Virus ??

Bonjour,

je suis de ses peré :( ....mon ordi est pret à etre reformaté je crains, mais avant de passer 8 heures supplementaires à re installer tout , quelqun aurait peut etre une solution à mon probleme :
Plusieurs trucs qui ne vont plus
1. Les icones du bureau ne reste plus à leur place et se regroupe à chaque actualisation sur le coté gauche
2. au demarrage une fenetre affiche " Le service de pare feu n'est pas en cours d'execution
3. la restauration de systeme est bloqué
4. Mon antivirus GDATA ne veut plus faire une mise à jour des virus ( " le programme n'a pas pu etre chargé ")
5. au bout de qq acces internet je perd ma connexion ( " LOCAL seulement")

C est triste tout ca je trouve, quelqun aurait une idée ?? ( à part le suicide :)

je me permet de coller le log Hijack:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 08:49:13, on 07/06/2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\G Data\InternetSecurity\AVKTray\AVKTray.exe
C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp64&d=1006&m=aspire_x1300
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://portail.free.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp64&d=1006&m=aspire_x1300
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp64&d=1006&m=aspire_x1300
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: BHO - {BA3295CF-17ED-4F49-9E95-D999A0ADBFDC} - C:\Program Files (x86)\Common Files\G DATA\AVKProxy\BanksafeBHO.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [G Data AntiVirus Tray Application] C:\Program Files (x86)\G Data\InternetSecurity\AVKTray\AVKTray.exe
O4 - HKLM\..\Run: [GDFirewallTray] C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files (x86)\CCleaner\CCleaner.exe" /AUTO
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User '?')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User '?')
O4 - HKUS\S-1-5-21-1215366262-1287831330-3407394165-1000\..\Run: [ccleaner] "C:\Program Files (x86)\CCleaner\CCleaner.exe" /AUTO (User '?')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube Download - C:\Users\ARNE\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\ARNE\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: Garmin Communicator Plug-In - https://static.garmincdn.com/gcp/ie/2.9.3.0/GarminAxControl.CAB
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://fichiers.touslesdrivers.com/maconfig/MaConfig_4_0_2_0.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - http://193.252.30.219/activex/AMC.cab
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\aelupsvc.dll,-1 (AeLookupSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%systemroot%\system32\appinfo.dll,-100 (Appinfo) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-204 (AudioEndpointBuilder) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-200 (AudioSrv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: G Data AntiVirus Proxy (AVKProxy) - Unknown owner - C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe
O23 - Service: @%SystemRoot%\system32\qmgr.dll,-1000 (BITS) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\browser.dll,-100 (Browser) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\certprop.dll,-11 (CertPropSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\cryptsvc.dll,-1001 (CryptSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @oleres.dll,-5012 (DcomLaunch) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: @%SystemRoot%\system32\dhcpcsvc.dll,-100 (Dhcp) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\dnsapi.dll,-101 (Dnscache) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\dot3svc.dll,-1102 (dot3svc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\dps.dll,-500 (DPS) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\eapsvc.dll,-1 (EapHost) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: EBP Pervasive.SQL - Unknown owner - C:\PVSW\Bin\WGE_SRV.exe
O23 - Service: @%SystemRoot%\ehome\ehrecvr.exe,-101 (ehRecvr) - Unknown owner - C:\Windows\ehome\ehRecvr.exe
O23 - Service: @%SystemRoot%\ehome\ehsched.exe,-101 (ehSched) - Unknown owner - C:\Windows\ehome\ehsched.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\emdmgmt.dll,-1000 (EMDMgmt) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wevtsvc.dll,-200 (Eventlog) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @comres.dll,-2450 (EventSystem) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\fdPHost.dll,-100 (fdPHost) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\fdrespub.dll,-100 (FDResPub) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\FntCache.dll,-100 (FontCache) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\bin32\nSvcAppFlt.exe
O23 - Service: Pare-feu personnel G Data (GDFwSvc) - G Data Software AG - C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFwSvcx64.exe
O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: Service Google Update (gupdate) (gupdate) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Service Google Update (gupdatem) (gupdatem) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\System32\hidserv.dll,-101 (hidserv) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\kmsvc.dll,-6 (hkmsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: hpqcxs08 - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: Service HP CUE DeviceDiscovery (hpqddsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\ikeext.dll,-501 (IKEEXT) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\IPBusEnum.dll,-102 (IPBusEnum) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2946 (KtmRm) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\srvsvc.dll,-100 (LanmanServer) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\wkssvc.dll,-100 (LanmanWorkstation) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\lltdres.dll,-1 (lltdsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\lmhsvc.dll,-101 (lmhosts) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\mmcss.dll,-100 (MMCSS) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\iscsidsc.dll,-5000 (MSiSCSI) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\msimsg.dll,-27 (msiserver) - Unknown owner - C:\Windows\system32\msiexec.exe
O23 - Service: @%SystemRoot%\system32\qagentrt.dll,-6 (napagent) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: Net Driver HPZ12 - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\netman.dll,-109 (Netman) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\netprof.dll,-246 (netprofm) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\nlasvc.dll,-1 (NlaSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\nsisvc.dll,-200 (nsi) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\bin32\nSvcIp.exe
O23 - Service: @%SystemRoot%\system32\p2psvc.dll,-8004 (p2pimsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\p2psvc.dll,-8006 (p2psvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\pcasvc.dll,-1 (PcaSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\sysWow64\perfhost.exe,-2 (PerfHost) - Unknown owner - C:\Windows\SysWow64\perfhost.exe
O23 - Service: @%systemroot%\system32\pla.dll,-500 (pla) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\umpnpmgr.dll,-100 (PlugPlay) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: Pml Driver HPZ12 - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\p2psvc.dll,-8002 (PNRPAutoReg) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\p2psvc.dll,-8000 (PNRPsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\polstore.dll,-5010 (PolicyAgent) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\profsvc.dll,-300 (ProfSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\rasauto.dll,-200 (RasAuto) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\rasmans.dll,-200 (RasMan) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @oleres.dll,-5010 (RpcSs) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\System32\SCardSvr.dll,-1 (SCardSvr) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\schedsvc.dll,-100 (Schedule) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\certprop.dll,-13 (SCPolicySvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\sdrsvc.dll,-107 (SDRSVC) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\Sens.dll,-200 (SENS) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\SessEnv.dll,-1026 (SessionEnv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\shsvcs.dll,-12288 (ShellHWDetection) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLUINotify.dll,-103 (SLUINotify) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%systemroot%\system32\ssdpsrv.dll,-100 (SSDPSRV) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\sstpsvc.dll,-200 (SstpSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wiaservc.dll,-9 (stisvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\swprv.dll,-103 (swprv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\sysmain.dll,-1000 (SysMain) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\TabSvc.dll,-100 (TabletInputService) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\tapisrv.dll,-10100 (TapiSrv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\tbssvc.dll,-100 (TBS) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\termsrv.dll,-268 (TermService) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\shsvcs.dll,-8192 (Themes) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\mmcss.dll,-102 (THREADORDER) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\trkwks.dll,-1 (TrkWks) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\servicing\TrustedInstaller.exe,-100 (TrustedInstaller) - Unknown owner - C:\Windows\servicing\TrustedInstaller.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%systemroot%\system32\upnphost.dll,-213 (upnphost) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\dwm.exe,-2000 (UxSms) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\w32time.dll,-200 (W32Time) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wcncsvc.dll,-3 (wcncsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\WcsPlugInService.dll,-200 (WcsPlugInService) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\wdi.dll,-502 (WdiServiceHost) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\wdi.dll,-500 (WdiSystemHost) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\webclnt.dll,-100 (WebClient) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wecsvc.dll,-200 (Wecsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wercplsupport.dll,-101 (wercplsupport) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wersvc.dll,-100 (WerSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\winhttp.dll,-100 (WinHttpAutoProxySvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\wbem\wmisvc.dll,-205 (Winmgmt) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\wsmsvc.dll,-101 (WinRM) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wlansvc.dll,-257 (Wlansvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: @%SystemRoot%\system32\wpcsvc.dll,-100 (WPCSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wpdbusenum.dll,-100 (WPDBusEnum) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100 (WPFFontCache_v0400) - Unknown owner - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe
O23 - Service: @%systemroot%\system32\SearchIndexer.exe,-103 (WSearch) - Unknown owner - C:\Windows\system32\SearchIndexer.exe
O23 - Service: @%systemroot%\system32\wuaueng.dll,-105 (wuauserv) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wudfsvc.dll,-1000 (wudfsvc) - Unknown owner - C:\Windows\system32\svchost.exe

--
End of file - 19497 bytes

35 réponses

Résumé de la discussion

Plusieurs symptômes touchent Windows Vista : les icônes du bureau se regroupent à l’actualisation, le pare-feu ne démarre pas et la restauration système est bloquée. Des solutions essentielles impliquent d’examiner les services liés au pare-feu et à la sécurité, de vérifier les composants de démarrage et d’évaluer les anomalies éventuelles détectées par un outil d’analyse. Le log HijackThis joint révèle de nombreux modules tiers et des LSP inconnus, ainsi que des services potentiellement douteux, ce qui peut indiquer une infection ou une désinfection insuffisante. La présence répétée d’un fichier nvlsp.dll et d’éléments Windows Live peut renforcer la piste d’une corruption système ou d’une intrusion.

Bobot (l’IA à votre service)
  1. Microsoft Windows [version 6.0.6002]
    Copyright (c) 2006 Microsoft Corporation. Tous droits réservés.

    C:\Users\ARNE>ipconfig /all

    Configuration IP de Windows

    Nom de l'hôte . . . . . . . . . . : PC-de-ARNE
    Suffixe DNS principal . . . . . . :
    Type de noeud. . . . . . . . . . : Hybride
    Routage IP activé . . . . . . . . : Non
    Proxy WINS activé . . . . . . . . : Non

    Carte Ethernet Connexion au réseau local :

    Suffixe DNS propre à la connexion. . . :
    Description. . . . . . . . . . . . . . : NVIDIA nForce 10/100/1000 Mbps Netwo
    rking Controller
    Adresse physique . . . . . . . . . . . : 00-1F-16-F4-E8-AE
    DHCP activé. . . . . . . . . . . . . . : Oui
    Configuration automatique activée. . . : Oui
    Adresse IPv6 de liaison locale. . : fe80::5515:3bc0:856b:d044%10(préféré)
    Adresse IPv4. . . . . . . . . . . : 192.168.0.11(préféré)
    Masque de sous-réseau. . . . . . . . . : 255.255.255.0
    Bail obtenu. . . . . . . . . . . . . . : vendredi 29 juin 2012 19:03:02
    Bail expirant. . . . . . . . . . . . . : samedi 30 juin 2012 07:03:02
    Passerelle par défaut. . . . . . . . . : 192.168.0.254
    Serveur DHCP . . . . . . . . . . . . . : 192.168.0.254
    IAID DHCPv6 . . . . . . . . . . . : 218109651
    DUID de client DHCPv6. . . . . . . . : 00-01-00-01-0C-BC-97-2D-00-1F-16-F4-E8
    -AE
    Serveurs DNS. . . . . . . . . . . . . : 192.168.0.254
    NetBIOS sur Tcpip. . . . . . . . . . . : Activé

    Carte Tunnel Connexion au réseau local* :

    Statut du média. . . . . . . . . . . . : Média déconnecté
    Suffixe DNS propre à la connexion. . . :
    Description. . . . . . . . . . . . . . : isatap.{A9BC1F18-5B7C-47EA-A542-ACF2
    EE590401}
    Adresse physique . . . . . . . . . . . : 00-00-00-00-00-00-00-E0
    DHCP activé. . . . . . . . . . . . . . : Non
    Configuration automatique activée. . . : Oui

    Carte Tunnel Connexion au réseau local* 6 :

    Statut du média. . . . . . . . . . . . : Média déconnecté
    Suffixe DNS propre à la connexion. . . :
    Description. . . . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
    Adresse physique . . . . . . . . . . . : 02-00-54-55-4E-01
    DHCP activé. . . . . . . . . . . . . . : Non
    Configuration automatique activée. . . : Oui

    C:\Users\ARNE>
    1. Contributeur sécurité
      Tu vas foire ceci
      Clique sur démarrer, puis executer et tu tapes cmd puis entrée.
      ensuite dans la fenêtre noire tu tapes IPCONFIG /ALL puis entrées
      Ensuite tu postes le résultat dans ta réponse

      Smart
      1. Contributeur sécurité
        Tu es connecté en Wifi ou par Ethernet

        Smart
        1. Contributeur sécurité
          Fais un clic droit sur ta connexion (2 écrans et cliques sur réparer)

          Smart
          1. ...ce que je ne comprends pas c est que quand je reinitialise le pare feu ... mes reseaux cochés sont les suivants :

            Connexion au reseau local
            Connexion haut debit
            SFR GPRS
            SFR GSM DATA

            je suis chez FREE pourtant !!??

            en plus je peux aller sur le net, MAIS l'icone connexion ( 2 ecrans) dans la barre en bas de l ecran a droite me dit NON CONNECTé / vous n etes actuellement connecté à aucun reseau.....
            1. RogueKiller V7.5.4 [07/06/2012] par Tigzy
              mail: tigzyRK<at>gmail<dot>com
              Remontees: http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html
              Blog: http://tigzyrk.blogspot.com

              Systeme d'exploitation: Windows Vista (6.0.6002 Service Pack 2) 64 bits version
              Demarrage : Mode normal
              Utilisateur: ARNE [Droits d'admin]
              Mode: Raccourcis RAZ -- Date: 15/06/2012 18:44:49

              ¤¤¤ Processus malicieux: 0 ¤¤¤

              ¤¤¤ Driver: [NON CHARGE] ¤¤¤

              ¤¤¤ Attributs de fichiers restaures: ¤¤¤
              Bureau: Success 0 / Fail 0
              Lancement rapide: Success 0 / Fail 0
              Programmes: Success 0 / Fail 0
              Menu demarrer: Success 0 / Fail 0
              Dossier utilisateur: Success 43 / Fail 0
              Mes documents: Success 0 / Fail 0
              Mes favoris: Success 0 / Fail 0
              Mes images: Success 0 / Fail 0
              Ma musique: Success 0 / Fail 0
              Mes videos: Success 0 / Fail 0
              Disques locaux: Success 1 / Fail 0
              Sauvegarde: [NOT FOUND]

              Lecteurs:
              [C:] \Device\HarddiskVolume2 -- 0x3 --> Restored
              [D:] \Device\HarddiskVolume3 -- 0x3 --> Restored
              [E:] \Device\CdRom0 -- 0x5 --> Skipped
              [G:] \Device\HarddiskVolume4 -- 0x2 --> Restored
              [H:] \Device\HarddiskVolume5 -- 0x2 --> Restored

              ¤¤¤ Infection : ¤¤¤

              Termine : << RKreport[4].txt >>
              RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt ; RKreport[4].txt
              1. voila...

                RogueKiller V7.5.4 [07/06/2012] par Tigzy
                mail: tigzyRK<at>gmail<dot>com
                Remontees: http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html
                Blog: http://tigzyrk.blogspot.com

                Systeme d'exploitation: Windows Vista (6.0.6002 Service Pack 2) 64 bits version
                Demarrage : Mode normal
                Utilisateur: ARNE [Droits d'admin]
                Mode: Suppression -- Date: 15/06/2012 18:42:04

                ¤¤¤ Processus malicieux: 0 ¤¤¤

                ¤¤¤ Entrees de registre: 0 ¤¤¤

                ¤¤¤ Fichiers / Dossiers particuliers: ¤¤¤

                ¤¤¤ Driver: [NON CHARGE] ¤¤¤

                ¤¤¤ Infection : ¤¤¤

                ¤¤¤ Fichier HOSTS: ¤¤¤
                127.0.0.1 localhost
                ::1 localhost

                ¤¤¤ MBR Verif: ¤¤¤

                +++++ PhysicalDrive0: WDC WD64 00AAKS-22A7B SCSI Disk Device +++++
                --- User ---
                [MBR] 732a19690e6e9c86a4027fdabcd8eb1c
                [BSP] 5f3b64d1643978e8ec7a507d31e4ed0a : Acer tatooed MBR Code
                Partition table:
                0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 15360 Mo
                1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 31459328 | Size: 297558 Mo
                2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 640858112 | Size: 297560 Mo
                User = LL1 ... OK!
                Error reading LL2 MBR!

                Termine : << RKreport[3].txt >>
                RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt
                1. Contributeur sécurité
                  Il faut que tu lances RogueKiller en mode administrateur. As-tu bien fait clic droit lancer en tant qu'administrateur.
                  Ou alors connecte toi avec un utilisateur ayant les droits administrateur
                  Car je vois toujours cette ligne:
                  Utilisateur: ARNE [Droits restreints]

                  Smart
                  1. RogueKiller V7.5.4 [07/06/2012] par Tigzy
                    mail: tigzyRK<at>gmail<dot>com
                    Remontees: http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html
                    Blog: http://tigzyrk.blogspot.com

                    Systeme d'exploitation: Windows Vista (6.0.6002 Service Pack 2) 64 bits version
                    Demarrage : Mode normal
                    Utilisateur: ARNE [Droits restreints]
                    Mode: Raccourcis RAZ -- Date: 14/06/2012 21:08:17

                    ¤¤¤ Processus malicieux: 3 ¤¤¤
                    [SUSP PATH] adwcleaner.exe -- C:\Users\ARNE\Desktop\Applications peu utilisées\NETTOYAGE\adwcleaner.exe -> KILLED [TermProc]
                    [SUSP PATH] adwcleaner.exe -- C:\Users\ARNE\Desktop\Applications peu utilisées\NETTOYAGE\adwcleaner.exe -> KILLED [TermProc]
                    [SUSP PATH] adwcleaner.exe -- C:\Users\ARNE\Desktop\Applications peu utilisées\NETTOYAGE\adwcleaner.exe -> KILLED [TermProc]

                    ¤¤¤ Driver: [NON CHARGE] ¤¤¤

                    ¤¤¤ Attributs de fichiers restaures: ¤¤¤
                    Bureau: Success 0 / Fail 0
                    Lancement rapide: Success 0 / Fail 0
                    Programmes: Success 0 / Fail 0
                    Menu demarrer: Success 0 / Fail 0
                    Dossier utilisateur: Success 2 / Fail 0
                    Mes documents: Success 0 / Fail 0
                    Mes favoris: Success 0 / Fail 0
                    Mes images: Success 0 / Fail 0
                    Ma musique: Success 0 / Fail 0
                    Mes videos: Success 0 / Fail 0
                    Disques locaux: Success 1 / Fail 3
                    Sauvegarde: [NOT FOUND]

                    Lecteurs:
                    [C:] \Device\HarddiskVolume2 -- 0x3 --> Restored
                    [D:] \Device\HarddiskVolume3 -- 0x3 --> Restored
                    [E:] \Device\CdRom0 -- 0x5 --> Skipped
                    [G:] \Device\HarddiskVolume4 -- 0x2 --> Restored
                    [H:] \Device\HarddiskVolume5 -- 0x2 --> Restored

                    ¤¤¤ Infection : ¤¤¤

                    Termine : << RKreport[3].txt >>
                    RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt
                    1. RogueKiller V7.5.4 [07/06/2012] par Tigzy
                      mail: tigzyRK<at>gmail<dot>com
                      Remontees: http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html
                      Blog: http://tigzyrk.blogspot.com

                      Systeme d'exploitation: Windows Vista (6.0.6002 Service Pack 2) 64 bits version
                      Demarrage : Mode normal
                      Utilisateur: ARNE [Droits restreints]
                      Mode: Recherche -- Date: 14/06/2012 21:06:16

                      ¤¤¤ Processus malicieux: 3 ¤¤¤
                      [SUSP PATH] adwcleaner.exe -- C:\Users\ARNE\Desktop\Applications peu utilisées\NETTOYAGE\adwcleaner.exe -> KILLED [TermProc]
                      [SUSP PATH] adwcleaner.exe -- C:\Users\ARNE\Desktop\Applications peu utilisées\NETTOYAGE\adwcleaner.exe -> KILLED [TermProc]
                      [SUSP PATH] adwcleaner.exe -- C:\Users\ARNE\Desktop\Applications peu utilisées\NETTOYAGE\adwcleaner.exe -> KILLED [TermProc]

                      ¤¤¤ Entrees de registre: 54 ¤¤¤
                      [] HKLM\[...]\Run : () -> ACCESS DENIED
                      [] HKLM\[...]\Wow6432Node\Run : () -> ACCESS DENIED
                      [] HKLM\[...]\RunOnce : () -> ACCESS DENIED
                      [] HKLM\[...]\Wow6432Node\RunOnce : () -> ACCESS DENIED
                      [] HKLM\[...]\Wow6432Node\RunOnceEx : () -> ACCESS DENIED
                      [] HKLM\[...]\Winlogon : () -> ACCESS DENIED
                      [] HKLM\[...]\Windows : () -> ACCESS DENIED
                      [] HKLM\[...]\Wow6432Node\Winlogon : () -> ACCESS DENIED
                      [] HKLM\[...]\Wow6432Node\Windows : () -> ACCESS DENIED
                      [] HKLM\[...]\services : () -> ACCESS DENIED
                      [] HKLM\[...]\services : () -> ACCESS DENIED
                      [] HKLM\[...]\Root : () -> ACCESS DENIED
                      [] HKLM\[...]\Root : () -> ACCESS DENIED
                      [] HKLM\[...]\Internet Settings : () -> ACCESS DENIED
                      [] HKLM\[...]\Parameters : () -> ACCESS DENIED
                      [] HKLM\[...]\Parameters : () -> ACCESS DENIED
                      [] HKLM\[...]\Image File Execution Options : () -> ACCESS DENIED
                      [] HKCU\[...]\System : () -> ACCESS DENIED
                      [] HKCU\[...]\System : () -> ACCESS DENIED
                      [] HKCU\[...]\System : () -> ACCESS DENIED
                      [] HKLM\[...]\System : () -> ACCESS DENIED
                      [] HKLM\[...]\System : () -> ACCESS DENIED
                      [] HKLM\[...]\System : () -> ACCESS DENIED
                      [] HKLM\[...]\Policies\Explorer\Explorer : () -> ACCESS DENIED
                      [] HKLM\[...]\Policies\Explorer\Explorer : () -> ACCESS DENIED
                      [] HKLM\[...]\SystemRestore : () -> ACCESS DENIED
                      [] HKLM\[...]\System : () -> ACCESS DENIED
                      [] HKLM\[...]\System : () -> ACCESS DENIED
                      [] HKLM\[...]\System : () -> ACCESS DENIED
                      [] HKLM\[...]\Security Center : () -> ACCESS DENIED
                      [] HKLM\[...]\Security Center : () -> ACCESS DENIED
                      [] HKLM\[...]\Security Center : () -> ACCESS DENIED
                      [] HKCR\[...]\InprocServer32 : () -> ACCESS DENIED
                      [] HKLM\[...]\ClassicStartMenu : () -> ACCESS DENIED
                      [] HKLM\[...]\NewStartPanel : () -> ACCESS DENIED
                      [] HKLM\[...]\ClassicStartMenu : () -> ACCESS DENIED
                      [] HKLM\[...]\NewStartPanel : () -> ACCESS DENIED
                      [] HKLM\[...]\ClassicStartMenu : () -> ACCESS DENIED
                      [] HKLM\[...]\NewStartPanel : () -> ACCESS DENIED
                      [] HKLM\[...]\command : () -> ACCESS DENIED
                      [] HKCR\[...]\command : () -> ACCESS DENIED
                      [] HKCR\[...].exe : () -> ACCESS DENIED
                      [] HKLM\[...]\command : () -> ACCESS DENIED
                      [] HKCR\[...]\command : () -> ACCESS DENIED
                      [] HKLM\[...]\SafeBoot : () -> ACCESS DENIED
                      [] HKLM\[...]\SafeBoot : () -> ACCESS DENIED
                      [] HKCR\[...]\InprocServer32 : () -> ACCESS DENIED
                      [] HKLM\[...]\Windows : () -> ACCESS DENIED
                      [] HKLM\[...]\ShellServiceObjectDelayLoad : () -> ACCESS DENIED
                      [] HKLM\[...]\SharedTaskScheduler : () -> ACCESS DENIED
                      [] HKLM\[...]\Browser Helper Objects : () -> ACCESS DENIED
                      [] HKLM\[...]\Run : () -> ACCESS DENIED
                      [] HKLM\[...]\Services : () -> ACCESS DENIED
                      [] HKLM\[...]\Services : () -> ACCESS DENIED

                      ¤¤¤ Fichiers / Dossiers particuliers: ¤¤¤

                      ¤¤¤ Driver: [NON CHARGE] ¤¤¤

                      ¤¤¤ Infection : ¤¤¤

                      ¤¤¤ Fichier HOSTS: ¤¤¤
                      127.0.0.1 localhost
                      ::1 localhost

                      ¤¤¤ MBR Verif: ¤¤¤

                      Termine : << RKreport[2].txt >>
                      RKreport[1].txt ; RKreport[2].txt
                      1. Contributeur sécurité
                        Il faut que tu lances RogueKiller en tant qu'administrateur
                        Fais un clic droit sur RogueKiller et puis lancer en tant qu'administrateur

                        * Attendre la fin du Prescan ...
                        * Clique sur Scan.
                        * A la fin du scan
                        * Clique sur Suppression. Clique sur Rapport. Copie et colle le rapport dans ta réponse

                        Smart
                        1. RogueKiller V7.5.4 [07/06/2012] par Tigzy
                          mail: tigzyRK<at>gmail<dot>com
                          Remontees: http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html
                          Blog: http://tigzyrk.blogspot.com

                          Systeme d'exploitation: Windows Vista (6.0.6002 Service Pack 2) 64 bits version
                          Demarrage : Mode normal
                          Utilisateur: ARNE [Droits restreints]
                          Mode: Recherche -- Date: 11/06/2012 22:05:39

                          ¤¤¤ Processus malicieux: 0 ¤¤¤

                          ¤¤¤ Entrees de registre: 54 ¤¤¤
                          [] HKLM\[...]\Run : () -> ACCESS DENIED
                          [] HKLM\[...]\Wow6432Node\Run : () -> ACCESS DENIED
                          [] HKLM\[...]\RunOnce : () -> ACCESS DENIED
                          [] HKLM\[...]\Wow6432Node\RunOnce : () -> ACCESS DENIED
                          [] HKLM\[...]\Wow6432Node\RunOnceEx : () -> ACCESS DENIED
                          [] HKLM\[...]\Winlogon : () -> ACCESS DENIED
                          [] HKLM\[...]\Windows : () -> ACCESS DENIED
                          [] HKLM\[...]\Wow6432Node\Winlogon : () -> ACCESS DENIED
                          [] HKLM\[...]\Wow6432Node\Windows : () -> ACCESS DENIED
                          [] HKLM\[...]\services : () -> ACCESS DENIED
                          [] HKLM\[...]\services : () -> ACCESS DENIED
                          [] HKLM\[...]\Root : () -> ACCESS DENIED
                          [] HKLM\[...]\Root : () -> ACCESS DENIED
                          [] HKLM\[...]\Internet Settings : () -> ACCESS DENIED
                          [] HKLM\[...]\Parameters : () -> ACCESS DENIED
                          [] HKLM\[...]\Parameters : () -> ACCESS DENIED
                          [] HKLM\[...]\Image File Execution Options : () -> ACCESS DENIED
                          [] HKCU\[...]\System : () -> ACCESS DENIED
                          [] HKCU\[...]\System : () -> ACCESS DENIED
                          [] HKCU\[...]\System : () -> ACCESS DENIED
                          [] HKLM\[...]\System : () -> ACCESS DENIED
                          [] HKLM\[...]\System : () -> ACCESS DENIED
                          [] HKLM\[...]\System : () -> ACCESS DENIED
                          [] HKLM\[...]\Policies\Explorer\Explorer : () -> ACCESS DENIED
                          [] HKLM\[...]\Policies\Explorer\Explorer : () -> ACCESS DENIED
                          [] HKLM\[...]\SystemRestore : () -> ACCESS DENIED
                          [] HKLM\[...]\System : () -> ACCESS DENIED
                          [] HKLM\[...]\System : () -> ACCESS DENIED
                          [] HKLM\[...]\System : () -> ACCESS DENIED
                          [] HKLM\[...]\Security Center : () -> ACCESS DENIED
                          [] HKLM\[...]\Security Center : () -> ACCESS DENIED
                          [] HKLM\[...]\Security Center : () -> ACCESS DENIED
                          [] HKCR\[...]\InprocServer32 : () -> ACCESS DENIED
                          [] HKLM\[...]\ClassicStartMenu : () -> ACCESS DENIED
                          [] HKLM\[...]\NewStartPanel : () -> ACCESS DENIED
                          [] HKLM\[...]\ClassicStartMenu : () -> ACCESS DENIED
                          [] HKLM\[...]\NewStartPanel : () -> ACCESS DENIED
                          [] HKLM\[...]\ClassicStartMenu : () -> ACCESS DENIED
                          [] HKLM\[...]\NewStartPanel : () -> ACCESS DENIED
                          [] HKLM\[...]\command : () -> ACCESS DENIED
                          [] HKCR\[...]\command : () -> ACCESS DENIED
                          [] HKCR\[...].exe : () -> ACCESS DENIED
                          [] HKLM\[...]\command : () -> ACCESS DENIED
                          [] HKCR\[...]\command : () -> ACCESS DENIED
                          [] HKLM\[...]\SafeBoot : () -> ACCESS DENIED
                          [] HKLM\[...]\SafeBoot : () -> ACCESS DENIED
                          [] HKCR\[...]\InprocServer32 : () -> ACCESS DENIED
                          [] HKLM\[...]\Windows : () -> ACCESS DENIED
                          [] HKLM\[...]\ShellServiceObjectDelayLoad : () -> ACCESS DENIED
                          [] HKLM\[...]\SharedTaskScheduler : () -> ACCESS DENIED
                          [] HKLM\[...]\Browser Helper Objects : () -> ACCESS DENIED
                          [] HKLM\[...]\Run : () -> ACCESS DENIED
                          [] HKLM\[...]\Services : () -> ACCESS DENIED
                          [] HKLM\[...]\Services : () -> ACCESS DENIED

                          ¤¤¤ Fichiers / Dossiers particuliers: ¤¤¤

                          ¤¤¤ Driver: [NON CHARGE] ¤¤¤

                          ¤¤¤ Infection : ¤¤¤

                          ¤¤¤ Fichier HOSTS: ¤¤¤
                          127.0.0.1 localhost
                          ::1 localhost

                          ¤¤¤ MBR Verif: ¤¤¤

                          Termine : << RKreport[1].txt >>
                          RKreport[1].txt

                          RogueKiller V7.5.4 [07/06/2012] par Tigzy
                          mail: tigzyRK<at>gmail<dot>com
                          Remontees: http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html
                          Blog: http://tigzyrk.blogspot.com

                          Systeme d'exploitation: Windows Vista (6.0.6002 Service Pack 2) 64 bits version
                          Demarrage : Mode normal
                          Utilisateur: ARNE [Droits restreints]
                          Mode: Raccourcis RAZ -- Date: 11/06/2012 22:07:40

                          ¤¤¤ Processus malicieux: 0 ¤¤¤

                          ¤¤¤ Driver: [NON CHARGE] ¤¤¤

                          ¤¤¤ Attributs de fichiers restaures: ¤¤¤
                          Bureau: Success 0 / Fail 0
                          Lancement rapide: Success 0 / Fail 0
                          Programmes: Success 0 / Fail 0
                          Menu demarrer: Success 0 / Fail 0
                          Dossier utilisateur: Success 44 / Fail 0
                          Mes documents: Success 0 / Fail 0
                          Mes favoris: Success 0 / Fail 0
                          Mes images: Success 0 / Fail 0
                          Ma musique: Success 0 / Fail 0
                          Mes videos: Success 0 / Fail 0
                          Disques locaux: Success 1 / Fail 3
                          Sauvegarde: [NOT FOUND]

                          Lecteurs:
                          [C:] \Device\HarddiskVolume2 -- 0x3 --> Restored
                          [D:] \Device\HarddiskVolume3 -- 0x3 --> Restored
                          [E:] \Device\CdRom0 -- 0x5 --> Skipped
                          [G:] \Device\HarddiskVolume4 -- 0x2 --> Restored
                          [H:] \Device\HarddiskVolume5 -- 0x2 --> Restored

                          ¤¤¤ Infection : ¤¤¤

                          Termine : << RKreport[2].txt >>
                          RKreport[1].txt ; RKreport[2].txt
                          1. Contributeur sécurité
                            En faisant une restauration système tu as dû rendre actif l'infection

                            Relance RogueKiller:

                            * Attendre la fin du Prescan ...
                            * Clique sur Scan.
                            * A la fin du scan
                            * Clique sur Suppression. Clique sur Rapport. Copie et colle le rapport dans ta réponse
                            * * Clique sur Racc. RAZ. Clique sur Rapport. Copier et coller le rapport dans ta réponse

                            Smart
                            1. adw cleaner reste bloqué et revient a chaque fois sur la fenetre " executer" :(...quoi faire ? :(
                              j ai qq applications que je n arrive pas faire demarrer...fenetre " le programme cesse de fonctionner" :(
                              1. Contributeur sécurité
                                Tu n'as pas passer AdwCleaner en option suppression". Fias le et poste le rapport.
                                Car tu as des adwares et des barres d'outilas néfastes et/ou inutiles

                                Smart
                                1. j ai reussi de faire une restauration de system , ca a l air de marcher là. Je te remercie beaucoup pour ton aide !! ;)
                                  1. RogueKiller V7.5.3 [05/06/2012] par Tigzy
                                    mail: tigzyRK<at>gmail<dot>com
                                    Remontees: http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html
                                    Blog: http://tigzyrk.blogspot.com

                                    Systeme d'exploitation: Windows Vista (6.0.6002 Service Pack 2) 64 bits version
                                    Demarrage : Mode normal
                                    Utilisateur: ARNE [Droits d'admin]
                                    Mode: Raccourcis RAZ -- Date: 07/06/2012 14:25:35

                                    ¤¤¤ Processus malicieux: 0 ¤¤¤

                                    ¤¤¤ Driver: [NON CHARGE] ¤¤¤

                                    ¤¤¤ Attributs de fichiers restaures: ¤¤¤
                                    Bureau: Success 0 / Fail 0
                                    Lancement rapide: Success 0 / Fail 0
                                    Programmes: Success 0 / Fail 0
                                    Menu demarrer: Success 0 / Fail 0
                                    Dossier utilisateur: Success 10 / Fail 0
                                    Mes documents: Success 0 / Fail 0
                                    Mes favoris: Success 0 / Fail 0
                                    Mes images: Success 0 / Fail 0
                                    Ma musique: Success 0 / Fail 0
                                    Mes videos: Success 0 / Fail 0
                                    Disques locaux: Success 1 / Fail 0
                                    Sauvegarde: [NOT FOUND]

                                    Lecteurs:
                                    [C:] \Device\HarddiskVolume2 -- 0x3 --> Restored
                                    [D:] \Device\HarddiskVolume3 -- 0x3 --> Restored
                                    [E:] \Device\CdRom0 -- 0x5 --> Skipped
                                    [G:] \Device\HarddiskVolume4 -- 0x2 --> Restored
                                    [H:] \Device\HarddiskVolume5 -- 0x2 --> Restored

                                    ¤¤¤ Infection : ¤¤¤

                                    Termine : << RKreport[2].txt >>
                                    RKreport[1].txt ; RKreport[2].txt
                                    • 1
                                    • 2