Infecté par un trojan skintrim

Résolu
Bonjour à tous,

Je suis novice à l'outil informatique, je fais donc appel à votre aide car j'ai realisé un scan sur Symantec Securité et je suis infecé par un trojan.skintrim.
Pouvez-vous me dire si cette chose est dangereuse pour mon ordinateur ?
Si oui comment puis-je m'en debarasser.
Merci d'avance de vos reponse.
Configuration: Windows XP
Internet Explorer 6.0

36 réponses

Résumé de la discussion

Une détection par Symantec signale Skintrim, cheval de Troie, après un scan sur un PC Windows XP avec Internet Explorer 6; un utilisateur novice sollicite des conseils pour évaluer le danger et s'en débarrasser. Plusieurs réponses recommandent CCleaner pour le nettoyage et AVG Anti-Spyware pour l’analyse puis la quarantaine, avec génération et partage du rapport après les actions recommandées. D'autres interventions évoquent des procédures guidées via des raccourcis spécifiques, des outils comme Navilog1 et HijackThis, ou des scans en ligne (BitDefender Online) pour obtenir des rapports et orienter le nettoyage. En cas de doute, des rapports montrent que certains outils ne détectent rien d’anormal et conseillent d’effectuer les opérations en mode sans échec pour limiter les risques pendant le nettoyage.

Bobot (l’IA à votre service)
  1. Oui en effet trojan, c'est pas cool du tout.
    Essaye "Spybot"+"Ad-Aware" tous deux gratuits,efficaces et complementaires. Bit defender aussi la demo est gratuite. Si t'arrive a identifier le fichier responsable (soit absolument sur de ton coup) sans que tu puisse l'effacer essaye en mode sans echec, HijackThis peut l'erradiquer aussi si tu c'est quel fichier effacer(atention se n'est pas un programme de rigolos!). Efface aussi les fichiers "temp" : "poste de travail/panneau de config/options internet/géneral/suprimer ler fichiers temporaires".
    HijackThis c'est en dernier recours essaye pluto le reste.
    Tu devrai trouver ton bonheur sur "telecharger.com" voila.Si les cookies te tracassent essaye : "cookies manager".
    Bonne chance.
    0
    1. Bonjour, merci de vos reponses rapides, je viens de terminer le scan avec Ad-Aware 2007 mais il n'a rien trouver, mise à part quelques cookies.
      J'ai refait un scan avec Symantec et j'ai toujours le même resultat : 2 infections par Trojan Skintrim.
      Pour complement d'info je suis equipé de Trend Security et Spyware Terminator. Est ce qu'il tienne la route (en tant qu'anti-virus, trojan, ...) ?
      Merci d'avance de vos reponses
      0
      1. Salut à vous deux fais sa stp:
        Télécharge CCleaner.

        https://www.pcastuces.com/logitheque/ccleaner.htm

        Installe le dans un répertoire dédié.

        Décoche pendant l'installation

        --- les deux cases "Ajouter l'option ... "

        --- Contrôler les mises à jour

        --- Ajouter la Barre d'Outils Yahoo! CCleaner

        * Lance Ccleaner pour un nettoyage complet.

        ------

        * télécharge AVG Anti-Spyware (ewido)

        https://www.avg.com/en-ww/free-antivirus-download

        * tu l'installes

        * lance AVG Anti-Spyware et clique sur le bouton Mise à jour. Patiente

        puis

        Lance AVG Anti-Spyware

        Clique sur le bouton Analyse (de la barre d'outils)

        puis fait dans l'ordre stp. Tu sauvegardes le rapport APRES avoir mis les actions.

        Puis sur l'onglet Paramètres,
        sous : "Comment réagir "clique sur Actions recommandées. Sélectionne Quarantaine.

        Reviens à l'onglet Analyse. Clique sur Analyse complète du système.

        A la fin du scan, choisis l'option 3

        "Appliquer toutes les actions " en bas.

        Clique sur "Enregistrer le rapport".

        Ceci génère un rapport en fichier texte qui se trouve dans le dossier Reports du dossier d'AVG Anti-Spyware.

        Poste le.
        0
        1. Bonjour,

          J'ai telechargé comme stipuler dans le precedant message AVG Anti-Spyware 7.5. J'ai mis à jour et realisé un scan, il n'a trouvé que quatres traces de cookie. Voici le rapport ci-dessous, mais il me semble que l'anlyse AVG n'a pas vu le trojan. Cependant je peux vous fournir des informations sur l'emplacement du trojan skintrim que Symantec m'a fournie. Il dit que je suis infecté sur 2 fichiers :
          - C:\WINDOWS\system32\sjucvfwb.exe.ren infecté par Trojan.Skintrim.
          - C:\WINDOWS\system32\wxkmfcqe.exe.ren infecté par Trojan.Skintrim.

          Comme d'habitude, merci d'avance aux ames charitables qui me viendront en aide.

          Rapport de AVG :
          ---------------------------------------------------------
          AVG Anti-Spyware - Rapport d'analyse
          ---------------------------------------------------------

          + Créé à: 20:04:55 18/06/2007

          + Résultat de l'analyse:

          C:\Documents and Settings\Laetitia\Cookies\laetitia@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
          C:\Documents and Settings\Laetitia\Cookies\laetitia@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Nettoyé.
          C:\Documents and Settings\Laetitia\Cookies\laetitia@serving-sys[2].txt -> TrackingCookie.Serving-sys : Nettoyé.
          C:\Documents and Settings\Laetitia\Cookies\laetitia@weborama[2].txt -> TrackingCookie.Weborama : Nettoyé.

          Fin du rapport
          0
          1. Contributeur sécurité
            télécharge et installe le logiciel HijackThis v1.99.1
            http://pchelpbordeaux.free.fr/logiciels.html
            Tutorial
            http://pchelpbordeaux.free.fr/tuto.html
            poste son rapport

            télécharge GenProc de Jean-Chretien1 et Narco4 sur ton bureau
            http://www.alt-shift-return.org/Info/Fichiers/GenProc.zip

            dézippe le dossier, double-clique sur GenProc.bat et poste le contenu du rapport qui s'ouvre

            Aide en images : http://www.alt-shift-return.org/Info/GenProc-HowTo.html
            poste les rapports car parfois il faut ajouter des consignes à la manip pour que cela fonctionne parfaitement
            0
            1. Bonsoir,

              Voici le rapport du logiciel HijackThis v1.99.1. il sert à quoi ce logiciel
              Logfile of HijackThis v1.99.1
              Scan saved at 21:20:06, on 18/06/2007
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
              C:\WINDOWS\system32\nvsvc32.exe
              C:\Program Files\Spyware Terminator\sp_rsser.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Trend Micro\Internet Security\Tmntsrv.exe
              C:\Program Files\Trend Micro\Internet Security\tmproxy.exe
              C:\Program Files\Trend Micro\Internet Security\pccguide.exe
              C:\Program Files\Trend Micro\Internet Security\PCClient.exe
              C:\Program Files\Trend Micro\Internet Security\TMOAgent.exe
              C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
              C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
              C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe
              C:\Program Files\Trend Micro\Internet Security\PccPfw.exe
              C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
              C:\Program Files\MSN Messenger\msnmsgr.exe
              C:\Program Files\MSN Messenger\usnsvc.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
              C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer fourni par Club-Internet
              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=proxy.club-internet.fr:8080
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
              O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
              O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
              O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
              O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
              O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
              O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security\pccguide.exe"
              O4 - HKLM\..\Run: [PCClient.exe] "C:\Program Files\Trend Micro\Internet Security\PCClient.exe"
              O4 - HKLM\..\Run: [TM Outbreak Agent] "C:\Program Files\Trend Micro\Internet Security\TMOAgent.exe" /run
              O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
              O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
              O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
              O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"
              O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
              O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
              O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
              O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
              O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
              O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
              O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
              O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
              O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
              O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP-1.0.cab
              O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
              O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
              O17 - HKLM\System\CCS\Services\Tcpip\..\{4B0E359C-A7CF-45CA-8648-45A6431CFD8F}: NameServer = 192.168.0.254
              O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
              O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
              O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
              O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
              O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
              O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
              O23 - Service: Trend Micro Personal Firewall (PccPfw) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Internet Security\PccPfw.exe
              O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
              O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Internet Security\Tmntsrv.exe
              O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Internet Security\tmproxy.exe
              0
              1. Rebonsoir,
                Voici le complement d'info, j'ai lancé GenProc comme demandé et posté le rapport.
                Au plaisir de vous lire, et merci de votre aide.

                Rapport GenProc 0.55 [1] effectué le 18/06/2007 à 21:37:35,23 - SystemRoot = C:\WINDOWS

                Dans CCleaner, clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures". Par la suite, laisse-le avec ses réglages par défaut. C'est tout.

                # Etape 1/ Télécharge :

                - ELIBAGLA en bas de cette page http://www.zonavirus.com/datos/descargas/95/elibagla.asp (clique sur le bouton "Descargar Elibagla") sur ton bureau.
                Lance l'outil ELIBAGLA, de préférence en mode sans échec si tu en as la possibilité, en mode normal dans le cas contraire. Patiente le temps du scan.
                Lorsque c'est terminé, redémarre ton ordinateur.

                # Etape 2/ Lance CCleaner > "Nettoyeur" > "Lancer le nettoyage" et c'est tout.

                # Etape 3/ Poste le contenu du fichier infosat.txt qui se trouve dans Poste de travail > disque C:\ et un nouveau rapport GenProc.
                0
                1. Contributeur sécurité
                  tu fais très exactement ce que te demande GenProc et tu postes les rapports obtenus
                  0
                  1. Bonjour,

                    Je ne trouve pas de ELIBAGLA sur le lien fournie ?
                    Ensuite comment on fait pour se mettre en mode sans echec ou normal ?
                    Merci d'avance
                    0
                    1. Contributeur sécurité
                      il semble que le lien ne soit plus valide
                      je recherche autre chose et te tiens au courant
                      0
                      1. Contributeur sécurité
                        Télécharge Blacklight (le 1er de la page)
                        https://europe.f-secure.com/exclude/blacklight/index.shtml

                        Enregistre le sur ton Bureau.
                        Double-clique fsbl.exe
                        Clique sur "I ACCEPT" .
                        clique Scan puis Next

                        Tu verras une liste de fichiers détectés apparaître. Tu verras également un rapport,
                        sur ton Bureau, nommé fsbl.xxxxxxx.log (les xxxxxxx sont des chiffres).

                        poste ce rapport dans ta prochaine réponse.
                        NE PAS choisir l'option "Rename" de suite car des fichiers légitimes peuvent être présents, tel wbemtest.exe
                        0
                        1. Bonjour
                          Voici le rapport mais à priori il n'a rien trouver d'anormales
                          06/19/07 17:14:38 [Info]: BlackLight Engine 1.0.64 initialized
                          06/19/07 17:14:38 [Info]: OS: 5.1 build 2600 (Service Pack 2)
                          06/19/07 17:14:38 [Note]: 7019 4
                          06/19/07 17:14:38 [Note]: 7005 0
                          06/19/07 17:14:49 [Note]: 7006 0
                          06/19/07 17:14:50 [Note]: 7011 1508
                          06/19/07 17:14:50 [Note]: 7026 0
                          06/19/07 17:14:50 [Note]: 7026 0
                          06/19/07 17:14:52 [Note]: FSRAW library version 1.7.1022
                          06/19/07 17:19:04 [Note]: 7006 0
                          06/19/07 17:19:04 [Note]: 7011 1508
                          06/19/07 17:19:04 [Note]: 7026 0
                          06/19/07 17:19:04 [Note]: 7026 0
                          06/19/07 17:19:06 [Note]: FSRAW library version 1.7.1022
                          06/19/07 17:19:32 [Note]: 7007 0
                          0
                          1. Contributeur sécurité
                            faire un scan antivirus en ligne avec internet explorer et accepter l'activex
                            poster le rapport ici ensuite
                            https://www.bitdefender.fr/

                            En bas, à gauche de la fenêtre, clique sur BitDefender SCAN ONLINE
                            Dans la nouvelle fenêtre, clique sur I agree
                            La fenêtre change encore, clique sur Click here to scan
                            Les signatures se chargent, etc.

                            tuto en image
                            http://pageperso.aol.fr/rginformatique/mapage/defender.htm
                            0
                            1. Bonjour voici le rapport de bitdefender, à priori il a trouvé le trojan skintrim.
                              Merci de votre aide pour me debarasser de ce trojan

                              <HTML>
                              <HEAD>
                              <TITLE>BitDefender Online Scanner - Rapport d'analyse</TITLE>
                              <META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
                              </HEAD>
                              <BODY BGCOLOR=#FFFFFF leftmargin="10" marginwidth="0" topmargin="20" marginheight="0" >

                              <table align="center" border="0" cellpadding="0" cellspacing="0" width="90%">
                              <tr>
                              <td width="458">
                              <p><font face="Arial" color=red><span style="font-size:14pt;"><b>BitDefender Online Scanner</b></span></font></p>
                              </td>
                              <td width="40%">
                              <p> </p>
                              </td>
                              <td width="10%">
                              <p> </p>
                              </td>
                              </tr>
                              <tr>
                              <td colspan="3" width="912">
                              <p><font face="Arial"><span style="font-size:11pt;"><B>Rapport d'analyse généré à: Wed, Jun 20, 2007 - 19:22:32</b></span></font></p>
                              </td>
                              </tr>

                              <tr>
                              <td width="458">
                              <p><font face="Arial"><span style="font-size:11pt;"><B> </b></span></font></p>
                              </td>
                              <td width="40%">
                              <p> </p>
                              </td>
                              <td width="10%">
                              <p> </p>
                              </td>
                              </tr>

                              <tr>
                              <td width="458">
                              <p><font face="Arial"><span style="font-size:11pt;"><B>Voie d'analyse: </b></span><span style="font-size:10pt;">A:\;C:\;D:\;E:\;F:\;H:\;</span></font></p>
                              </td>
                              <td width="40%">
                              <p> </p>
                              </td>
                              <td width="10%">
                              <p> </p>
                              </td>
                              </tr>

                              <tr>
                              <td width="458">
                              <p><font face="Arial"><span style="font-size:11pt;"><B> </b></span></font></p>
                              </td>
                              <td width="40%">
                              <p> </p>
                              </td>
                              <td width="10%">
                              <p> </p>
                              </td>
                              </tr>

                              <tr>
                              <td width="458">
                              <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
                              <tr>
                              <td width="451" colspan="2" bgcolor="#CCCCCC">
                              <p><font face="Arial" size="2"><B>Statistiques</b></font></p>
                              </td>
                              </tr>
                              <tr>
                              <td width="57%">
                              <p><font face="Arial" size="2">Temps</font></p>
                              </td>
                              <td width="43%" align="right">
                              <p><font face="Arial" size="2">01:14:47</font></p>
                              </td>
                              </tr>
                              <tr>
                              <td width="57%">
                              <p><font face="Arial" size="2">Fichiers</font></p>
                              </td>
                              <td width="43%" align="right">
                              <p><font face="Arial" size="2">72612</font></p>
                              </td>
                              </tr>
                              <tr>
                              <td width="57%">
                              <p><font face="Arial" size="2">Directoires</font></p>
                              </td>
                              <td width="43%" align="right">
                              <p><font face="Arial" size="2">3102</font></p>
                              </td>
                              </tr>
                              <tr>
                              <td width="57%">
                              <p><font face="Arial" size="2">Secteurs de boot</font></p>
                              </td>
                              <td width="43%" align="right">
                              <p><font face="Arial" size="2">2</font></p>
                              </td>
                              </tr>
                              <tr>
                              <td width="57%">
                              <p><font face="Arial" size="2">Archives</font></p>
                              </td>
                              <td width="43%" align="right">
                              <p><font face="Arial" size="2">1326</font></p>
                              </td>
                              </tr>
                              <tr>
                              <td width="57%">
                              <p><font face="Arial" size="2">Paquets programmes</font></p>
                              </td>
                              <td width="43%" align="right">
                              <p><font face="Arial" size="2">4826</font></p>
                              </td>
                              </tr>
                              </table>
                              </td>
                              <td width="40%">
                              <p> </p>
                              </td>
                              <td width="10%">
                              <p> </p>
                              </td>
                              </tr>

                              <tr>
                              <td width="458">
                              <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
                              <tr>
                              <td width="451" colspan="2" bgcolor="#CCCCCC">
                              <p><font face="Arial" size="2"><B>Résultats</b></font></p>
                              </td>
                              </tr>
                              <tr>
                              <td width="57%">
                              <p><font face="Arial" size="2">Virus identifiés</font></p>
                              </td>
                              <td width="43%" align="right">
                              <p><font face="Arial" size="2">1</font></p>
                              </td>
                              </tr>
                              <tr>
                              <td width="57%">
                              <p><font face="Arial" size="2">Fichiers infectés</font></p>
                              </td>
                              <td width="43%" align="right">
                              <p><font face="Arial" size="2">1</font></p>
                              </td>
                              </tr>
                              <tr>
                              <td width="57%">
                              <p><font face="Arial" size="2">Fichiers suspects</font></p>
                              </td>
                              <td width="43%" align="right">
                              <p><font face="Arial" size="2">0</font></p>
                              </td>
                              </tr>
                              <tr>
                              <td width="57%">
                              <p><font face="Arial" size="2">Avertissements</font></p>
                              </td>
                              <td width="43%" align="right">
                              <p><font face="Arial" size="2">0</font></p>
                              </td>
                              </tr>
                              <tr>
                              <td width="57%">
                              <p><font face="Arial" size="2">Désinfectés</font></p>
                              </td>
                              <td width="43%" align="right">
                              <p><font face="Arial" size="2">0</font></p>
                              </td>
                              </tr>
                              <tr>
                              <td width="57%">
                              <p><font face="Arial" size="2">Fichiers effacés</font></p>
                              </td>
                              <td width="43%" align="right">
                              <p><font face="Arial" size="2">1</font></p>
                              </td>
                              </tr>
                              </table>
                              </td>
                              <td width="40%">
                              <p> </p>
                              </td>
                              <td width="10%">
                              <p> </p>
                              </td>
                              </tr>

                              <tr>
                              <td width="458">
                              <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
                              <tr>
                              <td width="451" colspan="2" bgcolor="#CCCCCC">
                              <p><font face="Arial" size="2"><B>Info sur les moteurs</b></font></p>
                              </td>
                              </tr>
                              <tr>
                              <td width="57%">
                              <p><font face="Arial" size="2">Définition virus</font></p>
                              </td>
                              <td width="43%" align="right">
                              <p><font face="Arial" size="2">514494</font></p>
                              </td>
                              </tr>
                              <tr>
                              <td width="57%">
                              <p><font face="Arial" size="2">Version des moteurs</font></p>
                              </td>
                              <td width="43%" align="right">
                              <p><font face="Arial" size="2">AVCORE v1.0 (build 2410) (i386) (Jun 12 2007 21:08:27)</font></p>
                              </td>
                              </tr>
                              <tr>
                              <td width="57%">
                              <p><font face="Arial" size="2">Analyse des plugins</font></p>
                              </td>
                              <td width="43%" align="right">
                              <p><font face="Arial" size="2">14</font></p>
                              </td>
                              </tr>
                              <tr>
                              <td width="57%">
                              <p><font face="Arial" size="2">Archive des plugins</font></p>
                              </td>
                              <td width="43%" align="right">
                              <p><font face="Arial" size="2">38</font></p>
                              </td>
                              </tr>
                              <tr>
                              <td width="57%">
                              <p><font face="Arial" size="2">Unpack des plugins</font></p>
                              </td>
                              <td width="43%" align="right">
                              <p><font face="Arial" size="2">6</font></p>
                              </td>
                              </tr>
                              <tr>
                              <td width="57%">
                              <p><font face="Arial" size="2">E-mail plugins</font></p>
                              </td>
                              <td width="43%" align="right">
                              <p><font face="Arial" size="2">6</font></p>
                              </td>
                              </tr>
                              <tr>
                              <td width="57%">
                              <p><font face="Arial" size="2">Système plugins</font></p>
                              </td>
                              <td width="43%" align="right">
                              <p><font face="Arial" size="2">1</font></p>
                              </td>
                              </tr>
                              </table>
                              </td>
                              <td width="40%">
                              <p> </p>
                              </td>
                              <td width="10%">
                              <p> </p>
                              </td>
                              </tr>

                              <tr>
                              <td width="458">
                              <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
                              <tr>
                              <td width="451" colspan="2" bgcolor="#CCCCCC">
                              <p><font face="Arial" size="2"><B>Paramètres d'analyse</b></font></p>
                              </td>
                              </tr>
                              <tr>
                              <td width="57%">
                              <p><font face="Arial" size="2">Première action</font></p>
                              </td>
                              <td width="43%" align="right">
                              <p><font face="Arial" size="2">Désinfecté</font></p>
                              </td>
                              </tr>
                              <tr>
                              <td width="57%">
                              <p><font face="Arial" size="2">Seconde Action</font></p>
                              </td>
                              <td width="43%" align="right">
                              <p><font face="Arial" size="2">Supprimé</font></p>
                              </td>
                              </tr>
                              <tr>
                              <td width="57%">
                              <p><font face="Arial" size="2">Heuristique</font></p>
                              </td>
                              <td width="43%" align="right">
                              <p><font face="Arial" size="2">Oui</font></p>
                              </td>
                              </tr>
                              <tr>
                              <td width="57%">
                              <p><font face="Arial" size="2">Acceptez les avertissements</font></p>
                              </td>
                              <td width="43%" align="right">
                              <p><font face="Arial" size="2">Oui</font></p>
                              </td>
                              </tr>
                              <tr>
                              <td width="57%">
                              <p><font face="Arial" size="2">Extensions analysées</font></p>
                              </td>
                              <td width="43%" align="right">
                              <p><font face="Arial" size="2">*;</font></p>
                              </td>
                              </tr>

                              <tr>
                              <td width="57%">
                              <p><font face="Arial" size="2">Excludez les extensions</font></p>
                              </td>
                              <td width="43%" align="right">
                              <p><font face="Arial" size="2"> </font></p>
                              </td>
                              </tr>
                              <tr>
                              <td width="57%">
                              <p><font face="Arial" size="2">Analyse d'emails</font></p>
                              </td>
                              <td width="43%" align="right">
                              <p><font face="Arial" size="2">Oui</font></p>
                              </td>
                              </tr>
                              <tr>
                              <td width="57%">
                              <p><font face="Arial" size="2">Analyse des Archives</font></p>
                              </td>
                              <td width="43%" align="right">
                              <p><font face="Arial" size="2">Oui</font></p>
                              </td>
                              </tr>
                              <tr>
                              <td width="57%">
                              <p><font face="Arial" size="2">Analyser paquets programmes</font></p>
                              </td>
                              <td width="43%" align="right">
                              <p><font face="Arial" size="2">Oui</font></p>
                              </td>
                              </tr>
                              <tr>
                              <td width="57%">
                              <p><font face="Arial" size="2">Analyse des fichiers</font></p>
                              </td>
                              <td width="43%" align="right">
                              <p><font face="Arial" size="2">Oui</font></p>
                              </td>
                              </tr>
                              <tr>
                              <td width="57%">
                              <p><font face="Arial" size="2">Analyse de boot</font></p>
                              </td>
                              <td width="43%" align="right">
                              <p><font face="Arial" size="2">Oui</font></p>
                              </td>
                              </tr>
                              </table>
                              </td>
                              <td width="40%">
                              <p> </p>
                              </td>
                              <td width="10%">
                              <p> </p>
                              </td>
                              </tr>

                              <tr>
                              <td colspan=2>  
                              <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
                              <tr>
                              <td width="252" bgcolor="#CCCCCC">
                              <p><font face="Arial" size="2"><B>Fichier analysé</b></font></p>
                              </td>
                              <td width="195" bgcolor="#CCCCCC" align="right">
                              <p align="left"><b><font size="2" face="Arial"> Statut</font></b></p>
                              </td>
                              </tr>
                              <tr>
                              <td width="57%">
                              <p><font face="Arial" size="2">C:\WINDOWS\PACK.EPK.ren=>(NSIS 2g)=>lzma_solid_nsis0008</font></p>
                              </td>
                              <td width="43%" align="left">
                              <p><font face="Arial" size="2">Infecté par: Trojan.Skintrim.AJ</font></p>
                              </td>
                              </tr><tr>
                              <td width="57%">
                              <p><font face="Arial" size="2">C:\WINDOWS\PACK.EPK.ren=>(NSIS 2g)=>lzma_solid_nsis0008</font></p>
                              </td>
                              <td width="43%" align="left">
                              <p><font face="Arial" size="2">Echec de la désinfection</font></p>
                              </td>
                              </tr><tr>
                              <td width="57%">
                              <p><font face="Arial" size="2">C:\WINDOWS\PACK.EPK.ren=>(NSIS 2g)=>lzma_solid_nsis0008</font></p>
                              </td>
                              <td width="43%" align="left">
                              <p><font face="Arial" size="2">Supprimé</font></p>
                              </td>
                              </tr><tr>
                              <td width="57%">
                              <p><font face="Arial" size="2">C:\WINDOWS\PACK.EPK.ren=>(NSIS 2g)</font></p>
                              </td>
                              <td width="43%" align="left">
                              <p><font face="Arial" size="2">Echec de la mise à jour</font></p>
                              </td>
                              </tr>
                              </table>
                              </td>

                              <td width="10%">
                              <p> </p>
                              </td>
                              </tr>

                              <tr>
                              <td width="458">
                              <p><font face="Arial"><span style="font-size:11pt;"><B> </b></span></font></p>
                              </td>
                              <td width="40%">
                              <p> </p>
                              </td>
                              <td width="10%">
                              <p> </p>
                              </td>
                              </tr>

                              <tr>
                              <td width="458">
                              <p><font face="Arial"><span style="font-size:11pt;"><B> </b></span></font></p>
                              </td>
                              <td width="40%">
                              <p> </p>
                              </td>
                              <td width="10%">
                              <p> </p>
                              </td>
                              </tr>

                              </table>
                              <p> </p>

                              </body>
                              </html>
                              0
                              1. Contributeur sécurité
                                Clique sur ce lien :
                                http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
                                Clique sur navilog1.zip pour télécharger navilog1.exe.

                                Choisis Enregistrer

                                et enregistre-le sur ton bureau.

                                Ensuite double clique sur navilog1.exe pour lancer l'installation.
                                Une fois l'installation terminée, le fix s'exécutera automatiquement.
                                (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

                                Laisse-toi guider. Au menu principal, choisis 1 et valides.
                                (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

                                Patiente jusqu'au message :
                                *** Analyse Termine le ..... ***
                                Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
                                Copie-colle l'intégralité dans une réponse. Referme le blocnote.
                                Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)
                                0
                                1. Trouve ci joint le rapport fourni par le logiciel que tu m'a demandé de telecharger.

                                  Search Navipromo version 2.0.3 commencé le 21/06/2007 à 15:44:26,50

                                  !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                                  !!! Poster ce rapport sur le forum pour le faire analyser !!!
                                  !!! Ne pas lancer la partie désinfection sans l'avis d'un spécialiste !!!

                                  Fix lancé depuis C:\Program Files\navilog1
                                  Mise a jour le 08.06.2007 a 17h00 by IL-MAFIOSO

                                  Executé en mode normal

                                  *** Recherche Programmes installes ***

                                  *** Recherche dossiers dans C:\WINDOWS ***

                                  *** Recherche dossiers dans C:\Program Files ***

                                  *** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***

                                  *** Recherche dossiers dans C:\Documents and Settings\Laetitia\Application Data ***

                                  ...\Application Data\MessengerSkinner trouvé !

                                  *** Recherche avec BlackLight Engine/F-secure ***
                                  BlackLight Engine est un produit de F-secure, pour + d'infos :
                                  https://www.f-secure.com/en

                                  F-SECURE BLACKLIGHT ROOTKIT ELIMINATOR
                                  ======================================

                                  Copyright 2005-2006 F-Secure Corporation. All rights reserved.
                                  This is a beta version. It will expire on 1st of April, 2007.
                                  Version information: 2.2.1061.

                                  [+] Started on 06/21/07 at 15:44:27.
                                  [+] Initializing ...
                                  [+] Starting scan, press Ctrl-C to abort.
                                  [+] Scanning for hidden items ..................................
                                  [+] Scan complete.
                                  [+] Summary: 0 hidden item(s) found, 0 scheduled for renaming.
                                  [+] Exited on 06/21/07 at 15:47:17 (return code = 0).

                                  *** Recherche fichiers ***

                                  *** Recherche cles registre ***

                                  Recherche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs]

                                  Recherche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage]

                                  Recherche Clé Magic Control

                                  HKEY_CURRENT_USER\Software\Lanconfig trouvé !
                                  HKEY_USERS\S-1-5-21-746137067-1177238915-682003330-1003\Software\Lanconfig trouvé !

                                  *** Module de Recherche complémentaire ***
                                  (Recherche fichiers spécifiques)

                                  1)Recherche fichiers connus:

                                  2)Recherche Heuristique :
                                  *
                                  C:\WINDOWS\system32\bvcerfaubd.dat trouvé !
                                  **
                                  C:\WINDOWS\system32\bvcerfaubd.dat trouvé !
                                  ***
                                  ****
                                  C:\WINDOWS\system32\bvcerfaubd_navps.dat trouvé !
                                  *****
                                  C:\WINDOWS\system32\bvcerfaubd_nav.dat trouvé !
                                  ******
                                  *******
                                  ********
                                  C:\WINDOWS\system32\wxkmfcqe.exe trouvé !

                                  *** Analyse Terminé le 21/06/2007 à 15:47:54,81 ***
                                  0
                              2. Contributeur sécurité
                                Double clique sur le raccourci Navilog1 présent sur le bureau et laisse-toi guider.
                                Au menu principal, choisis 2 et valide.

                                Le fix va t'informer qu'il va alors redémarrer ton PC
                                Ferme toutes les fenêtres ouvertes et enregistre tes documents personnels ouverts
                                Appuie sur une touche comme demandé.
                                (si ton Pc ne redémarre pas automatiquement, fais le toi même)
                                Au redémarrage de ton PC, choisis ta session habituelle.

                                Patiente jusqu'au message :
                                *** Nettoyage Termine le ..... ***
                                Le blocnote va s'ouvrir.
                                Sauvegarde le rapport de manière à le retrouver
                                Referme le blocnote. Ton bureau va réapparaitre

                                PS:Si ton bureau ne réapparait pas, fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.
                                Puis rends-toi à l'onglet "processus". Cliques en haut à gauche sur fichiers et choisis "exécuter"
                                Tapes explorer et valides. Celà te fera apparaitre ton bureau

                                Fermez Internet explorer puis Démarrer/panneau de configuration/options Internet
                                - onglet "Contenu" puis onglet "Certificats" et si vous trouvez ceci, en particulier dans « éditeurs approuvés » :
                                electronic-group
                                egroup
                                Montorgueil
                                VIP
                                "Sunny Day Design Ltd"

                                Les supprimer.
                                poste le rapport obtenu avec un nouveau hijack this
                                0
                                1. Voici le rapport de Hijack This aprés avoir fait les manipulations demandés

                                  Logfile of HijackThis v1.99.1
                                  Scan saved at 17:39:12, on 21/06/2007
                                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                                  MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                                  Running processes:
                                  C:\WINDOWS\System32\smss.exe
                                  C:\WINDOWS\system32\winlogon.exe
                                  C:\WINDOWS\system32\services.exe
                                  C:\WINDOWS\system32\lsass.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\WINDOWS\system32\spoolsv.exe
                                  C:\WINDOWS\system32\nvsvc32.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\Program Files\Trend Micro\Internet Security\Tmntsrv.exe
                                  C:\Program Files\Trend Micro\Internet Security\tmproxy.exe
                                  C:\Program Files\Trend Micro\Internet Security\PccPfw.exe
                                  C:\WINDOWS\explorer.exe
                                  C:\Program Files\Trend Micro\Internet Security\pccguide.exe
                                  C:\Program Files\Internet Explorer\iexplore.exe
                                  C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                                  C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

                                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
                                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
                                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer fourni par Club-Internet
                                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=proxy.club-internet.fr:8080
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                  R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                  O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                  O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                                  O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                                  O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
                                  O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security\pccguide.exe"
                                  O4 - HKLM\..\Run: [PCClient.exe] "C:\Program Files\Trend Micro\Internet Security\PCClient.exe"
                                  O4 - HKLM\..\Run: [TM Outbreak Agent] "C:\Program Files\Trend Micro\Internet Security\TMOAgent.exe" /run
                                  O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                  O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"
                                  O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                                  O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                                  O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                                  O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                  O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
                                  O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
                                  O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                                  O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                                  O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
                                  O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                                  O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                                  O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                                  O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
                                  O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP-1.0.cab
                                  O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
                                  O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                                  O17 - HKLM\System\CCS\Services\Tcpip\..\{4B0E359C-A7CF-45CA-8648-45A6431CFD8F}: NameServer = 192.168.0.254
                                  O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                                  O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                                  O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
                                  O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
                                  O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                  O23 - Service: Trend Micro Personal Firewall (PccPfw) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Internet Security\PccPfw.exe
                                  O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Internet Security\Tmntsrv.exe
                                  O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Internet Security\tmproxy.exe
                                  0
                              3. Contributeur sécurité
                                comment va le PC?
                                as tu encore des soucis?
                                faire un scan antivirus en ligne avec internet explorer et accepter l'activex
                                poster le rapport ici ensuite

                                https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                                0
                                1. Je viens de terminer de faire un scan avec Symantec, il dit que j'ai toujours le trojan skintrim mais il a bougé de place.
                                  Je fais le scan que tu m'a demandé et je te poste le rapport.
                                  Quelque soit l'issue merci beaucoup de ton aide.
                                  0
                              4. Contributeur sécurité
                                il me faut le chemin de ce trojan...
                                0
                                1. Contributeur sécurité
                                  il serait bien aussi que tu fasses ceci
                                  # Etape 1/ Télécharge :

                                  - ELIBAGLA en bas de cette page http://www.zonavirus.com/datos/descargas/95/elibagla.asp (clique sur le bouton "Descargar Elibagla") sur ton bureau.
                                  Lance l'outil ELIBAGLA, de préférence en mode sans échec si tu en as la possibilité, en mode normal dans le cas contraire. Patiente le temps du scan.
                                  Lorsque c'est terminé, redémarre ton ordinateur.

                                  # Etape 2/ Lance CCleaner > "Nettoyeur" > "Lancer le nettoyage" et c'est tout.

                                  # Etape 3/ Poste le contenu du fichier infosat.txt qui se trouve dans Poste de travail > disque C:\ et un nouveau rapport GenProc.

                                  elibagla se trouve tout au bas de la page sur laquelle t'envoie le lien
                                  sous ceci,
                                  CONDICIONES DE LAS DESCARGAS de UTILIDADES de SATINFO
                                  
                                  ESTAS UTILIDADES NO PUEDEN SER OFRECIDAS POR CUALQUIER OTRO MEDIO NI POR NINGUNA OTRA WEB SIN EL CONTRATO POR ESCRITO DE SATINFO AL RESPECTO. EN ESTA WEB SE OFRECEN EN CONCEPTO DE EVALUACION EN EL FORO DE ZONAVIRUS, SIENDO COMO SON, NO COMO PUDIERA PENSARSE QUE DEBERIAN SER, O DESEARSE QUE FUERAN, QUEDANDO ZONAVIRUS.com Y SATINFO, AL IGUAL QUE LOS QUE LAS SUGIRIERAN USAR EN EL FORO de ZONAVIRUS.com, EXIMIDOS DE CUALQUIER RESPONSABILIDAD POR LOS PERJUICIOS QUE PUDIERAN OCASIONAR, Y EN CUALQUIER CASO ES RESPONSABILIDAD DEL USUARIO EL PROBARLAS, SIENDO NECESARIO CONT
                                  RATAR CON SATINFO LA LICENCIA DE USO DE LAS MISMAS, PARA SU USO FUERA DE ZONAVIRUS.com


                                  un tout petit rectangle dans lequel est écrit ceci
                                  descargar elibagla 10.41
                                  tu cliques dessus et le fichier anti trojan (bagle) va se charger
                                  0
                                  1. Voici le chemin fournie par l'analyse Symantec
                                    C:\WINDOWS\system32\sjucvfwb.exe.ren infecté par Trojan.Skintrim
                                    C:\RECYCLER\S-1-5-21-746137067-1177238915-682003330-1003\Dc13\Backupnavi\wxkmfcqe.exe infecté par Trojan.Skintrim

                                    Pendant ce temps je continue l'analyse avec Karserpky et je te poste le rapport dés que c'est fini
                                    0
                                    • 1
                                    • 2