DefenseNetsurfage et Protection conue

Bonjour,
Ce matin en allumant mon ordinateur j'ai remarqu頱ue le fond d'飲an avait chang頢your privacy is in danger" et il y avait des fenetres qui s'affich饳 me damandant de t鬩charger DefenseNetsurfage ou Protection conue. j'ai norton antivirus pourtant !!!!Donc j'ai cherch頳ur internet defenseNetsurfage et je suis tomb頳ur votre site ou j'ai trouv頵ne personne qui avait eu le mꭥ probl譥 que moi donc j'ai suivi les 鴡pes :
j'ai t鬩charg頳mitfraudfix en suivant les instructions Dieu merci en red魡rrant le fond d'飲an"your privacy is in danger" avait disparu
ensuite j'ai t鬩chargé ¨ttp://www.bitdefender.com/scan8/ie.html est j'ai encore des fichiers infecté³
Et le problè­¥ a recommencé ¬es fenetres DefenseNetsurfage et Protection conue apparaisent toujours que dois-je faire pour supprimer le problè­¥ mê­¥ en analysant le systè­¥ avec norton et en supprimant les virus.
Merci pour les solutions que vous pouvez apporté   mon problè­¥ !!!!
Configuration: Windows XP
Internet Explorer 6.0

54 réponses

Résumé de la discussion

Des messages d'alerte affichant 'your privacy is in danger' conduisent à des téléchargements de DefenseNetsurfage et Protection conue, malgré la présence d'un antivirus Norton. Des solutions proposées incluent des analyses par AVG Anti-Spyware et l'examen des rapports pour identifier les éléments malveillants, notamment des cookies et des fichiers détectés. D'autres préconisent l'usage d'HijackThis et d'OTMoveIt pour cibler des entrées de démarrage et des DLL suspectes. En cas de ce type d'infection, les participants insistent sur l'échange de rapports et sur des procédures de nettoyage ciblées impliquant des outils spécialisés.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    colle les rapports
    on verra
    1
    1. AVG Anti-Spyware - Rapport d'analyse
      ---------------------------------------------------------

      + Créé à: 23:32:48 24/10/2007

      + Résultat de l'analyse:

      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@247realmedia[1].txt -> TrackingCookie.247realmedia : Aucune action entreprise.
      :mozilla.108:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.2o7 : Aucune action entreprise.
      :mozilla.141:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.2o7 : Aucune action entreprise.
      C:\Documents and Settings\KAOUTAR\Cookies\kaoutar@2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@brightcove.112.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@cupolaventures.112.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@heavycom.122.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@karavel.112.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@adbrite[2].txt -> TrackingCookie.Adbrite : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@ads.adbrite[1].txt -> TrackingCookie.Adbrite : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@ads.addynamix[1].txt -> TrackingCookie.Addynamix : Aucune action entreprise.
      :mozilla.146:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.Adrevolver : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@adrevolver[3].txt -> TrackingCookie.Adrevolver : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@media.adrevolver[2].txt -> TrackingCookie.Adrevolver : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@adtech[1].txt -> TrackingCookie.Adtech : Aucune action entreprise.
      :mozilla.117:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.Advertising : Aucune action entreprise.
      :mozilla.118:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.Advertising : Aucune action entreprise.
      :mozilla.119:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.Advertising : Aucune action entreprise.
      :mozilla.120:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.Advertising : Aucune action entreprise.
      C:\Documents and Settings\KAOUTAR\Cookies\kaoutar@advertising[2].txt -> TrackingCookie.Advertising : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@advertising[1].txt -> TrackingCookie.Advertising : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@atdmt[2].txt -> TrackingCookie.Atdmt : Aucune action entreprise.
      :mozilla.52:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@bluestreak[1].txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@www.burstnet[2].txt -> TrackingCookie.Burstnet : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@ad1.clickhype[1].txt -> TrackingCookie.Clickhype : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@fl01.ct2.comclick[2].txt -> TrackingCookie.Comclick : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@dealtime[1].txt -> TrackingCookie.Dealtime : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@stat.dealtime[1].txt -> TrackingCookie.Dealtime : Aucune action entreprise.
      :mozilla.44:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.Doubleclick : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@doubleclick[2].txt -> TrackingCookie.Doubleclick : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@enhance[2].txt -> TrackingCookie.Enhance : Aucune action entreprise.
      :mozilla.21:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.Estat : Aucune action entreprise.
      C:\Documents and Settings\KAOUTAR\Cookies\kaoutar@estat[1].txt -> TrackingCookie.Estat : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@estat[1].txt -> TrackingCookie.Estat : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@fastclick[1].txt -> TrackingCookie.Fastclick : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@findwhat[1].txt -> TrackingCookie.Findwhat : Aucune action entreprise.
      :mozilla.25:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.Googleadservices : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@ehg-globalgamingleague.hitbox[2].txt -> TrackingCookie.Hitbox : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@ehg-veohnetworksinc.hitbox[1].txt -> TrackingCookie.Hitbox : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@hitbox[2].txt -> TrackingCookie.Hitbox : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@counter.hitslink[1].txt -> TrackingCookie.Hitslink : Aucune action entreprise.
      :mozilla.50:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.Imrworldwide : Aucune action entreprise.
      :mozilla.51:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.Imrworldwide : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@server.lon.liveperson[1].txt -> TrackingCookie.Liveperson : Aucune action entreprise.
      :mozilla.28:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.Mediaplex : Aucune action entreprise.
      C:\Documents and Settings\KAOUTAR\Cookies\kaoutar@mediaplex[1].txt -> TrackingCookie.Mediaplex : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@mediaplex[1].txt -> TrackingCookie.Mediaplex : Aucune action entreprise.
      C:\Documents and Settings\KAOUTAR\Cookies\kaoutar@ssl-hints.netflame[2].txt -> TrackingCookie.Netflame : Aucune action entreprise.
      :mozilla.31:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.Overture : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@overture[2].txt -> TrackingCookie.Overture : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@questionmarket[1].txt -> TrackingCookie.Questionmarket : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@revsci[2].txt -> TrackingCookie.Revsci : Aucune action entreprise.
      :mozilla.33:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
      :mozilla.34:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
      :mozilla.35:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
      :mozilla.36:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
      :mozilla.37:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
      :mozilla.42:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@bs.serving-sys[2].txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@serving-sys[1].txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
      :mozilla.38:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
      :mozilla.39:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
      :mozilla.40:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
      :mozilla.41:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
      C:\Documents and Settings\KAOUTAR\Cookies\kaoutar@smartadserver[2].txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@smartadserver[2].txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
      :mozilla.113:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.Statcounter : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@statcounter[1].txt -> TrackingCookie.Statcounter : Aucune action entreprise.
      :mozilla.147:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.Tradedoubler : Aucune action entreprise.
      :mozilla.148:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.Tradedoubler : Aucune action entreprise.
      :mozilla.149:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.Tradedoubler : Aucune action entreprise.
      :mozilla.150:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.Tradedoubler : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : Aucune action entreprise.
      :mozilla.11:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.Weborama : Aucune action entreprise.
      :mozilla.12:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.Weborama : Aucune action entreprise.
      :mozilla.13:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.Weborama : Aucune action entreprise.
      :mozilla.14:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.Weborama : Aucune action entreprise.
      C:\Documents and Settings\KAOUTAR\Cookies\kaoutar@weborama[2].txt -> TrackingCookie.Weborama : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@weborama[1].txt -> TrackingCookie.Weborama : Aucune action entreprise.
      :mozilla.76:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.Webtrends : Aucune action entreprise.
      :mozilla.77:C:\Documents and Settings\MOSTAFA\Application Data\Mozilla\Firefox\Profiles\3zwvl82s.default\cookies.txt -> TrackingCookie.Webtrends : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@m.webtrends[2].txt -> TrackingCookie.Webtrends : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@yadro[2].txt -> TrackingCookie.Yadro : Aucune action entreprise.
      C:\Documents and Settings\MOSTAFA\Cookies\mostafa@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Aucune action entreprise.

      Fin du rapport
      1
      1. Contributeur sécurité
        colle un rapport hijackthis

        http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download

        manuel :

        https://leblogdeclaude.blogspot.com/2006/10/informatique-section-hijackthis.html

        Je conseille de renomer Hijackthis, pour contrer une éventuelle infection de Vundo.

        ex:Renomme le fichier HijackThis.exe en eden.exe pour cela, fais un clic droit sur le fichier HijackThis.exe et choisis renommer dans la liste

        Ensuite avec Explorer créer un dossier c:\hijackthis
        Décompresser Hijackthis dans ce dossier.
        C'est important pour les sauvegardes."

        _______________________

        lance rogue remover

        pour telecharger :
        https://www.01net.com/telecharger/

        _______________________

        smit fraud fix (colle le rapport)

        1/ telecharger :

        http://siri.urz.free.fr/Fix/SmitfraudFix.php

        2/ double clique sur smitfraudfix. puis sélectionne 1 et appuyer sur entrée afin de créer le rapport des infection présentes. une fois le rapport effectué redémarre en mode sans échec (en appuyant sur F8 ou suppr, ou F5 au démarrage en général)

        3/ puis refaire comme en 2/ mais sélectionne l'option 2 et appuyer sur entrée pour commencer la désinfection. lorsque le programme demande si tu veut nettoyer le registre mets oui en tapant 0 et entrée

        colle le rapport d'un scan en ligne
        avec un des suivants:

        bitdefender en ligne :
        http://www.bitdefender.fr/scan_fr/scan8/ie.html

        Panda en ligne :
        http://pandasoftware.fr

        secuser en ligne :
        http://www.secuser.com/outils/antivirus.htm
        0
        1. Logfile of HijackThis v1.99.1
          Scan saved at 18:02:14, on 24/10/2007
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
          C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
          C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
          C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
          C:\WINDOWS\eHome\ehRecvr.exe
          C:\WINDOWS\eHome\ehSched.exe
          c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
          C:\Program Files\Norton AntiVirus\navapsvc.exe
          C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
          C:\WINDOWS\system32\nvsvc32.exe
          C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
          C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
          C:\WINDOWS\system32\SearchIndexer.exe
          C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
          C:\WINDOWS\system32\dllhost.exe
          C:\WINDOWS\ehome\ehtray.exe
          C:\WINDOWS\eHome\ehmsas.exe
          C:\WINDOWS\RTHDCPL.EXE
          C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
          C:\WINDOWS\system32\RUNDLL32.EXE
          C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
          C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
          C:\WINDOWS\system32\SysMonitor.exe
          C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
          C:\Program Files\BroadJump\Client Foundation\CFD.exe
          C:\PROGRA~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe
          C:\Program Files\Windows Live\Contrôle parental\fssui.exe
          C:\WINDOWS\system32\regsvr32.exe
          C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE
          C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe
          C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe
          C:\Program Files\Windows Desktop Search\WindowsSearch.exe
          C:\Program Files\Club-Internet\Lanceur\lanceur.exe
          C:\Program Files\Club-Internet\Le Compagnon Club\bin\mpbtn.exe
          C:\Program Files\Norton AntiVirus\SAVScan.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
          C:\Program Files\Messenger\msmsgs.exe
          C:\Program Files\BitDefender\BitDefender 2008\uiscan.exe
          C:\Program Files\Windows Live\Messenger\usnsvc.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Hijackthis Version Française\hijackthis vf.exe
          C:\WINDOWS\system32\SearchProtocolHost.exe

          R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://actus.sfr.fr
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer avec Club-Internet
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
          O2 - BHO: Windows Live OneCare Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Contrôle parental\fssbho.dll
          O2 - BHO: (no name) - {749C033F-C489-F3EF-B5C5-00B8C78C4344} - C:\Program Files\xxwmplvt\xlxzvmpw.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: CNavExtBho Class - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
          O2 - BHO: MSVPS System - {AC546B33-036A-41DA-B1CC-C1D15659520E} - C:\WINDOWS\movctrlflm.dll
          O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
          O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
          O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
          O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O3 - Toolbar: The nssfrch - {61AB8A39-FCCB-47CC-BAF3-750D1834E773} - C:\WINDOWS\nssfrch.dll
          O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
          O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
          O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
          O4 - HKLM\..\Run: [LaunchApp] Alaunch
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
          O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
          O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
          O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
          O4 - HKLM\..\Run: [ntiMUI] c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
          O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
          O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
          O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
          O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
          O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
          O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
          O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\WINDOWS\system32\SysMonitor.exe
          O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe 1
          O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
          O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
          O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe
          O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Contrôle parental\fssui.exe"
          O4 - HKLM\..\Run: [vobyxmrk] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\vobyxmrk.dll"
          O4 - HKLM\..\Run: [EPSON Stylus DX4000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE /FU "C:\WINDOWS\TEMP\E_S948.tmp" /EF "HKLM"
          O4 - HKLM\..\Run: [EPSON Product Rappel concernant l'enregistrement] C:\WINDOWS\Temp\RegModule.exe
          O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
          O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
          O4 - Startup: Club Internet.lnk = C:\Program Files\Club-Internet\Lanceur\lanceur.exe
          O4 - Global Startup: Acer Empowering Technology.lnk = ?
          O4 - Global Startup: Acer WLAN 11g USB Dongle.lnk = C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe
          O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
          O4 - Global Startup: LE COMPAGNON CLUB.lnk = C:\Program Files\Club-Internet\Le Compagnon Club\bin\matcli.exe
          O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
          O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
          O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
          O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
          O21 - SSODL: bxsbang - {B2301C26-2587-4AF5-BB45-8CC89D842A3D} - C:\WINDOWS\bxsbang.dll
          O21 - SSODL: ocgrep - {8D3EC1C6-7E47-460C-A1F0-3F7168F80186} - C:\WINDOWS\ocgrep.dll
          O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
          O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
          O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
          O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe" /service (file missing)
          O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~2.EXE
          O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
          O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
          O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
          O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
          O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
          O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
          O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
          O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
          O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe" /service (file missing)
          O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
          O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe" /service (file missing)
          0
          1. Mon ordinateur est très lent !!!! il y 3 icones qui apparaissent sur le bureau et dans mes favoris :
            Error Cleaner
            Privacy Protector
            Spyware&Malware Protection
            0
            1. Contributeur sécurité
              fais la suite: rogue remover, smitfraud fix et scan en ligne
              0
              1. SmitFraudFix v2.240

                Rapport fait à 18:41:51,67, 24/10/2007
                Executé à partir de C:\Documents and Settings\KAOUTAR\Bureau\SmitfraudFix
                OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                Le type du système de fichiers est NTFS
                Fix executé en mode normal

                »»»»»»»»»»»»»»»»»»»»»»»» Process

                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                C:\WINDOWS\Explorer.EXE
                C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
                C:\WINDOWS\eHome\ehRecvr.exe
                C:\WINDOWS\eHome\ehSched.exe
                c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                C:\Program Files\Norton AntiVirus\navapsvc.exe
                C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
                C:\WINDOWS\system32\nvsvc32.exe
                C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
                C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
                C:\WINDOWS\system32\SearchIndexer.exe
                C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
                C:\WINDOWS\system32\dllhost.exe
                C:\WINDOWS\ehome\ehtray.exe
                C:\WINDOWS\eHome\ehmsas.exe
                C:\WINDOWS\RTHDCPL.EXE
                C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
                C:\WINDOWS\system32\RUNDLL32.EXE
                C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
                C:\WINDOWS\system32\SysMonitor.exe
                C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
                C:\Program Files\BroadJump\Client Foundation\CFD.exe
                C:\PROGRA~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe
                C:\Program Files\Windows Live\Contrôle parental\fssui.exe
                C:\WINDOWS\system32\regsvr32.exe
                C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE
                C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe
                C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe
                C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                C:\Program Files\Club-Internet\Lanceur\lanceur.exe
                C:\Program Files\Club-Internet\Le Compagnon Club\bin\mpbtn.exe
                C:\Program Files\Norton AntiVirus\SAVScan.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
                C:\Program Files\Messenger\msmsgs.exe
                C:\Program Files\Windows Live\Messenger\usnsvc.exe
                C:\Program Files\Internet Explorer\IEXPLORE.EXE
                C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                C:\WINDOWS\system32\wuauclt.exe
                C:\WINDOWS\system32\SearchProtocolHost.exe
                C:\WINDOWS\system32\cmd.exe

                »»»»»»»»»»»»»»»»»»»»»»»» hosts

                »»»»»»»»»»»»»»»»»»»»»»»» C:\

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\KAOUTAR

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\KAOUTAR\Application Data

                »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\KAOUTAR\Favoris

                »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                "Source"="file:///C:\\WINDOWS\\privacy_danger\\index.htm"
                "SubscribedURL"=""
                "FriendlyName"="Privacy Protection"

                »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                SrchSTS.exe by S!Ri
                Search SharedTaskScheduler's .dll

                »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                "AppInit_DLLs"=""

                »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                "System"=""

                »»»»»»»»»»»»»»»»»»»»»»»» Rustock

                »»»»»»»»»»»»»»»»»»»»»»»» DNS

                Description: Generic Marvell Yukon Chipset based Ethernet Controller - Miniport d'ordonnancement de paquets
                DNS Server Search Order: 192.168.1.1
                DNS Server Search Order: 192.168.1.1

                HKLM\SYSTEM\CCS\Services\Tcpip\..\{C400098B-E93C-4F05-8D46-5D6222FF9779}: DhcpNameServer=192.168.1.1 192.168.1.1
                HKLM\SYSTEM\CS1\Services\Tcpip\..\{C400098B-E93C-4F05-8D46-5D6222FF9779}: DhcpNameServer=192.168.1.1 192.168.1.1
                HKLM\SYSTEM\CS3\Services\Tcpip\..\{C400098B-E93C-4F05-8D46-5D6222FF9779}: DhcpNameServer=192.168.1.1 192.168.1.1
                HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1
                HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1
                HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1

                »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                »»»»»»»»»»»»»»»»»»»»»»»» Fin
                0
                1. SmitFraudFix v2.240

                  Rapport fait à 18:48:34,03, 24/10/2007
                  Executé à partir de C:\Documents and Settings\KAOUTAR\Bureau\SmitfraudFix
                  OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                  Le type du système de fichiers est NTFS
                  Fix executé en mode sans echec

                  »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  SrchSTS.exe by S!Ri
                  Search SharedTaskScheduler's .dll

                  »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

                  »»»»»»»»»»»»»»»»»»»»»»»» hosts

                  127.0.0.1 localhost

                  »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                  S!Ri's WS2Fix: LSP not Found.

                  »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                  GenericRenosFix by S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

                  »»»»»»»»»»»»»»»»»»»»»»»» DNS

                  HKLM\SYSTEM\CCS\Services\Tcpip\..\{C400098B-E93C-4F05-8D46-5D6222FF9779}: DhcpNameServer=192.168.1.1 192.168.1.1
                  HKLM\SYSTEM\CS1\Services\Tcpip\..\{C400098B-E93C-4F05-8D46-5D6222FF9779}: DhcpNameServer=192.168.1.1 192.168.1.1
                  HKLM\SYSTEM\CS3\Services\Tcpip\..\{C400098B-E93C-4F05-8D46-5D6222FF9779}: DhcpNameServer=192.168.1.1 192.168.1.1
                  HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1
                  HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1
                  HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1

                  »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

                  »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                  "System"=""

                  »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                  Nettoyage terminé.

                  »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  SrchSTS.exe by S!Ri
                  Search SharedTaskScheduler's .dll

                  »»»»»»»»»»»»»»»»»»»»»»»» Fin
                  0
                  1. Salut à toi Oum-choucha,

                    Bizarremment j' ai exactement la même chose que toi.Mais alors pareil moi je l'ai eu hier aussi en allumant l' ordi.Je vois ''vous êtes infecter par des virus et spywares veuillez télécharger defensenetsurfage et protection conue pour les éliminer et avoir une protection complète''(à un peu de choses près les mots) alors que moi aussi j' ai un anti-virus un anti-spywares etc...D'abord je les avais installer et protection conue m' avait trouver des ''crasses'' mais il ne voulait pas me le enlever il fallait acheter le logiciel pour que ça marche.Je le ai donc désinstaller et donc encore aujourd'hui j' ai eu chaque fois un message qui m'indique que mon ordi est sous la menace de je ne sais plus quel virus et il me donne également à chaque fois une page internet qui ne fonctionne pas ainsi qu' un rond rouge avec une croix blanche dans ma barre de lancement qui ne part pas non plus.Ah oui j' ai également les trois icônes sur mon bureau qui s'affichent et même si je les effacent elles reviennent à chaque démarrage.Donc je ne sais pas quoi faire non-plus je suis comme toi oum-choucha impuissant devant ces fenêtres qui s'ouvrent toutes les 30 secondes et j' ai même refais tout mon scan avec anti-virus etc mais rien à faire.Alors si quelqu'un pouvait nous aider ou bien si il a le même problème qu'il nous en fasse part parce que c'est vraiment chi..t quand on est sur l'ordi et oum-choucha si tu as une solution pour ce problème n'hésite pas à m'en faire part.

                    Merci et bonne soirée.
                    0
                    1. Contributeur sécurité
                      slt cré ton propre post et colle un rapport hijackthis et smitraud fix svp sinon on se perd
                      0
                      1. <HTML>
                        <HEAD>
                        <TITLE>BitDefender Online Scanner -Scan Report</TITLE>
                        <META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
                        <meta name="generator" content="Namo WebEditor v5.0(Trial)">
                        </HEAD>
                        <BODY BGCOLOR=#FFFFFF leftmargin="10" marginwidth="0" topmargin="20" marginheight="0" >

                        <table align="center" border="0" cellpadding="0" cellspacing="0" width="90%">
                        <tr>
                        <td width="458">
                        <p><font face="Arial" color=red><span style="font-size:14pt;"><b>BitDefender
                        Online Scanner</b></span></font></p>
                        </td>
                        <td width="40%">
                        <p> </p>
                        </td>
                        <td width="10%">
                        <p> </p>
                        </td>
                        </tr>
                        <tr>
                        <td colspan="3" width="912">
                        <p><font face="Arial"><span style="font-size:11pt;"><B>Scan report generated
                        at: Wed, Oct 24, 2007 - 19:45:02</b></span></font></p>
                        </td>
                        </tr>

                        <tr>
                        <td width="458">
                        <p><font face="Arial"><span style="font-size:11pt;"><B> </b></span></font></p>
                        </td>
                        <td width="40%">
                        <p> </p>
                        </td>
                        <td width="10%">
                        <p> </p>
                        </td>
                        </tr>

                        <tr>
                        <td width="458">
                        <p><font face="Arial"><span style="font-size:11pt;"><B>Scan
                        path: </b></span><span style="font-size:10pt;">C:\;D:\;E:\;F:\;G:\;H:\;I:\;</span></font></p>
                        </td>
                        <td width="40%">
                        <p> </p>
                        </td>
                        <td width="10%">
                        <p> </p>
                        </td>
                        </tr>

                        <tr>
                        <td width="458">
                        <p><font face="Arial"><span style="font-size:11pt;"><B> </b></span></font></p>
                        </td>
                        <td width="40%">
                        <p> </p>
                        </td>
                        <td width="10%">
                        <p> </p>
                        </td>
                        </tr>

                        <tr>
                        <td width="458">
                        <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
                        <tr>
                        <td width="451" colspan="2" bgcolor="#CCCCCC">
                        <p><font face="Arial" size="2"><B>Statistics</b></font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Time</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">00:34:56</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Files</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">188694</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Folders</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">4270</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Boot Sectors</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">4</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Archives</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">7390</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Packed Files</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">12613</font></p>
                        </td>
                        </tr>
                        </table>
                        </td>
                        <td width="40%">
                        <p> </p>
                        </td>
                        <td width="10%">
                        <p> </p>
                        </td>
                        </tr>

                        <tr>
                        <td width="458">
                        <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
                        <tr>
                        <td width="451" colspan="2" bgcolor="#CCCCCC">
                        <p><font face="Arial" size="2"><B>Results</b></font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Identified Viruses </font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">1</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Infected Files </font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">4</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Suspect Files </font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">0</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Warnings</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">0</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Disinfected</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">0</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Deleted Files</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">4</font></p>
                        </td>
                        </tr>
                        </table>
                        </td>
                        <td width="40%">
                        <p> </p>
                        </td>
                        <td width="10%">
                        <p> </p>
                        </td>
                        </tr>

                        <tr>
                        <td width="458">
                        <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
                        <tr>
                        <td width="451" colspan="2" bgcolor="#CCCCCC">
                        <p><font face="Arial" size="2"><B>Engines Info</b></font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Virus Definitions</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">853538</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Engine build</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Scan plugins</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">14</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Archive plugins</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">38</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Unpack plugins</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">7</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">E-mail plugins</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">6</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">System plugins</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">1</font></p>
                        </td>
                        </tr>
                        </table>
                        </td>
                        <td width="40%">
                        <p> </p>
                        </td>
                        <td width="10%">
                        <p> </p>
                        </td>
                        </tr>

                        <tr>
                        <td width="458">
                        <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
                        <tr>
                        <td width="451" colspan="2" bgcolor="#CCCCCC">
                        <p><font face="Arial" size="2"><B>Scan Settings</b></font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">First Action</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">Disinfect</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Second Action</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">Delete</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Heuristics</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">Yes</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Enable Warnings</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">Yes</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Scanned Extensions</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">*;</font></p>
                        </td>
                        </tr>

                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Exclude Extensions</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2"> </font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Scan Emails</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">Yes</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Scan Archives</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">Yes</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Scan Packed</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">Yes</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Scan Files</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">Yes</font></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">Scan Boot</font></p>
                        </td>
                        <td width="43%" align="right">
                        <p><font face="Arial" size="2">Yes</font></p>
                        </td>
                        </tr>
                        </table>
                        </td>
                        <td width="40%">
                        <p> </p>
                        </td>
                        <td width="10%">
                        <p> </p>
                        </td>
                        </tr>

                        <tr>
                        <td colspan=2>  
                        <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
                        <tr>
                        <td width="252" bgcolor="#CCCCCC">
                        <p><font face="Arial" size="2"><B>Scanned File</b></font></p>
                        </td>
                        <td width="195" bgcolor="#CCCCCC" align="right">
                        <p align="left"><b><font size="2" face="Arial"> Status</font></b></p>
                        </td>
                        </tr>
                        <tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">C:\Documents and Settings\MOSTAFA\Local Settings\Temp\BIT1B0.tmp=>(NSIS o)=>lzma_solid_nsis0000</font></p>
                        </td>
                        <td width="43%" align="left">
                        <p><font face="Arial" size="2">Infected with: Trojan.Downloader.Zlob.AAVM</font></p>
                        </td>
                        </tr><tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">C:\Documents and Settings\MOSTAFA\Local Settings\Temp\BIT1B0.tmp=>(NSIS o)=>lzma_solid_nsis0000</font></p>
                        </td>
                        <td width="43%" align="left">
                        <p><font face="Arial" size="2">Disinfection failed</font></p>
                        </td>
                        </tr><tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">C:\Documents and Settings\MOSTAFA\Local Settings\Temp\BIT1B0.tmp=>(NSIS o)=>lzma_solid_nsis0000</font></p>
                        </td>
                        <td width="43%" align="left">
                        <p><font face="Arial" size="2">Deleted</font></p>
                        </td>
                        </tr><tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">C:\Documents and Settings\MOSTAFA\Local Settings\Temp\BIT1B0.tmp=>(NSIS o)</font></p>
                        </td>
                        <td width="43%" align="left">
                        <p><font face="Arial" size="2">Update failed</font></p>
                        </td>
                        </tr><tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">C:\Documents and Settings\MOSTAFA\Local Settings\Temp\BIT1B0.tmp=>(NSIS o)=>lzma_solid_nsis0004</font></p>
                        </td>
                        <td width="43%" align="left">
                        <p><font face="Arial" size="2">Infected with: Trojan.Downloader.Zlob.AAVM</font></p>
                        </td>
                        </tr><tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">C:\Documents and Settings\MOSTAFA\Local Settings\Temp\BIT1B0.tmp=>(NSIS o)=>lzma_solid_nsis0004</font></p>
                        </td>
                        <td width="43%" align="left">
                        <p><font face="Arial" size="2">Disinfection failed</font></p>
                        </td>
                        </tr><tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">C:\Documents and Settings\MOSTAFA\Local Settings\Temp\BIT1B0.tmp=>(NSIS o)=>lzma_solid_nsis0004</font></p>
                        </td>
                        <td width="43%" align="left">
                        <p><font face="Arial" size="2">Deleted</font></p>
                        </td>
                        </tr><tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">C:\Documents and Settings\MOSTAFA\Local Settings\Temp\BIT1B0.tmp=>(NSIS o)</font></p>
                        </td>
                        <td width="43%" align="left">
                        <p><font face="Arial" size="2">Update failed</font></p>
                        </td>
                        </tr><tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">C:\Documents and Settings\MOSTAFA\Local Settings\Temp\BIT1B9.tmp=>(NSIS o)=>lzma_solid_nsis0000</font></p>
                        </td>
                        <td width="43%" align="left">
                        <p><font face="Arial" size="2">Infected with: Trojan.Downloader.Zlob.AAVM</font></p>
                        </td>
                        </tr><tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">C:\Documents and Settings\MOSTAFA\Local Settings\Temp\BIT1B9.tmp=>(NSIS o)=>lzma_solid_nsis0000</font></p>
                        </td>
                        <td width="43%" align="left">
                        <p><font face="Arial" size="2">Disinfection failed</font></p>
                        </td>
                        </tr><tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">C:\Documents and Settings\MOSTAFA\Local Settings\Temp\BIT1B9.tmp=>(NSIS o)=>lzma_solid_nsis0000</font></p>
                        </td>
                        <td width="43%" align="left">
                        <p><font face="Arial" size="2">Deleted</font></p>
                        </td>
                        </tr><tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">C:\Documents and Settings\MOSTAFA\Local Settings\Temp\BIT1B9.tmp=>(NSIS o)</font></p>
                        </td>
                        <td width="43%" align="left">
                        <p><font face="Arial" size="2">Update failed</font></p>
                        </td>
                        </tr><tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">C:\Documents and Settings\MOSTAFA\Local Settings\Temp\BIT1B9.tmp=>(NSIS o)=>lzma_solid_nsis0004</font></p>
                        </td>
                        <td width="43%" align="left">
                        <p><font face="Arial" size="2">Infected with: Trojan.Downloader.Zlob.AAVM</font></p>
                        </td>
                        </tr><tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">C:\Documents and Settings\MOSTAFA\Local Settings\Temp\BIT1B9.tmp=>(NSIS o)=>lzma_solid_nsis0004</font></p>
                        </td>
                        <td width="43%" align="left">
                        <p><font face="Arial" size="2">Disinfection failed</font></p>
                        </td>
                        </tr><tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">C:\Documents and Settings\MOSTAFA\Local Settings\Temp\BIT1B9.tmp=>(NSIS o)=>lzma_solid_nsis0004</font></p>
                        </td>
                        <td width="43%" align="left">
                        <p><font face="Arial" size="2">Deleted</font></p>
                        </td>
                        </tr><tr>
                        <td width="57%">
                        <p><font face="Arial" size="2">C:\Documents and Settings\MOSTAFA\Local Settings\Temp\BIT1B9.tmp=>(NSIS o)</font></p>
                        </td>
                        <td width="43%" align="left">
                        <p><font face="Arial" size="2">Update failed</font></p>
                        </td>
                        </tr>
                        </table>
                        </td>

                        <td width="10%">
                        <p> </p>
                        </td>
                        </tr>

                        <tr>
                        <td width="458">
                        <p><font face="Arial"><span style="font-size:11pt;"><B> </b></span></font></p>
                        </td>
                        <td width="40%">
                        <p> </p>
                        </td>
                        <td width="10%">
                        <p> </p>
                        </td>
                        </tr>

                        <tr>
                        <td width="458">
                        <p><font face="Arial"><span style="font-size:11pt;"><B> </b></span></font></p>
                        </td>
                        <td width="40%">
                        <p> </p>
                        </td>
                        <td width="10%">
                        <p> </p>
                        </td>
                        </tr>

                        </table>
                        <p> </p>

                        </body>
                        </html>

                        message du scan de bitdefender mon ordinateur est encore infecté !

                        dois supprimer ce que j'ai installé ?
                        0
                        1. <HTML>
                          <HEAD>
                          <TITLE>BitDefender Online Scanner -Scan Report</TITLE>
                          <META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
                          <meta name="generator" content="Namo WebEditor v5.0(Trial)">
                          </HEAD>
                          <BODY BGCOLOR=#FFFFFF leftmargin="10" marginwidth="0" topmargin="20" marginheight="0" >

                          <table align="center" border="0" cellpadding="0" cellspacing="0" width="90%">
                          <tr>
                          <td width="458">
                          <p><font face="Arial" color=red><span style="font-size:14pt;"><b>BitDefender
                          Online Scanner</b></span></font></p>
                          </td>
                          <td width="40%">
                          <p> </p>
                          </td>
                          <td width="10%">
                          <p> </p>
                          </td>
                          </tr>
                          <tr>
                          <td colspan="3" width="912">
                          <p><font face="Arial"><span style="font-size:11pt;"><B>Scan report generated
                          at: Wed, Oct 24, 2007 - 19:45:02</b></span></font></p>
                          </td>
                          </tr>

                          <tr>
                          <td width="458">
                          <p><font face="Arial"><span style="font-size:11pt;"><B> </b></span></font></p>
                          </td>
                          <td width="40%">
                          <p> </p>
                          </td>
                          <td width="10%">
                          <p> </p>
                          </td>
                          </tr>

                          <tr>
                          <td width="458">
                          <p><font face="Arial"><span style="font-size:11pt;"><B>Scan
                          path: </b></span><span style="font-size:10pt;">C:\;D:\;E:\;F:\;G:\;H:\;I:\;</span></font></p>
                          </td>
                          <td width="40%">
                          <p> </p>
                          </td>
                          <td width="10%">
                          <p> </p>
                          </td>
                          </tr>

                          <tr>
                          <td width="458">
                          <p><font face="Arial"><span style="font-size:11pt;"><B> </b></span></font></p>
                          </td>
                          <td width="40%">
                          <p> </p>
                          </td>
                          <td width="10%">
                          <p> </p>
                          </td>
                          </tr>

                          <tr>
                          <td width="458">
                          <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
                          <tr>
                          <td width="451" colspan="2" bgcolor="#CCCCCC">
                          <p><font face="Arial" size="2"><B>Statistics</b></font></p>
                          </td>
                          </tr>
                          <tr>
                          <td width="57%">
                          <p><font face="Arial" size="2">Time</font></p>
                          </td>
                          <td width="43%" align="right">
                          <p><font face="Arial" size="2">00:34:56</font></p>
                          </td>
                          </tr>
                          <tr>
                          <td width="57%">
                          <p><font face="Arial" size="2">Files</font></p>
                          </td>
                          <td width="43%" align="right">
                          <p><font face="Arial" size="2">188694</font></p>
                          </td>
                          </tr>
                          <tr>
                          <td width="57%">
                          <p><font face="Arial" size="2">Folders</font></p>
                          </td>
                          <td width="43%" align="right">
                          <p><font face="Arial" size="2">4270</font></p>
                          </td>
                          </tr>
                          <tr>
                          <td width="57%">
                          <p><font face="Arial" size="2">Boot Sectors</font></p>
                          </td>
                          <td width="43%" align="right">
                          <p><font face="Arial" size="2">4</font></p>
                          </td>
                          </tr>
                          <tr>
                          <td width="57%">
                          <p><font face="Arial" size="2">Archives</font></p>
                          </td>
                          <td width="43%" align="right">
                          <p><font face="Arial" size="2">7390</font></p>
                          </td>
                          </tr>
                          <tr>
                          <td width="57%">
                          <p><font face="Arial" size="2">Packed Files</font></p>
                          </td>
                          <td width="43%" align="right">
                          <p><font face="Arial" size="2">12613</font></p>
                          </td>
                          </tr>
                          </table>
                          </td>
                          <td width="40%">
                          <p> </p>
                          </td>
                          <td width="10%">
                          <p> </p>
                          </td>
                          </tr>

                          <tr>
                          <td width="458">
                          <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
                          <tr>
                          <td width="451" colspan="2" bgcolor="#CCCCCC">
                          <p><font face="Arial" size="2"><B>Results</b></font></p>
                          </td>
                          </tr>
                          <tr>
                          <td width="57%">
                          <p><font face="Arial" size="2">Identified Viruses </font></p>
                          </td>
                          <td width="43%" align="right">
                          <p><font face="Arial" size="2">1</font></p>
                          </td>
                          </tr>
                          <tr>
                          <td width="57%">
                          <p><font face="Arial" size="2">Infected Files </font></p>
                          </td>
                          <td width="43%" align="right">
                          <p><font face="Arial" size="2">4</font></p>
                          </td>
                          </tr>
                          <tr>
                          <td width="57%">
                          <p><font face="Arial" size="2">Suspect Files </font></p>
                          </td>
                          <td width="43%" align="right">
                          <p><font face="Arial" size="2">0</font></p>
                          </td>
                          </tr>
                          <tr>
                          <td width="57%">
                          <p><font face="Arial" size="2">Warnings</font></p>
                          </td>
                          <td width="43%" align="right">
                          <p><font face="Arial" size="2">0</font></p>
                          </td>
                          </tr>
                          <tr>
                          <td width="57%">
                          <p><font face="Arial" size="2">Disinfected</font></p>
                          </td>
                          <td width="43%" align="right">
                          <p><font face="Arial" size="2">0</font></p>
                          </td>
                          </tr>
                          <tr>
                          <td width="57%">
                          <p><font face="Arial" size="2">Deleted Files</font></p>
                          </td>
                          <td width="43%" align="right">
                          <p><font face="Arial" size="2">4</font></p>
                          </td>
                          </tr>
                          </table>
                          </td>
                          <td width="40%">
                          <p> </p>
                          </td>
                          <td width="10%">
                          <p> </p>
                          </td>
                          </tr>

                          <tr>
                          <td width="458">
                          <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
                          <tr>
                          <td width="451" colspan="2" bgcolor="#CCCCCC">
                          <p><font face="Arial" size="2"><B>Engines Info</b></font></
                          0
                          1. <HTML>
                            <HEAD>
                            <TITLE>BitDefender Online Scanner -Scan Report</TITLE>
                            <META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
                            <meta name="generator" content="Namo WebEditor v5.0(Trial)">
                            </HEAD>
                            <BODY BGCOLOR=#FFFFFF leftmargin="10" marginwidth="0" topmargin="20" marginheight="0" >

                            <table align="center" border="0" cellpadding="0" cellspacing="0" width="90%">
                            <tr>
                            <td width="458">
                            <p><font face="Arial" color=red><span style="font-size:14pt;"><b>BitDefender
                            Online Scanner</b></span></font></p>
                            </td>
                            <td width="40%">
                            <p> </p>
                            </td>
                            <td width="10%">
                            <p> </p>
                            </td>
                            </tr>
                            <tr>
                            <td colspan="3" width="912">
                            <p><font face="Arial"><span style="font-size:11pt;"><B>Scan report generated
                            at: Wed, Oct 24, 2007 - 19:45:02</b></span></font></p>
                            </td>
                            </tr>

                            <tr>
                            <td width="458">
                            <p><font face="Arial"><span style="font-size:11pt;"><B> </b></span></font></p>
                            </td>
                            <td width="40%">
                            <p> </p>
                            </td>
                            <td width="10%">
                            <p> </p>
                            </td>
                            </tr>

                            <tr>
                            <td width="458">
                            <p><font face="Arial"><span style="font-size:11pt;"><B>Scan
                            path: </b></span><span style="font-size:10pt;">C:\;D:\;E:\;F:\;G:\;H:\;I:\;</span></font></p>
                            </td>
                            <td width="40%">
                            <p> </p>
                            </td>
                            <td width="10%">
                            <p> </p>
                            </td>
                            </tr>

                            <tr>
                            <td width="458">
                            <p><font face="Arial"><span style="font-size:11pt;"><B> </b></span></font></p>
                            </td>
                            <td width="40%">
                            <p> </p>
                            </td>
                            <td width="10%">
                            <p> </p>
                            </td>
                            </tr>

                            <tr>
                            <td width="458">
                            <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
                            <tr>
                            <td width="451" colspan="2" bgcolor="#CCCCCC">
                            <p><font face="Arial" size="2"><B>Statistics</b></font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Time</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">00:34:56</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Files</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">188694</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Folders</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">4270</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Boot Sectors</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">4</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Archives</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">7390</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Packed Files</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">12613</font></p>
                            </td>
                            </tr>
                            </table>
                            </td>
                            <td width="40%">
                            <p> </p>
                            </td>
                            <td width="10%">
                            <p> </p>
                            </td>
                            </tr>

                            <tr>
                            <td width="458">
                            <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
                            <tr>
                            <td width="451" colspan="2" bgcolor="#CCCCCC">
                            <p><font face="Arial" size="2"><B>Results</b></font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Identified Viruses </font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">1</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Infected Files </font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">4</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Suspect Files </font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">0</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Warnings</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">0</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Disinfected</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">0</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Deleted Files</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">4</font></p>
                            </td>
                            </tr>
                            </table>
                            </td>
                            <td width="40%">
                            <p> </p>
                            </td>
                            <td width="10%">
                            <p> </p>
                            </td>
                            </tr>

                            <tr>
                            <td width="458">
                            <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
                            <tr>
                            <td width="451" colspan="2" bgcolor="#CCCCCC">
                            <p><font face="Arial" size="2"><B>Engines Info</b></font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Virus Definitions</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">853538</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Engine build</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Scan plugins</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">14</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Archive plugins</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">38</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Unpack plugins</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">7</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">E-mail plugins</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">6</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">System plugins</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">1</font></p>
                            </td>
                            </tr>
                            </table>
                            </td>
                            <td width="40%">
                            <p> </p>
                            </td>
                            <td width="10%">
                            <p> </p>
                            </td>
                            </tr>

                            <tr>
                            <td width="458">
                            <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
                            <tr>
                            <td width="451" colspan="2" bgcolor="#CCCCCC">
                            <p><font face="Arial" size="2"><B>Scan Settings</b></font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">First Action</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">Disinfect</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            <p><font face="Arial" size="2">Second Action</font></p>
                            </td>
                            <td width="43%" align="right">
                            <p><font face="Arial" size="2">Delete</font></p>
                            </td>
                            </tr>
                            <tr>
                            <td width="57%">
                            0
                            1. Contributeur sécurité
                              je voudrais le rapport avec le nom des virus trouvés, les actions et le lieu des infections svp

                              recolle un rapport hijackthis

                              et surtout dis tes pbs
                              0
                              1. j'ai fait le scan avec mon antivirus bitdefender et il a trouvé 3 menaces touchant 9 objets :

                                Adware.Zango.AU :"Echec de la désinfection" Activé 3 infections je peux le supprimer
                                Detecté : C:\System volume Information\_restore...21\A0004370.exe=>(NSIS)=>Izma_solid_nsis0004
                                Detecté : C:\System volume Information\_restore...21\A0004383.exe=>(NSIS)=>Izma_solid_nsis0004
                                Detecté : C:\System volume Information\_restore...21\A0004396.exe=>(NSIS)=>Izma_solid_nsis0004

                                Trojan.Downloader.Zlob.AAVM :"Echec de la désinfection" Activé 4 infections je ne peux pas le supprimer
                                Infecté : C:\Documents and settings\MOSTAFA\Lo...Temp\BIT1B0.tmp=>(NSIS o)=>Izma_solid_nsis0000
                                Infecté : C:\Documents and settings\MOSTAFA\Lo...Temp\BIT1B0.tmp=>(NSIS o)=>Izma_solid_nsis0004
                                Infecté : C:\Documents and settings\MOSTAFA\Lo...Temp\BIT1B9.tmp=>(NSIS o)=>Izma_solid_nsis0000
                                Infecté : C:\Documents and settings\MOSTAFA\Lo...Temp\BIT1B9.tmp=>(NSIS o)=>Izma_solid_nsis0004

                                Trojan.Zlob.BWA :"Echec de la désinfection" Activé 2 infections je ne peux pas le supprimer
                                Infecté : C:\Documents and settings\MOSTAFA\Lo...Temp\BIT1B0.tmp=>(NSIS o)=>Izma_solid_nsis0005
                                Infecté : C:\Documents and settings\MOSTAFA\Lo...Temp\BIT1B9.tmp=>(NSIS o)=>Izma_solid_nsis0005

                                L'ordinateur est toujours lent surtout pour le net
                                0
                                1. Logfile of HijackThis v1.99.1
                                  Scan saved at 21:10:25, on 24/10/2007
                                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                                  MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                                  Running processes:
                                  C:\WINDOWS\System32\smss.exe
                                  C:\WINDOWS\system32\winlogon.exe
                                  C:\WINDOWS\system32\services.exe
                                  C:\WINDOWS\system32\lsass.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                                  C:\WINDOWS\Explorer.EXE
                                  C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                                  C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                                  C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                                  C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                                  C:\WINDOWS\system32\spoolsv.exe
                                  C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
                                  C:\WINDOWS\eHome\ehRecvr.exe
                                  C:\WINDOWS\eHome\ehSched.exe
                                  c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                  C:\Program Files\Norton AntiVirus\navapsvc.exe
                                  C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
                                  C:\WINDOWS\system32\nvsvc32.exe
                                  C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
                                  C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
                                  C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
                                  C:\WINDOWS\system32\SearchIndexer.exe
                                  C:\WINDOWS\system32\dllhost.exe
                                  C:\WINDOWS\ehome\ehtray.exe
                                  C:\WINDOWS\eHome\ehmsas.exe
                                  C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
                                  C:\WINDOWS\RTHDCPL.EXE
                                  C:\WINDOWS\system32\RUNDLL32.EXE
                                  C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                                  C:\WINDOWS\system32\SysMonitor.exe
                                  C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
                                  C:\Program Files\BroadJump\Client Foundation\CFD.exe
                                  C:\PROGRA~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe
                                  C:\Program Files\Windows Live\Contrôle parental\fssui.exe
                                  C:\WINDOWS\system32\regsvr32.exe
                                  C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE
                                  C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
                                  C:\WINDOWS\system32\ctfmon.exe
                                  C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                                  C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe
                                  C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe
                                  C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                                  C:\Program Files\Club-Internet\Lanceur\lanceur.exe
                                  C:\Program Files\Club-Internet\Le Compagnon Club\bin\mpbtn.exe
                                  C:\Program Files\Norton AntiVirus\SAVScan.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
                                  C:\Program Files\Internet Explorer\IEXPLORE.EXE
                                  C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                                  C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

                                  R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://actus.sfr.fr
                                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer avec Club-Internet
                                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                  R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                  O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                  O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                                  O2 - BHO: Windows Live OneCare Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Contrôle parental\fssbho.dll
                                  O2 - BHO: (no name) - {749C033F-C489-F3EF-B5C5-00B8C78C4344} - C:\Program Files\xxwmplvt\xlxzvmpw.dll
                                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                  O2 - BHO: CNavExtBho Class - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
                                  O2 - BHO: MSVPS System - {AC546B33-036A-41DA-B1CC-C1D15659520E} - C:\WINDOWS\movctrlflm.dll
                                  O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                                  O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
                                  O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
                                  O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                  O3 - Toolbar: The nssfrch - {61AB8A39-FCCB-47CC-BAF3-750D1834E773} - C:\WINDOWS\nssfrch.dll
                                  O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                                  O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
                                  O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
                                  O4 - HKLM\..\Run: [LaunchApp] Alaunch
                                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                  O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                                  O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                                  O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
                                  O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                                  O4 - HKLM\..\Run: [ntiMUI] c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
                                  O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                                  O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
                                  O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
                                  O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                                  O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                                  O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                                  O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
                                  O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\WINDOWS\system32\SysMonitor.exe
                                  O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe 1
                                  O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
                                  O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
                                  O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe
                                  O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Contrôle parental\fssui.exe"
                                  O4 - HKLM\..\Run: [vobyxmrk] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\vobyxmrk.dll"
                                  O4 - HKLM\..\Run: [EPSON Stylus DX4000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE /FU "C:\WINDOWS\TEMP\E_S948.tmp" /EF "HKLM"
                                  O4 - HKLM\..\Run: [EPSON Product Rappel concernant l'enregistrement] C:\WINDOWS\Temp\RegModule.exe
                                  O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
                                  O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
                                  O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                                  O4 - Startup: Club Internet.lnk = C:\Program Files\Club-Internet\Lanceur\lanceur.exe
                                  O4 - Global Startup: Acer Empowering Technology.lnk = ?
                                  O4 - Global Startup: Acer WLAN 11g USB Dongle.lnk = C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe
                                  O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                                  O4 - Global Startup: LE COMPAGNON CLUB.lnk = C:\Program Files\Club-Internet\Le Compagnon Club\bin\matcli.exe
                                  O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                  O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                                  O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                                  O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                                  O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                  O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                                  O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
                                  O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
                                  O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
                                  O21 - SSODL: bxsbang - {B2301C26-2587-4AF5-BB45-8CC89D842A3D} - C:\WINDOWS\bxsbang.dll
                                  O21 - SSODL: ocgrep - {8D3EC1C6-7E47-460C-A1F0-3F7168F80186} - C:\WINDOWS\ocgrep.dll
                                  O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
                                  O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                                  O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                  O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe" /service (file missing)
                                  O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~2.EXE
                                  O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
                                  O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
                                  O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
                                  O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                  O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                                  O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
                                  O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                                  O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                                  O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                                  O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe" /service (file missing)
                                  O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
                                  O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe" /service (file missing)
                                  0
                                  1. Contributeur sécurité
                                    tu as norton et bitdefender : vire un des deux

                                    ___________________

                                    utilise

                                    CCLEANER: (lance un nettoyage et répare 3 fois les erreurs) sans installer la barre yahoo

                                    https://www.01net.com/

                                    ___________________

                                    AVG antispyware

                                    https://www.01net.com/

                                    Tuto :
                                    http://www.kachouri.com/tuto/tuto-161-avg-anti-spyware-75-pour-votre-securite.html

                                    ->Relance AVG AS -> "Analyse" ->"Paramètres"

                                    Sous la question "Comment réagir ?" :

                                    -> clique sur "Actions recommandées" et choisis "Quarantaines"
                                    -> Re-clique sur l'onglet "Analyse" puis réalise une "Analyse complète du système"

                                    Si un fichier est infecté en fin d'analyse

                                    ->Clique sur "Appliquer toutes les actions "

                                    ->Clique sur "Enregistrer le rapport" puis sur "Enregistrer le rapport sous".

                                    ->Enregistre ce fichier texte sur ton bureau ensuite colle le rapport ici

                                    _______________________

                                    combofix (colle le rapport)

                                    http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe

                                    http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                                    http://mickael.barroux.free.fr/securite/combofix.php
                                    __________________________

                                    Colle le rapport :
                                    Clean permettra de faire du nettoyage et supprimer des fichiers que des anti-virus et anti-spywares n'ont pas pu trouver. Le logiciel est régulièrement mis à jour, vous devrez donc le re-téléchargé pour obtenir une version plus récente.

                                    · Téléchargez clean.zip, décompressez-le sur votre bureau (clic droit / extraire tout), vous obtenez alors un dossier clean
                                    · Démarrez Windows en mode sans échec : Guide pour redémarrer en mode sans échec
                                    · Ouvrez le dossier clean qui se trouve sur ton bureau, et double-cliquez sur clean.cmd, une fenêtre noire va apparaître pendant un instant, laissez la ouverte jusqu'à ce qu'elle se ferme.

                                    manuel:
                                    http://kerio.probb.fr/tuto-Clean-h37.html

                                    _______________________

                                    désactive la restauration système pour purger les virus qui seraient dedans(dans DEMARRER puis TOUS LES PROGRAMMES puis ACCESSOIRE puis OUTILS SYSTEME puis RESTAURATION SYSTEME puis paramètre)

                                    redemarre ton ordi
                                    puis
                                    puis réactive là
                                    ------------------
                                    0
                                    1. juste une question si je restaure le système avec les cd de restauration est ce que le problème sera règlé ?
                                      0
                                      1. je suis entrain de faire l'analyse complète avec avg anti-spyware
                                        les virus sont revenus !!! au secours !!!
                                        0
                                        1. le rapport que je viens d'envoyer c avant la quarantaine je suis entrain de faire une autre analyse et j'enverrai le rapport
                                          0
                                          • 1
                                          • 2
                                          • 3