Me revoila !
J'ai effectué toutes tes consignes, Land3, et voici la réponse :
========== PROCESSES ==========
Process explorer.exe killed successfully.
Unable to kill process: SearchSettings.exe
========== FILES ==========
C:\Program Files\Search Settings\kb127\temp moved successfully.
C:\Program Files\Search Settings\kb127\res moved successfully.
C:\Program Files\Search Settings\kb127 moved successfully.
C:\Program Files\Search Settings moved successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFB5F9.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFB616.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_6f4.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.7.1 log created on 11202008_171336
Files moved on Reboot...
File C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFB5F9.tmp not found!
File C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFB616.tmp not found!
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat moved successfully.
File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
C:\WINDOWS\temp\Perflib_Perfdata_6f4.dat moved successfully.
Encore
Ajout du 20-11-2008 à 17:42:
Re-bonjour !
Je signale que les problemes percistent :
C:\DocumentandSetting\Administrateur\rjlwvv.exe
C:\DocumentandSetting\Administrateur\vibwhl.exe
C:\DocumentandSetting\Administrateur\vmzqfe.exe
Tous infectés par Win32:Small-JNV [Trj]
Que faire ?