Virus tool security? qui peut m'aider?

Résolu
Bonjour,

Hier soir, tool security s'est installé sur mon pc, et depuis je n'arrive a rien. Il a effacé mon bureau etc
Je n'y connais pas grand chose en informatique, aidez moi s'il vous plait.Je m'excuse d'avance car je risque de ne pas comprendre un vocabulaire trop technique...
Merci d'avance
Sandrine
Configuration: Windows XP Internet Explorer 7.0

80 réponses

Résumé de la discussion

Une infection par un logiciel malveillant a été signalée sur Windows XP, entraînant la disparition du bureau et une perte de fonctionnalité, ce qui complique l’utilisation de l’ordinateur. Plusieurs mesures pertinentes visent à rétablir l’intégrité du système, notamment désinstaller Avast et Bitdefender via leurs utilitaires, puis installer ANTIVIR et configurer un scan complet. D’autres éléments clés incluent l’analyse des rapports de scan et l’utilisation de VirusTotal pour analyse de fichiers suspects, ainsi que la mise en quarantaine des éléments détectés par Avira. Des exemples trouvés dans les rapports mentionnent des fichiers comme AD-R.exe et Boonty.exe déplacés en quarantaine, ce qui illustre la progression possible vers une désinfection complète.

Bobot (l’IA à votre service)
  1. Clic ici https://www.virustotal.com/gui/
    et fais analyser ce fichier:
    C:\Documents and Settings\NetworkService\Application Data\anvkgp.dat

    Tuto:
    http://www.bibou0007.com/scans-en-ligne-f75/tutorial-sur-virustotal-t190.htm

    - un rapport va s'etablir si on te dit le fichier a deja ete analyser clic sur Réanalyser
    a la fin copie colle l'integralité du rapport

    a+
    1
    1. Impec....

      Refais la même chose avec ce script: (merciJFK)

      :reg
      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersio­n\Run]
      "EoWeather"=-
      "EoEngine"=-

      :commands
      [purity]
      [emptytemp]
      [start explorer]
      [Reboot]


      ENSUITE:

      Dans cet ordre:

      Désinstalles Avast avec cet utilitaire:
      https://www.commentcamarche.net/telecharger/securite/22859-utilitaire-de-desinstallation-de-avast/

      Désinstalles les restes de Bit defender:
      (utilises l'outil de désinstal)
      http://www.bitdefender.fr/KB333-fr--Desinstaller-BitDefender.html

      ==> Télécharges ANTIVIR
      http://www.commentcamarche.net/telecharger/telecharger-55-antivir

      -> Configures le ainsi:
      https://www.commentcamarche.net/faq/16831-tutoriel-configuration-optimale-d-antivir-personal

      -> Lances un scan et colles le rapport

      a+

      1
      1. Bonjour

        Télécharge rkill
        https://download.bleepingcomputer.com/grinler/rkill.exe
        Enregistre-le sur ton Bureau
        Double-clique sur l'icone rkill ( pour Vista/Seven clic-droit Exécuter en tant qu'Administrateur)
        Un bref écran noir t'indiquera que le tool s'est correctement exécuter, s'il ne lance pas
        change de lien de téléchargement en utilisant le suivant à partir d'ici:

        http://download.bleepingcomputer.com/grinler/rkill.pif
        https://download.bleepingcomputer.com/grinler/rkill.scr
        https://download.bleepingcomputer.com/grinler/rkill.com

        Puis:

        Fais un scan avec cet antispyware :
        Malwarebytes + tutoriel

        Tu l´installes; mets le a jour...(onglet mise a jour)
        Click maintenant sur l´onglet recherche et coche la case :
        "Executer un examen rapide".
        Puis click sur "rechercher".
        Laisses le scanner le pc...
        A la fin du scan, clique sur Afficher les résultats
        Si des elements on ete trouvés :
        > click sur supprimer la selection.
        si il t´es demandé de redemarrer > click sur "oui".
        A la fin un rapport va s´ouvrir;
        sauvegarde le de maniere a le retrouver en vue de le poster sur le forum.
        Copies et colles le rapport stp.

        a+

        0
        1. Mon dieu que l'informatique est compliqué...!!!
          Je vais essayer
          merci
          0
          1. ca ne finctionne pas, impossible de telecharger malwarebytes...
            apparement le virus a reculer car il est toujours sur le bureau mais n'apparait plus dans la barre du bat et ne m'envoie plus de message.
            Malgré tout le virus est encore la. quelle est donc la solution?
            0
            1. ---> Télécharge ComboFix.exe de sUBs sur ton Bureau :
              http://download.bleepingcomputer.com/sUBs/ComboFix.exe

              Choisis "Enregistrer" (sur le bureau)
              Et renommes le comme ceci :
              Dans Nom du fichier: Tapes sandrine.exe
              Dans Type: "tous les fichiers"

              /!\ Déconnecte-toi du net et ferme toutes les applications, antivirus et antispyware y compris /!\

              ---> Double-clique sur Combofix.exe
              Un "pop-up" va apparaître qui dit que "ComboFix est utilisé à vos risques et avec aucune garantie...".
              Accepte en cliquant sur "Oui"

              ---> Mets-le en langue française F
              Tape sur la touche 1 (Yes) pour démarrer le scan.

              /!\ Ne touche à rien tant que le scan n'est pas terminé. /!\

              En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

              Une fois le scan achevé, un rapport va s'afficher : Poste son contenu

              /!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\

              Note : Le rapport se trouve également là : C:\ComboFix.txt

              a+
              0
              1. Bonjour,
                j'ai finalement reussi a faire ce que tu m'indiquai a ton premier message soit,

                mode sans échec, ms config, malwarebyte's , scanner en ligne bitdefender, et quand le virus a été supprimer j'ai refait un scann minutieux avec avast qui a trouvé encore 1 infections, je l'ai supprimé.

                maintenent reste un soucis, 1 a 2 fois par heure, la page sur laquel je suis se fige, puis l'ecran devient noir, et je ne peux plus rien faire.Tout revient 2 a 3 min plus tard... mais ca n'arrivait pas avant tool security.que faire?

                autre question, dois je laisser le démarrage de windows en mode séléctif comme il a fallu le parametrer pour enlever le virus, ou le remettre en demarrage normal?
                Merci vraiment d'avance de me répondre.
                Sandrine

                ps: je n'ai pas fait combo fix car je n'avais pas vu le message, faut il le faire mnt ou pas besoin?
                0
            2. Relances Malwarebyte....
              Vas ds l'onglet "Rapport/log"
              Ouvres le rapport que tu y trouveras ...copies/colles le ds ta prochaine réponse....

              ***********************

              Pour voir l'état du pc:

              Télécharge RSIT (de random/random) sur le bureau :

              - Double clique sur RSIT.exe qui est sur le bureau
              - Clique sur "Continue" dans la fenêtre
              - RSIT téléchargera HijackThis si il n’est pas présent où détecté, alors il faudra accepter la licence
              - Poste le contenu de log.txt plus info.txt (réduit ds la barre de taches) à la fin de l’analyse .

              Les rapports sont dans le dossier ici C:\rsit
              a+

              0
              1. Je fais ca des demain, enfin j'essaye.et je transmet les rapports.

                Merci
                0
              2. voici le premier rapport fait le 24

                Malwarebytes' Anti-Malware 1.44
                Version de la base de données: 3628
                Windows 5.1.2600 Service Pack 2 (Safe Mode)
                Internet Explorer 8.0.6001.18702

                24/01/2010 20:15:23
                mbam-log-2010-01-24 (20-15-23).txt

                Type de recherche: Examen complet (C:\|D:\|E:\|G:\|H:\|I:\|J:\|)
                Eléments examinés: 258845
                Temps écoulé: 27 minute(s), 0 second(s)

                Processus mémoire infecté(s): 0
                Module(s) mémoire infecté(s): 0
                Clé(s) du Registre infectée(s): 75
                Valeur(s) du Registre infectée(s): 2
                Elément(s) de données du Registre infecté(s): 0
                Dossier(s) infecté(s): 1
                Fichier(s) infecté(s): 19

                Processus mémoire infecté(s):
                (Aucun élément nuisible détecté)

                Module(s) mémoire infecté(s):
                (Aucun élément nuisible détecté)

                Clé(s) du Registre infectée(s):
                HKEY_CLASSES_ROOT\hbcoresrv.dynamicprop (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\hbcoresrv.dynamicprop.1 (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\hbtcoresrv.hbtcoreservices (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\hbtcoresrv.hbtcoreservices.1 (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\hbtcoresrv.lfgax (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\hbtcoresrv.lfgax.1 (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\hbthostol.hbtmailanim (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\hbthostol.hbtmailanim.1 (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\hbthostol.hbtwebmailsend (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\hbthostol.hbtwebmailsend.1 (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\hbtinstie.hbinstobj (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\hbtinstie.hbinstobj.1 (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\hbtools.hbtcommband (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\hbtools.hbtcommband.1 (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\hbtsrv.hbtcoreservices (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\hbtsrv.hbtcoreservices.1 (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\hbttoolbar.hbthtmlmenuui (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\hbttoolbar.hbthtmlmenuui.1 (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\hbttoolbar.hbttoolbarctl (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\hbttoolbar.hbttoolbarctl.1 (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\hbttools.hbmain (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\hbttools.hbmain.1 (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{023a4648-601a-4c30-8a2e-c72ebfa99af6} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{175816a5-219e-4079-b2f9-53c501c409ba} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{19ebcbe0-9245-4397-bc5d-883d34782043} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{1c1793e0-1034-4cac-837d-aa545f6961bf} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{1e07646f-07c4-4847-a250-0ec8114f2963} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{27c4569f-8728-4958-a920-a607cae8153c} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{38370864-346f-4afa-8c4b-4fbff518c0bb} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{397a208b-3d09-4b3e-93e8-ca171886612e} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{421745e9-16df-4ee4-a758-d51f939c49cb} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{4331ec56-0aab-499e-8757-dd2ee44ad671} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{54286c3a-e044-4e65-bd44-528d6ae28a18} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{5d16197a-1eaa-45af-b29a-69f1aa055e87} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{5f2b9de7-f878-4762-8cfe-e9c58f082f0e} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{8654592e-952a-4e7c-a960-304763b35fa6} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{8a61a950-c325-4f44-ba64-273180ff3464} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{8d5c4ec6-af8e-4b85-ba27-64babe410510} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{8e98faf8-794f-47f9-af90-15305564ed81} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{af15975b-1498-4740-8e6c-90af78e4198c} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{b53d4cd4-406d-43cc-8244-7893d72236dd} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{b671426c-5c1a-48ac-9652-bc9402b1c404} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{b9bb3219-f84c-4060-966b-4a1e73e24226} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{bc8c2e5f-d8b4-4997-bce3-8775c3707956} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{d082721f-4bd4-4b8b-bb82-06753ee6174f} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{d24f9d3c-5d4c-47f8-9ab7-632b44ad6a0d} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{f43ec88b-b6c8-4969-a763-e2bf55602cce} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{f786cb18-3809-4e49-bc99-9a66da47db8b} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{f814be58-1bf9-4b50-829a-e889f86127ad} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\AppID\{0507fdde-f3b7-49f5-9e8f-c557e991f39b} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\CLSID\{0ab71193-ec19-4d70-85c2-e46e2ff02755} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\CLSID\{1e0004ec-5df0-48c7-a8f0-fbb0488a3d94} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\CLSID\{31a59636-0fa3-4a56-954d-db7ad02840d8} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\CLSID\{3fa917b9-df69-477f-9e4f-b60d929de79f} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\CLSID\{420c35c9-e4f2-49f9-bf67-2be1ecf86989} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\CLSID\{460ac4db-b0de-4626-a0f0-175dd84dcb9b} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\CLSID\{7e66936c-fea0-4984-ad26-7b6661ac5b2e} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\CLSID\{8c875948-9c60-4381-9248-0df180542d53} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\CLSID\{a14c0d8d-e753-4e73-9e2b-4070791d8940} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\CLSID\{c2baa4c9-ae1e-4605-ae2f-a1c49a30d881} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\CLSID\{ed8525ea-2bfc-4440-bd8a-20efb9d5e541} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\CLSID\{fa16bce1-5e36-472a-8466-e0cdd5ce00e6} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Typelib\{45397063-d7d0-47c2-9508-26487608a298} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Typelib\{4cf5a3c1-07a2-4336-9b54-6870452ebde1} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Typelib\{71e9cf40-af72-4b55-bd3f-1fea2a0eaea6} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Typelib\{71efe583-62fe-4419-9918-ca3b683f7b36} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Typelib\{9967a873-40f3-4c7e-9239-6c8760f19f61} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Typelib\{b9f51d42-cca0-4408-bb02-d433d1865a3a} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Typelib\{f8ee014f-b34c-4544-8e45-95a7971d323b} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{7e66936c-fea0-4984-ad26-7b6661ac5b2e} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{7e66936c-fea0-4984-ad26-7b6661ac5b2e} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\secdrv (Rootkit.Agent) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\AppID\WeatherOnTray.exe (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\EoRezo (Rogue.Eorezo) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ICF (Rootkit.Agent) -> Quarantined and deleted successfully.

                Valeur(s) du Registre infectée(s):
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ctfmon (Trojan.Bredolab) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysgif32 (Trojan.Agent) -> Quarantined and deleted successfully.

                Elément(s) de données du Registre infecté(s):
                (Aucun élément nuisible détecté)

                Dossier(s) infecté(s):
                C:\Documents and Settings\All Users\Application Data\17604018 (Rogue.Multiple) -> Quarantined and deleted successfully.

                Fichier(s) infecté(s):
                C:\WINDOWS\Temp\_ex-08.exe (Trojan.Bredolab) -> Quarantined and deleted successfully.
                C:\WINDOWS\system32\drivers\secdrv.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
                C:\WINDOWS\Temp\~TM1B.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
                C:\WINDOWS\Temp\~TM10.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
                C:\WINDOWS\Temp\_ex-68.exe (Rogue.SecurityTool) -> Quarantined and deleted successfully.
                C:\Documents and Settings\All Users\Application Data\17604018\17604018.exe (Rogue.SecurityTool) -> Quarantined and deleted successfully.
                C:\Documents and Settings\Serge\Local Settings\Temporary Internet Files\Content.IE5\RT02PVYL\wcap[1].exe (Trojan.Dropper) -> Quarantined and deleted successfully.
                C:\Documents and Settings\Serge\Local Settings\Temp\TMP8.tmp (Trojan.Dropper) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{D48032BB-B733-4232-997D-9562C8F43AFA}\RP961\A0147693.exe (Worm.Koobface) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{D48032BB-B733-4232-997D-9562C8F43AFA}\RP961\A0147694.exe (Worm.Koobface) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{D48032BB-B733-4232-997D-9562C8F43AFA}\RP961\A0147695.exe (Worm.Koobface) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{D48032BB-B733-4232-997D-9562C8F43AFA}\RP988\A0157596.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{D48032BB-B733-4232-997D-9562C8F43AFA}\RP988\A0157597.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{D48032BB-B733-4232-997D-9562C8F43AFA}\RP988\A0157604.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{D48032BB-B733-4232-997D-9562C8F43AFA}\RP988\A0157605.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
                C:\WINDOWS\logfile32.txt (Malware.Trace) -> Quarantined and deleted successfully.
                C:\Documents and Settings\Serge\Bureau\Security Tool.LNK (Rogue.SecurityTool) -> Quarantined and deleted successfully.
                C:\Documents and Settings\Serge\Menu Démarrer\Programmes\Security Tool.LNK (Rogue.SecurityTool) -> Quarantined and deleted successfully.
                C:\Documents and Settings\Serge\Application Data\avdrn.dat (Malware.Trace) -> Quarantined and deleted successfully.
                0
              3. et voici le 2éme resultat du scann que je vien juste de faire. Je terminerai demain avec rsit.

                Malwarebytes' Anti-Malware 1.44
                Version de la base de données: 3628
                Windows 5.1.2600 Service Pack 2
                Internet Explorer 8.0.6001.18702

                25/01/2010 23:13:19
                mbam-log-2010-01-25 (23-13-19).txt

                Type de recherche: Examen complet (C:\|D:\|E:\|G:\|H:\|I:\|J:\|)
                Eléments examinés: 245516
                Temps écoulé: 2 hour(s), 13 minute(s), 59 second(s)

                Processus mémoire infecté(s): 0
                Module(s) mémoire infecté(s): 0
                Clé(s) du Registre infectée(s): 0
                Valeur(s) du Registre infectée(s): 0
                Elément(s) de données du Registre infecté(s): 0
                Dossier(s) infecté(s): 0
                Fichier(s) infecté(s): 0

                Processus mémoire infecté(s):
                (Aucun élément nuisible détecté)

                Module(s) mémoire infecté(s):
                (Aucun élément nuisible détecté)

                Clé(s) du Registre infectée(s):
                (Aucun élément nuisible détecté)

                Valeur(s) du Registre infectée(s):
                (Aucun élément nuisible détecté)

                Elément(s) de données du Registre infecté(s):
                (Aucun élément nuisible détecté)

                Dossier(s) infecté(s):
                (Aucun élément nuisible détecté)

                Fichier(s) infecté(s):
                (Aucun élément nuisible détecté)
                0
              4. voila ce que tu m'as demandé, c'est bien ca?
                alors quel est votre diagnostique doc? je plaisante, mais si tu peux me dire quoi faire, ca serait genial.
                et pour le démarrage de mon ordi, est ce que je le laisse en mode séléctif ou est ce que je peux le remettre en mode normal? merci

                Logfile of random's system information tool 1.06 (written by random/random)
                Run by Serge at 2010-01-25 23:22:28
                Microsoft Windows XP Édition familiale Service Pack 2
                System drive C: has 120 GB (80%) free of 150 GB
                Total RAM: 511 MB (29% free)

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 23:23:29, on 25/01/2010
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\csrss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                C:\WINDOWS\Explorer.EXE
                C:\WINDOWS\system32\LEXBCES.EXE
                C:\WINDOWS\system32\spoolsv.exe
                C:\WINDOWS\system32\LEXPPS.EXE
                C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
                C:\Program Files\QuickTime\qttask.exe
                C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                C:\WINDOWS\system32\FsUsbExService.Exe
                C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
                C:\WINDOWS\System32\nvsvc32.exe
                C:\Program Files\Logitech\SetPoint\SetPoint.exe
                C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                C:\WINDOWS\DvzCommon\DvzMsgr.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\System32\MsPMSPSv.exe
                C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
                C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE
                C:\Program Files\Messenger\msmsgs.exe
                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                C:\WINDOWS\System32\alg.exe
                C:\WINDOWS\system32\wuauclt.exe
                C:\Program Files\Java\jre1.5.0_09\bin\jucheck.exe
                C:\Program Files\Windows Live\Contacts\wlcomm.exe
                C:\Documents and Settings\Serge\Mes documents\Téléchargements\RSIT.exe
                C:\WINDOWS\system32\wbem\wmiprvse.exe
                C:\Program Files\trend micro\Serge.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\eoRezo\EoAdv\EoRezoBHO.dll (file missing)
                O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                O2 - BHO: HbTools - {74CC49F7-EB32-4A08-B204-948962A6E3DB} - C:\Program Files\HbTools\Bin\4.8.0.0\HbtHostIE.dll (file missing)
                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
                O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                O3 - Toolbar: H&otbar - {74CC49F7-EB32-4A08-B204-948962A6E3DB} - C:\Program Files\HbTools\Bin\4.8.0.0\HbtHostIE.dll (file missing)
                O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Fichiers communs\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
                O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
                O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
                O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                O4 - HKCU\..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
                O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                O4 - Startup: MSN Pictures Displayer.lnk = C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
                O4 - Startup: wwwpos32.exe
                O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
                O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                O4 - Global Startup: Dataviz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe
                O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
                O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
                O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll
                O14 - IERESET.INF: START_PAGE_URL=https://www.free.fr/freebox/index.html
                O15 - Trusted Zone: www.jmec.fr
                O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Rawflow.cab
                O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
                O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
                O16 - DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} (CamfrogWEB Advanced Unicode Control) - http://activex.camfrogweb.com/advanced/2.0.1.14/cfweb_activex.camfrogweb.com-advanced-2.0.1.14_instmodule.exe
                O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by21fd.bay21.hotmail.msn.com/resources/MsnPUpld.cab
                O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/18a2bca39475b4b16817/netzip/RdxIE601_fr.cab
                O16 - DPF: {5CA8D349-C6E7-11D4-8166-009027DF3BB2} (France Telecom MDDK ActiveX Control) - http://accueil.ava.serveur-ava.com/stkid_data/ocx/mDKid.cab
                O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/fr/scan8/oscan8.cab
                O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1100635444078
                O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
                O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
                O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/4h/player.virtools.com/downloads/player/Install3.0/Installer.exe
                O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/install/installer.exe
                O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
                O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
                O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                O23 - Service: FsUsbExService - Teruten - C:\WINDOWS\system32\FsUsbExService.Exe
                O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
                O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                0
            3. et pour le démarrage de mon ordi, est ce que je le laisse en mode séléctif ou est ce que je peux le remettre en mode normal?


              ==> OUI tu peux....

              Reprends Malwarebytes...Vas ds l'onglet Quarantaine et supprimes tout ....

              PUIS:

              Le Rogue SecurityTool a été supprimé mais pas le rootkit qui l'accompagne :

              ---> Télécharge ComboFix.exe de sUBs sur ton Bureau :
              http://download.bleepingcomputer.com/sUBs/ComboFix.exe

              Choisis "Enregistrer" (sur le bureau)
              Et renommes le comme ceci :
              Dans Nom du fichier: Tapes sandrine.exe
              Dans Type: "tous les fichiers"


              /!\ Déconnecte-toi du net et ferme toutes les applications, antivirus et antispyware y compris /!\

              ---> Double-clique sur Combofix.exe
              Un "pop-up" va apparaître qui dit que "ComboFix est utilisé à vos risques et avec aucune garantie...".
              Accepte en cliquant sur "Oui"

              ---> Mets-le en langue française F
              Tape sur la touche 1 (Yes) pour démarrer le scan.

              /!\ Ne touche à rien tant que le scan n'est pas terminé. /!\

              En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

              Une fois le scan achevé, un rapport va s'afficher : Poste son contenu

              /!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\

              Note : Le rapport se trouve également là : C:\ComboFix.txt

              a+

              0
              1. Bonjour;

                Voici les dernières nouvelles...(je commence à désespérer,heureusement que tu es là !!)
                tout d'abord, j'ai juste demander un petit renseignement a pimprenelle27 hier soir car je n'arrivai pas a renommer ComboFix, ainsi j'ai pu le lancer pour la nuit.
                C'était peut etre une erreur de ma part... Ce matin j'ai trouvé mon pc qui avait redémarré, comme tu me l'avais dit après le scan, seulement je n'ai pas trouvé de rapport, et j'avais un message me disant que le systéme avait récupéré d'une erreur sérieuse...

                signature de l'erreur

                BCcode: 19 BCP1: 00000020 BCP3:8209F418 BCP4:1A830000 OSVer: 5_1_2600 SP:2_0 Product:768_1

                ensuite il était indiqué que les fichiers suivants seront inclus dans le rapport d'erreur:

                .........WER2cf8.dir00\Mini012710-01.dmp
                .........WER2cf8.dir00\sysdata.xml

                Bon forcément tout ça pour moi c'est du chinois... Mais j'espère que tu pourras m'en dire plus.
                Dans l'attente de ta réponse, je te souhaite de passer une bonne journée !! ;-)
                0
            4. j'ai téléchargé combofix mais je n'arrive pas a le rennommer.

              c'est important?
              0
              1. Contributeur sécurité
                Bonjour vous deux ;)

                Si besoin est télécharge Combofix ici

                Il est déja renommé en ComboKill .

                Bonne continuation ..
                0
                1. Merci, mais ce n'est pas le téléchargement qui n'a pas fonctionné, apparemment il y a eu une erreur en cours du scan, j'ai noté plus haut le rapport d'erreur........... pppppppffffffffffffff je désespère !!! lol

                  J'aurais du rester devant mon pc, mais pensant que ca serait long je suis allée me coucher en le laissant travaillé..
                  0
                  1. moi je les aussi mes je n'arrive pas a télécharger rkill car un pote me la aussi conseiller mes sécurity tool me dit que sais infécter ou sinon il y a une console noir et après plus rien sa s'enleve (je les resus depuis que j'ai installer teamspeak 3 ) svp aider moi
                    0
                    1. Contributeur sécurité
                      fabien 68480: créé ton propre topique dans Virus/sécu si tu veux qu'on t'aide .Merci .
                      0
                      1. me voila, je n'ai pas trouvé le lien dont tu me parle désolée
                        0
                        1. ca y est je t'ai mis le lien en message privé
                          0
                          1. Ok ...on y est ....

                            Tout d'abord : Salut à toi jfkpresident et merci pour ton intervention .....

                            sand2504

                            Avant toute chose ....Avais tu renommé Combo ?

                            ==> DIs moi le non qui figure sous l'icone Combo (tête de lion ds une icone rouge)
                            Cela me permettra de retrouver un éventuel rapport si celui ci a été créé !

                            a+

                            0
                            1. oui j'avais finalement reussi a le renommer sandrine.exe
                              0
                              1. Ok ...

                                Pour voir si un rapport a été créé...--> Poste de travail --> Rechercher et ds cette fenètre tapes
                                ou copies/colles : C:\sandrine.exe.txt
                                Dis moi ce que tu y trouves ....

                                a+

                                0
                                1. J'ai lancé la recherche je te tiens au courant quand j'ai le resultat
                                  0
                                  1. ça tourne toujours, c'est normal que ce soit si long?
                                    pour le moment pas de résultat...
                                    0
                                    • 1
                                    • 2
                                    • 3
                                    • 4