Infecté par BHO et autres

voila lors de la navigation sur internet, jai téléchargé messenger skinner, grosse erreur, jai plein de spywares maintenant. sur internet plein de page de pub saffiche comme casino ou de voyage ou si je lance firefox, il veut que je télécharge spyware secure ( ca va pas non!) ou alors des messages dalerte style Windows comme quoi jai été infecté et ca mest une page bleue comme sur un boot par exemple.
jai installé Ashampo antispy 2 et fait le scan et les antirotkit. ca en a enlevé un fichier nommé Fmceldcg.exe et dautres.

jai passe ad aware, spyboat, antivirus et ccleaner, jai rebooté mais ca reviens encore.
comment puis je men debarassé???
merci
Configuration: Windows XP
Firefox 2.0.0.6

14 réponses

  1. Contributeur sécurité
    Clique sur ce lien :
    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
    Clique sur navilog1.zip pour télécharger navilog1
    Choisis Enregistrer

    et enregistre-le sur ton bureau.

    Ensuite double clique sur navilog1.exe pour lancer l'installation.
    Une fois l'installation terminée, le fix s'exécutera automatiquement.
    (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

    Laisse-toi guider. Au menu principal, choisis 1 et valides.
    (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

    Patiente jusqu'au message :
    *** Analyse Termine le ..... ***
    Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
    Copie-colle l'intégralité dans une réponse. Referme le blocnote.
    Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)
    0
    1. Search Navipromo version 3.1.0 commencé le 21.09.2007 à 17:53:14.59

      !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
      !!! Poster ce rapport sur le forum pour le faire analyser !!!
      !!! Ne pas lancer la partie désinfection sans l'avis d'un spécialiste !!!

      Fix lancé depuis C:\Program Files\navilog1
      Mise a jour le 20.09.2007 a 14h00 by IL-MAFIOSO

      Microsoft Windows XP [version 5.1.2600]
      Internet Explorer : 7.0.5730.11

      *** Recherche Programmes installes ***

      *** Recherche dossiers dans C:\WINDOWS ***

      *** Recherche dossiers dans C:\Program Files ***

      *** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***

      *** Recherche dossiers dans C:\Documents and Settings\Gerard\Application Data ***

      ...\Application Data\MessengerSkinner trouvé !

      *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDÉ~1\PROGRA~1 ***

      *** Recherche avec BlackLight Engine/F-secure ***
      BlackLight Engine est un produit de F-secure, pour + d'infos :
      https://www.f-secure.com/en

      Fichier(s) caché(s) :

      C:\Documents and Settings\Gerard\local settings\application data\fmeeldcaba.exe

      Processus caché(s) :

      C:\Documents and Settings\Gerard\local settings\application data\fmeeldcaba.exe

      *** Recherche avec GenericNaviSearch ***
      !!! Tous Ces résultats peuvent révéler des fichiers légitimes !!!
      !!! A verifier impérativement avant toute suppression manuelle !!!

      * Scan C:\WINDOWS\system32 *

      Fichiers trouvés :

      bepgbeamza.exe trouvé !

      * Scan C:\Documents and Settings\Gerard\local settings\application data *

      Fichiers trouvés :

      fmeeldcaba.exe trouvé !

      *** Recherche fichiers ***

      C:\WINDOWS\system32\nvs2.inf trouvé !

      *** Recherche cles registre ***

      HKEY_CURRENT_USER\Software\Lanconfig trouvé !

      *** Module de Recherche complémentaire ***
      (Recherche fichiers spécifiques)

      1)Recherche fichiers connus:

      2)Recherche Heuristique :

      C:\Documents and Settings\Gerard\local settings\application data\fmeeldcaba.dat trouvé !

      3)Recherche Certificats :

      Certificat Egroup trouvé !

      *** Analyse Terminé le 21.09.2007 à 17:59:38.00 ***
      0
      1. Contributeur sécurité
        Double clique sur le raccourci Navilog1 présent sur le bureau et laisse-toi guider.
        Au menu principal, choisis 2 et valide.

        Le fix va t'informer qu'il va alors redémarrer ton PC
        Ferme toutes les fenêtres ouvertes et enregistre tes documents personnels ouverts
        Appuie sur une touche comme demandé.
        (si ton Pc ne redémarre pas automatiquement, fais le toi même)
        Au redémarrage de ton PC, choisis ta session habituelle.

        Patiente jusqu'au message :
        *** Nettoyage Termine le ..... ***
        Le blocnote va s'ouvrir.
        Sauvegarde le rapport de manière à le retrouver
        Referme le blocnote. Ton bureau va réapparaitre

        PS:Si ton bureau ne réapparait pas, fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.
        Puis rends-toi à l'onglet "processus". Clique en haut à gauche sur fichiers et choisis "exécuter"
        Tape explorer et valide. Celà te fera apparaitre ton bureau.
        poste le rapport obtenu et un rapport hijack this
        0
        1. Clean Navipromo version 3.1.0 commencé le 21.09.2007 à 18:07:42.85

          Fix lancé depuis C:\Program Files\navilog1
          Mise a jour le 20.09.2007 a 14h00 by IL-MAFIOSO

          Microsoft Windows XP [version 5.1.2600]
          Internet Explorer : 7.0.5730.11

          Mode suppression automatique

          *** Creation backups fichiers trouvés par Blacklight ***

          Copie vers "C:\Program Files\navilog1\Backupnavi"

          *** Suppression des fichiers trouvés avec Blacklight ***

          C:\Documents and Settings\Gerard\local settings\application data\fmeeldcaba.exe !!ERREUR SUPPRESSION!!

          ** 2ème passage **

          C:\WINDOWS\prefetch\fmeeldcaba*.pf trouvé !
          Copie C:\WINDOWS\prefetch\fmeeldcaba*.pf réalise avec succes !
          C:\WINDOWS\prefetch\fmeeldcaba*.pf supprimé !

          C:\Documents and Settings\Gerard\local settings\application data\fmeeldcaba.dat trouvé !
          Copie C:\Documents and Settings\Gerard\local settings\application data\fmeeldcaba.dat réalise avec succes !
          C:\Documents and Settings\Gerard\local settings\application data\fmeeldcaba.dat supprimé !

          C:\Documents and Settings\Gerard\local settings\application data\fmeeldcaba_nav.dat trouvé !
          Copie C:\Documents and Settings\Gerard\local settings\application data\fmeeldcaba_nav.dat réalise avec succes !
          C:\Documents and Settings\Gerard\local settings\application data\fmeeldcaba_nav.dat supprimé !

          C:\Documents and Settings\Gerard\local settings\application data\fmeeldcaba_navps.dat trouvé !
          Copie C:\Documents and Settings\Gerard\local settings\application data\fmeeldcaba_navps.dat réalise avec succes !
          C:\Documents and Settings\Gerard\local settings\application data\fmeeldcaba_navps.dat supprimé !

          C:\Documents and Settings\Gerard\local settings\application data\fmeeldcaba.exe trouvé !
          Copie C:\Documents and Settings\Gerard\local settings\application data\fmeeldcaba.exe réalise avec succes !
          C:\Documents and Settings\Gerard\local settings\application data\fmeeldcaba.exe supprimé !

          *** Suppression avec Backups résultats GenericNaviSearch ***

          * Scan C:\WINDOWS\system32 *

          bepgbeamza.exe trouvé !
          Copie bepgbeamza.exe réalise avec succes !
          bepgbeamza.exe supprimé !

          * Scan C:\Documents and Settings\Gerard\local settings\application data *

          *** Suppression dossiers dans C:\WINDOWS ***

          *** Suppression dossiers dans C:\Program Files ***

          *** Suppression dossiers dans C:\Documents and Settings\All Users\Application Data ***

          *** Suppression dossiers dans C:\Documents and Settings\Gerard\Application Data ***

          ...\Application Data\MessengerSkinner ...suppression...
          ...\Application Data\MessengerSkinner supprimé !

          *** Suppression dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDÉ~1\PROGRA~1 ***

          *** Suppression fichiers ***

          C:\WINDOWS\system32\nvs2.inf supprimé !

          *** Suppression fichiers temporaires ***

          Nettoyage contenu C:\WINDOWS\Temp effectué !
          Nettoyage contenu C:\Documents and Settings\Gerard\Local Settings\Temp effectué !

          *** Traitement Recherche complémentaire ***
          (Recherche fichiers spécifiques)

          1)Recherche fichiers connus:

          2)Recherche et Suppression Heuristique :

          *** Sauvegarde du registre vers dossier Backupnavi ***

          sauvegarde du registre réalise avec succes !

          *** Nettoyage registre ***

          Nettoyage registre Ok

          *** Certificats ***

          Certificat Egroup supprimé !

          *** Nettoyage termine le 21.09.2007 à 18:12:03.65 ***

          et le rapport hijackthis

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 18:15:38, on 21.09.2007
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16512)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\csrss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\WINDOWS\system32\spoolsv.exe
          c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
          C:\Program Files\Ashampoo\Ashampoo AntiSpyWare 2\AntiSpyWareService.exe
          C:\WINDOWS\eHome\ehRecvr.exe
          C:\WINDOWS\eHome\ehSched.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
          C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
          C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
          C:\WINDOWS\system32\oodag.exe
          C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
          C:\Program Files\CyberLink\Shared Files\RichVideo.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
          C:\WINDOWS\system32\SatSrv.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\DRIVERS\WtSrv.exe
          C:\Program Files\UltraVNC\WinVNC.exe
          C:\WINDOWS\ehome\mcrdsvc.exe
          c:\program files\pinnacle\shared files\programs\mediaserver\pmshost.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\WINDOWS\system32\wbem\wmiprvse.exe
          C:\WINDOWS\system32\dllhost.exe
          C:\WINDOWS\System32\alg.exe
          C:\WINDOWS\NOTEPAD.EXE
          C:\WINDOWS\system32\wuauclt.exe
          C:\Program Files\Unlocker\UnlockerAssistant.exe
          C:\WINDOWS\system32\LVCOMSX.EXE
          C:\Program Files\Steganos Security Suite 2007\SteganosHotKeyService.exe
          C:\Program Files\Steganos Security Suite 2007\fredirstarter.exe
          C:\Program Files\QuickTime\qttask.exe
          C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
          C:\program files\topthemesxp\txp.exe
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\Program Files\Logitech\Video\CameraAssistant.exe
          C:\WINDOWS\system32\ElkCtrl.exe
          C:\Program Files\Ashampoo\Ashampoo AntiSpyWare 2\AntiSpyWare2Guard.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\tunebite\tunebite.exe
          C:\Program Files\MSN Messenger\MsnMsgr.Exe
          C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
          C:\Program Files\Digital Line Detect\DLG.exe
          C:\Program Files\WinZip\WZQKPICK.EXE
          C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
          C:\WINDOWS\system32\wbem\wmiprvse.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com/spresults.aspx
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/spresults.aspx
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.bing.com/spresults.aspx
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
          R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.dell.com/fr-ch?c=ch&l=fr&s=gen&redirect=1
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer fourni par Yahoo! France
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
          O2 - BHO: GigagetIEHelper Class - {111CAA23-6F4F-42AC-8555-B48C1D87BBAB} - C:\WINDOWS\system32\gigagetbho_v10.dll
          O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
          O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
          O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
          O4 - HKLM\..\Run: [SSS2007 HotKeys] "C:\Program Files\Steganos Security Suite 2007\SteganosHotKeyService.exe"
          O4 - HKLM\..\Run: [SSS2007 File Redirection Starter] "C:\Program Files\Steganos Security Suite 2007\fredirstarter.exe"
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
          O4 - HKLM\..\Run: [TXP] c:\program files\topthemesxp\txp.exe
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
          O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Logitech\Video\CameraAssistant.exe
          O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect
          O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
          O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\UltraVNC\WinVNC.exe" -servicehelper
          O4 - HKLM\..\Run: [AntiSpyWare2Guard] C:\Program Files\Ashampoo\Ashampoo AntiSpyWare 2\AntiSpyWare2Guard.exe
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [PreAnnotate] C:\WINDOWS\system32\PreAnntt.exe
          O4 - HKCU\..\Run: [tunebite.exe] C:\Program Files\tunebite\tunebite.exe -hidden
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
          O4 - Startup: Outil de détection de support Picture Motion Browser.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
          O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
          O4 - Global Startup: Digital Line Detect.lnk = ?
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
          O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
          O8 - Extra context menu item: &Download All by Gigaget - C:\Program Files\Giganology\Gigaget\getallurl.htm
          O8 - Extra context menu item: &Download by Gigaget - C:\Program Files\Giganology\Gigaget\geturl.htm
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://D:\MICROS~1\OFFICE11\EXCEL.EXE/3000
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\MICROS~1\OFFICE11\REFIEBAR.DLL
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - http://a532.g.akamai.net/...
          O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.1.6.cab
          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
          O23 - Service: Ashampoo AntiSpyWare 2 Service (AASW2_Service) - Unknown owner - C:\Program Files\Ashampoo\Ashampoo AntiSpyWare 2\AntiSpyWareService.exe
          O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
          O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
          O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
          O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
          O23 - Service: Pinnacle Systems Media Service (PinnacleSys.MediaServer) - Pinnacle Systems - c:\program files\pinnacle\shared files\programs\mediaserver\pmshost.exe
          O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
          O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
          O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
          O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
          O23 - Service: Steganos AntiTheft - Unknown owner - C:\WINDOWS\system32\\SatSrv.exe
          O23 - Service: WinTab Service (WinTabService) - Unknown owner - C:\WINDOWS\system32\DRIVERS\WtSrv.exe
          O23 - Service: VNC Server (winvnc) - www.ultravnc.fr - C:\Program Files\UltraVNC\WinVNC.exe
          O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - www.ultravnc.fr - (no file)
          O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
          0
          1. Contributeur sécurité
            elle a XP ou Vista?
            0
            1. elle a xp aussi xp sp2 media center

              si tu veux apres elle te contact?
              0
              1. Contributeur sécurité
                après toi, on continuera avec elle
                SweetIM pas très pas très!!! supprime par ajout suppression de programmes tout ce qui porte ce nom!!

                lance hijack pour un scan et coche les lignes suivantes si encore présentes
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com/spresults.aspx
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/spresults.aspx
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
                R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.bing.com/spresults.aspx
                O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - http://a532.g.akamai.net/.
                O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.1.6.cab
                ferme toutes tes fenêtres y compris internet et clique sur fixer l'objet

                faire un scan antivirus en ligne avec internet explorer et accepter l'activex
                poster le rapport ici ensuite
                https://www.bitdefender.fr/

                En bas, à gauche de la fenêtre, clique sur BitDefender SCAN ONLINE
                Dans la nouvelle fenêtre, clique sur I agree
                La fenêtre change encore, clique sur Click here to scan
                Les signatures se chargent, etc.

                tuto en image
                http://pageperso.aol.fr/rginformatique/mapage/defender.htm
                0
                1. ok bien enlevé tout ce qui etait coché, mais jarrive pas avec lantivirus on line, jen ai essayé plusieurs mais a chaque fois pour le control active x , il me demande de me deconnecter, alors impossible de scanner..
                  sinon je sais pas ce que sait SweetIM, jai rien trouvé
                  je reessaye le scan, on verra bien....
                  0
                  1. ah non javais pas compris ; je scan avec bit defender : excuse:::::
                    0
                    1. Contributeur sécurité
                      ok j'attends ton rapport de scan en lignes dès qu'il est fini lol!!!
                      0
                      1. voila le rapport mais en format .txt, fallait pas????

                        <HTML>
                        <HEAD>
                        <TITLE>BitDefender Online Scanner - Rapport d'analyse</TITLE>
                        <META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
                        </HEAD>
                        <BODY BGCOLOR=#FFFFFF leftmargin="10" marginwidth="0" topmargin="20" marginheight="0" >

                        <table align="center" border="0" cellpadding="0" cellspacing="0" width="90%">
                        <tr>
                        <td width="458">
                        <p><font face="Arial" color=red><span style="font-size:14pt;"><b>BitDefender Online Scanner</b></span></font></p>
                        </td>
                        <td width="40%">
                        <p> </p>
                        </td>
                        <td width="10%">
                        <p> </p>
                        </td>
                        </tr>
                        <tr>
                        <td colspan="3" width="912">
                        <p><font face="Arial"><span style="font-size:11pt;"><B>Rapport d'analyse généré à: Fri, Sep 21, 2007 - 19:49:48</b></span></font></p>
                        </td>
                        </tr>

                        <tr>
                        <td width="458">
                        <p><font face="Arial"><span style="font-size:11pt;"><B> </b></span></font></p>
                        </td>
                        <td width="40%">
                        <p> </p>
                        </td>
                        <td width="10%">
                        <p> </p>
                        </td>
                        </tr>

                        <tr>
                        <td width="458">
                        <p><font face="Arial"><span style="font-size:11pt;"><B>Voie d'analyse: </b></span><span style="font-size:10pt;">C:\Config.Msi;C:\Documents and Settings;C:\Program Files;C:\TDdownload;C:\WINDOWS;</span></font></p>
                        </td>
                        <td width="40%">
                        <p> </p>
                        </td>
                        <td width="10%">
                        <p> </p>
                        </td>
                        </tr>

                        <tr>
                        <td width="458">
                        <p><font face="Arial"><span style="font-size:11pt;"><B> </b></span></font></p>
                        </td>
                        <td width="40%">
                        <p> </p>
                        </td>
                        <td width="10%">
                        <p> </p>
                        </td>
                        </tr>

                        <tr>
                        <td width="458">
                        <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
                        <tr>
                        <td width="451" colspan="2" bgcolor="#CCCCCC">
                        <p><font face="Arial" size="2"><B>Statistiques</b></font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Temps</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">00:27:22</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Fichiers</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">192209</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Directoires</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">7406</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Secteurs de boot</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">5</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Archives</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">1602</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Paquets programmes</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">13155</font></p>
                        </td>
                        </tr>
                        </table>
                        </td>
                        <td width="40%">
                        <p> </p>
                        </td>
                        <td width="10%">
                        <p> </p>
                        </td>
                        </tr>

                        <tr>
                        <td width="458">
                        <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
                        <tr>
                        <td width="451" colspan="2" bgcolor="#CCCCCC">
                        <p><font face="Arial" size="2"><B>Résultats</b></font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Virus identifiés</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">1</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Fichiers infectés</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">1</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Fichiers suspects</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">0</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Avertissements</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">0</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Désinfectés</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">0</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Fichiers effacés</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">1</font></p>
                        </td>
                        </tr>
                        </table>
                        </td>
                        <td width="40%">
                        <p> </p>
                        </td>
                        <td width="10%">
                        <p> </p>
                        </td>
                        </tr>

                        <tr>
                        <td width="458">
                        <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
                        <tr>
                        <td width="451" colspan="2" bgcolor="#CCCCCC">
                        <p><font face="Arial" size="2"><B>Info sur les moteurs</b></font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Définition virus</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">822859</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Version des moteurs</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">AVCORE v1.0 (build 2411) (i386) (Jul 9 2007 12:10:22)</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Analyse des plugins</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">14</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Archive des plugins</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">38</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Unpack des plugins</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">7</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">E-mail plugins</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">6</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Système plugins</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">1</font></p>
                        </td>
                        </tr>
                        </table>
                        </td>
                        <td width="40%">
                        <p> </p>
                        </td>
                        <td width="10%">
                        <p> </p>
                        </td>
                        </tr>

                        <tr>
                        <td width="458">
                        <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
                        <tr>
                        <td width="451" colspan="2" bgcolor="#CCCCCC">
                        <p><font face="Arial" size="2"><B>Paramètres d'analyse</b></font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Première action</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">Désinfecté</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Seconde Action</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">Supprimé</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Heuristique</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">Oui</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Acceptez les avertissements</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">Oui</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Extensions analysées</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">*;</font></p>
                        </td>
                        </tr>

                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Excludez les extensions</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2"> </font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Analyse d'emails</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">Oui</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Analyse des Archives</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">Oui</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Analyser paquets programmes</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">Oui</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Analyse des fichiers</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">Oui</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Analyse de boot</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">Oui</font></p>
                        </td>
                        </tr>
                        </table>
                        </td>
                        <td width="40%">
                        <p> </p>
                        </td>
                        <td width="10%">
                        <p> </p>
                        </td>
                        </tr>

                        <tr>
                        <td colspan=2>  
                        <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
                        <tr>
                        <td width="252" bgcolor="#CCCCCC">
                        <p><font face="Arial" size="2"><B>Fichier analysé</b></font></p>
                        </td>
                        <td width="195" bgcolor="#CCCCCC" align="right">
                        <p align="left"><b><font size="2" face="Arial"> Statut</font></b></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">C:\Program Files\TopThemesXP\TopThemesXp_keymaker_LaZzy_tPORt.exe</font></p>
                        </td>
                        <td width="43%" align="left">
                        <p><font face="Arial" size="2">Infecté par: Trojan.Downloader.Zlob.BKE</font></p>
                        </td>
                        </tr><tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">C:\Program Files\TopThemesXP\TopThemesXp_keymaker_LaZzy_tPORt.exe</font></p>
                        </td>
                        <td width="43%" align="left">
                        <p><font face="Arial" size="2">Echec de la désinfection</font></p>
                        </td>
                        </tr><tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">C:\Program Files\TopThemesXP\TopThemesXp_keymaker_LaZzy_tPORt.exe</font></p>
                        </td>
                        <td width="43%" align="left">
                        <p><font face="Arial" size="2">Supprimé</font></p>
                        </td>
                        </tr>
                        </table>
                        </td>

                        <td width="10%">
                        <p> </p>
                        </td>
                        </tr>

                        <tr>
                        <td width="458">
                        <p><font face="Arial"><span style="font-size:11pt;"><B> </b></span></font></p>
                        </td>
                        <td width="40%">
                        <p> </p>
                        </td>
                        <td width="10%">
                        <p> </p>
                        </td>
                        </tr>

                        <tr>
                        <td width="458">
                        <p><font face="Arial"><span style="font-size:11pt;"><B> </b></span></font></p>
                        </td>
                        <td width="40%">
                        <p> </p>
                        </td>
                        <td width="10%">
                        <p> </p>
                        </td>
                        </tr>

                        </table>
                        <p> </p>

                        </body>
                        </html>ila

                        sinon ya ca aussi

                        BitDefender Online Scanner - Rapport virus en temps réel

                        Généré à: Fri, Sep 21, 2007 - 19:51:35

                        --------------------------------------------------------------------------------

                        Info d'analyse

                        Fichiers scannés
                        199654

                        Infectés Fichiers
                        1

                        Virus Détectés

                        Trojan.Downloader.Zlob.BKE
                        1

                        --------------------------------------------------------------------------------

                        Ce sommaire du processus d'analyse sera utilisé par les laboratoires Antivirus BitDefender pour créer des statistiques agréguées sur l'activité des virus dans le monde.
                        0
                        1. Contributeur sécurité
                          si tout va bien supprime tout ce qu'on a utilisé car ce ne sera plus utile désormais
                          conserve néanmoins ccleaner
                          https://www.pcastuces.com/logitheque/ccleaner.htm
                          Télécharge : - CCleaner
                          https://www.pcastuces.com/logitheque/ccleaner.htm
                          Ce logiciel va permettre de supprimer tous les fichiers temporaires. Avant de cliquer sur le bouton "installer", décoche toutes les "options supplémentaires". Ensuite, Clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures". Par la suite, laisse-le avec ses réglages par défaut. C'est tout.
                          Un tuto
                          http://perso.orange.fr/jesses/Docs/Logiciels/CCleaner.htm
                          et effectue le nettoyage tous les jours avant de couper le PC

                          installe ce logiciel très utile et scanne ton PC avec une fois par semaine au moins...
                          AVG Antispyware
                          https://www.avg.com/en-ww/free-antivirus-download

                          mode d'utilisation :
                          Lance AVG Anti-Spyware, mets le à jour,
                          Clique sur le bouton « Analyse »
                          Puis « Comment réagir », clique sur Actions recommandées. Sélectionne Quarantaine.
                          Retour à l'onglet Analyse.
                          Clique sur Analyse complète du système.
                          A la fin du scan, choisis " Appliquer toutes les actions "
                          Clique sur "Enregistrer le rapport". Le fichier texte se trouve dans le dossier Reports du dossier d'AVG Anti-Spyware.

                          tu peux le coupler avec celui-ci
                          spybot search and destroy
                          https://www.safer-networking.org/?page=download

                          défragmente

                          pense à bien te protéger, j'ai découvert ce lien qui est plutôt pas mal à ce sujet

                          https://forum.pcastuces.com/default.asp

                          désactive ta restauration
                          clique droit sur poste de travail/propriétés/coche la case désactiver la restauration, appliquer
                          redémarre ton PC
                          clique droit sur poste de travail/propriétés/décoche la case désactiver la restauration, appliquer

                          la sécurité c'est très important mais ne remplace pas l'internaute, un surf prudent en évitant le crack, les sites "chauds", permet déjà d'éviter bien des soucis, le P2P lui aussi est source d'infections...

                          et bon surf
                          0
                          1. ok ok, je vais faire tout ca, encore un grand merci pour ton aide.
                            tiens ma copine qui a le meme probleme, cest nanette05, elle vient de mettre son message.
                            Bonne soirée et je vais suivre tes conseils
                            0
                            1. oui, tu dois trouver ca bizard mais nanette est a la maison, et on etait sur son pc dou le message envoyé avec son pc??!!
                              sinon donc si tu ne lis pas lautre, encore un grand merci pour ton aide et je vais suivre tes conseils avisés pour le surf
                              bye
                              0