Problème c/windows/system32/r_server.exe

Résolu
Bonjour,

j'ai un souci avec mon ordi, il est super lent et souvent l'internet explorer se bloque au lancement, j'ai donc voulu voir si il n'y avait pas de saleté et en faisant une analyse complète avec AVG il trouve que c\windows\system32\r_server.exe est "potentiellement malveillant" je ne sais pas si je dois les supprimer ou pas j'ai un peu peur de faire des bêtises.

Merci pour la bonne ame qui me répondra
Configuration: Windows XP
Internet Explorer 6.0

17 réponses

Résumé de la discussion

Un utilisateur signale qu'un ordinateur est extrêmement lent et qu'Internet Explorer bloque au démarrage, et qu’un scan AVG signale le fichier C:\Windows\System32\r_server.exe comme potentiellement malveillant. Plusieurs réponses proposent des outils spécialisés pour nettoyer l'infection, comme ComboFix, UsbFix et RSIT, avec des procédures détaillées et des transferts de supports USB pour lancer les analyses depuis un autre ordinateur. En parallèle, des conseils soulignent de ne pas supprimer directement r_server.exe et d'utiliser des scans et rapports pour déterminer l’infection, puis de redémarrer et de partager les rapports de nettoyage. D'autres éléments évoquent l'exécution de ces outils à partir d'une clé USB ou d'un PC sain, et le besoin d'examiner les journaux et listes de programmes pour évaluer l'étendue de l'infection.

Bobot (l’IA à votre service)


  1. il resiste ;)

    telecharge combofix : http://download.bleepingcomputer.com/sUBs/ComboFix.exe sur ton bureau

    Copie le texte ci-dessous :

    Driver::
    r_server

    File::
    R:\autorun.old.inf
    C:\WINDOWS\system32\ADMDLL.dll
    C:\WINDOWS\system32\r_server.exe


    Ouvre le Bloc-Notes puis colle le texte copié.
    (Démarrer\Tous les programmes\Accessoires\Bloc notes.)
    Sauvegarde ce fichier sous le nom de CFScript.txt

    Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ceci :

    Cela va lancer Combofix,

    Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

    Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

    Ne touche à rien tant que le scan n'est pas terminé.

    Après redémarrage, poste le contenu du rapport Combofix.txt

    S'il n'y a pas de rédémarrage, poste quand même le rapport
    2
    1. voici le rapport :

      ComboFix 09-04-22.A23 - STM 22/04/2009 18:05.1 - NTFSx86
      Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.639.312 [GMT 2:00]
      Lancé depuis: c:\documents and settings\STM\Bureau\ComboFix.exe
      Commutateurs utilisés :: c:\documents and settings\STM\Mes documents\CFScript.txt
      * Un nouveau point de restauration a été créé
      * Resident AV is active

      AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!

      FILE ::
      c:\windows\system32\ADMDLL.dll
      c:\windows\system32\r_server.exe
      R:\autorun.old.inf
      .

      (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
      .

      c:\documents and settings\STM\Application Data\Microsoft\SystemCertificates\Request
      c:\windows\system32\ADMDLL.dll
      c:\windows\system32\r_server.exe

      .
      ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
      .

      -------\Legacy_R_SERVER
      -------\Service_r_server

      ((((((((((((((((((((((((((((( Fichiers créés du 2009-03-22 au 2009-04-22 ))))))))))))))))))))))))))))))))))))
      .

      2009-04-22 16:05 . 2009-04-22 16:05 -------- d-----w C:\quarantine
      2009-04-22 15:29 . 2009-04-22 15:29 -------- d-sha-r C:\autorun.inf
      2009-04-22 15:22 . 2009-04-22 15:29 -------- d-----w C:\UsbFix
      2009-04-22 14:51 . 2009-04-22 14:51 -------- d-----w C:\rsit
      2009-04-16 08:46 . 2009-02-06 10:10 227840 ------w c:\windows\system32\dllcache\wmiprvse.exe
      2009-04-16 08:46 . 2009-03-06 14:20 286720 ------w c:\windows\system32\dllcache\pdh.dll
      2009-04-16 08:46 . 2009-02-09 11:23 111104 ------w c:\windows\system32\dllcache\services.exe
      2009-04-16 08:46 . 2009-02-09 10:53 401408 ------w c:\windows\system32\dllcache\rpcss.dll
      2009-04-16 08:46 . 2009-02-09 10:53 473600 ------w c:\windows\system32\dllcache\fastprox.dll
      2009-04-16 08:46 . 2009-02-09 10:53 685568 ------w c:\windows\system32\dllcache\advapi32.dll
      2009-04-16 08:46 . 2009-02-09 10:53 735744 ------w c:\windows\system32\dllcache\lsasrv.dll
      2009-04-16 08:46 . 2009-02-09 10:53 453120 ------w c:\windows\system32\dllcache\wmiprvsd.dll
      2009-04-16 08:46 . 2009-02-09 10:53 739840 ------w c:\windows\system32\dllcache\ntdll.dll
      2009-04-16 08:45 . 2008-12-16 12:31 354304 ------w c:\windows\system32\dllcache\winhttp.dll
      2009-04-16 08:45 . 2009-03-27 06:54 1203922 ------w c:\windows\system32\dllcache\sysmain.sdb
      2009-04-16 08:45 . 2008-04-21 21:15 219136 ------w c:\windows\system32\dllcache\wordpad.exe

      .
      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2009-04-22 16:12 . 2005-09-02 08:20 984548 ----a-w C:\ptdebug.txt
      2009-04-22 15:29 . 2009-04-22 15:26 4315 ----a-w C:\UsbFix.txt
      2009-04-22 11:40 . 2009-04-22 11:40 -------- d-----w c:\program files\AVG
      2009-04-22 08:56 . 2009-04-22 08:56 -------- d-----w c:\program files\CCleaner
      2009-04-22 08:45 . 2007-12-12 13:47 -------- d-----w c:\program files\Spybot - Search & Destroy
      2009-04-22 08:43 . 2007-12-12 13:47 -------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
      2009-04-17 07:10 . 2001-09-14 19:39 68738 ----a-w c:\windows\system32\perfc00C.dat
      2009-04-17 07:10 . 2001-09-14 19:39 452130 ----a-w c:\windows\system32\perfh00C.dat
      2009-04-01 11:51 . 2008-12-16 09:13 -------- d-----w c:\documents and settings\STM\Application Data\TlrPack
      2009-03-21 14:07 . 2009-03-21 14:07 1054720 ------w c:\windows\system32\dllcache\kernel32.dll
      2009-03-06 14:20 . 2001-09-14 19:38 286720 ----a-w c:\windows\system32\pdh.dll
      2009-03-03 09:24 . 2001-09-15 02:58 89299 ----a-w c:\windows\PCHEALTH\HELPCTR\OfflineCache\index.dat
      2009-03-03 09:08 . 2001-09-14 19:39 252240 --sha-r C:\ntldr
      2009-03-03 00:13 . 2006-05-10 05:24 826368 ----a-w c:\windows\system32\dllcache\wininet.dll
      2009-03-03 00:13 . 2004-08-23 17:16 826368 ----a-w c:\windows\system32\wininet.dll
      2009-02-28 04:54 . 2006-10-17 11:04 636072 ------w c:\windows\system32\dllcache\iexplore.exe
      2009-02-20 10:20 . 2007-05-10 07:17 13824 ------w c:\windows\system32\dllcache\ieudinit.exe
      2009-02-20 10:20 . 2001-09-14 19:38 70656 ----a-w c:\windows\system32\dllcache\ie4uinit.exe
      2009-02-20 05:14 . 2001-09-14 19:38 161792 ----a-w c:\windows\system32\dllcache\ieakui.dll
      2009-02-10 17:06 . 2008-10-16 07:12 2068096 ------w c:\windows\system32\dllcache\ntkrnlpa.exe
      2009-02-10 17:06 . 2001-08-23 17:12 2068096 ----a-w c:\windows\system32\ntkrnlpa.exe
      2009-02-09 14:05 . 2008-10-16 07:12 1846912 ------w c:\windows\system32\dllcache\win32k.sys
      2009-02-09 14:05 . 2001-09-14 19:39 1846912 ----a-w c:\windows\system32\win32k.sys
      2009-02-09 11:24 . 2008-10-16 07:12 2191104 ------w c:\windows\system32\dllcache\ntoskrnl.exe
      2009-02-09 11:24 . 2001-09-14 19:38 2191104 ----a-w c:\windows\system32\ntoskrnl.exe
      2009-02-09 11:23 . 2008-10-16 07:12 2025984 ------w c:\windows\system32\dllcache\ntkrpamp.exe
      2009-02-09 11:23 . 2008-10-16 07:12 2147328 ------w c:\windows\system32\dllcache\ntkrnlmp.exe
      2009-02-09 11:23 . 2001-09-14 19:38 111104 ----a-w c:\windows\system32\services.exe
      2009-02-09 10:53 . 2001-09-14 19:38 735744 ----a-w c:\windows\system32\lsasrv.dll
      2009-02-09 10:53 . 2004-11-17 09:37 401408 ----a-w c:\windows\system32\rpcss.dll
      2009-02-09 10:53 . 2001-09-14 19:38 739840 ----a-w c:\windows\system32\ntdll.dll
      2009-02-09 10:53 . 2001-09-14 19:37 685568 ----a-w c:\windows\system32\advapi32.dll
      2009-02-06 10:39 . 2001-09-14 19:38 35328 ----a-w c:\windows\system32\sc.exe
      2009-02-06 10:39 . 2001-09-14 19:38 35328 ----a-w c:\windows\system32\dllcache\sc.exe
      2009-02-03 19:58 . 2009-02-03 19:58 56832 ------w c:\windows\system32\dllcache\secur32.dll
      2009-02-03 19:58 . 2001-09-14 19:38 56832 ----a-w c:\windows\system32\secur32.dll
      2005-08-11 14:22 . 2002-11-13 10:08 62024 -c--a-w c:\documents and settings\STM\Application Data\GDIPFONTCACHEV1.DAT
      2004-11-23 09:49 . 2002-10-14 15:40 62024 -c--a-w c:\documents and settings\STM\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
      2003-10-09 14:40 . 2003-10-09 14:40 30208 -csha-w c:\program files\Thumbs.db
      2002-07-03 23:58 . 2002-07-19 00:11 3296 -c--a-w c:\documents and settings\STM\oem.reg
      2002-07-03 23:58 . 2002-07-19 00:10 3296 -c--a-w c:\windows\system32\config\systemprofile\oem.reg
      2002-07-03 23:58 . 2002-07-19 00:10 3296 -c--a-w c:\documents and settings\Default User\oem.reg
      2002-07-03 23:58 . 2002-07-03 23:58 3296 -c--a-w c:\documents and settings\Administrateur\oem.reg
      .

      ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
      REGEDIT4

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
      "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-29 68856]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "HPDJ Taskbar Utility"="c:\windows\System32\spool\drivers\w32x86\3\hpztsb02.exe" [2001-04-17 192512]
      "ShStatEXE"="c:\program files\Network Associates\VirusScan\SHSTAT.EXE" [2004-09-22 94208]
      "McAfeeUpdaterUI"="c:\program files\Network Associates\Common Framework\UpdaterUI.exe" [2004-08-06 139320]
      "Network Associates Error Reporting Service"="c:\program files\Fichiers communs\Network Associates\TalkBack\TBMon.exe" [2004-02-19 147514]
      "McAfeeFireTray"="c:\program files\Network Associates\McAfee Desktop Firewall pour Windows XP\Firetray.exe" [2005-04-20 655420]
      "SSBkgdUpdate"="c:\program files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
      "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-09-19 282624]
      "AtiPTA"="atiptaxx.exe" - c:\windows\system32\atiptaxx.exe [2001-10-15 270336]

      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
      "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

      c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
      Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]

      [HKEY_LOCAL_MACHINE\software\microsoft\security center]
      "AntiVirusOverride"=dword:00000001

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "%windir%\\system32\\sessmgr.exe"=
      "c:\\Program Files\\Jeux classiques\\Bin\\CmCenterV2.exe"=
      "c:\\Program Files\\Messenger\\msmsgs.exe"=
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
      "c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
      "c:\\Program Files\\MSN Messenger\\livecall.exe"=

      R2 AVWUpSrv;AntiVir Update; [x]
      R3 ati2mpaa;ati2mpaa;c:\windows\system32\DRIVERS\ati2mpaa.sys [2001-08-23 281984]
      S1 NaiAvTdi1;NaiAvTdi1;c:\windows\system32\drivers\mvstdi5x.sys [2004-09-22 58048]

      .
      .
      ------- Examen supplémentaire -------
      .
      uInternet Connection Wizard,ShellNext = iexplore
      IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
      Trusted Zone: cnamts.fr\www.dsij.ext
      Trusted Zone: creditmutuel.fr\www
      Trusted Zone: FACTOCIC.FR
      Trusted Zone: masternaut.com\www
      Trusted Zone: net-entreprises.fr\www
      Trusted Zone: urssaf.fr\www
      TCP: {4F6C503F-B664-4CE8-BA13-6F581682D32B} = 80.10.246.2,80.10.246.129
      DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
      .

      **************************************************************************

      catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2009-04-22 18:11
      Windows 5.1.2600 Service Pack 3 NTFS

      Recherche de processus cachés ...

      Recherche d'éléments en démarrage automatique cachés ...

      Recherche de fichiers cachés ...

      Scan terminé avec succès
      Fichiers cachés: 0

      **************************************************************************
      .
      --------------------- DLLs chargées dans les processus actifs ---------------------

      - - - - - - - > 'explorer.exe'(3940)
      c:\windows\system32\eappprxy.dll
      .
      ------------------------ Autres processus actifs ------------------------
      .
      c:\program files\Network Associates\McAfee Desktop Firewall pour Windows XP\FireSvc.exe
      c:\program files\Network Associates\Common Framework\FrameworkService.exe
      c:\program files\Network Associates\VirusScan\Mcshield.exe
      c:\program files\Network Associates\VirusScan\VsTskMgr.exe
      c:\progra~1\NETWOR~1\COMMON~1\naPrdMgr.exe
      .
      **************************************************************************
      .
      Heure de fin: 2009-04-22 18:14 - La machine a redémarré
      ComboFix-quarantined-files.txt 2009-04-22 16:14

      Avant-CF: 1 530 224 640 octets libres
      Après-CF: 1 475 080 192 octets libres

      164 --- E O F --- 2009-04-16 15:37
      0
    2. @beaaje vais devoir quitter, je serai là demain matin j'espère que vous pourrez continuer à m'aider.....merci en tout cas
      0
  2. telecharge Rsit sur une clé usb puis transfert le sur l autre pc , ensuite scan et transfert le rapport log.txt sur ta clé usb et communique le nous
    1
    1. Re , on va deja supprimer l infection :

      Telecharge UsbFix et transfert le sur ta clé usb ensuite instal le sur le pc malade :

      Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d avoir été infectés sans les ouvrir

      # Double clic sur le raccourci UsbFix présent sur ton bureau

      # choisis l option 2 ( Suppression )

      # Ton bureau disparaitra et le pc redémarrera .

      # Au redémarrage , UsbFix scannera ton pc , laisse travailler l outil.

      # Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .

      # Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

      ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

      1
      1. voici la rapport :

        ############################## [ UsbFix V3.010 ]

        # User : STM (Administrateurs) # BRAVO
        # Update on 19/04/09 by C_XX & Chiquitine29
        # Start at: 17:26:31 | 22/04/2009
        # Website : http://pagesperso-orange.fr/FindyKill.Ad.Remover/

        # Intel(R) Pentium(R) 4 CPU 1.80GHz
        # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
        # Internet Explorer 7.0.5730.11
        # Windows Firewall Status : Enabled

        # A:\ # Lecteur de disquettes 3 ½ pouces
        # C:\ # Disque fixe local # 9,77 Go (1,5 Go free) [SYSTEM] # NTFS
        # D:\ # Disque fixe local # 27,5 Go (27,49 Go free) [Data] # NTFS
        # E:\ # Disque amovible
        # F:\ # Disque CD-ROM
        # R:\ # Connexion réseau # 56,73 Go (55,58 Go free) [Data] # NTFS
        # Z:\ # Connexion réseau # 37,26 Go (27,48 Go free) # NTFS

        ############################## [ Processus actifs ]

        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\csrss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Network Associates\McAfee Desktop Firewall pour Windows XP\FireSvc.exe
        C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
        C:\Program Files\Network Associates\VirusScan\Mcshield.exe
        C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
        C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe
        C:\WINDOWS\System32\r_server.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\wbem\wmiprvse.exe
        C:\WINDOWS\System32\alg.exe

        ################## [ Fichiers # Dossiers infectieux ]

        (!) Not Deleted ! C:\WINDOWS\system32\ADMDLL.dll
        (!) Not Deleted ! C:\WINDOWS\system32\r_server.exe
        Deleted ! R:\autorun.inf

        ################## [ Registre # Clés Run infectieuses ]

        # -> Not Found !

        ################## [ Registre # Startup ]

        HKCU_Main: "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
        HKCU_Main: "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
        HKCU_Main: "Window Title"=""
        HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
        HKLM_logon: "DefaultUserName"=""
        HKLM_logon: "AltDefaultUserName"="STM"
        HKLM_logon: "LegalNoticeCaption"=""
        HKLM_logon: "LegalNoticeText"=""
        HKLM_Run: AtiPTA=atiptaxx.exe
        HKLM_Run: HPDJ Taskbar Utility=C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb02.exe
        HKLM_Run: ShStatEXE="C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
        HKLM_Run: McAfeeUpdaterUI="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
        HKLM_Run: Network Associates Error Reporting Service="C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe"
        HKLM_Run: McAfeeFireTray=C:\Program Files\Network Associates\McAfee Desktop Firewall pour Windows XP\Firetray.exe
        HKLM_Run: SSBkgdUpdate="C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
        HKLM_Run: QuickTime Task="C:\Program Files\QuickTime\qttask.exe" -atboottime
        HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
        HKCU_Run: ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe
        HKCU_Run: swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

        ################## [ Registre # Mountpoints2 ]

        Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{20abad07-da15-11dc-9ad1-0004232342f2}\Shell\AutoRun\command
        Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{20abad07-da15-11dc-9ad1-0004232342f2}\Shell\explore\Command
        Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{20abad07-da15-11dc-9ad1-0004232342f2}\Shell\open\Command

        ################## [ Listing des fichiers présent ]

        C:\AUTOEXEC.BAT
        C:\NTDETECT.COM
        C:\boot.ini
        R:\autorun.old.inf
        Z:\ntdetect.com
        Z:\boot.ini

        ################## [ Vaccination ]

        # C:\autorun.inf -> Folder created by UsbFix.
        # D:\autorun.inf -> Folder created by UsbFix.

        ################## [ ! Fin du rapport # UsbFix V3.010 ! ]
        0
    2. Contributeur sécurité
      slt analyse ce fichier sur virus total et mets nous le rapport: https://www.virustotal.com/gui/

      c\windows\system32\r_server.exe

      puis

      Télécharge ici :

      http://images.malwareremoval.com/random/RSIT.exe

      random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

      Double-clique sur RSIT.exe afin de lancer RSIT.

      Clique Continue à l'écran Disclaimer.

      Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

      Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

      Poste le contenu de log.txt (<<qui sera affiché)
      ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

      NB : Les rapports sont sauvegardés dans le dossier C:\rsit
      0
      1. alors pour l'instant AVG continu toujours sont analyse et ça depuis 1h, c'est surement pas fini...
        Je précise que je suis sous réseau (donc 3 postes) je ne sais pas si ça a beaucoup d'importance mais je préfère préciser car je ne voudrait pas mettre le bazarre dans tous les ordis
        0
    3. Contributeur sécurité
      ok tu collera pour ce pc le rapport avg puis tu mettra ce qui à été demandé au dessus . À plus
      0
      1. pfeeeuuu, j'suis pas douée surement j'arrive déjà pas à analyser les fichiers avec totalvirus il ne me met aucun rapport et d'ailleurs j'ai l'impression qu'il ne fait rien, pourrais tu m'en dire plus......merci
        0
    4. Salut jlpjlp & Beaa

      Pour suivre merci .
      0
      1. je crois que je me lance dans une belle galère.....
        Je redemarre mon pc car l'internet explorer à planté, il ne veut plus ouvrir aucun site ???
        J'ai quand meme essayé de scanner le fichier : c/windows/system32/r_server.exe , ainsi qu'un autre qu'AVG a trouvé c'est aussi system32, mais /admdll.dll, mais sans résultat car l'envoi du fichier est interminable........je poste quand j'ai du mieux....
        0
    5. RE Beaa , a ton retour fais ceci stp :

      Télécharge random's system information tool (RSIT) et sauvegarde-le sur le Bureau.

      Double-clique sur RSIT.exe afin de lancer RSIT.

      Lis le contenu de l'écran Disclaimer puis clique sur Continue (si tu acceptes les conditions).

      Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

      Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

      Poste le contenu de log.txt
      0
      1. Contributeur sécurité
        Slt chiquitine29 ! Mets nous le rapport avg et le rapport rsit demandé pour voir
        0
        1. alors voilà, heureusement que j'ai un autre pc pour vous parler car l'autre (celui qui merde) ne veut plus se connecter à internet .... je vais donc avoir beaucoup de mal à suivre vos indications !!!! comment faire ????
          De plus je n'est pas le rapport d'AVG non plus car j'ai arrêté le scan avant la fin et puis pour continuer dans le délire, j'ai viré AVG complètement du pc en me disant que tout ce que j'avais installé ce matin en vu de nettoyer mon pc, et ben c'est pire encore !!!
          En fait c'est Mc afee qui est a l'origine sur mon ordi, mais visiblement il ne fonctionne pas trés bien car il ne m'a jamais indiqué de virus ou autre......
          merci pour votre aide, comment faire maintenant ???
          0
      2. voici les rapports :

        info.txt logfile of random's system information tool 1.06 2009-04-22 16:51:41

        ======Uninstall list======

        -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
        -->MsiExec.exe /I{8A42F680-2DD6-11D4-9A8C-0040F6982C20}
        -->MsiExec.exe /I{A2529672-574A-4A99-86A5-C1770A0E31FE}
        -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
        Ad-Aware SE Personal-->C:\PROGRA~1\Lavasoft\AD-AWA~1\UNWISE.EXE C:\PROGRA~1\Lavasoft\AD-AWA~1\INSTALL.LOG
        Adobe Download Manager 2.2 (Supprimer uniquement)-->"C:\Program Files\Fichiers communs\Adobe\ESD\uninst.exe"
        Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
        Adobe Reader 7.1.0 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A71000000002}
        Adventi COMPTA-->MsiExec.exe /I{C4FF9BF5-8E05-420C-A419-3D9608106EB5}
        Adventi GESTION-->MsiExec.exe /I{1E5A0333-6A8C-4AA0-AC31-80EFEDA94B3B}
        ATI Display Driver-->rundll32 C:\WINDOWS\System32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
        CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
        Ciel Paye pour Windows-->C:\WINDOWS\unin040c.exe -fC:\CIEL\WPAYE\DeIsL1.isu
        Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
        Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
        EPSON Logiciel imprimante-->C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
        Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
        Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_0531C63A913CC9D1.exe" /uninstall
        hp deskjet 990c series (Supprimer uniquement)-->C:\Program Files\hp deskjet 990c series\hpfiui.exe -c -vdivid=HPF -vpnum=95 -vinstport=LPT1: -vproduct=990c -huninstall
        Jeux Classiques-->MsiExec.exe /X{6107371A-6504-43D4-9B11-AB633B84F700}
        Macromedia Shockwave Player-->C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
        McAfee Desktop Firewall 8.5-->"C:\Program Files\Network Associates\McAfee Desktop Firewall pour Windows XP\McAfeefire.exe" addremove
        McAfee VirusScan Enterprise-->MsiExec.exe /I{4DCA2739-9D16-4B55-808C-E72CD70A5BD3}
        Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
        Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
        Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
        Microsoft Office XP Small Business-->MsiExec.exe /I{9113040C-6000-11D3-8CFE-0050048383C9}
        Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
        Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media 9 (KB911565)-->"C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media 9 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP9$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Step by Step Interactive Training (KB898458)-->"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB928090)-->"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB929969)-->"C:\WINDOWS\ie7updates\KB929969\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB931768)-->"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB933566)-->"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
        MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
        MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
        MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
        PaperPort-->MsiExec.exe /I{71C97545-E547-4A8B-B0C8-61FF853270AC}
        Remote Administrator Server v2.1-->C:\Program Files\Radmin\uninstal.exe
        SAMSUNG CDMA Modem Driver Set-->C:\WINDOWS\system32\Samsung_USB_Drivers\3\SSCDUninstall.exe
        Samsung Mobile phone USB driver Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\5\SSSDUninstall.exe
        SAMSUNG Mobile USB Modem 1.0 Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\1\SS_Uninstall.exe
        SAMSUNG Mobile USB Modem Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
        Samsung PC Studio-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C4A4722E-79F9-417C-BD72-8D359A090C97}\setup.exe" -l0x40c -removeonly
        Windows Genuine Advantage v1.3.0254.0-->MsiExec.exe /I{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}
        Windows Live Messenger-->MsiExec.exe /I{F6326B60-1B1D-4ABF-BFCD-7B7404F44411}
        Windows Live Sign-in Assistant-->MsiExec.exe /I{49672EC2-171B-47B4-8CE7-50D7806360D7}
        Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"

        ======System event log======

        Computer Name: BRAVO
        Event Code: 7035
        Message: Un contrôle Démarrer a correctement été envoyé au service NLA (Network Location Awareness).

        Record Number: 13014
        Source Name: Service Control Manager
        Time Written: 20090130090929.000000+060
        Event Type: Informations
        User: AUTORITE NT\SYSTEM

        Computer Name: BRAVO
        Event Code: 7035
        Message: Un contrôle Démarrer a correctement été envoyé au service Gestionnaire de connexions d'accès distant.

        Record Number: 13013
        Source Name: Service Control Manager
        Time Written: 20090130090929.000000+060
        Event Type: Informations
        User: AUTORITE NT\SYSTEM

        Computer Name: BRAVO
        Event Code: 7036
        Message: Le service Téléphonie est entré dans l'état : en cours d'exécution.

        Record Number: 13012
        Source Name: Service Control Manager
        Time Written: 20090130090929.000000+060
        Event Type: Informations
        User:

        Computer Name: BRAVO
        Event Code: 7036
        Message: Le service Compatibilité avec le Changement rapide d'utilisateur est entré dans l'état : en cours d'exécution.

        Record Number: 13011
        Source Name: Service Control Manager
        Time Written: 20090130090929.000000+060
        Event Type: Informations
        User:

        Computer Name: BRAVO
        Event Code: 7035
        Message: Un contrôle Démarrer a correctement été envoyé au service Compatibilité avec le Changement rapide d'utilisateur.

        Record Number: 13010
        Source Name: Service Control Manager
        Time Written: 20090130090929.000000+060
        Event Type: Informations
        User: AUTORITE NT\SYSTEM

        =====Application event log=====

        Computer Name: BRAVO
        Event Code: 5000
        Message: VirusScan Enterprise Le service McShield a démarré - Recherche de 334987 virus en cours.

        Version de moteur : 5.2.00

        Version de .DAT : 5148

        Nom d'EXTRA.DAT : Aucun

        Nombre de signatures de virus dans EXTRA.DAT : Aucun

        Noms des virus détectés par EXTRA.DAT : Aucun

        Record Number: 8947
        Source Name: McLogEvent
        Time Written: 20071025090950.000000+120
        Event Type: Informations
        User: AUTORITE NT\SYSTEM

        Computer Name: BRAVO
        Event Code: 1800
        Message: Le service Centre de sécurité Windows a démarré.

        Record Number: 8946
        Source Name: SecurityCenter
        Time Written: 20071025090844.000000+120
        Event Type: Informations
        User:

        Computer Name: BRAVO
        Event Code: 5000
        Message: VirusScan Enterprise Le service McShield a démarré - Recherche de 334903 virus en cours.

        Version de moteur : 5.2.00

        Version de .DAT : 5147

        Nom d'EXTRA.DAT : Aucun

        Nombre de signatures de virus dans EXTRA.DAT : Aucun

        Noms des virus détectés par EXTRA.DAT : Aucun

        Record Number: 8945
        Source Name: McLogEvent
        Time Written: 20071025090842.000000+120
        Event Type: Informations
        User: AUTORITE NT\SYSTEM

        Computer Name: BRAVO
        Event Code: 11728
        Message: Product: MSXML 4.0 SP2 (KB936181) -- Configuration completed successfully.

        Record Number: 8944
        Source Name: MsiInstaller
        Time Written: 20071024182434.000000+120
        Event Type: Informations
        User: AUTORITE NT\SYSTEM

        Computer Name: BRAVO
        Event Code: 1517
        Message: Windows a sauvegardé le Registre utilisateur BRAVO\STM alors qu'une application ou un service utilisait toujours le Registre pendant la fermeture de la session. La mémoire utilisée par le Registre de l'utilisateur n'a pas été libérée. le Registre sera déchargé lorsqu'il ne sera plus utilisé.

        Cela est souvent causé par des services s'exécutant en tant que compte d'utilisateur, essayez de configurer les services pour s'exécuter dans le compte service réseau ou service local.

        Record Number: 8943
        Source Name: Userenv
        Time Written: 20071024182412.000000+120
        Event Type: Avertissement
        User: AUTORITE NT\SYSTEM

        ======Environment variables======

        "ComSpec"=%SystemRoot%\system32\cmd.exe
        "Path"=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Objcomsr;C:\Program Files\Samsung\Samsung PC Studio 3\
        "windir"=%SystemRoot%
        "OS"=Windows_NT
        "PROCESSOR_ARCHITECTURE"=x86
        "PROCESSOR_LEVEL"=15
        "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 1 Stepping 2, GenuineIntel
        "PROCESSOR_REVISION"=0102
        "NUMBER_OF_PROCESSORS"=1
        "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
        "TEMP"=%SystemRoot%\TEMP
        "TMP"=%SystemRoot%\TEMP
        "HP_TEMP"=D:
        "Uraloc"=C:
        "Urafic"=G:
        "Urapgm"=G:
        "FP_NO_HOST_CHECK"=NO

        -----------------EOF-----------------

        PUIS LE SECOND

        Logfile of random's system information tool 1.06 (written by random/random)
        Run by STM at 2009-04-22 16:51:32
        Microsoft Windows XP Professionnel Service Pack 3
        System drive C: has 2 GB (15%) free of 10 GB
        Total RAM: 639 MB (44% free)

        HijackThis download failed

        ======Registry dump======

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
        Adobe PDF Reader Link Helper - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-12-18 59032]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
        AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll []

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
        Windows Live Sign-in Helper - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2006-08-31 322368]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
        Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-01-15 251504]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
        Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll [2009-01-15 657904]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
        Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll [2009-01-15 522224]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
        {2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-01-15 251504]

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
        "AtiPTA"=C:\WINDOWS\system32\atiptaxx.exe [2001-10-15 270336]
        "HPDJ Taskbar Utility"=C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb02.exe [2001-04-17 192512]
        "ShStatEXE"=C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE [2004-09-22 94208]
        "McAfeeUpdaterUI"=C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe [2004-08-06 139320]
        "Network Associates Error Reporting Service"=C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe [2004-02-19 147514]
        "McAfeeFireTray"=C:\Program Files\Network Associates\McAfee Desktop Firewall pour Windows XP\Firetray.exe [2005-04-20 655420]
        "SSBkgdUpdate"=C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [2003-10-14 155648]
        "QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2006-09-19 282624]

        [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
        "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
        "swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2007-06-29 68856]

        C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
        Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
        C:\WINDOWS\system32\WgaLogon.dll [2008-09-06 267304]

        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
        "dontdisplaylastusername"=0
        "legalnoticecaption"=
        "legalnoticetext"=
        "shutdownwithoutlogon"=1
        "undockwithoutlogon"=1

        [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
        "NoDriveTypeAutoRun"=145

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
        "HonorAutoRunSetting"=

        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
        "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
        "C:\Program Files\Jeux classiques\Bin\CmCenterV2.exe"="C:\Program Files\Jeux classiques\Bin\CmCenterV2.exe:*:Disabled:CmCenter Module"
        "C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
        "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
        "C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
        "C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
        "C:\Program Files\Internet Explorer\iexplore.exe"="C:\Program Files\Internet Explorer\iexplore.exe:*:Disabled:Internet Explorer"

        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
        "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
        "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
        "C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
        "C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{20abad07-da15-11dc-9ad1-0004232342f2}]
        shell\AutoRun\command - 3wcxx91.cmd
        shell\explore\command - 3wcxx91.cmd
        shell\open\command - 3wcxx91.cmd

        ======List of files/folders created in the last 1 months======

        2009-04-22 16:51:32 ----D---- C:\rsit
        2009-04-22 15:34:35 ----A---- C:\WINDOWS\system32\ADMDLL.dll
        2009-04-22 15:33:46 ----A---- C:\WINDOWS\system32\r_server.exe
        2009-04-22 13:40:22 ----D---- C:\Program Files\AVG
        2009-04-22 10:56:02 ----D---- C:\Program Files\CCleaner
        2009-04-16 17:37:00 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
        2009-04-16 17:36:48 ----HDC---- C:\WINDOWS\$NtUninstallKB961373$
        2009-04-16 17:33:52 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
        2009-04-16 17:33:31 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
        2009-04-16 17:33:19 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
        2009-04-16 17:33:02 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$

        ======List of files/folders modified in the last 1 months======

        2009-04-22 16:51:38 ----A---- C:\ptdebug.txt
        2009-04-22 16:42:07 ----D---- C:\WINDOWS\Prefetch
        2009-04-22 16:41:22 ----HD---- C:\WINDOWS\inf
        2009-04-22 16:40:46 ----D---- C:\WINDOWS\system32\CatRoot2
        2009-04-22 16:26:16 ----D---- C:\WINDOWS\Temp
        2009-04-22 16:19:29 ----A---- C:\WINDOWS\SchedLgU.Txt
        2009-04-22 16:15:33 ----AD---- C:\WINDOWS\system32
        2009-04-22 16:14:19 ----D---- C:\WINDOWS\system32\drivers
        2009-04-22 16:14:19 ----AD---- C:\WINDOWS
        2009-04-22 13:40:22 ----RD---- C:\Program Files
        2009-04-22 13:40:10 ----SHD---- C:\WINDOWS\Installer
        2009-04-22 13:40:08 ----D---- C:\WINDOWS\WinSxS
        2009-04-22 11:10:03 ----D---- C:\WINDOWS\Debug
        2009-04-22 10:45:15 ----D---- C:\Program Files\Spybot - Search & Destroy
        2009-04-22 10:43:50 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
        2009-04-22 09:55:53 ----A---- C:\WINDOWS\WGescom.INI
        2009-04-21 11:20:14 ----A---- C:\WINDOWS\BRPP2KA.INI
        2009-04-17 18:40:33 ----A---- C:\WINDOWS\WD.INI
        2009-04-17 09:10:39 ----AC---- C:\WINDOWS\system32\PerfStringBackup.INI
        2009-04-17 09:05:59 ----D---- C:\WINDOWS\system32\wbem
        2009-04-17 09:05:58 ----D---- C:\WINDOWS\AppPatch
        2009-04-16 17:37:03 ----SHD---- C:\WINDOWS\system32\dllcache
        2009-04-16 17:36:24 ----D---- C:\WINDOWS\system32\fr-fr
        2009-04-16 17:36:24 ----D---- C:\Program Files\Internet Explorer
        2009-04-16 17:33:45 ----HD---- C:\WINDOWS\$hf_mig$
        2009-04-10 10:43:36 ----SD---- C:\WINDOWS\Tasks
        2009-04-09 11:46:28 ----D---- C:\wincpta
        2009-04-06 16:57:24 ----AC---- C:\WINDOWS\system32\MRT.exe
        2009-04-01 13:51:11 ----D---- C:\Documents and Settings\STM\Application Data\TlrPack

        ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

        R1 FireHook;McAfee Desktop Firewall; \??\C:\WINDOWS\system32\Drivers\Firehk5x.sys []
        R1 FireTDI;McAfee Desktop Firewall TDI Driver; \??\C:\WINDOWS\system32\Drivers\FireTDI.sys []
        R1 NaiAvTdi1;NaiAvTdi1; C:\WINDOWS\system32\drivers\mvstdi5x.sys [2004-09-22 58048]
        R1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2008-09-17 5632]
        R3 ac97intc;Service d'installation du pilote audio Intel(r) 82801 (WDM); C:\WINDOWS\system32\drivers\ac97intc.sys [2001-08-17 96256]
        R3 ati2mtaa;ati2mtaa; C:\WINDOWS\System32\DRIVERS\ati2mtaa.sys [2001-10-15 286592]
        R3 firelm01;firelm01; \??\C:\WINDOWS\system32\drivers\firelm01.sys []
        R3 NaiAvFilter1;NaiAvFilter1; C:\WINDOWS\system32\drivers\naiavf5x.sys [2004-09-22 108256]
        R3 usbhub;Concentrateur USB2; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
        R3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
        R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
        S1 P3;Pilote processeur Intel Pentium III; C:\WINDOWS\System32\DRIVERS\p3.sys [2008-04-14 46848]
        S3 ati2mpaa;ati2mpaa; C:\WINDOWS\System32\DRIVERS\ati2mpaa.sys [2001-08-24 281984]
        S3 E100B;Pilote de carte Intel (R) PRO; C:\WINDOWS\System32\DRIVERS\e100b325.sys [2001-08-23 117760]
        S3 i81x;i81x; C:\WINDOWS\System32\DRIVERS\i81xnt5.sys [2004-08-04 161020]
        S3 iAimFP0;iAimFP0; C:\WINDOWS\System32\DRIVERS\wADV01nt.sys [2004-08-04 12415]
        S3 iAimFP1;iAimFP1; C:\WINDOWS\System32\DRIVERS\wADV02NT.sys [2004-08-04 12127]
        S3 iAimFP2;iAimFP2; C:\WINDOWS\System32\DRIVERS\wADV05NT.sys [2004-08-04 11775]
        S3 iAimFP3;iAimFP3; C:\WINDOWS\System32\DRIVERS\wSiINTxx.sys [2004-08-04 12063]
        S3 iAimFP4;iAimFP4; C:\WINDOWS\System32\DRIVERS\wVchNTxx.sys [2004-08-04 19455]
        S3 iAimTV0;iAimTV0; C:\WINDOWS\System32\DRIVERS\wATV01nt.sys [2004-08-04 29311]
        S3 iAimTV1;iAimTV1; C:\WINDOWS\System32\DRIVERS\wATV02NT.sys [2004-08-04 19551]
        S3 iAimTV2;iAimTV2; C:\WINDOWS\System32\DRIVERS\wATV03nt.sys []
        S3 iAimTV3;iAimTV3; C:\WINDOWS\System32\DRIVERS\wATV04nt.sys [2004-08-04 33599]
        S3 iAimTV4;iAimTV4; C:\WINDOWS\System32\DRIVERS\wCh7xxNT.sys [2004-08-04 23615]
        S3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2001-08-28 5888]
        S3 ssm_bus;SAMSUNG Mobile USB Device II 1.0 driver (WDM); C:\WINDOWS\system32\DRIVERS\ssm_bus.sys [2005-08-30 58320]
        S3 ssm_mdfl;SAMSUNG Mobile USB Modem II 1.0 Filter; C:\WINDOWS\system32\DRIVERS\ssm_mdfl.sys [2005-08-30 8336]
        S3 ssm_mdm;SAMSUNG Mobile USB Modem II 1.0 Drivers; C:\WINDOWS\system32\DRIVERS\ssm_mdm.sys [2005-08-30 94000]
        S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
        S4 agpCPQ;Filtre de bus AGP Compaq; C:\WINDOWS\System32\DRIVERS\agpCPQ.sys [2008-04-13 44928]
        S4 alim1541;Filtre de bus AGP ALI; C:\WINDOWS\System32\DRIVERS\alim1541.sys [2008-04-13 42752]
        S4 amdagp;Pilote de filtre du bus AMD AGP; C:\WINDOWS\System32\DRIVERS\amdagp.sys [2008-04-13 43008]
        S4 cbidf;cbidf; C:\WINDOWS\System32\DRIVERS\cbidf2k.sys [2001-08-18 13952]
        S4 sisagp;Filtre de bus AGP SIS; C:\WINDOWS\System32\DRIVERS\sisagp.sys [2008-04-13 40960]
        S4 viaagp;Filtre de bus AGP VIA; C:\WINDOWS\System32\DRIVERS\viaagp.sys [2008-04-13 42240]

        ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

        R2 FireSvc;McAfee Desktop Firewall Service; C:\Program Files\Network Associates\McAfee Desktop Firewall pour Windows XP\FireSvc.exe [2005-04-20 766011]
        R2 McAfeeFramework;Service Framework McAfee; C:\Program Files\Network Associates\Common Framework\FrameworkService.exe [2004-08-06 102463]
        R2 McShield;Network Associates McShield; C:\Program Files\Network Associates\VirusScan\Mcshield.exe [2004-09-22 221191]
        R2 McTaskManager;Network Associates Task Manager; C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe [2004-09-22 28672]
        R2 r_server;Remote Administrator Service; C:\WINDOWS\System32\r_server.exe [2009-04-22 241664]
        S2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\System32\Ati2evxx.exe [2000-11-30 57344]
        S2 AVWUpSrv;AntiVir Update; C:\Program Files\AVPersonal\AVWUPSRV.EXE []
        S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
        S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
        S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-01-15 137200]
        S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
        S3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 97136]

        -----------------EOF-----------------
        0
        1. Sinon pour mon problème de connexion les 2 autres postes fonctionnent correctement, j'ai été voir les options de modems sur mon poste et il me met le modem comme étant "absent" j'espère que je ne l'ai pas viré enfin en meme temps je ne vois pas comment j'ai rien touché au niveau de l'internet ??? J'suis pourtant pas trop trop nul en informatique (enfin je croyait !!!), mais là je suis dépassée....
          0
      3. Ok je te prepare la suite dans 5 min ;)
        0
        1. si mon problème de connexion internet été régée ça serai plus pratique pour moi de suivre vos indications....je sais pas si vous avez une idée ??? merci
          0
        2. @beaaCOOL, j'ai réglé mon problème de connexion je vais pouvoir suivre vos infos plus sereinement.....
          0
      4. ok , ça va aller mieux , fais ce scan pour finir :

        Telecharge malwarebytes
        https://www.malwarebytes.com/

        Tu l´instale; le programme va se mettre automatiquement a jour.

        Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

        Click maintenant sur l´onglet recherche et coche la case : "executer un examen rapide".

        Puis click sur "rechercher".

        Laisse le scanner le pc...

        Si des elements on ete trouvés > click sur supprimer la selection.

        si il t´es demandé de redemarrer > click sur "yes".

        A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.

        Copie et colle le rapport stp.

        PS : les rapport sont aussi rangé dans l onglet rapport/log

        0
        1. Voici le rapport :

          Malwarebytes' Anti-Malware 1.36
          Version de la base de données: 2026
          Windows 5.1.2600 Service Pack 3

          22/04/2009 18:30:36
          mbam-log-2009-04-22 (18-30-36).txt

          Type de recherche: Examen rapide
          Eléments examinés: 75531
          Temps écoulé: 3 minute(s), 59 second(s)

          Processus mémoire infecté(s): 0
          Module(s) mémoire infecté(s): 0
          Clé(s) du Registre infectée(s): 0
          Valeur(s) du Registre infectée(s): 0
          Elément(s) de données du Registre infecté(s): 0
          Dossier(s) infecté(s): 0
          Fichier(s) infecté(s): 0

          Processus mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Module(s) mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Clé(s) du Registre infectée(s):
          (Aucun élément nuisible détecté)

          Valeur(s) du Registre infectée(s):
          (Aucun élément nuisible détecté)

          Elément(s) de données du Registre infecté(s):
          (Aucun élément nuisible détecté)

          Dossier(s) infecté(s):
          (Aucun élément nuisible détecté)

          Fichier(s) infecté(s):
          (Aucun élément nuisible détecté)
          0
        2. @beaamerci à demain, je viendrai vérifier si il reste des choses à faire...
          0
      5. ok Beaa , @ demain , il restera 2 / 3 details
        0
        1. bonjour Chiquitine,

          Bon je suis dispo, pour les 2/3 détails restant.....
          En tout cas ce matin, mon pc est bien plus rapide et l'ouverture d'internet explorer c'est fait sans souci !! ça faisait longtemps que c'était pas arrivée....
          0
      6. Salut Beaa , ;)

        -> Télécharge et instal Ccleaner

        (n'installe pas la barre d'outil Yahoo):

        -> Tuto : (fais registre : corriger les erreures et lancer le nettoyage)

        Télécharge ToolsCleaner sur ton bureau.
        -->
        http://pc-system.fr/
        http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner

        # Clique sur Recherche et laisse le scan agir ...
        # Clique sur Suppression pour finaliser.
        # Tu peux, si tu le souhaites, te servir des Options facultatives.
        # Clique sur Quitter pour obtenir le rapport.
        # Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

        Purge de la restauration système
        *Désactive ta restauration :
        Clique droit sur poste de travail/propriétés/Restauration système/coche la case désactiver la restauration, appliquer, OK
        ---> Redémarre ton PC ...

        *Réactive ta restauration :
        Clique droit sur poste de travail/propriétés/Restauration système/décoche la case désactiver la restauration, appliquer, OK
        --->Redémarre ton PC ...

        ( Note : tu peux aussi y accéder via panneau de configuration->" système "->" restauration système " ).

        Tuto xp : http://service1.symantec.com/support/inter/tsgeninfointl.Nsf/fr_docid/20020830101856924

        0
        1. voici le rapport :

          [ Rapport ToolsCleaner version 2.3.5 (par A.Rothstein & dj QUIOU) ]

          --> Recherche:

          C:\Combofix.txt: trouvé !
          C:\UsbFix.txt: trouvé !
          C:\Qoobox: trouvé !
          C:\UsbFix: trouvé !
          C:\Rsit: trouvé !
          C:\Documents and Settings\STM\Bureau\ComboFix.exe: trouvé !
          C:\Documents and Settings\STM\Bureau\UsbFix.lnk: trouvé !
          C:\Documents and Settings\STM\Menu Démarrer\Programmes\UsbFix: trouvé !
          C:\Documents and Settings\STM\Menu Démarrer\Programmes\UsbFix\UsbFix.lnk: trouvé !

          ---------------------------------
          --> Suppression:

          C:\Documents and Settings\STM\Bureau\ComboFix.exe: ERREUR DE SUPPRESSION !!
          C:\Combofix.txt: supprimé !
          C:\UsbFix.txt: supprimé !
          C:\Documents and Settings\STM\Bureau\UsbFix.lnk: supprimé !
          C:\Documents and Settings\STM\Menu Démarrer\Programmes\UsbFix\UsbFix.lnk: supprimé !
          C:\Qoobox: supprimé !
          C:\UsbFix: supprimé !
          C:\Rsit: supprimé !
          C:\Documents and Settings\STM\Menu Démarrer\Programmes\UsbFix: supprimé !
          0
      7. supprime combofix de ton bureau

        si tu n as pas d autres soucis change le statut du sujet en resolu stp

        http://www.commentcamarche.net/faq/sujet 11365 marquer un fil de discussion comme etant resolu
        0
        1. ok je supprime combofix, et est ce que je peux virer aussi Malwarebytes ???

          Sinon dernière petite question, j'ai l'intention de virer Mc Afee comme antivirus et de le remplacer par Avast quand penses tu ???

          Pas de souci je met le poste en résolu !!!

          Mille MERCI, tu m'as enlevé une grosse épine du pied, heureusement qu'il y a des personnes comme vous pour aider, merci merci
          0
      8. Malewarebytes's je te conseil de le garder et de scanner de temps en temps .

        C est un outil puissant et un bon allier pour ton antivirus.

        Si tu désinstal mc affee , pourquoi pas mais pas pour installer avast , car dépassé par les evenement actuels.

        Je te conseil plutot Antivir : antivir vs avast :

        -> http://forum.malekal.com/ftopic3528.php

        ->Antivir le telecharger

        -> http://www.commentcamarche.net/telecharger/telecharger 55 antivir

        tuto : https://www.malekal.com/avira-free-security-antivirus-gratuit/
        tuto : http://www.swl1f.net/viewtopic.php?f=14&t=59

        0
        1. ok pour antivir et sinon AVG c'est bien ou pas car c'est lui qui m'a trouvé les virus ???

          Je n'arrive pas à mettre le poste en "résolu", surement parce que je ne suis pas membre....j'essaye encore...
          0
      9. Avg est bien aussi d apres ce que j ai vu , moi j utilise antivir , pour mettre en resolu je vais le faire pour toi .

        Bonne journée Beaa ;)

        0
        1. merci encore, bonne journée à toi aussi !!
          0