Merci pour ta rapidité !
J'ai téléchargé RogueKiller, je l'ai exécuté , voici le rapport:
RogueKiller V2.4.0 by Tigzy
contact at www.sur-la-toile.com
mail: tigzy44<at>hotmail<dot>fr
Remontées:
http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html
Operating System: Windows XP (5.1.2600 Service Pack 3) version 32 bits
Mode: Scan -- Time : 02/11/2010 23:35:12
Bad processes:
Found:
Finished
RogueKiller V3.5.1 by Tigzy
contact at www.sur-la-toile.com
mail: tigzy44<at>hotmail<dot>fr
Feedback:
http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html
Operating System: Windows XP (5.1.2600 Service Pack 3) version 32 bits
Mode: Remove -- Time : 25/12/2010 20:44:17
Bad processes:
Killed c:\docume~1\francis\locals~1\temp\csrss.exe
Killed c:\documents and settings\francis\application data\microsoft\conhost.exe
Killed c:\documents and settings\francis\application data\dwm.exe
Killed c:\docume~1\francis\locals~1\applic~1\exselqt.exe
Deregistred:
HKLM\...\RUN\ conhost : C:\Documents and Settings\Francis\Application Data\Microsoft\conhost.exe
HKCU\...\RUNONCE\ SpybotDeletingB4371 : command.com /c del "C:\Documents and Settings\Francis\Local Settings\Temp\csrss.exe_old"
HKCU\...\RUNONCE\ SpybotDeletingD4635 : cmd.exe /c del "C:\Documents and Settings\Francis\Local Settings\Temp\csrss.exe_old"
HKLM\...\RUNONCE\ SpybotDeletingA6698 : command.com /c del "C:\Documents and Settings\Francis\Local Settings\Temp\csrss.exe_old"
HKLM\...\RUNONCE\ SpybotDeletingC7252 : cmd.exe /c del "C:\Documents and Settings\Francis\Local Settings\Temp\csrss.exe_old"
HKCU\...\Internet Settings\ ProxyServer : http=127.0.0.1:64283
Finished
RogueKiller V3.5.1 by Tigzy
contact at www.sur-la-toile.com
mail: tigzy44<at>hotmail<dot>fr
Feedback:
http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html
Operating System: Windows XP (5.1.2600 Service Pack 3) version 32 bits
Mode: Remove -- Time : 25/12/2010 20:55:22
Bad processes:
Killed c:\documents and settings\francis\local settings\application data\exselqt.exe
Deregistred:
Finished
et depuis les pop-ups ont cessé ! je vois toujours l'icone security shield en bas a droite mais ils ont arrerter de m'harceler et j'ai l'impression que les ".exe" remarchent sinon j'ai mis a jour Malware et je vais debuter l'analyse.
Je te tiens au courant après l'analyse