Virus TR/Dropper.Gen Trojan

Bonjour,

Depuis 3 jours, AntiVir m'envoie des avertissements 4 fois par jour pour me signaler des virus... Je fais "Delete" ms il m'envoie 3 fois de suite le même message puis s'arrête !
Je vous donne un exemple du message :

C:\Users\Barth\AppData\Local\qknhkt.exe
Is the TR/Dropper.Gen Trojan

Que dois-je faire ?

Merci d'avance pour votre aide !
Configuration: Windows Vista
Firefox 2.0.0.20

18 réponses

  1. La méthode la plus simple, je pense que tu pourrais commencer par aller dans ton poste de travail, que dans la ligne ou figure l'endroit où tu es et que tu y colle cela : C:\Users\Barth\AppData\Local\qknhkt.exe
    sachant que tu devras au préalable aller dans l'onglet : OUTILS, OPTIONS DES DOSSIERS, et AFFICHAGE, la tu coches ,si se n'est pas déjà fait, Afficher les fichiers et dossiers cachés.

    A partir du moment où tu es à l'emplacement indiqué, tu supprimeras tout ce qui sera au même endroit que ton .exe

    Je suis pas sûre que cela marche mais qq fois les méthodes sont les plus simples qui fonctionnent le mieux.
    0
    1. Merci de la réponse...
      MAis je ne peux pas supprimer les fichiers en question, Vista me dit qu'il faut que je dispose d'une autorisation...
      Pour info, j'ai plusieurs fichiers qui s'apellent "qknhkt" : j'ai donc le .exe, un .dat, un qknhkt_nav.dat et un qhknkt_navps.dat

      Une solution un peu plus compliquée peut être ?
      0
      1. Contributeur sécurité
        Bonsoir

        Désactive le contrôle des comptes utilisateurs
        (tu le réactiveras après ta désinfection):

        * Va dans démarrer puis panneau de configuration
        * Double Clique sur l'icône "Comptes d'utilisateurs"
        * Clique ensuite sur désactiver et valide.

        Tuto : https://forum.malekal.com/viewtopic.php?f=59&t=6517

        https://forum.pcastuces.com/navilog_de_il_mafioso_pour_vista-f31s12.htm

        Télécharge maintenant Navilog1 depuis-ce lien :

        http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

        * Enregistre la cible (du lien) sous... et enregistre-le sur ton bureau.
        Ensuite double clique sur navilog1.exe pour lancer l'installation.
        Une fois l'installation terminée :
        * Fais un Clic-droit sur le raccourci Navilog1 présent sur ton bureau et choisis
        "Exécuter en tant qu'administrateur".

        * Au menu principal, fais le choix 1
        Laisse toi guider et patiente.
        Patiente jusqu'au message :
        *** Analyse Terminée le ..... ***
        * Appuie sur une touche le blocnote va s'ouvrir.
        Copie-colle l'intégralité du rapport dans une réponse.
        * Referme le blocnote
        Le rapport fixnavi.txt est en outre sauvegardé dans %systemdrive%.
        0
        1. Search Navipromo version 3.7.4 commencé le 18/02/2009 à 22:21:20,01

          !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
          !!! Postez ce rapport sur le forum pour le faire analyser !!!
          !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

          Outil exécuté depuis C:\Program Files\navilog1

          Mise à jour le 16.02.2009 à 18h00 par IL-MAFIOSO

          Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
          X86-based PC ( Multiprocessor Free : AMD Turion Dual-Core RM-70 )
          BIOS : PhoenixBIOS 4.0 Release 6.1
          USER : Barth ( Administrator )
          BOOT : Normal boot

          Antivirus : AVG Anti-Virus Free 8.0 (Activated)

          C:\ (Local Disk) - NTFS - Total:139 Go (Free:41 Go)
          D:\ (Local Disk) - NTFS - Total:9 Go (Free:1 Go)
          E:\ (CD or DVD)
          F:\ (USB) - FAT - Total:483 Mo (Free:0 Go)
          G:\ (CD or DVD)

          Recherche executé en mode normal

          *** Recherche Programmes installés ***

          *** Recherche dossiers dans "C:\Windows" ***

          *** Recherche dossiers dans "C:\Program Files" ***

          ...\Live-Player trouvé !
          ...\WebMediaPlayer trouvé !

          *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

          ...\Live-Player trouvé !
          ...\WebMediaPlayer trouvé !

          *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1" ***

          *** Recherche dossiers dans "C:\ProgramData" ***

          *** Recherche dossiers dans "c:\users\barth\appdata\roaming\micros~1\windows\startm~1\programs" ***

          *** Recherche dossiers dans "C:\Users\Barth\AppData\Local\virtualstore\Program Files" ***

          *** Recherche dossiers dans "C:\Users\Barth\AppData\Local" ***

          ...\Live-Player trouvé !

          *** Recherche dossiers dans "C:\Users\Barth\AppData\Roaming" ***

          *** Recherche avec GenericNaviSearch ***
          !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
          !!! A vérifier impérativement avant toute suppression manuelle !!!

          * Recherche dans "C:\Windows\system32" *

          * Recherche dans "C:\Users\Barth\AppData\Local\Microsoft" *

          * Recherche dans "C:\Users\Barth\AppData\Local" *

          *** Recherche fichiers ***

          *** Recherche clés spécifiques dans le Registre ***
          !! Les clés trouvées ne sont pas forcément infectées !!

          HKEY_CURRENT_USER\Software\Lanconfig

          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "qknhkt"="\"c:\\users\\barth\\appdata\\local\\qknhkt.exe\" qknhkt"

          *** Module de Recherche complémentaire ***
          (Recherche fichiers spécifiques)

          1)Recherche nouveaux fichiers Instant Access :

          2)Recherche Heuristique :

          * Dans "C:\Windows\system32" :

          * Dans "C:\Users\Barth\AppData\Local\Microsoft" :

          * Dans "C:\Users\Barth\AppData\Local" :

          ioisk.dat trouvé !
          ioisk_nav.dat trouvé !
          ioisk_navps.dat trouvé !
          qknhkt.exe trouvé !
          qknhkt.dat trouvé !
          qknhkt_navps.dat trouvé !

          3)Recherche Certificats :

          Certificat Egroup absent !
          Certificat Electronic-Group trouvé !
          Certificat Montorgueil absent !
          Certificat OOO-Favorit trouvé !
          Certificat Sunny-Day-Design-Ltd absent !

          4)Recherche autres dossiers et fichiers connus :

          *** Analyse terminée le 18/02/2009 à 22:22:16,55 ***
          0
          1. Contributeur sécurité
            Assure-toi que l'UAC-User Account Control -contrôle des comptes utilisateurs est bien désactivé.

            Clique-droit sur le raccourci Navilog1 sur le Bureau et choisis "Exécuter en tant qu' Administrateur".

            * Sur le menu principal, choisis 2.
            * Suis les instructions et patiente.
            * L'outil va t'informer qu'il redémarrera ton ordinateur.
            * Sauvegarde les documents ouverts, s'il y en a, puis ferme toutes les fenêtres.
            * Appuie sur une touche ainsi que demandé.
            * Si ton ordinateur ne redémarre pas automatiquement, fais le manuellement.
            * Choisis ta session habituelle si nécessaire.
            Patiente jusqu'au message *** Nettoyage terminé le ….*** (il se peut que ça prenne un certain temps).
            Un document du Bloc-notes est créé. Sauvegarde le rapport de manière à le retrouver.
            * Copie/colle le contenu de ce compte-rendu dans ta prochaine réponse.
            Referme le Bloc-notes.
            Ton Bureau va réapparaître.

            Note : Si ton Bureau ne réapparaît pas, presse Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
            Onglet "Processus" > Fichier (menu) > Nouvelle tâche (Exécuter...) > tape explorer et clique sur OK.

            0
            1. Voici le rapport :

              Clean Navipromo version 3.7.4 commencé le 18/02/2009 à 22:28:19,19

              Outil exécuté depuis C:\Program Files\navilog1

              Mise à jour le 16.02.2009 à 18h00 par IL-MAFIOSO

              Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
              X86-based PC ( Multiprocessor Free : AMD Turion Dual-Core RM-70 )
              BIOS : PhoenixBIOS 4.0 Release 6.1
              USER : Barth ( Administrator )
              BOOT : Normal boot

              Antivirus : AVG Anti-Virus Free 8.0 (Activated)

              C:\ (Local Disk) - NTFS - Total:139 Go (Free:41 Go)
              D:\ (Local Disk) - NTFS - Total:9 Go (Free:1 Go)
              E:\ (CD or DVD)
              F:\ (USB) - FAT - Total:483 Mo (Free:0 Go)
              G:\ (CD or DVD)

              Mode suppression automatique
              avec prise en charge résultats Catchme et GNS

              Nettoyage exécuté au redémarrage de l'ordinateur

              *** fsbl1.txt non trouvé ***
              (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)

              *** Suppression avec sauvegardes résultats GenericNaviSearch ***

              * Suppression dans "C:\Windows\System32" *

              * Suppression dans "C:\Users\Barth\AppData\Local\Microsoft" *

              * Suppression dans "C:\Users\Barth\AppData\Local" *

              *** Suppression dossiers dans "C:\Windows" ***

              *** Suppression dossiers dans "C:\Program Files" ***

              ...\Live-Player ...suppression...
              ...\Live-Player supprimé !

              ...\WebMediaPlayer ...suppression...
              ...\WebMediaPlayer supprimé !

              *** Suppression dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

              ...\Live-Player ...suppression...
              ...\Live-Player supprimé !

              ...\WebMediaPlayer ...suppression...
              ...\WebMediaPlayer supprimé !

              *** Suppression dossiers dans "c:\progra~2\micros~1\windows\startm~1" ***

              *** Suppression dossiers dans "C:\ProgramData" ***

              *** Suppression dossiers dans c:\users\barth\appdata\roaming\micros~1\windows\startm~1\programs ***

              *** Suppression dossiers dans "C:\Users\Barth\AppData\Local\virtualstore\Program Files" ***

              *** Suppression dossiers dans "C:\Users\Barth\AppData\Local" ***

              *** Suppression dossiers dans "C:\Users\Barth\AppData\Roaming" ***

              *** Suppression fichiers ***

              *** Suppression fichiers temporaires ***

              Nettoyage contenu C:\Windows\Temp effectué !
              Nettoyage contenu C:\Users\Barth\AppData\Local\Temp effectué !

              *** Traitement Recherche complémentaire ***
              (Recherche fichiers spécifiques)

              1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

              2)Recherche, création sauvegardes et suppression Heuristique :

              * Dans "C:\Windows\system32" *

              C:\Windows\prefetch\qknhkt*.pf trouvé !
              Copie C:\Windows\prefetch\qknhkt*.pf réalisée avec succès !
              C:\Windows\prefetch\qknhkt*.pf supprimé !

              * Dans "C:\Users\Barth\AppData\Local\Microsoft" *

              * Dans "C:\Users\Barth\AppData\Local" *

              ioisk.dat trouvé !
              Copie ioisk.dat réalisée avec succès !
              ioisk.dat supprimé !

              ioisk_nav.dat trouvé !
              Copie ioisk_nav.dat réalisée avec succès !
              ioisk_nav.dat supprimé !

              ioisk_navps.dat trouvé !
              Copie ioisk_navps.dat réalisée avec succès !
              ioisk_navps.dat supprimé !

              qknhkt.exe trouvé !
              qknhkt.exe non supprimé !
              Echec Copie qknhkt.exe vers dossier Backupnavi

              qknhkt.dat trouvé !
              Copie qknhkt.dat réalisée avec succès !
              qknhkt.dat supprimé !

              qknhkt_navps.dat trouvé !
              Copie qknhkt_navps.dat réalisée avec succès !
              qknhkt_navps.dat supprimé !

              *** Sauvegarde du Registre vers dossier Safebackup ***

              sauvegarde du Registre réalisée avec succès !

              *** Nettoyage Registre ***

              Nettoyage Registre Ok

              *** Certificats ***

              Certificat Egroup absent !
              Certificat Electronic-Group supprimé !
              Certificat Montorgueil absent !
              Certificat OOO-Favorit supprimé !
              Certificat Sunny-Day-Design-Ltdt absent !

              *** Recherche autres dossiers et fichiers connus ***

              *** Nettoyage terminé le 18/02/2009 à 22:42:08,45 ***
              0
              1. Contributeur sécurité
                Télécharge le fichier d’installation d’Hijackthis en cliquant sur ce lien

                http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download

                * Enregistre HJTInstall.exe sur ton bureau.

                * Double-clique sur HJTInstall.exe pour lancer le programme

                Tuto : https://www.malekal.com/tutoriel-hijackthis/
                http://pagesperso-orange.fr/rginformatique/section%20virus/Hijenr.gif
                http://pagesperso-orange.fr/rginformatique/section%20virus/demohijack.htm

                * Accepte la license en cliquant sur le bouton "I Accept"
                * Choisis l'option "Do a system scan and save a log file"
                * Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note
                * Clique sur "Edition -> Sélectionner tout", puis sur "Edition -> Copier" pour copier tout le contenu du rapport

                * Colle le rapport que tu viens de copier sur ce forum
                0
                1. Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 22:49:09, on 18/02/2009
                  Platform: Windows Vista SP1 (WinNT 6.00.1905)
                  MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                  Boot mode: Normal

                  Running processes:
                  C:\Windows\System32\smss.exe
                  C:\Windows\system32\csrss.exe
                  C:\Windows\system32\wininit.exe
                  C:\Windows\system32\csrss.exe
                  C:\Windows\system32\services.exe
                  C:\Windows\system32\lsass.exe
                  C:\Windows\system32\lsm.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\nvvsvc.exe
                  C:\Windows\system32\winlogon.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\SLsvc.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\WLANExt.exe
                  C:\Windows\System32\spoolsv.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                  C:\Windows\system32\svchost.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                  C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                  C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\SMINST\BLService.exe
                  C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                  C:\Program Files\Spyware Doctor\pctsAuxs.exe
                  C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                  C:\PROGRA~1\AVG\AVG8\avgnsx.exe
                  C:\Program Files\Spyware Doctor\pctsSvc.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\system32\SearchIndexer.exe
                  C:\Windows\system32\DRIVERS\xaudio.exe
                  C:\PROGRA~1\AVG\AVG8\avgemc.exe
                  C:\Windows\system32\WUDFHost.exe
                  C:\Program Files\AVG\AVG8\avgcsrvx.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\system32\rundll32.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\Explorer.EXE
                  C:\Windows\system32\conime.exe
                  c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                  C:\Windows\System32\rundll32.exe
                  C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  C:\Program Files\HP\QuickPlay\QPService.exe
                  C:\Program Files\Windows Defender\MSASCui.exe
                  C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                  C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                  C:\Program Files\Java\jre6\bin\jusched.exe
                  C:\Program Files\AVG\AVG8\avgtray.exe
                  C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                  C:\Program Files\Search Settings\SearchSettings.exe
                  C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                  C:\Program Files\Windows Sidebar\sidebar.exe
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  C:\Windows\ehome\ehtray.exe
                  C:\Windows\system32\wbem\wmiprvse.exe
                  C:\Windows\ehome\ehmsas.exe
                  C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
                  C:\Windows\system32\wbem\unsecapp.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
                  C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
                  C:\Program Files\Windows Live\Messenger\usnsvc.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\system32\SearchProtocolHost.exe
                  C:\Windows\system32\SearchFilterHost.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                  C:\Windows\system32\wbem\wmiprvse.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=compaq-notebook.msn.com&ocid=HPDHP&pc=CPNTDF
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yougoo.fr/meteo
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=compaq-notebook.msn.com&ocid=HPDHP&pc=CPNTDF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=compaq-notebook.msn.com&ocid=HPDHP&pc=CPNTDF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                  R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll
                  O1 - Hosts: ::1 localhost
                  O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                  O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                  O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                  O2 - BHO: DealioBHO Class - {6A87B991-A31F-4130-AE72-6D0C294BF082} - C:\Program Files\Dealio\kb127\Dealio.dll (file missing)
                  O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                  O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                  O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                  O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0"
                  O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
                  O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                  O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                  O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                  O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                  O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                  O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
                  O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                  O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                  O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                  O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                  O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                  O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
                  O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                  O13 - Gopher Prefix:
                  O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                  O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                  O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                  O20 - AppInit_DLLs: avgrsstx.dll
                  O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                  O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                  O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
                  O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                  O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
                  O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
                  O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                  O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                  O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
                  O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe
                  O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                  O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
                  O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
                  O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                  0
                  1. Contributeur sécurité
                    Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.

                    https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

                    * Lance l'installation du programme en exécutant le fichier téléchargé.
                    * Double-clique maintenant sur le raccourci de Toolbar-S&D.
                    * Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
                    * Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
                    * Poste le rapport généré. (C:\TB.txt)
                    0
                    1. -----------\\ ToolBar S&D 1.2.8 XP/Vista

                      Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
                      X86-based PC ( Multiprocessor Free : AMD Turion Dual-Core RM-70 )
                      BIOS : PhoenixBIOS 4.0 Release 6.1
                      USER : Barth ( Administrator )
                      BOOT : Normal boot
                      Antivirus : AVG Anti-Virus Free 8.0 (Activated)
                      C:\ (Local Disk) - NTFS - Total:139 Go (Free:41 Go)
                      D:\ (Local Disk) - NTFS - Total:9 Go (Free:1 Go)
                      E:\ (CD or DVD)
                      F:\ (USB) - FAT - Total:483 Mo (Free:0 Go)
                      G:\ (CD or DVD)

                      "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
                      Option : [1] ( 18/02/2009|23:08 )

                      [ UAC => 0 ]

                      -----------\\ Recherche de Fichiers / Dossiers ...

                      C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com
                      C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\CHROME\CONTENT\searchsettingsplugin.js
                      C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\CHROME\CONTENT\searchsettingsplugin.xul
                      C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\CHROME\LOCALE\EN-US\searchsettingsplugin.dtd
                      C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\CHROME\LOCALE\EN-US\searchsettingsplugin.properties
                      C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\COMPONENTS\SearchSettingsFF.dll
                      C:\Program Files\Search Settings
                      C:\Program Files\Search Settings\kb127
                      C:\Program Files\Search Settings\SearchSettings.exe
                      C:\Program Files\Search Settings\kb127\res
                      C:\Program Files\Search Settings\kb127\SearchSettings.dll
                      C:\Program Files\Search Settings\kb127\SearchSettingsRes409.dll
                      C:\Program Files\Search Settings\kb127\temp

                      -----------\\ [..\Internet Explorer\Main]

                      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                      "Start Page"="http://www.yougoo.fr/meteo"
                      "Default_Page_URL"="https://www.msn.com/fr-fr?cobrand=compaq-notebook.msn.com&ocid=HPDHP&pc=CPNTDF"
                      "Local Page"="C:\\Windows\\system32\\blank.htm"
                      "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                      "Url"="https://www.msn.com/fr-fr/actualite/"

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                      "Start Page"="https://www.msn.com/fr-fr?cobrand=compaq-notebook.msn.com&ocid=HPDHP&pc=CPNTDF"
                      "Default_Page_URL"="https://www.msn.com/fr-fr?cobrand=compaq-notebook.msn.com&ocid=HPDHP&pc=CPNTDF"
                      "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                      "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"

                      --------------------\\ Recherche d'autres infections

                      C:\Users\Barth\AppData\Local\live-player
                      C:\Users\Barth\AppData\Local\live-player\flv.swf
                      C:\Users\Barth\AppData\Local\live-player\liveplayer.s3db
                      [b]==> EGDACCESS <==/b

                      --------------------\\ Cracks & Keygens ..

                      C:\Users\Barth\PES\Pro evolution soccer 2009 [PC-DVD][Multi5][matrixmersion]\Crack
                      C:\Users\Barth\PES\Pro evolution soccer 2009 [PC-DVD][Multi5][matrixmersion]\Crack\pes2009.exe

                      [ UAC => 1 ]

                      1 - "C:\ToolBar SD\TB_1.txt" - 18/02/2009|23:09 - Option : [1]

                      -----------\\ Fin du rapport a 23:09:50,89
                      0
                  2. Contributeur sécurité
                    Relance Toolbar-S&D en double-cliquant sur le raccourci. Tape sur "2" puis valide en appuyant sur "Entrée".

                    ! Ne ferme pas la fenêtre lors de la suppression !

                    Un rapport sera généré, poste son contenu ici.

                    NOTE : Si ton Bureau ne réapparait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
                    Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."
                    Tape explorer puis valide.

                    0
                    1. Salut ! Voici le rapport du jour ! (merci encore pr ton aide !)

                      -----------\\ ToolBar S&D 1.2.8 XP/Vista

                      Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
                      X86-based PC ( Multiprocessor Free : AMD Turion Dual-Core RM-70 )
                      BIOS : PhoenixBIOS 4.0 Release 6.1
                      USER : Barth ( Administrator )
                      BOOT : Normal boot
                      Antivirus : AVG Anti-Virus Free 8.0 (Activated)
                      C:\ (Local Disk) - NTFS - Total:139 Go (Free:41 Go)
                      D:\ (Local Disk) - NTFS - Total:9 Go (Free:1 Go)
                      E:\ (CD or DVD)
                      F:\ (USB) - FAT - Total:483 Mo (Free:0 Go)
                      G:\ (CD or DVD)

                      "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
                      Option : [2] ( 19/02/2009|11:19 )

                      [ UAC => 1 ]

                      -----------\\ SUPPRESSION

                      Supprime! - C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com
                      Supprime! - C:\Program Files\Search Settings\kb127
                      Supprime! - C:\Program Files\Search Settings\SearchSettings.exe
                      Supprime! - C:\Program Files\Search Settings

                      -----------\\ Recherche de Fichiers / Dossiers ...

                      -----------\\ [..\Internet Explorer\Main]

                      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                      "Start Page"="http://www.yougoo.fr/meteo"
                      "Default_Page_URL"="http://ie.redirect.hp.com/..."
                      "Local Page"="C:\\Windows\\system32\\blank.htm"
                      "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                      "Url"="https://www.msn.com/fr-fr/actualite/"

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                      "Start Page"="https://www.msn.com/fr-fr/"
                      "Default_Page_URL"="http://ie.redirect.hp.com/..."
                      "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                      "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"

                      --------------------\\ Recherche d'autres infections

                      C:\Users\Barth\AppData\Local\live-player
                      C:\Users\Barth\AppData\Local\live-player\flv.swf
                      C:\Users\Barth\AppData\Local\live-player\liveplayer.s3db
                      [b]==> EGDACCESS <==/b

                      --------------------\\ Cracks & Keygens ..

                      C:\Users\Barth\PES\Pro evolution soccer 2009 [PC-DVD][Multi5][matrixmersion]\Crack
                      C:\Users\Barth\PES\Pro evolution soccer 2009 [PC-DVD][Multi5][matrixmersion]\Crack\pes2009.exe

                      [ UAC => 1 ]

                      1 - "C:\ToolBar SD\TB_1.txt" - 18/02/2009|23:09 - Option : [1]
                      2 - "C:\ToolBar SD\TB_2.txt" - 19/02/2009|11:21 - Option : [2]

                      -----------\\ Fin du rapport a 11:21:45,35
                      0
                      1. Contributeur sécurité
                        Imprime ces instructions ou sauvegarde les sur ton Bureau car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

                        Télécharge Malwarebytes' Anti-Malware (MBAM) et enregistre le sur ton bureau à partir de ce lien :

                        https://download.cnet.com/Malwarebytes/3000-8022_4-10804572.html

                        A la fin du téléchargement, ferme toutes les fenêtres et programmes, y compris celui-ci.

                        Double-clique sur l'icône Download_mbam-setup.exe sur ton bureau pour démarrer le programme d'installation.

                        Pendant l'installation, suis les indications (en particulier le choix de la langue et l'autorisation d'accession à Internet). N'apporte aucune modification aux réglages par défaut et, en fin d'installation, vérifie que les options Update Malwarebytes' Anti-Malware et Launch Malwarebytes' Anti-Malware sont cochées.

                        MBAM démarrera automatiquement et enverra un message demandant à mettre à jour le programme avant de lancer une analyse. Comme MBAM se met automatiquement à jour en fin d'installation, clique sur OK pour fermer la boîte de dialogue. La fenêtre principale de MBAM s'affiche :

                        Dans l'onglet analyse, vérifie que "Exécuter un examen rapide" est coché et clique sur le bouton Rechercher pour démarrer l'analyse.

                        MBAM analyse ton ordinateur. L'analyse peut prendre un certain teps. Il suffit de vérifier de temps en temps son avancement.

                        A la fin de l'analyse, un message s'affiche indiquant la fin de l'analyse. Clique sur OK pour poursuivre.

                        Si des malwares ont été détectés, leur liste s'affiche.
                        En cliquant sur Suppression (?) , MBAM va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.

                        MBAM va ouvrir le bloc-notes et y copier le rapport d'analyse. Ferme le bloc-note. (Le rapport peut être retrouvé sous l'onglet Rapports/logs)

                        Ferme MBAM en cliquant sur Quitter.

                        Poste le rapport sur le forum.

                        0
                        1. Alors il me dit ne trouver aucun malveillants ! LE rapport :

                          Malwarebytes' Anti-Malware 1.34
                          Version de la base de données: 1778
                          Windows 6.0.6001 Service Pack 1

                          19/02/2009 12:08:14
                          mbam-log-2009-02-19 (12-08-14).txt

                          Type de recherche: Examen rapide
                          Eléments examinés: 55728
                          Temps écoulé: 4 minute(s), 54 second(s)

                          Processus mémoire infecté(s): 0
                          Module(s) mémoire infecté(s): 0
                          Clé(s) du Registre infectée(s): 0
                          Valeur(s) du Registre infectée(s): 0
                          Elément(s) de données du Registre infecté(s): 0
                          Dossier(s) infecté(s): 0
                          Fichier(s) infecté(s): 0

                          Processus mémoire infecté(s):
                          (Aucun élément nuisible détecté)

                          Module(s) mémoire infecté(s):
                          (Aucun élément nuisible détecté)

                          Clé(s) du Registre infectée(s):
                          (Aucun élément nuisible détecté)

                          Valeur(s) du Registre infectée(s):
                          (Aucun élément nuisible détecté)

                          Elément(s) de données du Registre infecté(s):
                          (Aucun élément nuisible détecté)

                          Dossier(s) infecté(s):
                          (Aucun élément nuisible détecté)

                          Fichier(s) infecté(s):
                          (Aucun élément nuisible détecté)
                          0
                          1. Des nouvelles ? Que dois-je faire maintenant ?
                            PArcequ'à vrai dire AntiVir devient deplus en plus pressant et m'alerte quasi continuement....
                            MErci d'avance !
                            0
                            1. Contributeur sécurité
                              Bizarre, le fichier qui déclencahit l'alerte a théoriquement été supprimé.
                              Tu peux refaire navilog, option 1, pour voir.
                              0
                              1. MErci de m'avoir répondu !
                                Qd je regarde ds le dossier concerné, le fichier .exe est tjrs présent....
                                Je te joins le rapport Navilog...
                                Deplus a l'instant, AVG me signale autre chose... :

                                File Name : C:\Windows\System32\gnc.exe
                                Threat Name : Runtime packed fsg
                                Detected on open

                                Je fais quoi ? "Add to Exceptions"?

                                Voicu le rapport

                                Search Navipromo version 3.7.4 commencé le 20/02/2009 à 13:10:03,80

                                !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                                !!! Postez ce rapport sur le forum pour le faire analyser !!!
                                !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

                                Outil exécuté depuis C:\Program Files\navilog1

                                Mise à jour le 16.02.2009 à 18h00 par IL-MAFIOSO

                                Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
                                X86-based PC ( Multiprocessor Free : AMD Turion Dual-Core RM-70 )
                                BIOS : PhoenixBIOS 4.0 Release 6.1
                                USER : Barth ( Administrator )
                                BOOT : Normal boot

                                Antivirus : AVG Anti-Virus Free 8.0 (Activated)

                                C:\ (Local Disk) - NTFS - Total:139 Go (Free:40 Go)
                                D:\ (Local Disk) - NTFS - Total:9 Go (Free:1 Go)
                                E:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
                                F:\ (USB) - FAT - Total:483 Mo (Free:0 Go)
                                G:\ (CD or DVD)

                                Recherche executé en mode normal

                                *** Recherche Programmes installés ***

                                *** Recherche dossiers dans "C:\Windows" ***

                                *** Recherche dossiers dans "C:\Program Files" ***

                                *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

                                *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1" ***

                                *** Recherche dossiers dans "C:\ProgramData" ***

                                *** Recherche dossiers dans "c:\users\barth\appdata\roaming\micros~1\windows\startm~1\programs" ***

                                *** Recherche dossiers dans "C:\Users\Barth\AppData\Local\virtualstore\Program Files" ***

                                *** Recherche dossiers dans "C:\Users\Barth\AppData\Local" ***

                                ...\Live-Player trouvé !

                                *** Recherche dossiers dans "C:\Users\Barth\AppData\Roaming" ***

                                *** Recherche avec GenericNaviSearch ***
                                !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
                                !!! A vérifier impérativement avant toute suppression manuelle !!!

                                * Recherche dans "C:\Windows\system32" *

                                * Recherche dans "C:\Users\Barth\AppData\Local\Microsoft" *

                                * Recherche dans "C:\Users\Barth\AppData\Local" *

                                *** Recherche fichiers ***

                                *** Recherche clés spécifiques dans le Registre ***
                                !! Les clés trouvées ne sont pas forcément infectées !!

                                *** Module de Recherche complémentaire ***
                                (Recherche fichiers spécifiques)

                                1)Recherche nouveaux fichiers Instant Access :

                                2)Recherche Heuristique :

                                * Dans "C:\Windows\system32" :

                                * Dans "C:\Users\Barth\AppData\Local\Microsoft" :

                                * Dans "C:\Users\Barth\AppData\Local" :

                                3)Recherche Certificats :

                                Certificat Egroup absent !
                                Certificat Electronic-Group absent !
                                Certificat Montorgueil absent !
                                Certificat OOO-Favorit absent !
                                Certificat Sunny-Day-Design-Ltd absent !

                                4)Recherche autres dossiers et fichiers connus :

                                *** Analyse terminée le 20/02/2009 à 13:12:12,84 ***
                                0
                            2. Contributeur sécurité
                              Et là, on ne le retrouve pas mais il u a Live Player

                              Refais également l'option 2 de navilog stp.
                              0
                              1. Clean Navipromo version 3.7.4 commencé le 20/02/2009 à 18:51:26,93

                                Outil exécuté depuis C:\Program Files\navilog1

                                Mise à jour le 16.02.2009 à 18h00 par IL-MAFIOSO

                                Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
                                X86-based PC ( Multiprocessor Free : AMD Turion Dual-Core RM-70 )
                                BIOS : PhoenixBIOS 4.0 Release 6.1
                                USER : Barth ( Administrator )
                                BOOT : Normal boot

                                Antivirus : AVG Anti-Virus Free 8.0 (Activated)

                                C:\ (Local Disk) - NTFS - Total:139 Go (Free:40 Go)
                                D:\ (Local Disk) - NTFS - Total:9 Go (Free:1 Go)
                                E:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
                                F:\ (USB) - FAT - Total:483 Mo (Free:0 Go)
                                G:\ (CD or DVD)

                                Mode suppression automatique
                                avec prise en charge résultats Catchme et GNS

                                Nettoyage exécuté au redémarrage de l'ordinateur

                                *** fsbl1.txt non trouvé ***
                                (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)

                                *** Suppression avec sauvegardes résultats GenericNaviSearch ***

                                * Suppression dans "C:\Windows\System32" *

                                * Suppression dans "C:\Users\Barth\AppData\Local\Microsoft" *

                                * Suppression dans "C:\Users\Barth\AppData\Local" *

                                *** Suppression dossiers dans "C:\Windows" ***

                                *** Suppression dossiers dans "C:\Program Files" ***

                                *** Suppression dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

                                *** Suppression dossiers dans "c:\progra~2\micros~1\windows\startm~1" ***

                                *** Suppression dossiers dans "C:\ProgramData" ***

                                *** Suppression dossiers dans c:\users\barth\appdata\roaming\micros~1\windows\startm~1\programs ***

                                *** Suppression dossiers dans "C:\Users\Barth\AppData\Local\virtualstore\Program Files" ***

                                *** Suppression dossiers dans "C:\Users\Barth\AppData\Local" ***

                                *** Suppression dossiers dans "C:\Users\Barth\AppData\Roaming" ***

                                *** Suppression fichiers ***

                                *** Suppression fichiers temporaires ***

                                Nettoyage contenu C:\Windows\Temp effectué !
                                Nettoyage contenu C:\Users\Barth\AppData\Local\Temp effectué !

                                *** Traitement Recherche complémentaire ***
                                (Recherche fichiers spécifiques)

                                1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

                                2)Recherche, création sauvegardes et suppression Heuristique :

                                * Dans "C:\Windows\system32" *

                                * Dans "C:\Users\Barth\AppData\Local\Microsoft" *

                                * Dans "C:\Users\Barth\AppData\Local" *

                                *** Sauvegarde du Registre vers dossier Safebackup ***

                                sauvegarde du Registre réalisée avec succès !

                                *** Nettoyage Registre ***

                                Nettoyage Registre Ok

                                *** Certificats ***

                                Certificat Egroup absent !
                                Certificat Electronic-Group absent !
                                Certificat Montorgueil absent !
                                Certificat OOO-Favorit absent !
                                Certificat Sunny-Day-Design-Ltdt absent !

                                *** Recherche autres dossiers et fichiers connus ***

                                *** Nettoyage terminé le 20/02/2009 à 19:42:15,02 ***
                                0
                                1. Contributeur sécurité
                                  Pas concluant !
                                  Fais un nouvel Hijackthis stp.
                                  0
                                  1. Logfile of Trend Micro HijackThis v2.0.2
                                    Scan saved at 19:53:43, on 20/02/2009
                                    Platform: Windows Vista SP1 (WinNT 6.00.1905)
                                    MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                                    Boot mode: Normal

                                    Running processes:
                                    C:\Windows\System32\smss.exe
                                    C:\Windows\system32\csrss.exe
                                    C:\Windows\system32\wininit.exe
                                    C:\Windows\system32\csrss.exe
                                    C:\Windows\system32\services.exe
                                    C:\Windows\system32\lsass.exe
                                    C:\Windows\system32\lsm.exe
                                    C:\Windows\system32\winlogon.exe
                                    C:\Windows\system32\svchost.exe
                                    C:\Windows\system32\nvvsvc.exe
                                    C:\Windows\system32\svchost.exe
                                    C:\Windows\System32\svchost.exe
                                    C:\Windows\System32\svchost.exe
                                    C:\Windows\System32\svchost.exe
                                    C:\Windows\system32\svchost.exe
                                    C:\Windows\system32\SLsvc.exe
                                    C:\Windows\system32\svchost.exe
                                    C:\Windows\system32\svchost.exe
                                    C:\Windows\system32\WLANExt.exe
                                    C:\Windows\System32\spoolsv.exe
                                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                    C:\Windows\system32\svchost.exe
                                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                                    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                    C:\Windows\system32\svchost.exe
                                    C:\Windows\SMINST\BLService.exe
                                    C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                                    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                                    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
                                    C:\Program Files\Spyware Doctor\pctsAuxs.exe
                                    C:\Program Files\Spyware Doctor\pctsSvc.exe
                                    C:\Windows\system32\svchost.exe
                                    C:\Windows\System32\svchost.exe
                                    C:\Windows\system32\SearchIndexer.exe
                                    C:\Windows\system32\DRIVERS\xaudio.exe
                                    C:\PROGRA~1\AVG\AVG8\avgemc.exe
                                    C:\Windows\system32\WUDFHost.exe
                                    C:\Program Files\AVG\AVG8\avgcsrvx.exe
                                    C:\Windows\system32\rundll32.exe
                                    C:\Windows\system32\taskeng.exe
                                    c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                                    C:\Windows\system32\taskeng.exe
                                    C:\Windows\system32\Dwm.exe
                                    C:\Windows\Explorer.EXE
                                    C:\Windows\system32\conime.exe
                                    C:\Windows\System32\rundll32.exe
                                    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                    C:\Program Files\HP\QuickPlay\QPService.exe
                                    C:\Program Files\Windows Defender\MSASCui.exe
                                    C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                                    C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                                    C:\Program Files\Java\jre6\bin\jusched.exe
                                    C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                                    C:\Windows\system32\wbem\wmiprvse.exe
                                    C:\Program Files\AVG\AVG8\avgtray.exe
                                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                                    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                                    C:\Program Files\Windows Sidebar\sidebar.exe
                                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                    C:\Windows\ehome\ehtray.exe
                                    C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
                                    C:\Windows\ehome\ehmsas.exe
                                    C:\Windows\system32\wbem\unsecapp.exe
                                    C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
                                    C:\Program Files\Mozilla Firefox\firefox.exe
                                    C:\Program Files\Windows Live\Messenger\usnsvc.exe
                                    C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
                                    C:\Windows\system32\wbem\wmiprvse.exe
                                    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/...
                                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yougoo.fr/meteo
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/...
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                    R3 - Default URLSearchHook is missing
                                    O1 - Hosts: ::1 localhost
                                    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                                    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                                    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                                    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                                    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                                    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                                    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                    O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0"
                                    O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
                                    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                                    O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                                    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                                    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                                    O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                                    O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
                                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                                    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                                    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                                    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                                    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                                    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                                    O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                                    O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                                    O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
                                    O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
                                    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                                    O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
                                    O13 - Gopher Prefix:
                                    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                                    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                                    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                                    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                                    O20 - AppInit_DLLs: avgrsstx.dll
                                    O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                    O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                    O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
                                    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                                    O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
                                    O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
                                    O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                                    O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
                                    O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe
                                    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                                    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
                                    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
                                    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                                    0