) ntdll.dll - NtTerminateThread : Unknown @ 0x76f103f0 (jmp 0x15ec10)
      [IAT:Inl] (explorer.exe @ ADVAPI32.dll) ntdll.dll - NtCreateEvent : Unknown @ 0x76f102d0 (jmp 0x15eba0)
      [IAT:Inl] (explorer.exe @ ADVAPI32.dll) ntdll.dll - NtDuplicateObject : Unknown @ 0x76f10390 (jmp 0x15ed20)
      [IAT:Inl] (explorer.exe @ ADVAPI32.dll) ntdll.dll - NtSetSystemInformation : Unknown @ 0x76f101f0 (jmp 0x15d850)
      [IAT:Inl] (explorer.exe @ ADVAPI32.dll) ntdll.dll - NtQueryObject : Unknown @ 0x76f10450 (jmp 0x15f0a0)
      [IAT:Inl] (explorer.exe @ sechost.dll) ntdll.dll - NtTerminateProcess : Unknown @ 0x76f103e0 (jmp 0x15ee70)
      [IAT:Inl] (explorer.exe @ RPCRT4.dll) ntdll.dll - NtAlpcSendWaitReceivePort : Unknown @ 0x76f10480 (jmp 0x15e980)
      [IAT:Inl] (explorer.exe @ RPCRT4.dll) ntdll.dll - NtCreateSection : Unknown @ 0x76f10310 (jmp 0x15ebc0)
      [IAT:Inl] (explorer.exe @ RPCRT4.dll) ntdll.dll - NtQueueApcThreadEx : Unknown @ 0x76f10440 (jmp 0x15de80)
      [IAT:Inl] (explorer.exe @ GDI32.dll) ntdll.dll - NtVdmControl : Unknown @ 0x76f10280 (jmp 0x15d700)
      [IAT:Inl] (explorer.exe @ GDI32.dll) ntdll.dll - NtCreateSection : Unknown @ 0x76f10310 (jmp 0x15ebc0)
      [IAT:Inl] (explorer.exe @ USER32.dll) ntdll.dll - NtVdmControl : Unknown @ 0x76f10280 (jmp 0x15d700)
      [IAT:Inl] (explorer.exe @ SHELL32.dll) ntdll.dll - NtQueryObject : Unknown @ 0x76f10450 (jmp 0x15f0a0)
      [IAT:Inl] (explorer.exe @ ole32.dll) ntdll.dll - NtTerminateProcess : Unknown @ 0x76f103e0 (jmp 0x15ee70)
      [IAT:Inl] (explorer.exe @ ole32.dll) ntdll.dll - NtQueryObject : Unknown @ 0x76f10450 (jmp 0x15f0a0)
      [IAT:Inl] (explorer.exe @ MSCTF.dll) ntdll.dll - NtAlpcSendWaitReceivePort : Unknown @ 0x76f10480 (jmp 0x15e980)
      [IAT:Inl] (explorer.exe @ UxTheme.dll) ntdll.dll - NtOpenEvent : Unknown @ 0x76f102e0 (jmp 0x15ec30)
      [IAT:Inl] (explorer.exe @ SETUPAPI.dll) ntdll.dll - NtQueryObject : Unknown @ 0x76f10450 (jmp 0x15f0a0)
      [IAT:Inl] (explorer.exe @ dwmapi.dll) ntdll.dll - NtCreateSection : Unknown @ 0x76f10310 (jmp 0x15ebc0)
      [IAT:Inl] (explorer.exe @ Secur32.dll) ntdll.dll - NtOpenSection : Unknown @ 0x76f10320 (jmp 0x15ed00)
      [IAT:Inl] (explorer.exe @ SSPICLI.DLL) ntdll.dll - NtDuplicateObject : Unknown @ 0x76f10390 (jmp 0x15ed20)
      [IAT:Inl] (explorer.exe @ SSPICLI.DLL) ntdll.dll - NtOpenEvent : Unknown @ 0x76f102e0 (jmp 0x15ec30)
      [IAT:Inl] (explorer.exe @ WINSTA.dll) ntdll.dll - NtOpenProcess : Unknown @ 0x76f10370 (jmp 0x15ee60)
      [IAT:Inl] (explorer.exe @ WINSTA.dll) ntdll.dll - NtTerminateProcess : Unknown @ 0x76f103e0 (jmp 0x15ee70)
      [IAT:Inl] (explorer.exe @ apphelp.dll) ntdll.dll - NtCreateSection : Unknown @ 0x76f10310 (jmp 0x15ebc0)
      [IAT:Inl] (explorer.exe @ apphelp.dll) ntdll.dll - NtQueryObject : Unknown @ 0x76f10450 (jmp 0x15f0a0)
      [IAT:Inl] (explorer.exe @ CLBCatQ.DLL) ntdll.dll - NtOpenEvent : Unknown @ 0x76f102e0 (jmp 0x15ec30)
      [IAT:Inl] (explorer.exe @ dbghelp.dll) ntdll.dll - NtQueryObject : Unknown @ 0x76f10450 (jmp 0x15f0a0)
      [IAT:Inl] (explorer.exe @ cscapi.dll) ntdll.dll - NtCreateEvent : Unknown @ 0x76f102d0 (jmp 0x15eba0)
      [IAT:Inl] (explorer.exe @ tiptsf.dll) ntdll.dll - NtAlpcSendWaitReceivePort : Unknown @ 0x76f10480 (jmp 0x15e980)
      [IAT:Inl] (explorer.exe @ ntmarta.dll) ntdll.dll - NtOpenTimer : Unknown @ 0x76f10340 (jmp 0x15e070)
      [IAT:Inl] (explorer.exe @ ntmarta.dll) ntdll.dll - NtOpenThread : Unknown @ 0x76f10380 (jmp 0x15e0c0)
      [IAT:Inl] (explorer.exe @ ntmarta.dll) ntdll.dll - NtOpenSemaphore : Unknown @ 0x76f102c0 (jmp 0x15e030)
      [IAT:Inl] (explorer.exe @ ntmarta.dll) ntdll.dll - NtOpenSection : Unknown @ 0x76f10320 (jmp 0x15ed00)
      [IAT:Inl] (explorer.exe @ ntmarta.dll) ntdll.dll - NtOpenProcess : Unknown @ 0x76f10370 (jmp 0x15ee60)
      [IAT:Inl] (explorer.exe @ ntmarta.dll) ntdll.dll - NtOpenMutant : Unknown @ 0x76f102a0 (jmp 0x15e060)
      [IAT:Inl] (explorer.exe @ ntmarta.dll) ntdll.dll - NtOpenEventPair : Unknown @ 0x76f10300 (jmp 0x15e130)
      [IAT:Inl] (explorer.exe @ ntmarta.dll) ntdll.dll - NtOpenEvent : Unknown @ 0x76f102e0 (jmp 0x15ec30)
      [IAT:Inl] (explorer.exe @ ntmarta.dll) ntdll.dll - NtQueryObject : Unknown @ 0x76f10450 (jmp 0x15f0a0)
      [IAT:Inl] (explorer.exe @ gameux.dll) ntdll.dll - NtCreateSection : Unknown @ 0x76f10310 (jmp 0x15ebc0)
      [IAT:Inl] (explorer.exe @ CRYPT32.dll) ntdll.dll - NtQueryObject : Unknown @ 0x76f10450 (jmp 0x15f0a0)
      [IAT:Inl] (explorer.exe @ wer.dll) ntdll.dll - NtOpenEvent : Unknown @ 0x76f102e0 (jmp 0x15ec30)
      [IAT:Inl] (explorer.exe @ wer.dll) ntdll.dll - NtAlpcSendWaitReceivePort : Unknown @ 0x76f10480 (jmp 0x15e980)
      [IAT:Inl] (explorer.exe @ authui.dll) ntdll.dll - NtOpenProcess : Unknown @ 0x76f10370 (jmp 0x15ee60)
      [IAT:Inl] (explorer.exe @ authui.dll) ntdll.dll - NtSetSystemInformation : Unknown @ 0x76f101f0 (jmp 0x15d850)
      [IAT:Inl] (explorer.exe @ WINMM.dll) ntdll.dll - NtCreateEvent : Unknown @ 0x76f102d0 (jmp 0x15eba0)
      [IAT:Inl] (explorer.exe @ WINMM.dll) ntdll.dll - NtCreateTimer : Unknown @ 0x76f10330 (jmp 0x15e5f0)
      [IAT:Inl] (explorer.exe @ AVRT.dll) ntdll.dll - NtOpenEvent : Unknown @ 0x76f102e0 (jmp 0x15ec30)
      [IAT:Inl] (explorer.exe @ AVRT.dll) ntdll.dll - NtAlpcSendWaitReceivePort : Unknown @ 0x76f10480 (jmp 0x15e980)
      [IAT:Inl] (explorer.exe @ AVRT.dll) ntdll.dll - NtCreateEvent : Unknown @ 0x76f102d0 (jmp 0x15eba0)
      [IAT:Inl] (explorer.exe @ AVRT.dll) ntdll.dll - NtTerminateProcess : Unknown @ 0x76f103e0 (jmp 0x15ee70)
      [IAT:Inl] (explorer.exe @ AUDIOSES.DLL) ntdll.dll - NtAlpcSendWaitReceivePort : Unknown @ 0x76f10480 (jmp 0x15e980)
      [IAT:Inl] (explorer.exe @ es.dll) ntdll.dll - NtOpenEvent : Unknown @ 0x76f102e0 (jmp 0x15ec30)
      [IAT:Inl] (explorer.exe @ NSI.dll) ntdll.dll - NtTerminateProcess : Unknown @ 0x76f103e0 (jmp 0x15ee70)
      [IAT:Inl] (explorer.exe @ WS2_32.dll) ntdll.dll - NtLoadDriver : Unknown @ 0x76f101e0 (jmp 0x15e140)
      [IAT:Inl] (explorer.exe @ WinSATAPI.dll) ntdll.dll - NtQueryObject : Unknown @ 0x76f10450 (jmp 0x15f0a0)
      [IAT:Inl] (explorer.exe @ WinSATAPI.dll) ntdll.dll - NtSetSystemInformation : Unknown @ 0x76f101f0 (jmp 0x15d850)
      [IAT:Inl] (explorer.exe @ ncrypt.dll) ntdll.dll - NtOpenProcess : Unknown @ 0x76f10370 (jmp 0x15ee60)
      [IAT:Inl] (explorer.exe @ bcrypt.dll) ntdll.dll - NtTerminateProcess : Unknown @ 0x76f103e0 (jmp 0x15ee70)
      [IAT:Inl] (explorer.exe @ bcryptprimitives.dll) ntdll.dll - NtTerminateProcess : Unknown @ 0x76f103e0 (jmp 0x15ee70)
      [IAT:Inl] (explorer.exe @ mswsock.dll) ntdll.dll - NtLoadDriver : Unknown @ 0x76f101e0 (jmp 0x15e140)
      [IAT:Inl] (explorer.exe @ mswsock.dll) ntdll.dll - NtCreateIoCompletion : Unknown @ 0x76f10350 (jmp 0x15e730)
      [IAT:Inl] (explorer.exe @ mswsock.dll) ntdll.dll - NtCreateEvent : Unknown @ 0x76f102d0 (jmp 0x15eba0)
      [IAT:Inl] (explorer.exe @ wship6.dll) ntdll.dll - NtTerminateProcess : Unknown @ 0x76f103e0 (jmp 0x15ee70)
      [IAT:Inl] (explorer.exe @ wshtcpip.dll) ntdll.dll - NtTerminateProcess : Unknown @ 0x76f103e0 (jmp 0x15ee70)
      [IAT:Inl] (explorer.exe @ fwpuclnt.dll) ntdll.dll - NtQueryObject : Unknown @ 0x76f10450 (jmp 0x15f0a0)
      [IAT:Inl] (explorer.exe @ schannel.DLL) ntdll.dll - NtDuplicateObject : Unknown @ 0x76f10390 (jmp 0x15ed20)
      [IAT:Inl] (explorer.exe @ schannel.DLL) ntdll.dll - NtOpenEvent : Unknown @ 0x76f102e0 (jmp 0x15ec30)
      [IAT:Inl] (explorer.exe @ schannel.DLL) ntdll.dll - NtCreateEvent : Unknown @ 0x76f102d0 (jmp 0x15eba0)
      [IAT:Inl] (explorer.exe @ dsrole.dll) ntdll.dll - NtOpenEvent : Unknown @ 0x76f102e0 (jmp 0x15ec30)

      ¤¤¤ Navigateurs web : 1 ¤¤¤
      [PUM.HomePage][FIREFX:Config] 1f3s7vcl.default-1399806629570 : user_pref("browser.startup.homepage", "www.google.fr"); -> Trouvé(e)

      ¤¤¤ Vérification MBR : ¤¤¤
      +++++ PhysicalDrive0: WDC WD10EALX-559BA0 +++++
      --- User ---
      [MBR] 20481bf5ec6780bbba99ba4698d59f01
      [BSP] de601e2c91bce739d63b7b535cf979ec : Windows Vista/7/8 MBR Code
      Partition table:
      0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 19101 MB
      1 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 39120896 | Size: 100 MB
      2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 39325696 | Size: 934666 MB
      User = LL1 ... OK
      User = LL2 ... OK

      ============================================
      RKreport_DEL_08232014_211917.log - RKreport_SCN_08232014_173124.log - RKreport_SCN_08232014_173437.log - RKreport_SCN_08232014_211429.log
      0
      1. Contributeur sécurité
        Re,
        [*] Télécharger et enregistre RogueKiller (by tigzy) sur le bureau à partir l'un des deux liens ci-dessous :
        Si tuas la version 32 bits, ici :
        http://www.adlice.com/softs/roguekiller/RogueKiller.exe

        Si tu as la version 64 bist, ici :
        http://www.adlice.com/softs/roguekiller/RogueKillerX64.exe

        [*] Quitter tous les programmes
        [*] Lancer RogueKiller.exe.
        [*] Utilisateur de W7 et W8, clique droit sur l'outil, puis le lancer en tant qu'administrateur.
        [*] Attendre que le Prescan ait fini ...
        [*] Cliquer sur Scan.
        Attends la fin de scan
        Clique sur le bouton rapport et copie et colle la totalité de son contenu sur ton prochain message

        NOTE: Si l'infection bloque le programme, il faut le relancer plusieurs fois ou le renommer en winlogon.exe

        Site officiel de rogueKiller:
        https://www.adlice.com/fr/roguekiller/

        @+
        0
        1. toujours le meme pb :(
          0
          1. Contributeur sécurité
            Salut,
            Quel est le résultat de : sfc /scannow et chkdsk c: /F/R ?
            0
          2. il me dit : "le type du systeme de fichiers est ntfs. impossibe de verrouiller le lecteur en cours.
            chkdsk ne peut pas s'exécuter parce que le volume est utilisé par un autre processus. Voulez vous que ce volume soit vérifié au prochain démarrage du systeme?"
            0
        2. Contributeur sécurité
          Bonsoir,

          Comment fonctionne ton PC maintenant ?

          Bonne soirée
          0
          1. merci de ta réponse.
            je fais quoi ensuite ?
            0
            1. Contributeur sécurité
              Bonsoir,
              1/
              -> Sur Vista/Seven, dans le champ "Recherche" tape cmd , sur le résultat qui apparait, clic droit > exécuter en tant qu'administrateur

              * Dans la fenêtre noire, tape sfc /scannow et laisse Windows réparer les fichiers.
              Aide :
              https://forums.cnetfrance.fr/tutoriels-logiciels-et-applis/431-sfc-scannow-verifier-les-fichiers-systemes

              2/
              Menu Démarrer, dans la barre blanche "Rechercher"
              Tape cmd, clic droit sur cmd.exe, Exécuter en tant qu'administrateur
              Dans l'invite qui s'ouvre, copie et colle cette ligne

              chkdsk c: /F/R

              Bonne soirée

              0
              1. le pb persiste et je n'ai pas de message d'erreur.
                0
                1. Rapport de ZHPFix 2014.10.5.8 par Nicolas Coolman, Update du 05/10/2014
                  Fichier d'export Registre :
                  Run by Home at 21/11/2014 13:41:36
                  High Elevated Privileges : OK
                  Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)

                  Corbeille vidée (00mn 02s)

                  ========== Clés du Registre ==========
                  SUPPRIMÉ: CLSID BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f}
                  SUPPRIMÉ CLSID MPSK: {675cc1bf-b939-11e1-bdfc-ccaf78d0b172}

                  ========== Eléments de donnée du Registre ==========
                  REMPLACÉ Value NoActiveDesktopChanges : Good (0) - Bad (1)

                  ========== Fichiers ==========
                  SUPPRIMÉ: c:\users\home\appdata\local\google\chrome\user data\default\preferences

                  ========== Récapitulatif ==========
                  2 : Clés du Registre
                  1 : Eléments de donnée du Registre
                  1 : Fichiers

                  End of clean in 00mn 03s

                  ========== Chemin de fichier rapport ==========
                  C:\Users\Home\AppData\Roaming\ZHP\ZHPFix[R1].txt - 25/08/2014 08:55:39 [3973]
                  C:\Users\Home\AppData\Roaming\ZHP\ZHPFix[R2].txt - 12/10/2014 14:53:10 [1783]
                  C:\Users\Home\AppData\Roaming\ZHP\ZHPFix[R3].txt - 21/11/2014 13:41:39 [1019]
                  0
                  1. Contributeur sécurité
                    Bonsoir,
                    1/
                    --> Copie tout le texte présent en gras ci-dessous (Sélectionne-le, clique droit dessus et choisis "Copier").


                    Script ZHPFix
                    [MD5.9F2543F7BBC73F2B025AB32BBFA08709] [SPRF][14/06/2013] (...) -- C:\ProgramData\9of0l.bat [56]
                    [MD5.8D310A194E56AD15C436FC0C7BA97C8B] [SPRF][14/06/2013] (...) -- C:\ProgramData\9of0l.reg [151]
                    [MD5.1BFE585FDC3E8A6DDA72BD1850E5476B] [SPRF][14/06/2013] (...) -- C:\ProgramData\eqrdz0.bat [57]
                    [MD5.0E716AE5EA069A8D829AC9E2C4605141] [SPRF][14/06/2013] (...) -- C:\ProgramData\eqrdz0.reg [152]
                    [MD5.51628839BD51C538EC626EDA466E5E34] [SPRF][21/09/2012] (...) -- C:\Users\Home\AppData\Roaming\mdbu.bin [227]
                    G2 - GCE: Preference [User Data\Default] [ahfgeienlihckogmohjhadlkjgocpleb] Google Store v.0.2 (Activé)
                    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
                    O2 - BHO: Bing Bar Helper [64Bits] - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} . (...) -- "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (.not file.)
                    [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D2CE3E00-F94A-4740-988E-03DC2F38C34F}]
                    O51 - MPSK:{675cc1bf-b939-11e1-bdfc-ccaf78d0b172}\AutoRun\command. (...) -- E:\Autorun.exe (.not file.)



                    => Puis lance ZHPFix depuis le raccourci situé sur ton Bureau.
                    (Sous Vista/Win7/Win8, il faut cliquer droit sur le raccourci de ZHPFix et choisir Exécuter en tant qu'administrateur)
                    => Une fois ZHPFix ouvert, clique sur "importer" puis sur "ok" et ensuite colle le texte dans la fenêtre, clique sur GO en bas de page et confirme par oui pour lancer le nettoyage des données

                    => laisse travailler l'outil et ne touche à rien ...
                    => S'il t'est demandé de redémarrer le PC pour finir le nettoyage, fais le !

                    Une fois terminé, un nouveau rapport s'affiche : poste le contenu de ce dernier dans ta prochaine réponse ...
                    Ce rapport est copié sur le bureau

                    ( ce rapport est en outre sauvegardé dans ce dossier C:/ZHP/ZHPDIAG)

                    2/
                    Redémarre ton PC si le même problème existe, est ce que tu as un message d'erreur ?

                    @+

                    0
                    1. Contributeur sécurité
                      Bonjour,
                      1/
                      Il me faut un nouveau rapport ZHPDiag.

                      2/
                      Comment fonctionne ton PC maintenant ?

                      @+
                      0
                      1. Contributeur sécurité
                        Bonjour,
                        On va faire un peu de nettoyage :
                        1/
                        - Télécharge SFTGC.exe : http://www.archive-host.com
                        - Enregistre le fichier sur le bureau.
                        - Ouvre SFTGC.exe et patiente durant l'initialisation du logiciel.
                        - Pour lancer le nettoyage, il suffit de cliquer sur Go.
                        - À la fin du nettoyage, un rapport (présent sur le bureau) va s'ouvrir. Pour le poster, héberge-le sur : FEC Upload ou : malekal.com

                        2/
                        . télécharges Ccleaner à partir de cette adresse et enregistres le sur le bureau

                        https://filehippo.com/fr/download_ccleaner/

                        .double-cliques sur le fichier pour lancer l'installation
                        .sur la fenêtre de l'installation langage bien choisir français et OK
                        .cliques sur suivant
                        .lis la licence et j'accepte
                        .cliques sur suivant
                        .la tu ne gardes de coché que mettre un raccourci sur le bureau et puis contrôler automatiquement les mises à jour de Ccleaner
                        .cliques sur installer
                        .cliques sur fermer
                        .double-cliques sur l'icône de Ccleaner pour l'ouvrir
                        .une fois ouvert tu cliques sur option et puis avancé
                        .tu décoches effacer uniquement les fichiers, du dossier temp de windows plus vieux que 24 heures
                        .cliques sur nettoyeur
                        .cliques sur windows et dans la colonne avancé
                        .coches la première case vieilles données du perfetch que celle-la ce qui te donnes la case vielles données du perfetch et la case avancé qui c'est coché automatiquement mais que celle-la
                        .cliques sur analyse une fois l'analyse terminé
                        .cliques sur lancer le nettoyage et sur la demande de confirmation OK il vas falloir que tu le refasses une autre fois une fois fini vériffis en appuiant de nouveau sur analyse pour être sur qu'il n'y est plus rien
                        .cliques maintenant sur registre et puis sur rechercher les erreurs
                        .laisses tout cochées et cliques sur réparrer les erreurs sélectionnées
                        .il te demande de sauvegarder OUI
                        .tu lui donnes un nom pour pouvoir la retrouver et enregistre
                        .cliques sur corriger toutes les erreurs sélectionnées et sur la demande de confirmation OK
                        .il supprime et fermer tu vérifies en relançant rechercher les erreurs
                        .tu retournes dans option et tu recoches la case effacer uniquement les fichiers, du dossier temp de windows plus vieux que 48 heures et sur nettoyeur, windows sous avancé tu décoches la première case vieilles données du perfetch
                        .tu peux fermer Ccleaner

                        tuto installation & nettoyage :
                        https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/#tutoriel-ccleaner

                        @+

                        ¤¤¤ Le meilleur remède pour tous les problèmes, c'est la patience.... ¤¤¤
                        0
                        1. voici le rapport :

                          Rapport de ZHPFix 2014.10.5.8 par Nicolas Coolman, Update du 05/10/2014
                          Fichier d'export Registre :
                          Run by Home at 12/10/2014 15:53:07
                          High Elevated Privileges : OK
                          Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)

                          Corbeille vidée (00mn 03s)
                          Dossier Prefetcher vidé
                          Réparation des raccourcis navigateur

                          ========== Clés du Registre ==========
                          SUPPRIMÉ: SearchScopes :{52db1893-8a90-4192-aede-08e00b8f8473}
                          SUPPRIMÉ: [HKLM\Software\Classes\Installer\Products\\25BD30E1BC5D83343A835E62DDD4D41B]
                          SUPPRIMÉ: [HKLM\Software\Classes\Installer\Features\25BD30E1BC5D83343A835E62DDD4D41B]
                          SUPPRIMÉ: HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BingBar_RASAPI32
                          SUPPRIMÉ: Service: BBSvc
                          SUPPRIMÉ: Service: SeaPort
                          SUPPRIMÉ:* HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\25BD30E1BC5D83343A835E62DDD4D41B

                          ========== Dossiers ==========
                          Aucun dossiers CLSID Local utilisateur vide
                          SUPPRIMÉS Flash Cookies (0)
                          SUPPRIMÉS Temporaires Windows (40)

                          ========== Fichiers ==========
                          SUPPRIMÉ: c:\program files (x86)\microsoft\bingbar\bbsvc.exe
                          SUPPRIMÉ Redémarrage: c:\program files (x86)\microsoft\bingbar\seaport.exe
                          SUPPRIMÉ: C:\Windows\Installer\bd9d.msi
                          SUPPRIMÉS Flash Cookies (0) (0 octets)
                          SUPPRIMÉS Temporaires Windows (939) (151 463 706 octets)

                          ========== Fichier HOSTS ==========
                          Le fichier Hosts n'est pas réparé, veuillez désactiver votre antivirus.

                          ========== Récapitulatif ==========
                          7 : Clés du Registre
                          3 : Dossiers
                          5 : Fichiers
                          1 : Fichier HOSTS

                          End of clean in 00mn 06s

                          ========== Chemin de fichier rapport ==========
                          C:\Users\Home\AppData\Roaming\ZHP\ZHPFix[R1].txt - 25/08/2014 08:55:39 [3973]
                          C:\Users\Home\AppData\Roaming\ZHP\ZHPFix[R2].txt - 12/10/2014 15:53:10 [1704]

                          pour le fonctionnement du pc, je vais regarder s'il continue a bugger :)
                          0
                          1. Contributeur sécurité
                            Bonjour,
                            1/
                            --> Copie tout le texte présent en gras ci-dessous (Sélectionne-le, clique droit dessus et choisis "Copier").


                            Script ZHPFix
                            Hostfix
                            EmptyPrefetch
                            ShortcutFix
                            [MD5.9F2543F7BBC73F2B025AB32BBFA08709] [SPRF][14/06/2013] (...) -- C:\ProgramData\9of0l.bat [56]
                            [MD5.8D310A194E56AD15C436FC0C7BA97C8B] [SPRF][14/06/2013] (...) -- C:\ProgramData\9of0l.reg [151]
                            [MD5.51628839BD51C538EC626EDA466E5E34] [SPRF][21/09/2012] (...) -- C:\Users\Home\AppData\Roaming\mdbu.bin [227]
                            O69 - SBI: SearchScopes [HKCU] {52db1893-8a90-4192-aede-08e00b8f8473} - (Ask.com) - https://www.search.ask.com/web?l=dis&q=&o=APN10655A&apn_dtid=%5EBND101%5EYY%5EFR&shad=s_0048&gct=hp&apn_ptnrs=%5EAG5&d=101-0&lang=en&atb=sysid%3D101%3Auid%3De71e508e6f0b6f35%3Asrc%3Dhmp%3Ao%3DAPN10655A%3Atg%3D&p2=%5EAG5%5EBND101%5EYY%5EFR
                            O90 - PUC: "25BD30E1BC5D83343A835E62DDD4D41B" . (.Bing Bar.) -- C:\Windows\Installer\{1E03DB52-D5CB-4338-A338-E526DD4D4DB1}\icon_installer_ico
                            [MD5.030EF57D730EC0A96C633715399B37B9] [WIS][01/03/2011] (.Microsoft Corporation - Bing Bar.) -- C:\Windows\Installer\bd9d.msi [4424192]
                            HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BingBar_RASAPI32
                            SS - | Demand 01/03/2011 183560 | (BBSvc) . (.Microsoft Corporation..) - C:\Program Files (x86)\Microsoft\BingBar\BBSvc.exe
                            SR - | Auto 25/02/2011 249648 | (SeaPort) . (.Microsoft Corporation.) - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.exe
                            [HKLM\Software\Wow6432Node\Microsoft\Tracing\BingBar_RASAPI32]
                            [HKLM\Software\Classes\Installer\Features\25BD30E1BC5D83343A835E62DDD4D41B]
                            [HKLM\Software\Classes\Installer\Products\25BD30E1BC5D83343A835E62DDD4D41B]
                            [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\25BD30E1BC5D83343A835E62DDD4D41B]
                            [HKLM\Software\Wow6432Node\Classes\Installer\Features\25BD30E1BC5D83343A835E62DDD4D41B]
                            [HKLM\Software\Wow6432Node\Classes\Installer\Products\25BD30E1BC5D83343A835E62DDD4D41B]
                            C:\Windows\Installer\bd9d.msi

                            EmptyCLSID
                            EmptyFlash
                            EmptyTemp


                            => Puis lance ZHPFix depuis le raccourci situé sur ton Bureau.
                            (Sous Vista/Win7/Win8, il faut cliquer droit sur le raccourci de ZHPFix et choisir Exécuter en tant qu'administrateur)
                            => Une fois ZHPFix ouvert, clique sur "importer" puis sur "ok" et ensuite colle le texte dans la fenêtre, clique sur GO en bas de page et confirme par oui pour lancer le nettoyage des données

                            => laisse travailler l'outil et ne touche à rien ...
                            => S'il t'est demandé de redémarrer le PC pour finir le nettoyage, fais le !

                            Une fois terminé, un nouveau rapport s'affiche : poste le contenu de ce dernier dans ta prochaine réponse ...
                            Ce rapport est copié sur le bureau

                            ( ce rapport est en outre sauvegardé dans ce dossier C:/ZHP/ZHPDIAG)

                            2/
                            Comment fonctionne ton PC maintenant ?

                            @+

                            0
                            1. Contributeur sécurité
                              Bonsoir,
                              Lance ZHPDiag depuis le bureau

                              Ensuite, lance l'analyse et héberge le rapport. colle le lien dans ta prochaine réponse.

                              @+

                              0
                              1. rapport 2 :

                                Malwarebytes Anti-Malware
                                www.malwarebytes.org

                                Date de l'examen: 05/10/2014
                                Heure de l'examen: 18:45:53
                                Fichier journal:
                                Administrateur: Oui

                                Version: 2.00.2.1012
                                Base de données Malveillants: v2014.10.05.07
                                Base de données Rootkits: v2014.09.19.01
                                Licence: Gratuite
                                Protection contre les malveillants: Désactivé(e)
                                Protection contre les sites Web malveillants: Désactivé(e)
                                Self-protection: Désactivé(e)

                                Système d'exploitation: Windows 7 Service Pack 1
                                Processeur: x64
                                Système de fichiers: NTFS
                                Utilisateur: Home

                                Type d'examen: Examen "Menaces"
                                Résultat: Terminé
                                Objets analysés: 377691
                                Temps écoulé: 14 min, 37 sec

                                Mémoire: Activé(e)
                                Démarrage: Activé(e)
                                Système de fichiers: Activé(e)
                                Archives: Activé(e)
                                Rootkits: Activé(e)
                                Heuristics: Activé(e)
                                PUP: Activé(e)
                                PUM: Activé(e)

                                Processus: 0
                                (No malicious items detected)

                                Modules: 0
                                (No malicious items detected)

                                Clés du Registre: 0
                                (No malicious items detected)

                                Valeurs du Registre: 0
                                (No malicious items detected)

                                Données du Registre: 0
                                (No malicious items detected)

                                Dossiers: 0
                                (No malicious items detected)

                                Fichiers: 0
                                (No malicious items detected)

                                Secteurs physiques: 0
                                (No malicious items detected)

                                (end)
                                0
                                • 1
                                • 2