Problème avec un virus

Bonjour,
Je suis embêté avec un virus.
Mon antivirus ( norton ) le détecte mais n'arrive pas à le supprimer.
Je ne sais pas comment faire pour m'en débarasser !
Ce virus se trouve dan un fichier nommé svchost.exe et il se nomme IRC.Backdoor.Trojan.
merci de me venir en aide par votre réponse.
Configuration: Windows XP
Internet Explorer 6.0

45 réponses

Résumé de la discussion

Infection virale détectée sur Windows XP, où svchost.exe est signalé IRC.Backdoor.Trojan par Norton et nécessite une désinfection approfondie à l'aide d'outils spécialisés pour éviter toute persistance. Des éléments de réponse recommandent d'analyser les fichiers suspects, rendre visibles les dossiers cachés et utiliser des outils de sécurité tels que Malwarebytes et ComboFix pour extraire les traces malveillantes. La procédure conseille également d'utiliser VirusTotal pour les fichiers suspects, et d'analyser les rapports avec des outils tels que Navilog et SDFix, puis de sauvegarder les résultats. Des mesures post-désinfection recommandent de restaurer les paramètres réseau, de vérifier les tâches planifiées et de recréer des points de restauration propres pour prévenir une réinfection.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Merci ..............Mais surtout fais gaffe ou tu met les pieds sur la toile -;)

    Au plaisir de ne pas te revoir ici .
    0
    1. Salut jfkprésident !
      Plus aucun virus n'est détecté par mon antivirus donc j'en déduis que tout est ok lol !!!
      Je ne sais comment te remercier !
      Merci mille fois tu es un dieu en informatique...
      Je te souhaite qu'il t'arrive les meilleures choses au monde...
      Bonne continuation dans la vie...
      Lucien....
      0
      1. voici le rapport !

        [ Rapport ToolsCleaner version 2.3.0 (par A.Rothstein & dj QUIOU) ]

        -->- Recherche:

        C:\Combofix.txt: trouvé !
        C:\fixnavi.txt: trouvé !
        C:\lopR.txt: trouvé !
        C:\SDFIX: trouvé !
        C:\Combofix: trouvé !
        C:\Lop SD: trouvé !
        C:\Qoobox: trouvé !
        C:\Documents and Settings\All Users\Bureau\Navilog1.lnk: trouvé !
        C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1: trouvé !
        C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1\Navilog1.lnk: trouvé !
        C:\Documents and Settings\Lucien\Bureau\SdFix.exe: trouvé !
        C:\Documents and Settings\Lucien\Bureau\LopSD.exe: trouvé !
        C:\Documents and Settings\Lucien\Bureau\Navilog1.exe: trouvé !
        C:\Documents and Settings\Lucien\Bureau\ComboFix.exe: trouvé !
        C:\Documents and Settings\Lucien\Bureau\HijackThis.exe: trouvé !
        C:\Documents and Settings\Lucien\Bureau\hijackthis.log: trouvé !
        C:\Documents and Settings\Lucien\Bureau\dds.scr: trouvé !
        C:\Documents and Settings\Lucien\Mes documents\dds.txt: trouvé !
        C:\Program Files\Navilog1: trouvé !
        C:\Program Files\Navilog1\Navilog1.bat: trouvé !

        ---------------------------------
        -->- Suppression:

        C:\Documents and Settings\All Users\Bureau\Navilog1.lnk: supprimé !
        C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1\Navilog1.lnk: supprimé !
        C:\Documents and Settings\Lucien\Bureau\SdFix.exe: supprimé !
        C:\Documents and Settings\Lucien\Bureau\LopSD.exe: supprimé !
        C:\Documents and Settings\Lucien\Bureau\Navilog1.exe: supprimé !
        C:\Documents and Settings\Lucien\Bureau\ComboFix.exe: ERREUR DE SUPPRESSION !!
        C:\Documents and Settings\Lucien\Bureau\HijackThis.exe: supprimé !
        C:\Program Files\Navilog1\Navilog1.bat: supprimé !
        C:\Combofix.txt: supprimé !
        C:\fixnavi.txt: supprimé !
        C:\lopR.txt: supprimé !
        C:\Documents and Settings\Lucien\Bureau\hijackthis.log: supprimé !
        C:\Documents and Settings\Lucien\Bureau\dds.scr: supprimé !
        C:\Documents and Settings\Lucien\Mes documents\dds.txt: supprimé !
        C:\SDFIX: supprimé !
        C:\Combofix: supprimé !
        C:\Lop SD: supprimé !
        C:\Qoobox: supprimé !
        C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1: supprimé !
        C:\Program Files\Navilog1: supprimé !
        0
        1. Contributeur sécurité
          ok ,

          Pour supprimer toutes les traces des logiciels qui ont servi à traiter les infections spécifiques :

          · Télécharge ToolsCleaner de A.Roshtein sur ton Bureau.
          http://pc-system.fr/
          · Clique sur Recherche et laisse le scan se terminer.
          · Clique, sur Suppression pour finaliser.
          · Tu peux, si tu le souhaites, te servir des Options facultatives.
          · Clique sur Quitter, pour que le rapport puisse se créer.
          · Poste moi le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur( C:\).
          =============================
          Maintenant que ton PC n'est plus infecté, désactive ta "Restauration du système" puis réactive la afin de créer un point de restauration sain.

          * Désactivation :
          Cliquer droit sur le "Poste de travail" > Propriétés > onglet "Restauration du système" > cocher la case "Désactiver la Restauration du système sur tous les lecteurs"
          > Appliquer patiente jusqu a que cela soit marqué "désactivée" puis Ok.

          * Activation :
          Suivre le même chemin ; décocher la case "Désactiver la Restauration du système sur tous les lecteurs"
          > Appliquer attends que cela soit a nouveau sur "surveillance" puis Ok. Redémarrer l'ordinateur..
          ==========================
          Fait les Mise a jour suivantes :

          Mise a jour Xp sp3 : http://www.commentcamarche.net/telecharger/telecharger 34055430 windows xp sp3

          mettre à jour java
          https://www.java.com/fr/download/manual.jsp
          mettre a jour explorer
          https://support.microsoft.com/fr-fr/allproducts
          ==========================
          évite surtout les sites un peu chaud si tu vois ce que je veux dire ...

          un peu de lecture afin de ne pas revenir ici

          Tu peux mettre en résolu si tu n'as plus de soucis .

          Bon surf ! @jamais +

          0
          1. voici le rapport !

            BitDefender Online Scanner

            Scan report generated at: Thu, Jan 29, 2009 - 00:02:42

            Scan path: A:\;C:\;D:\;

            Statistics

            Time
            00:32:07

            Files
            125555

            Folders
            4129

            Boot Sectors
            0

            Archives
            1915

            Packed Files
            8684

            Results

            Identified Viruses
            10

            Infected Files
            42

            Suspect Files
            0

            Warnings
            0

            Disinfected
            0

            Deleted Files
            62

            Engines Info

            Virus Definitions
            2615289

            Engine build
            AVCORE v1.7 (build 8314.19) (i386) (Sep 29 2008 17:19:14)

            Scan plugins
            17

            Archive plugins
            45

            Unpack plugins
            7

            E-mail plugins
            6

            System plugins
            4

            Scan Settings

            First Action
            Disinfect

            Second Action
            Delete

            Heuristics
            Yes

            Enable Warnings
            Yes

            Scanned Extensions
            *;

            Exclude Extensions

            Scan Emails
            Yes

            Scan Archives
            Yes

            Scan Packed
            Yes

            Scan Files
            Yes

            Scan Boot
            Yes

            Scanned File
            Status

            C:\Qoobox\Quarantine\C\mpsn.exe.vir=>(RAR Sfx o)=>svchost.exe
            Infected with: IRC-Worm.Generic.4961

            C:\Qoobox\Quarantine\C\mpsn.exe.vir=>(RAR Sfx o)=>svchost.exe
            Deleted

            C:\Qoobox\Quarantine\C\mpsn.exe.vir=>(RAR Sfx o)
            Update failed

            C:\Qoobox\Quarantine\C\mpsn.exe.vir=>(RAR Sfx o)=>d
            Infected with: Trojan.Irc.Flood.BI

            C:\Qoobox\Quarantine\C\mpsn.exe.vir=>(RAR Sfx o)=>d
            Deleted

            C:\Qoobox\Quarantine\C\mpsn.exe.vir=>(RAR Sfx o)
            Update failed

            C:\Qoobox\Quarantine\C\mpsn.exe.vir=>(RAR Sfx o)=>vir
            Infected with: Trojan.Irc.Flood.Winhelp.F

            C:\Qoobox\Quarantine\C\mpsn.exe.vir=>(RAR Sfx o)=>vir
            Deleted

            C:\Qoobox\Quarantine\C\mpsn.exe.vir=>(RAR Sfx o)
            Update failed

            C:\SDFix\backups\backups.zip=>backups/d
            Infected with: Trojan.Irc.Flood.BI

            C:\SDFix\backups\backups.zip=>backups/d
            Deleted

            C:\SDFix\backups\backups.zip
            Updated

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP431\A0158241.exe
            Detected with: Application.Generic.24435

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP431\A0158241.exe
            Disinfection failed

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP431\A0158241.exe
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162399.exe=>(Quarantine-2)
            Infected with: BehavesLike:Win32.ExplorerHijack

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162399.exe=>(Quarantine-2)
            Disinfection failed

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162399.exe=>(Quarantine-2)
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162399.exe
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162400.exe=>(Quarantine-2)
            Infected with: BehavesLike:Win32.ExplorerHijack

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162400.exe=>(Quarantine-2)
            Disinfection failed

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162400.exe=>(Quarantine-2)
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162400.exe
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162401.exe=>(Quarantine-2)
            Infected with: BehavesLike:Win32.ExplorerHijack

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162401.exe=>(Quarantine-2)
            Disinfection failed

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162401.exe=>(Quarantine-2)
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162401.exe
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162402.exe=>(Quarantine-2)
            Infected with: BehavesLike:Win32.ExplorerHijack

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162402.exe=>(Quarantine-2)
            Disinfection failed

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162402.exe=>(Quarantine-2)
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162402.exe
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162403.sys=>(Quarantine-2)
            Infected with: Rootkit.Kobcka.A

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162403.sys=>(Quarantine-2)
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162403.sys
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162404.sys=>(Quarantine-2)
            Infected with: Rootkit.Kobcka.A

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162404.sys=>(Quarantine-2)
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162404.sys
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162405.sys=>(Quarantine-2)
            Infected with: Rootkit.Kobcka.A

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162405.sys=>(Quarantine-2)
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162405.sys
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162406.exe=>(Quarantine-2)
            Infected with: BehavesLike:Win32.ExplorerHijack

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162406.exe=>(Quarantine-2)
            Disinfection failed

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162406.exe=>(Quarantine-2)
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162406.exe
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162407.dll=>(Quarantine-2)
            Infected with: Trojan.FakeAlert.ABZ

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162407.dll=>(Quarantine-2)
            Disinfection failed

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162407.dll=>(Quarantine-2)
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162407.dll
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162408.sys=>(Quarantine-2)
            Infected with: Rootkit.Kobcka.A

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162408.sys=>(Quarantine-2)
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162408.sys
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162409.sys=>(Quarantine-2)
            Infected with: Rootkit.Kobcka.A

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162409.sys=>(Quarantine-2)
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162409.sys
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162410.dll=>(Quarantine-2)
            Infected with: Trojan.FakeAlert.ABZ

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162410.dll=>(Quarantine-2)
            Disinfection failed

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162410.dll=>(Quarantine-2)
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162410.dll
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162411.sys=>(Quarantine-2)
            Infected with: Rootkit.Kobcka.A

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162411.sys=>(Quarantine-2)
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162411.sys
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162412.exe=>(Quarantine-2)
            Infected with: Trojan.FatObfus.Gen

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162412.exe=>(Quarantine-2)
            Disinfection failed

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162412.exe=>(Quarantine-2)
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162412.exe
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162413.sys=>(Quarantine-2)
            Infected with: Rootkit.Kobcka.A

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162413.sys=>(Quarantine-2)
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162413.sys
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162414.exe=>(Quarantine-2)
            Infected with: Trojan.FatObfus.Gen

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162414.exe=>(Quarantine-2)
            Disinfection failed

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162414.exe=>(Quarantine-2)
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162414.exe
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162415.sys=>(Quarantine-2)
            Infected with: Rootkit.Kobcka.A

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162415.sys=>(Quarantine-2)
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162415.sys
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162416.sys=>(Quarantine-2)
            Infected with: Rootkit.Kobcka.A

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162416.sys=>(Quarantine-2)
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162416.sys
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162417.exe=>(Quarantine-2)
            Infected with: BehavesLike:Win32.ExplorerHijack

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162417.exe=>(Quarantine-2)
            Disinfection failed

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162417.exe=>(Quarantine-2)
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162417.exe
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162418.exe=>(Quarantine-2)
            Infected with: Trojan.FatObfus.Gen

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162418.exe=>(Quarantine-2)
            Disinfection failed

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162418.exe=>(Quarantine-2)
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP464\A0162418.exe
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP472\A0165956.dll
            Infected with: Trojan.Generic.1264054

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP472\A0165956.dll
            Disinfection failed

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP472\A0165956.dll
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP472\A0165957.dll
            Infected with: Trojan.Generic.1264054

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP472\A0165957.dll
            Disinfection failed

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP472\A0165957.dll
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP473\A0166234.dll
            Infected with: Trojan.Generic.1264054

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP473\A0166234.dll
            Disinfection failed

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP473\A0166234.dll
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP473\A0166235.dll
            Infected with: Trojan.Generic.1264054

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP473\A0166235.dll
            Disinfection failed

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP473\A0166235.dll
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP474\A0166318.exe
            Infected with: IRC-Worm.Generic.4961

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP474\A0166318.exe
            Disinfection failed

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP474\A0166318.exe
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP474\A0166489.exe=>(RAR Sfx o)=>svchost.exe
            Infected with: IRC-Worm.Generic.4961

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP474\A0166489.exe=>(RAR Sfx o)=>svchost.exe
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP474\A0166489.exe=>(RAR Sfx o)
            Update failed

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP474\A0166489.exe=>(RAR Sfx o)=>d
            Infected with: Trojan.Irc.Flood.BI

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP474\A0166489.exe=>(RAR Sfx o)=>d
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP474\A0166489.exe=>(RAR Sfx o)
            Update failed

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP474\A0166489.exe=>(RAR Sfx o)=>vir
            Infected with: Trojan.Irc.Flood.Winhelp.F

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP474\A0166489.exe=>(RAR Sfx o)=>vir
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP474\A0166489.exe=>(RAR Sfx o)
            Update failed

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP476\A0167009.exe
            Infected with: Backdoor.IRC.ZGG

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP476\A0167009.exe
            Disinfection failed

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP476\A0167009.exe
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP476\A0167010.exe
            Infected with: Backdoor.IRC.ZGG

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP476\A0167010.exe
            Disinfection failed

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP476\A0167010.exe
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP476\A0167011.exe
            Infected with: Backdoor.IRC.ZGG

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP476\A0167011.exe
            Disinfection failed

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP476\A0167011.exe
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP476\A0167014.dll
            Infected with: Trojan.Generic.1264054

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP476\A0167014.dll
            Disinfection failed

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP476\A0167014.dll
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP476\A0167015.dll
            Infected with: Trojan.Generic.1264054

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP476\A0167015.dll
            Disinfection failed

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP476\A0167015.dll
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP484\A0170325.exe=>(RAR Sfx o)=>svchost.exe
            Infected with: IRC-Worm.Generic.4961

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP484\A0170325.exe=>(RAR Sfx o)=>svchost.exe
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP484\A0170325.exe=>(RAR Sfx o)
            Update failed

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP484\A0170325.exe=>(RAR Sfx o)=>d
            Infected with: Trojan.Irc.Flood.BI

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP484\A0170325.exe=>(RAR Sfx o)=>d
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP484\A0170325.exe=>(RAR Sfx o)
            Update failed

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP484\A0170325.exe=>(RAR Sfx o)=>vir
            Infected with: Trojan.Irc.Flood.Winhelp.F

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP484\A0170325.exe=>(RAR Sfx o)=>vir
            Deleted

            C:\System Volume Information\_restore{4A74F9AE-6BB6-4371-978E-725D2233110D}\RP484\A0170325.exe=>(RAR Sfx o)
            Update failed

            C:\WINDOWS\system\vir
            Infected with: Trojan.Irc.Flood.Winhelp.F

            C:\WINDOWS\system\vir
            Deleted
            0
            1. Contributeur sécurité
              tout est dans le tutoriel .
              0
              1. euh je vais sur internet explorer mais activeX ?
                la barre anti pop up ?
                merci de ta réponse...
                0
                1. le pc va bien pour le moment !
                  j'effectue la démarche et t'envoies le rapport !
                  0
                  1. Contributeur sécurité
                    Comment va le pc ?

                    On fait une derniere vérif avant de conclure :

                    Fais ce scan anti-virus en ligne avec Internet Explorer, accepte l'active X;

                    la barre anti-popup du SP2 (en haut) va se mettre à clignoter,
                    clic dessus et choisis "accepter l'active X" pour faire fonctionner le scan anti-virus.
                    Une fois qu'il a terminé colle le rapport ici stp
                    https://www.bitdefender.com/toolbox/
                    Copie/Colle le rapport

                    tutoriel
                    0
                    1. voici le rapport !

                      ComboFix 09-01-21.04 - Lucien 2009-01-28 17:35:06.2 - NTFSx86
                      Microsoft Windows XP Professionnel 5.1.2600.1.1252.1.1036.18.959.594 [GMT 1:00]
                      Running from: c:\documents and settings\Lucien\Bureau\ComboFix.exe
                      Command switches used :: c:\documents and settings\Lucien\Bureau\CFscript.txt
                      * Created a new restore point

                      WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

                      FILE ::
                      C:\mpsn.exe
                      C:\osy.exe
                      .

                      ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
                      .

                      C:\mpsn.exe
                      C:\osy.exe

                      .
                      ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                      .

                      -------\Legacy_ATI2UXXX
                      -------\Service_ati0gjxx
                      -------\Service_ati0ycxx
                      -------\Service_ati2uxxx
                      -------\Service_ati4ehxx
                      -------\Service_ati5xbxx
                      -------\Service_ati6nqxx
                      -------\Service_ati6uxxx
                      -------\Service_ati7xbxx

                      ((((((((((((((((((((((((( Files Created from 2008-12-28 to 2009-01-28 )))))))))))))))))))))))))))))))
                      .

                      2009-01-23 07:20 . 2009-01-23 07:20 <REP> d-------- c:\program files\Viewpoint
                      2009-01-23 07:20 . 2009-01-23 07:20 <REP> d-------- c:\documents and settings\All Users\Application Data\Viewpoint
                      2009-01-22 21:39 . 2009-01-22 21:39 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
                      2009-01-22 21:39 . 2009-01-22 21:39 <REP> d-------- c:\documents and settings\Lucien\Application Data\Malwarebytes
                      2009-01-22 21:39 . 2009-01-22 21:39 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
                      2009-01-22 21:39 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
                      2009-01-22 21:39 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys
                      2009-01-22 21:16 . 2009-01-22 21:25 <REP> d-------- C:\Lop SD
                      2009-01-22 19:38 . 2009-01-22 20:31 <REP> d-------- c:\program files\Navilog1
                      2009-01-22 18:48 . 2009-01-22 18:48 <REP> d-------- c:\windows\ERUNT
                      2009-01-22 17:55 . 2009-01-22 19:00 <REP> d-------- C:\SDFix
                      2009-01-21 19:30 . 2009-01-21 19:30 <REP> d-------- c:\program files\SymNetDrv
                      2009-01-21 19:20 . 2009-01-21 19:30 <REP> d-------- c:\program files\Symantec

                      .
                      (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
                      .
                      2009-01-21 21:50 --------- d-----w c:\program files\Norton AntiVirus
                      2009-01-21 21:50 --------- d-----w c:\program files\Fichiers communs\Symantec Shared
                      2009-01-21 18:08 --------- d-----w c:\program files\Yahoo!
                      2008-12-16 14:26 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
                      2008-12-08 16:31 --------- d-----w c:\program files\Alwil Software
                      2008-12-07 10:18 12,800 ----a-w c:\windows\system32\svchost.exe
                      2007-04-28 15:03 54,648 ----a-w c:\documents and settings\Nathalie\Application Data\GDIPFONTCACHEV1.DAT
                      2006-12-01 17:40 28,301 ----a-w c:\program files\Bambi[1].2.FRENCH.DVDRip.XviD-LOST .torrent
                      2006-12-01 17:39 14,246 ----a-w c:\program files\Walt[1].Disney Bambi .avi.torrent
                      2006-12-01 17:38 54,938 ----a-w c:\program files\Disney_Rox Et Roucky[1].avi.torrent
                      2006-12-01 17:37 52,102 ----a-w c:\program files\Blanche Neige Et Les 7 Nains[1].avi.torrent
                      2006-12-01 17:37 31,499 ----a-w c:\program files\la belle et la bete.torrent
                      2006-12-01 17:37 28,263 ----a-w c:\program files\Robin des Bois[1].avi.torrent
                      2006-12-01 17:36 31,200 ----a-w c:\program files\Frere[1].des.Ours.2.(2006).FRENCH.Xvid-lrd.torrent
                      2006-12-01 17:27 42,502 ----a-w c:\program files\les simpson saison 9 episode 16,17 et 18[1].rar.torrent
                      2006-11-26 17:58 12,833,359 ----a-w c:\program files\setupProfEcole.exe
                      2006-11-23 21:38 119,808 ----a-w c:\program files\construction_d_une_sequence.ppt
                      2006-11-21 14:12 8,282,187 ----a-w c:\program files\vlc-0.8.5-win32.exe
                      2006-11-07 18:47 836 ----a-w c:\documents and settings\Lucien\Application Data\ViewerApp.dat
                      2006-11-03 22:25 278,528 ----a-w c:\program files\Fichiers communs\FDEUnInstaller.exe
                      .

                      ((((((((((((((((((((((((((((( snapshot@2009-01-24_10.33.25,23 )))))))))))))))))))))))))))))))))))))))))
                      .
                      + 2005-10-20 19:02:28 163,328 ----a-w c:\windows\ERDNT\subs\ERDNT.EXE
                      - 2009-01-23 21:39:35 16,384 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
                      + 2009-01-28 16:37:58 16,384 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
                      - 2009-01-23 21:39:35 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\index.dat
                      + 2009-01-28 16:37:58 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\index.dat
                      - 2009-01-23 21:39:35 65,536 ----a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
                      + 2009-01-28 16:37:58 65,536 ----a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
                      .
                      ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
                      .
                      .
                      *Note* empty entries & legit default entries are not shown
                      REGEDIT4

                      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "CTFMON.EXE"="c:\windows\System32\ctfmon.exe" [2002-08-29 13312]
                      "MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
                      "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\lib\NMBgMonitor.exe" [2005-10-28 94208]

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "AOLDialer"="c:\program files\Fichiers communs\AOL\ACS\AOLDial.exe" [2007-05-16 71216]
                      "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-11-03 98304]
                      "SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_09\bin\jusched.exe" [2006-10-12 49263]
                      "MPFExe"="c:\progra~1\McAfee.com\PERSON~1\MpfTray.exe" [2003-08-19 1048576]
                      "WorksFUD"="c:\program files\Microsoft Works\wkfud.exe" [2000-07-12 24576]
                      "Microsoft Works Portfolio"="c:\program files\Microsoft Works\WksSb.exe" [2000-07-12 311350]
                      "Microsoft Works Update Detection"="c:\program files\Microsoft Works\WkDetect.exe" [2000-08-04 28739]
                      "SSC_UserPrompt"="c:\program files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe" [2004-11-10 218240]
                      "RaidTool"="c:\program files\VIA\RAID\raid_tool.exe" [2005-11-23 1060864]
                      "RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2007-03-09 26112]
                      "NeroFilterCheck"="c:\windows\System32\NeroCheck.exe" [2001-07-09 155648]
                      "AOLSAV"="c:\progra~1\TECHCI~1\AOLSAV\AOLAgent.exe" [2004-03-15 73728]
                      "HostManager"="c:\program files\Fichiers communs\AOL\1179168765\ee\AOLSoftware.exe" [2006-11-17 50736]
                      "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
                      "ccApp"="c:\program files\Fichiers communs\Symantec Shared\ccApp.exe" [2006-04-04 71304]
                      "NAV CfgWiz"="c:\program files\Fichiers communs\Symantec Shared\CfgWiz.exe" [2003-08-22 124048]
                      "Symantec NetDriver Monitor"="c:\progra~1\SYMNET~1\SNDMon.exe" [2009-01-21 95960]
                      "VTTimer"="VTTimer.exe" [2005-03-07 c:\windows\system32\VTTimer.exe]
                      "S3Trayp"="S3trayp.exe" [2005-04-04 c:\windows\system32\S3Trayp.exe]

                      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                      "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2002-08-29 13312]
                      "ALUAlert"="c:\program files\Symantec\LiveUpdate\ALUNotify.exe" [2008-08-01 152952]

                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
                      "AppInit_DLLs"=ywxdwl.dll

                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati0gjxx.sys]
                      @="Driver"

                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati0ycxx.sys]
                      @="Driver"

                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati2uxxx.sys]
                      @="Driver"

                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati4ehxx.sys]
                      @="Driver"

                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati5xbxx.sys]
                      @="Driver"

                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati6nqxx.sys]
                      @="Driver"

                      R3 S3G700;S3G700;c:\windows\system32\drivers\S3G700m.sys [2007-03-09 792576]

                      [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{28ABC5C0-4FCB-11CF-AAX5-21CX5C574571}]
                      c:\config\S-1-5-21-1482476501-1644491937-682003330-1013\Cfg.exe
                      .
                      Contents of the 'Scheduled Tasks' folder

                      2009-01-28 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
                      - c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2006-07-07 17:26]

                      2009-01-23 c:\windows\Tasks\Norton AntiVirus - Analyser mon ordinateur.job
                      - c:\progra~1\NORTON~1\Navw32.exe [2003-12-04 20:06]
                      .
                      .
                      ------- Supplementary Scan -------
                      .
                      uStart Page = hxxp://www.a2articles.com
                      uSearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
                      IE: &Recherche AOL Toolbar - c:\program files\aol\aol toolbar 2.0\resources\fr-FR\local\search.html
                      IE: &Traduire à partir de l'anglais - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html
                      IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
                      IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
                      IE: Ouvrir dans un nouvel onglet d'arrière-plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?289d6e19bf494bbdbe121c8aba3d0bd5
                      IE: Ouvrir dans un nouvel onglet de premier plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?289d6e19bf494bbdbe121c8aba3d0bd5
                      IE: Pages liées - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
                      IE: Pages similaires - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
                      IE: Recherche &Google - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
                      IE: Version de la page actuelle disponible dans le cache Google - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
                      IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
                      DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
                      DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
                      DPF: {8731163E-77B9-4F91-9122-F112521C28AF} - hxxp://mmt.bouyguestelecom.fr/mmawap/jsp/composer/player/mmsPlayer.cab
                      .

                      **************************************************************************

                      catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                      Rootkit scan 2009-01-28 17:38:23
                      Windows 5.1.2600 Service Pack 1 NTFS

                      scanning hidden processes ...

                      scanning hidden autostart entries ...

                      HKLM\Software\Microsoft\Windows\CurrentVersion\Run
                      AOLSAV = c:\progra~1\TECHCI~1\AOLSAV\AOLAgent.exe?e?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

                      scanning hidden files ...

                      scan completed successfully
                      hidden files: 0

                      **************************************************************************
                      .
                      --------------------- DLLs Loaded Under Running Processes ---------------------

                      - - - - - - - > 'winlogon.exe'(676)
                      c:\windows\System32\ODBC32.dll

                      - - - - - - - > 'lsass.exe'(732)
                      c:\windows\System32\dssenh.dll
                      .
                      ------------------------ Other Running Processes ------------------------
                      .
                      c:\program files\Fichiers communs\Symantec Shared\CCSETMGR.EXE
                      c:\program files\Fichiers communs\Symantec Shared\CCEVTMGR.EXE
                      c:\program files\Fichiers communs\AOL\ACS\AOLacsd.exe
                      c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                      c:\progra~1\McAfee.com\PERSON~1\MpfService.exe
                      c:\program files\Norton AntiVirus\navapsvc.exe
                      c:\windows\wanmpsvc.exe
                      c:\progra~1\McAfee.com\PERSON~1\MpfAgent.exe
                      c:\program files\Fichiers communs\AOL\1179168765\ee\services\antiSpywareApp\ver2_0_28_1\AOLSP Scheduler.exe
                      c:\program files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
                      c:\program files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
                      c:\program files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe
                      c:\program files\Messenger\msmsgs.exe
                      .
                      **************************************************************************
                      .
                      Completion time: 2009-01-28 19:05:21 - machine was rebooted
                      ComboFix-quarantined-files.txt 2009-01-28 18:05:19
                      ComboFix2.txt 2009-01-24 09:34:51

                      Pre-Run: 121 559 085 056 octets libres
                      Post-Run: 121,550,372,864 octets libres

                      193
                      0
                      1. Contributeur sécurité
                        ça ne fonctionne pas quand je suis la procédure il me met un message comme quoi i386 a été placé peut être à un emplacement différent...

                        On va faire sans ...

                        > Ferme tout tes navigateurs (donc copie ou imprime les instructions avant)
                        - Crée un nouveau document texte : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie/colle dedans les lignes suivantes :

                        Driver::
                        ati0gjxx
                        ati0ycxx
                        ati2uxxx
                        ati4ehxx
                        ati5xbxx
                        ati6nqxx
                        ati6uxxx
                        ati7xbxx
                        Folder::

                        File::
                        C:\mpsn.exe
                        C:\osy.exe
                        Reg::
                        [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati0gjxx.sys]
                        [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati0ycxx.sys]
                        [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati2uxxx.sys]
                        [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati4ehxx.sys]
                        [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati5xbxx.sys]
                        [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati6nqxx.sys]

                        - Enregistre ce fichier sous le nom CFScript
                        - Fait un glisser/déposer de ce fichier CFScrïpt sur le fichier ComboFix.exe comme sur cette image. (Clique sur le fichier CFScript, maintient le doigt enfoncé et glisse la souris pour que l'icône du CFScript vienne recouvrir l'icône de Combofix. Relache la souris.) Combofix va démarrer.
                        - Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
                        - Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!
                        - Ne touche à rien tant que le scan n'est pas terminé sinon le PC peut planter !
                        - Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
                        Note : Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt

                        0
                        1. ça ne fonctionne pas quand je suis la procédure il me met un message comme quoi i386 a été placé peut être à un emplacement différent...
                          Je suis bloqué !!!
                          Au secours..
                          0
                          1. Contributeur sécurité
                            tout y est expliqué sur le tuto (en bas ) .
                            0
                            1. désolé mais je suis perdu !
                              glisser déposer ?
                              0
                              1. Contributeur sécurité
                                tu as fait le "glisser/deposer" sur l'icone combofix ?
                                0
                                1. j'ai enregistré winxp-fr-pro mais maintenant que dois je faire ?
                                  l'icone est sur monb ureau mais maintenant que dois je faire merci ?
                                  0
                                  1. Contributeur sécurité
                                    ca remarche ,je ne pouvais plus poster de messages !

                                    installer la console de recup avec combofix
                                    0
                                    1. je n'ai pas le cd d'installation de windows !!!
                                      0
                                      • 1
                                      • 2
                                      • 3