Generic host Process Win32 Services danger???

Bonjour,
Zone alarm me demande l'autorisation pour Generic host Process Win32 Services d'accédez des connexions d'une zone sûre.Dois je accepter??

--
La connerie n'a pas de frontière, c'est pour ça que tous les hommes sont frères...
Configuration: Windows XP
Firefox 3.0.1

52 réponses

Résumé de la discussion

Zone Alarm demande l'autorisation pour le Generic Host Process Win32 Services d'accéder à des connexions dans une zone sûre, et la question porte sur l'opportunité d'accepter. Plusieurs réponses notent que ce processus peut héberger des applications et avoir été exploité par virus, il est prudent de ne pas accepter sans vérification et d'effectuer un scan avec Malwarebytes ou The Cleaner. En cas de doute, il est conseillé de vérifier les mises à jour de Windows et du navigateur, puis d'examiner les résultats des outils de sécurité; certains éléments signalés peuvent être adware. D'autres interventions suggèrent des sources externes comme des pages de sécurité ou des utilitaires, notamment pour isoler ou bloquer des composants malveillants, sans conclure sur l'état final du PC.

Bobot (l’IA à votre service)
  1. Bonjour,

    Ce Generic Hosts process peut avoir plusieurs applications. Il a par exemple déjà été exploité par certains virus et sert à la résolution DNS cependant il n'est pas obligatoire et peut être désactivé

    Démarrer > exécuter > tape services.msc
    recherche dans la liste "client DNS", double clique dessus type de démarrage désactivé et clique sur arrêter.

    Pour l'icône
    Panneaux de configuration > centre de sécurité > clique a gauche sur "modifier la façon dont le centre de sécurité me previen > décoche les cases ou uniquement celle concernant les mises à jour automatiques.
    0
    1. il me proposer la connexion entre plusieurs zone sure.
      0
      1. win 32 est suspect?
        0
        1. voui
          0
      2. tu as sauvegarder les rapport de malware et the cleaner?
        si oui post les, sinon...refait les ;)
        0
        1. j'ai faire repair selected et maintenat j'ai system health, j'aurai pas du?
          0
          1. S ID Object Name Threat

            00001 C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP199\A0070942.dll Win32.Suspect

            00002 C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP200\A0071357.dll Win32.Suspect

            00003 C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP200\A0071588.dll Win32.Suspect

            00004 C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP200\A0071621.exe RiskTool.Win32.PsKill.p

            0
            1. c'est le rapport de quoi ça U_u
              0
              1. the cleaner.^^oublié dsl
                0
            2. tu as passé un scan avec anti malware?
              https://informatique-123.superforum.fr/t7-tutorial-malwarebytes-anti-malware

              A la fin de l'installation, veille à ce que l'option Mettre à jour Malwarebytes' Anti-Malware soit cochée. >>> clique sur "Terminer"
              Lance Malwarebyte's Anti-Malware en double-cliquant sur l'icône sur le bureau.
              Au premier lancement, une fenêtre t'annonce que la version est Free >>> clique sur ok

              Laisse les Mises à jour se télécharger
              *** Referme le programme ***

              Lance Malwarebyte's Anti-Malware
              Onglet "Recherche" >>> coche Exécuter un examen complet >>> Rechercher
              Sélectionne ton disque dur >>> clic sur Lancer l'examen
              Suppression des éléments détectés >>>> clique sur Supprimer la sélection
              Colle le rapport de malwarebytes dans ta réponse
              S'il t'es demandé de redémarrer >>> clique sur "Yes"

              puis repost un rapport hijackthis
              0
              1. rapport hijackthis :

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 10:34:00, on 13/08/2008
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                C:\WINDOWS\Explorer.EXE
                C:\WINDOWS\ehome\ehtray.exe
                C:\WINDOWS\RTHDCPL.EXE
                C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
                C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
                C:\WINDOWS\system32\rundll32.exe
                C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                C:\Program Files\iTunes\iTunesHelper.exe
                C:\Program Files\Bonjour\mDNSResponder.exe
                C:\WINDOWS\eHome\ehRecvr.exe
                C:\WINDOWS\eHome\ehSched.exe
                C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                C:\WINDOWS\system32\nvsvc32.exe
                C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\issch.exe
                C:\Program Files\QuickTime\QTTask.exe
                C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                C:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP2c\RpcAgentSrv.exe
                C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
                C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\Elservice.exe
                C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
                C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
                C:\WINDOWS\system32\dllhost.exe
                C:\Program Files\iPod\bin\iPodService.exe
                C:\WINDOWS\eHome\ehmsas.exe
                C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
                C:\Program Files\Mozilla Firefox\firefox.exe
                C:\Program Files\aMSN\bin\wish.exe
                C:\HP\KBD\KBD.EXE
                c:\windows\system\hpsysdrv.exe
                C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://fr.search.yahoo.com/?fr=cb-hp06
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com/?SearchSource=10&ctid=CT1098640
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60312
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60312
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://fr.search.yahoo.com/?fr=cb-hp06
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://fr.search.yahoo.com/?fr=cb-hp06
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60312
                R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                R3 - URLSearchHook: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll
                O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
                O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                O2 - BHO: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL
                O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                O2 - BHO: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll
                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                O3 - Toolbar: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL
                O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                O3 - Toolbar: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll
                O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
                O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
                O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
                O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
                O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
                O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
                O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                O4 - HKLM\..\Run: [BootSkin Startup Jobs] "C:\PROGRA~1\Stardock\WINCUS~1\BootSkin\BootSkin.exe" /StartupJobs
                O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                O4 - HKLM\..\Run: [ISUSScheduler] "C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\issch.exe" -start
                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe" /automount
                O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
                O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
                O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
                O4 - Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE
                O4 - Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe
                O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
                O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                O23 - Service: Intel(R) Quick Resume technology (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\Elservice.exe
                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP2c\RpcAgentSrv.exe
                O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe

                End of file - 12606 bytes

                Je l'ai fait analysé ici.

                0
            3. si je les fix maintenant j'aurai plus les deux infections??

              quand je regarde anti malware j'ai effectivement 2 infections même si le scan n'est pas encore terminé...

              soit dis en passant antivir me fait des alertes concernant google toblar et hidjackthis le confirme apparement selon l'analyse que j'ai fait là
              0
              1. les deux lignes ne correspondent pas aux infections.

                ce sont celle ci:
                O4 - Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE
                O4 - Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe

                mais les fixer ne servira à rien, hijackthis ne les supprimera pas.
                fixer une ligne efface juste la valeur du registre, il la remet à zéro.

                La désinfection marchera si au prochain scann les deux lignes mentionné précédemment auront disparu.
                0
              2. antivir viens de me faire une alerte de googletoblar c'est un trojan...
                0
              3. @varfendellelles sont encore là toute les deux même si j'ai supprimé les fichier infécté découvert par anti malware..
                0
              4. @lunastix275même si j'ai supprimé les fichier infécté découvert par anti malware..
                ==> hélas, malware ne les à pas supprimé. c'est bien la le problème.
                0
            4. désinstalle ce logiciel alors ^^'
              0
              1. ok c'est fait...

                rapport anti malware :

                Malwarebytes' Anti-Malware 1.24
                Version de la base de données: 1047
                Windows 5.1.2600 Service Pack 2

                11:28:31 13/08/2008
                mbam-log-8-13-2008 (11-28-22).txt

                Type de recherche: Examen complet (C:\|D:\|)
                Eléments examinés: 185629
                Temps écoulé: 57 minute(s), 25 second(s)

                Processus mémoire infecté(s): 0
                Module(s) mémoire infecté(s): 0
                Clé(s) du Registre infectée(s): 1
                Valeur(s) du Registre infectée(s): 0
                Elément(s) de données du Registre infecté(s): 0
                Dossier(s) infecté(s): 1
                Fichier(s) infecté(s): 1

                Processus mémoire infecté(s):
                (Aucun élément nuisible détecté)

                Module(s) mémoire infecté(s):
                (Aucun élément nuisible détecté)

                Clé(s) du Registre infectée(s):
                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} (Adware.Agent) -> No action taken.

                Valeur(s) du Registre infectée(s):
                (Aucun élément nuisible détecté)

                Elément(s) de données du Registre infecté(s):
                (Aucun élément nuisible détecté)

                Dossier(s) infecté(s):
                C:\Program Files\OneStepSearch (Adware.OneStepSearch) -> No action taken.

                Fichier(s) infecté(s):
                C:\Documents and Settings\jocelyn bis\Bureau\Jocelyn\instalateur\DivX Movies\EvID4226Patch.exe (Adware.Agent) -> No action taken.
                0
                1. ok je suis en train de faire le scan avec navilog....
                  0
                  1. Contributeur
                    Salut,
                    En passant >>> No action taken. signifie que rien n'a été supprimé à la fin du scan de Malwarebytes' Anti-Malware . Il faut le recommencer!

                    * Démarre en mode sans échec
                    Comment faire >> https://www.micro-astuce.com/depannage/demarrer-mode-sans-echec.php
                    Redémarres l’ordinateur
                    Dès le chargement du BIOS, commences à appuyer sur la touche F8 de ton clavier,i jusqu'au ou le menu des options avancées de Windows apparait.
                    Sélectionne "Mode sans échec" dans le menu puis appuyez sur Entrée.

                    * Lance MalwareByte's Anti-Malware, clique sur Exécuter un examen complet puis Rechercher et sélectionnez tous tes disques durs

                    * Une fois le scan terminé, clique sur supprimer (si un message te demande de redémarrer le PC, accepte.)

                    * Un rapport sera généré, enregistre le de manière à le retrouver sur ton bureau par exemple et poste le ici.

                    @++
                    0
                    1. je suis allez en quarantaine et j'ai tout supprimés c'est bon?
                      0
                    2. Contributeur
                      @lunastix275je suis allez en quarantaine et j'ai tout supprimés c'est bon?
                      Oui c'est bon mais en mode sans échec c'est plus efficace ;-)

                      Met un nouveau rapport hijackthis.

                      ++
                      0
                    3. @lunastix275Je te conseil de faire plutôt ce que E..T propose, c'est effectivement la meilleur solution. ce n'est pas si simple de supprimer un fichier infecté, même s'il est mis en quarantaine
                      0
                    4. @varfendellvoila le rapport hijackthis :

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 11:57:22, on 13/08/2008
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\WINDOWS\ehome\ehtray.exe
                      C:\WINDOWS\RTHDCPL.EXE
                      C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
                      C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
                      C:\WINDOWS\system32\rundll32.exe
                      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                      C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      C:\Program Files\iTunes\iTunesHelper.exe
                      C:\Program Files\Bonjour\mDNSResponder.exe
                      C:\WINDOWS\eHome\ehRecvr.exe
                      C:\WINDOWS\eHome\ehSched.exe
                      C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                      C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                      C:\WINDOWS\system32\nvsvc32.exe
                      C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\issch.exe
                      C:\Program Files\QuickTime\QTTask.exe
                      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                      C:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP2c\RpcAgentSrv.exe
                      C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
                      C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                      C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\Elservice.exe
                      C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
                      C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
                      C:\WINDOWS\system32\dllhost.exe
                      C:\Program Files\iPod\bin\iPodService.exe
                      C:\WINDOWS\eHome\ehmsas.exe
                      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
                      C:\Program Files\Mozilla Firefox\firefox.exe
                      C:\Program Files\aMSN\bin\wish.exe
                      C:\HP\KBD\KBD.EXE
                      c:\windows\system\hpsysdrv.exe
                      C:\WINDOWS\system32\rundll32.exe
                      C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                      C:\WINDOWS\system32\NOTEPAD.EXE

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://fr.search.yahoo.com/?fr=cb-hp06
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60312
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60312
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://fr.search.yahoo.com/?fr=cb-hp06
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://fr.search.yahoo.com/?fr=cb-hp06
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60312
                      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
                      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                      R3 - URLSearchHook: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll
                      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                      O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                      O2 - BHO: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL
                      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                      O2 - BHO: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll
                      O3 - Toolbar: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL
                      O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                      O3 - Toolbar: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll
                      O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
                      O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
                      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                      O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                      O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
                      O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
                      O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                      O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
                      O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
                      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                      O4 - HKLM\..\Run: [BootSkin Startup Jobs] "C:\PROGRA~1\Stardock\WINCUS~1\BootSkin\BootSkin.exe" /StartupJobs
                      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                      O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                      O4 - HKLM\..\Run: [ISUSScheduler] "C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\issch.exe" -start
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe" /automount
                      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                      O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
                      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                      O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                      O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
                      O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
                      O4 - Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE
                      O4 - Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe
                      O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                      O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
                      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                      O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                      O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                      O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                      O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                      O23 - Service: Intel(R) Quick Resume technology (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\Elservice.exe
                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                      O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP2c\RpcAgentSrv.exe
                      O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
                      0
                  2. navilog :

                    Search Navipromo version 3.6.3 commencé le 13/08/2008 à 11:45:33,23

                    !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                    !!! Postez ce rapport sur le forum pour le faire analyser !!!
                    !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

                    Outil exécuté depuis C:\Program Files\navilog1
                    Session actuelle : "jocelyn bis"

                    Mise à jour le 09.08.2008 à 18h00 par IL-MAFIOSO

                    Microsoft Windows XP [version 5.1.2600]
                    Internet Explorer : 6.0.2900.2180
                    Système de fichiers : NTFS

                    Recherche executé en mode normal

                    *** Recherche Programmes installés ***

                    *** Recherche dossiers dans "C:\WINDOWS" ***

                    *** Recherche dossiers dans "C:\Program Files" ***

                    *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

                    *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***

                    *** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***

                    *** Recherche dossiers dans "C:\Documents and Settings\jocelyn bis\applic~1" ***

                    *** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\applic~1" ***

                    *** Recherche dossiers dans "C:\DOCUME~1\Myriam\applic~1" ***

                    *** Recherche dossiers dans "C:\DOCUME~1\Patrick\applic~1" ***

                    *** Recherche dossiers dans "C:\Documents and Settings\jocelyn bis\locals~1\applic~1" ***

                    *** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" ***

                    *** Recherche dossiers dans "C:\DOCUME~1\HP_ADM~1\locals~1\applic~1" ***

                    *** Recherche dossiers dans "C:\DOCUME~1\Myriam\locals~1\applic~1" ***

                    *** Recherche dossiers dans "C:\DOCUME~1\Patrick\locals~1\applic~1" ***

                    *** Recherche dossiers dans "C:\Documents and Settings\jocelyn bis\menudm~1\progra~1" ***

                    *** Recherche dossiers dans "C:\DOCUME~1\Myriam\menudm~1\progra~1" ***

                    *** Recherche dossiers dans "C:\DOCUME~1\Patrick\menudm~1\progra~1" ***

                    *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
                    pour + d'infos : http://www.gmer.net

                    *** Recherche avec GenericNaviSearch ***
                    !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
                    !!! A vérifier impérativement avant toute suppression manuelle !!!

                    * Recherche dans "C:\WINDOWS\system32" *

                    * Recherche dans "C:\Documents and Settings\jocelyn bis\locals~1\applic~1" *

                    * Recherche dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

                    * Recherche dans "C:\DOCUME~1\HP_ADM~1\locals~1\applic~1" *

                    * Recherche dans "C:\DOCUME~1\Myriam\locals~1\applic~1" *

                    * Recherche dans "C:\DOCUME~1\Patrick\locals~1\applic~1" *

                    *** Recherche fichiers ***

                    *** Recherche clés spécifiques dans le Registre ***

                    *** Module de Recherche complémentaire ***
                    (Recherche fichiers spécifiques)

                    1)Recherche nouveaux fichiers Instant Access :

                    2)Recherche Heuristique :

                    * Dans "C:\WINDOWS\system32" :

                    * Dans "C:\Documents and Settings\jocelyn bis\locals~1\applic~1" :

                    * Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" :

                    * Dans "C:\DOCUME~1\HP_ADM~1\locals~1\applic~1" :

                    * Dans "C:\DOCUME~1\Myriam\locals~1\applic~1" :

                    * Dans "C:\DOCUME~1\Patrick\locals~1\applic~1" :

                    3)Recherche Certificats :

                    Certificat Egroup absent !
                    Certificat Electronic-Group absent !
                    Certificat Montorgueil absent !
                    Certificat OOO-Favorit absent !
                    Certificat Sunny-Day-Design-Ltd absent !

                    4)Recherche fichiers connus :

                    *** Analyse terminée le 13/08/2008 à 11:49:51,18 ***
                    0
                    1. j'utilise mozilla firefox, et j'ai désinstallé internet explorer avec c cleaner(apparement sa a pas marcher -_-')
                      0
                      1. Contributeur
                        Ouep,

                        Désinstalle la toolbar yahoo :
                        https://fr.aide.yahoo.com/kb/account?redirect=true

                        Met internet explorer à jour message 31

                        Télécharge >> Lop S&D.exe << puis enregistres-le sur ton Bureau .
                        double-clic sur le fichier LopSD.exe suffira à lancer l'installation
                        Accepte le contat de licence
                        Créer le répertoire de destination, accepte en cliquant sur oui
                        Un raccourci sera créé sur ton Bureau.
                        Double clic dessus.
                        Choisis la langue f pour Français puis valide par Entrée.
                        Choisis l'option Recherche en saisissant 1 valides par Entrée.
                        Ton bureau va disparaitre c'est normal.
                        Patiente le temps du scan
                        A la fin du scan un rapport sera généré et s'ouvrira automatiquement dans le Bloc-Notes.
                        Copies-colles le contenu de ce rapport ici.
                        >>On le trouve aussi en %systemdrive%\LopR.txt

                        @++
                        0
                        1. le scan dure longtemps?
                          0
                      • 1
                      • 2
                      • 3