Mozilla déraille

Résolu
Bonjour,

Depuis deux jours, quand je vais sur Mozilla j'ai une page de base sans couleur ni image, que du texte et des cadres même lors d'une recherche c'est la même chose, textes et cadres comme quand on construit un site. J'ai supprimé Mozilla et je l'ai réinstallé idem.
Merci si vous avez une réponse.

34 réponses

Résumé de la discussion

Le fil porte sur un problème de rendu Web sous Windows XP avec Mozilla et Internet Explorer 6, où une page s’affiche en texte et cadres sans couleur ni images, même après réinstallation. Des réponses évoquent une infection potentielle et recommandent d’exécuter MBAM, de mettre à jour le programme et d’analyser le système, puis de générer et partager les rapports pour diagnostic. D’autres conseils promeuvent ZHPDiag et, éventuellement, ComboFix, en indiquant les étapes d’installation, la désactivation des antivirus et l’envoi des fichiers logs pour aide technique spécifique. En cas de suite, plusieurs intervenants coordonnent leurs actions et proposent des liens de téléchargement pour les outils d’analyse, avec les mentions des rapports et des étapes à suivre.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Bonjour,

    le rapport Ad-remover dit :

    --------------------\\ ROOTKIT !!

    Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_TDSSSERV.SYS]


    ca ne part pas avec les logiciels que ont t'a donné (ni avec les mises à jour même si il faut les faire).

    ===

    1) Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

    2) Télécharge Malwarebytes' Anti-Malware (MBAM) et enregistre le sur ton Bureau.

    hxxp://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html

    3) A la fin du téléchargement, ferme toutes les fenêtres et programmes, y compris celui-ci.

    4) Double-clique sur l'icône Download_mbam-setup.exe sur ton bureau pour démarrer le programme d'installation.

    5) Pendant l'installation, suis les indications (en particulier le choix de la langue et l'autorisation d'accession à Internet). N'apporte aucune modification aux réglages par défaut et, en fin d'installation, vérifie que les options Update Malwarebytes' Anti-Malware et Launch Malwarebytes' Anti-Malware sont cochées.

    6) MBAM démarrera automatiquement et enverra un message demandant à mettre à jour le programme avant de lancer une analyse. Comme MBAM se met automatiquement à jour en fin d'installation, clique sur OK pour fermer la boîte de dialogue. La fenêtre principale de MBAM s'affiche :

    7) Dans l'onglet analyse, vérifie que "Exécuter une analyse rapide" est coché et clique sur le bouton Rechercher pour démarrer l'analyse.

    8) MBAM analyse ton ordinateur. L'analyse peut prendre un certain temps. Il suffit de vérifier de temps en temps son avancement.

    9) A la fin de l'analyse, un message s'affiche indiquant la fin de l'analyse. Clique sur OK pour poursuivre.

    10) Si des malwares ont été détectés, leur liste s'affiche.
    En cliquant sur Suppression (?) , MBAM va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.

    11) MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Ferme le Bloc-notes. (Le rapport peut être retrouvé sous l'onglet Rapports/logs)

    12) Ferme MBAM en cliquant sur Quitter.

    13) Poste le rapport dans ta réponse

    ===
    Pour voir ce qui reste :

    Télécharge la dernière version de ZHPDiag

    Enregistre le sur ton Bureau.

    Une fois le téléchargement achevé,fais un double clic sur ZHPDiag.exe et suis les instructions.

    N'oublie pas de cocher la case qui permet de mettre un raccourci sur le Bureau.

    pour Xp :Double clique sur le raccourci ZHPDiag sur ton Bureau.

    pour vista et Seven : fais un clic droit sur le raccourci ZHPDiag sur ton Bureau et choisis "exécuter en tant qu'administrateur".

    /|\ l'outil a créé 2 icônes ZHPDiag et ZHPFix.

    Clique sur la loupe pour lancer l'analyse.

    Laisse l'outil travailler, il peut être assez long.

    Ferme ZHPDiag en fin d'analyse.

    Pour transmettre le rapport clique sur Cijoint

    Clique sur Parcourir et cherche le répertoire où est installé ZHPDiag (en général C:\Program Files\ZHPDiag).

    Sélectionne le fichier ZHPDiag.txt.

    Clique sur "Cliquez ici pour déposer le fichier".

    Un lien de cette forme :

    http://www.cijoint.fr/cjlink.php?file=cj200905/cijSKAP5fU.txt

    est ajouté dans la page.

    Copie ce lien dans ta réponse.
    3
    1. Contributeur sécurité
      Bonjour,

      tu as fait le reste ?

      ===

      mets à jour MBAM, relance le et poste le rapport.

      ===

      Télécharge la dernière version de ZHPDiag

      Enregistre le sur ton Bureau.

      Une fois le téléchargement achevé,fais un double clic sur ZHPDiag.exe et suis les instructions.

      N'oublie pas de cocher la case qui permet de mettre un raccourci sur le Bureau.

      pour Xp :Double clique sur le raccourci ZHPDiag sur ton Bureau.

      pour vista et Seven : fais un clic droit sur le raccourci ZHPDiag sur ton Bureau et choisis "exécuter en tant qu'administrateur".

      /|\ l'outil a créé 2 icônes ZHPDiag et ZHPFix.

      Clique sur la loupe pour lancer l'analyse.

      Laisse l'outil travailler, il peut être assez long.

      Ferme ZHPDiag en fin d'analyse.

      Pour transmettre le rapport clique sur Cijoint

      Clique sur Parcourir et cherche le répertoire où est installé ZHPDiag (en général C:\Program Files\ZHPDiag).

      Sélectionne le fichier ZHPDiag.txt.

      Clique sur "Cliquez ici pour déposer le fichier".

      Un lien de cette forme :

      http://www.cijoint.fr/cjlink.php?file=cj200905/cijSKAP5fU.txt

      est ajouté dans la page.

      Copie ce lien dans ta réponse.

      ===

      Je suis absent de cet AM à vendredi soir.

      Je vais demander à sKe69 de poursuivre la désinfection (on travaille avec les mêmes outils et les mêmes méthodes).
      1
      1. ok merci
        0
    2. Salut, télécharge ceci pour faire tes mise à jour:

      https://www.flexera.com/products/operations/software-vulnerability-management.html

      mets le en mode Avancer,

      dans l'ongler------>Analyser, clic sur Analyser (attends la fin du scan!)

      ensuite clic sur Vulnérable,

      en face de chaque logiciels, tu as un lien ,

      clic dessus pour faire ta mise à jour

      tu feras pareille pour : Fin de vie

      Télécharge: Ccleaner:

      https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/

      clic sur: option/avancer: décoche,éffacer uniquement les fichier temporaire de Windows datant de plus de 24heures

      dans: options/cookies:garde les cookies de tes sites préféré

      dans Parametre/effacement:mets toi sur:effacement secusé(lent)

      en dessous cherche: Gutmann(35passages)

      coche toutes les cases dans:Lecteur

      coche aussi en dessous:netoyer l'espace libre: MFT

      dans: Netoyeur, coche: Cache dns et Vieille données prefecth

      Ensuite,tu te mets sur: NETOYEUR et fais une Analyse puis Nétoyer(clic ok)

      Dans:Registre,Clic sur: chercher les érreurs puis corriger les erreurs sélectionnées(sauvegarde)

      Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
      https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cpVobGk5bHnxrhQ4yaoEUDJvOYNnEGyYjgqHZz5GqZLfutR3fMFPlsC3-CGIilfupPAguYATNyua3csodN_frdMK8sSzUpit10Yac-QJCOkMqJKkbdKcP6ySs8trWPgoNVIq4TGGWCe6o0txXQv-ZueJF9vZzw3RXsGwFYIqN2lvF2LPdQzS8mE1d5kWOVOz6EMzQuE5-lClSJM869uq3oc7-t7yg%3D%3D&attredirects=3
      ou ici : https://sites.google.com/site/toolbarsd/

      * Lance l'installation du programme en exécutant le fichier téléchargé.
      * Double-clique maintenant sur le raccourci de Toolbar-S&D.

      * Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
      * Choisis maintenant l'option 2
      Patiente jusqu'à la fin de la recherche.
      * Poste le rapport généré. (C:\TB.txt)

      Tuto :
      https://www.malekal.com/adwcleaner-supprimer-virus-adwares-pup/
      0
      1. Merci à tous, je vais tester celà cette après midi je vous tiens au courant.
        0
      2. J'ai testé les deux premiers raté, pour le troisième où dois je poste le rapport ?
        merci
        0
    3. re-

      1) As tu télécharger : Sécunia (mis en mode avancer)

      et fais toutes tes mises à jour?

      2) As-tu télécharger Ccleaner, configurer comme décris,

      et fais le nétoyage et aussi le registre

      3)le rapport tu le trouve: Poste le rapport généré. (C:\TB.txt)

      tu poste ici, stp
      0
      1. -----------\\ ToolBar S&D 1.2.9 XP/Vista

        Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
        X86-based PC ( Uniprocessor Free : AMD Sempron(tm) Processor 3200+ )
        BIOS : Ver 1.00PARTTBL
        USER : xxxxxxxxx ( Administrator )
        BOOT : Normal boot
        Antivirus : avast! antivirus 4.8.1368 [VPS 100609-0] 4.8.1368 (Activated)
        C:\ (Local Disk) - NTFS - Total:55 Go (Free:28 Go)
        D:\ (CD or DVD)

        "C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
        Option : [2] ( mer. 09/06/2010|16:45 )

        -----------\\ Recherche de Fichiers / Dossiers ...

        -----------\\ Extensions

        (xxxxxxxxxx) - {c45c406e-ab73-11d8-be73-000a95be3b12} => webdeveloper

        -----------\\ [..\Internet Explorer\Main]

        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
        "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
        "Start Page"="https://www.google.be/?gws_rd=ssl"
        "Search Page"="https://www.bing.com/?fdr=lc&toHttps=1&redig=FA6AD360E0BE4C719380F8C470A3D3A8"
        "Search Bar"="http://www.bing.com/spresults.aspx"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
        "Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
        "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
        "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
        "Start Page"="https://www.msn.com/fr-fr/"

        --------------------\\ Recherche d'autres infections

        --------------------\\ ROOTKIT !!

        Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_TDSSSERV.SYS]
        Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Enum\Root\LEGACY_TDSSSERV.SYS]
        Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TDSSSERV.SYS]
        Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TDSSserv.sys]
        Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\TDSSserv.sys]
        Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\TDSSserv.sys]
        Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\TDSSserv.sys]
        Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TDSSserv.sys]

        --------------------\\ Suspect ..

        C:\WINDOWS\system32\TDSSkkai.log
        C:\WINDOWS\system32\TDSSlxwp.dll
        C:\WINDOWS\system32\TDSSrpyd.dat

        --------------------\\ Cracks & Keygens ..

        C:\DOCUME~1\Poupol~1\Mes documents\poupoule\perso\Keygen Office 2007.exe

        1 - "C:\ToolBar SD\TB_1.txt" - mer. 09/06/2010|16:26 - Option : [2]
        2 - "C:\ToolBar SD\TB_2.txt" - mer. 09/06/2010|16:43 - Option : [1]
        3 - "C:\ToolBar SD\TB_3.txt" - mer. 09/06/2010|16:46 - Option : [2]

        -----------\\ Fin du rapport a 16:46:44,73
        0
    4. Peux tu répondre à mes questions?, stp

      quand tu dis raté,que veux tu dire?

      ensuite désinstalle Avast(ancienne version)

      https://www.commentcamarche.net/telecharger/securite/22859-utilitaire-de-desinstallation-de-avast/

      puis installe celle ci et biensurs, tu la configure

      http://www.commentcamarche.net/download/telecharger-151-avast
      0
      1. Bonjour,
        Voilà j'ai tout ce que tu m'as dit de faire et sur Mozilla j'ai toujours le même souci pas d'images comme si pas de CSS lorsque l'on fait un site , hier quand je disais raté c'était parceque je ne pensais pas que je devais faire toutes les étapes, ici j'ai refait mais tjs pareil!
        Merci qd même
        0
    5. Salut,

      Télécharge AD-Remover ( de C_XX ) sur ton bureau

      https://www.clubic.com/telecharger-fiche313780-ad-remover-2010.html

      ! Déconnecte toi et ferme toutes applications en cours !

      ? Double clique sur "AD-R.exe" pour lancer l'installation et laisse les paramètres d'installation par défaut .

      ? Double-clique sur le raccourci AD-Remover qui est sur ton bureau pour lancer l'outil .

      ? Sur la page, clique sur le bouton « Nettoyer »

      -> Confirme l'opération

      ? Laisse travailler l'outil et ne touche à rien ! .

      ? Poste le rapport qui apparait à la fin sur le forum.

      Note:
      Le rapport est sauvegardé aussi sous C:\Ad-report-clean.log

      Télécharge et installe UsbFix (par El Desaparecido, C_XX & Chimay8) sur le Bureau

      http://www.commentcamarche.net/download/telecharger-34066197-usbfix

      ! ! Branche tous tes supports amovibles (clés USB, DD externes, etc...) sans les ouvrir !!
      * Double clique sur l'icône UsbFix présent sur le bureau pour lancer l'outil
      Sous Vista/Seven : clic-droit sur l'icône et choisir "Exécuter en tant qu'administrateur" dans le menu contextuel.
      * Au menu principal choisis F pour français et valide par Entrée
      * Choisis l'option 2 suppréssions
      * Patiente le temps du balayage qui peut durer plusieurs minutes
      * Le rapport doit s'ouvrir spontanément à la fin du scan
      * Copie/colle le rapport dans le prochain message

      Le rapport est sauvegardé à la racine du disque C:\Usbfix.txt

      "Process.exe" est détecté par certains antivirus comme étant un RiskTool.
      Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Le mieux étant de désactiver temporairement ton antivirus

      fais un scan complet avec:

      https://www.commentcamarche.net/telecharger/securite/14361-malwarebytes-anti-malware/

      Avant le Scan, Fais la mise à Jour(onglet mise à jour)

      Clic sur l'onglet : Recherche

      éxécuter un scan complet

      clic plus bas sur : Recherche(sélectionne tout tes lecteurs)

      puis: Recherche (le scan peut durer 1 à 2 heures!)

      à la fin du scan, Supprime la sélection

      poste le rapport
      0
      1. .
        ======= RAPPORT D'AD-REMOVER 2.0.0.0,D | UNIQUEMENT XP/VISTA/7 =======
        .
        Mis à jour par C_XX le 19/05/10 à 19:20
        Contact: AdRemover.contact@gmail.com
        Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
        .
        Lancé à: 12:52:48 le 10/06/2010 | Mode normal | Option: CLEAN
        Exécuté de: C:\Ad-Remover\ADR.exe
        SE: Microsoft Windows XP Édition familiale (Service Pack 3 - X86)
        Nom du PC: PC_DE_POUPOULE
        Utilisateur actuel: *******************************************
        .
        ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
        .
        .
        C:\Program Files\PartyGaming

        (!) -- Fichiers temporaires supprimés.
        .
        HKCU\Software\32 Vegas Casino
        HKCU\Software\Casino.com
        HKCU\Software\PartyGaming
        HKLM\Software\32 Vegas Casino
        HKLM\Software\Casino.com
        HKLM\Software\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\format.ini
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\GRA.ini
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\allLangVersion.txt
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\account_but_newacocunt.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\allversion.txt
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\bonus-icon.gif
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\but.bmp
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\but_account.bmp
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\but_skin.gif
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\but_skin_account.gif
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\client_bottom.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\client_bottom_right.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\client_gradient.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\client_top.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\connect_screen_bg.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\down_arrow.gif
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\down_arrow_o.gif
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\addplaymoney_button.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\aud.png
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\autospincancel_button.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\autospinoptions_background.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\autospinstart_button.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\balance_strip.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\bottombar_logo_net.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\bottombar_net.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\bottombar_net_big.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\bottombar_net_medium.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\buyin_botbg.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\buyin_cancelbutton.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\buyin_cashierbutton.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\buyin_midbg.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\buyin_okbutton.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\buyin_topbg.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\BuyInConfig.ini
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\cad.png
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\cashier_button.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\cashout_midbg.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\cent_strip.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\chf.png
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\chips.wav
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\czk.png
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\dkk.png
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\eur.png
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\exit_button.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\format.ini
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\game_topbar_pff.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\gamelogs_button.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\gbp.png
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\hkd.png
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\huf.png
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\ils.png
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\inr.png
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\jpy.png
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\krw.png
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\myr.png
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\nok.png
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\nzd.png
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\php.png
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\pln.png
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\popup_but_cancel.gif
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\popup_but_ok.gif
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\popup_buyin_but_all.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\popup_buyin_tab.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\PushBut.wav
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\quickdeposit_button.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\ron.png
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\rur.png
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\sek.png
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\sgd.png
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\skk.png
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\status_dlg.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\sys_icons.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\system_but_close.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\system_but_inactive_close.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\system_but_inactive_minimise.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\system_but_minimise.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\table_logo_com.png
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\table_logo_net.png
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\thb.png
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\trny_buyin_botbg.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\try.png
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\twd.png
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\usd.png
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\version.txt
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\version_button.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\win.wav
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\games\zar.png
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\icon_three.gif
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\icon_ticked.gif
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\lhn_account_background.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\lhn_account_divider.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\lhn_ani_refresh.gif
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\lhn_bar_jackpot.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\lhn_bar_jackpot_numbers.gif
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\lhn_bar_jackpot_numbers.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\lhn_bar_jackpot_numbers_small.gif
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\lhn_bar_news.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\lhn_but_cashout.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\lhn_but_deposit.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\lhn_but_deposit_large.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\lhn_but_options.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\lhn_but_redeem.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\lhn_but_refresh.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\lhn_but_reload_play.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\lhn_but_status.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\lhn_details_open.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\lhn_link_arrow.gif
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\lhn_tab_background.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\loading.gif
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\menu_01_myaccount.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\menu_02_cashier.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\menu_03_news.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\menu_04_rules.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\menu_05_tellfriend.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\menu_06_about.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\menu_07_help.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\new-mail-icon.gif
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\no-mail-icon.gif
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\PartyCasino.ico
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\popup_login_bottom.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\popup_login_top.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\popup_register_bottomleft.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\popup_register_top.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\skin.bmp
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\skin_account.bmp
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\spacer.gif
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\system_but_bets.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\system_but_bingo.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\system_but_cashier.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\system_but_connected.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\system_but_gammon.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\system_but_poker.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\system_but_security.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\ticker_bg.jpg
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\up_arrow.gif
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\up_arrow_o.gif
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\images\version.txt
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\lang_pack_en_US.txt
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\en_US\version.txt
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\language\version.txt
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\lobbyconfig.txt
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\PartyCasino.dll
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\sys.ini
        HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|c:\program files\partygaming\PartyCasino\version.txt
        .
        .
        ============== SCAN ADDITIONNEL ==============
        .
        * Mozilla FireFox Version 3.5.9 (fr) *
        .
        C:\Documents and Settings\Nom supprimé Moderation CCM\..\uw2p2f6d.default\prefs.js - browser.startup.homepage: hxxp://www.google.com
        C:\Documents and Settings\POUPOULE\..\uw2p2f6d.default\prefs.js - browser.startup.homepage_override.mstone: rv:1.9.1.9
        .
        .
        * Internet Explorer Version 6.0.2900.5512 *
        .
        [HKCU\Software\Microsoft\Internet Explorer\Main]
        .
        Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
        Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
        Do404Search: 0x01000000
        Enable Browser Extensions: yes
        Local Page: C:\WINDOWS\system32\blank.htm
        Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
        Show_ToolBar: yes
        Start Page: hxxp://fr.msn.com/
        Use Custom Search URL: 1
        Use Search Asst: no
        .
        [HKLM\Software\Microsoft\Internet Explorer\Main]
        .
        Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
        Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
        Delete_Temp_Files_On_Exit: yes
        Local Page: %SystemRoot%\system32\blank.htm
        Search bar: hxxp://search.msn.com/spbasic.htm
        Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
        Start Page: hxxp://fr.msn.com/
        .
        [HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
        .
        Tabs: res://ieframe.dll/tabswelcome.htm
        Blank: res://mshtml.dll/blank.htm
        .
        ========================================
        .
        C:\Ad-Remover\Quarantine: 0 Fichier(s)
        C:\Ad-Remover\Backup: 13 Fichier(s)
        .
        C:\Ad-Report-CLEAN[1].txt - 22666 Octet(s)
        .
        Fin à: 13:01:45, 10/06/2010
        .
        ============== E.O.F - CLEAN[1] ==============
        0
      2. en téléchargeant le http://www.commentcamarche.net/download/telecharger-34066197-usbfix
        Avast a détecté un cheval de troie donc j'ai arrêté le processus de téléchargement
        0
      3. ok j'ai vu qu'il fallait désactivé l'anti virus mais j'ai un doute ?????
        0
    6. Re-

      tu m'as bien dis que tu avais tout fais précédament?

      pourquoi ton systeme n'est pas à jour??????????? !!!!!!!!!

      désactive ton Anti virus et si tu as spybot,désactive le tea timer

      ensuite fais: USBfix , stp

      faut lire entiérement et ensuite faire
      0
      1. Pourquoi ? il y a des logiciels que je veux à tout prix garder et que je n'ai pas su mettre à jour, pour le reste j'en ai mis à jour et supprimé certains. :-) et puis je ne suis pas une pro du système.
        0
    7. Tu as juste à me demander quand tu ne sais pas,

      ouvre Sécunia en haut à droite, clic mode avancer

      clic sur l'ongler: Analyser

      puis fais Analyser, tu attends jusqu'a la fin du scan

      ensuite regarde dans: Vulnérable

      en face de chaque logiciels tu as un lien, clic dessus pour faire ta mise à jour

      tout est expliquer plus haut,

      quels sont les logiciels que tu n'arrive pas à mettre à jour?

      pour USBfix, ne t'inquiéte pas pour l'alerte d'Avast, tout-est normal

      tu peux le faire
      0
      1. Pour les vulnérables
        Office 2007, Citrix program Neghborhood client, adobe flash player 10.x que j'ai essayé de supprimé mais il reste.
        Pour les fins de vie
        macromédia flash player 6 fichiers
        Win dvd gold 5
        File Zilla 2.x
        Adope acrobat 7.x
        pour le USBfix c'est fait le rapport est envoyé
        0
    8. Contributeur sécurité
      Re,

      "no action taken"

      tu as pris le rapport trop tôt ou tu n'as pas mis en quarantaine ?

      Si c'est le dernier cas, il faut que tu recommences.
      0
      1. Ok j'ai refait

        Malwarebytes' Anti-Malware 1.46
        www.malwarebytes.org

        Version de la base de données: 4186

        Windows 5.1.2600 Service Pack 3
        Internet Explorer 6.0.2900.5512

        10/06/2010 15:58:55
        mbam-log-2010-06-10 (15-58-55).txt

        Type d'examen: Examen rapide
        Elément(s) analysé(s): 125702
        Temps écoulé: 8 minute(s), 54 seconde(s)

        Processus mémoire infecté(s): 0
        Module(s) mémoire infecté(s): 0
        Clé(s) du Registre infectée(s): 0
        Valeur(s) du Registre infectée(s): 0
        Elément(s) de données du Registre infecté(s): 2
        Dossier(s) infecté(s): 0
        Fichier(s) infecté(s): 0

        Processus mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Module(s) mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Clé(s) du Registre infectée(s):
        (Aucun élément nuisible détecté)

        Valeur(s) du Registre infectée(s):
        (Aucun élément nuisible détecté)

        Elément(s) de données du Registre infecté(s):
        HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BITS\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemRoot%\system32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wuauserv\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemroot%\system32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> Quarantined and deleted successfully.

        Dossier(s) infecté(s):
        (Aucun élément nuisible détecté)

        Fichier(s) infecté(s):
        (Aucun élément nuisible détecté)
        0
    9. Contributeur sécurité
      Re,

      fais redémarrer l'ordi;

      Exécute ZHPDiag comme demandé;

      ===

      Toujours des problèmes avec Mozilla ?
      0
      1. j'ai tout suivi ,j'ai un tas d'icônes sur mon bureau depuis hier et tjs rien de changé pour mozilla
        :-(((
        0
    10. Contributeur sécurité
      Re,

      Je ne peux pas avancer sans le rapport de ZHPDiag (ou très difficilement)
      0
      1. j'ai envoyé le rapport comme écrit mais je peux le poster ici mais il prend beaucoup de place
        0
      2. Voici le lien du rapport
        http://www.cijoint.fr/cjlink.php?file=cj201006/cijgGLCTIs.txt
        0
    11. Contributeur sécurité
      Bonsoir,

      c'est un ordi professionnel ?

      ===

      On va utiliser ComboFix.exe. Rends toi sur cette page web pour obtenir les liens de téléchargement, ainsi que des instructions pour exécuter l'outil:

      https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

      * au moment où on va te demander où et sous quel nom tu veux l'enregistrer, choisis bien ton Bureau et nomme le antitruc.exe (il faut le renommer avant de l'enregistrer sur ton disque dur sinon c'est inutile)

      * Vérifie que tu as fermé/désactivé tous les programmes anti-virus, anti-malware ou anti-spyware afin qu'ils n'interfèrent pas avec le travail de ComboFix.

      Envoie le contenu de C:\ComboFix.txt dans ta prochaine réponse afin que je l'examine.
      0
      1. c'était un portable que j'utilisais pour mon job mais plus aujourd'hui, j'ai téléchargé le programme en stoppant l'antivirus et les autres j'ai lancé et au bout de pas mal d'étapes, celà c'est coupé et j'ai eu une page bleue avec une écriture blanche sur tout l'écran signalant qu'une erreur était détectée et que window devait être coup. j'ai du arrêter mon ordi manuellement sur power.
        Donc je n'ai pas recommencé?
        0
    12. Contributeur sécurité
      Re,

      relance le.

      0
      1. je l'ai relancé et j'ai toujours le même problème
        0
    13. Contributeur sécurité
      Re,

      on va changer d'outil :

      Télécharge TDSSKiller et enregistre le sur ton Bureau :

      https://support.kaspersky.com/downloads/utils/tdsskiller.zip

      * Extrait le fichier et exécute le
      * A la fin de l'exécution, il va produire un rapport enregistré sous C:\
      * Poste le rapport dans ta réponse.

      0
      1. 22:04:08:093 2348 TDSS rootkit removing tool 2.3.2.0 May 31 2010 10:39:48
        22:04:08:093 2348 ================================================================================
        22:04:08:093 2348 SystemInfo:

        22:04:08:093 2348 OS Version: 5.1.2600 ServicePack: 3.0
        22:04:08:093 2348 Product type: Workstation
        22:04:08:093 2348 ComputerName: PC_DE_POUPOULE
        22:04:08:093 2348 UserName:
        22:04:08:093 2348 Windows directory: C:\WINDOWS
        22:04:08:093 2348 Processor architecture: Intel x86
        22:04:08:093 2348 Number of processors: 1
        22:04:08:093 2348 Page size: 0x1000
        22:04:08:109 2348 Boot type: Normal boot
        22:04:08:109 2348 ================================================================================
        22:04:08:531 2348 Initialize success
        22:04:08:531 2348
        22:04:08:531 2348 Scanning Services ...
        22:04:09:171 2348 Raw services enum returned 352 services
        22:04:09:187 2348
        22:04:09:187 2348 Scanning Drivers ...
        22:04:10:187 2348 Aavmker4 (a5246ed2586aa807af0bcf63165a71cc) C:\WINDOWS\system32\drivers\Aavmker4.sys
        22:04:10:312 2348 ACPI (e5e6dbfc41ea8aad005cb9a57a96b43b) C:\WINDOWS\system32\DRIVERS\ACPI.sys
        22:04:10:390 2348 ACPIEC (e4abc1212b70bb03d35e60681c447210) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
        22:04:10:640 2348 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
        22:04:10:765 2348 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys
        22:04:11:078 2348 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
        22:04:11:171 2348 AmdK8 (08329f6ae482b184725d2e07e9a79e16) C:\WINDOWS\system32\DRIVERS\AmdK8.sys
        22:04:11:453 2348 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
        22:04:11:609 2348 aswFsBlk (1b6ed99291ddf5d2501554cc5757aab6) C:\WINDOWS\system32\drivers\aswFsBlk.sys
        22:04:11:687 2348 aswMon2 (81432b1a4b31036c822eb967decf613c) C:\WINDOWS\system32\drivers\aswMon2.sys
        22:04:11:765 2348 aswRdr (3e2b6112d2766f87eda8466fde86a986) C:\WINDOWS\system32\drivers\aswRdr.sys
        22:04:11:937 2348 aswSP (d78b644816db540e103d0b0766fd9967) C:\WINDOWS\system32\drivers\aswSP.sys
        22:04:12:000 2348 aswTdi (606d731008d98b6ef946730c597c1642) C:\WINDOWS\system32\drivers\aswTdi.sys
        22:04:12:093 2348 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
        22:04:12:265 2348 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
        22:04:12:578 2348 ati2mtag (2fbdfec8cd60cec3d55e615865333033) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
        22:04:12:703 2348 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
        22:04:12:875 2348 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
        22:04:12:984 2348 BCM43XX (e7debb46b9ef1f28932e533be4a3d1a9) C:\WINDOWS\system32\DRIVERS\bcmwl5.sys
        22:04:13:093 2348 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
        22:04:13:218 2348 BTWUSB (e6bcc8cd48a7bb9c83ea1536fcff0fd1) C:\WINDOWS\system32\Drivers\btwusb.sys
        22:04:13:406 2348 CAMCAUD (23913c28ac89875bbfa03bccdc3a41e5) C:\WINDOWS\system32\drivers\camc6aud.sys
        22:04:14:062 2348 CAMCHALA (e6edb12a44dafcef05dbddf3ed652388) C:\WINDOWS\system32\drivers\camc6hal.sys
        22:04:14:640 2348 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
        22:04:14:734 2348 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
        22:04:14:921 2348 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
        22:04:15:109 2348 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
        22:04:15:171 2348 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
        22:04:15:390 2348 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
        22:04:15:578 2348 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
        22:04:15:703 2348 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
        22:04:15:843 2348 dmboot (f5deadd42335fb33edca74ecb2f36cba) C:\WINDOWS\system32\drivers\dmboot.sys
        22:04:16:031 2348 dmio (5a7c47c9b3f9fb92a66410a7509f0c71) C:\WINDOWS\system32\drivers\dmio.sys
        22:04:16:125 2348 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
        22:04:16:296 2348 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
        22:04:16:468 2348 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
        22:04:16:546 2348 eabfiltr (81b7808d3b5892388f33273119c2dc31) C:\WINDOWS\system32\drivers\EABFiltr.sys
        22:04:16:640 2348 eabusb (1ba14da377b66278335d4b9e8824cd42) C:\WINDOWS\system32\drivers\eabusb.sys
        22:04:16:750 2348 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
        22:04:16:921 2348 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
        22:04:17:000 2348 Fips (31f923eb2170fc172c81abda0045d18c) C:\WINDOWS\system32\drivers\Fips.sys
        22:04:17:062 2348 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
        22:04:17:203 2348 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
        22:04:17:406 2348 fssfltr (c6ee3a87fe609d3e1db9dbd072a248de) C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys
        22:04:17:484 2348 FsUsbExDisk (790a4ca68f44be35967b3df61f3e4675) C:\WINDOWS\system32\FsUsbExDisk.SYS
        22:04:17:625 2348 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
        22:04:17:718 2348 Ftdisk (a86859b77b908c18c2657f284aa29fe3) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
        22:04:17:906 2348 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
        22:04:18:015 2348 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
        22:04:18:312 2348 HSFHWATI (13d4b70bf2f9bc550e9079da864d3ec1) C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys
        22:04:18:531 2348 HSF_DP (dfa8f86c0dbca7db948043aa3be6793b) C:\WINDOWS\system32\DRIVERS\HSF_DP.sys
        22:04:18:671 2348 HTTP (f6aacf5bce2893e0c1754afeb672e5c9) C:\WINDOWS\system32\Drivers\HTTP.sys
        22:04:18:937 2348 i8042prt (a09bdc4ed10e3b2e0ec27bb94af32516) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
        22:04:19:000 2348 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
        22:04:19:125 2348 IntelIde (4b6da2f0a4095857a9e3f3697399d575) C:\WINDOWS\system32\DRIVERS\intelide.sys
        22:04:19:359 2348 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
        22:04:19:484 2348 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
        22:04:19:593 2348 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
        22:04:19:734 2348 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
        22:04:19:890 2348 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
        22:04:19:968 2348 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
        22:04:20:031 2348 isapnp (355836975a67b6554bca60328cd6cb74) C:\WINDOWS\system32\DRIVERS\isapnp.sys
        22:04:20:171 2348 Kbdclass (16813155807c6881f4bfbf6657424659) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
        22:04:20:312 2348 klmd23 (67e1faa88fb397b3d56909d7e04f4dd3) C:\WINDOWS\system32\drivers\klmd.sys
        22:04:20:437 2348 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
        22:04:20:578 2348 KSecDD (1705745d900dabf2d89f90ebaddc7517) C:\WINDOWS\system32\drivers\KSecDD.sys
        22:04:20:781 2348 mdmxsdk (3c318b9cd391371bed62126581ee9961) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
        22:04:20:890 2348 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
        22:04:21:015 2348 Modem (510ade9327fe84c10254e1902697e25f) C:\WINDOWS\system32\drivers\Modem.sys
        22:04:21:140 2348 Mouclass (027c01bd7ef3349aaebc883d8a799efb) C:\WINDOWS\system32\DRIVERS\mouclass.sys
        22:04:21:437 2348 mouhid (124d6846040c79b9c997f78ef4b2a4e5) C:\WINDOWS\system32\DRIVERS\mouhid.sys
        22:04:21:562 2348 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
        22:04:21:734 2348 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
        22:04:21:890 2348 MRxSmb (60ae98742484e7ab80c3c1450e708148) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
        22:04:22:031 2348 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
        22:04:22:140 2348 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
        22:04:22:281 2348 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
        22:04:22:390 2348 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
        22:04:22:500 2348 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
        22:04:23:015 2348 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
        22:04:23:640 2348 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
        22:04:23:703 2348 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
        22:04:23:781 2348 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
        22:04:23:953 2348 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
        22:04:24:062 2348 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
        22:04:24:125 2348 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
        22:04:24:171 2348 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
        22:04:24:656 2348 NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS\system32\drivers\NDProxy.sys
        22:04:24:875 2348 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
        22:04:24:984 2348 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
        22:04:25:062 2348 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
        22:04:25:218 2348 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
        22:04:25:328 2348 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
        22:04:25:437 2348 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
        22:04:25:515 2348 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
        22:04:25:687 2348 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
        22:04:25:796 2348 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
        22:04:25:875 2348 Parport (8fd0bdbea875d06ccf6c945ca9abaf75) C:\WINDOWS\system32\DRIVERS\parport.sys
        22:04:25:953 2348 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
        22:04:26:109 2348 ParVdm (9575c5630db8fb804649a6959737154c) C:\WINDOWS\system32\drivers\ParVdm.sys
        22:04:26:203 2348 pccsmcfd (175cc28dcf819f78caa3fbd44ad9e52a) C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys
        22:04:26:343 2348 PCI (043410877bda580c528f45165f7125bc) C:\WINDOWS\system32\DRIVERS\pci.sys
        22:04:26:546 2348 PCIIde (f4bfde7209c14a07aaa61e4d6ae69eac) C:\WINDOWS\system32\DRIVERS\pciide.sys
        22:04:26:609 2348 Pcmcia (f0406cbc60bdb0394a0e17ffb04cdd3d) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
        22:04:26:734 2348 pfc (6c1618a07b49e3873582b6449e744088) C:\WINDOWS\system32\drivers\pfc.sys
        22:04:26:796 2348 PID_0920 (2f81e367875c5d7d6f05454ba84d27a9) C:\WINDOWS\system32\DRIVERS\LV532AV.SYS
        22:04:26:921 2348 PPJoyBus (89045b00bd36cfe3910e3cb6762c2db0) C:\WINDOWS\system32\drivers\PPJoyBus.sys
        22:04:27:125 2348 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
        22:04:27:281 2348 Processor (e19c9632ac828f6f214391e2bdda11cb) C:\WINDOWS\system32\DRIVERS\processr.sys
        22:04:27:343 2348 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
        22:04:27:390 2348 PSI (14e6fb92f1788982e2bbc81d915b1f02) C:\WINDOWS\system32\DRIVERS\psi_mf.sys
        22:04:27:500 2348 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
        22:04:27:656 2348 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\WINDOWS\system32\Drivers\PxHelp20.sys
        22:04:27:781 2348 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
        22:04:27:890 2348 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
        22:04:27:953 2348 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
        22:04:28:140 2348 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
        22:04:28:281 2348 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
        22:04:28:343 2348 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
        22:04:28:453 2348 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
        22:04:28:625 2348 redbook (d8eb2a7904db6c916eb5361878ddcbae) C:\WINDOWS\system32\DRIVERS\redbook.sys
        22:04:28:703 2348 RTL8023xp (1e7978c5e355407efdfc7b7328ef13e7) C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys
        22:04:28:812 2348 sdbus (8d04819a3ce51b9eb47e5689b44d43c4) C:\WINDOWS\system32\DRIVERS\sdbus.sys
        22:04:28:906 2348 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
        22:04:29:046 2348 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
        22:04:29:156 2348 Serial (93d313c31f7ad9ea2b75f26075413c7c) C:\WINDOWS\system32\DRIVERS\serial.sys
        22:04:29:250 2348 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
        22:04:29:484 2348 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
        22:04:29:578 2348 SMCIRDA (039f7b892ad78fd836cd56f0551dab33) C:\WINDOWS\system32\DRIVERS\smcirda.sys
        22:04:29:703 2348 snpstd (969f26008c5d98df4e0eee693a202b8d) C:\WINDOWS\system32\DRIVERS\snpstd.sys
        22:04:29:859 2348 SONYPVU1 (a1eceeaa5c5e74b2499eb51d38185b84) C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS
        22:04:29:984 2348 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
        22:04:30:078 2348 sr (39626e6dc1fb39434ec40c42722b660a) C:\WINDOWS\system32\DRIVERS\sr.sys
        22:04:30:250 2348 Srv (3bb03f2ba89d2be417206c373d2af17c) C:\WINDOWS\system32\DRIVERS\srv.sys
        22:04:30:437 2348 ss_bbus (eaa66218cd39f5bb1b4853a78c67c787) C:\WINDOWS\system32\DRIVERS\ss_bbus.sys
        22:04:30:531 2348 ss_bmdfl (91765f99914ed8693d8bc76524f21581) C:\WINDOWS\system32\DRIVERS\ss_bmdfl.sys
        22:04:30:640 2348 ss_bmdm (840e7b738b03c10ee91d9b7d3d6eff15) C:\WINDOWS\system32\DRIVERS\ss_bmdm.sys
        22:04:30:796 2348 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
        22:04:30:906 2348 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
        22:04:30:968 2348 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
        22:04:31:390 2348 SynTP (1dbc86da355b5db35174f862c110fd09) C:\WINDOWS\system32\DRIVERS\SynTP.sys
        22:04:31:500 2348 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
        22:04:31:718 2348 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
        22:04:31:796 2348 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
        22:04:31:875 2348 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
        22:04:31:953 2348 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
        22:04:32:171 2348 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
        22:04:32:406 2348 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
        22:04:32:484 2348 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
        22:04:32:640 2348 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
        22:04:32:765 2348 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys
        22:04:32:843 2348 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
        22:04:32:953 2348 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
        22:04:33:140 2348 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
        22:04:33:250 2348 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
        22:04:33:375 2348 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
        22:04:33:468 2348 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
        22:04:33:515 2348 VolSnap (46de1126684369bace4849e4fc8c43ca) C:\WINDOWS\system32\drivers\VolSnap.sys
        22:04:33:703 2348 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
        22:04:33:781 2348 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
        22:04:33:921 2348 winachsf (473ee64c368ce2eed110376c11960259) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
        22:04:34:125 2348 WmiAcpi (c42584fd66ce9e17403aebca199f7bdb) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys
        22:04:34:234 2348 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
        22:04:34:296 2348 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
        22:04:34:296 2348
        22:04:34:296 2348 Completed
        22:04:34:296 2348
        22:04:34:296 2348 Results:
        22:04:34:296 2348 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
        22:04:34:296 2348 File objects infected / cured / cured on reboot: 0 / 0 / 0
        22:04:34:296 2348
        22:04:34:312 2348 KLMD(ARK) unloaded successfully
        0
    14. Contributeur sécurité
      Bonsoir,

      l'outil n'a rien trouvé.

      ===

      On va faire plusieurs choses;

      ===

      1 Un peu de ménage :

      Pour Xp : Double clique sur l'icône ZHPFix.exe sur ton Bureau.

      Pour Vista : Clique droit sur l'icône ZHPFix.exe sur ton Bureau,
      puis sélectionne 'Exécuter en tant qu'administrateur'.

      Clique sur le A rouge (Nettoyeur de Tools).

      Clique sur Nettoyer.

      Fais redémarrer l'ordi pour terminer le nettoyage.

      ===

      2 Mettre à jour Firefox :

      https://www.commentcamarche.net/telecharger/web-internet/9879-securite-firefox-deux-failles-graves-corrigees-en-urgence/

      ===

      3 Voir ce que dit un autre analyseur de rootkit :

      * Télécharge gmer

      http://www2.gmer.net/gmer.zip

      sur le bureau et dézippe-le (clic droit et extraire ici).
      * Double-clique sur gmer.exe sur le bureau. Si ton antivirus réagit, ne t'inquiète et ignore l'alerte.
      * Clique sur l'onglet "rootkit", puis vérifie que toutes les cases sont bien cochées,
      * Clique sur scan.
      * A la fin du scan, clique sur le bouton copy.
      * Dans démarrer>programmes>accessoires : ouvre le bloc-note et clique sur CTRL+V afin de copier le rapport dans ce même bloc-note.
      * Edite ce rapport dans ta prochaine réponse.

      0
      1. Cela a fait comme l'autre fois une page bleue et et lettres blanches, simplement en cliquant sur l'icone, j'ai encore éteint manuellement :-(
        0
    15. Contributeur sécurité
      Hello lucie , hello Lyonnais92 .

      Pas de soucis pour prendre la relève .... ;o)

      j'attends donc le nouveau rapport ZHPDiag demandé pour analyse ....

      "Baby, I'm going on an airplane, And I don't know if I'll be back again"
      IMPORTANT : ne vous croyez pas tiré d'affaire tant qu'on ne
      vous l'a pas dit !
      0
      1. Bonjour
        Voici le rapport au fait qd le scan est terminé il y a toujours un fichier manquant updater.exe est-ce important?

        Malwarebytes' Anti-Malware 1.46
        www.malwarebytes.org

        Version de la base de données: 4196

        Windows 5.1.2600 Service Pack 3
        Internet Explorer 6.0.2900.5512

        14/06/2010 8:41:58
        mbam-log-2010-06-14 (08-41-58).txt

        Type d'examen: Examen rapide
        Elément(s) analysé(s): 130766
        Temps écoulé: 12 minute(s), 41 seconde(s)

        Processus mémoire infecté(s): 0
        Module(s) mémoire infecté(s): 0
        Clé(s) du Registre infectée(s): 0
        Valeur(s) du Registre infectée(s): 0
        Elément(s) de données du Registre infecté(s): 0
        Dossier(s) infecté(s): 0
        Fichier(s) infecté(s): 0

        Processus mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Module(s) mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Clé(s) du Registre infectée(s):
        (Aucun élément nuisible détecté)

        Valeur(s) du Registre infectée(s):
        (Aucun élément nuisible détecté)

        Elément(s) de données du Registre infecté(s):
        (Aucun élément nuisible détecté)

        Dossier(s) infecté(s):
        (Aucun élément nuisible détecté)

        Fichier(s) infecté(s):
        (Aucun élément nuisible détecté)
        0
      2. voici le lien du deuxième rapport

        http://www.cijoint.fr/cjlink.php?file=cj201006/cijDq8CenV.txt
        0
    16. Contributeur sécurité
      hello,

      ZHPDiag v1.25.1431

      > tu n'as pas installé la dernière version de ZHPDiag comme demandé !

      donc il faut recommencer ... fait ainsi stp :

      1- Supprime l'ancienne version en utilisant l'utilitaire de désinstallation Unins000.exe présent dans le dossier C:\Program files\ZHPDiag .

      supprime ensuite le dossier C:\Program files\ZHPDiag qui restera .

      =========================

      2- On reprends ainsi depuis le téléchargement :

      Télécharge ZHPDiag (de Nicolas Coolman) sur ton bureau :

      -> https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html

      !! déconnecte toi et ferme toutes tes applications en cours !!

      > Double-clique sur "ZHPDiag.exe" ( avec Vista/Seven faire clique droit / "executer en tant qu'admin..." ) pour lancer l'installation de l'outil et laisse toi guider. Ne modifie pas les paramètres d'installe et coche bien la case "créer une icone sur le bureau" afin d'avoir les raccourcis "ZHPDiag" et "ZHPFix" .

      > A la fin de l'installe , laisse bien la case "executer ZHPDiag" cochée et clique sur "Terminer " > l'outil se lancera donc automatiquement .

      > Une fois ZHPDiag ouvert, clique sur le bouton "option" en haut sur la droite .
      ( celui avec le tournevis )

      Une liste apparait dans l'encadré principal > coche toutes les lignes sauf les 045 et 066 ( important ! ) .

      > clique sur le bouton "calendrier" qui est en haut à droite : choisis 15 days

      > Puis clique sur le bouton de "la loupe" ( en haut à gauche ) pour lancer le scan .

      Laisses travailler l'outil ... ( cela peut-être relativement long . Si ton antivirus émets des alertes lors du scan , ignore les , ne mets rien en quarataine ! )

      > Une fois terminé, le rapport obtenu ( ZHPDiag.txt ) est sauvegardé sur ton bureau.

      Ferme le programme ...

      -> Pour me faire parvenir ce rapport, rends toi sur ce site : http://www.cijoint.fr/

      * Clique sur "parcourir" et va jusqu'au rapport ZHPDiag.txt qui est sauvegardé sur le bureau .
      * Clique ensuite sur "cliquer ici pour déposer le fichier" et patiente ...
      * Une fois l'upload finit , un lien apparait > copie/colle le dans ta prochaine réponse stp ....

      "Baby, I'm going on an airplane, And I don't know if I'll be back again"
      IMPORTANT : ne vous croyez pas tiré d'affaire tant qu'on ne
      vous l'a pas dit !
      0
      1. http://www.cijoint.fr/cjlink.php?file=cj201006/cijP5I6wiO.txt
        0
      2. Contributeur sécurité
        non !

        toujours pas ...

        vire ZHPDiag que tu as et retélécharge le !

        j'attends le rapport avec la dernière version !

        PS : supprime ZHPDiag.txt qui est sur ton bureau également ....
        0
      3. alors le lien que tu me donnes n'est pas le bon car je l'ai téléchargé à partir de ton lien
        0
      4. il ya télcharger avec forum et telecharger ? j'ai pris celui sans forum ensuite comme rien ne se télécharger j'ai cliqué sur le lien proposé
        0
      5. voilà la version proposée Version : 1.25.14 ce n'est pas celle là ?
        0
    17. Contributeur sécurité
      ENFIN !

      on a la bonne version v1.25.1434 avec le module 81 ! ... :))

      on va poursuivre donc ... dans l'ordre :

      1- Utilisation de l'outil ZHPFix :

      * Copie le tout le texte présent dans l'encadré ci-dessous ( tu le selectionnes avec ta souris / Clique droit dessus et choisis "copier" ou fait Ctrl+C )

      C:\WINDOWS\system32\drivers\tdssserv.sys 
      O41 - Driver: (1cf2204c) . (.Pas de propriétaire - Pas de description.) - C:\WINDOWS\system32\drivers\1cf2204c.sys 
      O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\Symantec Shared 
      O44 - LFC:[MD5.F9664659474227B1521A0EED8876A517] - 10/06/2010 - 12:40:27 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\UsbFix_Upload_Me_PC_DE_PASCALE.zip   [6408] 
      Services: CurCS - (.not file.) - Kl1 (kl1)  .(.Pas de propriétaire - Pas de description.) - LEGACY_KL1 
      O64 - Services: CurCS - (.not file.) - Klif (klif)  .(.Pas de propriétaire - Pas de description.) - LEGACY_KLIF  
      O64 - Services: CurCS - (.not file.) - klmd23 (klmd23)  .(.Pas de propriétaire - Pas de description.) - LEGACY_KLMD23 
      Services: CurCS - (.not file.) - srescan (srescan)  .(.Pas de propriétaire - Pas de description.) - LEGACY_SRESCAN   
      O64 - Services: CurCS - (.not file.) - SymEvent (SymEvent)  .(.Pas de propriétaire - Pas de description.) - LEGACY_SYMEVENT      
      O64 - Services: CurCS - (.not file.) - SYMIDSCO (SYMIDSCO)  .(.Pas de propriétaire - Pas de description.) - LEGACY_SYMIDSCO  
      O64 - Services: CurCS - (.not file.) - SYMTDI (SYMTDI)  .(.Pas de propriétaire - Pas de description.) - LEGACY_SYMTDI  
      O64 - Services: CurCS - (.not file.) - TDSSserv.sys (TDSSserv.sys)  .(.Pas de propriétaire - Pas de description.) - LEGACY_TDSSSERV.SYS  
      Services: CurCS - (.not file.) - VET File System Filter (VET-FILT)  .(.Pas de propriétaire - Pas de description.) - LEGACY_VET-FILT  
      O64 - Services: CurCS - (.not file.) - VET File System Recognizer (VET-REC)  .(.Pas de propriétaire - Pas de description.) - LEGACY_VET-REC 
      O64 - Services: CurCS - (.not file.) - VET File and Macro Monitor (VETMONNT)  .(.Pas de propriétaire - Pas de description.) - LEGACY_VETMONNT  
      O64 - Services: CurCS - (.not file.) - vsdatant (vsdatant)  .(.Pas de propriétaire - Pas de description.) - LEGACY_VSDATANT        
      O81 - IFC: Internet Feature Controls [HKUS\.DEFAULT] [feature_enable_ie_compression] -- svchost.exe   
      O81 - IFC: Internet Feature Controls [HKUS\S-1-5-18] [feature_enable_ie_compression] -- svchost.exe 


      Puis Lance ZHPFix depuis le raccouci du bureau .

      * Une fois l'outil ZHPFix ouvert , clique sur le bouton [ H ] ( "coller les lignes Helper" ) .

      * Dans l'encadré principal tu verras donc les lignes que tu as copié précédemment apparaitrent .

      Vérifie que toutes les lignes que je t'ai demandé de copier (et seulement elles) sont dans la fenêtre.

      * Puis clique sur le bouton [ OK ] .
      > à ce moment là , il apparaitra au début de chaque ligne une petite case vide .

      Ne touche plus à rien !

      !! Déconnecte toi, désactive tes défenses ( anti-virus,anti-spyware ) et ferme bien toutes autres applications ( navigateurs compris ) !!

      * Clique sur le bouton [ Tous ] . Vérifies que toutes les lignes soient bien cochées .

      * Enfin clique sur le bouton [ Nettoyer ] .

      -> laisse travailler l'outil et ne touche à rien ...

      -> Si il t'est demandé de redémarrer le PC pour finir le nettoyage , fais le !

      Une fois terminé , un nouveau rapport s'affiche : poste le contenu de ce dernier dans ta prochaine réponse ...

      ( ce rapport est en outre sauvegardé dans ce dossier > C:\Program files\ZHPDiag\ZHPFixReport.txt )

      Pense à réactiver tes défenses !...

      =========================

      2- Si tu as encore Combofix sur ton PC , supprime le !

      On va reprendre avec cet outil de cette manière :

      Télécharge, avec Internet Explorer, ComboFix (de sUBs) sur ton Bureau (et pas ailleurs !):

      http://download.bleepingcomputer.com/sUBs/ComboFix.exe <--- clique droit sur ce lien et choisis "enregistrer la cible sous ... " : dans la fenêtre qui s'ouvre tape ske et valide .

      - le renommer au téléchargement est primordial pour contrer l'infection, sinon l'outil sera inutilisable -

      --------------------------------- [ ! ATTENTION ! ] ------------------------------------------
      * Ferme tes applications en cours ( ainsi que ton navigateur ) .
      * DESACTIVE TOUTES TES DEFENSES (anti-virus, garde anti spy-ware, pare-feu) le temps de la manipe .
      En effet, activés, ils pourraient gêner fortement la procédure de recherche et de nettoyage de l'outil ( voir planter le PC )...Tu les réactiveras donc après !
      ->Important : si tu rencontres des difficultés à ce niveau là, fais m'en part avant de poursuivre ...
      * Tuto ( aide ) ici : https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
      * Note : pour XP, il est IMPERATIF d'installer la Console de Récupération de Windows si l'outil le demande ( voir tuto ci-dessus ).
      --------------------------------- [ ! ATTENTION ! ] ------------------------------------------

      Ensuite :
      > Double-clique sur l'icône "ske.exe" ( = ComboFix ) pour lancer l'outil .
      > A la fenêtre "DISCLAIMER..." , clique sur "oui" et laisse travailler ...

      -- Pour XP, l' installation de la Console de Récupération sera demandé :
      * Laisse toi guider et fais l'installe de la "console de récupération" ( en anglais, "Windows Recovery Console" ) lorsque l'outil te le demandera ( important ! ).
      image > http://img.photobucket.com/albums/v706/ried7/RcAuto1.gif
      *Une fois la console installée,
      image > http://img.photobucket.com/albums/v706/ried7/whatnext.png
      Déconnecte toi si possible avant de cliquer sur "yes" pour lancer le scan --

      Notes importantes :
      -> n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi .
      -> Il se peut que le PC redémarre de lui même ( pour finaliser le nettoyage ) , laisse le faire .
      -> Si l'outil t'annonce ceci : "combofix a détecté la présence de rootkit et a besoin de faire redémarrer votre machine", tu acceptes .
      -> Si après un reboot éventuel , ton anti-virus s'affole lorsque travail encore Combofix , ignore les alertes ! ( ne supprime rien et ne mets rien en quarantaine )

      Le rapport sera crée ici: C:\Combofix.txt

      Réactive bien tes défenses

      Poste le rapport Combofix pour analyse et attends la suite ...

      "Baby, I'm going on an airplane, And I don't know if I'll be back again"
      IMPORTANT : ne vous croyez pas tiré d'affaire tant qu'on ne
      vous l'a pas dit !
      0
      1. http://www.cijoint.fr/cjlink.php?file=cj201006/cijc50ypoZ.txt
        0
      2. Contributeur sécurité
        vu,

        j'attends le rapport de ComboFix ....
        0
      3. Bonjour,
        pas de rapport car mon portable s'est bloqué arrivé au code 50, j'ai eu une page bleue et écritures blanches il était écrit ceci :
        un problème a été détecté et windows a été arrêté afin de prévenir tout dommage

        J'ai fait plusieurs fois cet action de combofix avec les deux autres personnes qui m'ont aidée et c'est toujours un échec.
        0
    18. Contributeur sécurité
      mouais ...

      dis moi , tu as bien renommé Combofix au téléchargement comme demandé ?

      Autre chose, une nouvelle version de ZHPDiag est disponible et on va l'utiliser ...

      Donc désinstalle la version que tu as proprement ( supprime également le dossier ZHPDiag qui restera dans "program files") , supprime les rapports ZHPDiag.txt que tu as ....

      reprends avec la dernière version que tu télécharges ici > http://www.cijoint.fr/cj201006/cijbISNmeh.zip

      ( extrait le set-up de l'archive / lance l'installe etc etc ... )

      j'attends donc le nouveau rapport obtenu via "Cijoint" pour analyse ...

      "Baby, I'm going on an airplane, And I don't know if I'll be back again"
      IMPORTANT : ne vous croyez pas tiré d'affaire tant qu'on ne
      vous l'a pas dit !
      0
      1. oui de plus cette action je l'avais déjà faite avec un autre aidant on l'avait nommé antitruc j'ai l'impression de tourner en rond
        0
      2. http://www.cijoint.fr/cjlink.php?file=cj201006/cijXQyBkp1.txt
        0
    19. Contributeur sécurité
      re,

      tu ne tournes pas en rond ... on avance là ... cette infection est très coriace ...

      le dernier rapport de ZHPDiag montre déjà qu'un driver infectieux a bien été shooté ...

      parcontre , il reste surement des fichiers systeme patché ... et la c'est plus merdique ....

      fait déjà ceci dans un premier temps ... dans l'ordre :

      1- Utilisation de l'outil ZHPFix :

      * Copie le tout le texte présent dans l'encadré ci-dessous ( tu le selectionnes avec ta souris / Clique droit dessus et choisis "copier" ou fait Ctrl+C )

      O64 - Services: CurCS - (.not file.) - Kl1 (kl1)  .(.Pas de propriétaire - Pas de description.) - LEGACY_KL1
      O64 - Services: CurCS - (.not file.) - srescan (srescan)  .(.Pas de propriétaire - Pas de description.) - LEGACY_SRESCAN
      O64 - Services: CurCS - (.not file.) - VET File System Filter (VET-FILT)  .(.Pas de propriétaire - Pas de description.) - LEGACY_VET-FILT      
      O81 - IFC: Internet Feature Controls [HKUS\.DEFAULT] [feature_enable_ie_compression] -- svchost.exe
      O81 - IFC: Internet Feature Controls [HKUS\S-1-5-18] [feature_enable_ie_compression] -- svchost.exe 


      Puis Lance ZHPFix depuis le raccouci du bureau .

      * Une fois l'outil ZHPFix ouvert , clique sur le bouton [ H ] ( "coller les lignes Helper" ) .

      * Dans l'encadré principal tu verras donc les lignes que tu as copié précédemment apparaitrent .

      Vérifie que toutes les lignes que je t'ai demandé de copier (et seulement elles) sont dans la fenêtre.

      * Puis clique sur le bouton [ OK ] .
      > à ce moment là , il apparaitra au début de chaque ligne une petite case vide .

      Ne touche plus à rien !

      !! Déconnecte toi, désactive tes défenses ( anti-virus,anti-spyware ) et ferme bien toutes autres applications ( navigateurs compris ) !!

      * Clique sur le bouton [ Tous ] . Vérifies que toutes les lignes soient bien cochées .

      * Enfin clique sur le bouton [ Nettoyer ] .

      -> laisse travailler l'outil et ne touche à rien ...

      -> Si il t'est demandé de redémarrer le PC pour finir le nettoyage , fais le !

      Une fois terminé , un nouveau rapport s'affiche : poste le contenu de ce dernier dans ta prochaine réponse ...

      ( ce rapport est en outre sauvegardé dans ce dossier > C:\Program files\ZHPDiag\ZHPFixReport.txt )

      Pense à réactiver tes défenses !...

      =========================

      2- supprime GMER si tu l'as encore ...

      et reprends ainsi :

      Télécharge gmer sur le bureau :

      > https://www.cjoint.com/?gpmlfLZRxh

      Impératif : Démarrer en mode sans echec .

      /!\ Ne jamais démarrer en mode sans échec via MSCONFIG /!\

      Comment aller en Mode sans échec :
      a) Redémarre ton ordi .
      b) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip" .
      c) Tu tapotes jusqu' à l'apparition de l'écran avec les options de démarrage .
      d) Choisis la première option : Sans Échec , et valide en tapant sur [Entrée] .
      e) Choisis ton compte habituel ( et pas Administrateur ).
      attention : pas de connexion possible en mode sans échec , donc copie ou imprime bien la manipe pour éviter les erreurs ...

      * Double-clique sur ..._gmer.exe pour lancer l'outil .
      * Mets toi bien sur l'onglet "rootkit".
      * A droite, vérifies que toutes les options soit cochées.
      * puis clique sur scan.

      > laisse travailler et ne touche à rien ! ( cela est relativement long, donc patience !... )

      > Pour sauvegarder le rapport:
      * A la fin du scan, clique sur le bouton copy.
      * Puis va dans "démarrer" > "programmes" > "accessoires" : ouvre le bloc-note et clique sur CTRL+V afin de copier le rapport dans ce même bloc-note. Enfin sauvegarde ce rapport de manière à le retrouver ! ( sur le bureau par exemple....

      -> Redémarre ton PC ( retour en mode normal ) et poste le rapport via "Cijoint" stp ...

      0
      1. http://www.cijoint.fr/cjlink.php?file=cj201006/cijbgrb5ML.txt
        0
      2. Contributeur sécurité
        vu ...

        continue ... ;)
        0
      3. mon ordi bloque qd je veux exécuter Gmer
        0
      4. Contributeur sécurité
        re,

        tu l'as lancé en mode sans échec ? ... Il bloque à quel moment ?
        0
      5. http://www.cijoint.fr/cjlink.php?file=cj201006/cij6aJvOQb.txt
        0
    • 1
    • 2