Virus bloodhound

Bonjour,

Norton antivirus vient de détecter 3 virus bloodhound. Je vient de télécharger hijack this mais je ne sais pas comment l'utiliser pour supprimer le virus défintivement.
Configuration: Windows XP
Internet Explorer 7.0

12 réponses

Résumé de la discussion

Problème initial: Norton détecte trois menaces Bloodhound et l'utilisateur cherche à utiliser HijackThis pour les supprimer durablement sur Windows XP avec Internet Explorer 7 dans le contexte donné. Plusieurs contributions mentionnent le rapport BitDefender Online Scanner qui ne révèle aucun fichier infecté, tandis que des conseils préconisent RavAntivirus, MalwareBytes et Navilog pour diagnostiquer et désinfecter, puis vérifier le démarrage. Des échanges suggèrent CCleaner pour la suppression des traces et msconfig pour limiter les programmes au démarrage, avec des tutoriels incluant le renommage de HijackThis et des procédures de navifix ou de navilog. En dernier lieu, un utilisateur signale un démarrage très lent et demande des méthodes d’optimisation, notamment la suppression de programmes inutiles et la vérification des processus au démarrage.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    slt,

    Fais un clic droit sur ce lien : (IL-MAFIOSO)
    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
    Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
    Ensuite double clique sur navilog1.exe pour lancer l'installation.
    Une fois l'installation terminée, le fix s'exécutera automatiquement.
    (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

    Laisse-toi guider. Au menu principal, choisis 1 et valides.
    (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

    Patiente jusqu'au message :
    *** Analyse Termine le ..... ***
    Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
    Copie-colle l'intégralité dans une réponse. Referme le blocnote.
    Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)

    ___________

    colle un rapport hijackthis

    http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download

    manuel :
    http://pagesperso-orange.fr/rginformatique/section%20virus/demohijack.htm
    https://leblogdeclaude.blogspot.com/2006/10/informatique-section-hijackthis.html

    Je conseille de renomer Hijackthis, pour contrer une éventuelle infection de Vundo.

    ex:Renomme le fichier HijackThis.exe en eden.exe pour cela, fais un clic droit sur le fichier HijackThis.exe et choisis renommer dans la liste

    Ensuite avec Explorer créer un dossier c:\hijackthis
    Décompresser Hijackthis dans ce dossier.
    C'est important pour les sauvegardes."
    0
    1. Voilà le rapport de navilog que vous m'avez demandé :

      Search Navipromo version 3.5.1 commencé le 26/03/2008 à 20:57:38,78

      !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
      !!! Postez ce rapport sur le forum pour le faire analyser !!!
      !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

      Outil exécuté depuis C:\Program Files\navilog1
      Session actuelle : "Nabila"

      Mise à jour le 23.03.2008 à 22h00 par IL-MAFIOSO

      Microsoft Windows XP [version 5.1.2600]
      Internet Explorer : 7.0.5730.13
      Système de fichiers : NTFS

      Executé en mode normal

      *** Recherche Programmes installés ***

      *** Recherche dossiers dans C:\WINDOWS ***

      *** Recherche dossiers dans C:\Program Files ***

      *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\APPLIC~1 ***

      *** Recherche dossiers dans "C:\Documents and Settings\Nabila\applic~1" ***

      *** Recherche dossiers dans "C:\Documents and Settings\Nabila\locals~1\applic~1" ***

      *** Recherche dossiers dans "C:\Documents and Settings\Nabila\menudm~1\progra~1" ***

      *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

      *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
      pour + d'infos : http://www.gmer.net

      Aucun Fichier trouvé

      *** Recherche avec GenericNaviSearch ***
      !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
      !!! A vérifier impérativement avant toute suppression manuelle !!!

      * Recherche dans C:\WINDOWS\system32 *

      * Recherche dans "C:\Documents and Settings\Nabila\locals~1\applic~1" *

      *** Recherche fichiers ***

      *** Recherche clés spécifiques dans le Registre ***

      *** Module de Recherche complémentaire ***
      (Recherche fichiers spécifiques)

      1)Recherche nouveaux fichiers Instant Access :

      2)Recherche Heuristique :

      * Dans C:\WINDOWS\system32 :

      * Dans "C:\Documents and Settings\Nabila\locals~1\applic~1" :

      3)Recherche Certificats :

      Certificat Egroup absent !
      Certificat Electronic-Group absent !
      Certificat OOO-Favorit absent !
      Certificat Sunny-Day-Design-Ltd absent !

      4)Recherche fichiers connus :

      *** Analyse terminée le 26/03/2008 à 21:01:16,54 ***
      0
  2. Contributeur sécurité
    colle un rapport hijackthis

    http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download

    manuel :
    http://pagesperso-orange.fr/rginformatique/section%20virus/demohijack.htm
    https://leblogdeclaude.blogspot.com/2006/10/informatique-section-hijackthis.html

    Je conseille de renomer Hijackthis, pour contrer une éventuelle infection de Vundo.

    ex:Renomme le fichier HijackThis.exe en eden.exe pour cela, fais un clic droit sur le fichier HijackThis.exe et choisis renommer dans la liste

    Ensuite avec Explorer créer un dossier c:\hijackthis
    Décompresser Hijackthis dans ce dossier.
    C'est important pour les sauvegardes."
    0
    1. Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 21:31:54, on 26/03/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16608)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
      C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
      C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
      C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Norton AntiVirus\navapsvc.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
      C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\samsung\Samsung Network Manager\SNMWLANService.exe
      C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
      C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\WINDOWS\AGRSMMSG.exe
      C:\Program Files\Samsung\Samsung Command Center\PIC_UI.exe
      C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
      C:\PROGRA~1\Samsung\SAMSUN~1\SAMSUN~1.EXE
      C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\Program Files\SAMSUNG\MagicKBD\MagicKBD.exe
      C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\Skype\Phone\Skype.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
      C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
      C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
      C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
      C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
      C:\Program Files\Skype\Plugin Manager\skypePM.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Windows Live\Messenger\usnsvc.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
      O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
      O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
      O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
      O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
      O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
      O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
      O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
      O4 - HKLM\..\Run: [SamsungPIC] C:\Program Files\Samsung\Samsung Command Center\PIC_UI.exe
      O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [MagicKeyboard] C:\Program Files\SAMSUNG\MagicKBD\PreMKBD.exe
      O4 - HKLM\..\Run: [BatteryManager] C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
      O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: hp psc 1000 series.lnk = ?
      O4 - Global Startup: hpoddt01.exe.lnk = ?
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
      O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
      O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) - http://eu.download.games.yahoo.com/zylom/activex/zylomloader.cab
      O17 - HKLM\System\CCS\Services\Tcpip\..\{8A600658-69A8-422F-9F76-D3F304576B68}: NameServer = 192.168.1.1
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
      O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
      O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
      O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
      O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
      O23 - Service: Samsung Update Plus - Unknown owner - C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe
      O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
      O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
      O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
      O23 - Service: SNM WLAN Service - Unknown owner - C:\Program Files\samsung\Samsung Network Manager\SNMWLANService.exe
      O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
      O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
      0
  3. Contributeur sécurité
    quels fichiers sont inféctés selon norton (colle le rapport des infections)

    _____________

    colle le rapport d'un scan en ligne
    avec un des suivants:

    bitdefender en ligne :
    http://www.bitdefender.fr/scan_fr/scan8/ie.html

    Panda en ligne :
    http://pandasoftware.fr

    Kaspersky en ligne
    https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
    0
    1. les fichiers infectés selon norton sont les suivants :
      22umqpcg.dll
      aqb2.dll
      k4jm.dll

      Nom de la menace : bloodhound.packed.Jmp

      qd au scan de bitdefender, il est tjrs en cours. Je te l'envoie dès qu'il se termine.
      0
  4. Contributeur sécurité
    ok tu n'as pas le lien exact des fichiers inféctés commencant par C
    0
    1. ce ne serai pas ça :

      C:\GetPaths.vbs
      0
    2. Tiens voici le rapport de norton :

      Catégorie de menace : VirusSource :C:\xp19.com,Description :Le fichier C:\xp19.com est infecté par le virus W32.Gammima.AG.
      Catégorie de menace : VirusSource :C:\WINDOWS\system32\amvo1.dll,Description :Le fichier C:\WINDOWS\system32\amvo1.dll est infecté par le virus W32.Gammima.AG.
      Catégorie de menace : VirusSource :C:\WINDOWS\system32\amvo0.dll,Description :Le fichier C:\WINDOWS\system32\amvo0.dll est infecté par le virus W32.Gammima.AG.
      Catégorie de menace : VirusSource :C:\Documents and Settings\Nabila\Local Settings\Temp\k4jm.dll,Description :Le fichier C:\Documents and Settings\Nabila\Local Settings\Temp\k4jm.dll est infecté par le virus Bloodhound.Packed.Jmp.
      Catégorie de menace : VirusSource :C:\Documents and Settings\Nabila\Local Settings\Temp\gj4hn.dll,Description :Le fichier C:\Documents and Settings\Nabila\Local Settings\Temp\gj4hn.dll est infecté par le virus Hacktool.Rootkit.
      Catégorie de menace : VirusSource :C:\Documents and Settings\Nabila\Local Settings\Temp\cfmwfbi.dll,Description :Le fichier C:\Documents and Settings\Nabila\Local Settings\Temp\cfmwfbi.dll est infecté par le virus Hacktool.Rootkit.
      Catégorie de menace : VirusSource :C:\Documents and Settings\Nabila\Local Settings\Temp\boalrz.dll,Description :Le fichier C:\Documents and Settings\Nabila\Local Settings\Temp\boalrz.dll est infecté par le virus Hacktool.Rootkit.
      Catégorie de menace : VirusSource :C:\Documents and Settings\Nabila\Local Settings\Temp\aqb2.dll,Description :Le fichier C:\Documents and Settings\Nabila\Local Settings\Temp\aqb2.dll est infecté par le virus Bloodhound.Packed.Jmp.
      Catégorie de menace : VirusSource :C:\Documents and Settings\Nabila\Local Settings\Temp\aupg.dll,Description :Le fichier C:\Documents and Settings\Nabila\Local Settings\Temp\aupg.dll est infecté par le virus Infostealer.Gampass.
      Catégorie de menace : VirusSource :C:\Documents and Settings\Nabila\Local Settings\Temp\9sob2.dll,Description :Le fichier C:\Documents and Settings\Nabila\Local Settings\Temp\9sob2.dll est infecté par le virus Hacktool.Rootkit.
      Catégorie de menace : VirusSource :C:\Documents and Settings\Nabila\Local Settings\Temp\22umqpcg.dll,Description :Le fichier C:\Documents and Settings\Nabila\Local Settings\Temp\22umqpcg.dll est infecté par le virus Bloodhound.Packed.Jmp.
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\mgjpcfdg.cmd
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\SYSTEM32\AMVO0.DLL
      Source :C:\WINDOWS\SYSTEM32\AMVO0.DLL
      Source :C:\WINDOWS\SYSTEM32\AMVO0.DLL
      Source :C:\WINDOWS\SYSTEM32\AMVO0.DLL
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      Source :C:\WINDOWS\system32\amvo0.dll
      0
  5. Contributeur sécurité
    parfait!

    Télécharge Combofix de sUBs : Renomme le avant toute installation, par exemple, nomme le "KillBagle". aide ici : https://forum.pcastuces.com/sujet.asp?f=25&s=37315

    http://download.bleepingcomputer.com/sUBs/ComboFix.exe
    Sauvegarde le sur ton bureau et pas ailleurs !

    Aide à l’utilisation de combofix ici: https://bibou0007.forumpro.fr/login?redirect=%2Ft121-topic

    Double-clic sur combofix, Il va te poser une question, réponds par la touche 1 et entrée pour valider, laisse toi guider.
    Attends que combofix ait terminé, un rapport sera créé. Poste le rapport.
    _____________

    scan avec
    MalwareByte's Anti-Malware et vire ce qui est trouvé et colle le rapport

    https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

    ________________
    recolle un hijakchits
    0
    1. Tu as tjrs besoin du rapport bitdefender ou j'arrête l'analyse ?
      0
    2. Voilà le rapport :

      ComboFix 08-03-25.4 - Nabila 2008-03-26 22:53:34.1 - NTFSx86
      Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.229 [GMT 1:00]
      Endroit: C:\Documents and Settings\Nabila\Bureau\Combo-Fix.exe
      * Création d'un nouveau point de restauration

      [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
      .

      (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
      .

      C:\Autorun.inf
      C:\WINDOWS\system32\test.dll

      .
      ((((((((((((((((((((((((((((( Fichiers créés 2008-02-26 to 2008-03-26 ))))))))))))))))))))))))))))))))))))
      .

      2008-03-26 21:58 . 2008-03-26 22:41 <REP> d-------- C:\WINDOWS\BDOSCAN8
      2008-03-26 21:52 . 2008-03-26 21:52 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
      2008-03-26 21:52 . 2008-03-26 21:52 <REP> d-------- C:\WINDOWS\LastGood
      2008-03-26 20:53 . 2008-03-26 21:02 <REP> d-------- C:\Program Files\Navilog1
      2008-03-26 19:31 . 2008-03-26 19:31 <REP> d-------- C:\Program Files\Trend Micro
      2008-03-22 15:46 . 2008-03-22 15:46 0 --a------ C:\WINDOWS\nsreg.dat
      2008-03-19 17:24 . 2008-03-25 13:05 54,156 --ah----- C:\WINDOWS\QTFont.qfn
      2008-03-19 17:24 . 2008-03-19 17:24 1,409 --a------ C:\WINDOWS\QTFont.for
      2008-03-18 11:31 . 2008-03-18 11:31 82,380 --a------ C:\WINDOWS\system32\drivers\AFS2K.SYS
      2008-03-18 10:39 . 2008-03-18 11:42 20,454 --a------ C:\WINDOWS\hpoins01.dat
      2008-03-18 10:39 . 2003-04-05 12:24 16,618 --------- C:\WINDOWS\hpomdl01.dat
      2008-03-18 10:34 . 2003-03-09 05:31 81,920 -ra------ C:\WINDOWS\system32\hpovst08.dll
      2008-03-16 12:46 . 2008-03-16 12:46 22 --a------ C:\WINDOWS\system32\ati64hl2.stb
      2008-03-16 06:00 . 2008-03-16 06:00 22 --a------ C:\WINDOWS\system32\ati64hlp.stb
      2008-03-15 21:49 . 2008-03-15 21:49 <REP> d-------- C:\WINDOWS\system32\NtmsData
      2008-03-15 21:41 . 2008-03-15 21:51 <REP> d-------- C:\WINDOWS\SxsCaPendDel
      2008-03-12 14:25 . 2008-03-12 14:25 <REP> d-------- C:\Documents and Settings\All Users\Application Data\WinZip
      2008-03-12 12:13 . 2008-03-12 12:13 <REP> d-------- C:\Documents and Settings\LocalService\Mes documents
      2008-03-12 10:10 . 2008-03-12 14:23 <REP> d-------- C:\DesignWorkshop Lite Installer
      2008-03-12 07:54 . 2008-03-12 07:54 244 --ah----- C:\sqmnoopt00.sqm
      2008-03-12 07:54 . 2008-03-12 07:54 232 --ah----- C:\sqmdata00.sqm
      2008-03-08 17:21 . 2004-08-03 23:10 10,880 --a------ C:\WINDOWS\system32\drivers\NdisIP.sys
      2008-03-08 17:21 . 2004-08-03 23:10 10,880 --a--c--- C:\WINDOWS\system32\dllcache\ndisip.sys
      2008-03-08 17:21 . 2004-08-03 22:58 5,504 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys
      2008-03-08 17:21 . 2004-08-03 22:58 5,504 --a--c--- C:\WINDOWS\system32\dllcache\mstee.sys
      2008-03-08 17:19 . 2008-03-08 17:19 <REP> d-------- C:\WebCam
      2008-03-08 10:08 . 2008-03-08 10:08 107,172 -r-hs---- C:\v.com
      2008-03-07 11:23 . 2008-03-07 11:23 <REP> d-------- C:\WatchNow
      2008-03-01 16:08 . 2008-03-01 16:08 <REP> d-------- C:\Documents and Settings\Nabila\Application Data\Nokia Multimedia Player
      2008-03-01 15:52 . 2008-03-01 15:52 <REP> d-------- C:\Program Files\Fichiers communs\PCSuite
      2008-03-01 15:52 . 2008-03-01 15:52 <REP> d-------- C:\Program Files\Fichiers communs\Nokia
      2008-03-01 15:51 . 2008-03-01 15:52 <REP> d-------- C:\Program Files\Nokia
      2008-03-01 15:51 . 2007-02-22 10:15 137,216 --a------ C:\WINDOWS\system32\drivers\nmwcd.sys
      2008-03-01 15:51 . 2007-02-22 10:15 65,536 --a------ C:\WINDOWS\system32\nmwcdcocls.dll
      2008-03-01 15:51 . 2007-02-22 10:15 12,288 --a------ C:\WINDOWS\system32\drivers\nmwcdcm.sys
      2008-03-01 15:51 . 2007-02-22 10:15 8,320 --a------ C:\WINDOWS\system32\drivers\nmwcdc.sys
      2008-03-01 13:10 . 2008-03-01 13:10 <REP> d-------- C:\Program Files\DIFX
      2008-03-01 13:10 . 2008-03-01 13:19 <REP> d-------- C:\Documents and Settings\Nabila\Application Data\Nokia
      2008-03-01 13:10 . 2008-03-01 13:12 <REP> d-------- C:\Documents and Settings\All Users\Application Data\PC Suite
      2008-03-01 13:08 . 2008-03-01 13:28 <REP> d-------- C:\Documents and Settings\Nabila\Application Data\PC Suite
      2008-03-01 13:07 . 2008-03-01 13:07 <REP> d-------- C:\Program Files\PC Connectivity Solution
      2008-03-01 13:05 . 2008-03-01 13:05 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Installations
      2008-02-29 10:32 . 2008-02-29 10:32 <REP> d-------- C:\Program Files\Norton Security Scan

      .
      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2008-03-26 15:02 --------- d-----w C:\Documents and Settings\Nabila\Application Data\skypePM
      2008-03-25 20:02 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
      2008-03-23 10:10 --------- d-----w C:\Documents and Settings\Nabila\Application Data\Skype
      2008-03-15 20:44 --------- d-----w C:\Program Files\Hewlett-Packard
      2008-03-15 20:43 --------- d-----w C:\Program Files\CyberLink
      2008-03-15 20:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
      2008-03-07 08:08 --------- d-----w C:\Program Files\Java
      2008-03-03 16:20 --------- d-----w C:\Documents and Settings\Nabila\Application Data\AdobeUM
      2008-03-01 12:59 --------- d-----w C:\Program Files\IKEA HomePlanner
      2008-02-06 09:29 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
      2008-02-06 09:26 --------- d-----w C:\Program Files\Skype
      2008-02-06 09:26 --------- d-----w C:\Program Files\Fichiers communs\Skype
      2008-02-06 09:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
      2008-02-05 16:07 --------- d-----w C:\Documents and Settings\Nabila\Application Data\HP
      2008-02-05 16:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\WEBREG
      2008-02-05 15:57 --------- d-----w C:\Program Files\HP
      2008-02-05 15:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\HPSSUPPLY
      2008-02-05 15:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
      2008-02-02 10:11 --------- d-----w C:\Program Files\Windows Media Connect 2
      2008-01-29 20:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Zylom
      2008-01-26 08:17 --------- d-----w C:\Documents and Settings\Nabila\Application Data\Apple Computer
      2008-01-13 19:05 4,300 ----a-w C:\WINDOWS\system32\MEMIO.SYS
      2008-01-04 21:59 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
      2008-01-04 21:58 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
      2008-01-04 21:58 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
      2008-01-04 21:58 129,784 ------w C:\WINDOWS\system32\pxafs.dll
      2008-01-04 21:58 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
      2008-01-04 21:58 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
      2008-01-04 21:58 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
      2008-01-04 21:57 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
      2008-01-04 21:57 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
      2008-01-04 21:57 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
      2008-01-04 21:57 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
      2008-01-04 21:57 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
      2008-01-04 21:57 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
      2008-01-04 21:57 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
      2008-01-04 21:57 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
      2008-01-04 21:57 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
      2008-01-04 21:57 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
      2008-01-04 21:57 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
      2008-01-04 21:57 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
      2008-01-04 21:56 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
      2008-01-04 21:56 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
      2005-09-10 07:34 624 ----a-w C:\Documents and Settings\Nabila\install.cmd
      .

      ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      REGEDIT4
      *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 13:00 15360]
      "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-21 19:43 68856]
      "Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-02-01 17:22 21898024]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
      "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-03 21:05 344064]
      "SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-07-27 13:48 1388544]
      "SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2004-08-06 08:27 860160]
      "SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-02-02 11:12 102492]
      "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-02-02 11:11 692316]
      "AGRSMMSG"="AGRSMMSG.exe" [2005-03-04 11:01 88209 C:\WINDOWS\AGRSMMSG.exe]
      "SamsungPIC"="C:\Program Files\Samsung\Samsung Command Center\PIC_UI.exe" [2005-06-17 18:18 2785280]
      "ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2007-02-21 16:29 58984]
      "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
      "MagicKeyboard"="C:\Program Files\SAMSUNG\MagicKBD\PreMKBD.exe" [2005-04-11 13:01 151552]
      "BatteryManager"="C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe" [2005-06-07 20:22 1933312]
      "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-14 16:20 286720]
      "Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2008-01-15 09:43 100056]
      "TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-01-17 08:12 185896]
      "HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2006-12-10 21:52 49152]

      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
      "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 13:00 15360]
      "Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 17:35 1294336]

      C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
      hp psc 1000 series.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-04-06 01:17:18 147456]
      hpoddt01.exe.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-04-06 01:06:58 28672]

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
      "DisableMonitoring"=dword:00000001

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
      "DisableMonitoring"=dword:00000001

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
      "EnableFirewall"= 0 (0x0)

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "%windir%\\system32\\sessmgr.exe"=
      "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
      "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
      "C:\\Program Files\\Skype\\Phone\\Skype.exe"=

      R2 DOSMEMIO;MEMIO;C:\WINDOWS\system32\MEMIO.SYS [2008-01-13 20:05]
      R2 SNM WLAN Service;SNM WLAN Service;"C:\Program Files\samsung\Samsung Network Manager\SNMWLANService.exe" [2005-05-28 08:35]
      R3 wowfilter;WOW XT Filter Driver;C:\WINDOWS\system32\drivers\wowfilter.sys [2005-06-08 16:58]
      S3 V0090VID;Creative WebCam Vista Plus;C:\WINDOWS\system32\DRIVERS\V0090Vid.sys [2005-04-14 01:00]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
      HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7365133b-c217-11dc-ab16-00137701e9b3}]
      \Shell\AutoRun\command - G:\mgjpcfdg.cmd
      \Shell\explore\Command - G:\mgjpcfdg.cmd
      \Shell\open\Command - G:\mgjpcfdg.cmd

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7a371340-c20f-11dc-ab15-806d6172696f}]
      \Shell\AutoRun\command - C:\v.com
      \Shell\explore\Command - C:\v.com
      \Shell\open\Command - C:\v.com

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7a371342-c20f-11dc-ab15-00137701e9b3}]
      \Shell\AutoRun\command - F:\22wcb21o.exe
      \Shell\explore\Command - F:\22wcb21o.exe
      \Shell\open\Command - F:\22wcb21o.exe

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a6779e41-c289-11dc-ab18-00137701e9b3}]
      \Shell\AutoRun\command - E:\fppg1.exe
      \Shell\explore\Command - E:\fppg1.exe
      \Shell\open\Command - E:\fppg1.exe

      *Newly Created Service* - CATCHME
      .
      Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
      "2008-01-19 20:29:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
      - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
      "2008-03-18 10:49:18 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1205837188.job"
      - C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe4-I
      "2008-03-14 19:00:49 C:\WINDOWS\Tasks\Norton AntiVirus - Analyser mon ordinateur - Nabila.job"
      - C:\PROGRA~1\NORTON~1\Navw32.exeh/task:
      .
      **************************************************************************

      catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2008-03-26 22:56:37
      Windows 5.1.2600 Service Pack 2 NTFS

      Balayage processus cachés ...

      Balayage caché autostart entries ...

      Balayage des fichiers cachés ...

      Scan terminé avec succès
      Les fichiers cachés: 0

      **************************************************************************
      .
      Temps d'accomplissement: 2008-03-26 22:57:23
      ComboFix-quarantined-files.txt 2008-03-26 21:57:13
      .
      2008-03-12 12:05:56 --- E O F ---
      0
  6. Contributeur sécurité
    oui colle le rapport bitdefender

    ______________

    Télécharge RavAntivirus d'Evosla :
    http://ww25.evosla.com/compteur.php?soft=rav_antivirus

    # Si tu as une clé USB, disque dur externe, etc, branche-les sans les ouvrir avant de lancer ce FIX
    # Fais un clic droit sur le fichier .ZIP > Extraire sur > le Bureau
    # Doucle-clique sur >> RAV.exe << afin de lancer l'outil.
    # Une fois RAV ANTIVIRUS lancé, laisse-le réagir , il scanne automatiquement tout les lecteurs (disques fixes et amovibles)
    # Si infection > un log s'établira, sinon le soft affichera (très rapide) ==>Votre Ordinateur est sain .
    # Retire tes disques amovibles et redémarrez votre ordinateur.
    # Poste le rapport, si infection!

    _______________

    scan avec
    MalwareByte's Anti-Malware et vire ce qui est trouvé et colle le rapport

    https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

    ________________
    recolle un hijakchits
    0
    1. Mon pc a beugué j'ai donc dû reprendre l'analyse bitdefender, je suis désolée

      Je ne pensai pas que ça prendrai autant de temps donc si tu en a assez et que tu veux aller te coucher, on reprendra demain si tu le veux bien.
      0
    2. BitDefender Online Scanner

      Rapport d'analyse généré à: Wed, Mar 26, 2008 - 23:48:47

      Voie d'analyse: C:\;D:\;

      Statistiques

      Temps
      00:30:54

      Fichiers
      100477

      Directoires
      4299

      Secteurs de boot
      3

      Archives
      991

      Paquets programmes
      10401

      Résultats

      Virus identifiés
      10

      Fichiers infectés
      214

      Fichiers suspects
      0

      Avertissements
      0

      Désinfectés
      0

      Fichiers effacés
      254

      Info sur les moteurs

      Définition virus
      1025735

      Version des moteurs
      AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)

      Analyse des plugins
      16

      Archive des plugins
      41

      Unpack des plugins
      7

      E-mail plugins
      6

      Système plugins
      5

      Paramètres d'analyse

      Première action
      Désinfecté

      Seconde Action
      Supprimé

      Heuristique
      Oui

      Acceptez les avertissements
      Oui

      Extensions analysées
      exe;com;dll;ocx;scr;bin;dat;386;vxd;sys;wdm;cla;class;ovl;ole;hlp;doc;dot;xls;ppt;wbk;wiz;pot;ppa;xla;xlt;vbs;vbe;mdb;rtf;htm;hta;html;xml;xtp;php;asp;js;shs;chm;lnk;pif;prc;url;smm;pfd;msi;ini;csc;cmd;bas;

      Excludez les extensions

      Analyse d'emails
      Oui

      Analyse des Archives
      Oui

      Analyser paquets programmes
      Oui

      Analyse des fichiers
      Oui

      Analyse de boot
      Oui

      Fichier analysé
      Statut

      C:\Program Files\Norton AntiVirus\Quarantine\12BF5623.dll=>(Quarantine-2)
      Infecté par: Packer.Malware.NSAnti.R

      C:\Program Files\Norton AntiVirus\Quarantine\12BF5623.dll=>(Quarantine-2)
      Echec de la désinfection

      C:\Program Files\Norton AntiVirus\Quarantine\12BF5623.dll=>(Quarantine-2)
      Supprimé

      C:\Program Files\Norton AntiVirus\Quarantine\12C2001F.dll=>(Quarantine-2)
      Infecté par: Trojan.PWS.OnlineGames.RAB

      C:\Program Files\Norton AntiVirus\Quarantine\12C2001F.dll=>(Quarantine-2)
      Echec de la désinfection

      C:\Program Files\Norton AntiVirus\Quarantine\12C2001F.dll=>(Quarantine-2)
      Supprimé

      C:\Program Files\Norton AntiVirus\Quarantine\16117A26.exe=>(Quarantine-2)
      Infecté par: Packer.Malware.NSAnti.T

      C:\Program Files\Norton AntiVirus\Quarantine\16117A26.exe=>(Quarantine-2)
      Echec de la désinfection

      C:\Program Files\Norton AntiVirus\Quarantine\16117A26.exe=>(Quarantine-2)
      Supprimé

      C:\Program Files\Norton AntiVirus\Quarantine\17671881.exe=>(Quarantine-2)
      Infecté par: Trojan.PWS.OnlineGames.RAB

      C:\Program Files\Norton AntiVirus\Quarantine\17671881.exe=>(Quarantine-2)
      Echec de la désinfection

      C:\Program Files\Norton AntiVirus\Quarantine\17671881.exe=>(Quarantine-2)
      Supprimé

      C:\Program Files\Norton AntiVirus\Quarantine\23705B70.cmd=>(Quarantine-2)
      Infecté par: Trojan.PWS.OnlineGames.SRE

      C:\Program Files\Norton AntiVirus\Quarantine\23705B70.cmd=>(Quarantine-2)
      Echec de la désinfection

      C:\Program Files\Norton AntiVirus\Quarantine\23705B70.cmd=>(Quarantine-2)
      Supprimé

      C:\Program Files\Norton AntiVirus\Quarantine\23705B70.exe=>(Quarantine-2)
      Infecté par: Packer.Malware.NSAnti.U

      C:\Program Files\Norton AntiVirus\Quarantine\23705B70.exe=>(Quarantine-2)
      Echec de la désinfection

      C:\Program Files\Norton AntiVirus\Quarantine\23705B70.exe=>(Quarantine-2)
      Supprimé

      C:\Program Files\Norton AntiVirus\Quarantine\2373056C.com=>(Quarantine-2)
      Infecté par: Packer.Malware.NSAnti.U

      C:\Program Files\Norton AntiVirus\Quarantine\2373056C.com=>(Quarantine-2)
      Echec de la désinfection

      C:\Program Files\Norton AntiVirus\Quarantine\2373056C.com=>(Quarantine-2)
      Supprimé

      C:\Program Files\Norton AntiVirus\Quarantine\26177884.cmd=>(Quarantine-2)
      Infecté par: Packer.Malware.NSAnti.T

      C:\Program Files\Norton AntiVirus\Quarantine\26177884.cmd=>(Quarantine-2)
      Echec de la désinfection

      C:\Program Files\Norton AntiVirus\Quarantine\26177884.cmd=>(Quarantine-2)
      Supprimé

      C:\Program Files\Norton AntiVirus\Quarantine\2FDF43C0.dll=>(Quarantine-2)
      Infecté par: Trojan.PWS.OnlineGames.SRE

      C:\Program Files\Norton AntiVirus\Quarantine\2FDF43C0.dll=>(Quarantine-2)
      Echec de la désinfection

      C:\Program Files\Norton AntiVirus\Quarantine\2FDF43C0.dll=>(Quarantine-2)
      Supprimé

      C:\Program Files\Norton AntiVirus\Quarantine\2FE36DBC.dll=>(Quarantine-2)
      Infecté par: Packer.Malware.NSAnti.S

      C:\Program Files\Norton AntiVirus\Quarantine\2FE36DBC.dll=>(Quarantine-2)
      Echec de la désinfection

      C:\Program Files\Norton AntiVirus\Quarantine\2FE36DBC.dll=>(Quarantine-2)
      Supprimé

      C:\Program Files\Norton AntiVirus\Quarantine\2FE617B9.dll=>(Quarantine-2)
      Infecté par: Trojan.PWS.OnlineGames.SRE

      C:\Program Files\Norton AntiVirus\Quarantine\2FE617B9.dll=>(Quarantine-2)
      Echec de la désinfection

      C:\Program Files\Norton AntiVirus\Quarantine\2FE617B9.dll=>(Quarantine-2)
      Supprimé

      C:\Program Files\Norton AntiVirus\Quarantine\2FED6BB2.dll=>(Quarantine-2)
      Infecté par: Trojan.PWS.OnlineGames.SRE

      C:\Program Files\Norton AntiVirus\Quarantine\2FED6BB2.dll=>(Quarantine-2)
      Echec de la désinfection

      C:\Program Files\Norton AntiVirus\Quarantine\2FED6BB2.dll=>(Quarantine-2)
      Supprimé

      C:\Program Files\Norton AntiVirus\Quarantine\3000679C.dll=>(Quarantine-2)
      Infecté par: Packer.Malware.NSAnti.T

      C:\Program Files\Norton AntiVirus\Quarantine\3000679C.dll=>(Quarantine-2)
      Echec de la désinfection

      C:\Program Files\Norton AntiVirus\Quarantine\3000679C.dll=>(Quarantine-2)
      Supprimé

      C:\Program Files\Norton AntiVirus\Quarantine\40F92E82.exe=>(Quarantine-2)
      Infecté par: Worm.RJump.K

      C:\Program Files\Norton AntiVirus\Quarantine\40F92E82.exe=>(Quarantine-2)
      Supprimé

      C:\Program Files\Norton AntiVirus\Quarantine\414F768F.dll=>(Quarantine-2)
      Infecté par: Packer.Malware.NSAnti.T

      C:\Program Files\Norton AntiVirus\Quarantine\414F768F.dll=>(Quarantine-2)
      Echec de la désinfection

      C:\Program Files\Norton AntiVirus\Quarantine\414F768F.dll=>(Quarantine-2)
      Supprimé

      C:\Program Files\Norton AntiVirus\Quarantine\4153208C.dll=>(Quarantine-2)
      Infecté par: Packer.Malware.NSAnti.T

      C:\Program Files\Norton AntiVirus\Quarantine\4153208C.dll=>(Quarantine-2)
      Echec de la désinfection

      C:\Program Files\Norton AntiVirus\Quarantine\4153208C.dll=>(Quarantine-2)
      Supprimé

      C:\Program Files\Norton AntiVirus\Quarantine\44385B5C.com=>(Quarantine-2)
      Infecté par: Trojan.PWS.OnlineGames.SRE

      C:\Program Files\Norton AntiVirus\Quarantine\44385B5C.com=>(Quarantine-2)
      Echec de la désinfection

      C:\Program Files\Norton AntiVirus\Quarantine\44385B5C.com=>(Quarantine-2)
      Supprimé

      C:\Program Files\Norton AntiVirus\Quarantine\777302FC.dll=>(Quarantine-2)
      Infecté par: Packer.Malware.NSAnti.U

      C:\Program Files\Norton AntiVirus\Quarantine\777302FC.dll=>(Quarantine-2)
      Echec de la désinfection

      C:\Program Files\Norton AntiVirus\Quarantine\777302FC.dll=>(Quarantine-2)
      Supprimé

      C:\Program Files\Norton AntiVirus\Quarantine\777956F5.dll=>(Quarantine-2)
      Infecté par: Packer.Malware.NSAnti.U

      C:\Program Files\Norton AntiVirus\Quarantine\777956F5.dll=>(Quarantine-2)
      Echec de la désinfection

      C:\Program Files\Norton AntiVirus\Quarantine\777956F5.dll=>(Quarantine-2)
      Supprimé

      C:\Program Files\Norton AntiVirus\Quarantine\777C00F1.dll=>(Quarantine-2)
      Infecté par: Trojan.PWS.OnlineGames.SQS

      C:\Program Files\Norton AntiVirus\Quarantine\777C00F1.dll=>(Quarantine-2)
      Echec de la désinfection

      C:\Program Files\Norton AntiVirus\Quarantine\777C00F1.dll=>(Quarantine-2)
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP100\A0031507.com
      Infecté par: Trojan.PWS.OnlineGames.SQS

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP100\A0031507.com
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP100\A0031507.com
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP101\A0031518.com
      Infecté par: Trojan.PWS.OnlineGames.SQS

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP101\A0031518.com
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP101\A0031518.com
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP102\A0031546.dll
      Infecté par: Trojan.PWS.OnlineGames.SQS

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP102\A0031546.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP102\A0031546.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP102\A0031547.com
      Infecté par: Trojan.PWS.OnlineGames.SQS

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP102\A0031547.com
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP102\A0031547.com
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP102\A0031549.exe
      Infecté par: Trojan.PWS.OnlineGames.SQS

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP102\A0031549.exe
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP102\A0031549.exe
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP103\A0031562.exe
      Infecté par: Packer.Malware.NSAnti.U

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP103\A0031562.exe
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP103\A0031562.exe
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP103\A0031568.dll
      Infecté par: Packer.Malware.NSAnti.U

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP103\A0031568.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP103\A0031568.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP103\A0031576.exe
      Infecté par: Packer.Malware.NSAnti.U

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP103\A0031576.exe
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP103\A0031576.exe
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP103\A0031577.com
      Infecté par: Trojan.PWS.OnlineGames.SQS

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP103\A0031577.com
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP103\A0031577.com
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP103\A0031971.dll
      Infecté par: Trojan.PWS.OnlineGames.SQS

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP103\A0031971.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP103\A0031971.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP103\A0031983.dll
      Infecté par: Packer.Malware.NSAnti.U

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP103\A0031983.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP103\A0031983.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP103\A0031984.exe
      Infecté par: Packer.Malware.NSAnti.U

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP103\A0031984.exe
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP103\A0031984.exe
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP103\A0031995.dll
      Infecté par: Packer.Malware.NSAnti.U

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP103\A0031995.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP103\A0031995.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP103\A0031996.exe
      Infecté par: Packer.Malware.NSAnti.U

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP103\A0031996.exe
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP103\A0031996.exe
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP104\A0032011.exe
      Infecté par: Packer.Malware.NSAnti.U

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP104\A0032011.exe
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP104\A0032011.exe
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP104\A0032995.dll
      Infecté par: Packer.Malware.NSAnti.U

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP104\A0032995.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP104\A0032995.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP104\A0032996.exe
      Infecté par: Packer.Malware.NSAnti.U

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP104\A0032996.exe
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP104\A0032996.exe
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP104\A0033009.dll
      Infecté par: Packer.Malware.NSAnti.U

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP104\A0033009.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP104\A0033009.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP104\A0033010.exe
      Infecté par: Packer.Malware.NSAnti.U

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP104\A0033010.exe
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP104\A0033010.exe
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP104\A0033012.exe
      Infecté par: Packer.Malware.NSAnti.U

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP104\A0033012.exe
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP104\A0033012.exe
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP104\A0033013.dll
      Infecté par: Trojan.PWS.OnlineGames.SQS

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP104\A0033013.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP104\A0033013.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP104\A0033023.dll
      Infecté par: Packer.Malware.NSAnti.U

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP104\A0033023.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP104\A0033023.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP104\A0033025.com
      Infecté par: Packer.Malware.NSAnti.U

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP104\A0033025.com
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP104\A0033025.com
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP104\A0033030.exe
      Infecté par: Packer.Malware.NSAnti.U

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP104\A0033030.exe
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP104\A0033030.exe
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP105\A0033044.cmd
      Infecté par: Trojan.PWS.OnlineGames.SRE

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP105\A0033044.cmd
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP105\A0033044.cmd
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP105\A0033054.dll
      Infecté par: Trojan.PWS.OnlineGames.SRE

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP105\A0033054.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP105\A0033054.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP105\A0033055.cmd
      Infecté par: Trojan.PWS.OnlineGames.SRE

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP105\A0033055.cmd
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP105\A0033055.cmd
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP105\A0033065.dll
      Infecté par: Trojan.PWS.OnlineGames.SRE

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP105\A0033065.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP105\A0033065.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP105\A0033066.cmd
      Infecté par: Trojan.PWS.OnlineGames.SRE

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP105\A0033066.cmd
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP105\A0033066.cmd
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP105\A0033172.exe
      Infecté par: Trojan.PWS.OnlineGames.SRE

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP105\A0033172.exe
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP105\A0033172.exe
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP105\A0033174.dll
      Infecté par: Packer.Malware.NSAnti.U

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP105\A0033174.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP105\A0033174.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP106\A0033445.com
      Infecté par: Trojan.PWS.OnLineGames.SQZ

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP106\A0033445.com
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP106\A0033445.com
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP107\A0033463.com
      Infecté par: Trojan.PWS.OnLineGames.SQZ

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP107\A0033463.com
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP107\A0033463.com
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP108\A0033649.com
      Infecté par: Trojan.PWS.OnLineGames.SQZ

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP108\A0033649.com
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP108\A0033649.com
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP109\A0033894.com
      Infecté par: Trojan.PWS.OnLineGames.SQZ

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP109\A0033894.com
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP109\A0033894.com
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP109\A0033959.dll
      Infecté par: Trojan.PWS.OnlineGames.SRE

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP109\A0033959.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP109\A0033959.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP109\A0033960.com
      Infecté par: Trojan.PWS.OnLineGames.SQZ

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP109\A0033960.com
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP109\A0033960.com
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP110\A0033963.com
      Infecté par: Trojan.PWS.OnLineGames.SQZ

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP110\A0033963.com
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP110\A0033963.com
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP110\A0034099.dll
      Infecté par: Trojan.PWS.OnLineGames.SQZ

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP110\A0034099.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP110\A0034099.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP110\A0034100.com
      Infecté par: Trojan.PWS.OnLineGames.SQZ

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP110\A0034100.com
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP110\A0034100.com
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP110\A0034110.dll
      Infecté par: Trojan.PWS.OnLineGames.SQZ

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP110\A0034110.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP110\A0034110.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP110\A0034111.com
      Infecté par: Trojan.PWS.OnLineGames.SQZ

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP110\A0034111.com
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP110\A0034111.com
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP110\A0034130.dll
      Infecté par: Trojan.PWS.OnLineGames.SQZ

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP110\A0034130.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP110\A0034130.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP110\A0034131.com
      Infecté par: Trojan.PWS.OnLineGames.SQZ

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP110\A0034131.com
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP110\A0034131.com
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP110\A0034133.exe
      Infecté par: Trojan.PWS.OnLineGames.SQZ

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP110\A0034133.exe
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP110\A0034133.exe
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP111\A0034141.com
      Infecté par: Trojan.PWS.OnlineGames.SRE

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP111\A0034141.com
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP111\A0034141.com
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP111\A0034151.dll
      Infecté par: Trojan.PWS.OnlineGames.SRE

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP111\A0034151.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP111\A0034151.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP111\A0034152.com
      Infecté par: Trojan.PWS.OnlineGames.SRE

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP111\A0034152.com
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP111\A0034152.com
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP111\A0034162.dll
      Infecté par: Trojan.PWS.OnlineGames.SRE

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP111\A0034162.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP111\A0034162.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP111\A0034163.com
      Infecté par: Trojan.PWS.OnlineGames.SRE

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP111\A0034163.com
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP111\A0034163.com
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP111\A0034175.dll
      Infecté par: Trojan.PWS.OnlineGames.SRE

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP111\A0034175.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP111\A0034175.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP111\A0034176.com
      Infecté par: Trojan.PWS.OnlineGames.SRE

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP111\A0034176.com
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP111\A0034176.com
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP111\A0034186.dll
      Infecté par: Trojan.PWS.OnlineGames.SRE

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP111\A0034186.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP111\A0034186.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP111\A0034187.com
      Infecté par: Trojan.PWS.OnlineGames.SRE

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP111\A0034187.com
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP111\A0034187.com
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP112\A0034199.com
      Infecté par: Trojan.PWS.OnlineGames.SRE

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP112\A0034199.com
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP112\A0034199.com
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP113\A0034204.com
      Infecté par: Trojan.PWS.OnlineGames.SRE

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP113\A0034204.com
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP113\A0034204.com
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP113\A0034244.dll
      Infecté par: Trojan.PWS.OnlineGames.SRE

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP113\A0034244.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP113\A0034244.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP114\A0034245.com
      Infecté par: Trojan.PWS.OnlineGames.SRE

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP114\A0034245.com
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP114\A0034245.com
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP114\A0034256.dll
      Infecté par: Trojan.PWS.OnlineGames.SRE

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP114\A0034256.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP114\A0034256.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP114\A0034257.com
      Infecté par: Trojan.PWS.OnlineGames.SRE

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP114\A0034257.com
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP114\A0034257.com
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP114\A0034259.exe
      Infecté par: Trojan.PWS.OnlineGames.SRE

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP114\A0034259.exe
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP114\A0034259.exe
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP114\A0034260.dll
      Infecté par: Trojan.PWS.OnLineGames.SQZ

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP114\A0034260.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP114\A0034260.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP114\A0035256.dll
      Infecté par: Trojan.PWS.OnlineGames.SRE

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP114\A0035256.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP114\A0035256.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP114\A0035269.dll
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP114\A0035269.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP114\A0035269.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP114\A0035270.cmd
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP114\A0035270.cmd
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP114\A0035270.cmd
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP114\A0035280.dll
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP114\A0035280.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP114\A0035280.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP114\A0035281.cmd
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP114\A0035281.cmd
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP114\A0035281.cmd
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP115\A0035283.cmd
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP115\A0035283.cmd
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP115\A0035283.cmd
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP115\A0035294.dll
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP115\A0035294.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP115\A0035294.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP115\A0035295.cmd
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP115\A0035295.cmd
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP115\A0035295.cmd
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP115\A0035305.dll
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP115\A0035305.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP115\A0035305.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP115\A0035306.cmd
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP115\A0035306.cmd
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP115\A0035306.cmd
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP115\A0035316.dll
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP115\A0035316.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP115\A0035316.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP115\A0035317.cmd
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP115\A0035317.cmd
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP115\A0035317.cmd
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP115\A0035329.dll
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP115\A0035329.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP115\A0035329.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP115\A0035330.cmd
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP115\A0035330.cmd
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP115\A0035330.cmd
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP115\A0035340.dll
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP115\A0035340.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP115\A0035340.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP115\A0035341.cmd
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP115\A0035341.cmd
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP115\A0035341.cmd
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035343.cmd
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035343.cmd
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035343.cmd
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035353.dll
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035353.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035353.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035354.cmd
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035354.cmd
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035354.cmd
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035365.dll
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035365.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035365.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035366.cmd
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035366.cmd
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035366.cmd
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035376.dll
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035376.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035376.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035377.cmd
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035377.cmd
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035377.cmd
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035396.dll
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035396.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035396.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035397.cmd
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035397.cmd
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035397.cmd
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035407.dll
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035407.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035407.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035408.cmd
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035408.cmd
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035408.cmd
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035418.dll
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035418.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035418.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035419.cmd
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035419.cmd
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP116\A0035419.cmd
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP117\A0035423.cmd
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP117\A0035423.cmd
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP117\A0035423.cmd
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP117\A0035433.dll
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP117\A0035433.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP117\A0035433.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP117\A0035434.cmd
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP117\A0035434.cmd
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP117\A0035434.cmd
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP117\A0035445.dll
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP117\A0035445.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP117\A0035445.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP117\A0035446.cmd
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP117\A0035446.cmd
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP117\A0035446.cmd
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP117\A0035456.dll
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP117\A0035456.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP117\A0035456.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP117\A0035457.cmd
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP117\A0035457.cmd
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP117\A0035457.cmd
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP117\A0035467.dll
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP117\A0035467.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP117\A0035467.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP117\A0035468.cmd
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP117\A0035468.cmd
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP117\A0035468.cmd
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035470.cmd
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035470.cmd
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035470.cmd
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035480.dll
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035480.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035480.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035481.cmd
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035481.cmd
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035481.cmd
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035502.dll
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035502.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035502.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035503.cmd
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035503.cmd
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035503.cmd
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035513.dll
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035513.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035513.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035514.cmd
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035514.cmd
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035514.cmd
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035524.dll
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035524.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035524.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035525.cmd
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035525.cmd
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035525.cmd
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035535.dll
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035535.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035535.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035536.cmd
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035536.cmd
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035536.cmd
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035541.exe
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035541.exe
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035541.exe
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035542.cmd
      Infecté par: Trojan.PWS.OnlineGames.SRE

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035542.cmd
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035542.cmd
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035543.exe
      Infecté par: Packer.Malware.NSAnti.U

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035543.exe
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035543.exe
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035544.com
      Infecté par: Packer.Malware.NSAnti.U

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035544.com
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0035544.com
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0036535.dll
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0036535.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0036535.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0036536.dll
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0036536.dll
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0036536.dll
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0036537.com
      Infecté par: Trojan.PWS.OnlineGames.SRE

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0036537.com
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP118\A0036537.com
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP120\A0036608.dll=>(Quarantine-2)
      Infecté par: Packer.Malware.NSAnti.R

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP120\A0036608.dll=>(Quarantine-2)
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP120\A0036608.dll=>(Quarantine-2)
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP120\A0036609.dll=>(Quarantine-2)
      Infecté par: Trojan.PWS.OnlineGames.RAB

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP120\A0036609.dll=>(Quarantine-2)
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP120\A0036609.dll=>(Quarantine-2)
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP120\A0036610.exe=>(Quarantine-2)
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP120\A0036610.exe=>(Quarantine-2)
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP120\A0036610.exe=>(Quarantine-2)
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP120\A0036611.exe=>(Quarantine-2)
      Infecté par: Trojan.PWS.OnlineGames.RAB

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP120\A0036611.exe=>(Quarantine-2)
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP120\A0036611.exe=>(Quarantine-2)
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP120\A0036612.cmd=>(Quarantine-2)
      Infecté par: Trojan.PWS.OnlineGames.SRE

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP120\A0036612.cmd=>(Quarantine-2)
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP120\A0036612.cmd=>(Quarantine-2)
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP120\A0036613.exe=>(Quarantine-2)
      Infecté par: Packer.Malware.NSAnti.U

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP120\A0036613.exe=>(Quarantine-2)
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP120\A0036613.exe=>(Quarantine-2)
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP120\A0036614.com=>(Quarantine-2)
      Infecté par: Packer.Malware.NSAnti.U

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP120\A0036614.com=>(Quarantine-2)
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP120\A0036614.com=>(Quarantine-2)
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP120\A0036615.cmd=>(Quarantine-2)
      Infecté par: Packer.Malware.NSAnti.T

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP120\A0036615.cmd=>(Quarantine-2)
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP120\A0036615.cmd=>(Quarantine-2)
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP120\A0036616.dll=>(Quarantine-2)
      Infecté par: Trojan.PWS.OnlineGames.SRE

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP120\A0036616.dll=>(Quarantine-2)
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP120\A0036616.dll=>(Quarantine-2)
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP120\A0036617.dll=>(Quarantine-2)
      Infecté par: Packer.Malware.NSAnti.S

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP120\A0036617.dll=>(Quarantine-2)
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP120\A0036617.dll=>(Quarantine-2)
      Supprimé

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP120\A0036618.dll=>(Quarantine-2)
      Infecté par: Trojan.PWS.OnlineGames.SRE

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP120\A0036618.dll=>(Quarantine-2)
      Echec de la désinfection

      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP120\A0036618.dll=>(Quarantine-2)
      Supprimé
      0
  7. Contributeur sécurité
    ok

    je comprends mieux!

    _______________

    Télécharge RavAntivirus d'Evosla :
    http://ww25.evosla.com/compteur.php?soft=rav_antivirus

    # Si tu as une clé USB, disque dur externe, etc, branche-les sans les ouvrir avant de lancer ce FIX
    # Fais un clic droit sur le fichier .ZIP > Extraire sur > le Bureau
    # Doucle-clique sur >> RAV.exe << afin de lancer l'outil.
    # Une fois RAV ANTIVIRUS lancé, laisse-le réagir , il scanne automatiquement tout les lecteurs (disques fixes et amovibles)
    # Si infection > un log s'établira, sinon le soft affichera (très rapide) ==>Votre Ordinateur est sain .
    # Retire tes disques amovibles et redémarrez votre ordinateur.
    # Poste le rapport, si infection!
    _________________

    Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
    http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
    Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
    • Redémarre ton ordinateur
    • Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
    • A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
    • Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
    • Choisis ton compte.
    Déroule la liste des instructions ci-dessous :
    • Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
    • Appuie sur Y pour commencer le processus de nettoyage.
    • Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
    • Appuie sur une touche pour redémarrer le PC.
    • Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
    • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
    • Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
    • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
    • Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum

    ______________

    scan avec
    MalwareByte's Anti-Malware et vire ce qui est trouvé et colle le rapport

    https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

    ____________

    si tout c'est bien passé désactive la restauration système pour purger les virus qui seraient dedans puis
    redemarre ton ordi
    réactive là : https://www.informatruc.com

    _____________

    vire tout ce qui est en quarantaine dans norton
    _____________
    recolle un scan bitdefender en ligne
    0
    1. Voilà le rapport Report.txt

      [b]SDFix: Version 1.162 [/b]

      Run by Nabila on 27/03/2008 at 17:04

      Microsoft Windows XP [version 5.1.2600]
      Running From: C:\DOCUME~1\Nabila\Bureau\SDFix

      [b]Checking Services [/b]:

      Restoring Windows Registry Values
      Restoring Windows Default Hosts File

      Rebooting

      [b]Checking Files [/b]:

      No Trojan Files Found

      Removing Temp Files

      [b]ADS Check [/b]:

      [b]Final Check [/b]:

      catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2008-03-27 17:24:12
      Windows 5.1.2600 Service Pack 2 NTFS

      scanning hidden processes ...

      scanning hidden services & system hive ...

      scanning hidden registry entries ...

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
      "TracesProcessed"=dword:00000071
      "TracesSuccessful"=dword:00000006

      scanning hidden files ...

      scan completed successfully
      hidden processes: 0
      hidden services: 0
      hidden files: 3

      [b]Remaining Services [/b]:

      Authorized Application Key Export:

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
      "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
      "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
      "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
      "C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
      "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
      "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
      "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

      [b]Remaining Files [/b]:

      File Backups: - C:\DOCUME~1\Nabila\Bureau\SDFix\backups\backups.zip

      [b]Files with Hidden Attributes [/b]:

      Tue 7 Sep 2004 36,864 A..H. --- "C:\Program Files\Samsung\Samsung Battery Manager\igfxexps.dll"
      Tue 7 Sep 2004 106,496 A..H. --- "C:\Program Files\Samsung\Samsung Battery Manager\igfxext.exe"
      Sat 2 Feb 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
      Sun 9 Mar 2008 128,704,971 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\ad213d081e2675ef87a62c73b8abf209\BIT1.tmp"
      Mon 14 Jan 2008 16,891,402 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\c065a2fc85e8c7a034ea63dd1b6a9ff3\download\BIT3F.tmp"

      [b]Finished![/b]
      0
  8. Contributeur sécurité
    ok fais le reste

    a plus
    0
    1. Et voici le rapport Malwarebytes' Anti-Malware :

      Malwarebytes' Anti-Malware 1.09
      Version de la base de données: 551

      Type de recherche: Examen complet (C:\|)
      Eléments examinés: 71705
      Temps écoulé: 1 hour(s), 29 minute(s), 36 second(s)

      Processus mémoire infecté(s): 0
      Module(s) mémoire infecté(s): 0
      Clé(s) du Registre infectée(s): 0
      Valeur(s) du Registre infectée(s): 0
      Elément(s) de données du Registre infecté(s): 0
      Dossier(s) infecté(s): 0
      Fichier(s) infecté(s): 4

      Processus mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Module(s) mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Clé(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Valeur(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Elément(s) de données du Registre infecté(s):
      (Aucun élément nuisible détecté)

      Dossier(s) infecté(s):
      (Aucun élément nuisible détecté)

      Fichier(s) infecté(s):
      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP27\A0001096.dll (Worm.Voterai) -> Quarantined and deleted successfully.
      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP27\A0001100.dll (Worm.Voterai) -> Quarantined and deleted successfully.
      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP37\A0002823.dll (Worm.Voterai) -> Quarantined and deleted successfully.
      C:\System Volume Information\_restore{C559F6E6-92E1-4900-98A2-F6EAFC16BC52}\RP37\A0002828.dll (Worm.Voterai) -> Quarantined and deleted successfully.
      0
  9. Contributeur sécurité
    ok

    si tout c'est bien passé désactive la restauration système pour purger les virus qui seraient dedans puis
    redemarre ton ordi
    réactive là : https://www.informatruc.com

    _____________

    vire tout ce qui est en quarantaine dans norton
    _____________
    recolle un scan bitdefender en ligne

    et dis tes soucis actuels
    0
    1. Et enfin voici le rapport bitdefender :

      BitDefender Online Scanner

      Rapport d'analyse généré à: Thu, Mar 27, 2008 - 21:37:16

      Voie d'analyse: C:\;D:\;

      Statistiques

      Temps
      00:23:25

      Fichiers
      65911

      Directoires
      3960

      Secteurs de boot
      3

      Archives
      701

      Paquets programmes
      6666

      Résultats

      Virus identifiés
      0

      Fichiers infectés
      0

      Fichiers suspects
      0

      Avertissements
      0

      Désinfectés
      0

      Fichiers effacés
      0

      Info sur les moteurs

      Définition virus
      1035557

      Version des moteurs
      AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)

      Analyse des plugins
      16

      Archive des plugins
      41

      Unpack des plugins
      7

      E-mail plugins
      6

      Système plugins
      5

      Paramètres d'analyse

      Première action
      Désinfecté

      Seconde Action
      Supprimé

      Heuristique
      Oui

      Acceptez les avertissements
      Oui

      Extensions analysées
      exe;com;dll;ocx;scr;bin;dat;386;vxd;sys;wdm;cla;class;ovl;ole;hlp;doc;dot;xls;ppt;wbk;wiz;pot;ppa;xla;xlt;vbs;vbe;mdb;rtf;htm;hta;html;xml;xtp;php;asp;js;shs;chm;lnk;pif;prc;url;smm;pfd;msi;ini;csc;cmd;bas;

      Excludez les extensions

      Analyse d'emails
      Oui

      Analyse des Archives
      Oui

      Analyser paquets programmes
      Oui

      Analyse des fichiers
      Oui

      Analyse de boot
      Oui

      Fichier analysé
      Statut

      Aucun virus trouvé.
      0
    2. Un énorme MERCI d'avoir pris le temps de m'aider.

      En fait, le seul problème qu'il reste à régler avec mon pc c'est le démarrage : il est très lent au démarrage et j'aimerai bien que tu m'explique comment optimiser mon pc, parce qu'il y a bcp de programmes inutiles.

      Merci pour tout.
      0
  10. Contributeur sécurité
    pour nettoyer ton pc utilise regulierement ccleaner

    utilise pour supprimer tes traces

    CCLEANER: (lance un nettoyage et répare 3 fois le registre) sans installer la barre yahoo

    https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html
    -----------------------

    pour nettoyer le demarrage:

    fais DEMARRER puis EXECUTER et tape msconfig puis dans l'onglet demarrer decoche ce que tu ne veux pas au demarrage ( au demarrage suivant accepte pour toujours ce qui est demandé)
    0
    1. mon ordinateur affiche à chaque fois la fenêtre autoprotecte aniti virus de symantec, montrant que le virus est détruit et ampêche aussi de faire le scan des discs C et D.je veux résoudre le problème définitivement.
      Si vraiment le Virus Bloodhoud.packed.Jmp est détruit comme le signale mon ordinateur que l'antivirus continue à faire le quick et le full des discs C et D. merci de bien vouloir m'aider
      0
      1. Contributeur sécurité
        cré ton propre post merci
        0