Neebasrjia.exe

Résolu
bonjour,
Dans mon pc, j'ai trouvé ce fichier : neebasrjia.exe, plus précisément dans system32.
Est-ce un virus? Que dois-je faire?
Merci!
Configuration: Windows XP
Firefox 1.5.0.12

28 réponses

Résumé de la discussion

Fichier neebasrjia.exe repéré dans system32 sur Windows XP soulève une suspicion de malware et la question de savoir s’il s’agit d’un virus, d’un logiciel légitime ou d’un élément manipulé. Des analyses et logs, notamment HijackThis, sont partagés pour diagnostiquer les entrées système, les processus et les extensions de navigateur susceptibles d’être associées à ce fichier. Plusieurs propositions d’outils et méthodes de nettoyage sont discutées, comme ComboFix et Silent Runners, avec des précautions et des rapports à poster pour évaluer l’étendue de l’infection et les résultats. En cas de nettoyage, une issue manuelle apparaît avec des logs de suppression et la démonstration de la suppression du fichier et de fichiers associés dans System32, puis un rapport récapitulatif.

Bobot (l’IA à votre service)
  1. Tout d'abord Bonjour et bienvenue sur le forum d'entraide COMMENT CA MARCHE

    Télécharge HijackThis ici:
    http://www.merijn.org/files/hijackthis.zip
    ou ici :
    https://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/29061.html

    Dézippe le dans un dossier prévu à cet effet.
    Par exemple C:\hijackthis < Enregistre le bien dans c : !
    Démo : (Merci a Balltrap34 pour cette réalisation)
    http://perso.orange.fr/rginformatique/section%20virus/Hijenr.gif

    Lance le puis:
    clique sur "do a system scan and save logfile" (cf démo)
    faire un copier coller du log entier sur le forum

    Démo : (Merci a Balltrap34 pour cette réalisation)

    http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm

    Bon courage
    A+
    1. merci à tous!
      première chose, voici le log de hijackthis:
      Logfile of HijackThis v1.99.1
      Scan saved at 21:49:06, on 10/08/2007
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
      C:\WINDOWS\Explorer.EXE
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
      C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
      C:\Program Files\Prevx2\PXAgent.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
      C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
      C:\Program Files\StartClock\StartClock.EXE
      C:\Program Files\MSN Messenger\msnmsgr.exe
      C:\WINDOWS\system32\slserv.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://actus.sfr.fr
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer avec Club-Internet
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.netscape.fr"); (C:\Documents and Settings\LAURENCE\Application Data\Mozilla\Profiles\default\yzx2dsbb.slt\prefs.js)
      N3 - Netscape 7: user_pref("browser.search.defaultengine", ""); (C:\Documents and Settings\LAURENCE\Application Data\Mozilla\Profiles\default\yzx2dsbb.slt\prefs.js)
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
      O2 - BHO: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
      O4 - HKLM\..\Run: [EPSON Stylus C42 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus C42 Series" /O6 "USB001" /M "Stylus C42"
      O4 - HKCU\..\Run: [StartClock] C:\Program Files\StartClock\StartClock.EXE
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
      O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?0d7e5373c3474ee38f518c4704a46d75
      O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?0d7e5373c3474ee38f518c4704a46d75
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
      O16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} (AimSp32 Class) - http://www.stylist4all.com/IE20020716/save/makeover.cab
      O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (Contrôleur de DownloadManager) - http://dlmanager.akamaitools.com.edgesuite.net/dlmanager/versions/activex/dlm-activex-2.0.6.0.cab
      O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8300.cab
      O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
      O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.inoculer.com/antivirus/Msie/bitdefender.cab
      O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
      O16 - DPF: {B79A53C0-1DAC-4636-BACE-FD086A7A79BF} (AdSignerLCContrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP.cab
      O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/4h/player.virtools.com/downloads/player/Install3.0/Installer.exe
      O16 - DPF: {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -
      O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - https://www.ea.com/ea-studios/popcap
      O16 - DPF: {E1AF091A-9F23-4059-89D7-C05EE073285D} (Canal+ Active MSWAY) - https://www.canalplus.com/canalplay/
      O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
      O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
      O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
      O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
      O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
      O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
      O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx2\PXAgent.exe" -f (file missing)
      O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe

      Pour l'analyse en ligne, c'est en cours.
      Je vous donne le résultat dès que possible.
      1. Ouf, ça se précise!
        Voici le résultat de Virus Total:
        Fichier neebasrjia.exe reçu le 2007.08.10 21:52:48 (CET)
        Situation actuelle: en cours de chargement ... mis en file d'attente en attente en cours d'analyse terminé NON TROUVE ARRETE
        Résultat: 5/32 (15.63%)
        en train de charger les informations du serveur...
        Votre fichier est dans la file d'attente, en position: 2.
        L'heure estimée de démarrage est entre 46 et 66 secondes.
        Ne fermez pas la fenêtre avant la fin de l'analyse.
        L'analyseur qui traitait votre fichier est actuellement stoppé, nous allons attendre quelques secondes pour tenter de récupérer vos résultats.
        Si vous attendez depuis plus de cinq minutes, vous devez renvoyer votre fichier.
        Votre fichier est, en ce moment, en cours d'analyse par VirusTotal,
        les résultats seront affichés au fur et à mesure de leur génération.
        Formaté Formaté
        Impression des résultats Impression des résultats
        Votre fichier a expiré ou n'existe pas.
        Le service est en ce moment, stoppé, votre fichier attend d'être analysé (position : ) depuis une durée indéfinie.

        Vous pouvez attendre une réponse du Web (re-chargement automatique) ou taper votre e-mail dans le formulaire ci-dessous et cliquer "Demande" pour que le système vous envoie une notification quand l'analyse sera terminée.
        Email:

        Antivirus Version Dernière mise à jour Résultat
        AhnLab-V3 2007.8.9.2 2007.08.10 -
        AntiVir 7.4.0.60 2007.08.10 HEUR/Malware
        Authentium 4.93.8 2007.08.10 -
        Avast 4.7.1029.0 2007.08.10 -
        AVG 7.5.0.476 2007.08.10 -
        BitDefender 7.2 2007.08.10 -
        CAT-QuickHeal 9.00 2007.08.10 (Suspicious) - DNAScan
        ClamAV 0.91 2007.08.10 -
        DrWeb 4.33 2007.08.10 -
        eSafe 7.0.15.0 2007.08.10 -
        eTrust-Vet 31.1.5048 2007.08.10 -
        Ewido 4.0 2007.08.10 -
        FileAdvisor 1 2007.08.10 -
        Fortinet 2.91.0.0 2007.08.10 -
        F-Prot 4.3.2.48 2007.08.10 W32/SecRisk-ProcessPatcher-based!Maximus
        F-Secure 6.70.13030.0 2007.08.10 -
        Ikarus T3.1.1.12 2007.08.10 -
        Kaspersky 4.0.2.24 2007.08.10 -
        McAfee 5095 2007.08.10 -
        Microsoft 1.2704 2007.08.10 -
        NOD32v2 2450 2007.08.10 -
        Norman 5.80.02 2007.08.09 -
        Panda 9.0.0.4 2007.08.10 -
        Prevx1 V2 2007.08.10 -
        Rising 19.35.42.00 2007.08.10 -
        Sophos 4.19.0 2007.08.01 -
        Sunbelt 2.2.907.0 2007.08.10 -
        Symantec 10 2007.08.10 Trojan.Skintrim
        TheHacker 6.1.7.166 2007.08.10 -
        VBA32 3.12.2.2 2007.08.10 -
        VirusBuster 4.3.26:9 2007.08.10 -
        Webwasher-Gateway 6.0.1 2007.08.10 Heuristic.Malware
        Information additionnelle
        File size: 268288 bytes
        MD5: d9bd8d5003da05101b275406062357fc
        SHA1: 214e697e6d97b7cc2dc0c8ee1160ad8e6b3dd466

        et maintenant celui de Jotti:
        A-Squared
        Found nothing
        AntiVir
        Found HEUR/Malware
        ArcaVir
        Found nothing
        Avast
        Found nothing
        AVG Antivirus
        Found nothing
        BitDefender
        Found nothing
        ClamAV
        Found nothing
        CPsecure
        Found nothing
        Dr.Web
        Found nothing
        F-Prot Antivirus
        Found nothing
        F-Secure Anti-Virus
        Found nothing
        Fortinet
        Found nothing
        Kaspersky Anti-Virus
        Found nothing
        NOD32
        Found nothing
        Norman Virus Control
        Found nothing
        Panda Antivirus
        Found nothing
        Rising Antivirus
        Found nothing
        Sophos Antivirus
        Found nothing
        VirusBuster
        Found nothing
        VBA32
        Found nothing

        A ce que je comprends, c'est un malware et, au passage, j'en ai toute une petite famille dans system32 (5 fichiers), donc que dois-je faire pour m'en débarrasser?
        Merci d'avance!
    2. Contributeur sécurité

      hello TLM

      j'ai commencé ou continuer je ne sais pas sans savoir qu'il y avait plusieurs topic
      je vous le laisse

      pc infecte
      1. Contributeur sécurité
        Ok merci Catherine !

        Clique ici:
        http://secubox.gateweb.org/mad.php

        Clique sur Parcourir et recherche neebasrjia.exe
        Message additionnel, met:

        Antivirus Version Dernière mise à jour Résultat
        AhnLab-V3 2007.8.9.2 2007.08.10 -
        AntiVir 7.4.0.60 2007.08.10 HEUR/Malware
        Authentium 4.93.8 2007.08.10 -
        Avast 4.7.1029.0 2007.08.10 -
        AVG 7.5.0.476 2007.08.10 -
        BitDefender 7.2 2007.08.10 -
        CAT-QuickHeal 9.00 2007.08.10 (Suspicious) - DNAScan
        ClamAV 0.91 2007.08.10 -
        DrWeb 4.33 2007.08.10 -
        eSafe 7.0.15.0 2007.08.10 -
        eTrust-Vet 31.1.5048 2007.08.10 -
        Ewido 4.0 2007.08.10 -
        FileAdvisor 1 2007.08.10 -
        Fortinet 2.91.0.0 2007.08.10 -
        F-Prot 4.3.2.48 2007.08.10 W32/SecRisk-ProcessPatcher-based!Maximus
        F-Secure 6.70.13030.0 2007.08.10 -
        Ikarus T3.1.1.12 2007.08.10 -
        Kaspersky 4.0.2.24 2007.08.10 -
        McAfee 5095 2007.08.10 -
        Microsoft 1.2704 2007.08.10 -
        NOD32v2 2450 2007.08.10 -
        Norman 5.80.02 2007.08.09 -
        Panda 9.0.0.4 2007.08.10 -
        Prevx1 V2 2007.08.10 -
        Rising 19.35.42.00 2007.08.10 -
        Sophos 4.19.0 2007.08.01 -
        Sunbelt 2.2.907.0 2007.08.10 -
        Symantec 10 2007.08.10 Trojan.Skintrim
        TheHacker 6.1.7.166 2007.08.10 -
        VBA32 3.12.2.2 2007.08.10 -
        VirusBuster 4.3.26:9 2007.08.10 -
        Webwasher-Gateway 6.0.1 2007.08.10 Heuristic.Malware
        Information additionnelle
        File size: 268288 bytes
        MD5: d9bd8d5003da05101b275406062357fc
        SHA1: 214e697e6d97b7cc2dc0c8ee1160ad8e6b3dd466

        Puis clique sur envoyer.

        A+
        1. ok, c'est fait.
      2. Contributeur sécurité
        Merci.

        Télécharge Combofix sUBs :
        http://download.bleepingcomputer.com/sUBs/ComboFix.exe
        et sauvegarde le sur ton bureau et pas ailleurs!

        Double-clic sur combofix, Il va te poser une question, réponds par la touche 1 et entrée pour valider.
        Attends que combofix ait terminé, un rapport sera créé. Poste le rapport.

        A+
        1. Hello!
          les manips sur mon pc sont de plus en plus difficiles, ça demande un temps fou et ça bug très souvent. Résultat, j'ai enfin pu dl combofix et le lancer. Mais voila, ça fait une heure que combofix scanne et ça n'en finit pas. Je continue?
        2. @zeldaUne précision. Voici ce qui est écrit dans l'écran bleu de combofix:

          Scanning for infected files...
          This typically doesn't take more than ten minutes
          Scan times for badly infected machines may easily double
          le système ne peut exécuter le programme spécifié

          Combofix has changed your clock settings.
          Do not change it back. it shall be restored later.
      3. Bon, pas moyen de passer combofix. j'ai arrêté le premier scan qui n'avançait pas. Et quand je veux relancer, j'ai le message "le système ne peut pas éxécuter l'application" et ça se ferme :/
        1. Contributeur sécurité
          OK.

          Télécharge ceci (clique droit sur le lien < enregistrer sous)
          https://www.silentrunners.org/Silent%20Runners.vbs
          Exécute le, attends quelques minutes, il va créer ensuite un dossier juste a coté de Silent runner sous format texte, copie/colle le rapport.

          A+
          1. Bonjour,
            Voici le contenu du fichier créé par silent runners (Startup programs):

            "Silent Runners.vbs", revision 52, https://www.silentrunners.org/
            Operating System: Windows XP SP2
            Output limited to non-default values, except where indicated by "{++}"

            Startup items buried in registry:
            ---------------------------------

            HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
            "StartClock" = "C:\Program Files\StartClock\StartClock.EXE" ["Grégory HARGOUS - www.GregLand.Net"]
            "msnmsgr" = ""C:\Program Files\MSN Messenger\msnmsgr.exe" /background" [MS]
            "ctfmon.exe" = "C:\WINDOWS\system32\ctfmon.exe" [MS]

            HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
            "AVG7_CC" = "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP" ["GRISOFT, s.r.o."]
            "EPSON Stylus C42 Series" = "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus C42 Series" /O6 "USB001" /M "Stylus C42"" ["SEIKO EPSON CORPORATION"]

            HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
            {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
            -> {HKLM...CLSID} = "AcroIEHlprObj Class"
            \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
            {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33}\(Default) = (no title provided)
            -> {HKLM...CLSID} = "VMN Toolbar"
            \InProcServer32\(Default) = "C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL" [empty string]
            {53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
            -> {HKLM...CLSID} = (no title provided)
            \InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]
            {55EA1964-F5E4-4D6A-B9B2-125B37655FCB}\(Default) = "Malicious Scripts Scanner"
            -> {HKLM...CLSID} = "URLDetector Class"
            \InProcServer32\(Default) = "C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll" ["Prevx Ltd."]
            {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)
            -> {HKLM...CLSID} = "SSVHelper Class"
            \InProcServer32\(Default) = "C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll" ["Sun Microsystems, Inc."]
            {9030D464-4C02-4ABF-8ECC-5164760863C6}\(Default) = (no title provided)
            -> {HKLM...CLSID} = "Windows Live Sign-in Helper"
            \InProcServer32\(Default) = "C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll" [MS]
            {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}\(Default) = (no title provided)
            -> {HKLM...CLSID} = "Windows Live Toolbar Helper"
            \InProcServer32\(Default) = "C:\Program Files\Windows Live Toolbar\msntb.dll" [MS]

            HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
            "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Extension icône HyperTerminal"
            -> {HKLM...CLSID} = "HyperTerminal Icon Ext"
            \InProcServer32\(Default) = "C:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."]
            "{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
            -> {HKLM...CLSID} = (no title provided)
            \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\msohev.dll" [MS]
            "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Shell Extension"
            -> {HKLM...CLSID} = "AVG7 Shell Extension Class"
            \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]
            "{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Find Extension"
            -> {HKLM...CLSID} = "AVG7 Find Extension Class"
            \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]
            "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
            -> {HKLM...CLSID} = "WinRAR"
            \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
            "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"
            -> {HKLM...CLSID} = "RealOne Player Context Menu Class"
            \InProcServer32\(Default) = "C:\Program Files\Real\RealPlayer\rpshell.dll" ["RealNetworks, Inc."]
            "{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"
            -> {HKLM...CLSID} = "Portable Media Devices Menu"
            \InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS]
            "{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D}" = "Messenger Sharing Folders"
            -> {HKLM...CLSID} = "Mes dossiers de partage"
            \InProcServer32\(Default) = "C:\Program Files\MSN Messenger\fsshext.8.1.0178.00.dll" [MS]

            HKLM\System\CurrentControlSet\Control\Session Manager\
            <<!>> "BootExecute" = "autocheck autochk *"|"lsdelete" [null data]

            HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
            AVG7 Shell Extension\(Default) = "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"
            -> {HKLM...CLSID} = "AVG7 Shell Extension Class"
            \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]
            WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
            -> {HKLM...CLSID} = "WinRAR"
            \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

            HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
            WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
            -> {HKLM...CLSID} = "WinRAR"
            \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

            HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
            AVG7 Shell Extension\(Default) = "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"
            -> {HKLM...CLSID} = "AVG7 Shell Extension Class"
            \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]
            WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
            -> {HKLM...CLSID} = "WinRAR"
            \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

            Group Policies {policy setting}:
            --------------------------------

            Note: detected settings may not have any effect.

            HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\

            "shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001
            {Shutdown: Allow system to be shut down without having to log on}

            "undockwithoutlogon" = (REG_DWORD) hex:0x00000001
            {Devices: Allow undock without having to log on}

            Active Desktop and Wallpaper:
            -----------------------------

            Active Desktop may be disabled at this entry:
            HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

            Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
            HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
            "Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Mes documents\Mes images\kikie.bmp"

            Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
            HKCU\Control Panel\Desktop\
            "Wallpaper" = "C:\Documents and Settings\LAURENCE\Mes documents\Mes images\kikie.bmp"

            Enabled Scheduled Tasks:
            ------------------------

            "Vérifier les mises à jour de Windows Live Toolbar" -> launches: "C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE" [MS]

            Winsock2 Service Provider DLLs:
            -------------------------------

            Namespace Service Providers

            HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
            000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
            000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
            000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

            Transport Service Providers

            HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
            0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
            %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 19
            %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05

            Toolbars, Explorer Bars, Extensions:
            ------------------------------------

            Toolbars

            HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\
            "{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}"
            -> {HKLM...CLSID} = "Windows Live Toolbar"
            \InProcServer32\(Default) = "C:\Program Files\Windows Live Toolbar\msntb.dll" [MS]

            HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
            "{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}"
            -> {HKLM...CLSID} = "Windows Live Toolbar"
            \InProcServer32\(Default) = "C:\Program Files\Windows Live Toolbar\msntb.dll" [MS]
            "{4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33}"
            -> {HKLM...CLSID} = "VMN Toolbar"
            \InProcServer32\(Default) = "C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL" [empty string]

            HKLM\Software\Microsoft\Internet Explorer\Toolbar\
            "{4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33}" = (no title provided)
            -> {HKLM...CLSID} = "VMN Toolbar"
            \InProcServer32\(Default) = "C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL" [empty string]
            "{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" = (no title provided)
            -> {HKLM...CLSID} = "Windows Live Toolbar"
            \InProcServer32\(Default) = "C:\Program Files\Windows Live Toolbar\msntb.dll" [MS]

            Extensions (Tools menu items, main toolbar menu buttons)

            HKLM\Software\Microsoft\Internet Explorer\Extensions\
            {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
            "MenuText" = "Console Java (Sun)"
            "CLSIDExtension" = "{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC}"
            -> {HKCU...CLSID} = "Java Plug-in 1.6.0_01"
            \InProcServer32\(Default) = "C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll" ["Sun Microsystems, Inc."]
            -> {HKLM...CLSID} = "Java Plug-in 1.6.0_01"
            \InProcServer32\(Default) = "C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll" ["Sun Microsystems, Inc."]

            {E2E2DD38-D088-4134-82B7-F2BA38496583}\
            "MenuText" = "@xpsp3res.dll,-20001"
            "Exec" = "%windir%\Network Diagnostic\xpnetdiag.exe" [MS]

            {FB5F1910-F110-11D2-BB9E-00C04F795683}\
            "ButtonText" = "Messenger"
            "MenuText" = "Windows Messenger"
            "Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]

            Running Services (Display Name, Service Name, Path {Service DLL}):
            ------------------------------------------------------------------

            Ad-Aware 2007 Service, aawservice, ""C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe"" ["Lavasoft AB"]
            AVG E-mail Scanner, AVGEMS, "C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe" ["GRISOFT, s.r.o."]
            AVG7 Alert Manager Server, Avg7Alrt, "C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe" ["GRISOFT, s.r.o."]
            AVG7 Update Service, Avg7UpdSvc, "C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe" ["GRISOFT, s.r.o."]
            EPSON Printer Status Agent2, EPSONStatusAgent2, "C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe" ["SEIKO EPSON CORPORATION"]
            Machine Debug Manager, MDM, ""C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe"" [MS]
            Prevx Agent, PREVXAgent, ""C:\Program Files\Prevx2\PXAgent.exe" -f" ["Prevx"]
            SmartLinkService, SLService, "slserv.exe" [" "]
            Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\system32\wdfmgr.exe" [MS]

            Print Monitors:
            ---------------

            HKLM\System\CurrentControlSet\Control\Print\Monitors\
            EPSON V5 2KMonitor\Driver = "EBPMON2.DLL" ["SEIKO EPSON CORPORATION"]

            ---------- (launch time: 2007-08-12 11:04:49)
            <<!>>: Suspicious data at a malware launch point.

            + This report excludes default entries except where indicated.
            + To see *everywhere* the script checks and *everything* it finds,
            launch it from a command prompt or a shortcut with the -all parameter.
            + The search for DESKTOP.INI DLL launch points on all local fixed drives
            took 287 seconds.
            ---------- (total run time: 558 seconds)
        2. Contributeur sécurité
          Salut

          Fais un clic droit sur ce lien :
          http://perso.orange.fr/il.mafioso/Navifix/Navilog1.zip
          Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
          Fais un clic droit sur navilog1.zip et choisis "tout extraire"
          Ensuite double clique sur navilog1.exe pour lancer l'installation.
          Une fois l'installation terminée, le fix s'exécutera automatiquement.
          (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

          Laisse-toi guider. Au menu principal, choisis 1 et valides.
          (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)
          Patiente jusqu'au message :
          *** Analyse Termine le ..... ***
          Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
          Copie-colle l'intégralité dans une réponse. Referme le blocnote.
          Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)
          1. ok, voici le rapport de navilog:

            Search Navipromo version 2.0.7 commencé le 12/08/2007 à 11:37:58,53

            !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
            !!! Poster ce rapport sur le forum pour le faire analyser !!!
            !!! Ne pas lancer la partie désinfection sans l'avis d'un spécialiste !!!

            Fix lancé depuis C:\Program Files\navilog1
            Mise a jour le 11.08.2007 a 18h00 by IL-MAFIOSO

            Executé en mode normal

            *** Recherche Programmes installes ***

            *** Recherche dossiers dans C:\WINDOWS ***

            *** Recherche dossiers dans C:\Program Files ***

            *** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***

            *** Recherche dossiers dans C:\Documents and Settings\LAURENCE\Application Data ***

            *** Recherche avec BlackLight Engine/F-secure ***
            BlackLight Engine est un produit de F-secure, pour + d'infos :
            https://www.f-secure.com/en

            F-SECURE BLACKLIGHT ROOTKIT ELIMINATOR
            ======================================

            Copyright 2005-2006 F-Secure Corporation. All rights reserved.
            This is a beta version. It will expire on 1st of October, 2007.
            Version information: 2.2.1064.

            [+] Started on 08/12/07 at 11:38:10.
            [+] Initializing ...
            [+] Starting scan, press Ctrl-C to abort.
            [+] Scanning for hidden items .....................................................................................................................................................................................................
            [+] Scan complete.
            [+] Summary: 0 hidden item(s) found, 0 scheduled for renaming.
            [+] Exited on 08/12/07 at 12:03:18 (return code = 0).

            *** Recherche fichiers ***

            C:\WINDOWS\pack.epk trouvé !
            C:\WINDOWS\system32\nvs2.inf trouvé !

            *** Recherche cles registre ***

            Recherche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs]

            Recherche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage]

            Recherche Clé Magic Control

            HKEY_CURRENT_USER\Software\Lanconfig trouvé !
            HKEY_USERS\S-1-5-21-2025429265-1482476501-1801674531-1004\Software\Lanconfig trouvé !

            *** Module de Recherche complémentaire ***
            (Recherche fichiers spécifiques)

            1)Recherche fichiers connus:

            2)Recherche Heuristique :
            *
            C:\WINDOWS\system32\neebasrjia.dat trouvé !
            **
            C:\WINDOWS\system32\neebasrjia.dat trouvé !
            ***
            ****
            C:\WINDOWS\system32\neebasrjia_navps.dat trouvé !
            *****
            C:\WINDOWS\system32\neebasrjia_nav.dat trouvé !
            ******
            *******
            ********

            3)Recherche Certificats :

            Certificat Egroup trouvé !

            *** Recherche avec GenericNaviSearch Beta ***
            !!! Tous Ces résultats peuvent révéler des fichiers légitimes !!!
            !!! A verifier impérativement avant toute suppression manuelle !!!

            Fichiers trouvés :

            C:\WINDOWS\system32\neebasrjia.exe trouvé !

            Fichiers suspects :

            Aucun Fichier suspect trouvé !

            *** Analyse Terminé le 12/08/2007 à 12:05:18,93 ***
        3. Contributeur sécurité
          Re,

          Double clique sur le raccourci Navilog1 présent sur le bureau et laisse-toi guider.
          Au menu principal, choisis 4 et valide.

          Le fix va te demander de saisir le nom de fichier.
          Saisies ce qui est en gras ci-dessous et rien d'autre puis valide:

          neebasrjia

          Le fix va te demander de le resaisir, fais-le et valide

          Le fix va t'informer qu'il va alors redémarrer ton PC
          Ferme toutes les fenêtres ouvertes et enregistre tes documents personnels ouverts
          Appuie sur une touche comme demandé.
          (si ton Pc ne redémarre pas automatiquement, fais le toi même)
          Au redémarrage de ton PC, choisis ta session habituelle.

          Patiente jusqu'au message :
          *** Nettoyage Termine le ..... ***
          Le blocnote va s'ouvrir.
          Sauvegarde le rapport de manière à le retrouver
          Referme le blocnote. Ton bureau va réapparaitre

          PS:Si ton bureau ne réapparait pas, fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.
          Puis rends-toi à l'onglet "processus". Cliques en haut à gauche sur fichiers et choisis "exécuter"
          Tapes explorer et valides. Celà te fera apparaitre ton bureau
          1. re, et merci de t'occuper de mon cas même un dimanche :=)

            J'ai fait ce que tu m'as dit, et tout s'est bien passé. Voici le rapport:

            Clean Navipromo version 2.0.7 commencé le 12/08/2007 à 18:14:57,10

            Fix lancé depuis C:\Program Files\navilog1
            Mise a jour le 11.08.2007 a 18h00 by IL-MAFIOSO

            Mode suppression par méthode manuelle

            Nom du fichier saisi : neebasrjia

            *** Recherche, Creation backups et suppression ***

            C:\WINDOWS\system32\neebasrjia_navup.dat absent !
            C:\WINDOWS\system32\neebasrjia_navtmp.dat absent !
            C:\WINDOWS\system32\neebasrjia_m2s.xml absent !
            C:\WINDOWS\prefetch\neebasrjia*.pf absent !

            C:\WINDOWS\System32\neebasrjia.exe trouvé !
            Copie C:\WINDOWS\system32\neebasrjia.exe réalise avec succes !
            C:\WINDOWS\system32\neebasrjia.exe supprimé !

            C:\WINDOWS\System32\neebasrjia.dat trouvé !
            Copie C:\WINDOWS\system32\neebasrjia.dat réalise avec succes !
            C:\WINDOWS\system32\neebasrjia.dat supprimé !

            C:\WINDOWS\System32\neebasrjia_nav.dat trouvé !
            Copie C:\WINDOWS\system32\neebasrjia_nav.dat réalise avec succes !
            C:\WINDOWS\system32\neebasrjia_nav.dat supprimé !

            C:\WINDOWS\System32\neebasrjia_navps.dat trouvé !
            Copie C:\WINDOWS\system32\neebasrjia_navps.dat réalise avec succes !
            C:\WINDOWS\system32\neebasrjia_navps.dat supprimé !

            *** Suppression dossiers dans C:\WINDOWS ***

            *** Suppression dossiers dans C:\Program Files ***

            *** Suppression dossiers dans C:\Documents and Settings\All Users\Application Data ***

            *** Suppression dossiers dans C:\Documents and Settings\LAURENCE\Application Data ***

            *** Suppression fichiers ***

            C:\WINDOWS\pack.epk supprimé !
            C:\WINDOWS\system32\nvs2.inf supprimé !

            *** Suppression fichiers temporaires ***

            Nettoyage contenu C:\WINDOWS\Temp effectué !
            Nettoyage contenu C:\Documents and Settings\LAURENCE\Local Settings\Temp effectué !

            *** Sauvegarde du registre vers dossier Backupnavi ***

            sauvegarde du registre réalise avec succes !

            *** Nettoyage registre ***

            Nettoyage registre Ok

            *** Traitement Recherche complémentaire ***
            (Recherche fichiers spécifiques)

            1)Recherche fichiers connus:

            2)Recherche et Suppression Heuristique :

            *
            **
            ***
            ****
            *****
            ******
            *******
            ********

            3)Contrôle présence clés Rootkit dans le registre :

            Aucune autre clés présente dans le registre !

            4)Certificats :

            Certificat Egroup supprimé !

            *** Recherche avec GenericNaviSearch Beta ***
            !!! Ces résultats peuvent révéler des fichiers légitimes !!!
            !!! A verifier impérativement avant toute suppression manuelle !!!

            Fichiers trouvés non supprimés :

            Aucun Fichier trouvé !

            Fichiers suspects non supprimés :

            Aucun Fichier suspect trouvé !

            *** Nettoyage termine le 12/08/2007 à 18:20:57,29 ***
        4. Contributeur sécurité
          Pas de probleme, ca fera 40euros, nan je plaisante lol

          Tu me remet un HijackThis?

          A+
          1. re!
            ok à vos ordres mon capitaine, rapport hijackthis:

            Logfile of HijackThis v1.99.1
            Scan saved at 19:24:31, on 12/08/2007
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.5730.0011)

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
            C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
            C:\WINDOWS\Explorer.EXE
            C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
            C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
            C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
            C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
            C:\Program Files\Prevx2\PXAgent.exe
            C:\WINDOWS\system32\slserv.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\Program Files\StartClock\StartClock.EXE
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.01net.com/telecharger/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.01net.com/telecharger/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.01net.com/telecharger/
            R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.netscape.fr"); (C:\Documents and Settings\LAURENCE\Application Data\Mozilla\Profiles\default\yzx2dsbb.slt\prefs.js)
            N3 - Netscape 7: user_pref("browser.search.defaultengine", ""); (C:\Documents and Settings\LAURENCE\Application Data\Mozilla\Profiles\default\yzx2dsbb.slt\prefs.js)
            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
            O2 - BHO: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL
            O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
            O3 - Toolbar: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL
            O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
            O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
            O4 - HKLM\..\Run: [EPSON Stylus C42 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus C42 Series" /O6 "USB001" /M "Stylus C42"
            O4 - HKCU\..\Run: [StartClock] C:\Program Files\StartClock\StartClock.EXE
            O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
            O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
            O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?0d7e5373c3474ee38f518c4704a46d75
            O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?0d7e5373c3474ee38f518c4704a46d75
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O11 - Options group: [INTERNATIONAL] International*
            O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
            O16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} (AimSp32 Class) - http://www.stylist4all.com/IE20020716/save/makeover.cab
            O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (Contrôleur de DownloadManager) - http://dlmanager.akamaitools.com.edgesuite.net/dlmanager/versions/activex/dlm-activex-2.0.6.0.cab
            O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8300.cab
            O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
            O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.inoculer.com/antivirus/Msie/bitdefender.cab
            O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
            O16 - DPF: {B79A53C0-1DAC-4636-BACE-FD086A7A79BF} (AdSignerLCContrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP.cab
            O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/4h/player.virtools.com/downloads/player/Install3.0/Installer.exe
            O16 - DPF: {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -
            O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - https://www.ea.com/ea-studios/popcap
            O16 - DPF: {E1AF091A-9F23-4059-89D7-C05EE073285D} (Canal+ Active MSWAY) - https://www.canalplus.com/canalplay/
            O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
            O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
            O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
            O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
            O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
            O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
            O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
            O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
            O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx2\PXAgent.exe" -f (file missing)
            O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
            1. Contributeur sécurité
              Salut,

              ¤Relance HijackThis, coche les cases devant ces lignes et ensuite clique sur fix checked :

              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

              Ferme HijackThis.

              Ou en sont tes soucis?

              A+
              1. j'ai un doute: fixchecked = fixer objet?
            2. Contributeur sécurité
              Oui :-)
              1. ok, visiblement tout fonctionne bien, on dirait un nouveau pc tout neuf !
                Voici le dernier rapport hijackthis:

                Logfile of HijackThis v1.99.1
                Scan saved at 21:10:39, on 12/08/2007
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v7.00 (7.00.6000.16473)

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
                C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
                C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
                C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
                C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                C:\WINDOWS\Explorer.EXE
                C:\Program Files\Prevx2\PXAgent.exe
                C:\WINDOWS\system32\slserv.exe
                C:\WINDOWS\system32\svchost.exe
                C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\Hijackthis Version Française\hijackthis vf.exe
                C:\WINDOWS\system32\NOTEPAD.EXE

                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.01net.com/telecharger/
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.01net.com/telecharger/
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.01net.com/telecharger/
                R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.netscape.fr"); (C:\Documents and Settings\LAURENCE\Application Data\Mozilla\Profiles\default\yzx2dsbb.slt\prefs.js)
                N3 - Netscape 7: user_pref("browser.search.defaultengine", ""); (C:\Documents and Settings\LAURENCE\Application Data\Mozilla\Profiles\default\yzx2dsbb.slt\prefs.js)
                O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
                O2 - BHO: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL
                O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                O3 - Toolbar: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL
                O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
                O4 - HKLM\..\Run: [EPSON Stylus C42 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus C42 Series" /O6 "USB001" /M "Stylus C42"
                O4 - HKCU\..\Run: [StartClock] C:\Program Files\StartClock\StartClock.EXE
                O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
                O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?0d7e5373c3474ee38f518c4704a46d75
                O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?0d7e5373c3474ee38f518c4704a46d75
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O11 - Options group: [INTERNATIONAL] International*
                O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
                O16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} (AimSp32 Class) - http://www.stylist4all.com/IE20020716/save/makeover.cab
                O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (Contrôleur de DownloadManager) - http://dlmanager.akamaitools.com.edgesuite.net/dlmanager/versions/activex/dlm-activex-2.0.6.0.cab
                O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8300.cab
                O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
                O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.inoculer.com/antivirus/Msie/bitdefender.cab
                O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
                O16 - DPF: {B79A53C0-1DAC-4636-BACE-FD086A7A79BF} (AdSignerLCContrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP.cab
                O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/4h/player.virtools.com/downloads/player/Install3.0/Installer.exe
                O16 - DPF: {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -
                O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - https://www.ea.com/ea-studios/popcap
                O16 - DPF: {E1AF091A-9F23-4059-89D7-C05EE073285D} (Canal+ Active MSWAY) - https://www.canalplus.com/canalplay/
                O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
                O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
                O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
                O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx2\PXAgent.exe" -f (file missing)
                O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
            3. Contributeur sécurité
              Ok !

              Tout est ok?

              A+
              1. Tout a l'air ok pour l'instant, oui.
                Gros soulagement, mon pc me sert beaucoup dans mon boulot. Comment puis-je remercier mon sauveur?
            • 1
            • 2