Pub s'ouvre quand je lance internet

Bonjour,
je me permets de vous contacter car j'ai une page de pub qui s'ouvre quand je me connecte à internet. j'ai téléchargé HijackThis mais je ne sais pas quoi faire avec....
si quelqu'un peut m'aider ce serait sympa.
merci d'avance
Configuration: Windows XP
Firefox 3.0.8

6 réponses

  1. Contributeur
    OK Loupi, je te laisses avec " l'expert en la matière "

    Fix200, continues tu tiens le bon bout ! mdr

    @++
    1
    1. Contributeur
      Salut,

      Telecharges RSIT " Random's System Information Tool " sur ton bureau : http://images.malwareremoval.com/random/RSIT.exe

      - Fermes toutes les applications en cours et double clic sur RSIT.exe
      - Selectionnes " Continue " à l'ecran >> RSIT va analyser le pc et verifier si l'outil hijackthis ( version à jour) est present sur le pc, si ce n'est pas le cas, RSIT le telechargera >> acceptes la license
      - Une fois l'analyse terminée, 2 rapports.txt s'ouvrent, log.txt à l'écran et info.txt dans la barre des taches
      - Postes le contenu des 2 rapports
      0
      1. voici les deux fichiers textes
        merci encore

        2:34:53

        ======Uninstall list======

        -->"C:\Program Files\Fichiers communs\aolshare\Coach\AolCInUn.exe" -lang="fr-fr"
        -->C:\PROGRA~1\FICHIE~1\AOL\ACS\AcsUninstall.exe /c
        -->C:\PROGRA~1\GOTOSO~1\VADERE~1\UNWISE.EXE C:\PROGRA~1\GOTOSO~1\VADERE~1\INSTALL.LOG
        -->C:\PROGRA~1\Norman\NORMAN~1\UNWISE.EXE C:\PROGRA~1\Norman\NORMAN~1\INSTALL.LOG
        -->C:\Program Files\Fichiers communs\AOL\Screensaver\uninst_ygpss.exe
        -->C:\Program Files\Fichiers communs\aolshare\Aolunins_fr.exe
        -->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
        -->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
        -->C:\Program Files\Learn2.com\StRunner\stuninst.exe
        -->C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
        -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
        -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
        -->C:\WINDOWS\unvise32qt.exe C:\WINDOWS\system32\QuickTime\Uninstall.log
        -->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
        -->MsiExec.exe /I{8B543A39-9401-44F4-B572-069E64C15189}
        -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\Setup.EXE" -uninstall
        -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3F9CFBD8-8F77-4DCD-8CB5-CDD5F653C872}\setup.exe" -l0x40c
        -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4F1DA6BF-3614-48A1-9970-9E90F646789E}\setup.exe" -l0x40c
        -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5A065EA0-0EEC-4E94-A2A0-40812576C122}\setup.exe" -l0x40c
        -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5AFA4872-16B2-419E-ADCA-8E96E739115D}\setup.exe" -l0x40c
        -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0A32C786-85DE-48F8-9E54-848B3E34A90C}\setup.exe" -l0x40c -removeonly
        -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
        Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
        Adobe Reader 7.0 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A70000000000}
        ALUpdate-->"C:\Program Files\ESTsoft\ALUpdate\unins000.exe"
        ALZip-->"C:\Program Files\ESTsoft\ALZip\unins000.exe"
        avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
        CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
        Codeur Windows Media Série 9-->MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
        Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
        Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
        dBpowerAMP AAC Codec-->"C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP AAC Codec.dat
        dBpowerAMP AAC to Mp4 Codec-->"C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP AAC to Mp4 Codec.dat
        dBPowerAMP AIFF codec r4-->"C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBPowerAMP AIFF codec r4.dat
        dBpowerAMP FAAC Mp4 Codec-->"C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP FAAC Mp4 Codec.dat
        dBpowerAMP FLAC Codec-->"C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP FLAC Codec.dat
        dBpowerAMP Monkeys Audio Codec-->"C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP Monkeys Audio Codec.dat
        dBpowerAMP mp3PRO Input Codec-->"C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP mp3PRO Input Codec.dat
        dBpowerAMP Mp4 & AAC Decode Codec-->"C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP Mp4 & AAC Decode Codec.dat
        dBpowerAMP Musepack Codec-->"C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP Musepack Codec.dat
        dBpowerAMP Music Converter-->"C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP Music Converter.dat
        dBpowerAMP Ogg Vorbis Codec-->"C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP Ogg Vorbis Codec.dat
        dBpowerAMP Real Audio Codec-->"C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP Real Audio Codec.dat
        dBPowerAMP Real Audio Encoder R3-->"C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBPowerAMP Real Audio Encoder R3.dat
        dBpowerAMP VQF Codec-->"C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP VQF Codec.dat
        dBpowerAMP Winamp Codec-->"C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP Winamp Codec.dat
        dBpowerAMP WMA V9 Codec-->"C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP WMA V9 Codec.dat
        dMC mp3PRO (CLI) Encoder-->"C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dMC mp3PRO (CLI) Encoder.dat
        eMule-->"C:\Program Files\eMule\Uninstall.exe"
        Favorit-->"d:\documents and settings\romain\local settings\application data\mkkie.exe" -uninstall
        Football Manager 2009-->"D:\Documents and Settings\romain\Mes documents\Uninstall_Football Manager 2009\Uninstall Football Manager 2009.exe"
        Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
        High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
        HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
        Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
        J2SE Runtime Environment 5.0 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150020}
        Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
        Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
        Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
        Macromedia Shockwave Player-->MsiExec.exe /X{7D1D6A24-65D4-454C-8815-4F08A5FFF12C}
        MeuhMeuhTV (désinstallation uniquement)-->C:\Program Files\MeuhMeuhTV\UninstMMTV.exe
        Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
        Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
        Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
        Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
        Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
        Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
        Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
        Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour le Codeur Windows Media (KB954156)-->"C:\WINDOWS\$NtUninstallKB954156_WM9L$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media 10 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958215)-->"C:\WINDOWS\$NtUninstallKB958215$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960714)-->"C:\WINDOWS\$NtUninstallKB960714$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB963027)-->"C:\WINDOWS\$NtUninstallKB963027$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
        Mozilla Firefox (3.0.8)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
        MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
        NVIDIA Drivers-->C:\WINDOWS\system32\nvuninst.exe UninstallGUI
        OpenOffice.org 3.0-->MsiExec.exe /I{6860B340-530D-46B3-91F8-1AE1F70F7C33}
        Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
        Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x40c -removeonly
        Sonic MyDVD-->MsiExec.exe /I{21657574-BD54-48A2-9450-EB03B2C7FC29}
        Sonic RecordNow!-->MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}
        Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
        System Requirements Lab-->C:\Program Files\SystemRequirementsLab\Uninstall.exe
        Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
        Visual C++ 2008 x86 Runtime - v9.0.30729.01-->C:\WINDOWS\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
        Vuze-->C:\Program Files\Vuze\uninstall.exe
        Winamp-->"C:\Program Files\Winamp\UninstWA.exe"
        Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
        Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
        Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
        Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
        ZoneAlarm-->C:\Program Files\Zone Labs\ZoneAlarm\zauninst.exe

        ======Hosts File======

        127.0.0.1 www.007guard.com
        127.0.0.1 007guard.com
        127.0.0.1 008i.com
        127.0.0.1 www.008k.com
        127.0.0.1 008k.com
        127.0.0.1 www.00hq.com
        127.0.0.1 00hq.com
        127.0.0.1 010402.com
        127.0.0.1 www.032439.com
        127.0.0.1 032439.com

        ======Security center information======

        AV: avast! antivirus 4.8.1335 [VPS 090422-0]
        FW: ZoneAlarm Firewall

        ======System event log======

        Computer Name: SN112327070311
        Event Code: 4201
        Message: Le système a détecté que la carte réseau \DEVICE\TCPIP_{E46C811E-C7B4-404C-B054-2FC37E7EC32D} était connectée au réseau,
        et a lancé une opération normale sur la carte réseau.

        Record Number: 5510
        Source Name: Tcpip
        Time Written: 20090307194905.000000+060
        Event Type: Informations
        User:

        Computer Name: SN112327070311
        Event Code: 4201
        Message: Le système a détecté que la carte réseau \DEVICE\TCPIP_{E46C811E-C7B4-404C-B054-2FC37E7EC32D} était connectée au réseau,
        et a lancé une opération normale sur la carte réseau.

        Record Number: 5509
        Source Name: Tcpip
        Time Written: 20090307194848.000000+060
        Event Type: Informations
        User:

        Computer Name: SN112327070311
        Event Code: 7036
        Message: Le service Carte de performance WMI est entré dans l'état : en cours d'exécution.

        Record Number: 5508
        Source Name: Service Control Manager
        Time Written: 20090307193502.000000+060
        Event Type: Informations
        User:

        Computer Name: SN112327070311
        Event Code: 7035
        Message: Un contrôle Démarrer a correctement été envoyé au service Carte de performance WMI.

        Record Number: 5507
        Source Name: Service Control Manager
        Time Written: 20090307193502.000000+060
        Event Type: Informations
        User: AUTORITE NT\SYSTEM

        Computer Name: SN112327070311
        Event Code: 7036
        Message: Le service Service COM de gravage de CD IMAPI est entré dans l'état : arrêté.

        Record Number: 5506
        Source Name: Service Control Manager
        Time Written: 20090307193457.000000+060
        Event Type: Informations
        User:

        =====Application event log=====

        Computer Name: SN112327070311
        Event Code: 0
        Message:
        Record Number: 429
        Source Name: CLSched
        Time Written: 20090223114713.000000+060
        Event Type: Informations
        User:

        Computer Name: SN112327070311
        Event Code: 1800
        Message: Le service Centre de sécurité Windows a démarré.

        Record Number: 428
        Source Name: SecurityCenter
        Time Written: 20090223114712.000000+060
        Event Type: Informations
        User:

        Computer Name: SN112327070311
        Event Code: 0
        Message:
        Record Number: 427
        Source Name: CLCapSvc
        Time Written: 20090223114711.000000+060
        Event Type: Informations
        User:

        Computer Name: SN112327070311
        Event Code: 0
        Message:
        Record Number: 426
        Source Name: gusvc
        Time Written: 20090223114708.000000+060
        Event Type: Informations
        User:

        Computer Name: SN112327070311
        Event Code: 1002
        Message: L'environnement s'est arrêté de façon inattendue et Explorer.exe a redémarré.

        Record Number: 425
        Source Name: Winlogon
        Time Written: 20090222225930.000000+060
        Event Type: Informations
        User:

        ======Environment variables======

        "ComSpec"=%SystemRoot%\system32\cmd.exe
        "Path"=%SYSTEMROOT%\SYSTEM32;%SYSTEMROOT%;%SYSTEMROOT%\SYSTEM32\WBEM;C:\PROGRAM FILES\FICHIERS COMMUNS\ULEAD SYSTEMS\MPEG;C:\PROGRA~1\FICHIE~1\SONICS~1;C:\PROGRAM FILES\ESTSOFT\ALZIP;C:\WINDOWS;C:\WINDOWS\SYSTEM32\WBEM;C:\WINDOWS\SYSTEM32;
        "windir"=%SystemRoot%
        "FP_NO_HOST_CHECK"=NO
        "OS"=Windows_NT
        "PROCESSOR_ARCHITECTURE"=x86
        "PROCESSOR_LEVEL"=15
        "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 3, GenuineIntel
        "PROCESSOR_REVISION"=0403
        "NUMBER_OF_PROCESSORS"=2
        "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
        "TEMP"=%SystemRoot%\TEMP
        "TMP"=%SystemRoot%\TEMP
        "tvdumpflags"=8

        -----------------EOF-----------------
        Logfile of random's system information tool 1.06 (written by random/random)
        Run by romain at 2009-04-23 12:34:36
        Microsoft Windows XP Édition familiale Service Pack 3
        System drive C: has 16 GB (40%) free of 39 GB
        Total RAM: 3071 MB (80% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 12:34:48, on 23/04/2009
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\SYSTEM32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\ZoneLabs\vsmon.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
        c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
        C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
        C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
        C:\Program Files\Java\jre6\bin\jqs.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
        C:\WINDOWS\RTHDCPL.EXE
        C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe
        C:\Apps\Powercinema\PCMService.exe
        C:\apps\ABoard\ABoard.exe
        C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
        C:\Program Files\Winamp\winampa.exe
        C:\WINDOWS\system32\RUNDLL32.EXE
        C:\Program Files\Java\jre6\bin\jusched.exe
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\Program Files\DAEMON Tools Lite\daemon.exe
        c:\APPS\Powercinema\Kernel\TV\CLSched.exe
        C:\Program Files\Messenger\msmsgs.exe
        C:\apps\ABoard\AOSD.exe
        D:\documents and settings\romain\local settings\application data\mkkie.exe
        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\WINDOWS\system32\wbem\wmiapsrv.exe
        C:\WINDOWS\System32\svchost.exe
        D:\Documents and Settings\romain\Bureau\RSIT.exe
        C:\Program Files\Trend Micro\HijackThis\romain.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://format.packardbell.com/cgi-bin/redirect/?country=FR&range=AD&phase=6&key=SEARCH
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\fr.htm
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
        O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
        O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
        O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
        O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
        O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
        O4 - HKLM\..\Run: [Vade Retro Outlook Express] "C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe"
        O4 - HKLM\..\Run: [BootWarn] C:\Program Files\Norton Internet Security\Norton AntiVirus\BootWarn.exe /a
        O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
        O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
        O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
        O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
        O4 - HKCU\..\Run: [mkkie] "d:\documents and settings\romain\local settings\application data\mkkie.exe" mkkie
        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
        O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
        O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
        O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
        O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
        O23 - Service: MysqlInventime - Unknown owner - C:\Apps\INVENT~1\mysql\bin\mysqld-nt.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
        O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
        0
        1. Contributeur sécurité
          Bonjour,
          Tu as un infection Navipromo ,

          Fais ceci S.T.P:

          Télécharge Navilog1

          Ensuite double clique sur navilog1.exe pour lancer l'installation.
          Une fois l'installation terminée, le fix s'exécutera automatiquement.
          (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

          Laisse-toi guider. Au menu principal, choisis 1 et valides.
          (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

          Patiente jusqu'au message :
          *** Analyse Termine le ..... ***
          Appuie sur une touche comme demandé, le bloc notes va s'ouvrir.
          Copie-colle l'intégralité dans une réponse. Referme le bloc notes.
          Note:
          Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)
          0
          1. voici le fichier bloc note:
            Search Navipromo version 3.7.6 commencé le 25/04/2009 à 13:16:59,12

            !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
            !!! Postez ce rapport sur le forum pour le faire analyser !!!
            !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

            Outil exécuté depuis C:\Program Files\navilog1

            Mise à jour le 14.03.2009 à 18h00 par IL-MAFIOSO

            Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
            X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) 4 CPU 3.00GHz )
            BIOS : Award Medallion BIOS v6.00PG
            USER : romain ( Administrator )
            BOOT : Normal boot

            Antivirus : avast! antivirus 4.8.1335 [VPS 090425-0] 4.8.1335 (Activated)
            Firewall : ZoneAlarm Firewall 7.0.483.000 (Activated)

            A:\ (USB)
            C:\ (Local Disk) - NTFS - Total:37 Go (Free:15 Go)
            D:\ (Local Disk) - NTFS - Total:195 Go (Free:100 Go)
            E:\ (CD or DVD)
            F:\ (CD or DVD)
            H:\ (USB)
            I:\ (USB)
            J:\ (USB)
            K:\ (CD or DVD)
            L:\ (USB)

            Recherche executé en mode normal

            *** Recherche dossiers dans "C:\WINDOWS" ***

            *** Recherche dossiers dans "C:\Program Files" ***

            *** Recherche dossiers dans "D:\Documents and Settings\All Users\menudm~1\progra~1" ***

            *** Recherche dossiers dans "D:\Documents and Settings\All Users\menudm~1" ***

            *** Recherche dossiers dans "d:\docume~1\alluse~1\applic~1" ***

            *** Recherche dossiers dans "D:\Documents and Settings\romain\applic~1" ***

            *** Recherche dossiers dans "D:\Documents and Settings\romain\locals~1\applic~1" ***

            *** Recherche dossiers dans "D:\Documents and Settings\romain\menudm~1\progra~1" ***

            *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
            pour + d'infos : http://www.gmer.net

            *** Recherche avec GenericNaviSearch ***
            !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
            !!! A vérifier impérativement avant toute suppression manuelle !!!

            * Recherche dans "C:\WINDOWS\system32" *

            * Recherche dans "D:\Documents and Settings\romain\locals~1\applic~1" *

            *** Recherche fichiers ***

            *** Recherche clés spécifiques dans le Registre ***
            !! Les clés trouvées ne sont pas forcément infectées !!

            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "mmeuqsk"="\"d:\\documents and settings\\romain\\local settings\\application data\\mmeuqsk.exe\" mmeuqsk"

            *** Module de Recherche complémentaire ***
            (Recherche fichiers spécifiques)

            1)Recherche nouveaux fichiers Instant Access :

            2)Recherche Heuristique :

            * Dans "C:\WINDOWS\system32" :

            * Dans "D:\Documents and Settings\romain\locals~1\applic~1" :

            mmeuqsk.exe trouvé !
            mmeuqsk.dat trouvé !
            mmeuqsk_nav.dat trouvé !
            mmeuqsk_navps.dat trouvé !

            3)Recherche Certificats :

            Certificat Egroup absent !
            Certificat Electronic-Group absent !
            Certificat Montorgueil absent !
            Certificat OOO-Favorit absent !
            Certificat Sunny-Day-Design-Ltd absent !

            4)Recherche autres dossiers et fichiers connus :

            *** Analyse terminée le 25/04/2009 à 13:20:01,81 ***
            0
            1. Contributeur sécurité
              OK

              Le Nettoyage:

              Double-clique sur le raccourci Navilog1 présent sur le bureau

              Tape 2 puis valide

              Patiente jusqu'au message :
              *** Analyse Termine le ..... ***

              Appuie sur une touche comme demandé, le bloc notes va s'ouvrir.

              Copie-colle l'intégralité dans une réponse. Referme le bloc notes.
              0
              1. voila

                je transmets le bloc note:
                Clean Navipromo version 3.7.6 commencé le 27/04/2009 à 10:32:01,32

                Outil exécuté depuis C:\Program Files\navilog1

                Mise à jour le 14.03.2009 à 18h00 par IL-MAFIOSO

                Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
                X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) 4 CPU 3.00GHz )
                BIOS : Award Medallion BIOS v6.00PG
                USER : romain ( Administrator )
                BOOT : Normal boot

                Antivirus : avast! antivirus 4.8.1335 [VPS 090426-0] 4.8.1335 (Activated)
                Firewall : ZoneAlarm Firewall 7.0.483.000 (Activated)

                A:\ (USB)
                C:\ (Local Disk) - NTFS - Total:37 Go (Free:15 Go)
                D:\ (Local Disk) - NTFS - Total:195 Go (Free:98 Go)
                E:\ (CD or DVD)
                F:\ (CD or DVD)
                H:\ (USB)
                I:\ (USB)
                J:\ (USB)
                K:\ (CD or DVD)
                L:\ (USB)

                Mode suppression automatique
                avec prise en charge résultats Catchme et GNS

                Nettoyage exécuté au redémarrage de l'ordinateur

                *** fsbl1.txt non trouvé ***
                (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)

                *** Suppression avec sauvegardes résultats GenericNaviSearch ***

                * Suppression dans "C:\WINDOWS\System32" *

                * Suppression dans "D:\Documents and Settings\romain\locals~1\applic~1" *

                *** Suppression dossiers dans "C:\WINDOWS" ***

                *** Suppression dossiers dans "C:\Program Files" ***

                *** Suppression dossiers dans "D:\Documents and Settings\All Users\menudm~1\progra~1" ***

                *** Suppression dossiers dans "D:\Documents and Settings\All Users\menudm~1" ***

                *** Suppression dossiers dans "d:\docume~1\alluse~1\applic~1" ***

                *** Suppression dossiers dans "D:\Documents and Settings\romain\applic~1" ***

                *** Suppression dossiers dans "D:\Documents and Settings\romain\locals~1\applic~1" ***

                *** Suppression dossiers dans "D:\Documents and Settings\romain\menudm~1\progra~1" ***

                *** Suppression fichiers ***

                *** Suppression fichiers temporaires ***

                Nettoyage contenu C:\WINDOWS\Temp effectué !
                Nettoyage contenu D:\Documents and Settings\romain\locals~1\Temp effectué !

                *** Traitement Recherche complémentaire ***
                (Recherche fichiers spécifiques)

                1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

                2)Recherche, création sauvegardes et suppression Heuristique :

                * Dans "C:\WINDOWS\system32" *

                C:\WINDOWS\prefetch\mmeuqsk*.pf trouvé !
                Copie C:\WINDOWS\prefetch\mmeuqsk*.pf réalisée avec succès !
                C:\WINDOWS\prefetch\mmeuqsk*.pf supprimé !

                * Dans "D:\Documents and Settings\romain\locals~1\applic~1" *

                mmeuqsk.exe trouvé !
                Copie mmeuqsk.exe réalisée avec succès !
                mmeuqsk.exe supprimé !

                mmeuqsk.dat trouvé !
                Copie mmeuqsk.dat réalisée avec succès !
                mmeuqsk.dat supprimé !

                mmeuqsk_nav.dat trouvé !
                Copie mmeuqsk_nav.dat réalisée avec succès !
                mmeuqsk_nav.dat supprimé !

                mmeuqsk_navps.dat trouvé !
                Copie mmeuqsk_navps.dat réalisée avec succès !
                mmeuqsk_navps.dat supprimé !

                *** Sauvegarde du Registre vers dossier Safebackup ***

                sauvegarde du Registre réalisée avec succès !

                *** Nettoyage Registre ***

                Nettoyage Registre Ok

                *** Certificats ***

                Certificat Egroup absent !
                Certificat Electronic-Group absent !
                Certificat Montorgueil absent !
                Certificat OOO-Favorit absent !
                Certificat Sunny-Day-Design-Ltdt absent !

                *** Recherche autres dossiers et fichiers connus ***

                *** Nettoyage terminé le 27/04/2009 à 10:36:14,46 ***
                0
              2. Contributeur sécurité
                @loupiSuper,

                Maintenant Fais ceci:

                Télécharges UsbFix

                --> Lance l'installation avec les paramètres par défaut

                Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d avoir été infectés sans les ouvrir

                --> Double clic sur le raccourci UsbFix sur ton bureau

                --> choisis "1" puis valide

                --> Le PC va redémarrer

                -->Apres redémarrage post le rapport UsbFix.txt

                Note : le rapport UsbFix.txt est sauvegardé a la racine du disque

                Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides


                Et s.t.p poste un log RSIT

                @+
                0