Virus en provenance de MSN Messenger??

Bonsoir à tous les experts,
Ma fille utilise constamment MSN Messenger et a dû "embarquer" un virus que mon Norton ne parvient décidemment pas à détecter.

Les symptômes (qui affectent toutes les applications : Word, Excel, Internet Explorer, Windows Explorer... SAUF MSN Messenger - il n'y a pas de justice!) sont les suivants :
- Ecran qui n'arrête pas de défiler aléatoirement (ex : en Excel, on descend progressivement jusqu'à la ligne 32000, sur Internet Explorer l'écran se ballade soit au début soit en fin de page, en tout cas vers la partie que l'on ne veut pas voir..., sur Windows Explorer (sous XP) les directories défilent sans que l'on puisse sélectionner celle que l'on veut)
- par moment (de plus en plus rare) stabilisation.

L'un d'entre vous a-t-il déjà rencontré ce type de problème et est-il posible au béotien que je suis de le résoudre??

Merci d'avance,
Patrick
Configuration: Windows 2000
Internet Explorer 6.0

22 réponses

  1. Contributeur
    Bonsoir,

    On va voir si sa provient vraiment d'Msn.

    Téléchargez MSNFix.zip (de !aur3n7) sur votre bureau:
    http://sosvirus.changelog.fr/MSNFix.zip

    Décompressez-le (clic droit >> Extraire ici) et double cliquer sur le fichier MSNFix.bat.
    - Exécutez l'option R.
    -- Si l'infection est détectée, exécutez l'option N.
    --- Sauvegardez ce rapport puis faites un copier/coller de ce rapport sur le forum, ainsi qu'un nouveau scan HijackThis fait en mode normal.

    Note :
    Si une erreur de suppression est détectée un message s'affichera demandant de redémarrer l'ordinateur afin de terminer les opérations. Dans ce cas il suffit de redémarrer l'ordinateur en mode normal
    Sauvegarder et fermer le rapport pour que Windows termine de se lancer normalement.

    0
    1. Darkkiller,
      Même le prompt DOS a la bougeotte ce soir...
      J'ai suivi tes instructions (péniblement à cause de l'écran parkinsonien), ai lancé l'option Rechercher qui me signale
      "Infection absente". Je suppose donc que MSN Mesenger n'est pas en cause, ce qui me rend de plus en plus perplexe...
      Patrick
      0
    2. Darkkiller,
      SUite à ta demande, il y a de la matière ci-dessous!!!
      Patrick

      Logfile of HijackThis v1.99.1
      Scan saved at 21:23:12, on 10/04/2007
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16414)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
      C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
      C:\Program Files\Norton Internet Security\ISSVC.exe
      C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
      C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
      C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
      C:\WINDOWS\system32\UStorSrv.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Analog Devices\Core\smax4pnp.exe
      C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
      C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe
      C:\Program Files\Dell Photo AIO Printer 942\memcard.exe
      C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
      C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
      C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
      C:\Program Files\Support.com\bin\tgcmd.exe
      C:\Program Files\Dell Photo AIO Printer 942\dlbubmon.exe
      C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
      C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
      C:\Program Files\HP\HP Software Update\HPWuSchd.exe
      C:\WINDOWS\system32\dla\tfswctrl.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\AVerTV USB 2.0 Plus\QuickTV.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\DOCUME~1\Patrick\LOCALS~1\Temp\Répertoire temporaire 1 pour hijackthis.zip\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.proximus.be/pickx?new_lang=fr
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
      O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
      O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
      O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
      O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
      O4 - HKLM\..\Run: [Dell Photo AIO Printer 942] "C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe"
      O4 - HKLM\..\Run: [DellMCM] "C:\Program Files\Dell Photo AIO Printer 942\memcard.exe"
      O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
      O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
      O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
      O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
      O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /server /startmonitor
      O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
      O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
      O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
      O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
      O4 - HKLM\..\Run: [objskipcomproam] C:\Documents and Settings\All Users\Application Data\glueflagobjskip\DOES EACH.exe
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
      O4 - Global Startup: AVerTV USB 2.0.lnk = C:\Program Files\AVerTV USB 2.0 Plus\QuickTV.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O11 - Options group: [INTERNATIONAL] International*
      O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
      O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
      O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/download/scanner/wlscbase8460.cab
      O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
      O16 - DPF: {C45B1500-7B63-47C2-AB25-C28CB46AFDEE} (MediaBar) - http://sib1.od2.com/common/musicmanager/installation/MusicManagerPlugin.CAB
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
      O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
      O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
      O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
      O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - Unknown owner - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe (file missing)
      O23 - Service: AVG7 Update Service (Avg7UpdSvc) - Unknown owner - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe (file missing)
      O23 - Service: AVG E-mail Scanner (AVGEMS) - Unknown owner - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe (file missing)
      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
      O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
      O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
      O23 - Service: dlbu_device - Dell - C:\WINDOWS\system32\dlbucoms.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
      O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
      O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
      O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
      O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
      O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
      O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
      O23 - Service: UStorage Server Service - OTi - C:\WINDOWS\system32\UStorSrv.exe
      0
  2. Contributeur
    Re,

    Ce n'est pas MSN.

    télécharge HijackThis ici:
    http://telechargement.zebulon.fr/138-hijackthis-1991.html

    Dézippe le dans un dossier prévu à cet effet.
    Par exemple C:\hijackthis < Enregistre le bien dans c : !
    Démo : (Merci a Balltrap34 pour cette réalisation)
    http://pageperso.aol.fr/balltrap34/Hijenr.gif

    Lance le puis:
    clique sur "do a system scan and save logfile" (cf démo)
    faire un copier coller du log entier sur le forum

    Démo : (Merci a Balltrap34 pour cette réalisation)
    http://pageperso.aol.fr/balltrap34/demohijack.htm

    0
    1. Contributeur
      Re,

      Vas sur le site virus total : http://www.virustotal.com/en/indexf.html

      Puis dans un encadré blanc entre ce fichier :

      C:\Documents and Settings\All Users\Application Data\glueflagobjskip\DOES EACH.exe

      Puis clique sur "Send". Attend quelques minutes le temps que le rapport soit généré.

      Puis fait la meme chose avec ce fichier :

      C:\WINDOWS\system32\dlbucoms.exe

      Puis poste ces 2 logs dans ton prochain poste.
      0
      1. Darkkiller,
        il y a visiblement du monde dans la queue (je suis #104 car la première tentative a été stoppée en cours d'exécution-après détection de 4 virus a priori si j'en crois le log provisoire déroulant pendant le scan).
        Je relance la procédure mais ce sera peut-être pour demain car je dois me lever à l'aube.
        Patrick
        0
    2. Contributeur
      Re,

      Ok pas de problème tu m'envoye sa quand tu veux ;)
      0
      1. Darkkiller,
        Voilà

        Complete scanning result of "dlbucoms.exe", received in VirusTotal at 04.10.2007, 22:40:24 (CET).
        Antivirus Version Update Result
        AhnLab-V3 2007.4.10.0 04.10.2007 no virus found
        AntiVir 7.3.1.50 04.10.2007 no virus found
        Authentium 4.93.8 04.09.2007 no virus found
        Avast 4.7.936.0 04.10.2007 no virus found
        AVG 7.5.0.447 04.10.2007 no virus found
        BitDefender 7.2 04.10.2007 no virus found
        CAT-QuickHeal 9.00 04.10.2007 no virus found
        ClamAV devel-20070312 04.10.2007 no virus found
        DrWeb 4.33 04.10.2007 no virus found
        eSafe 7.0.15.0 04.10.2007 no virus found
        eTrust-Vet 30.7.3557 04.10.2007 no virus found
        Ewido 4.0 04.10.2007 no virus found
        FileAdvisor 1 04.10.2007 No threat detected
        Fortinet 2.85.0.0 04.10.2007 no virus found
        F-Prot 4.3.1.45 04.08.2007 no virus found
        F-Secure 6.70.13030.0 04.10.2007 no virus found
        Ikarus T3.1.1.5 04.10.2007 no virus found
        Kaspersky 4.0.2.24 04.10.2007 no virus found
        McAfee 5005 04.10.2007 no virus found
        Microsoft 1.2405 04.10.2007 no virus found
        NOD32v2 2178 04.10.2007 no virus found
        Norman 5.80.02 04.10.2007 no virus found
        Panda 9.0.0.4 04.09.2007 no virus found
        Prevx1 V2 04.10.2007 no virus found
        Sophos 4.16.0 04.06.2007 no virus found
        Sunbelt 2.2.907.0 04.07.2007 no virus found
        Symantec 10 04.10.2007 no virus found
        TheHacker 6.1.6.088 04.09.2007 no virus found
        VBA32 3.11.3 04.10.2007 no virus found
        VirusBuster 4.3.7:9 04.10.2007 no virus found
        Webwasher-Gateway 6.0.1 04.10.2007 no virus found
        Aditional Information
        File size: 421888 bytes
        MD5: 2566463c2b37d6d5f64d9177641468a3

        Complete scanning result of "DOES_EACH.exe", received in VirusTotal at 04.10.2007, 22:13:28 (CET).
        Antivirus Version Update Result
        AhnLab-V3 2007.4.10.0 04.10.2007 no virus found
        AntiVir 7.3.1.50 04.10.2007 no virus found
        Authentium 4.93.8 04.09.2007 no virus found
        Avast 4.7.936.0 04.10.2007 no virus found
        AVG 7.5.0.447 04.10.2007 Downloader.Obfuskated
        BitDefender 7.2 04.10.2007 Trojan.FatObfus.Gen
        CAT-QuickHeal 9.00 04.10.2007 no virus found
        ClamAV devel-20070312 04.10.2007 no virus found
        DrWeb 4.33 04.10.2007 no virus found
        eSafe 7.0.15.0 04.10.2007 no virus found
        eTrust-Vet 30.7.3557 04.10.2007 no virus found
        Ewido 4.0 04.10.2007 no virus found
        FileAdvisor 1 04.10.2007 no virus found
        Fortinet 2.85.0.0 04.10.2007 suspicious
        F-Prot 4.3.1.45 04.08.2007 no virus found
        F-Secure 6.70.13030.0 04.10.2007 Trojan.Win32.Obfuscated.en
        Ikarus T3.1.1.5 04.10.2007 no virus found
        Kaspersky 4.0.2.24 04.10.2007 Trojan.Win32.Obfuscated.en
        McAfee 5005 04.10.2007 no virus found
        Microsoft 1.2405 04.10.2007 no virus found
        NOD32v2 2178 04.10.2007 no virus found
        Norman 5.80.02 04.10.2007 no virus found
        Panda 9.0.0.4 04.09.2007 no virus found
        Prevx1 V2 04.10.2007 no virus found
        Sophos 4.16.0 04.06.2007 no virus found
        Sunbelt 2.2.907.0 04.07.2007 no virus found
        Symantec 10 04.10.2007 no virus found
        TheHacker 6.1.6.088 04.09.2007 no virus found
        VBA32 3.11.3 04.09.2007 MalwareScope.Trojan-Downloader.Obfuscated.2
        VirusBuster 4.3.7:9 04.10.2007 Adware.Lop.Gen
        Webwasher-Gateway 6.0.1 04.10.2007 Win32.Malware.gen (suspicious)
        0
        1. Contributeur
          Re,

          Ouvre Hijackthis et clique sur "Do a system scan only" et coche cette ligne :

          O4 - HKLM\..\Run: [objskipcomproam] C:\Documents and Settings\All Users\Application Data\glueflagobjskip\DOES EACH.exe

          Et quand tu as coché cette ligne, cliqur sur "Fix Checked"

          Ensuite supprime ce fichier :

          C:\Documents and Settings\All Users\Application Data\glueflagobjskip

          Si ca ne marche pas, fais-le en mode sans échec tuto : ttp://forum.telecharger.01net.com/telecharger/virus_et_assimiles/failles_de_securite/redemarrer_en_mode_sans_echec_pourquoi_et_comment-387297/messages-1.html

          0
          1. Darkkiller,
            J'ignore si tu as reçu mon mail précédent mais je jongle entre mon PC privé et mon portable du bureau. Je repose donc ma question :
            quand tu fais référence à :

            Ensuite supprime ce fichier :

            C:\Documents and Settings\All Users\Application Data\glueflagobjskip

            vises-tu le fichier DOES_EACH.exe infecté par le Trojan ou fais-tu référence à l'ensemble de la directory en question (qui contient deux autres fichiers (activeplay.exe et option window.exe)???

            J'attends ta réponse avant de faire une bêtise, en regardant danser l'écran sous Windows Explorer...

            Patrick
            0
            1. Contributeur
              Re,

              Effectivement j'ai fait une ptite erreur

              Supprime ce fichier :

              C:\Documents and Settings\All Users\Application Data\glueflagobjskip\DOES_EACH.exe

              Mais en connais-tu la provenance de ce fichier ?
              0
              1. Absolument aucune idée de l'origine. Si j'en crois Windows explorer, il aurait été créé le 27 mars dernier (alors que le problème remonte à plus longtemps). Je suppose que c'est encore un machin qui s'est greffé à un fichier downloadé par ma fille...
                Je supprime donc le fichier et te fais signe du résultat.
                Patrick
                0
                1. Rien de neuf sous le soleil, l'écran swingue toujours autant...
                  Patrick
                  0
                  1. Contributeur
                    Re,

                    Je pense surtout a un dossier créer par le virus mais supprime juste le .exe on verra plus tard si il faut supprimer le dossier entierement.
                    0
                    1. Darkkiller,
                      J'ai éliminé l'ensemble de la directory hier soir.
                      Pas de changement. Je suppose qu'il doit y avoir un Trojan caché quelque part dans le système.
                      Patrick
                      0
                  2. Contributeur
                    RE,

                    scan kaspersky https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr

                    Clic sur l'image Kaspersky Online Scanner
                    Clic sur J'accepte
                    Installes le ActiveX
                    Tu attends que la mise à jour se termine, une fois terminé,
                    clic sur Suivant
                    Clic sur Paramètres d'analyse
                    Coche la case Étendue >> Ok
                    Clic sur Poste de travail pour faire un scan complet
                    Une fois le scan fini à 100%, clic sur Enregistrer rapport
                    sous...
                    Enregistrer le rapport au format .txt (en nom tu mets rapport ou
                    ce que tu veux et en type tu choisis fichier texte (*.txt)
                    Tu ouvres le fichier que tu viens de sauvegarder, copie et colle
                    le rapport ici si tu es infecté
                    0
                    1. Le PC se bloque sur l'écran ou il faut accepter (alors que l'application tourne correctement sur mon portable, connecté au même hub). Impossible d'aller plus loin, va comprendre pourquoi,
                      Patrick
                      0
                      1. Contributeur
                        RE,

                        Autre scan : https://www.bitdefender.fr/

                        Clique en bas a gauche sur bitdefender online scanner et accepte tout les installations ainsi que les controles Actives X.
                        0
                        1. Celui-là fonctionne.
                          Analyse en cours, résultats attendus dans 30 minutes mais çà grouille de Trojans...
                          Je te tiens au courant si j'ai du mal à exporter le log car l'écran est en forme olympique aujourd'hui et tente de battre le record du nombre d'oscillations à la minute...
                          Patrick
                          0
                          1. Analyse complète : 35 fichiers infectés par les Trojan si j'en crois le rapport.
                            J'attends avec impatience to analyse du fichier.txt ci-dessous (car je pars pour une semaine aux USA demain - idée de software antivirus que je peux acheter là-bas en remplacement du Norton-passoire ou téléchargement suffit?)

                            Bonne lecture de ce qui ressemble à du chinois pour moi.
                            En attendant, l'écran a toujours la tremblotte mais moins que tout à l'heure

                            <HTML>
                            <HEAD>
                            <TITLE>BitDefender Online Scanner - Rapport d'analyse</TITLE>
                            <META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
                            </HEAD>
                            <BODY BGCOLOR=#FFFFFF leftmargin="10" marginwidth="0" topmargin="20" marginheight="0" >

                            <table align="center" border="0" cellpadding="0" cellspacing="0" width="90%">
                            <tr>
                            <td width="458">
                            <p><font face="Arial" color=red><span style="font-size:14pt;"><b>BitDefender Online Scanner</b></span></font></p>
                            </td>
                            <td width="40%">
                            <p> </p>
                            </td>
                            <td width="10%">
                            <p> </p>
                            </td>
                            </tr>
                            <tr>
                            <td colspan="3" width="912">
                            <p><font face="Arial"><span style="font-size:11pt;"><B>Rapport d'analyse généré à: Sat, Apr 14, 2007 - 12:31:13</b></span></font></p>
                            </td>
                            </tr>

                            <tr>
                            <td width="458">
                            <p><font face="Arial"><span style="font-size:11pt;"><B> </b></span></font></p>
                            </td>
                            <td width="40%">
                            <p> </p>
                            </td>
                            <td width="10%">
                            <p> </p>
                            </td>
                            </tr>

                            <tr>
                            <td width="458">
                            <p><font face="Arial"><span style="font-size:11pt;"><B>Voie d'analyse: </b></span><span style="font-size:10pt;">C:\;D:\;E:\;F:\;</span></font></p>
                            </td>
                            <td width="40%">
                            <p> </p>
                            </td>
                            <td width="10%">
                            <p> </p>
                            </td>
                            </tr>

                            <tr>
                            <td width="458">
                            <p><font face="Arial"><span style="font-size:11pt;"><B> </b></span></font></p>
                            </td>
                            <td width="40%">
                            <p> </p>
                            </td>
                            <td width="10%">
                            <p> </p>
                            </td>
                            </tr>

                            <tr>
                            <td width="458">
                            <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
                            <tr>
                            <td width="451" colspan="2" bgcolor="#CCCCCC">
                            <p><font face="Arial" size="2"><B>Statistiques</b></font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Temps</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">01:00:20</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Fichiers</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">522452</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Directoires</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">6896</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Secteurs de boot</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">2</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Archives</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">3093</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Paquets programmes</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">71445</font></p>
                            </td>
                            </tr>
                            </table>
                            </td>
                            <td width="40%">
                            <p> </p>
                            </td>
                            <td width="10%">
                            <p> </p>
                            </td>
                            </tr>

                            <tr>
                            <td width="458">
                            <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
                            <tr>
                            <td width="451" colspan="2" bgcolor="#CCCCCC">
                            <p><font face="Arial" size="2"><B>Résultats</b></font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Virus identifiés</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">2</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Fichiers infectés</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">35</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Fichiers suspects</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">0</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Avertissements</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">0</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Désinfectés</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">0</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Fichiers effacés</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">40</font></p>
                            </td>
                            </tr>
                            </table>
                            </td>
                            <td width="40%">
                            <p> </p>
                            </td>
                            <td width="10%">
                            <p> </p>
                            </td>
                            </tr>

                            <tr>
                            <td width="458">
                            <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
                            <tr>
                            <td width="451" colspan="2" bgcolor="#CCCCCC">
                            <p><font face="Arial" size="2"><B>Info sur les moteurs</b></font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Définition virus</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">485905</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Version des moteurs</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">AVCORE v1.0 (build 2397) (i386) (Feb 8 2007 14:24:08)</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Analyse des plugins</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">14</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Archive des plugins</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">38</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Unpack des plugins</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">6</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">E-mail plugins</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">6</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Système plugins</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">1</font></p>
                            </td>
                            </tr>
                            </table>
                            </td>
                            <td width="40%">
                            <p> </p>
                            </td>
                            <td width="10%">
                            <p> </p>
                            </td>
                            </tr>

                            <tr>
                            <td width="458">
                            <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
                            <tr>
                            <td width="451" colspan="2" bgcolor="#CCCCCC">
                            <p><font face="Arial" size="2"><B>Paramètres d'analyse</b></font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Première action</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">Désinfecté</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Seconde Action</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">Supprimé</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Heuristique</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">Oui</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Acceptez les avertissements</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">Oui</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Extensions analysées</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">*;</font></p>
                            </td>
                            </tr>

                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Excludez les extensions</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2"> </font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Analyse d'emails</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">Oui</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Analyse des Archives</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">Oui</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Analyser paquets programmes</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">Oui</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Analyse des fichiers</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">Oui</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Analyse de boot</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">Oui</font></p>
                            </td>
                            </tr>
                            </table>
                            </td>
                            <td width="40%">
                            <p> </p>
                            </td>
                            <td width="10%">
                            <p> </p>
                            </td>
                            </tr>

                            <tr>
                            <td colspan=2>  
                            <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
                            <tr>
                            <td width="252" bgcolor="#CCCCCC">
                            <p><font face="Arial" size="2"><B>Fichier analysé</b></font></p>
                            </td>
                            <td width="195" bgcolor="#CCCCCC" align="right">
                            <p align="left"><b><font size="2" face="Arial"> Statut</font></b></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\Documents and Settings\Mégane\Application Data\Dashnewfunk\bend locks.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Infecté par: Trojan.FatObfus.Gen</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\Documents and Settings\Mégane\Application Data\Dashnewfunk\bend locks.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Echec de la désinfection</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\Documents and Settings\Mégane\Application Data\Dashnewfunk\bend locks.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Supprimé</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\Documents and Settings\Mégane\Application Data\Dashnewfunk\IDLE BIND CREATIVE.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Infecté par: Trojan.FatObfus.Gen</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\Documents and Settings\Mégane\Application Data\Dashnewfunk\IDLE BIND CREATIVE.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Echec de la désinfection</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\Documents and Settings\Mégane\Application Data\Dashnewfunk\IDLE BIND CREATIVE.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Supprimé</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\Documents and Settings\Mégane\Application Data\Dashnewfunk\ozxbvmpx.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Infecté par: Trojan.FatObfus.Gen</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\Documents and Settings\Mégane\Application Data\Dashnewfunk\ozxbvmpx.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Echec de la désinfection</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\Documents and Settings\Mégane\Application Data\Dashnewfunk\ozxbvmpx.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Supprimé</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\Documents and Settings\Mégane\Application Data\Dashnewfunk\qkaswpsi.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Infecté par: Trojan.FatObfus.Gen</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\Documents and Settings\Mégane\Application Data\Dashnewfunk\qkaswpsi.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Echec de la désinfection</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\Documents and Settings\Mégane\Application Data\Dashnewfunk\qkaswpsi.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Supprimé</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\Documents and Settings\Mégane\Application Data\Dashnewfunk\second file trust great.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Infecté par: Trojan.FatObfus.Gen</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\Documents and Settings\Mégane\Application Data\Dashnewfunk\second file trust great.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Echec de la désinfection</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\Documents and Settings\Mégane\Application Data\Dashnewfunk\second file trust great.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Supprimé</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\Documents and Settings\Mégane\Application Data\Dashnewfunk\sshvntmc.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Infecté par: Trojan.FatObfus.Gen</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\Documents and Settings\Mégane\Application Data\Dashnewfunk\sshvntmc.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Echec de la désinfection</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\Documents and Settings\Mégane\Application Data\Dashnewfunk\sshvntmc.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Supprimé</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\Program Files\Adverts\uninst.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Infecté par: Trojan.FatObfus.Gen</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\Program Files\Adverts\uninst.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Echec de la désinfection</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\Program Files\Adverts\uninst.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Supprimé</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\03EE7060.t$m=>(Quarantine-2)</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Infecté par: Trojan.Downloader.Banload.ADP</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\03EE7060.t$m=>(Quarantine-2)</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Echec de la désinfection</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\03EE7060.t$m=>(Quarantine-2)</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Supprimé</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2FC95AE1.exe=>(Quarantine-2)</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Infecté par: Trojan.FatObfus.Gen</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2FC95AE1.exe=>(Quarantine-2)</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Echec de la désinfection</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2FC95AE1.exe=>(Quarantine-2)</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Supprimé</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\32CE65F4.exe=>(Quarantine-2)</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Infecté par: Trojan.Downloader.Banload.ADP</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\32CE65F4.exe=>(Quarantine-2)</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Echec de la désinfection</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\32CE65F4.exe=>(Quarantine-2)</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Supprimé</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\RECYCLER\S-1-5-21-1606980848-1417001333-725345543-1004\Dc16.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Infecté par: Trojan.FatObfus.Gen</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\RECYCLER\S-1-5-21-1606980848-1417001333-725345543-1004\Dc16.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Echec de la désinfection</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\RECYCLER\S-1-5-21-1606980848-1417001333-725345543-1004\Dc16.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Supprimé</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\RECYCLER\S-1-5-21-1606980848-1417001333-725345543-1004\Dc55.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Infecté par: Trojan.FatObfus.Gen</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\RECYCLER\S-1-5-21-1606980848-1417001333-725345543-1004\Dc55.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Echec de la désinfection</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\RECYCLER\S-1-5-21-1606980848-1417001333-725345543-1004\Dc55.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Supprimé</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\RECYCLER\S-1-5-21-1606980848-1417001333-725345543-1004\Dc56\Activeplay.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Infecté par: Trojan.FatObfus.Gen</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\RECYCLER\S-1-5-21-1606980848-1417001333-725345543-1004\Dc56\Activeplay.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Echec de la désinfection</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\RECYCLER\S-1-5-21-1606980848-1417001333-725345543-1004\Dc56\Activeplay.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Supprimé</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\RECYCLER\S-1-5-21-1606980848-1417001333-725345543-1004\Dc56\OPTION WINDOW.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Infecté par: Trojan.FatObfus.Gen</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\RECYCLER\S-1-5-21-1606980848-1417001333-725345543-1004\Dc56\OPTION WINDOW.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Echec de la désinfection</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\RECYCLER\S-1-5-21-1606980848-1417001333-725345543-1004\Dc56\OPTION WINDOW.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Supprimé</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP190\A0042511.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Infecté par: Trojan.FatObfus.Gen</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP190\A0042511.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Echec de la désinfection</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP190\A0042511.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Supprimé</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP199\A0045170.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Infecté par: Trojan.FatObfus.Gen</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP199\A0045170.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Echec de la désinfection</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP199\A0045170.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Supprimé</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP199\A0045171.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Infecté par: Trojan.FatObfus.Gen</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP199\A0045171.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Echec de la désinfection</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP199\A0045171.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Supprimé</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP203\A0046583.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Infecté par: Trojan.FatObfus.Gen</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP203\A0046583.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Echec de la désinfection</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP203\A0046583.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Supprimé</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP203\A0047006.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Infecté par: Trojan.FatObfus.Gen</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP203\A0047006.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Echec de la désinfection</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP203\A0047006.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Supprimé</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP203\A0047007.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Infecté par: Trojan.FatObfus.Gen</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP203\A0047007.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Echec de la désinfection</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP203\A0047007.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Supprimé</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP203\A0047008.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Infecté par: Trojan.FatObfus.Gen</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP203\A0047008.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Echec de la désinfection</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP203\A0047008.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Supprimé</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP203\A0047009.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Infecté par: Trojan.FatObfus.Gen</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP203\A0047009.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Echec de la désinfection</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP203\A0047009.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Supprimé</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP208\A0047932.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Infecté par: Trojan.FatObfus.Gen</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP208\A0047932.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Echec de la désinfection</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP208\A0047932.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Supprimé</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP208\A0047933.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Infecté par: Trojan.FatObfus.Gen</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP208\A0047933.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Echec de la désinfection</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP208\A0047933.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Supprimé</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP208\A0047934.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Infecté par: Trojan.FatObfus.Gen</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP208\A0047934.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Echec de la désinfection</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP208\A0047934.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Supprimé</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP208\A0047935.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Infecté par: Trojan.FatObfus.Gen</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP208\A0047935.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Echec de la désinfection</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP208\A0047935.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Supprimé</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP208\A0047936.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Infecté par: Trojan.FatObfus.Gen</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP208\A0047936.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Echec de la désinfection</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP208\A0047936.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Supprimé</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP208\A0047937.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Infecté par: Trojan.FatObfus.Gen</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP208\A0047937.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Echec de la désinfection</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP208\A0047937.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Supprimé</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP208\A0047938.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Infecté par: Trojan.FatObfus.Gen</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP208\A0047938.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Echec de la désinfection</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP208\A0047938.exe</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Supprimé</font></p>
                            </td>
                            </tr><tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">C:\System Volume Information\_restore{BEC86B26-C033-4607-86FA-2FE07762C8E9}\RP208\A0047939.exe=>(Quarantine-2)</font></p>
                            </td>
                            <td width="43%" align="left">
                            <p><font face="Arial" size="2">Infecté par: Trojan.FatObfus.Gen</font></p>
                            </td>
                            </tr><tr>
                            0
                            1. Contributeur
                              Re,
                              Vide ta corbeille, ta quarantaine de norton et on va creer un nouveau point de restauration :

                              ¤Désactive ta restauration système (uniquement si tu es sous XP):
                              Clic droit sur poste de travail puis,
                              propriété, tu cliques sur onglet restauration système
                              tu coches la case « désactiver la restauration » et applique.

                              Puis,

                              ¤Réactive ta restauration système (uniquement si tu es sous XP):
                              Clic droit sur poste de travail puis,
                              propriété, tu cliques sur onglet restauration système
                              tu décoches la case « désactiver la restauration » et applique.

                              Puis relance un scan BitDefender.

                              0
                              1. Si j'en crois Bitdefender, il n'y a plus de virus... mais le problème persiste au niveau de l'écran balladeur.
                                Patrick
                                0
                                1. Contributeur
                                  Re,

                                  Si il n'y as plus de virus c'est que c'est ton matériel qui a un problème alors pour cela je te conseille de te rendre dans la section Hardware du forum.
                                  0
                                  • 1
                                  • 2