Svp help me spyware secure

Résolu
Bonjour,est ce que quelqu un pourrai m aider svp souci page intempestive spyware secure merci @+
Configuration: Windows Vista
Firefox 2.0.0.11

35 réponses

Résumé de la discussion

Plusieurs messages décrivent une infection de spyware et de Trojan sur Windows Vista, avec des pages qui s'ouvrent sans consentement et des doutes sur les outils antivirus disponibles. Des analyses révèlent des détections de fichiers malveillants et la mise en quarantaine de composants comme des trojans ou modules suspects, suivies de conseils pratiques pour nettoyer. Les réponses proposent d'exécuter des outils en mode administrateur, de désactiver temporairement UAC, et d'utiliser des rapports d'outils tels que HijackThis et des suites antivirus complémentaires pour identifier les entrées indésirables. En cas de réapparition du problème, des démarches incluent la suppression manuelle des éléments douteux et la réactivation des protections système après le redémarrage.

Bobot (l’IA à votre service)
  1. salut girly et merci pour tout bien sympa de m avoir aidé,et j espere ne pas t avoir sur un forum de si tot (lol).

    @+ merci fabien.
    1. Contributeur
      salut fafoot,

      oui antivir est plus peformant qu´avast :

      tu peux regarder ceci pour confirmer mes dires :

      antivir vs avast :

      -> http://forum.malekal.com/ftopic3528.php

      et oui le trojan a ete supprimé en meme temps de la quarantaine lors de la desinstallation...

      @+
      1. salut girly,avant de recevoir ton message j ai desinstalé antivir et remis avast.par contre antivir avait en quarantaine le trojan.et apres avoir recu ton message j ai donc reinstallé antivir,et j ai maintenant desinstallé avast. ptite question antivir est mieux qu avast?

        est ce que tu crois que d avoir desinstallé antivir ca ma remis ce qui etait en quarantaine voila @+ j espere que j ai pas fait de boulette tchao...
        1. Contributeur
          salut fafoot,

          oui ca me parait ok.

          garde antivir et zone alarm et surtout ne reinstale pas avast...

          tiens moi au courrant.

          @+
          1. j ai l impression qu il reagit plus rapidement est ce que tu crois que tout est ok? est ce que je dois garder zone alarme et antivir,ou j enleve les deux et relance avast? merci @+
            1. Contributeur
              ok fafoot

              tu peut supprimer navilog bt fix et clean...

              comment va ton pc maintenant?

              @+
              1. salut girly ca roule,c bon j ai fait ce que tu m as dit,voici cher mademoiselle,mdame....msieur???

                AntiVir PersonalEdition Classic
                Report file date: mardi 11 décembre 2007 14:26

                Scanning for 965647 virus strains and unwanted programs.

                Licensed to: Avira AntiVir PersonalEdition Classic
                Serial number: 0000149996-ADJIE-0001
                Platform: Windows Vista
                Windows version: (plain) [6.0.6000]
                Username: fabien
                Computer name: PCSIMONFAMILY

                Version information:
                BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
                AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
                AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
                LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
                LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
                ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
                ANTIVIR1.VDF : 7.0.0.0 1640448 Bytes 13/09/2007 14:26:55
                ANTIVIR2.VDF : 7.0.1.30 1575424 Bytes 30/11/2007 18:31:20
                ANTIVIR3.VDF : 7.0.1.67 138752 Bytes 10/12/2007 18:31:20
                AVEWIN32.DLL : 7.6.0.40 3064320 Bytes 10/12/2007 18:31:20
                AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
                AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
                AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
                AVPACK32.DLL : 7.3.0.15 360488 Bytes 03/08/2007 08:46:00
                AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
                AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
                AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
                NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
                RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
                RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
                SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21

                Configuration settings for the scan:
                Jobname..........................: Local Drives
                Configuration file...............: c:\program files\avira\antivir personaledition classic\alldrives.avp
                Logging..........................: low
                Primary action...................: interactive
                Secondary action.................: ignore
                Scan master boot sector..........: off
                Scan boot sector.................: on
                Boot sectors.....................: J:,
                Scan memory......................: on
                Process scan.....................: on
                Scan registry....................: on
                Search for rootkits..............: off
                Scan all files...................: All files
                Scan archives....................: on
                Recursion depth..................: 20
                Smart extensions.................: on
                Macro heuristic..................: on
                File heuristic...................: high

                Start of the scan: mardi 11 décembre 2007 14:26

                The scan of running processes will be started
                Scan process 'avscan.exe' - '1' Module(s) have been scanned
                Scan process 'WmiPrvSE.exe' - '1' Module(s) have been scanned
                Scan process 'unsecapp.exe' - '1' Module(s) have been scanned
                Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                Scan process 'explorer.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'guard.exe' - '1' Module(s) have been scanned
                Scan process 'aawservice.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'lsm.exe' - '1' Module(s) have been scanned
                Scan process 'lsass.exe' - '1' Module(s) have been scanned
                Scan process 'services.exe' - '1' Module(s) have been scanned
                Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                Scan process 'wininit.exe' - '1' Module(s) have been scanned
                Scan process 'csrss.exe' - '1' Module(s) have been scanned
                Scan process 'csrss.exe' - '1' Module(s) have been scanned
                Scan process 'smss.exe' - '1' Module(s) have been scanned
                21 processes with 21 modules were scanned

                Start scanning boot sectors:
                Boot sector 'C:\'
                [NOTE] No virus was found!
                Boot sector 'D:\'
                [NOTE] No virus was found!
                Boot sector 'A:\'
                [NOTE] In the drive 'A:\' no data medium is inserted!
                Boot sector 'F:\'
                [NOTE] In the drive 'F:\' no data medium is inserted!
                Boot sector 'G:\'
                [NOTE] In the drive 'G:\' no data medium is inserted!
                Boot sector 'H:\'
                [NOTE] In the drive 'H:\' no data medium is inserted!
                Boot sector 'I:\'
                [NOTE] In the drive 'I:\' no data medium is inserted!
                Boot sector 'K:\'
                [NOTE] In the drive 'K:\' no data medium is inserted!

                Starting to scan the registry.
                The registry was scanned ( '30' files ).

                Starting the file scan:

                Begin scan in 'C:\' <ACER>
                C:\pagefile.sys
                [WARNING] The file could not be opened!
                C:\Program Files\Navilog1\Backupnavi\rxsorbi.exe
                [DETECTION] Is the Trojan horse TR/Dropper.Gen
                [INFO] The file was moved to '47d197ff.qua'!
                C:\Windows\System32\drivers\sptd.sys
                [WARNING] The file could not be opened!
                Begin scan in 'D:\' <DATA>
                Begin scan in 'A:\'
                Search path A:\ could not be opened!
                Le périphérique n'est pas prêt.

                Begin scan in 'F:\'
                Search path F:\ could not be opened!
                Le périphérique n'est pas prêt.

                Begin scan in 'G:\'
                Search path G:\ could not be opened!
                Le périphérique n'est pas prêt.

                Begin scan in 'H:\'
                Search path H:\ could not be opened!
                Le périphérique n'est pas prêt.

                Begin scan in 'I:\'
                Search path I:\ could not be opened!
                Le périphérique n'est pas prêt.

                Begin scan in 'K:\'
                Search path K:\ could not be opened!
                Le périphérique n'est pas prêt.

                Begin scan in 'E:\' <MD35-V1_0W>
                Begin scan in 'J:\'
                Search path J:\ could not be opened!
                Le périphérique n'est pas prêt.

                End of the scan: mardi 11 décembre 2007 15:34
                Used time: 1:07:49 min

                The scan has been done completely.

                15994 Scanning directories
                489375 Files were scanned
                1 viruses and/or unwanted programs were found
                0 Files were classified as suspicious:
                0 files were deleted
                0 files were repaired
                1 files were moved to quarantine
                0 files were renamed
                2 Files cannot be scanned
                489374 Files not concerned
                4448 Archives were scanned
                6 Warnings
                1 Notes

                @+
                1. Contributeur
                  bon tres bien,

                  tu peux reactiver le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

                  - Va dans démarrer puis panneau de configuration
                  - Double Clique sur l'icône "Comptes d'utilisateurs"
                  - Clique ensuite sur désactiver et valide

                  ce que je te propose maintenant :

                  instal ce par feu compatible vista :

                  https://www.generation-nt.com/zonealarm-vista-checkpoint-firewall-telecharger-actualite-42256.html

                  desinstal avast et remplace le par antivir lui aussi compatible vista :

                  ps au moment de desinstaller avast coupe toi du net pour eviter les infections et commence l´installation d´antivir et reconnecte toi au net quand antivir voudra faire les mises a jour

                  https://www.01net.com/telecharger/windows/Securite/antivirus-antitrojan/fiches/13198.html

                  confirmation de mes dires :

                  antivir vs avast :

                  -> http://forum.malekal.com/ftopic3528.php

                  puis regarde ceci pour le configurer :

                  http://mickael.barroux.free.fr/securite/antivir.php <- tutoriel configuration du scanner...

                  une fois antivir ouvert click sur l´onglet scanner dans la fenetre du dessous tu va voir : rootkit search click sur le petit + pour deployer et coche la case a coté de ton disk dur
                  puis click sur configuration en haut a droite puis dans la nouvelle fenetre a gauche >scanner > scan all files et en dessous >scanner priority = High
                  toujours a gauche > scan > deploie > heuristique > macrovirus heuristic = coché et en dessous > win32 heuristic la case coché et high detection level

                  et effectue un scan complet de ta machine avec en mode sans echec et post le rapport generé ici :

                  redemarrer en mode sans echec :
                  http://www.sophos.fr/support/knowledgebase/article/21486.html

                  @+
                  1. mission accomplie voila pour toi:

                    C:\autorun.inf Non trouvé
                    C:\MS32DLL.dll.vbs Non trouvé
                    D:\autorun.inf Non trouvé
                    D:\MS32DLL.dll.vbs Non trouvé
                    E:\autorun.inf Non trouvé
                    E:\MS32DLL.dll.vbs Non trouvé
                    K:\autorun.inf Non trouvé
                    K:\MS32DLL.dll.vbs Non trouvé
                    C:\Windows\MS32DLL.dll.vbs non trouvé

                    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
                    Windows Defender REG_EXPAND_SZ %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                    RtHDVCpl REG_SZ RtHDVCpl.exe
                    Acer Empowering Technology Monitor REG_SZ C:\Windows\system32\SysMonitor.exe
                    Acer Tour REG_SZ
                    WarReg_PopUp REG_SZ C:\Acer\WR_PopUp\WarReg_PopUp.exe
                    eRecoveryService REG_SZ
                    avast! REG_SZ C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                    SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                    Adobe Photo Downloader REG_SZ "C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Apps\apdproxy.exe"
                    NeroFilterCheck REG_SZ C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
                    Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                    LifeCam REG_SZ "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
                    VX3000 REG_SZ C:\Windows\vVX3000.exe
                    PKR Pal REG_SZ "C:\Program Files\PKR\pkrpal.exe" -osboot
                    eDataSecurity Loader REG_SZ C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
                    !AVG Anti-Spyware REG_SZ "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                    a-squared REG_SZ "C:\Program Files\a-squared Anti-Malware\a2guard.exe" /d=60
                    NvSvc REG_SZ RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                    NvCplDaemon REG_SZ RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                    NvMediaCenter REG_SZ RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                    OWCWebCamDV REG_SZ C:\Windows\system\wcdvtray.exe

                    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents

                    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
                    Sidebar REG_SZ C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                    WindowsWelcomeCenter REG_SZ rundll32.exe oobefldr.dll,ShowWelcomeCenter
                    ????r REG_SZ
                    ????????? REG_SZ ??????????????e
                    IncrediMail REG_SZ C:\Program Files\IncrediMail\bin\IncMail.exe /c
                    DAEMON Tools REG_SZ "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
                    MsnMsgr REG_SZ "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                    EPSON Stylus DX5000 Series REG_SZ C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIBVE.EXE /FU "C:\Windows\TEMP\E_SDE3F.tmp" /EF "HKCU"
                    ehTray.exe REG_SZ C:\Windows\ehome\ehTray.exe
                    LaunchList REG_SZ C:\Program Files\Pinnacle\Studio 11\LaunchList2.exe
                    ISUSPM Startup REG_SZ "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
                    Skype REG_SZ "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
                    1. Contributeur
                      re,

                      Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

                      - Va dans démarrer puis panneau de configuration
                      - Double Clique sur l'icône "Comptes d'utilisateurs"
                      - Clique ensuite sur désactiver et valide.

                      et recommence
                      1. salut girly ,le probleme c est que j ai bien cree le fichier bat,mais lorsque je le lance il me met

                        acces refusé.puis un message d erreur exception processing message 0xc0000013.......etc.
                        voila desolé.
                        1. Contributeur
                          salut fafoot,

                          ok pour les pubs mais il en reste encore :

                          fais ceci :

                          Ouvre le bloc notes (Démarrer >> exécuter et tape notepad), et copie tout ce qui ci-dessous:

                          @ echo off

                          if exist \G!RLY.TXT del \G!RLY.TXT
                          FOR %%A in (C D E F G H I J K L M N O P Q R S T U V W X Y Z) DO IF EXIST %%A: (
                          IF EXIST %%A:\autorun.inf ECHO %%A:\autorun.inf Présent>>\G!RLY.TXT
                          IF NOT EXIST %%A:\autorun.inf ECHO %%A:\autorun.inf Non trouvé>>\G!RLY.TXT
                          IF EXIST %%A:\MS32DLL.dll.vbs ECHO %%A:\MS32DLL.dll.vbs Présent>>\G!RLY.TXT
                          IF NOT EXIST %%A:\MS32DLL.dll.vbs ECHO %%A:\MS32DLL.dll.vbs Non trouvé>>\G!RLY.TXT
                          )
                          IF EXIST %WINDIR%\MS32DLL.dll.vbs (
                          ECHO %WINDIR%\MS32DLL.dll.vbs Présent>>\G!RLY.TXT) else (
                          ECHO %WINDIR%\MS32DLL.dll.vbs non trouvé >>\G!RLY.TXT)
                          REG QUERY "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run" >>\G!RLY.TXT
                          REG QUERY "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run" >>\G!RLY.TXT
                          notepad \G!RLY.TXT
                          exit

                          Dans le menu du bloc notes, clic sur "Fichier" >> Enregistrer sous.
                          Choisis le bureau comme lieu d'enregistrement, puis dans:

                          Type -> choisis "tous les fichiers"
                          Nom du fichier -> tape G!RLY.bat
                          clic sur enregistrer.

                          Sur ton bureau tu auras maintenant un fichier nommé G!RLY.bat.

                          Connecte les périphériques externes susceptibles d'avoir été infectés au pc:
                          Clé USB, DD externe... etc

                          Puis une fois fait, double clic sur le fichier G!RLY.bat.
                          Une fenêtre noire va s'ouvrir et se refermer rapidement, c'est normal.
                          Le bloc note va s'ouvrir ensuite avec le listing des fichiers que le script aura détecté.
                          Copie et colle ici le contenu de ce rapport.

                          @+
                          1. re,juste pour info pour l instant je vais sur internet et je n ai plus de pub qui s affiche! c est normal ou bien le malware n est pas encore degagé @+
                            1. salut voici le rapport ok appparement a bientot....

                              Jottis Malwarescan 2.99-TRANSITION_TO_3.00-R1
                              Datei, die hochgeladen und gescannt werden soll:

                              Dienst
                              Datei: vVX3000.exe
                              Auslastung:
                              0% 100%
                              Status:
                              OK
                              Entdeckte Packprogramme:
                              -
                              Bit9 rapportiert: File not found

                              A-Squared
                              Keine Viren gefunden
                              AntiVir
                              Keine Viren gefunden
                              ArcaVir
                              Keine Viren gefunden
                              Avast
                              Keine Viren gefunden
                              AVG Antivirus
                              Keine Viren gefunden
                              BitDefender
                              Keine Viren gefunden
                              ClamAV
                              Keine Viren gefunden
                              CPsecure
                              Keine Viren gefunden
                              Dr.Web
                              Keine Viren gefunden
                              F-Prot Antivirus
                              Keine Viren gefunden
                              F-Secure Anti-Virus
                              Keine Viren gefunden
                              Fortinet
                              Keine Viren gefunden
                              Ikarus
                              Keine Viren gefunden
                              Kaspersky Anti-Virus
                              Keine Viren gefunden
                              NOD32
                              Keine Viren gefunden
                              Norman Virus Control
                              Keine Viren gefunden
                              Panda Antivirus
                              Keine Viren gefunden
                              Rising Antivirus
                              Keine Viren gefunden
                              Sophos Antivirus
                              Keine Viren gefunden
                              VirusBuster
                              Keine Viren gefunden
                              VBA32
                              Keine Viren gefunden

                              Powered by
                              images/asquared.png images/antivir.png images/arcabit.png images/avast.png images/avg.gif images/bitdefender.png images/clamav-logo1.png images/cpsecure.gif images/drweb.gif images/f-prot.png images/f-secure_logo.gif images/fortinet.gif images/ikarus.gif images/kaspersky.png images/nod32.gif images/norman.png images/panda.png images/rising.gif images/sophos.gif images/virusbuster.gif images/vba32.png Bit9
                              Disclaimer
                              Durch das Hochladen von Dateien auf diesen Server stimmen Sie zu, dass ihre Dateien lokal gespeichert werden.

                              Ferner: Dieser Dienst ist keineswegs hundertprozentig sicher. Falls der Scanner ein 'OK' gibt, bedeutet das nicht notwendigerweise, dass die Datei sauber ist. Es könnte ein völlig neuer Virus auf freiem Fuß sein! Verlassen Sie sich niemals auf ein einzelnes Produkt alleine, selbst auf diesen Dienst nicht, obwohl er mehrere Produkte einsetzt. Für Schäden, die durch diesen nichtkommerziellen Online-Dienst verursacht wurden, bin ich daher nicht verantwortlich, noch kann ich dafür verantwortlich gemacht werden.

                              Ich bin mir auch über die Folgen einer Einrichtung wie dieser im klaren. Ich bin mir sicher, dass diese ganze Geschichte keinesfalls wissenschaftlich korrekt ist, da dies ein vollautomatischer Dienst ist (obwohl eine manuelle Korrektur möglich ist). Ich bin mir zum Beispiel bewußt, dass "False Positives" (ein Fehlalarm, bei dem eine saubere Datei irrtümlich als Virus detektiert wird) auftreten könnten, trotz der Anstrengungen, diesen proaktiv zu begegnen. Ich halte das nicht für eine große Sache, also schicken Sie mir bitte keine Emails über solche Vorkommnisse. Dies ist ein einfacher Onlinescanner, und nicht die Universität von Magdeburg.

                              Die Virensignaturen werden jede Stunde aktualisiert. Das Dateigrößenlimit beträgt 10 MB pro Datei.
                              DIE MISSBRÄUCHLICHE NUTZUNG DIESES DIENSTES (EINSCHLIESSLICH DES HOCHLADENS ABSICHTLICH MODIFIZIERTER -GEPACKTER/VERSCHLÜSSELTER/BYTESWAPPED- VERSIONEN DER GLEICHEN DATEI) HAT ZUR FOLGE, DASS IHRE IP GESPERRT WIRD.

                              Bitte fordern Sie keine dieser Viren an, wenn Sie nicht für Hersteller von Anti-Viren-Software arbeiten. Viren sind nicht zum Tauschen da.

                              Das Scannen kann eine Weile dauern, da mehrere Scanner benutzt werden. Zudem nutzen einige Scanner eine sehr hohe Heuristikstufe (was zeitaufwendig ist). Die benutzten Scanner sind Linuxversionen, und es können sich (oder auch nicht) Unterschiede zu Windowsscannern ergeben. Noch eine Anmerkung: manche Scanner detektieren nur einen Virus, wenn Archive mit mehreren Malwaredateien gescannt werden.

                              Gefördert durch Spenden (in willkürlicher Reihenfolge) von: Stormbyte Technologies LLC, The ClamAV project, James Love, Gideon Pertzov, Malcolm Murray, Nigel Thomas, Wendy Dickerson, Anthony Midmore, "ethereal", Mark Rubins, Steve S., Eric Johansen, Eric Schechter, Paul Bokel, Wilders Security, Wilfried Lilie, Prevx, SonicWALL, Lance Mueller, Ewido networks, und einigen Leuten, die es vorziehen, anonym zu bleiben... Vielen Dank an alle!

                              Statistik
                              Zuletzt gefundene Malware war 7.html, gefunden von:

                              Scanner Name der Malware
                              A-Squared X
                              AntiVir HEUR/Exploit.HTML
                              ArcaVir X
                              Avast X
                              AVG Antivirus X
                              BitDefender X
                              ClamAV X
                              CPsecure Troj.Downloader.VBS.Psyme.x
                              Dr.Web X
                              F-Prot Antivirus VBS/Psyme.EN
                              F-Secure Anti-Virus X
                              Fortinet X
                              Ikarus X
                              Kaspersky Anti-Virus X
                              NOD32 X
                              Norman Virus Control X
                              Panda Antivirus X
                              Rising Antivirus Trojan.DL.VBS.Agent.cll
                              Sophos Antivirus X
                              VirusBuster X
                              VBA32 X

                              Es steht Ihnen frei, diese automatisch generierten, ungültigen Statistiken (falsch) zu interpretieren. Für Vergleichstests von Anti-Viren Software, besuchen Sie AV comparatives.

                              Häufig gestellte Fragen (FAQ) - Feedback/Kommentare/Fragen/Fehlalarme (bitte ausschließlich auf Englisch)

                              Debian

                              © Jordi Bosveld 2004-2007

                              Deutsche Übersetzung von
                              1. Contributeur
                                salut,

                                fais analyser ceci :
                                C:\Windows\vVX3000.exe

                                ici

                                http://virusscan.jotti.org/de/

                                et post le resultat

                                @+
                                1. alut girly voila ce que tu mas demandé @

                                  Process:

                                  System Idle Process
                                  System
                                  C:\Windows\System32\smss.exe
                                  C:\Program Files\Skype\Phone\Skype.exe
                                  C:\Program Files\Mozilla Firefox\firefox.exe
                                  C:\Windows\System32\csrss.exe
                                  C:\Windows\System32\wininit.exe
                                  C:\Windows\System32\csrss.exe
                                  C:\Windows\System32\services.exe
                                  C:\Windows\System32\lsass.exe
                                  C:\Windows\System32\lsm.exe
                                  C:\Windows\explorer.exe
                                  C:\Windows\System32\winlogon.exe
                                  C:\Windows\System32\svchost.exe
                                  C:\Windows\System32\svchost.exe
                                  C:\Windows\System32\svchost.exe
                                  C:\Windows\System32\Ati2evxx.exe
                                  C:\Windows\System32\svchost.exe
                                  C:\Windows\System32\svchost.exe
                                  C:\Windows\System32\svchost.exe
                                  C:\Windows\System32\audiodg.exe
                                  C:\Windows\System32\SLsvc.exe
                                  C:\Windows\System32\svchost.exe
                                  C:\Users\fabien\Desktop\is120en_vista\is120en_vista\IceSword.exe
                                  C:\Windows\System32\svchost.exe
                                  C:\Windows\System32\taskeng.exe
                                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                                  C:\Windows\System32\spoolsv.exe
                                  C:\Windows\System32\svchost.exe
                                  C:\Windows\System32\dwm.exe
                                  C:\Windows\System32\taskeng.exe
                                  C:\Program Files\a-squared Anti-Malware\a2service.exe
                                  C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                  C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
                                  C:\Program Files\Windows Defender\MSASCui.exe
                                  C:\Windows\RtHDVCpl.exe
                                  C:\Windows\System32\SysMonitor.exe
                                  C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                                  C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                                  C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Apps\apdproxy.exe
                                  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                  C:\Windows\vVX3000.exe
                                  C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
                                  C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
                                  C:\Windows\System32\SearchFilterHost.exe
                                  C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                  C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                  C:\Program Files\Microsoft LifeCam\MSCamS32.exe
                                  C:\Windows\System32\SearchProtocolHost.exe
                                  C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                                  C:\Windows\System32\svchost.exe
                                  C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                                  C:\Windows\System32\svchost.exe
                                  C:\Windows\System32\svchost.exe
                                  C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
                                  C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
                                  C:\Windows\System32\SearchIndexer.exe
                                  C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                                  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                                  C:\Windows\System32\WUDFHost.exe
                                  C:\Windows\System32\rundll32.exe
                                  C:\Windows\system\wcdvtray.exe
                                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                  C:\Program Files\Windows Sidebar\sidebar.exe
                                  C:\Windows\System32\rundll32.exe
                                  C:\Windows\System32\mobsync.exe
                                  C:\Program Files\DAEMON Tools\daemon.exe
                                  C:\Program Files\MSN Messenger\msnmsgr.exe
                                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                  C:\Windows\ehome\ehtray.exe
                                  C:\Program Files\TribalWeb\tribalweb.exe
                                  C:\Windows\System32\wbem\WmiPrvSE.exe
                                  C:\Windows\ehome\ehmsas.exe
                                  C:\Program Files\Skype\Plugin Manager\skypePM.exe
                                  C:\Acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe
                                  C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
                                  C:\Program Files\MSN Messenger\usnsvc.exe
                                  C:\Windows\System32\svchost.exe
                                  C:\PROGRA~1\INCRED~1\bin\ImApp.exe
                                  C:\Windows\System32\VSSVC.exe
                                  C:\Program Files\MSN Messenger\livecall.exe
                                  1. Contributeur
                                    oui c´est bien ce que je voulais,,

                                    si tu as bien redemarré en mode sans echec et fait la manip avec btfix continue :

                                    a l´aide de hiajack this coche ceci :

                                    R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - (no file)
                                    O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - (no file)
                                    O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - (no file)
                                    O3 - Toolbar: (no name) - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - (no file)

                                    comment fixer :

                                    Tutoriel d´utilisation (video) :

                                    -> http://pageperso.aol.fr/balltrap34/demohijack.htm

                                    Télécharge IceSword ici:
                                    http://202.38.64.10/~jfpan/download/is120en_vista.zip
                                    Enregistre le sur ton bureau.

                                    Fais un clic droit sur le dossier is120en_vista.zip que tu viens de télécharger et clic sur "Extraire tout".
                                    Dans le nouveau dossier nommé is120en_vista qui sera apparu sur ton bureau, double clic sur le fichier IceSword.exe.

                                    A gauche dans la fenêtre du programme, clic sur "Process" (icône en forme de roue crantée).
                                    Une fois fait, click dans le menu du haut sur "LOG" (en bleu).

                                    Une boîte de dialogue va s'ouvrir, donne un nom au fichier rapport et enregistre le à un endroit ou tu seras sure de le retrouver facilement (le bureau...).
                                    Ensuite referme la fenêtre d'icesword et n'y touche plus :-).

                                    Si tu as suivie mon exemple tu auras donc sur ton bureau un fichier .log
                                    Ouvre-le et copie et colle tout son contenu dans ton prochain message.

                                    @+
                                    1. hou lala ca se complique je ne capte rien je te laisse la main voici le dernier rapport hijack+btfix (analyse faite apres redemarrage de mon pc c est bien ceux la que tu veux? @+

                                      Logfile of Trend Micro HijackThis v2.0.2
                                      Scan saved at 19:00:10, on 08/12/2007
                                      Platform: Windows Vista (WinNT 6.00.1904)
                                      MSIE: Internet Explorer v7.00 (7.00.6000.16546)
                                      Boot mode: Normal

                                      Running processes:
                                      C:\Windows\system32\taskeng.exe
                                      C:\Windows\system32\Dwm.exe
                                      C:\Windows\Explorer.EXE
                                      C:\Program Files\Windows Defender\MSASCui.exe
                                      C:\Windows\RtHDVCpl.exe
                                      C:\Windows\System32\SysMonitor.exe
                                      C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                                      C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                                      C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
                                      C:\Program Files\Adobe\Reader 8.0\Reader\Reader_SL.exe
                                      C:\Windows\vVX3000.exe
                                      C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
                                      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                                      C:\Windows\System32\rundll32.exe
                                      C:\Windows\system\wcdvtray.exe
                                      C:\Program Files\Windows Sidebar\sidebar.exe
                                      C:\Windows\System32\mobsync.exe
                                      C:\Program Files\DAEMON Tools\daemon.exe
                                      C:\Program Files\MSN Messenger\msnmsgr.exe
                                      C:\Windows\ehome\ehtray.exe
                                      C:\Program Files\Skype\Phone\Skype.exe
                                      C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                                      C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
                                      C:\Program Files\TribalWeb\tribalweb.exe
                                      C:\Windows\System32\rundll32.exe
                                      C:\Windows\ehome\ehmsas.exe
                                      C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
                                      C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
                                      C:\PROGRA~1\INCRED~1\bin\ImApp.exe
                                      C:\Program Files\Skype\Plugin Manager\skypePM.exe
                                      C:\Program Files\MSN Messenger\livecall.exe
                                      C:\Program Files\Mozilla Firefox\firefox.exe
                                      C:\Users\fabien\Desktop\HiJackThis\HijackThis.exe

                                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                      R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                      R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - (no file)
                                      O1 - Hosts: ::1 localhost
                                      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                      O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
                                      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                      O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - (no file)
                                      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
                                      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                      O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - (no file)
                                      O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                      O3 - Toolbar: (no name) - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - (no file)
                                      O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
                                      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                                      O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Windows\system32\SysMonitor.exe
                                      O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
                                      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                                      O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
                                      O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
                                      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                      O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
                                      O4 - HKLM\..\Run: [VX3000] C:\Windows\vVX3000.exe
                                      O4 - HKLM\..\Run: [PKR Pal] "C:\Program Files\PKR\pkrpal.exe" -osboot
                                      O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
                                      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                                      O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe" /d=60
                                      O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                                      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                                      O4 - HKLM\..\Run: [OWCWebCamDV] C:\Windows\system\wcdvtray.exe
                                      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                                      O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                                      O4 - HKCU\..\Run: [?????????] ??????????????e
                                      O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
                                      O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
                                      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                                      O4 - HKCU\..\Run: [EPSON Stylus DX5000 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIBVE.EXE /FU "C:\Windows\TEMP\E_SDE3F.tmp" /EF "HKCU"
                                      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                      O4 - HKCU\..\Run: [LaunchList] C:\Program Files\Pinnacle\Studio 11\LaunchList2.exe
                                      O4 - HKCU\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
                                      O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
                                      O4 - Startup: TribalWeb.lnk = C:\Program Files\TribalWeb\tribalweb.exe
                                      O4 - Global Startup: Empowering Technology Launcher.lnk = ?
                                      O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                                      O4 - Global Startup: Picture Package Menu.lnk = ?
                                      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                                      O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                                      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                                      O13 - Gopher Prefix:
                                      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                                      O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
                                      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                                      O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Malware\a2service.exe
                                      O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                      O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
                                      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                      O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
                                      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                      O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                                      O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
                                      O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
                                      O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                      O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
                                      O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
                                      O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                                      1. Contributeur
                                        re,

                                        ca a marché c´est cool ;-)

                                        1 Télécharge CCleaner.
                                        http://www.filehippo.com/download_ccleaner.html
                                        Installe le dans un répertoire dédié.

                                        2 Redémarre en mode sans echec. Attention, tu n'as pas accès à internet dans ce mode, note bien ce que tu as à faire.
                                        Démarre l'ordinateur.
                                        Une fois le chargement du BIOS terminé, il y a un écran noir. Appuye sur la touche F8 jusqu'à l'affichage du menu des options avancées de Windows.
                                        En utilisant les touches du curseur, sélectionne Mode sans échec et appuye sur Entrée.

                                        3.Lance le nettoyage des fichiers temporaires a l´aide de ccleaner : "nettoyeur"

                                        -> décoche la derniere case (Avancé si elle est cochée) puis click sur "lancer le nettoyage" qunand il aura terminé le scan click en bas a droite sur "lancer le nettoyage" et accepte par oui.

                                        4Ouvre BTFix.
                                        Clique sur Nettoyer.
                                        Un rapport va apparaître.

                                        5 Relance ccleaner pour nettoyer les erreures : "erreurs" :

                                        ->Coches toutes les cases dans les propriétés du nettoyeur de l´onglet "windows" et "applications", puis click en bas sur "chercher des erreurs" une fois terminé, clic sur "reparer les erreurs", tu auras un message pour sauvegarder ta base de registre, tu click "oui" puis tu recommence jusqu'à ce qu'il ne trouve plus rien.

                                        ps : les sauvegardes que tu auras faites, pourront etre supprimées ulterieurement si tout va bien.

                                        6 Redémarre normalement

                                        7 Poste un nouveau log HijackThis avec le rapport de BTFix.

                                        et repost un nouveau hijack this stpleaz

                                        @+
                                        • 1
                                        • 2