je pense savoir d'où sa vient...
Avant d'utiliser Hijackthis on va nettoyer le PC :
Il existe un logiciel nommé Ccleaner, qui vous permet de supprimer tout les fichiers inutiles de votre ordinateur, parfois responsables de la lenteur :
http://www.filehippo.com/download_ccleaner/
ATTENTION : décochez la ligne Ajouter la barre d'Outils Yahoo! CCleaner.
Pour CCleaner : Afin que le nettoyage soit le plus en profondeur et que tu puisse garder un certain confort tu peux cocher sans problèmes :
POUR L'ONGLET WINDOWS :
- Tout internet explorer (vu que tu es sous firefox)
- Tout Windows explorer
- Tout dans Système, exceptés : Raccourcis du menu démarrer et l'autre
- Dans avancé : Vieilles données du prefecht, fichiers journal ISS, désinstallateurs de hotfixes
POUR L'ONGLET APPLICATION :
- Mozilla : cache, cookies, et les 2 historiques
- Après tu peux tout cocher, sauf ce qui est liés à la sécurité du PC (windows defender, Spybot etc...)
PARTIE REGISTRE :
Tu coches TOUT sauf extensions de fichiers inexistantes puis chercher les erreurs, sans oublier de bien faire la sauvegarde proposée en la gardant dans mes documents.
>>>
Télécharges hijackthis :
http://www.trendsecure.com/portal/en-US/_download/HiJackThis.zip
et voici un gif pour bien l'installer :
http://pageperso.aol.fr/balltrap34/Hijenr.gif
- Une fois téléchargé,
renommer l'éxécutable en HJT.exe pour contrer une éventuelle infection vundo
- Double-clic dessus
- Clic sur "Do a system scan and save the log"
- Copies le rapport, le coller dans la réponse
Et voici le rapport :
10:07:08 21/08/2008
mbam-log-08-21-2008 (10-07-08).txt
Type de recherche: Examen complet (C:\|D:\|J:\|)
Eléments examinés: 400597
Temps écoulé: 6 hour(s), 0 minute(s), 6 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 1
Clé(s) du Registre infectée(s): 10
Valeur(s) du Registre infectée(s): 4
Elément(s) de données du Registre infecté(s): 1
Dossier(s) infecté(s): 2
Fichier(s) infecté(s): 17
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
C:\WINDOWS\tsxngabr.dll (Trojan.FakeAlert) -> Delete on reboot.
Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\CLSID\{3c20d79f-c89d-49a4-8c76-961a62e6e963} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{6fa52c61-0329-438c-ad18-e22b11dada24} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{72125bfd-32cc-4138-b9a5-e727053d2e83} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\webvideo (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{88416f66-93eb-4ed8-a754-a60e9b911f29} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{9b6b8049-87dc-4e92-a0db-c87de7b4000d} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{948b15cf-e36c-438e-b455-9f7c9ef387d2} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VSPlugin (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\rafbsvnx.baqn (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\rafbsvnx.toolbar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\run (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\tsxngabr (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{948b15cf-e36c-438e-b455-9f7c9ef387d2} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\vtqnxfko (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Run (Trojan.Agent) -> Data: c:\documents and settings\nico\application data\adobe\manager.exe -> Quarantined and deleted successfully.
Dossier(s) infecté(s):
C:\WINDOWS\privacy_danger (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\privacy_danger\images (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Fichier(s) infecté(s):
J:\Mes documents\Logiciel\Magix vidéeo\_SubNet_ crack magix video deluxe 2008 by RAZOR Video\crack.exe (Adware.Shopper) -> Quarantined and deleted successfully.
J:\Mes documents\Logiciel\Magix vidéeo\_SubNet_ crack magix video deluxe 2008 by RAZOR Video\setup.exe (Adware.Agent) -> Quarantined and deleted successfully.
J:\Mes documents\adobe CS3Efr\ADOBE PHOTOSHOP CS3 EXTENDED FRENCH\Keygens\PhotoShop.CS3.Extended.Keygen+Activation\PhotoShop.CS3.Extended.Keygen+Activation.exe (Trojan.Horst) -> Quarantined and deleted successfully.
J:\Nouveau dossier (2)\adobe CS3Efr\ADOBE PHOTOSHOP CS3 EXTENDED FRENCH\Keygens\PhotoShop.CS3.Extended.Keygen+Activation\PhotoShop.CS3.Extended.Keygen+Activation.exe (Trojan.Horst) -> Quarantined and deleted successfully.
J:\Downloads By Firefox\Ahead.Nero.v8.3.2.1.Incl.Keymaker-EMBRACE\Ahead.Nero.v8.3.2.1.Incl.Keymaker-EMBRACE\keygen.exe (Trojan.Agent) -> Quarantined and deleted successfully.
J:\Toutes les seveugardes c'est ici ;)\Mardi 5 Août !\Azureus Downloads\adobe CS3Efr\ADOBE PHOTOSHOP CS3 EXTENDED FRENCH\Keygens\PhotoShop.CS3.Extended.Keygen+Activation\PhotoShop.CS3.Extended.Keygen+Activation.exe (Trojan.Horst) -> Quarantined and deleted successfully.
J:\DD HP PAVILLON SEV\Nicolas.CALM-7E62A90304\Local Settings\Temp\nsz527.tmp\blowfish.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\privacy_danger\index.htm (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\privacy_danger\images\capt.gif (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\privacy_danger\images\danger.jpg (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\privacy_danger\images\down.gif (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\privacy_danger\images\spacer.gif (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\tsxngabr.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\tqwolser.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\rafbsvnx.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Nico\Application Data\Adobe\Manager.exe (Trojan.Agent) -> Quarantined and deleted successfully.