Un virus m'attaque!!!!!!SOS

Résolu
Bonjour,
je pense avoir attrapé un virus.une fenetre s'ouvre régulierement depuis que mon antivirus(Avira Antivir)l'a détecté et
l'a détruit!!
voici le rapport hijackthis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:36:27, on 28/01/2009
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.packardbell.fr/center
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - Global Startup: DSLMON.lnk = ?
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O14 - IERESET.INF: START_PAGE_URL=www.packardbell.fr/center
O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

--
End of file - 3534 bytes

--
même si vous pensez que vous n'avez aucune connaissance.vous pourrez peut etre aider quelqu'un qui a vraiment besoin d'aide. penser aussi que ça peut etre cette persone qui vous aidera demain
Configuration: Windows XP
Internet Explorer 6.0

45 réponses

Résumé de la discussion

Un utilisateur signale des fenêtres qui s'ouvrent régulièrement après la détection et la suppression d'un élément par l'antivirus, et partage un log HijackThis détaillant les processus actifs. Plusieurs réponses proposent des vérifications complémentaires via BitDefender Online Scanner et Malwarebytes, et résument les éléments du log HijackThis : entrées au démarrage, modules externes et extensions potentiellement problématiques. En cas de doute, la discussion suggère des nettoyages avec des outils anti-malware et des guides d'installation, notamment Malwarebytes, afin d'éliminer les restes éventuels et prévenir de nouvelles infections. Le dernier élément du fil mentionne un balayage complet qui ne détecte aucune infection et confirme l'importance d'une approche multi-outils pour le nettoyage.

Bobot (l’IA à votre service)
  1. qu est ce vous avez tous avec avira c de la m... tel eset nod 32 ou norton 2009 et fini la panique a bon entendeur
    0
    1. bonjour :

      vide la quarantaine d'Avira

      ensuite :

      Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

      -> http://images.malwareremoval.com/random/RSIT.exe

      ! Déconnecte toi et ferme toutes tes applications en cours !

      Double-clique sur " RSIT.exe " pour le lancer .

      -> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

      * Devant l'option "List files/folders created ..." , tu choisis : 2 months

      * clique ensuite sur " Continue " pour lancer l'analyse ...

      -> laisse faire le scan et ne touche pas au PC ...

      Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

      Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

      Important : poste un rapport, puis l'autre dans la réponse suivante
      Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum

      ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )

      0
      1. voilà le fichier log.txt:
        Logfile of random's system information tool 1.05 (written by random/random)
        Run by anna l'etang at 2009-01-28 19:00:48
        Microsoft Windows XP Édition familiale
        System drive C: has 74 GB (94%) free of 78 GB
        Total RAM: 255 MB (50% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 19:00:53, on 28/01/2009
        Platform: Windows XP (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 (6.00.2600.0000)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
        C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
        C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
        C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
        C:\WINDOWS\System32\nvsvc32.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\MSN Messenger\usnsvc.exe
        C:\Documents and Settings\anna l'etang\Mes documents\logiciel\RSIT.exe
        C:\Program Files\Trend Micro\HijackThis\anna l'etang.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.packardbell.fr/center
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
        O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
        O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
        O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800"
        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
        O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
        O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
        O4 - Global Startup: DSLMON.lnk = ?
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
        O14 - IERESET.INF: START_PAGE_URL=www.packardbell.fr/center
        O17 - HKLM\System\CCS\Services\Tcpip\..\{2646BC82-B8C6-4058-8146-B91EA97BA0B9}: NameServer = 80.10.246.130 80.10.246.3
        O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
        O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
        O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
        O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
        0
        1. et voilà le fichier info.txt:
          info.txt logfile of random's system information tool 1.05 2009-01-28 19:00:56

          ======Uninstall list======

          -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
          -->CIAunwdm.exe
          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5809E7CF-4DCF-11D4-9875-00105ACE7734}\SETUP.EXE" -l040c UNINSTALL
          -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
          Adobe Flash Player 10 ActiveX-->C:\WINDOWS\System32\Macromed\Flash\uninstall_activeX.exe
          AVG Anti-Spyware 7.5-->C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Uninstall.exe
          Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
          EPSON Attach To Email-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{20C45B32-5AB6-46A4-94EF-58950CAF05E5} /l1033 ADDREMOVEDLG
          EPSON Copy Utility 3-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{67EDD823-135A-4D59-87BD-950616D6E857}\SETUP.EXE" -l0x40c -UnInstall
          EPSON Easy Photo Print-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5DA7BC15-18D3-41A0-9F59-838DA3EAEF17}\SETUP.EXE" -l0x40c UNINST
          EPSON File Manager-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E86BC406-944E-41F6-ADE6-2C136734C96B}\Setup.exe" -l0x40c UNINST
          EPSON Image Clip Palette-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{314F6D08-A8B7-11D8-8446-0050BA1D384D}\Setup.exe" -l0x40c -u
          EPSON Logiciel imprimante-->C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
          EPSON Scan Assistant-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}\Setup.exe" -l0x40c -u
          EPSON Scan-->C:\Program Files\epson\escndv\setup\setup.exe /r
          EPSON Web-To-Page-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}\SETUP.EXE" -l0x40c -anything
          ESDX3800 Guide d'utilisation-->C:\Program Files\EPSON\TPMANUAL\ESDX3800\USE_G\DOCUNINS.EXE
          HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
          Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
          Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
          NVIDIA Windows 2000/XP Display Drivers-->rundll32.exe C:\WINDOWS\System32\nvinstnt.dll,NvUninstallNT4 nvne.inf
          PIF DESIGNER-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B90450DF-E781-46FD-B1F1-0C86DA40E443}\SETUP.EXE" -l0x40c anything
          SAGEM F@st 800-840-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4AE3A0CB-87B0-4F51-BECD-3D1F8DFDD62F}\Setup.exe" -l0x40c
          Windows Live Messenger-->MsiExec.exe /I{F6326B60-1B1D-4ABF-BFCD-7B7404F44411}
          Windows Live Sign-in Assistant-->MsiExec.exe /I{49672EC2-171B-47B4-8CE7-50D7806360D7}
          Windows XP Hotfix (SP1) [See Q317277 for more information]-->C:\WINDOWS\$NtUninstallQ317277$\spuninst\spuninst.exe

          System event log

          Computer Name: SN2749087003
          Event Code: 1003
          Message: Code erreur 100000ea, paramètre 1 815f6b08, paramètre 2 81601ae8, paramètre 3 816f70d0, paramètre 4 00000001.

          Record Number: 5
          Source Name: System Error
          Time Written: 20090128082323.000000+060
          Event Type: erreur
          User:

          Computer Name: SN2749087003
          Event Code: 1003
          Message: Code erreur 100000ea, paramètre 1 814d3da8, paramètre 2 81602ec0, paramètre 3 816f91b8, paramètre 4 00000001.

          Record Number: 4
          Source Name: System Error
          Time Written: 20090128082318.000000+060
          Event Type: erreur
          User:

          Computer Name: SN2749087003
          Event Code: 1003
          Message: Code erreur 100000ea, paramètre 1 81504c30, paramètre 2 8160a0a0, paramètre 3 816ec2b0, paramètre 4 00000001.

          Record Number: 3
          Source Name: System Error
          Time Written: 20090128082314.000000+060
          Event Type: erreur
          User:

          Computer Name: SN2749087003
          Event Code: 1003
          Message: Code erreur 100000ea, paramètre 1 8135b190, paramètre 2 8161aa58, paramètre 3 816fbbf8, paramètre 4 00000001.

          Record Number: 2
          Source Name: System Error
          Time Written: 20090128082304.000000+060
          Event Type: erreur
          User:

          Computer Name: SN2749087003
          Event Code: 115
          Message: Le suivi de la Restauration système a été activé sur tous les lecteurs.

          Record Number: 1
          Source Name: SRService
          Time Written: 20090128082254.000000+060
          Event Type: Informations
          User:

          Application event log

          Computer Name: SN2749087003
          Event Code: 4354
          Message: Le système d'événements de COM+ n'a pas pu déclencher la méthode ConnectionMade de l'abonnement {DF6A903A-9AF4-45B1-A67E-39D34473FB1C}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}. L'abonné a renvoyé HRESULT 80004001.
          Record Number: 5
          Source Name: EventSystem
          Time Written: 20090128083454.000000+060
          Event Type: Avertissement
          User:

          Computer Name: SN2749087003
          Event Code: 2001
          Message: Le service EAPOL a été démarré correctement

          Record Number: 4
          Source Name: EAPOL
          Time Written: 20090128083249.000000+060
          Event Type: Informations
          User:

          Computer Name: SN2749087003
          Event Code: 1000
          Message: Les compteurs de performances pour le service WmiApRpl (WmiApRpl) ont été chargés.
          Les données d'enregistrement contiennent les nouvelles valeurs d'index
          assignées à ce service.

          Record Number: 3
          Source Name: LoadPerf
          Time Written: 20090128082632.000000+060
          Event Type: Informations
          User:

          Computer Name: SN2749087003
          Event Code: 1001
          Message: Les compteurs de performances pour le service WmiApRpl (WmiApRpl) ont été supprimés.
          Les données d'enregistrement contiennent les nouvelles valeurs du dernier compteur système
          et les dernières entrées du registre d'aide.

          Record Number: 2
          Source Name: LoadPerf
          Time Written: 20090128082632.000000+060
          Event Type: Informations
          User:

          Computer Name: SN2749087003
          Event Code: 4354
          Message: Le système d'événements de COM+ n'a pas pu déclencher la méthode StartShell de l'abonnement {A5978620-5B3F-F1D1-8ED2-00FA0035B753}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}. L'abonné a renvoyé HRESULT 80004001.
          Record Number: 1
          Source Name: EventSystem
          Time Written: 20090128082318.000000+060
          Event Type: Avertissement
          User:

          ======Environment variables======

          "ComSpec"=%SystemRoot%\system32\cmd.exe
          "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
          "windir"=%SystemRoot%
          "OS"=Windows_NT
          "PROCESSOR_ARCHITECTURE"=x86
          "PROCESSOR_LEVEL"=6
          "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 6 Stepping 2, AuthenticAMD
          "PROCESSOR_REVISION"=0602
          "NUMBER_OF_PROCESSORS"=1
          "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
          "TEMP"=%SystemRoot%\TEMP
          "TMP"=%SystemRoot%\TEMP

          -----------------EOF-----------------

          0
          1. @ beskmax :

            premierement on dit bonjour;

            duexiemement , si c est pour dire des conn******* y'a d autres forums pour cela

            troisiemement , ne conseilles pas des choses que tu ne connais pas

            quatriemement , trouve toi un topic a ouvrir au lieu de polluer

            @Maestro 94 :

            je ne vois rien de méchant

            Télécharge ATF Cleaner par Atribune:
            http://www.atribune.org/ccount/click.php?id=1
            Double-clique ATF-Cleaner.exe afin de lancer le programme.
            Sous l'onglet Main, choisis : Select All
            Clique sur le bouton Empty Selected
            Si tu utilises le navigateur Firefox :
            Clique Firefox au haut et choisis : Select All
            Clique le bouton Empty Selected
            NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.
            Si tu utilises le navigateur Opera :
            Clique Opera au haut et choisis : Select All
            Clique le bouton Empty Selected
            NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.
            Clique Exit, du menu prinicipal, afin de fermer le programme.
            Pour obtenir du Support technique, double-clique l'adresse électronique située au bas de chacun des menus.

            ensuite :

            - > Ouvre ce lien pour scanner ton PC avec un BitDefender en ligne (uniquement sous Internet Explorer) :

            http://www.bitdefender.fr/scan_fr/scan8/ie.html

            Utilisation :
            Cliquer sur "J'accepte" puis accepter également l'ActiveX bloqué par la barre anti-popup de Windows qui clignotera en haut et l'installer.
            Ensuite, cliquer sur "Cliquez ici pour scanner".
            Patienter jusqu'à la fin du scan qui peut durer assez longtemps...

            Copier/coller le rapport entier sur le forum.
            0
            1. j'ai fais ce que tu m'as dit pour le logiciel ATF-Cleaner et une fenetre s'est ouverte où était écrit done cleaning!!ATF-Cleaner has freed 7 924 00KBs.
              c'est normale??
              0
              1. oui il t a fait le menage :)

                la suite ..
                0
                1. je n'ai pa pu faire le scanner ça ne fonctionne pas!!mon antivirus detecte de plus en plus fréquemment un cheval de troie: TR/Crypt.XPACK.Gen
                  0
                  1. Télécharge MalwareByte's :
                    http://www.malwarebytes.org/mbam.php ou ici :
                    http://www.malwarebytes.org/mbam/program/mbam-setup.exe

                    * Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

                    (NB : S'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : https://www.malekal.com/tutorial-aboutbuster/ )

                    * Potasse le tuto pour te familiariser avec le prg :
                    https://forum.pcastuces.com/sujet.asp?f=31&s=3
                    ( cela dis, il est très simple d'utilisation ).

                    ! Déconnecte toi et ferme toutes applications en cours !

                    * Lance Malwarebyte's .

                    Fais un examen dit "Rapide" .

                    --> Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
                    --> à la fin tu cliques sur "résultat" .
                    --> Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

                    Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

                    Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)

                    0
                    1. je l'avais déja fait hier mais il n'avait rien détecté pareil pour aujourd'hui!!
                      0
                      1. mon antivirus detecte de plus en plus fréquemment un cheval de troie: TR/Crypt.XPACK.Gen

                        tu peux dire dans quel fichier ?

                        Telecharge maintenant FindyKill sur ton bureau :

                        http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.exe

                        --> Lance l installation avec les parametres par default

                        --> Au menu principal,choisi l option 1 (Recherche)

                        --> Post le rapport FindyKill.txt

                        Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
                        0
                        1. il se trouve dans le fichier C:\ARK3.tmp

                          voilà le rapport:

                          ###################### [ FindyKill V4.715 ]

                          # User : anna l'etang - SN2749087003
                          # Emplacement : C:\Program Files\FindyKill
                          # Outils Mis a jours 29/01/09 par Chiquitine29
                          # Recherche effectuée à 20:56:09 le 29/01/2009
                          # Windows XP - Internet Explorer 6.0.2600.0000

                          # [ FindyKill V4.715 - Scan ] ##############

                          \\\\\\\\\\\\\\\\\\\\ [ Processus actifs ] ///////////////////

                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\csrss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                          C:\WINDOWS\System32\nvsvc32.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
                          C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE
                          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                          C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe

                          \\\\\\\\\\\\\\\\\\ [ Fichiers/Dossiers infectieux ] ///////////////////

                          ################## [ C:\ ]

                          ################## [ C:\WINDOWS ]

                          ################## [ C:\WINDOWS\Prefetch ]

                          Found ! - C:\WINDOWS\prefetch\.EXE-2656339D.pf

                          ################## [ C:\WINDOWS\system32 ]

                          ################## [ C:\WINDOWS\system32\drivers ]

                          ################## [ C:\Documents and Settings\anna l'etang\Application Data ]

                          ################## [ C:\DOCUME~1\ANNAL'~1\LOCALS~1\Temp ]

                          \\\\\\\\\\\\\\\\\\ [ Registre / Startup ] ///////////////////

                          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
                          NvCplDaemon=RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
                          EM_EXEC=C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
                          EPSON Stylus DX3800 Series=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800"
                          avgnt="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                          !AVG Anti-Spyware="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                          HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
                          HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
                          Installed=1
                          HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
                          Installed=1
                          NoChange=1
                          HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
                          Installed=1

                          \\\\\\\\\\\\\\\\\\ [ Registre / Clés infectieuses ] ///////////////////

                          \\\\\\\\\\\\\\\\\\ [ Etat / Services ] ///////////////////

                          # Services : [ Auto=2 / Demande=3 / Désactivé=4 ]

                          Ndisuio - # Type de démarrage = 3

                          SharedAccess - # Type de démarrage = 3

                          wuauserv - # Type de démarrage = 2

                          \\\\\\\\\\\\\\\\\\ [ Recherche dans supports amovibles] ///////////////////

                          # Informations :

                          C: - Lecteur fixe

                          # presence des fichiers :

                          \\\\\\\\\\\\\\\\\\ [ Registre / Mountpoint2 ] ///////////////////

                          -> Not found !

                          ################## [ ! Fin du rapport # FindyKill V4.715 ! ]

                          0
                          1. ---> Désactive ton antivirus le temps de la manipulation car OTMoveIt3 est détecté comme une infection à tort.

                            ---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :
                            http://oldtimer.geekstogo.com/OTMoveIt3.exe

                            ---> Double-clique sur OTMoveIt3.exe afin de le lancer.

                            ---> Copie (Ctrl+C) le texte suivant ci-dessous :



                            :processes
                            explorer.exe

                            :files
                            C:\ARK3.tmp

                            :commands
                            [purity]
                            [emptytemp]
                            [start explorer]
                            [reboot]


                            ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

                            ---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

                            Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
                            Accepte en cliquant sur YES.

                            ---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
                            Le nom du rapport correspond au moment de sa création : date_heure.log

                            ensuite :


                            Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

                            --> Fais clic droit sur le raccourci FindyKill sur ton bureau

                            --> Au menu principal,choisi l option 2 (Suppression)

                            /!\ il y aura 2 redémarrage, laisse travailler l outils jusqu a l apparition du message "nettoyage effectué"

                            /!\ Ne te sert pas du pc durant la suppression , ton bureau ne sera pas accessible c est normal !

                            -------> ensuite post le rapport FindyKill.txt

                            Note : le rapport FindyKill.txt est sauvegardé a la racine du disque

                            ensuite :

                            renvoie un rsit stp
                            0
                            1. j'ai remarqué que aprés avoir utilisé le logiciel OT Moveit3 le logiciel rsit a disparu!!c'est normale??
                              0
                              1. utilisé le logiciel OT Moveit3 le logiciel rsit a disparu!!c'est normale??

                                premiere fois que ca arrive !!!

                                vois pour la suite
                                0
                                1. voila le rapport log.txt:
                                  Logfile of random's system information tool 1.05 (written by random/random)
                                  Run by anna l'etang at 2009-01-29 22:57:22
                                  Microsoft Windows XP Édition familiale
                                  System drive C: has 73 GB (94%) free of 78 GB
                                  Total RAM: 255 MB (36% free)

                                  Logfile of Trend Micro HijackThis v2.0.2
                                  Scan saved at 22:57:37, on 29/01/2009
                                  Platform: Windows XP (WinNT 5.01.2600)
                                  MSIE: Internet Explorer v6.00 (6.00.2600.0000)
                                  Boot mode: Normal

                                  Running processes:
                                  C:\WINDOWS\System32\smss.exe
                                  C:\WINDOWS\system32\winlogon.exe
                                  C:\WINDOWS\system32\services.exe
                                  C:\WINDOWS\system32\lsass.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\WINDOWS\Explorer.EXE
                                  C:\WINDOWS\system32\spoolsv.exe
                                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                  C:\WINDOWS\System32\nvsvc32.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
                                  C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE
                                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                                  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                                  C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                                  C:\Program Files\Internet Explorer\iexplore.exe
                                  C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                                  C:\Documents and Settings\anna l'etang\Mes documents\logiciel\RSIT.exe
                                  C:\Program Files\Trend Micro\HijackThis\anna l'etang.exe

                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.fr/
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.packardbell.fr/center
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                  O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                  O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                                  O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                                  O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
                                  O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
                                  O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800"
                                  O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                                  O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                                  O4 - Global Startup: DSLMON.lnk = ?
                                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                                  O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                                  O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                                  O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                                  O14 - IERESET.INF: START_PAGE_URL=www.packardbell.fr/center
                                  O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                                  O17 - HKLM\System\CCS\Services\Tcpip\..\{2646BC82-B8C6-4058-8146-B91EA97BA0B9}: NameServer = 80.10.246.130 80.10.246.3
                                  O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                  O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                  O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                  O23 - Service: Network helper Service (MSDisk) - Unknown owner - C:\WINDOWS\System32\irdvxc.exe (file missing)
                                  O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                                  0
                                  1. et voila le rapport info.txt:
                                    info.txt logfile of random's system information tool 1.05 2009-01-29 22:57:40

                                    ======Uninstall list======

                                    -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
                                    -->CIAunwdm.exe
                                    -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5809E7CF-4DCF-11D4-9875-00105ACE7734}\SETUP.EXE" -l040c UNINSTALL
                                    -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
                                    Adobe Flash Player 10 ActiveX-->C:\WINDOWS\System32\Macromed\Flash\uninstall_activeX.exe
                                    AVG Anti-Spyware 7.5-->C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Uninstall.exe
                                    Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
                                    EPSON Attach To Email-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{20C45B32-5AB6-46A4-94EF-58950CAF05E5} /l1033 ADDREMOVEDLG
                                    EPSON Copy Utility 3-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{67EDD823-135A-4D59-87BD-950616D6E857}\SETUP.EXE" -l0x40c -UnInstall
                                    EPSON Easy Photo Print-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5DA7BC15-18D3-41A0-9F59-838DA3EAEF17}\SETUP.EXE" -l0x40c UNINST
                                    EPSON File Manager-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E86BC406-944E-41F6-ADE6-2C136734C96B}\Setup.exe" -l0x40c UNINST
                                    EPSON Image Clip Palette-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{314F6D08-A8B7-11D8-8446-0050BA1D384D}\Setup.exe" -l0x40c -u
                                    EPSON Logiciel imprimante-->C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
                                    EPSON Scan Assistant-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}\Setup.exe" -l0x40c -u
                                    EPSON Scan-->C:\Program Files\epson\escndv\setup\setup.exe /r
                                    EPSON Web-To-Page-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}\SETUP.EXE" -l0x40c -anything
                                    ESDX3800 Guide d'utilisation-->C:\Program Files\EPSON\TPMANUAL\ESDX3800\USE_G\DOCUNINS.EXE
                                    FindyKill-->C:\Program Files\FindyKill\Uninstal.exe
                                    HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
                                    Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
                                    Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
                                    NVIDIA Windows 2000/XP Display Drivers-->rundll32.exe C:\WINDOWS\System32\nvinstnt.dll,NvUninstallNT4 nvne.inf
                                    PIF DESIGNER-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B90450DF-E781-46FD-B1F1-0C86DA40E443}\SETUP.EXE" -l0x40c anything
                                    SAGEM F@st 800-840-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4AE3A0CB-87B0-4F51-BECD-3D1F8DFDD62F}\Setup.exe" -l0x40c
                                    Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803$\spuninst\spuninst.exe"
                                    Windows Live Messenger-->MsiExec.exe /I{F6326B60-1B1D-4ABF-BFCD-7B7404F44411}
                                    Windows Live Sign-in Assistant-->MsiExec.exe /I{49672EC2-171B-47B4-8CE7-50D7806360D7}
                                    Windows XP Hotfix (SP1) [See Q317277 for more information]-->C:\WINDOWS\$NtUninstallQ317277$\spuninst\spuninst.exe

                                    System event log

                                    Computer Name: SN2749087003
                                    Event Code: 1003
                                    Message: Code erreur 100000ea, paramètre 1 815f6b08, paramètre 2 81601ae8, paramètre 3 816f70d0, paramètre 4 00000001.

                                    Record Number: 5
                                    Source Name: System Error
                                    Time Written: 20090128082323.000000+060
                                    Event Type: erreur
                                    User:

                                    Computer Name: SN2749087003
                                    Event Code: 1003
                                    Message: Code erreur 100000ea, paramètre 1 814d3da8, paramètre 2 81602ec0, paramètre 3 816f91b8, paramètre 4 00000001.

                                    Record Number: 4
                                    Source Name: System Error
                                    Time Written: 20090128082318.000000+060
                                    Event Type: erreur
                                    User:

                                    Computer Name: SN2749087003
                                    Event Code: 1003
                                    Message: Code erreur 100000ea, paramètre 1 81504c30, paramètre 2 8160a0a0, paramètre 3 816ec2b0, paramètre 4 00000001.

                                    Record Number: 3
                                    Source Name: System Error
                                    Time Written: 20090128082314.000000+060
                                    Event Type: erreur
                                    User:

                                    Computer Name: SN2749087003
                                    Event Code: 1003
                                    Message: Code erreur 100000ea, paramètre 1 8135b190, paramètre 2 8161aa58, paramètre 3 816fbbf8, paramètre 4 00000001.

                                    Record Number: 2
                                    Source Name: System Error
                                    Time Written: 20090128082304.000000+060
                                    Event Type: erreur
                                    User:

                                    Computer Name: SN2749087003
                                    Event Code: 115
                                    Message: Le suivi de la Restauration système a été activé sur tous les lecteurs.

                                    Record Number: 1
                                    Source Name: SRService
                                    Time Written: 20090128082254.000000+060
                                    Event Type: Informations
                                    User:

                                    ======Environment variables======

                                    "ComSpec"=%SystemRoot%\system32\cmd.exe
                                    "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
                                    "windir"=%SystemRoot%
                                    "OS"=Windows_NT
                                    "PROCESSOR_ARCHITECTURE"=x86
                                    "PROCESSOR_LEVEL"=6
                                    "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 6 Stepping 2, AuthenticAMD
                                    "PROCESSOR_REVISION"=0602
                                    "NUMBER_OF_PROCESSORS"=1
                                    "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
                                    "TEMP"=%SystemRoot%\TEMP
                                    "TMP"=%SystemRoot%\TEMP

                                    -----------------EOF-----------------
                                    0
                                    1. relis bien je voulais que tu fasses findykill option 2 avant ;)
                                      0
                                      1. ben c'est pas se que j'ai fais??
                                        0
                                        1. ensuite :

                                          Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

                                          --> Fais clic droit sur le raccourci FindyKill sur ton bureau

                                          --> Au menu principal,choisi l option 2 (Suppression)

                                          /!\ il y aura 2 redémarrage, laisse travailler l outils jusqu a l apparition du message "nettoyage effectué"

                                          /!\ Ne te sert pas du pc durant la suppression , ton bureau ne sera pas accessible c est normal !

                                          -------> ensuite post le rapport FindyKill.txt

                                          Note : le rapport FindyKill.txt est sauvegardé a la racine du disque

                                          ensuite :
                                          --
                                          On vous aide ailleurs ? signalez-le !!!!!
                                          Mettre en resolu pour les autres  Merci
                                                    ®© ----g3и-н@¢км@и---- ©®
                                          0
                                          • 1
                                          • 2
                                          • 3