Bitdefender ne répond plus

Bonjour,

Mon problème est que mon antivirus BitDefender total security 2009 s'est désactivé (depuis quelques semaines) et je ne peux plus l'activer. Lorsque je clique sur "activer", rien ne se passe...

Si quelqu'un peut m'aider, j'ai fait un scan hijackthis

Merci
Configuration: Windows Vista
Firefox 3.5.5

23 réponses

  1. Rebonjour, j'ai juste changer de pseudo ;))

    Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent

    ▶ Télécharge List&Kill'em et enregistre le sur ton bureau

    ▶ dezippe-le , (clic droit/ extraire.....)

    Il ne necessite pas d'installation

    ▶double clic (clic droit "executer en tant qu'administrateur" pour Vista) pour lancer le scan

    choisis la langue puis choisis l'option 1 = Mode Recherche

    ▶laisse travailler l'outil

    ▶Poste le contenu du rapport qui s'ouvre

    1
    1. Le RSIT sert à diagnostiquer ton PC pour visualiser les processus et fichiers système pour me permettre d'en déduire si oui ou non tu est infecté.

      Pour Listkill'em c'est un programme conçus par Gen-Hackman (que je salut au passage) il servira à neutraliser quelques infections qui se loge chez toi.

      1
      1. Salut,

        Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

        ! Déconnecte toi et FERME TOUTES TES APPLICATIONS EN COURS !

        Double-clique sur " RSIT.exe " pour le lancer .

        ▶ Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

        ▶ Devant l'option "List files/folders created ..." , tu choisis : 2 months

        ▶ clique ensuite sur " Continue " pour lancer l'analyse ...

        ▶ laisse faire le scan et ne touche pas au PC ...

        Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

        Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

        Important : poste un rapport, puis l'autre dans la réponse suivante
        Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum

        ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )
        0
        1. Salut,
          D'avance merci pour ton aide. voici mon fichier log.

          Logfile of random's system information tool 1.06 (written by random/random)
          Run by Di at 2009-11-28 16:07:29
          Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
          System drive C: has 12 GB (12%) free of 103 GB
          Total RAM: 2037 MB (42% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 16:07:47, on 28/11/2009
          Platform: Windows Vista SP1 (WinNT 6.00.1905)
          MSIE: Internet Explorer v8.00 (8.00.6001.18828)
          Boot mode: Normal

          Running processes:
          C:\Windows\system32\Dwm.exe
          C:\Windows\Explorer.EXE
          C:\Windows\system32\taskeng.exe
          C:\Program Files\Apoint2K\Apoint.exe
          C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
          C:\Program Files\Hp\QuickPlay\QPService.exe
          C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
          C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
          C:\Program Files\Java\jre6\bin\jusched.exe
          C:\Windows\System32\igfxtray.exe
          C:\Windows\System32\hkcmd.exe
          C:\Windows\System32\igfxpers.exe
          C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
          C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
          C:\Program Files\Windows Sidebar\sidebar.exe
          C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
          C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
          C:\Windows\ehome\ehtray.exe
          C:\Program Files\Eltima Software\SWF Live Preview\swf_lp.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe
          C:\Windows\system32\igfxsrvc.exe
          C:\Program Files\Windows Media Player\wmpnscfg.exe
          C:\Windows\ehome\ehmsas.exe
          C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
          C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
          C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
          C:\Program Files\Apoint2K\ApMsgFwd.exe
          C:\Program Files\Apoint2K\Apntex.exe
          C:\Windows\system32\conime.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\Windows\system32\rundll32.exe
          C:\Windows\system32\SearchFilterHost.exe
          C:\Windows\system32\wuauclt.exe
          C:\Users\Di\Desktop\RSIT.exe
          C:\Users\Di\Downloads\Di.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=compaq-notebook.msn.com&ocid=HPDHP&pc=CPNTDF
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=compaq-notebook.msn.com&ocid=HPDHP&pc=CPNTDF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=compaq-notebook.msn.com&ocid=HPDHP&pc=CPNTDF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.1.144:53
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          O1 - Hosts: ::1 localhost
          O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
          O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
          O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
          O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
          O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
          O3 - Toolbar: (no name) - {66886C4D-B307-4ECA-A228-52CA9B9851A4} - (no file)
          O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
          O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
          O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
          O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
          O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
          O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
          O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
          O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
          O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
          O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
          O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
          O4 - HKLM\..\Run: [DellNSCST_GRNCH] "C:\Program Files\Dell\Dell Laser MFP 1815\NetworkScan\DNSCST.exe" /HIDEUI
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
          O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
          O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
          O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun
          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
          O4 - HKCU\..\Run: [eemwa] "c:\users\di\appdata\local\eemwa.exe" eemwa
          O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
          O4 - HKCU\..\Run: [SWF Live Preview] C:\Program Files\Eltima Software\SWF Live Preview\swf_lp.exe
          O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
          O4 - Global Startup: McAfee Security Scan.lnk = ?
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
          O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
          O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
          O13 - Gopher Prefix:
          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
          O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
          O23 - Service: Planificateur LiveUpdate automatique (Automatic LiveUpdate Scheduler) - Symantec Corporation - c:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
          O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
          O23 - Service: EloSystemService - Elo Touchsystems - C:\Windows\system32\EloSrvce.exe
          O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
          O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
          O23 - Service: Service Google Update (gupdate1ca0659d0db58ee) (gupdate1ca0659d0db58ee) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
          O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
          O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
          O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
          O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
          O23 - Service: LiveUpdate - Symantec Corporation - c:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
          O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
          O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
          O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
          O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
          0
      2. Rien :/

        Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

        ▶ Télécharge :

        Malwarebytes

        ou :

        Malwarebytes

        ▶ Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

        (NB : Si tu as un message d'erreur t'indiquant qu'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX

        ▶ Potasses le Tuto pour te familiariser avec le prg :

        ( cela dit, il est très simple d'utilisation ).

        relance malwarebytes en suivant scrupuleusement ces consignes :

        ! Déconnecte toi et ferme toutes applications en cours !

        ▶ Lance Malwarebyte's .

        Fais un examen dit "Complet" .

        ▶ Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
        ▶ à la fin tu cliques sur "résultat" .
        Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

        Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

        Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)

        0
        1. Contributeur sécurité
          Bonjour à vous 2 :

          Helpeur mask y a infection navipromo et autres.:

          O4 - HKCU\..\Run: [eemwa] "c:\users\di\appdata\local\eemwa.exe" eemwa
          C:\Windows\tasks\RegCure Program Check.job
          C:\Windows\tasks\RegCure.job
          "eemwa"=c:\users\di\appdata\local\eemwa.exe eemwa []
          0
          1. Merci Pimprenelle j'exécute un Navilog après ce qui suit.
            0
            1. Contributeur sécurité
              non helper mask c'est un navilog d'abord qu'il faut faire, ensuite voir comment supprimer ça C:\Windows\tasks\RegCure Program Check.job, C:\Windows\tasks\RegCure.job et seulement après faire malwarebyte's. Malwarebyte's ce fait toujours à la fin quand on a vraiment tout désinfecté.
              0
              1. Salut,

                Par rapport à mon problème de départ avec BitDefender, j'ai écris au support Bitdefender qui m'a envoyé 2 liens pour télécharger des fichiers. L'un pour désinstaller le BDF 2009 que j'avais, et l'autre pour installer la dernière verions 2010. Depuis que je l'ai installé il y'a qques jours, il ne semble plus y avoir de problèmes, l'antivirus est et reste actif.

                Ensuite par rapport à ta remarque pimprenelle27, j'ai refais un scan et je constate que j'ai toujours les lignes que tu as relevé...
                Du coup que me conseilles-tu ?

                Merci à vous.
                Dia
                0
            2. Re,

              Helper-Mask, Malwarebytes. Comme dit, j'ai installé et lancé Malwarebytes qui a trouvé 5 éléments infectés. Ci-joint le rapport.

              Malwarebytes' Anti-Malware 1.42
              Version de la base de données: 3300
              Windows 6.0.6002 Service Pack 2
              Internet Explorer 8.0.6001.18828

              05/12/2009 21:30:36
              mbam-log-2009-12-05 (21-30-36).txt

              Type de recherche: Examen complet (C:\|D:\|)
              Eléments examinés: 329874
              Temps écoulé: 2 hour(s), 37 minute(s), 12 second(s)

              Processus mémoire infecté(s): 0
              Module(s) mémoire infecté(s): 0
              Clé(s) du Registre infectée(s): 3
              Valeur(s) du Registre infectée(s): 1
              Elément(s) de données du Registre infecté(s): 0
              Dossier(s) infecté(s): 0
              Fichier(s) infecté(s): 1

              Processus mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Module(s) mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Clé(s) du Registre infectée(s):
              HKEY_CURRENT_USER\SOFTWARE\fcn (Rogue.Residue) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\OOO (Malware.Trace) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\OOO (Rogue.LivePlayer) -> Quarantined and deleted successfully.

              Valeur(s) du Registre infectée(s):
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\eemwa (Trojan.Agent.H) -> Quarantined and deleted successfully.

              Elément(s) de données du Registre infecté(s):
              (Aucun élément nuisible détecté)

              Dossier(s) infecté(s):
              (Aucun élément nuisible détecté)

              Fichier(s) infecté(s):
              C:\Users\Di\Downloads\Moovida_setup.exe (Adware.NaviPromo) -> Quarantined and deleted successfully.
              0
              1. Aussi, juste une reflexion sur l'antivirus bitdefender, je ne trouve pas ça trop normal d'acheter un antivirus et de voir que j'ai quand meme des éléments infectés dans mon ordinateur... à se demander si ça me protège réellement bien.

                A+
                0
                1. Télécharge Navilog1 depuis-ce lien

                  ▶ Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
                  ▶ Ensuite double clique sur navilog1.exe pour lancer l'installation.

                  Une fois l'installation terminée, le fix s'exécutera automatiquement.

                  ▶ Au menu principal, Fais le choix 1 >> Recherche / suppression automatique

                  Patiente jusqu'au message :
                  *** Analyse Termine le ..... ***

                  >>>>> Le fix peut durer une dizaine de minutes ;)

                  ▶ Appuie sur une touche le bloc note va s'ouvrir.

                  ▶ Copie-colle le rapport ici.

                  0
                  1. Contributeur sécurité
                    dia.031, tu eux faire ce qu'à mis helper mask c'est à dire navilog.
                    0
                    1. Voici le rapport navilog.

                      DebugFile Navilog1 07/12/2009 19:57:53,50

                      Language French selected
                      Check OS
                      OS is Vista
                      Taking DelphPaths 07/12/2009 19:58:12,34
                      DelphPaths Ok 07/12/2009 19:58:12,79
                      C:\Program Files\navilog1\process.exe missing 07/12/2009 19:58:47,49
                      All Files presents 07/12/2009 19:58:47,56
                      Ch1 began 07/12/2009 at 19:59:20,99
                      Scan SF1 07/12/2009 19:59:21,05
                      End SF1 07/12/2009 19:59:21,11
                      Scan SF2 07/12/2009 19:59:21,13
                      End SF2 07/12/2009 19:59:21,18
                      Scan SF3 07/12/2009 19:59:21,19
                      End SF3 07/12/2009 19:59:21,25
                      Scan SF4 07/12/2009 19:59:21,26
                      End SF4 07/12/2009 19:59:21,33
                      Scan SF5 07/12/2009 19:59:21,34
                      End SF5 07/12/2009 19:59:21,39
                      Scan SFV1 07/12/2009 19:59:21,41
                      End SFV1 07/12/2009 19:59:30,38
                      Scan SFV2 07/12/2009 19:59:30,41
                      End SFV2 07/12/2009 19:59:34,29
                      Start SFiles 07/12/2009 19:59:34,35
                      End SFiles 07/12/2009 19:59:34,76
                      Start SReg 07/12/2009 19:59:34,81
                      End SReg 07/12/2009 19:59:42,18
                      Start Sheur 07/12/2009 19:59:42,20
                      End Sheur 07/12/2009 20:00:11,72
                      Start SCert 07/12/2009 20:00:11,74
                      End SCert 07/12/2009 20:00:16,03
                      Ch1 finished 07/12/2009 20:00:16,08
                      Language French selected
                      Check OS
                      OS is Vista
                      Taking DelphPaths
                      DelphPaths Ok
                      Cleanning stage on reboot 07/12/2009 20:11:21,60
                      Start SSF1 07/12/2009 20:11:43,49
                      End SSF1 07/12/2009 20:11:43,55
                      Start SSF2 07/12/2009 20:11:43,56
                      End SSF2 07/12/2009 20:11:43,67
                      Start SSF3 07/12/2009 20:11:43,67
                      End SSF3 07/12/2009 20:11:43,84
                      Start SSFV1 07/12/2009 20:11:43,86
                      End SSFV1 07/12/2009 20:11:51,39
                      Start SSFV2 07/12/2009 20:11:51,43
                      End SSFV2 07/12/2009 20:11:53,95
                      Start SSFiles 07/12/2009 20:11:53,97
                      End SSFiles 07/12/2009 20:11:54,66
                      Start SSHeur 07/12/2009 20:11:54,67
                      End SSHeur 07/12/2009 20:13:27,57
                      Start SSTemp 07/12/2009 20:13:27,58
                      End SSTemp 07/12/2009 20:13:49,56
                      Start CleanReg 07/12/2009 20:13:49,58
                      End CleanReg 07/12/2009 20:13:50,67
                      Start SSCert 07/12/2009 20:13:50,67
                      End SSCert 07/12/2009 20:14:02,04
                      Start Xtra 07/12/2009 20:14:02,09
                      End Xtra 07/12/2009 20:14:04,65
                      Ch234 finished 07/12/2009 20:14:04,67
                      0
                      1. C'est quoi cette chose ?o0
                        0
                        1. Contributeur sécurité
                          Bonsoir,

                          Dia 031 si tu as exécuté navilog normalement tu doit avoir un rapport qui se trouve là :

                          ▶un rapport : fixnavi.txt dans ==> C:
                          0
                          1. Si il répond plus, il a peut être changé de n° . . .
                            ok je sort désolé pour la blague pourrit a 1h13 du mat!
                            0
                            1. Bon alors voilà en espérant qu'il sagit du bon fichier (cleannavi.txt - j'ai pas trouvé de fichier fixnavi.txt)

                              Fix Navipromo version 4.0.5 commencé le 08/12/2009 17:36:12,88

                              !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                              !!! Postez ce rapport sur le forum pour le faire analyser !!!

                              Outil exécuté depuis C:\Program Files\navilog1

                              Mise à jour le 10.11.2009 à 18h00 par IL-MAFIOSO

                              Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6002 ) Service Pack 2
                              X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) Dual CPU T2390 @ 1.86GHz )
                              BIOS : Default System BIOS
                              USER : Di ( Administrator )
                              BOOT : Normal boot

                              C:\ (Local Disk) - NTFS - Total:100 Go (Free:12 Go)
                              D:\ (Local Disk) - NTFS - Total:11 Go (Free:2 Go)
                              E:\ (CD or DVD)

                              Recherche executée en mode normal

                              [b]Aucune Infection Navipromo/Egdaccess trouvée/b

                              *** Scan terminé 08/12/2009 17:37:16,12 ***
                              0
                              1. Refait nous un RSIT stp ..
                                0
                                1. Salut,
                                  Voici le rapport RIST. Est-ce qu'il te faut le info.txt ?
                                  J'ai un nouveau problème sur mon PC (depuis ces derniers jours), je ne sais pas si c'est lié aux dernières manip que j'ai fait mais en gros, au bout de quelques minutes après avoir démarrer, mon PC se bloque (quelque soit ce que je fais) je suis obligée de le forcer à s'éteindre en appuyant longtemps sur la touche d'arret, car rien ne répond et Ctrl+Alt+Suppr ne fonctionne pas non plus...

                                  Logfile of random's system information tool 1.06 (written by random/random)
                                  Run by Di at 2009-12-09 22:13:09
                                  Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
                                  System drive C: has 12 GB (12%) free of 103 GB
                                  Total RAM: 2037 MB (51% free)

                                  Logfile of Trend Micro HijackThis v2.0.2
                                  Scan saved at 22:13:55, on 09/12/2009
                                  Platform: Windows Vista SP2 (WinNT 6.00.1906)
                                  MSIE: Internet Explorer v8.00 (8.00.6001.18828)
                                  Boot mode: Normal

                                  Running processes:
                                  C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe
                                  C:\Windows\system32\Dwm.exe
                                  C:\Windows\Explorer.EXE
                                  C:\Program Files\Apoint2K\Apoint.exe
                                  C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                                  C:\Program Files\Hp\QuickPlay\QPService.exe
                                  C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
                                  C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                                  C:\Windows\System32\igfxtray.exe
                                  C:\Windows\System32\hkcmd.exe
                                  C:\Windows\System32\igfxpers.exe
                                  C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
                                  C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
                                  C:\Program Files\Java\jre6\bin\jusched.exe
                                  C:\Program Files\Windows Sidebar\sidebar.exe
                                  C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
                                  C:\Windows\ehome\ehtray.exe
                                  C:\Program Files\Windows Media Player\wmpnscfg.exe
                                  C:\Program Files\Eltima Software\SWF Live Preview\swf_lp.exe
                                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                  C:\Windows\System32\mobsync.exe
                                  C:\Program Files\BitDefender\BitDefender 2010\seccenter.exe
                                  C:\Windows\system32\taskeng.exe
                                  C:\Windows\system32\taskeng.exe
                                  C:\Program Files\Apoint2K\ApMsgFwd.exe
                                  C:\Windows\system32\igfxsrvc.exe
                                  C:\Windows\ehome\ehmsas.exe
                                  C:\Program Files\Apoint2K\Apntex.exe
                                  C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
                                  C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
                                  C:\Users\Di\Desktop\RSIT.exe
                                  C:\Users\Di\Downloads\Di.exe
                                  C:\Windows\system32\SearchProtocolHost.exe
                                  C:\Windows\system32\SearchFilterHost.exe
                                  C:\Windows\system32\wuauclt.exe

                                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=compaq-notebook.msn.com&ocid=HPDHP&pc=CPNTDF
                                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=compaq-notebook.msn.com&ocid=HPDHP&pc=CPNTDF
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=compaq-notebook.msn.com&ocid=HPDHP&pc=CPNTDF
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.1.144:53
                                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                  O1 - Hosts: ::1 localhost
                                  O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                                  O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                                  O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
                                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
                                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                                  O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
                                  O3 - Toolbar: (no name) - {66886C4D-B307-4ECA-A228-52CA9B9851A4} - (no file)
                                  O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2010\IEToolbar.dll
                                  O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
                                  O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
                                  O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
                                  O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
                                  O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
                                  O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                  O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                                  O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                                  O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                                  O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                                  O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                                  O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                                  O4 - HKLM\..\Run: [DellNSCST_GRNCH] "C:\Program Files\Dell\Dell Laser MFP 1815\NetworkScan\DNSCST.exe" /HIDEUI
                                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                                  O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2010\IEShow.exe"
                                  O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe"
                                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                                  O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                                  O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
                                  O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                  O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                  O4 - HKCU\..\Run: [SWF Live Preview] C:\Program Files\Eltima Software\SWF Live Preview\swf_lp.exe
                                  O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                                  O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                                  O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                                  O13 - Gopher Prefix:
                                  O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                                  O23 - Service: BitDefender Serveur Arrakis (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe
                                  O23 - Service: Planificateur LiveUpdate automatique (Automatic LiveUpdate Scheduler) - Symantec Corporation - c:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                                  O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                  O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
                                  O23 - Service: EloSystemService - Elo Touchsystems - C:\Windows\system32\EloSrvce.exe
                                  O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                                  O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
                                  O23 - Service: Service Google Update (gupdate1ca0659d0db58ee) (gupdate1ca0659d0db58ee) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                                  O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                  O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                                  O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                                  O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                  O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
                                  O23 - Service: LiveUpdate - Symantec Corporation - c:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
                                  O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                                  O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                                  O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe
                                  O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                                  0
                                  • 1
                                  • 2