Ransom

Résolu
Bonjour a tous,
j'ai besoin de votre aide.

Mon PC est apparemment infecté par le cheval de troie Ransom.

Pouvez vous m'aider?

Je ne sais pas si c'est lié mais lorsque je veux lancer une restauration système Windows me dit que la protection du système est désactivée, alors que dans les paramètres tout est bien activé.

Merci

23 réponses

  1. salut tonpc n'estpas à jour

    ==

    Attention : cet outil peut etre détecté à tort comme virus

    tous les processus "non vitaux de windows" vont être coupés , enregistre ton travail.

    Désactive toutes tes protections si possible , antivirus , sandbox , pare-feux , etc....

    telecharge et enregistre Pre_Scan sur ton bureau :

    http://forums-fec.be/gen-hackman/Pre_Scan.exe

    mirroirs :

    http://general-changelog-team.fr/fr/downloads/viewdownload/41-outils-de-gen-hackman/52-pre-scan
    http://www.archive-host.com

    Avertissement :Il y aura une extinction du bureau pendant le scan --> pas de panique.

    une fois telechargé lance-le , laisse faire le scan jusqu'à l'apparition de "Pre_scan_la_date_et_l'heure.txt" sur le bureau.

    si l'outil est relancé plusieurs fois , il te proposera un menu et qu'aucune option n'est demandée, lance l'option "Kill"

    si l'outil est bloqué par l'infection utilise cette version avec extension .pif :

    http://forums-fec.be/gen-hackman/Pre_Scan.pif

    si l'outil detecte un proxy et que tu n'en as pas installé clique sur "supprimer le proxy"

    Il se peut qu'une multitude de fenêtres noires clignotent , laisse-le travailler

    Poste Pre_Scan_la_date_et_l'heure.txt qui apparaitra sur le bureau en fin de scan

    Il est possible que l'outil fasse redemarrer ton pc plusieurs fois , laisse-le faire

    NE LE POSTE PAS SUR LE FORUM !!! (il est trop long)

    Heberge le rapport sur http://pjjoint.malekal.com puis donne le lien obtenu en echange sur le forum où tu te fais aider
    0
    1. tu installes n'importe quoi.....ton pc est une poubelle numérique

      desinstalle Barre d'applications alOt
      desinstalle softonic et tout ce qui a attrait (de plus ne telecharge plus chez eux ni 01net , ils pourrissent les programmes )
      desinstalle Conduit/ConduitEngine
      desinstalle tout java
      desinstalle PriceGong
      desinstalle Wajam
      desinstalle adobe reader 9
      desinstalle RechercherWeb Toolbar
      desinstalle Crazy Browser

      ======================

      Fais analyser le(s) fichier(s) suivants sur Virustotal :

      Virus Total

      clique sur "Parcourir" et trouve puis selectionne ce(s) fichier(s) :

      C:\Windows\system32\pdfcmnnt.dll

      * Clique maintenant sur Envoyer le fichier. et laisse travailler tant que "Situation actuelle : en cours d'analyse" est affiché.
      * Il est possible que le fichier soit mis en file d'attente en raison d'un grand nombre de demandes d'analyses. En ce cas, il te faudra patienter sans actualiser la page.
      * Lorsque l'analyse est terminée colle le lien de(s)( la) page(s) dans ta prochaine réponse.

      ==========================

      Attention !!! pense à re-désactiver tes protections

      Clique sur ce lien : https://www.cjoint.com/?BHlmvqHguO1

      Selectionne tout le texte qui s'y trouve CTRL+A puis CTRL+C ou clic droit/copier

      Relance Pre_scan puis choisis l'option "Script"

      une page va s'ouvrir

      logiquement le texte que tu as sélectionné s'y trouve déjà , donc tu fermes et le programme va travailler.

      sinon colle-le (clic droit/coller ou ctrl+V) dans la page vierge.

      puis onglet fichier => enregistrer (pas enregistrer sous...) , puis ferme le texte

      des fenetres noires risquent de clignoter , c'est normal , c'est le programme qui travaille

      poste Pre_Script.txt qui apparaitra sur le bureau en fin de travail
      0
      1. "tu installes n'importe quoi.....ton pc est une poubelle numérique"
        C'est le PC de mes parents. Désolé pour eux ^^
        0
        1. lol la suite ^^
          0
      2. Le fichier existe bien sous system32 mais Virustotal ne le trouve pas.
        0
        1. copie-le sur ton bureau et analyse-le à partir du bureau
          0
          1. ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Pre_Script | 2.811 ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

            daniel : Windows 7 Home Premium (64 bits)

            Switchs : https://gen-hackman.kanak.fr/

            Script : 18:19:17

            ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

            ¤¤¤¤¤¤¤¤¤¤ | Registry Deletions

            Value Deleted : [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:
            Value Deleted : [HKU\S-1-5-21-1400645390-3981374266-313038540-1001\Software\Microsoft\Internet Explorer\URLSearchHooks]:{4daac69c-cba7-45e2-9bc8-1044483d3352}:
            Value Deleted : [HKU\S-1-5-21-1400645390-3981374266-313038540-1001\Software\Microsoft\Internet Explorer\URLSearchHooks]:{CA3EB689-8F09-4026-AA10-B9534C691CE0}:
            Value Deleted : [HKU\S-1-5-21-1400645390-3981374266-313038540-1001_Classes\Software\Microsoft\Internet Explorer\URLSearchHooks]:{CA3EB689-8F09-4026-AA10-B9534C691CE0}:
            Value Deleted : [HKU64\S-1-5-21-1400645390-3981374266-313038540-1001\Software\Microsoft\Internet Explorer\URLSearchHooks]:{4daac69c-cba7-45e2-9bc8-1044483d3352}:
            Value Deleted : [HKU64\S-1-5-21-1400645390-3981374266-313038540-1001\Software\Microsoft\Internet Explorer\URLSearchHooks]:{CA3EB689-8F09-4026-AA10-B9534C691CE0}:
            Value Deleted : [HKU64\S-1-5-21-1400645390-3981374266-313038540-1001_Classes\Software\Microsoft\Internet Explorer\URLSearchHooks]:{CA3EB689-8F09-4026-AA10-B9534C691CE0}:
            Value Deleted : [HKLM\Software\Microsoft\Internet Explorer\URLSearchHooks]:{4daac69c-cba7-45e2-9bc8-1044483d3352}
            Value Deleted : [HKLM\Software\Microsoft\Internet Explorer\Toolbar]:{4daac69c-cba7-45e2-9bc8-1044483d3352}
            Value Deleted : [HKLM\Software\Microsoft\Internet Explorer\Toolbar]:{30F9B915-B755-4826-820B-08FBA6BD249D}
            Value Deleted : [HKLM\Software\Microsoft\Internet Explorer\Toolbar]:{8FFA7469-654F-423E-84FE-6A583CB1C284}
            Value Deleted : [HKLM\Software\Microsoft\Internet Explorer\Toolbar]:{A531D99C-5A22-449b-83DA-872725C6D0ED}
            Key Deleted : HKU\S-1-5-21-1400645390-3981374266-313038540-1001\Software\Microsoft\Internet Explorer\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
            Key Deleted : HKU\S-1-5-21-1400645390-3981374266-313038540-1001\Software\Microsoft\Internet Explorer\SearchScopes\{A531D99C-5A22-449b-83DA-872725C6D0ED}
            Key Deleted : HKU64\S-1-5-21-1400645390-3981374266-313038540-1001\Software\Microsoft\Internet Explorer\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
            Key Deleted : HKU64\S-1-5-21-1400645390-3981374266-313038540-1001\Software\Microsoft\Internet Explorer\SearchScopes\{A531D99C-5A22-449b-83DA-872725C6D0ED}
            Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{08f24d68-9087-4b24-81ad-7b34af3e3ed5}
            Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{15B3FB63-66F4-4EFC-B717-BB283B85E79B}
            Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{343263AB-D732-4066-A274-4A487A07F108}
            Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{358E6F10-DE8A-4602-8424-179CA217F8EE}
            Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4becf16c-74f0-429b-8d3e-4fba507ac661}
            Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{56EF864B-75EA-4632-A968-29FA1D7D0BA0}
            Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
            Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8E1F80F4-953F-41E7-8460-E64AE5BE4ED3}
            Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{95a4104c-1c49-4c2a-9830-1be0f47e926c}
            Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9C6A861C-B233-4994-AFB1-C158EE4FC578}
            Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9da1d2cb-796d-4bec-bbaa-0aa9ccd80e15}
            Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C42103E4-7D10-4cc9-B2B4-C546BCCF8706}
            Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F8ADE2B4-33F7-479C-A949-BB7AA809F940}
            Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{fb9e068b-c612-4fa8-bdb9-d728a716a420}
            Key Deleted : HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{08f24d68-9087-4b24-81ad-7b34af3e3ed5}
            Key Deleted : HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4becf16c-74f0-429b-8d3e-4fba507ac661}
            Key Deleted : HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{95a4104c-1c49-4c2a-9830-1be0f47e926c}
            Key Deleted : HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9da1d2cb-796d-4bec-bbaa-0aa9ccd80e15}
            Key Deleted : HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{e5f90a07-7db7-4dcb-bd6d-d3fecd376ca3}
            Key Deleted : HKLM64\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{fb9e068b-c612-4fa8-bdb9-d728a716a420}
            Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1631550F-191D-4826-B069-D9439253D926}
            Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}
            Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4daac69c-cba7-45e2-9bc8-1044483d3352}
            Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{85F5CF95-EC8F-49fc-BB3F-38C79455CBA2}
            Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
            Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
            Key Deleted : HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}
            Key Deleted : HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
            Key Deleted : HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}
            Key Deleted : HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
            Key Deleted : HKU\S-1-5-21-1400645390-3981374266-313038540-1001\Software\Softonic
            Key Deleted : HKU\S-1-5-21-1400645390-3981374266-313038540-1001\Software\fAfvfSfP fVf#f" fEfBfU fh'Å ¶ ¬'³'ê'½f fJf< fAfvfSfP fVf#f"
            Key Deleted : HKU64\S-1-5-21-1400645390-3981374266-313038540-1001\Software\fAfvfSfP fVf#f" fEfBfU fh'Å ¶ ¬'³'ê'½f fJf< fAfvfSfP fVf#f"
            Key Deleted : HKLM\Software\Conduit
            Key Deleted : HKLM\Software\conduitEngine
            Key Deleted : HKLM\Software\Softonic_France
            Key Deleted : HKLM\Software\Wajam

            ¤

            Folder Deleted : |D| - C:\Users\daniel\AppData\Roaming\Mozilla\Firefox\Profiles\uueqny8b.default\extensions\m3ffxtbr@mywebsearch.com
            C:\Users\daniel\AppData\Roaming\Mozilla\Firefox\Profiles\uueqny8b.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829} : Not Found !
            File Deleted : |A| - C:\Users\daniel\AppData\Roaming\Mozilla\Firefox\Profiles\uueqny8b.default\searchplugins\fissa.xml
            File Deleted : |A| - C:\Users\daniel\AppData\Roaming\Mozilla\Firefox\Profiles\uueqny8b.default\searchplugins\recherche-alot.xml
            File Deleted : |A| - C:\Users\daniel\AppData\Roaming\Mozilla\Firefox\Profiles\uueqny8b.default\searchplugins\sweetim.xml
            File Deleted : |A| - C:\alotserviceruntime.log
            File Deleted : |A| - C:\Windows\v
            File Deleted : |A| - C:\Users\daniel\Downloads\*.exe
            C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong : Not Found !
            Folder Deleted : |D| - C:\Users\daniel\AppData\Roaming\OfferBox
            File Deleted : |A| - C:\ProgramData\dmrcgucxyodvcgc
            Folder Deleted : |D| - C:\ProgramData\xwnrjujkqarmqwo
            Folder Deleted : |HD| - C:\Users\daniel\AppData\Local\OpenCandy
            Folder Deleted : |D| - C:\Users\daniel\AppData\Local\Wajam
            C:\Program Files (x86)\Conduit : Not Found !
            C:\Program Files (x86)\ConduitEngine : Not Found !
            Folder Deleted : |D| - C:\Program Files (x86)\pdfforge Toolbar
            C:\Program Files (x86)\PriceGong : Not Found !
            C:\Program Files (x86)\RechercherWeb Toolbar : Not Found !
            C:\Program Files (x86)\Softonic_France : Not Found !
            C:\Program Files (x86)\Wajam : Not Found !
            File Deleted : |A| - C:\Windows\System32\Tasks\{D9B6DB02-46E5-4637-9040-69BE355ACECF}
            File Deleted : |A| - C:\Windows\System32\Tasks\{EDAEAF9C-4CB4-40FB-9EE6-19C51C988C2B}
            : Not Found !

            ¤¤¤¤¤¤¤¤¤¤ | MBR

            Windows Version: Windows 7 Home Premium Edition
            Windows Information: Service Pack 1 (build 7601), 64-bit
            Base Board Manufacturer: MSI
            BIOS Manufacturer: American Megatrends Inc.
            System Manufacturer: HP-Pavilion
            System Product Name: WC963AA-ABF p6355fr
            Logical Drives Mask: 0x000007dc

            Analysis of file "C:\Pre_Scan\MBR.bin":
            Unknown MBR code

            ¤

            ¤¤¤¤¤¤¤¤¤¤ | Nettoyage disque

            Nettoyage du disque effectué

            ¤

            Fin : 18:20:07

            ¤¤¤¤¤¤¤¤¤¤ ( EOF ) ¤¤¤¤¤¤¤¤¤¤
            0
            1. Télécharge et enregistre ADWcleaner sur ton bureau :

              ADWCleaner (Merci à Xplode)

              Lance le,

              (Pour vista et seven => clic droit "executer en tant qu'administrateur")

              clique sur suppression et poste son rapport.
              0
              1. # AdwCleaner v1.800 - Rapport créé le 11/08/2012 à 23:36:42
                # Mis à jour le 01/08/2012 par Xplode
                # Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)
                # Nom d'utilisateur : daniel - DANIEL-PC
                # Exécuté depuis : C:\Users\daniel\Desktop\adwcleaner.exe
                # Option [Suppression]

                ***** [Services] *****

                ***** [Fichiers / Dossiers] *****

                Dossier Supprimé : C:\Users\daniel\AppData\LocalLow\FunWebProducts
                Dossier Supprimé : C:\Users\daniel\AppData\LocalLow\MyWebSearch
                Dossier Supprimé : C:\Users\daniel\AppData\LocalLow\pdfforge
                Dossier Supprimé : C:\Users\daniel\AppData\LocalLow\Search Settings
                Dossier Supprimé : C:\Users\daniel\AppData\Roaming\Mozilla\Firefox\Profiles\uueqny8b.default\SweetIMToolbarData
                Fichier Supprimé : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk

                ***** [Registre] *****

                [*] Clé Supprimée : HKLM\SOFTWARE\Classes\Toolbar.CT2542115
                Clé Supprimée : HKCU\Software\AppDataLow\Software\Fun Web Products
                Clé Supprimée : HKCU\Software\AppDataLow\Software\FunWebProducts
                Clé Supprimée : HKCU\Software\AppDataLow\Software\MyWebSearch
                Clé Supprimée : HKCU\Software\AppDataLow\Software\PriceGong
                Clé Supprimée : HKCU\Software\Softonic
                Clé Supprimée : HKLM\SOFTWARE\Classes\Conduit.Engine
                Clé Supprimée : HKLM\SOFTWARE\Google\Chrome\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp
                Clé Supprimée : HKLM\SOFTWARE\MozillaPlugins\@mywebsearch.com/Plugin
                Valeur Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform [FunWebProducts]
                Valeur Supprimée : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [m3ffxtbr@mywebsearch.com]

                ***** [Registre - GUID] *****

                Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}
                Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}
                Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}
                Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{3E720453-B472-4954-B7AA-33069EB53906}
                Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}
                Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{BBABDC90-F3D5-4801-863A-EE6AE529862D}
                Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}
                Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}
                Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8}
                [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}
                [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{120927BF-1700-43BC-810F-FAB92549B390}
                [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}
                [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{1F52A5FA-A705-4415-B975-88503B291728}
                [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{247A115F-06C2-4FB3-967D-2D62D3CF4F0A}
                [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}
                [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}
                [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{3E720453-B472-4954-B7AA-33069EB53906}
                [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}
                [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}
                [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}
                [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{7473D293-B7BB-4F24-AE82-7E2CE94BB6A9}
                [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9}
                [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9}
                [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{8E9CF769-3D3B-40EB-9E2D-76E7A205E4D2}
                [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{90449521-D834-4703-BB4E-D3AA44042FF8}
                [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{991AAC62-B100-47CE-8B75-253965244F69}
                [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{A626CDBD-3D13-4F78-B819-440A28D7E8FC}
                [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{BBABDC90-F3D5-4801-863A-EE6AE529862D}
                [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{D6FF3684-AD3B-48EB-BBB4-B9E6C5A355C1}
                [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{DE38C398-B328-4F4C-A3AD-1B5E4ED93477}
                [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}
                [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{E79DFBC9-5697-4FBD-94E5-5B2A9C7C1612}
                [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}
                [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8}
                [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{F87D7FB5-9DC5-4C8C-B998-D8DFE02E2978}

                ***** [Navigateurs] *****

                -\\ Internet Explorer v9.0.8112.16421

                [OK] Le registre ne contient aucune entrée illégitime.

                -\\ Mozilla Firefox v14.0.1 (fr)

                Nom du profil : default
                Fichier : C:\Users\daniel\AppData\Roaming\Mozilla\Firefox\Profiles\uueqny8b.default\prefs.js

                [OK] Le fichier ne contient aucune entrée illégitime.

                -\\ Google Chrome v [Impossible d'obtenir la version]

                Fichier : C:\Users\daniel\AppData\Local\Google\Chrome\User Data\Default\Preferences

                [OK] Le fichier ne contient aucune entrée illégitime.

                *************************

                AdwCleaner[S1].txt - [5542 octets] - [11/08/2012 23:36:42]

                ########## EOF - C:\AdwCleaner[S1].txt - [5670 octets] ##########
                0
                1. fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

                  ▶ Télécharge ici :

                  Malwarebytes

                  ▶ Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

                  relance malwarebytes en suivant scrupuleusement ces consignes :

                  ! Déconnecte toi et ferme toutes applications en cours !

                  ▶ Lance Malwarebyte's .

                  Fais un examen dit "Complet" .

                  ▶ Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
                  ▶ à la fin tu cliques sur "résultat" .
                  Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

                  Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

                  Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)

                  0
                  1. Malwarebytes Anti-Malware 1.62.0.1300
                    www.malwarebytes.org

                    Version de la base de données: v2012.08.11.04

                    Windows 7 Service Pack 1 x64 NTFS
                    Internet Explorer 9.0.8112.16421
                    daniel :: DANIEL-PC [administrateur]

                    12/08/2012 09:37:27
                    mbam-log-2012-08-12 (09-37-27).txt

                    Type d'examen: Examen complet (C:\|D:\|K:\|)
                    Options d'examen activées: Mémoire | Démarrage | Registre | Système de fichiers | Heuristique/Extra | Heuristique/Shuriken | PUP | PUM
                    Options d'examen désactivées: P2P
                    Elément(s) analysé(s): 464687
                    Temps écoulé: 1 heure(s), 43 minute(s), 44 seconde(s)

                    Processus mémoire détecté(s): 0
                    (Aucun élément nuisible détecté)

                    Module(s) mémoire détecté(s): 0
                    (Aucun élément nuisible détecté)

                    Clé(s) du Registre détectée(s): 0
                    (Aucun élément nuisible détecté)

                    Valeur(s) du Registre détectée(s): 0
                    (Aucun élément nuisible détecté)

                    Elément(s) de données du Registre détecté(s): 0
                    (Aucun élément nuisible détecté)

                    Dossier(s) détecté(s): 0
                    (Aucun élément nuisible détecté)

                    Fichier(s) détecté(s): 1
                    C:\Users\daniel\Desktop\winlogon.exe (Heuristics.Reserved.Word.Exploit) -> Mis en quarantaine et supprimé avec succès.

                    (fin)
                    0
                    1. Ca a l'air bon. MERCI.

                      Tu m'as demandé de supprimer Adobe Reader, tu me conseilles quoi en remplacement pour ouvrir les pdf?
                      0
                      1. J'ai suivi les directives. Tout est OK.
                        Encore merci.
                        0
                        1. Ah non, encore un truc.
                          Lorsque je lance la restauration du système, il me dit que la restauration est désactivée.
                          Dans la configuration la ligne "Ne restaurer que les versions précédentes des fichiers" est sélectionnée et "restaurer les paramètres système et les versions précédentes des fichiers" est grisée.
                          0
                          1. ah ouai mais non
                            je n'etais pas sous le bon disque
                            0
                            • 1
                            • 2