Warning potential spyware operation

Résolu
Bonjour,
Même problème pour moi.
La fenêtre "warning potential spyware operation" qui s'ouvre.
Qqn peut m'aider svp ?
Merci d'avance.
Configuration: Windows XP
Internet Explorer 6.0

41 réponses

Résumé de la discussion

Une alerte apparaît avec la fenêtre 'warning potential spyware operation' sur Windows XP et Internet Explorer 6, et la discussion porte sur l'analyse des logs HijackThis pour identifier les éléments malveillants. Plusieurs participants proposent des étapes préventives et de vérification, notamment désactiver puis réactiver la restauration système, relancer un scan en ligne et partager le rapport complet pour interprétation. Des solutions variées sont évoquées, allant du recours à Bitdefender ou à des rapports Navilog/Navifix, jusqu'à la suppression des fichiers suspects et l'examen des éléments 'backdoor.hupigon' potentiels. En cas d'impossibilité d'exécution des outils en ligne, une approche consiste à télécharger et extraire manuellement des compressés Navilog1.zip puis ouvrir navilog1.bat pour générer le rapport fixnavi.txt localement.

Bobot (l’IA à votre service)
  1. Bonsoir,

    fais ceci :
    * Prendre connaissance du contenu du lien suivant: http://www.f-secure.com/products/license-terms/eult_fra.pdf
    * Vous avez donc pris connaissance et accepté les conditions d'utilisations du programme blacklight qui est inclus dans le dossier compressé navilog1.zip que vous allez télécharger.
    * Faire un clic droit sur ce lien : http://perso.orange.fr/il.mafioso/Navifix/Navilog1.zip
    * Enregistrez la cible (du lien) sous... et enregistrez-le sur le bureau.
    * Faire un clic droit sur navilog1.zip et choisir "tout extraire"
    * Double-cliquez sur navilog1.bat
    * Arriver au menu principal, choisir l'option 1 et valider.
    * Patientez jusqu'au message : Analyse Termine le ...
    * Le rapport sera en outre sauvegardé à la racine du disque (fixnavi.txt)
    et postes le rapport.
    0
    1. Bonjour,
      D'abord merci de bien vouloir t'occuper de moi.
      Voici le rapport.

      Search Navipromo version 3.2.1 commencé le 15/10/2007 à 6:59:33,31

      !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
      !!! Poster ce rapport sur le forum pour le faire analyser !!!
      !!! Ne pas lancer la partie désinfection sans l'avis d'un spécialiste !!!

      Fix lancé depuis C:\Program Files\navilog1
      Mise a jour le 09.10.2007 a 18h00 by IL-MAFIOSO

      Microsoft Windows XP [version 5.1.2600]
      Internet Explorer : 6.0.2800.1106

      *** Recherche Programmes installes ***

      *** Recherche dossiers dans C:\WINDOWS ***

      *** Recherche dossiers dans C:\Program Files ***

      *** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***

      *** Recherche dossiers dans C:\Documents and Settings\Propri‚taire\Application Data ***

      *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

      *** Recherche avec Catchme-rootkit/stealth malware detector by gmer ***
      pour + d'infos : http://www.gmer.net

      Aucun fichier trouvé dans :

      - C:\WINDOWS\system32
      - C:\DOCUME~1\PROPRI~1\LOCALS~1\APPLIC~1

      *** Recherche avec GenericNaviSearch ***
      !!! Tous Ces résultats peuvent révéler des fichiers légitimes !!!
      !!! A verifier impérativement avant toute suppression manuelle !!!

      * Scan C:\WINDOWS\system32 *

      * Scan C:\DOCUME~1\PROPRI~1\LOCALS~1\APPLIC~1 *

      *** Recherche fichiers ***

      *** Recherche cles registre ***

      *** Module de Recherche complémentaire ***
      (Recherche fichiers spécifiques)

      1)Recherche fichiers connus:

      2)Recherche Heuristique :

      3)Recherche Certificats :

      Certificat Egroup absent !

      *** Analyse Terminé le 15/10/2007 à 7:00:20,89 ***
      0
      1. Bonjour,
        Voici le rapport de AVG.
        Par contre impossible de faire le scan en ligne. Le message suivant apparaît : " Could not load the Online Scanner! "
        J'ai aussi quand j'ouvre une page web le message suivant : "les paramêtres de sécurité actuels ne vous permettent pas d'effectuer les contrôles ActiveX de cette page..."

        Search Navipromo version 3.2.1 commencé le 15/10/2007 à 6:59:33,31

        !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
        !!! Poster ce rapport sur le forum pour le faire analyser !!!
        !!! Ne pas lancer la partie désinfection sans l'avis d'un spécialiste !!!

        Fix lancé depuis C:\Program Files\navilog1
        Mise a jour le 09.10.2007 a 18h00 by IL-MAFIOSO

        Microsoft Windows XP [version 5.1.2600]
        Internet Explorer : 6.0.2800.1106

        *** Recherche Programmes installes ***

        *** Recherche dossiers dans C:\WINDOWS ***

        *** Recherche dossiers dans C:\Program Files ***

        *** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***

        *** Recherche dossiers dans C:\Documents and Settings\Propri‚taire\Application Data ***

        *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

        *** Recherche avec Catchme-rootkit/stealth malware detector by gmer ***
        pour + d'infos : http://www.gmer.net

        Aucun fichier trouvé dans :

        - C:\WINDOWS\system32
        - C:\DOCUME~1\PROPRI~1\LOCALS~1\APPLIC~1

        *** Recherche avec GenericNaviSearch ***
        !!! Tous Ces résultats peuvent révéler des fichiers légitimes !!!
        !!! A verifier impérativement avant toute suppression manuelle !!!

        * Scan C:\WINDOWS\system32 *

        * Scan C:\DOCUME~1\PROPRI~1\LOCALS~1\APPLIC~1 *

        *** Recherche fichiers ***

        *** Recherche cles registre ***

        *** Module de Recherche complémentaire ***
        (Recherche fichiers spécifiques)

        1)Recherche fichiers connus:

        2)Recherche Heuristique :

        3)Recherche Certificats :

        Certificat Egroup absent !

        *** Analyse Terminé le 15/10/2007 à 7:00:20,89 ***

        Merci de ton aide !
        0
        1. euh non ça c'est un rapport navilog...
          0
          1. Désolé, voici le bon rapport

            AVG Anti-Spyware - Rapport d'analyse
            ---------------------------------------------------------

            + Créé à: 20:07:53 15/10/2007

            + Résultat de l'analyse:

            C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119231.exe -> Backdoor.Hupigon : Aucune action entreprise.
            C:\Documents and Settings\Propriétaire\Cookies\propriétaire@adtech[1].txt -> TrackingCookie.Adtech : Aucune action entreprise.
            C:\Documents and Settings\Propriétaire\Cookies\propriétaire@search.msn[2].txt -> TrackingCookie.Msn : Aucune action entreprise.
            C:\Documents and Settings\Propriétaire\Cookies\propriétaire@ssl-hints.netflame[2].txt -> TrackingCookie.Netflame : Aucune action entreprise.
            C:\Documents and Settings\Propriétaire\Cookies\propriétaire@smartadserver[2].txt -> TrackingCookie.Smartadserver : Aucune action entreprise.

            Fin du rapport
            0
            1. pas grave,

              on refait la meme chose en lui faisant supprimer les fichiers... ça serait bien qu'il nous débarasse de backdoor.hupigon... meme si c'est dans les fichiers de restauration system.

              et puis j'aimerai voir le rapport de bitdefender
              0
              1. Ok je refais l'analyse et vais supprimer ce qu'il y a à supprimer.
                Par contre impossible de lancer bitdefender. Y a t il une autre solution ?
                0
                1. essai en un autre : http://www.zebulon.fr/outils/antivirus/antivirus-en-ligne.php
                  0
                  1. J'ai l'impression qu'aucun anti virus en ligne ne fonctionne.
                    Est ce en rapport avec le message "les paramêtres de sécurité actuels ne vous permettent pas d'effectuer les contrôles ActiveX de cette page..."
                    0
                    1. ok
                      Télécharger hijackthis

                      Utilisation :

                      * L'installer dans un dossier prévu à cet effet.
                      o Par exemple, C:\HijackThis
                      o Choisis l'option "do a system scan and save a logfile"; un rapport va être généré…
                      o Copier/coller le rapport sur le forum virus/sécurité.
                      0
                      1. Comme demandé, rapport Hijack this

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 21:37:48, on 15/10/2007
                        Platform: Windows XP SP1 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
                        Boot mode: Normal

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\System32\Ati2evxx.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\WINDOWS\system32\Ati2evxx.exe
                        C:\WINDOWS\Explorer.exe
                        C:\WINDOWS\System32\printer.exe
                        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                        C:\WINDOWS\System32\gearsec.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
                        C:\windows\system\hpsysdrv.exe
                        C:\HP\KBD\KBD.EXE
                        C:\Program Files\iTunes\iTunesHelper.exe
                        C:\WINDOWS\AGRSMMSG.exe
                        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                        C:\WINDOWS\ALCXMNTR.EXE
                        C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
                        C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
                        C:\Program Files\Logitech\Video\LogiTray.exe
                        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        C:\WINDOWS\System32\LVComS.exe
                        C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
                        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        C:\Program Files\iPod\bin\iPodService.exe
                        C:\Program Files\MSN Messenger\msnmsgr.exe
                        C:\PROGRA~1\PRESAR~1\Presario\XPHWWRS4\plugin\bin\pchbutton.exe
                        C:\WINDOWS\System32\wuauclt.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=compaq-desktop.msn.com&ocid=HPDHP&pc=CPDTDF
                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q304&bd=presario&pf=desktop
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q304&bd=presario&pf=desktop
                        R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.surething.com/focus/expresslabeler/labels?af=VST-SON-01
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                        F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\System32\printer.exe
                        O2 - BHO: IEHlprObj Class - {ABCDECF0-4B15-11D1-ABED-709549C10000} - C:\WINDOWS\System32\vtr.dll
                        O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
                        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                        O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
                        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
                        O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                        O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                        O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
                        O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                        O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                        O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
                        O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                        O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
                        O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
                        O4 - HKLM\..\Run: [UpdateManager] "c:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
                        O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
                        O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\System32\NeroCheck.exe
                        O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
                        O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
                        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        O4 - HKLM\..\Run: [ALDI_FotoSuite_Download] "C:\Program Files\ALDI Service Photo\ALDI_Service_Photo\FotoSuite.exe" /autorun
                        O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                        O4 - HKLM\..\Run: [WinAVX] C:\WINDOWS\System32\WinAvXX.exe
                        O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
                        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                        O4 - HKCU\..\Run: [Internet Download Accelerator] C:\Program Files\IDA\ida.exe -autorun
                        O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
                        O4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\PRESAR~1\Presario\XPHWWRS4\plugin\bin\pchbutton.exe
                        O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
                        O4 - HKCU\..\Run: [WinAVX] C:\WINDOWS\System32\WinAvXX.exe
                        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                        O4 - Startup: system.exe
                        O4 - Global Startup: autorun.exe
                        O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                        O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
                        O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
                        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
                        O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                        O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                        O16 - DPF: {64311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab
                        O20 - AppInit_DLLs: C:\WINDOWS\System32\sulimo.dat
                        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
                        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                        O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\ALDI Service Photo\Common\Database\bin\fbserver.exe
                        O23 - Service: Service de sécurité matérielle (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
                        O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
                        0
                        1. Bon...
                          il va y avoir un peu de travail....

                          1/ relances hijackthis et coches ces lignes :
                          F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\System32\printer.exe
                          O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
                          O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
                          O16 - DPF: {64311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab
                          puis tu cliques sur fix checked.

                          2/ tu vas faire ces manip : http://www.malekal.com/WinAntiVirusPro2007_winavxmy.php
                          et postes les rapports
                          0
                          1. Bonjour,
                            J'ai fait les différentes manips.
                            Je n'ai toujours pas réussi à faire un scan en ligne et n'ai pu nettoyer le registre avec regcleaner.
                            Le message warning potential spyware operation semble avoir disparru.
                            Sauf que j'ai toujours les problèmes suivants :
                            1) qd j'ouvre une page web le message suivant apparaît :les paramêtres de sécurité actuels ne vous permettent pas d'effectuer les contrôles ActiveX de cette page..."
                            2) je n'ai plus accès aux propriétés du poste de travail et au gestionnaire de tâche. le message suivant apparaît : Cette opération a été annulée en raison des restrictions en vigueur sur cet ordinateur...
                            3) qd Windows démarre j'ai le message suivant : Windows ne trouve pas C:WINDOWS/SYSTEM32/printer.exe. Normal vu que c'est une ligne qu'on a supprimé avec HiJack This.

                            Peux tu m'aider pour tout ça stp ?
                            Merci d'avance.
                            0
                            1. repostes un rapport hijack pour voir ou on en est.

                              pour ton scan en ligne il va falloir que tu autorise les controles active x dans tes paramétres internet
                              pour ça tu vas dans outils / options internet, onglet sécurité
                              0
                              1. Bjr,
                                Voici le new rapport Hijack
                                Merci

                                Logfile of Trend Micro HijackThis v2.0.2
                                Scan saved at 07:38:45, on 17/10/2007
                                Platform: Windows XP SP1 (WinNT 5.01.2600)
                                MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
                                Boot mode: Normal

                                Running processes:
                                C:\WINDOWS\System32\smss.exe
                                C:\WINDOWS\system32\winlogon.exe
                                C:\WINDOWS\system32\services.exe
                                C:\WINDOWS\system32\lsass.exe
                                C:\WINDOWS\System32\Ati2evxx.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                C:\WINDOWS\system32\spoolsv.exe
                                C:\WINDOWS\system32\Ati2evxx.exe
                                C:\WINDOWS\Explorer.exe
                                C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                C:\WINDOWS\System32\gearsec.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
                                C:\windows\system\hpsysdrv.exe
                                C:\HP\KBD\KBD.EXE
                                C:\WINDOWS\AGRSMMSG.exe
                                C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                                C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
                                C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
                                C:\Program Files\QuickTime\qttask.exe
                                C:\Program Files\Logitech\Video\LogiTray.exe
                                C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                                C:\Program Files\MSN Messenger\msnmsgr.exe
                                C:\WINDOWS\System32\LVComS.exe
                                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                C:\PROGRA~1\PRESAR~1\Presario\XPHWWRS4\plugin\bin\pchbutton.exe
                                C:\WINDOWS\System32\wuauclt.exe
                                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/...
                                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/...
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://neufportail.fr/
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/...
                                R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.surething.com/focus/expresslabeler/labels?af=VST-SON-01
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\System32\printer.exe
                                O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                O2 - BHO: IEHlprObj Class - {ABCDECF0-4B15-11D1-ABED-709549C10000} - C:\WINDOWS\System32\vtr.dll (file missing)
                                O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
                                O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                                O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
                                O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
                                O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                                O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                                O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
                                O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                                O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                                O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
                                O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                                O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                                O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
                                O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
                                O4 - HKLM\..\Run: [UpdateManager] "c:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
                                O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
                                O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
                                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\System32\NeroCheck.exe
                                O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
                                O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
                                O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                O4 - HKLM\..\Run: [ALDI_FotoSuite_Download] "C:\Program Files\ALDI Service Photo\ALDI_Service_Photo\FotoSuite.exe" /autorun
                                O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                                O4 - HKLM\..\Run: [WinAVX] C:\WINDOWS\System32\WinAvXX.exe
                                O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
                                O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                                O4 - HKCU\..\Run: [Internet Download Accelerator] C:\Program Files\IDA\ida.exe -autorun
                                O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
                                O4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\PRESAR~1\Presario\XPHWWRS4\plugin\bin\pchbutton.exe
                                O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
                                O4 - HKCU\..\Run: [WinAVX] C:\WINDOWS\System32\WinAvXX.exe
                                O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                                O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
                                O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
                                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
                                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
                                O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
                                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                                O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                                O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                                O20 - AppInit_DLLs: C:\WINDOWS\System32\sulimo.dat
                                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
                                O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\ALDI Service Photo\Common\Database\bin\fbserver.exe
                                O23 - Service: Service de sécurité matérielle (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
                                O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
                                0
                                1. on va refaire les manips, tu vas poster tous les rapports,

                                  1/ relances hijackthis et coches ces lignes :

                                  F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\System32\printer.exe
                                  O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
                                  O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

                                  puis tu cliques sur fix checked.

                                  2/ http://www.malekal.com/WinAntiVirusPro2007_winavxmy.php

                                  0
                                  1. Pour info, voici le rapport de bitdefender
                                    Fichier analysé
                                    Statut

                                    C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage\system.exe
                                    Infecté par: Trojan.Peed.JZ

                                    C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage\system.exe
                                    Echec de la désinfection

                                    C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage\system.exe
                                    Supprimé

                                    C:\Documents and Settings\Propriétaire\Bureau\NedroFun pour Mise à jour Hebdo avec fichier nfs.exe
                                    Infecté par: Trojan.Genlot.LI

                                    C:\Documents and Settings\Propriétaire\Bureau\NedroFun pour Mise à jour Hebdo avec fichier nfs.exe
                                    Echec de la désinfection

                                    C:\Documents and Settings\Propriétaire\Bureau\NedroFun pour Mise à jour Hebdo avec fichier nfs.exe
                                    Supprimé

                                    C:\Documents and Settings\Propriétaire\Bureau\NedroFun.exe
                                    Infecté par: Trojan.Genlot.LI

                                    C:\Documents and Settings\Propriétaire\Bureau\NedroFun.exe
                                    Echec de la désinfection

                                    C:\Documents and Settings\Propriétaire\Bureau\NedroFun.exe
                                    Supprimé

                                    C:\Documents and Settings\Propriétaire\Local Settings\Application Data\Identities\{848C1443-FEA4-4399-BE14-0F9436317B56}\Microsoft\Outlook Express\Boîte de réception.dbx=>(message 110)=>[Subject: =?iso-8859-1?Q?pour_votre_d=E9mod.?=][Date: Fri, 15 Sep 2006 22:21:02 +0200]=>(MIME part)=>complet 9000NG4.zip=>NedroFun pour Mise ? jour Hebdo avec fichier nfs.exe
                                    Infecté par: Trojan.Genlot.LI

                                    C:\Documents and Settings\Propriétaire\Local Settings\Application Data\Identities\{848C1443-FEA4-4399-BE14-0F9436317B56}\Microsoft\Outlook Express\Boîte de réception.dbx=>(message 110)=>[Subject: =?iso-8859-1?Q?pour_votre_d=E9mod.?=][Date: Fri, 15 Sep 2006 22:21:02 +0200]=>(MIME part)=>complet 9000NG4.zip=>NedroFun pour Mise ? jour Hebdo avec fichier nfs.exe
                                    Echec de la désinfection

                                    C:\Documents and Settings\Propriétaire\Local Settings\Application Data\Identities\{848C1443-FEA4-4399-BE14-0F9436317B56}\Microsoft\Outlook Express\Boîte de réception.dbx=>(message 110)=>[Subject: =?iso-8859-1?Q?pour_votre_d=E9mod.?=][Date: Fri, 15 Sep 2006 22:21:02 +0200]=>(MIME part)=>complet 9000NG4.zip=>NedroFun pour Mise ? jour Hebdo avec fichier nfs.exe
                                    Supprimé

                                    C:\Documents and Settings\Propriétaire\Local Settings\Application Data\Identities\{848C1443-FEA4-4399-BE14-0F9436317B56}\Microsoft\Outlook Express\Boîte de réception.dbx=>(message 110)=>[Subject: =?iso-8859-1?Q?pour_votre_d=E9mod.?=][Date: Fri, 15 Sep 2006 22:21:02 +0200]=>(MIME part)=>complet 9000NG4.zip
                                    Mis à jour

                                    C:\Documents and Settings\Propriétaire\Local Settings\Application Data\Identities\{848C1443-FEA4-4399-BE14-0F9436317B56}\Microsoft\Outlook Express\Boîte de réception.dbx=>(message 110)=>[Subject: =?iso-8859-1?Q?pour_votre_d=E9mod.?=][Date: Fri, 15 Sep 2006 22:21:02 +0200]=>(MIME part)
                                    Mis à jour

                                    C:\Documents and Settings\Propriétaire\Local Settings\Application Data\Identities\{848C1443-FEA4-4399-BE14-0F9436317B56}\Microsoft\Outlook Express\Boîte de réception.dbx=>(message 110)
                                    Mis à jour

                                    C:\Documents and Settings\Propriétaire\Local Settings\Application Data\Identities\{848C1443-FEA4-4399-BE14-0F9436317B56}\Microsoft\Outlook Express\Boîte de réception.dbx
                                    Echec de la mise à jour

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP389\S0108314.Acl
                                    Infecté par: Win32.MyPics.A@mm

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP389\S0108314.Acl
                                    Echec de la désinfection

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP389\S0108314.Acl
                                    Supprimé

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119129.exe
                                    Infecté par: Trojan.Peed.JZ

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119129.exe
                                    Echec de la désinfection

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119129.exe
                                    Supprimé

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119204.exe
                                    Infecté par: Trojan.Peed.JZ

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119204.exe
                                    Echec de la désinfection

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119204.exe
                                    Supprimé

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119205.exe
                                    Infecté par: Trojan.Peed.JZ

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119205.exe
                                    Echec de la désinfection

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119205.exe
                                    Supprimé

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119206.exe
                                    Infecté par: Trojan.Peed.JZ

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119206.exe
                                    Echec de la désinfection

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119206.exe
                                    Supprimé

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119216.exe
                                    Infecté par: Trojan.Peed.JZ

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119216.exe
                                    Echec de la désinfection

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119216.exe
                                    Supprimé

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119217.exe
                                    Infecté par: Trojan.Peed.JZ

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119217.exe
                                    Echec de la désinfection

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119217.exe
                                    Supprimé

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119218.exe
                                    Infecté par: Trojan.Peed.JZ

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119218.exe
                                    Echec de la désinfection

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119218.exe
                                    Supprimé

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119232.exe
                                    Infecté par: Trojan.Peed.JZ

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119232.exe
                                    Echec de la désinfection

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119232.exe
                                    Supprimé

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119262.exe
                                    Infecté par: Trojan.Peed.JZ

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119262.exe
                                    Echec de la désinfection

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119262.exe
                                    Supprimé

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119263.exe
                                    Infecté par: Trojan.Peed.JZ

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119263.exe
                                    Echec de la désinfection

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119263.exe
                                    Supprimé

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119264.exe
                                    Infecté par: Trojan.Peed.JZ

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119264.exe
                                    Echec de la désinfection

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119264.exe
                                    Supprimé

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119281.exe
                                    Infecté par: Trojan.Peed.JZ

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119281.exe
                                    Echec de la désinfection

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119281.exe
                                    Supprimé

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119282.exe
                                    Infecté par: Trojan.Peed.JZ

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119282.exe
                                    Echec de la désinfection

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119282.exe
                                    Supprimé

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119283.exe
                                    Infecté par: Trojan.Peed.JZ

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119283.exe
                                    Echec de la désinfection

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119283.exe
                                    Supprimé

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119303.exe
                                    Infecté par: Trojan.Peed.JZ

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119303.exe
                                    Echec de la désinfection

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119303.exe
                                    Supprimé

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119304.exe
                                    Infecté par: Trojan.Peed.JZ

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119304.exe
                                    Echec de la désinfection

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119304.exe
                                    Supprimé

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119305.exe
                                    Infecté par: Trojan.Peed.JZ

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119305.exe
                                    Echec de la désinfection

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119305.exe
                                    Supprimé

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119310.exe
                                    Infecté par: Trojan.Peed.JZ

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119310.exe
                                    Echec de la désinfection

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119310.exe
                                    Supprimé

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119318.exe
                                    Infecté par: Trojan.Peed.JZ

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119318.exe
                                    Echec de la désinfection

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119318.exe
                                    Supprimé

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119319.exe
                                    Infecté par: Trojan.Peed.JZ

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119319.exe
                                    Echec de la désinfection

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119319.exe
                                    Supprimé

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119320.exe
                                    Infecté par: Trojan.Peed.JZ

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119320.exe
                                    Echec de la désinfection

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119320.exe
                                    Supprimé

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119326.exe
                                    Infecté par: Trojan.Peed.JZ

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119326.exe
                                    Echec de la désinfection

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119326.exe
                                    Supprimé

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119327.exe
                                    Infecté par: Trojan.Peed.JZ

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119327.exe
                                    Echec de la désinfection

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119327.exe
                                    Supprimé

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119329.exe
                                    Infecté par: Trojan.Peed.JZ

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119329.exe
                                    Echec de la désinfection

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119329.exe
                                    Supprimé

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119334.exe
                                    Infecté par: Trojan.Peed.JZ

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119334.exe
                                    Echec de la désinfection

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119334.exe
                                    Supprimé

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119335.dll
                                    Infecté par: Trojan.Peed.JZ

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119335.dll
                                    Echec de la désinfection

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119335.dll
                                    Supprimé

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP449\A0119709.exe
                                    Infecté par: Trojan.Peed.JZ

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP449\A0119709.exe
                                    Echec de la désinfection

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP449\A0119709.exe
                                    Supprimé

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP449\A0119710.exe
                                    Infecté par: Trojan.Genlot.LI

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP449\A0119710.exe
                                    Echec de la désinfection

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP449\A0119710.exe
                                    Supprimé

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP449\A0119711.exe
                                    Infecté par: Trojan.Genlot.LI

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP449\A0119711.exe
                                    Echec de la désinfection

                                    C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP449\A0119711.exe
                                    Supprimé

                                    C:\WINDOWS\system32\drivers\etc\hosts.20071014-152116.backup
                                    Infecté par: Generic.Qhost.16934822

                                    C:\WINDOWS\system32\drivers\etc\hosts.20071014-152116.backup
                                    Echec de la désinfection

                                    C:\WINDOWS\system32\drivers\etc\hosts.20071014-152116.backup
                                    Supprimé

                                    C:\WINDOWS\system32\drivers\etc\hosts.20071014-152227.backup
                                    Infecté par: Generic.Qhost.EA61E6F9

                                    C:\WINDOWS\system32\drivers\etc\hosts.20071014-152227.backup
                                    Echec de la désinfection

                                    C:\WINDOWS\system32\drivers\etc\hosts.20071014-152227.backup
                                    Supprimé

                                    C:\WINDOWS\system32\drivers\etc\hosts.20071014-152228.backup
                                    Infecté par: Generic.Qhost.58CDE1B3

                                    C:\WINDOWS\system32\drivers\etc\hosts.20071014-152228.backup
                                    Echec de la désinfection

                                    C:\WINDOWS\system32\drivers\etc\hosts.20071014-152228.backup
                                    Supprimé

                                    C:\WINDOWS\system32\drivers\etc\hosts.20071014-152229.backup
                                    Infecté par: Generic.Qhost.C553DA89

                                    C:\WINDOWS\system32\drivers\etc\hosts.20071014-152229.backup
                                    Echec de la désinfection

                                    C:\WINDOWS\system32\drivers\etc\hosts.20071014-152229.backup
                                    Supprimé
                                    0
                                    1. Pour info, voici le rapport de bitdefender
                                      Fichier analysé
                                      Statut

                                      C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage\system.exe
                                      Infecté par: Trojan.Peed.JZ

                                      C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage\system.exe
                                      Echec de la désinfection

                                      C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage\system.exe
                                      Supprimé

                                      C:\Documents and Settings\Propriétaire\Bureau\NedroFun pour Mise à jour Hebdo avec fichier nfs.exe
                                      Infecté par: Trojan.Genlot.LI

                                      C:\Documents and Settings\Propriétaire\Bureau\NedroFun pour Mise à jour Hebdo avec fichier nfs.exe
                                      Echec de la désinfection

                                      C:\Documents and Settings\Propriétaire\Bureau\NedroFun pour Mise à jour Hebdo avec fichier nfs.exe
                                      Supprimé

                                      C:\Documents and Settings\Propriétaire\Bureau\NedroFun.exe
                                      Infecté par: Trojan.Genlot.LI

                                      C:\Documents and Settings\Propriétaire\Bureau\NedroFun.exe
                                      Echec de la désinfection

                                      C:\Documents and Settings\Propriétaire\Bureau\NedroFun.exe
                                      Supprimé

                                      C:\Documents and Settings\Propriétaire\Local Settings\Application Data\Identities\{848C1443-FEA4-4399-BE14-0F9436317B56}\Microsoft\Outlook Express\Boîte de réception.dbx=>(message 110)=>[Subject: =?iso-8859-1?Q?pour_votre_d=E9mod.?=][Date: Fri, 15 Sep 2006 22:21:02 +0200]=>(MIME part)=>complet 9000NG4.zip=>NedroFun pour Mise ? jour Hebdo avec fichier nfs.exe
                                      Infecté par: Trojan.Genlot.LI

                                      C:\Documents and Settings\Propriétaire\Local Settings\Application Data\Identities\{848C1443-FEA4-4399-BE14-0F9436317B56}\Microsoft\Outlook Express\Boîte de réception.dbx=>(message 110)=>[Subject: =?iso-8859-1?Q?pour_votre_d=E9mod.?=][Date: Fri, 15 Sep 2006 22:21:02 +0200]=>(MIME part)=>complet 9000NG4.zip=>NedroFun pour Mise ? jour Hebdo avec fichier nfs.exe
                                      Echec de la désinfection

                                      C:\Documents and Settings\Propriétaire\Local Settings\Application Data\Identities\{848C1443-FEA4-4399-BE14-0F9436317B56}\Microsoft\Outlook Express\Boîte de réception.dbx=>(message 110)=>[Subject: =?iso-8859-1?Q?pour_votre_d=E9mod.?=][Date: Fri, 15 Sep 2006 22:21:02 +0200]=>(MIME part)=>complet 9000NG4.zip=>NedroFun pour Mise ? jour Hebdo avec fichier nfs.exe
                                      Supprimé

                                      C:\Documents and Settings\Propriétaire\Local Settings\Application Data\Identities\{848C1443-FEA4-4399-BE14-0F9436317B56}\Microsoft\Outlook Express\Boîte de réception.dbx=>(message 110)=>[Subject: =?iso-8859-1?Q?pour_votre_d=E9mod.?=][Date: Fri, 15 Sep 2006 22:21:02 +0200]=>(MIME part)=>complet 9000NG4.zip
                                      Mis à jour

                                      C:\Documents and Settings\Propriétaire\Local Settings\Application Data\Identities\{848C1443-FEA4-4399-BE14-0F9436317B56}\Microsoft\Outlook Express\Boîte de réception.dbx=>(message 110)=>[Subject: =?iso-8859-1?Q?pour_votre_d=E9mod.?=][Date: Fri, 15 Sep 2006 22:21:02 +0200]=>(MIME part)
                                      Mis à jour

                                      C:\Documents and Settings\Propriétaire\Local Settings\Application Data\Identities\{848C1443-FEA4-4399-BE14-0F9436317B56}\Microsoft\Outlook Express\Boîte de réception.dbx=>(message 110)
                                      Mis à jour

                                      C:\Documents and Settings\Propriétaire\Local Settings\Application Data\Identities\{848C1443-FEA4-4399-BE14-0F9436317B56}\Microsoft\Outlook Express\Boîte de réception.dbx
                                      Echec de la mise à jour

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP389\S0108314.Acl
                                      Infecté par: Win32.MyPics.A@mm

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP389\S0108314.Acl
                                      Echec de la désinfection

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP389\S0108314.Acl
                                      Supprimé

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119129.exe
                                      Infecté par: Trojan.Peed.JZ

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119129.exe
                                      Echec de la désinfection

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119129.exe
                                      Supprimé

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119204.exe
                                      Infecté par: Trojan.Peed.JZ

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119204.exe
                                      Echec de la désinfection

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119204.exe
                                      Supprimé

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119205.exe
                                      Infecté par: Trojan.Peed.JZ

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119205.exe
                                      Echec de la désinfection

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119205.exe
                                      Supprimé

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119206.exe
                                      Infecté par: Trojan.Peed.JZ

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119206.exe
                                      Echec de la désinfection

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119206.exe
                                      Supprimé

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119216.exe
                                      Infecté par: Trojan.Peed.JZ

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119216.exe
                                      Echec de la désinfection

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119216.exe
                                      Supprimé

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119217.exe
                                      Infecté par: Trojan.Peed.JZ

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119217.exe
                                      Echec de la désinfection

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119217.exe
                                      Supprimé

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119218.exe
                                      Infecté par: Trojan.Peed.JZ

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119218.exe
                                      Echec de la désinfection

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119218.exe
                                      Supprimé

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119232.exe
                                      Infecté par: Trojan.Peed.JZ

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119232.exe
                                      Echec de la désinfection

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119232.exe
                                      Supprimé

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119262.exe
                                      Infecté par: Trojan.Peed.JZ

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119262.exe
                                      Echec de la désinfection

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119262.exe
                                      Supprimé

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119263.exe
                                      Infecté par: Trojan.Peed.JZ

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119263.exe
                                      Echec de la désinfection

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119263.exe
                                      Supprimé

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119264.exe
                                      Infecté par: Trojan.Peed.JZ

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119264.exe
                                      Echec de la désinfection

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP446\A0119264.exe
                                      Supprimé

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119281.exe
                                      Infecté par: Trojan.Peed.JZ

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119281.exe
                                      Echec de la désinfection

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119281.exe
                                      Supprimé

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119282.exe
                                      Infecté par: Trojan.Peed.JZ

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119282.exe
                                      Echec de la désinfection

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119282.exe
                                      Supprimé

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119283.exe
                                      Infecté par: Trojan.Peed.JZ

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119283.exe
                                      Echec de la désinfection

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119283.exe
                                      Supprimé

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119303.exe
                                      Infecté par: Trojan.Peed.JZ

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119303.exe
                                      Echec de la désinfection

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119303.exe
                                      Supprimé

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119304.exe
                                      Infecté par: Trojan.Peed.JZ

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119304.exe
                                      Echec de la désinfection

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119304.exe
                                      Supprimé

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119305.exe
                                      Infecté par: Trojan.Peed.JZ

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119305.exe
                                      Echec de la désinfection

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119305.exe
                                      Supprimé

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119310.exe
                                      Infecté par: Trojan.Peed.JZ

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119310.exe
                                      Echec de la désinfection

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119310.exe
                                      Supprimé

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119318.exe
                                      Infecté par: Trojan.Peed.JZ

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119318.exe
                                      Echec de la désinfection

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119318.exe
                                      Supprimé

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119319.exe
                                      Infecté par: Trojan.Peed.JZ

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119319.exe
                                      Echec de la désinfection

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119319.exe
                                      Supprimé

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119320.exe
                                      Infecté par: Trojan.Peed.JZ

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119320.exe
                                      Echec de la désinfection

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119320.exe
                                      Supprimé

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119326.exe
                                      Infecté par: Trojan.Peed.JZ

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119326.exe
                                      Echec de la désinfection

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119326.exe
                                      Supprimé

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119327.exe
                                      Infecté par: Trojan.Peed.JZ

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119327.exe
                                      Echec de la désinfection

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119327.exe
                                      Supprimé

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119329.exe
                                      Infecté par: Trojan.Peed.JZ

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119329.exe
                                      Echec de la désinfection

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119329.exe
                                      Supprimé

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119334.exe
                                      Infecté par: Trojan.Peed.JZ

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119334.exe
                                      Echec de la désinfection

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119334.exe
                                      Supprimé

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119335.dll
                                      Infecté par: Trojan.Peed.JZ

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119335.dll
                                      Echec de la désinfection

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP447\A0119335.dll
                                      Supprimé

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP449\A0119709.exe
                                      Infecté par: Trojan.Peed.JZ

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP449\A0119709.exe
                                      Echec de la désinfection

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP449\A0119709.exe
                                      Supprimé

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP449\A0119710.exe
                                      Infecté par: Trojan.Genlot.LI

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP449\A0119710.exe
                                      Echec de la désinfection

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP449\A0119710.exe
                                      Supprimé

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP449\A0119711.exe
                                      Infecté par: Trojan.Genlot.LI

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP449\A0119711.exe
                                      Echec de la désinfection

                                      C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP449\A0119711.exe
                                      Supprimé

                                      C:\WINDOWS\system32\drivers\etc\hosts.20071014-152116.backup
                                      Infecté par: Generic.Qhost.16934822

                                      C:\WINDOWS\system32\drivers\etc\hosts.20071014-152116.backup
                                      Echec de la désinfection

                                      C:\WINDOWS\system32\drivers\etc\hosts.20071014-152116.backup
                                      Supprimé

                                      C:\WINDOWS\system32\drivers\etc\hosts.20071014-152227.backup
                                      Infecté par: Generic.Qhost.EA61E6F9

                                      C:\WINDOWS\system32\drivers\etc\hosts.20071014-152227.backup
                                      Echec de la désinfection

                                      C:\WINDOWS\system32\drivers\etc\hosts.20071014-152227.backup
                                      Supprimé

                                      C:\WINDOWS\system32\drivers\etc\hosts.20071014-152228.backup
                                      Infecté par: Generic.Qhost.58CDE1B3

                                      C:\WINDOWS\system32\drivers\etc\hosts.20071014-152228.backup
                                      Echec de la désinfection

                                      C:\WINDOWS\system32\drivers\etc\hosts.20071014-152228.backup
                                      Supprimé

                                      C:\WINDOWS\system32\drivers\etc\hosts.20071014-152229.backup
                                      Infecté par: Generic.Qhost.C553DA89

                                      C:\WINDOWS\system32\drivers\etc\hosts.20071014-152229.backup
                                      Echec de la désinfection

                                      C:\WINDOWS\system32\drivers\etc\hosts.20071014-152229.backup
                                      Supprimé
                                      0
                                      • 1
                                      • 2
                                      • 3