Pb page internet s'ouvre toute seule, trojan?

bonjour,
j'ai moi aussi un pb de pages internet qui s'ouvrent toutes seules,
j'ai essayé de lire de nombreux forums sur le sujet mais avoue ne rien n'y comprendre

ce sont souvent des pages vierges sans liens et plus rarement de la pub
je suis sous vista
on m'a conseillé de changer avast pour Avira antivir mais ça n'a rien changer pur l'instant

j'ai vu qu'un rapport hijackthis permettait d'en savoir plus alors ci desous le mien

d'avance merci à tous ceux qui prendront le temps de m'aider,

Logfile of HijackThis v1.99.1
Scan saved at 07:55:28, on 18/02/2009
Platform: Unknown Windows (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16809)

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\tsnp2std.exe
C:\Program Files\System Control Manager\MGSysCtrl.exe
C:\Windows\vsnp2std.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\uTorrent\uTorrent.exe
c:\users\beren\appdata\local\sacam.exe
C:\Windows\system32\PresentationSettings.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
C:\Users\beren\Desktop\test.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msi.com.tw
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [tsnp2std] C:\Windows\tsnp2std.exe
O4 - HKLM\..\Run: [MGSysCtrl] C:\Program Files\System Control Manager\MGSysCtrl.exe
O4 - HKLM\..\Run: [snp2std] C:\Windows\vsnp2std.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [aeiaeek] "c:\users\beren\appdata\local\aeiaeek.exe" aeiaeek
O4 - HKCU\..\Run: [ycayqso] "c:\users\beren\appdata\local\ycayqso.exe" ycayqso
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [sacam] "c:\users\beren\appdata\local\sacam.exe" sacam
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Cooking%20Dash/Images/stg_drm.ocx
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/VistaMSNPUpldfr-fr.cab
O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} (Image Uploader Control) - http://copainsdavant.linternaute.com/html_include_bibliotheque/objimageuploader/5.0.15.0/ImageUploader5.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Cooking%20Dash/Images/armhelper.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://files-mjf.jeuxvideo-flash.com/popcap/popcaploader_v10_fr.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: SCM Driver Daemon (NishService) - Unknown owner - C:\Program Files\System Control Manager\edd.exe
O23 - Service: O2Micro Flash Memory (O2Flash) - O2Micro International - C:\Windows\system32\o2flash.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
Configuration: Windows Vista
Internet Explorer 7.0

13 réponses

  1. Contributeur sécurité
    Salut,

    ta version de Hijack est obsolète

    vire la et télécharge la ici

    TrendMicro™ HijackThis™

    relance hijack et coche cette ligne

    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://files-mjf.jeuxvideo-flash.com/popcap/popcaploader_v10_fr.cab

    clic sur fix checked

    ensuite

    /!\IMPORTANT/!\
    Désactive l'UAC (User Account Control ou Contrôle de Compte Utilisateur) le temps de la désinfection,tu le réactiveras après ta désinfection:
    • Va dans Panneau de Configuration puis Comptes d'Utilisateurs.
    • Clique sur Activer ou désactiver le contrôle des comptes utilisateurs.
    • Décoche la case Utiliser le contrôle des comptes utilisateurs pour vous aider à protéger votre ordinateur.
    • Clique sur OK pour enregistrer la modification et redémarre ton PC lorsque cela t'est demandé.

    aide en cas de problèmes

    ensuite

    Télécharge Navilog1.exe de il mafioso

    Note : Si, lors du téléchargement, ton Antivirus fais une alerte, ignore-là, un composant de Navilog1 est détecté par certains AntiVirus comme étant un Malware .
    Ce n'en est nullement un !


    * Choisis Enregistrer sous.... et enregistre-le sur ton bureau.
    * Sous XP, double clique sur navilog1.exe pour lancer l'installation.
    **Sous VISTA, fais un clic droit dessus et dans le menu contextuel choisis "Exécuter en tant qu'administrateur".
    tuto pour vista

    Une fois l'installation terminée, fais un clic droit sur le raccourci Navilog1
    présent sur ton bureau et choisis "Exécuter en tant qu'administrateur".
    (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

    Laisse-toi guider. Au menu principal, choisis 1 et valide.
    (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

    * Patiente jusqu'au message :
    ***Analyse Termine le.....***
    * Appuie sur une touche comme demandé, le bloc-note va s'ouvrir.
    * Copie/colle l'intégralité du rapport dans ta réponse.
    Referme le bloc-note.

    * Le rapport est en outre sauvegardé à la racine du disque C:\ (fixnavi.txt)

    Copie/colle le ici dans ta prochaine réponse stp.
    0
    1. Contributeur sécurité
      attention,j'ai édité mon message
      0
      1. merci beaucoup pour ton aide,

        j'ai fais tout ce que tu m'as dis et voila le rapport:

        Search Navipromo version 3.7.4 commencé le 18/02/2009 à 13:15:59,47

        !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
        !!! Postez ce rapport sur le forum pour le faire analyser !!!
        !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

        Outil exécuté depuis C:\Program Files\navilog1

        Mise à jour le 16.02.2009 à 18h00 par IL-MAFIOSO

        Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6000 )
        X86-based PC ( Multiprocessor Free : AMD Athlon(tm) 64 X2 Dual Core Processor TK-53 )
        BIOS : A1632NMS Ver7.08
        USER : beren ( Administrator )
        BOOT : Normal boot

        Antivirus : Norton Internet Security 2007 (Activated)
        Firewall : Norton Internet Security 2007 (Not Activated)

        C:\ (Local Disk) - NTFS - Total:34 Go (Free:15 Go)
        D:\ (Local Disk) - NTFS - Total:109 Go (Free:90 Go)
        E:\ (CD or DVD)

        Recherche executé en mode normal

        *** Recherche Programmes installés ***
        *** Recherche dossiers dans "C:\Windows" ***
        *** Recherche dossiers dans "C:\Program Files" ***
        *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***
        *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1" ***
        *** Recherche dossiers dans "C:\ProgramData" ***
        *** Recherche dossiers dans "c:\users\beren\appdata\roaming\micros~1\windows\startm~1\programs" ***
        *** Recherche dossiers dans "C:\Users\beren\AppData\Local\virtualstore\Program Files" ***
        ...\InternetGameBox trouvé !
        *** Recherche dossiers dans "C:\Users\beren\AppData\Local" ***
        *** Recherche dossiers dans "C:\Users\beren\AppData\Roaming" ***
        *** Recherche avec GenericNaviSearch ***
        !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
        !!! A vérifier impérativement avant toute suppression manuelle !!!

        * Recherche dans "C:\Windows\system32" *
        * Recherche dans "C:\Users\beren\AppData\Local\Microsoft" *
        * Recherche dans "C:\Users\beren\AppData\Local" *

        *** Recherche fichiers ***

        *** Recherche clés spécifiques dans le Registre ***
        !! Les clés trouvées ne sont pas forcément infectées !!

        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "aeiaeek"="\"c:\\users\\beren\\appdata\\local\\aeiaeek.exe\" aeiaeek"

        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "ycayqso"="\"c:\\users\\beren\\appdata\\local\\ycayqso.exe\" ycayqso"

        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "sacam"="\"c:\\users\\beren\\appdata\\local\\sacam.exe\" sacam"

        *** Module de Recherche complémentaire ***
        (Recherche fichiers spécifiques)

        1)Recherche nouveaux fichiers Instant Access :

        2)Recherche Heuristique :

        * Dans "C:\Windows\system32" :
        * Dans "C:\Users\beren\AppData\Local\Microsoft" :
        * Dans "C:\Users\beren\AppData\Local" :
        sacam.exe trouvé !
        sacam.dat trouvé !
        sacam_nav.dat trouvé !
        sacam_navps.dat trouvé !

        3)Recherche Certificats :
        Certificat Egroup trouvé !
        Certificat Electronic-Group trouvé !
        Certificat Montorgueil absent !
        Certificat OOO-Favorit trouvé !
        Certificat Sunny-Day-Design-Ltd absent !

        4)Recherche autres dossiers et fichiers connus :

        *** Analyse terminée le 18/02/2009 à 13:17:17,89 ***

        j'attends tes futures indications pour la suite
        0
        1. Contributeur sécurité
          Relance Navilog, Sur le menu principal, choisis l'option 2.
          Suis les instructions et patiente.
          L'outil va t'informer qu'il redémarrera ton ordinateur.
          Sauvegarde les documents ouverts, s'il y en a, puis ferme toutes les fenêtres.
          Appuie sur une touche ainsi que demandé.
          Si ton ordinateur ne redémarre pas automatiquement, fais le manuellement.
          Choisis ta session habituelle si nécessaire.
          Patiente jusqu'au message *** Nettoyage terminé le ….*** (il se peut que ça prenne un certain temps).
          Un document du Bloc-notes est créé. Sauvegarde le rapport de manière à le retrouver.
          * Copie/colle le contenu de ce compte-rendu dans ta prochaine réponse.
          Referme le Bloc-notes.
          Ton Bureau va réapparaître.

          Note : Si ton Bureau ne réapparaît pas, presse Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
          Onglet "Processus" > Fichier (menu) > Nouvelle tâche (Exécuter...) > tape explorer et clique sur OK.
          0
          1. bonsoir,

            voilà le rapport obtenu:

            Clean Navipromo version 3.7.4 commencé le 18/02/2009 à 18:05:42,60

            Outil exécuté depuis C:\Program Files\navilog1

            Mise à jour le 16.02.2009 à 18h00 par IL-MAFIOSO

            Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6000 )
            X86-based PC ( Multiprocessor Free : AMD Athlon(tm) 64 X2 Dual Core Processor TK-53 )
            BIOS : A1632NMS Ver7.08
            USER : beren ( Administrator )
            BOOT : Normal boot

            Antivirus : Norton Internet Security 2007 (Activated)
            Firewall : Norton Internet Security 2007 (Not Activated)

            C:\ (Local Disk) - NTFS - Total:34 Go (Free:15 Go)
            D:\ (Local Disk) - NTFS - Total:109 Go (Free:90 Go)
            E:\ (CD or DVD)

            Mode suppression automatique
            avec prise en charge résultats Catchme et GNS

            Nettoyage exécuté au redémarrage de l'ordinateur

            *** fsbl1.txt non trouvé ***
            (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)

            *** Suppression avec sauvegardes résultats GenericNaviSearch ***

            * Suppression dans "C:\Windows\System32" *

            * Suppression dans "C:\Users\beren\AppData\Local\Microsoft" *

            * Suppression dans "C:\Users\beren\AppData\Local" *

            *** Suppression dossiers dans "C:\Windows" ***

            *** Suppression dossiers dans "C:\Program Files" ***

            *** Suppression dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

            *** Suppression dossiers dans "c:\progra~2\micros~1\windows\startm~1" ***

            *** Suppression dossiers dans "C:\ProgramData" ***

            *** Suppression dossiers dans c:\users\beren\appdata\roaming\micros~1\windows\startm~1\programs ***

            *** Suppression dossiers dans "C:\Users\beren\AppData\Local\virtualstore\Program Files" ***

            ...\InternetGamebox ...suppression...
            ...\InternetGamebox supprimé !

            *** Suppression dossiers dans "C:\Users\beren\AppData\Local" ***

            *** Suppression dossiers dans "C:\Users\beren\AppData\Roaming" ***

            *** Suppression fichiers ***

            *** Suppression fichiers temporaires ***

            Nettoyage contenu C:\Windows\Temp effectué !
            Nettoyage contenu C:\Users\beren\AppData\Local\Temp effectué !

            *** Traitement Recherche complémentaire ***
            (Recherche fichiers spécifiques)

            1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

            2)Recherche, création sauvegardes et suppression Heuristique :

            * Dans "C:\Windows\system32" *

            C:\Windows\prefetch\sacam*.pf trouvé !
            Copie C:\Windows\prefetch\sacam*.pf réalisée avec succès !
            C:\Windows\prefetch\sacam*.pf supprimé !

            * Dans "C:\Users\beren\AppData\Local\Microsoft" *

            * Dans "C:\Users\beren\AppData\Local" *

            sacam.exe trouvé !
            Copie sacam.exe réalisée avec succès !
            sacam.exe supprimé !

            sacam.dat trouvé !
            Copie sacam.dat réalisée avec succès !
            sacam.dat supprimé !

            sacam_nav.dat trouvé !
            Copie sacam_nav.dat réalisée avec succès !
            sacam_nav.dat supprimé !

            sacam_navps.dat trouvé !
            Copie sacam_navps.dat réalisée avec succès !
            sacam_navps.dat supprimé !

            *** Sauvegarde du Registre vers dossier Safebackup ***

            sauvegarde du Registre réalisée avec succès !

            *** Nettoyage Registre ***

            Nettoyage Registre Ok

            *** Certificats ***

            Certificat Egroup supprimé !
            Certificat Electronic-Group supprimé !
            Certificat Montorgueil absent !
            Certificat OOO-Favorit supprimé !
            Certificat Sunny-Day-Design-Ltdt absent !

            *** Recherche autres dossiers et fichiers connus ***

            *** Nettoyage terminé le 18/02/2009 à 18:22:06,35 ***

            et maintenant je fais quoi de plus?
            encore merci
            0
            1. Contributeur sécurité
              re,

              poste moi un nouveau rapport Hijack stp
              0
              1. bonjour,
                voilà le nouveau rapport

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 12:50:58, on 19/02/2009
                Platform: Windows Vista (WinNT 6.00.1904)
                MSIE: Internet Explorer v7.00 (7.00.6000.16809)
                Boot mode: Normal

                Running processes:
                C:\Windows\system32\taskeng.exe
                C:\Windows\system32\Dwm.exe
                C:\Windows\Explorer.EXE
                C:\Windows\tsnp2std.exe
                C:\Program Files\System Control Manager\MGSysCtrl.exe
                C:\Windows\System32\rundll32.exe
                C:\Windows\vsnp2std.exe
                C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                C:\Program Files\PopUp Destroy\Popup-Destroy.exe
                C:\Program Files\Windows Sidebar\sidebar.exe
                C:\Windows\ehome\ehtray.exe
                C:\Windows\system32\wbem\unsecapp.exe
                C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
                C:\Windows\system32\PresentationSettings.exe
                C:\Windows\ehome\ehmsas.exe
                C:\Windows\system32\wuauclt.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Windows\system32\SearchFilterHost.exe
                C:\Users\beren\Desktop\HiJackThis.exe
                C:\Windows\system32\DllHost.exe

                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msi.com.tw
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                O1 - Hosts: ::1 localhost
                O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                O4 - HKLM\..\Run: [tsnp2std] C:\Windows\tsnp2std.exe
                O4 - HKLM\..\Run: [MGSysCtrl] C:\Program Files\System Control Manager\MGSysCtrl.exe
                O4 - HKLM\..\Run: [snp2std] C:\Windows\vsnp2std.exe
                O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                O4 - HKLM\..\Run: [PopUp Destroy] C:\Program Files\PopUp Destroy\Popup-Destroy.exe
                O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
                O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
                O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O13 - Gopher Prefix:
                O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Cooking%20Dash/Images/stg_drm.ocx
                O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/VistaMSNPUpldfr-fr.cab
                O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} (Image Uploader Control) - http://copainsdavant.linternaute.com/html_include_bibliotheque/objimageuploader/5.0.15.0/ImageUploader5.cab
                O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Cooking%20Dash/Images/armhelper.ocx
                O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://files-mjf.jeuxvideo-flash.com/popcap/popcaploader_v10_fr.cab
                O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
                O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                O23 - Service: SCM Driver Daemon (NishService) - Unknown owner - C:\Program Files\System Control Manager\edd.exe
                O23 - Service: O2Micro Flash Memory (O2Flash) - O2Micro International - C:\Windows\system32\o2flash.exe
                O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                0
                1. Contributeur sécurité
                  relance hijack(scan only) et coche ces lignes

                  O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://files-mjf.jeuxvideo-flash.com/popcap/popcaploader_v10_fr.cab
                  O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Cooking%20Dash/Images/stg_drm.ocx
                  O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Cooking%20Dash/Images/armhelper.ocx

                  clic sur fix checked

                  ensuite

                  Télécharge Malwarebytes' Anti-Malware et enregistre le sur ton Bureau.
                  https://www.malwarebytes.com/

                  (NB : S'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharges le ici : https://www.malekal.com/tutorial-aboutbuster/ )

                  A la fin du téléchargement, ferme toutes les fenêtres et programmes, y compris celui-ci.
                  Double-clique sur l'icône "Download_mbam-setup.exe" sur ton bureau pour démarrer le programme d'installation.

                  Pendant l'installation, suis les indications n'apporte aucune modification aux réglages par défaut et en fin d'installation, vérifie que les options "Update Malwarebytes' Anti-Malware" et "Launch Malwarebytes' Anti-Malware" soit cochées.
                  MBAM démarrera automatiquement et enverra un message demandant à mettre à jour le programme avant de lancer une analyse. Comme MBAM se met automatiquement à jour en fin d'installation, clique sur OK pour fermer la boîte de dialogue.
                  La fenêtre principale de MBAM s'affiche :
                  Dans l'onglet analyse, vérifie que "Exécuter un examen rapide" est coché et clique sur le bouton Rechercher pour démarrer l'analyse.
                  MBAM analyse ton ordinateur.
                  L'analyse peut prendre un certain temps. Il suffit de vérifier de temps en temps son avancement.
                  A la fin de l'analyse, un message s'affiche indiquant la fin de l'analyse. Clique sur OK pour poursuivre.
                  Si des malwares sont détectés, leur liste s'affiche.
                  ***EN CLIQUANT SUR SUPPRESSION(?)FAIT LE*** , MBAM va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
                  MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Ferme le Bloc-notes. (Le rapport peut être retrouvé sous l'onglet Rapports/logs)
                  Ferme MBAM en cliquant sur Quitter.
                  Poste le rapport dans ta réponse
                  0
                  1. bonsoir,

                    il y avait bien 1 element infecté

                    Malwarebytes' Anti-Malware 1.34
                    Version de la base de données: 1778
                    Windows 6.0.6000

                    19/02/2009 20:44:22
                    mbam-log-2009-02-19 (20-44-22).txt

                    Type de recherche: Examen rapide
                    Eléments examinés: 55080
                    Temps écoulé: 3 minute(s), 24 second(s)

                    Processus mémoire infecté(s): 0
                    Module(s) mémoire infecté(s): 0
                    Clé(s) du Registre infectée(s): 1
                    Valeur(s) du Registre infectée(s): 0
                    Elément(s) de données du Registre infecté(s): 0
                    Dossier(s) infecté(s): 0
                    Fichier(s) infecté(s): 0

                    Processus mémoire infecté(s): (Aucun élément nuisible détecté)

                    Module(s) mémoire infecté(s): (Aucun élément nuisible détecté)

                    Clé(s) du Registre infectée(s):
                    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.

                    Valeur(s) du Registre infectée(s): (Aucun élément nuisible détecté)

                    Elément(s) de données du Registre infecté(s): (Aucun élément nuisible détecté)

                    Dossier(s) infecté(s): (Aucun élément nuisible détecté)

                    Fichier(s) infecté(s): (Aucun élément nuisible détecté)

                    Que faut il faire maintenant?
                    pourras tu me dire si je dois ( et si oui : quand? ) supprimer tous les fichiers téléchargés

                    encore merci pour ton aide
                    0
                    1. Contributeur sécurité
                      il ne faut pas supprimer tous les fichiers télécharger,c'est inutile

                      par contre je veux bien un nouveau rapport hijack stp
                      0
                      1. salut
                        demander et vous recevrez! lol

                        jai pas été longtemps sur internet depuis hier
                        mais il ne me semble pas avoir eu de pages intempestives
                        alors qu'avant c'était très recurrent
                        peut etre qe c'est réglé

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 07:22:34, on 20/02/2009
                        Platform: Windows Vista (WinNT 6.00.1904)
                        MSIE: Internet Explorer v7.00 (7.00.6000.16809)
                        Boot mode: Normal

                        Running processes:
                        C:\Windows\system32\taskeng.exe
                        C:\Windows\system32\Dwm.exe
                        C:\Windows\Explorer.EXE
                        C:\Windows\tsnp2std.exe
                        C:\Program Files\System Control Manager\MGSysCtrl.exe
                        C:\Windows\System32\rundll32.exe
                        C:\Windows\vsnp2std.exe
                        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                        C:\Program Files\PopUp Destroy\Popup-Destroy.exe
                        C:\Program Files\Windows Sidebar\sidebar.exe
                        C:\Windows\ehome\ehtray.exe
                        C:\Windows\system32\wbem\unsecapp.exe
                        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                        C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
                        C:\Windows\ehome\ehmsas.exe
                        C:\Windows\system32\wuauclt.exe
                        C:\Program Files\uTorrent\uTorrent.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\Windows\system32\SearchFilterHost.exe
                        C:\Users\beren\Desktop\HiJackThis.exe

                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msi.com.tw
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://recherche.neuf.fr/
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://recherche.neuf.fr/ie/default.html
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                        O1 - Hosts: ::1 localhost
                        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                        O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                        O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                        O4 - HKLM\..\Run: [tsnp2std] C:\Windows\tsnp2std.exe
                        O4 - HKLM\..\Run: [MGSysCtrl] C:\Program Files\System Control Manager\MGSysCtrl.exe
                        O4 - HKLM\..\Run: [snp2std] C:\Windows\vsnp2std.exe
                        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                        O4 - HKLM\..\Run: [PopUp Destroy] C:\Program Files\PopUp Destroy\Popup-Destroy.exe
                        O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] D:\mes docs\telechargement\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
                        O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                        O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
                        O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                        O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
                        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                        O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O13 - Gopher Prefix:
                        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/VistaMSNPUpldfr-fr.cab
                        O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} (Image Uploader Control) - http://copainsdavant.linternaute.com/...
                        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                        O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
                        O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                        O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                        O23 - Service: SCM Driver Daemon (NishService) - Unknown owner - C:\Program Files\System Control Manager\edd.exe
                        O23 - Service: O2Micro Flash Memory (O2Flash) - O2Micro International - C:\Windows\system32\o2flash.exe
                        O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                        O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                        0
                        1. Contributeur sécurité
                          c'est nickel

                          balance navilog à la poubelle

                          tes prog ne sont pas à jour(dangereux),le seul fait d'ouvrir une page hacké sur le net et ces l'infections à coup sur!

                          tu dois faire un scan de vulnérabilités afin de vérifier que tes logiciels soit bien à jour et sans failles de sécurités.

                          https://www.malekal.com/tester-la-vulnerabilite-de-son-systeme-2/
                          ou ici:
                          http://alt-shift-return.org/Info/Update_Checker.html

                          ensuite

                          Télécharges : - CCleaner (n'installe pas la barre d'outil Yahoo)
                          https://www.pcastuces.com/logitheque/ccleaner.htm
                          Ce logiciel va permettre de supprimer tous les fichiers temporaires et de corrigé ton registre .Lors de l'installation, avant de cliquer sur le bouton "installer", décoche toutes les "options supplémentaires" sauf les 2 première.
                          Une fois le prg instalé et lancé, Clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures"( Par la suite, laisse-le avec ses réglages par défaut. C'est tout ).

                          Un tuto ( aide ):
                          http://perso.orange.fr/jesses/Docs/Logiciels/CCleaner.htm

                          ---> Utilisation:
                          ! déconnectes toi et fermes toutes applications en cours !
                          * vas dans "nettoyeur" : fait analyse puis nettoyage
                          * vas dans "registre" : fait chercher les erreurs et réparer ( plusieurs fois jusqu'à ce qu'il n'y est plus d'erreur ) .

                          ( CCleaner : soft à garder sur son PC , super utile pour de bons nettoyages ... )

                          ***très important***

                          Suppression des points de restauration :

                          sous vista
                          https://www.01net.com/actualites/
                          http://www.commentcamarche.net/faq/sujet 13214 desactiver reactiver la restauration systeme de vista

                          Ne pas oublier de créer un nouveau point de restauration en procédant comme indiqué sur le lien ci dessous

                          https://www.vulgarisation-informatique.com/creer-point-restauration.php

                          si tu n as pas d autres soucis change le statut du sujet en resolu stp

                          Prévention & Sécurité sur le net(Format pdf)
                          0
                          1. Merci pour tout
                            le temps passé, la patience, les super conseils, ..........

                            ça a l'air de marché correctement maintenant
                            0