Pb firefox plante

Résolu
Bonjour,
voila mon probleme firefox plante dès que je le lance
voila le rapport de plantage :

Add-ons: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.2
BuildID: 20090729225027
CrashTime: 1251220122
InstallTime: 1251215772
ProductName: Firefox
SecondsSinceLastCrash: 629
StartupTime: 1251220081
Theme: classic/1.0
Throttleable: 1
URL: https://www.google.fr/?gws_rd=ssl
Vendor: Mozilla
Version: 3.5.2

Ce rapport contient également des informations techniques sur l'état de l'application lors du plantage.

est ce que quelqu'un peut m'aider ....
j'avais poster mon message dans la rubrique internet mais on m'a conseiller de poster ici parce qu'on m'a dit que j'avais peut être un adware

--
"Stulti Timent Fortunam Sapientes Ferunt"
Les sots craignent leur sort, les sages le supportent
Configuration: Windows Vista SP1
Processeur : Intel core 2 Quad Q6600
Carte Grraphique : Nvidia geforce 8600 GS
Memoire RAM : 2048 Mo
Disque dur : 2 X 500 Go

42 réponses

Résumé de la discussion

Firefox plante au lancement et le rapport de crash détaille des informations techniques, dont une extension par défaut et des éléments système sensibles, avec une suspicion d’adware et des indications sur le comportement du navigateur. Pour résoudre le problème, des nettoyages et des tests avec divers outils de sécurité sont proposés, Windows Defender étant mentionné comme action susceptible d'améliorer la situation. D'autres participants signalent que le problème peut toucher d'autres navigateurs et que des tests complémentaires avaient été envisagés, ce qui souligne la diversité des méthodes préconisées.

Bobot (l’IA à votre service)
  1. Contributeur
    telecharge AVZ http://z-oleg.com/avz4.zip
    extrait sur ton bureau
    ouvre le dossier AVZ4
    double clique sur avz.exe
    clique sur file (en haut à gauche)
    dans la liste choisie Custom scripts
    dans le carré qui apparait colle ce qui est en gras dessous
    puis clique sur Run
    valide le message, ton PC va redémarrer
    une fois redémarrer ouvre le dossier AVZ4
    poste le contenu de AvzBootCleaner.log
    lance combofix rapidement !

    var
    service, driverfile, AvzDir : string;

    begin
    AvzDir:=GetAVZDirectory;
    service:=('kbiwkmovlruvid');
    driverfile:=('kbiwkmvvxudnbs.sys');
    ShowMessage('Wichtig! Beende alle Programme, bevor du auf Okay klickst und das Skript startest! Windows wird automatisch neustarten.');
    SearchRootKit(true,true);
    SetAVZGuardStatus(true);
    BC_QrFile('%System32%\Drivers\'+driverfile);
    BC_DeleteSvc(service);
    BC_LogFile(AvzDir + 'AvzBootCleaner.log');
    BC_Activate;
    RebootWindows(true);
    end.
    1. Contributeur
      Etape 1/ Télécharge :

      ToolsCleaner! (A.Rothstein & Dj QUIOU) sur ton Bureau.
      http://pc-system.fr/

      Etape 2/
      - Supprime le dossier avz4
      - Double-clique sur ToolsCleaner2.exe pour le lancer.
      - Clique sur Recherche et laisse le scan agir.
      - Clique sur Suppression pour finaliser.
      - Tu peux, si tu le souhaites, te servir des Options Facultatives.
      - Clique sur Quitter pour obtenir le rapport C:\TCleaner.txt

      Etape 3/
      Poste ce rapport
      https://www.micro-astuce.com/securite/NanoScan-Panda.php
      1. Contributeur
        Bonjour,

        télécharge GenProc http://www.genproc.com/GenProc.exe

        double-clique sur GenProc.exe et poste le contenu du rapport qui s'ouvre
        1. voila le rapport TB

          -----------\\ ToolBar S&D 1.2.9 XP/Vista

          Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
          X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU P8600 @ 2.40GHz )
          BIOS : MEGA BOOK GX720, BIOS Version: A1722IMS Ver1.0H
          USER : Florian ( Administrator )
          BOOT : Fail-safe boot
          C:\ (Local Disk) - NTFS - Total:43 Go (Free:9 Go)
          D:\ (Local Disk) - NTFS - Total:246 Go (Free:78 Go)
          E:\ (CD or DVD)
          F:\ (CD or DVD)
          G:\ (CD or DVD)

          "C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
          Option : [2] ( 25/08/2009|21:17 )

          [ UAC => 0 ]

          -----------\\ SUPPRESSION

          Supprime! - C:\Program Files\DAEMON Tools Toolbar

          -----------\\ Recherche de Fichiers / Dossiers ...

          -----------\\ [..\Internet Explorer\Main]

          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
          "Local Page"="C:\\Windows\\system32\\blank.htm"
          "Start Page"="https://www.google.com/?gws_rd=ssl"
          "Default_Page_URL"="https://www.google.com/?gws_rd=ssl"
          "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
          "Url"="https://www.msn.com/fr-fr/actualite/"

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
          "Default_Page_URL"="https://www.google.com/?gws_rd=ssl"
          "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
          "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
          "Local Page"="C:\\Windows\\System32\\blank.htm"
          "Start Page"="https://www.msn.com/fr-fr/"

          --------------------\\ Recherche d'autres infections

          --------------------\\ Cracks & Keygens ..

          [ UAC => 1 ]

          1 - "C:\ToolBar SD\TB_1.txt" - 25/08/2009|21:19 - Option : [2]

          -----------\\ Fin du rapport a 21:19:29,07
          1. maintenant le rapport hijackthis

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 21:27:58, on 25/08/2009
            Platform: Windows Vista SP1 (WinNT 6.00.1905)
            MSIE: Internet Explorer v8.00 (8.00.6001.18813)
            Boot mode: Normal

            Running processes:
            C:\Windows\system32\Dwm.exe
            C:\Windows\system32\taskeng.exe
            C:\Windows\Explorer.EXE
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\Windows\RtHDVCpl.exe
            C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
            C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
            C:\Program Files\System Control Manager\MGSysCtrl.exe
            C:\Program Files\Toshiba\Bluetooth Toshiba Stack\ItSecMng.exe
            C:\Windows\System32\rundll32.exe
            D:\Program Files\GEO Fond Ecran\365GEO.exe
            C:\Program Files\Java\jre6\bin\jusched.exe
            C:\Program Files\Orange\AntivirusFirewall\Common\FSM32.EXE
            D:\Program Files\iTunes\iTunesHelper.exe
            C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
            C:\Windows\ehome\ehtray.exe
            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            C:\Windows\ehome\ehmsas.exe
            C:\Program Files\Windows Media Player\wmpnscfg.exe
            C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
            D:\Downloads\BatteryAlarm.exe
            C:\Program Files\OpenOffice.org 3\program\soffice.exe
            C:\Program Files\OpenOffice.org 3\program\soffice.bin
            C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
            C:\Windows\system32\conime.exe
            C:\Windows\system32\wbem\unsecapp.exe
            C:\Program Files\Orange\AntivirusFirewall\FSGUI\fsguidll.exe
            C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
            C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\Windows\system32\NOTEPAD.EXE
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
            C:\Windows\system32\SearchFilterHost.exe

            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
            R3 - Default URLSearchHook is missing
            O1 - Hosts: ::1 localhost
            O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
            O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
            O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
            O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
            O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
            O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
            O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
            O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
            O4 - HKLM\..\Run: [MGSysCtrl] C:\Program Files\System Control Manager\MGSysCtrl.exe
            O4 - HKLM\..\Run: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
            O4 - HKLM\..\Run: [GEO365] D:\Program Files\GEO Fond Ecran\365GEO.exe
            O4 - HKLM\..\Run: [TrayServer] D:\Program Files\MAGIX\Video_deluxe_2008_e-version\TrayServer.exe
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
            O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
            O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Orange\AntivirusFirewall\Common\FSM32.EXE" /splash
            O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Orange\AntivirusFirewall\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
            O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
            O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
            O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
            O4 - HKCU\..\Run: [Google Update] "C:\Users\Florian\AppData\Local\Google\Update\GoogleUpdate.exe" /c
            O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
            O4 - HKCU\..\Run: [mocws] "c:\users\florian\appdata\local\mocws.exe" mocws
            O4 - HKCU\..\Run: [DAEMON Tools Lite] "D:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
            O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
            O4 - HKCU\..\Run: [AlcoholAutomount] "d:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
            O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
            O4 - Startup: BatteryAlarm - Raccourci.lnk = D:\Downloads\BatteryAlarm.exe
            O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
            O4 - Global Startup: Bluetooth Manager.lnk = ?
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
            O8 - Extra context menu item: Save Flash - res://D:\Program Files\UnH Solutions\Flash Saving Plugin\FlashSButton.dll/210
            O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - D:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
            O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - D:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
            O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
            O9 - Extra button: Flash - {43CF38F3-5AEC-45a3-AD31-04EB06E9C6CA} - D:\Program Files\UnH Solutions\Flash Saving Plugin\FlashSButton.dll (HKCU)
            O13 - Gopher Prefix:
            O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} (Battlefield Heroes Updater) - https://play.battlefield-heroes.com/static/updater/BFHUpdater_4.0.15.0.cab
            O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            O23 - Service: Planificateur LiveUpdate automatique (Automatic LiveUpdate Scheduler) - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
            O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
            O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\Orange\AntivirusFirewall\Anti-Virus\fsgk32st.exe
            O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - D:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
            O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\Orange\AntivirusFirewall\FSAUA\program\fsaua.exe
            O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Orange\AntivirusFirewall\FWES\Program\fsdfwd.exe
            O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\Orange\AntivirusFirewall\Common\FSMA32.EXE
            O23 - Service: F-Secure ORSP Client (FSORSPClient) - F-Secure Corporation - C:\Program Files\Orange\AntivirusFirewall\ORSP Client\fsorsp.exe
            O23 - Service: Google Update Service (gupdate1c98c69d3fd79e4) (gupdate1c98c69d3fd79e4) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
            O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
            O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
            O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
            O23 - Service: Micro Star SCM - Unknown owner - C:\Program Files\System Control Manager\MSIService.exe
            O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
            O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe
            O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
            O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
            O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
            O23 - Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) - Protection Technology (StarForce) - C:\Windows\system32\sfrem01.exe
            O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - d:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
            O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
            O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\Windows\system32\UAService7.exe
            O23 - Service: [webwiz] - webcam via ftp - [RUELEPIC] (webwiz) - [ruelepic] - D:\PROGRA~1\_WEBWI~1\Webwizsvc.exe
            O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe
            1. maintenant y me demande de scanner des fichiers

              Rapport GenProc 2.615 [2] - 25/08/2009 à 21:29:08
              @ Windows Vista Service Pack 1 - Mode normal
              @ Mozilla Firefox (3.0.13) [Navigateur par défaut]

              ~~ CM DISK ERROR ~~
              ~~ INTERRUPTION REQUETES COMPTEURMAX ~~

              GenProc n'a détecté aucune infection caractéristique et suggère de suivre la procédure suivante :

              Fais scanner le(s) fichier(s) suivant(s) sur ce site https://www.virustotal.com/gui/ :

              C:\Windows\System32\Log_20090804_154307_1D68.txt
              C:\Windows\System32\Log_20090804_154308_10F4.txt
              C:\Windows\System32\Log_20090804_154308_1378.txt
              C:\Windows\System32\Log_20090804_154308_1AD4.txt
              C:\Windows\System32\Log_20090804_154308_1BF4.txt

              et poste le(s) rapport(s) obtenu(s) dans ta prochaine réponse.

              ~~~~ INFORMATION COMPLEMENTAIRE ~~~~

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 21:30:49, on 25/08/2009
              Platform: Windows Vista SP1 (WinNT 6.00.1905)
              MSIE: Internet Explorer v8.00 (8.00.6001.18813)
              Boot mode: Normal

              Running processes:
              C:\Windows\system32\Dwm.exe
              C:\Windows\system32\taskeng.exe
              C:\Windows\Explorer.EXE
              C:\Program Files\Windows Defender\MSASCui.exe
              C:\Windows\RtHDVCpl.exe
              C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
              C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
              C:\Program Files\System Control Manager\MGSysCtrl.exe
              C:\Program Files\Toshiba\Bluetooth Toshiba Stack\ItSecMng.exe
              C:\Windows\System32\rundll32.exe
              D:\Program Files\GEO Fond Ecran\365GEO.exe
              C:\Program Files\Java\jre6\bin\jusched.exe
              C:\Program Files\Orange\AntivirusFirewall\Common\FSM32.EXE
              D:\Program Files\iTunes\iTunesHelper.exe
              C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
              C:\Windows\ehome\ehtray.exe
              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              C:\Windows\ehome\ehmsas.exe
              C:\Program Files\Windows Media Player\wmpnscfg.exe
              C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
              D:\Downloads\BatteryAlarm.exe
              C:\Program Files\OpenOffice.org 3\program\soffice.exe
              C:\Program Files\OpenOffice.org 3\program\soffice.bin
              C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
              C:\Windows\system32\conime.exe
              C:\Windows\system32\wbem\unsecapp.exe
              C:\Program Files\Orange\AntivirusFirewall\FSGUI\fsguidll.exe
              C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
              C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
              C:\Windows\system32\NOTEPAD.EXE
              C:\Windows\system32\cmd.exe
              C:\Users\Florian\AppData\Local\Google\Chrome\Application\chrome.exe
              C:\Users\Florian\AppData\Local\Google\Chrome\Application\chrome.exe
              C:\Genproc\outil\Florian_GenProc.exe

              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
              R3 - Default URLSearchHook is missing
              O1 - Hosts: ::1 localhost
              O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
              O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
              O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
              O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
              O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
              O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
              O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
              O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
              O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
              O4 - HKLM\..\Run: [MGSysCtrl] C:\Program Files\System Control Manager\MGSysCtrl.exe
              O4 - HKLM\..\Run: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
              O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
              O4 - HKLM\..\Run: [GEO365] D:\Program Files\GEO Fond Ecran\365GEO.exe
              O4 - HKLM\..\Run: [TrayServer] D:\Program Files\MAGIX\Video_deluxe_2008_e-version\TrayServer.exe
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
              O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
              O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
              O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Orange\AntivirusFirewall\Common\FSM32.EXE" /splash
              O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Orange\AntivirusFirewall\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
              O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
              O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
              O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
              O4 - HKCU\..\Run: [Google Update] "C:\Users\Florian\AppData\Local\Google\Update\GoogleUpdate.exe" /c
              O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
              O4 - HKCU\..\Run: [mocws] "c:\users\florian\appdata\local\mocws.exe" mocws
              O4 - HKCU\..\Run: [DAEMON Tools Lite] "D:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
              O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
              O4 - HKCU\..\Run: [AlcoholAutomount] "d:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
              O4 - Startup: BatteryAlarm - Raccourci.lnk = D:\Downloads\BatteryAlarm.exe
              O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
              O4 - Global Startup: Bluetooth Manager.lnk = ?
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
              O8 - Extra context menu item: Save Flash - res://D:\Program Files\UnH Solutions\Flash Saving Plugin\FlashSButton.dll/210
              O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - D:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
              O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - D:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
              O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
              O9 - Extra button: Flash - {43CF38F3-5AEC-45a3-AD31-04EB06E9C6CA} - D:\Program Files\UnH Solutions\Flash Saving Plugin\FlashSButton.dll (HKCU)
              O13 - Gopher Prefix:
              O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} (Battlefield Heroes Updater) - https://play.battlefield-heroes.com/static/updater/BFHUpdater_4.0.15.0.cab
              O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              O23 - Service: Planificateur LiveUpdate automatique (Automatic LiveUpdate Scheduler) - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
              O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
              O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\Orange\AntivirusFirewall\Anti-Virus\fsgk32st.exe
              O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - D:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
              O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\Orange\AntivirusFirewall\FSAUA\program\fsaua.exe
              O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Orange\AntivirusFirewall\FWES\Program\fsdfwd.exe
              O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\Orange\AntivirusFirewall\Common\FSMA32.EXE
              O23 - Service: F-Secure ORSP Client (FSORSPClient) - F-Secure Corporation - C:\Program Files\Orange\AntivirusFirewall\ORSP Client\fsorsp.exe
              O23 - Service: Google Update Service (gupdate1c98c69d3fd79e4) (gupdate1c98c69d3fd79e4) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
              O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
              O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
              O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
              O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
              O23 - Service: Micro Star SCM - Unknown owner - C:\Program Files\System Control Manager\MSIService.exe
              O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
              O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe
              O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
              O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
              O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
              O23 - Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) - Protection Technology (StarForce) - C:\Windows\system32\sfrem01.exe
              O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - d:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
              O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
              O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\Windows\system32\UAService7.exe
              O23 - Service: [webwiz] - webcam via ftp - [RUELEPIC] (webwiz) - [ruelepic] - D:\PROGRA~1\_WEBWI~1\Webwizsvc.exe
              O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe
              1. Contributeur
                [*] Télécharge combofix (sUBs) http://download.bleepingcomputer.com/sUBs/ComboFix.exe sur ton Bureau
                [*] Double clique combofix.exe et suis les instructions.
                [*] Installe la console de récupération si proposé et continue.
                [*] Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

                NOTE : Le rapport se trouve également ici : C:\Combofix.txt
                1. je suis pas sur que combofix fonctionne
                  ça me met : please wait combofix is preparing to run
                  et après ça s'arrête ...
                  1. y a pas que firefox qui plante y a aussi IE et Safari heureusement que j'ai Google Chrome ....

                    merci à tout ceux qui m'aiderons
                    1. Contributeur
                      ---> Télécharge Gmer http://www2.gmer.net/gmer.zip sur ton Bureau.

                      ---> Extrais le contenu de l'archive puis renomme gmer.exe en tib.exe (Le .exe n'est pas forcément visible).
                      sur ton burreau

                      ---> Double-clique sur tib.exe.

                      ---> Onglet "Rootkit/Malware", clique sur "Scan" puis patiente.

                      ---> si un message apparait vite clique sur no
                      ---> puis save (en-bas à droite)
                      ---> enregistre sur ton bureau,poste le

                      sinon

                      ---> En fin de traitement, clique sur "Save..." et enregistre sur ton Bureau "gmer.txt".

                      ---> Double-clique sur "gmer.txt", le rapport apparaît, poste-le.
                      1. quand je lance le scan avec tib au bout de 2 min a peu près j'ai un écran bleu comme quoi Windows a détecté un pb et doit s'arrêter ..............
                        1. ouais j'ai ce message comment faut faire pour pas lancer le scan en entier ???
                          1. Contributeur
                            dés que tu as le message tu clique sur NON
                            puis save en bas à droite
                            enregistre sur ton bureau puis poste le ici
                            1. donc je fais pas de scan
                              si oui voici le save

                              GMER 1.0.15.15077 [tib.exe] - http://www.gmer.net
                              Rootkit quick scan 2009-08-26 12:02:58
                              Windows 6.0.6001 Service Pack 1

                              ---- System - GMER 1.0.15 ----

                              Code 905DD2F0 ZwEnumerateKey
                              Code 90489240 ZwFlushInstructionCache
                              Code 904DD3F6 ZwSaveKey
                              Code 905FA2EE ZwSaveKeyEx
                              Code 9055E2ED IofCallDriver
                              Code 905F12EE IofCompleteRequest

                              ---- Devices - GMER 1.0.15 ----

                              Device \FileSystem\Ntfs \Ntfs 855291F8

                              ---- Services - GMER 1.0.15 ----

                              Service C:\Windows\System32\alg.exe? (*** hidden *** ) [MANUAL] ALG <-- ROOTKIT !!!
                              Service C:\Windows\system32\drivers\kbiwkmvvxudnbs.sys (*** hidden *** ) [SYSTEM] kbiwkmovlruvid <-- ROOTKIT !!!

                              ---- EOF - GMER 1.0.15 ----

                              1. Contributeur
                                - Télécharge The Avenger ici http://www.geekstogo.com/forum/files/file/393-the-avenger-by-swandog46/ et dézippe-le sur ton bureau.
                                Lance le fichier avenger.exe, valide le message d'accueil par OK et copie les lignes en gras suivante, d'un trait, dans le cadre "input Script here" :

                                Drivers to unload:
                                kbiwkmovlruvid


                                --> Clique ensuite sur "Execute", puis accepte de redémarrer ton pc
                                Après le redémarrage, un rapport devrait apparaitre (sinon ouvre le fichier C:\[b]avenger.txt[/b]) et copie/colle son contenu ici, lance combofix comme indiqué
                                Double clique combofix.exe et suis les instructions.
                                [*] Installe la console de récupération si proposé et continue.
                                [*] Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.


                                1. voici le rapport avenger

                                  Logfile of The Avenger Version 2.0, (c) by Swandog46
                                  http://swandog46.geekstogo.com

                                  Platform: Windows Vista

                                  *******************

                                  Script file opened successfully.
                                  Script file read successfully.

                                  Backups directory opened successfully at C:\Avenger

                                  *******************

                                  Beginning to process script file:

                                  Rootkit scan active.

                                  Hidden driver "a4jjd9zt" found!
                                  Could not open driver a4jjd9zt for rootkit scan. Error:c0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
                                  --> the object does not exist

                                  Hidden driver "ai0k7fyy" found!
                                  Could not open driver ai0k7fyy for rootkit scan. Error:c0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
                                  --> the object does not exist

                                  Rootkit scan completed.

                                  Driver "kbiwkmovlruvid" deleted successfully.

                                  Completed script processing.

                                  *******************

                                  Finished! Terminate.
                                  1. y se passe pas grand chose quand je lance combofix ...
                                    ça me met combofix is preparing too run et puis ça s'arrête
                                    • 1
                                    • 2
                                    • 3