Infesté par navipromo

Bonjour,
je viens de faire reinstallé mon ordi et voilà que je suis déjà infecté par 2 navipromo.bqx et l'autre je ne me rappelle plus. Enfin bref j'ai pas trop les moyens de le ramener maintenant et j'aimerais vraiement le desinfecté. Quelqu'un pourrait il m'aider. D'avance merci
Configuration: Windows XP
Internet Explorer 7.0

30 réponses

Résumé de la discussion

Une personne ayant réinstallé son ordinateur se retrouve infectée par deux malwares, dont navipromo.bqx, et cherche une désinfection efficace sous Windows XP et Internet Explorer 7. Des conseils portent sur l’utilisation de l’outil Navilog avec l’option 1 puis vérification, et sur l’éventualité de lancer l’option 2 seulement après avis, afin d’éviter une désinfection invalide. D’autres évoquent des scans avec des outils comme Bitdefender ou SiSoftware Sandra, et rapportent des difficultés lorsque certains programmes ne sont pas installés, ce qui peut compliquer l’obtention d’un nettoyage complet. En cas de doute, des échanges portent aussi sur le fait que des rapports navilog doivent être copiés et partagés pour évaluer correctement les infections et adapter l’étape suivante.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    re,
    dans le rapport navilog on voit que l'infection vient de messenger skinner:C:\Program Files\MessengerSkinner trouvé !
    pourquoi ne pas faire l'option 2 maintenant et vérification apres???
    1
    1. Contributeur sécurité
      merci a toi dlld j'ai besoin d'etre épaulé des fois que!
      virgoginie:option 2 (desinfection auto)puis poste le rapport obtenu
      1
      1. Voici donc le rapport de navilog que jfkpresident m'a demandé et merci de votre aide j'espère que je me sortirai de ce virus. Sinon il y a un site 000favorit qui propose un logiciel de desinstalllation de navipromo. Qu'en pensez vous ?

        *** fsbl1.txt non trouvé ***
        (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)

        *** Suppression avec sauvegardes résultats GenericNaviSearch ***

        * Suppression dans C:\WINDOWS\System32 *

        * Suppression dans C:\DOCUME~1\LAURENCE\LOCALS~1\APPLIC~1 *

        *** Suppression dossiers dans C:\WINDOWS ***

        *** Suppression dossiers dans C:\Program Files ***

        *** Suppression dossiers dans C:\Documents and Settings\All Users\Application Data ***

        *** Suppression dossiers dans C:\Documents and Settings\laurence\Application Data ***

        *** Suppression dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

        *** Suppression fichiers ***

        *** Suppression fichiers temporaires ***

        Nettoyage contenu C:\WINDOWS\Temp effectué !
        Nettoyage contenu C:\Documents and Settings\laurence\Local Settings\Temp effectué !

        *** Traitement Recherche complémentaire ***
        (Recherche fichiers spécifiques)

        1)Recherche fichiers connus:

        2)Recherche, création sauvegardes et suppression Heuristique :

        *** Sauvegarde du Registre vers dossier Backupnavi ***

        sauvegarde du Registre réalisé avec succès !

        *** Nettoyage Registre ***

        Nettoyage Registre Ok

        *** Certificats ***

        Certificat Egroup absent !

        *** Fichiers suspects non supprimés par Navilog1 ***
        !! Fichiers légitimes possibles, à contrôler avant suppression !!

        *** Nettoyage terminé le 08/12/2007 à 11:36:50,23 ***
        0
      2. Re,

        elle est bien infectée...

        Sinon il y a un site 000favorit qui propose un logiciel de desinstalllation de navipromo. Qu'en pensez vous ?
        Il existe de multiples façons de ce débarasser de cette crasse mais je suis au regret de te dire que tu n'as pas que ça....
        0
    2. Contributeur sécurité
      télécharge navilog:http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
      fais l'option 1 puis copie/colle ton rapport ici
      ne fais pas l'option 2 sans avis!
      0
      1. Search Navipromo version 3.3.6 commencé le 05/12/2007 à 22:18:22,01

        !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
        !!! Postez ce rapport sur le forum pour le faire analyser !!!
        !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

        Outil exécuté depuis C:\Program Files\navilog1
        Mise à jour le 14.11.2007 à 18h00 par IL-MAFIOSO

        Microsoft Windows XP [version 5.1.2600]
        Internet Explorer : 7.0.5730.13

        *** Recherche Programmes installés ***

        *** Recherche dossiers dans C:\WINDOWS ***

        *** Recherche dossiers dans C:\Program Files ***

        C:\Program Files\MessengerSkinner trouvé !

        *** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***

        *** Recherche dossiers dans C:\Documents and Settings\laurence\Application Data ***

        ...\Application Data\MessengerSkinner trouvé !

        *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

        *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
        pour + d'infos : http://www.gmer.net

        Aucun fichier trouvé dans :

        - C:\WINDOWS\system32
        - C:\DOCUME~1\LAURENCE\LOCALS~1\APPLIC~1

        *** Recherche avec GenericNaviSearch ***
        !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
        !!! A vérifier impérativement avant toute suppression manuelle !!!

        * Recherche dans C:\WINDOWS\system32 *

        Fichiers suspects :

        * Recherche dans C:\DOCUME~1\LAURENCE\LOCALS~1\APPLIC~1 *

        Fichiers trouvés :

        ognvfnfmue.exe trouvé !
        ognvfnfmue_m2s.xml trouvé !

        *** Recherche fichiers ***

        C:\WINDOWS\system32\nvs2.inf trouvé !

        *** Recherche clés spécifiques dans le Registre ***

        HKEY_CURRENT_USER\Software\Lanconfig trouvé !

        *** Module de Recherche complémentaire ***
        (Recherche fichiers spécifiques)

        1)Recherche fichiers connus:

        2)Recherche Heuristique :

        C:\DOCUME~1\LAURENCE\LOCALS~1\APPLIC~1\ognvfnfmue.dat trouvé !

        3)Recherche Certificats :

        Certificat Egroup trouvé !

        *** Analyse terminée le 05/12/2007 à 22:19:42,09 ***
        0
    3. Contributeur sécurité
      d'accord avec toi surtout quand j'ai vu:navipromo.bqx
      bqx m'a intrigué dans un premier temps
      mais ca reste un post pour supprimer navipromo?
      0
      1. Salut,

        Il te faut une mise à jour, un parefeu, un antivirus et des antispyware(s)....

        > Télécharge SiSoftware Sandra Lite XIIc,
        puis
        0
        1. pourquoi SiSoftware Sandra Lite XIIc ?

          0
        2. @orb42Je préfers ce message,
          0
        3. heuuu, mais j'ai déjà tous ca
          0
        4. donc voilà :
          SiSoftware Sandra

          Système
          Nom de l'Hôte : PCBUREAU
          Utilisateur : laurence
          Groupe de Travail : MSHOME

          Processeur
          Modèle : Intel(R) Celeron(R) CPU 2.66GHz
          Vitesse : 2.67GHz
          Noyaux par Processeur : 1 Unité(s)
          Threads par Noyau : 1 Unité(s)
          Cache de Données Interne : 1x 16kB, Synchrone, Ecriture Directe, jeu à 8 voies, 64 octets de taille de ligne
          Cache sur Carte L2 : 1x 256kB, ECC, Synchrone, ATC, jeu à 4 voies, 64 octets de taille de ligne, 2 lignes par secteur

          Système
          Système : P4VM800
          Carte mère : P4VM800
          Bus : AGP PCI IMB USB i2c/SMBus
          Support MP : 1 Processeur(s)
          APIC MP : Oui
          BIOS Système : American Megatrends Inc. P1.30
          Mémoire Totale : 1GB DDR-SDRAM

          Chipset 1
          Modèle : ASRock Inc Standard Host Bridge
          Vitesse du Bus Principal : 4x 133MHz (532MHz taux de transfert)
          Mémoire Totale : 1GB DDR-SDRAM
          Vitesse du Bus Mémoire : 2x 166MHz (332MHz taux de transfert)

          Système Vidéo
          Moniteur/Panneau : Écran Plug-and-Play
          Adaptateur : RADEON 9550
          Adaptateur : RADEON 9550 Secondary
          Périphérique d'Images : Labtec WebCam Pro

          Dispositifs de Stockage Physiques
          Maxtor 6Y120L0 (ATA) : 114GB (C:)
          BENQ DVD DD DW1650 (ATAPI) : 530MB (D:)

          Dispositifs de Stockage Logiques
          Disque Dur (C:) : 114GB (102GB, 89% Espace Libre) (NTFS) @ Maxtor 6Y120L0 (ATA)
          ZT2ZCD1 (D:) : 529MB (CDFS) @ BENQ DVD DD DW1650 (ATAPI)
          3.5" 1.44Mo (A:) : N/A

          Périphériques
          Port(s) Série/Parallèle : 1 COM / 1 LPT
          Contrôleur USB/Hub : Contrôleur hôte universel USB Rev 5 ou ultérieur VIA
          Contrôleur USB/Hub : Contrôleur hôte universel USB Rev 5 ou ultérieur VIA
          Contrôleur USB/Hub : Contrôleur hôte universel USB Rev 5 ou ultérieur VIA
          Contrôleur USB/Hub : Contrôleur hôte universel USB Rev 5 ou ultérieur VIA
          Contrôleur USB/Hub : Contrôleur hôte étendu USB VIA
          Contrôleur USB/Hub : Concentrateur USB racine
          Contrôleur USB/Hub : Concentrateur USB racine
          Contrôleur USB/Hub : Concentrateur USB racine
          Contrôleur USB/Hub : Concentrateur USB racine
          Contrôleur USB/Hub : Concentrateur USB racine
          Contrôleur USB/Hub : Périphérique USB composite
          Clavier : Clavier standard 101/102 touches ou clavier Microsoft Natural Keyboard PS/2
          Souris : Souris Microsoft PS/2

          Dispositif(s) Multimédia
          Dispositif : C-Media AC97 Audio Device

          Gestion de l'Énergie
          Etat de la Ligne AC : Connecté

          Système(s) d'Exploitation
          Système Windows : Microsoft Windows XP (2002) Personnel 5.01.2600 (Service Pack 2)
          Compatibilité de Plate-forme : Win32 x86

          Services Réseau
          Adaptateur : Carte Fast Ethernet compatible VIA

          Conseils de Performance
          Conseil 2546 : Les gros modules de mémoire devraient être ECC/Parités.
          Conseil 2 : Double-cliquez sur le Conseil ou appuyez sur la touche Enter si le Conseil est sélectionné pour en savoir plus concernant cet élément.
          0
      2. MMMmm
        MessengerSkinner...

        virgogine,

        Poste nous un rapport HijackThis stp,

        Télécharge HiJackThis
        0
        1. Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 00:16:49, on 08/12/2007
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16544)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\csrss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Windows Defender\MsMpEng.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\guard.exe
          C:\WINDOWS\System32\FTRTSVC.exe
          C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          C:\Program Files\Spyware Doctor\svcntaux.exe
          C:\Program Files\Spyware Doctor\swdsvc.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\wdfmgr.exe
          C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
          C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
          C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
          C:\WINDOWS\system32\RunDll32.exe
          C:\Program Files\Spyware Doctor\SDTrayApp.exe
          C:\Program Files\Windows Defender\MSASCui.exe
          C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
          C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\avgas.exe
          C:\WINDOWS\System32\alg.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
          C:\PROGRA~1\Wanadoo\ComComp.exe
          C:\PROGRA~1\Wanadoo\Toaster.exe
          C:\PROGRA~1\Wanadoo\Inactivity.exe
          C:\PROGRA~1\Wanadoo\PollingModule.exe
          C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
          C:\Program Files\Messenger\msmsgs.exe
          C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
          C:\PROGRA~1\Wanadoo\Watch.exe
          C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
          C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
          C:\Program Files\Google\Google Updater\GoogleUpdater.exe
          C:\Program Files\Windows Live\Messenger\usnsvc.exe
          C:\Program Files\Internet Explorer\IEXPLORE.EXE
          C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
          C:\Documents and Settings\laurence\Mes documents\eMule\emule.exe
          C:\Program Files\BitDefender\BitDefender 2008\uiscan.exe
          C:\WINDOWS\explorer.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
          C:\WINDOWS\system32\wbem\wmiprvse.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
          R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - (no file)
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
          O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL (file missing)
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
          O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL (file missing)
          O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
          O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
          O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
          O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
          O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
          O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
          O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
          O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\avgas.exe" /minimized
          O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
          O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
          O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Global Startup: AVG Anti-Spyware 7.5
          O4 - Global Startup: BTTray.lnk = ?
          O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
          O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
          O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
          O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
          O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
          O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\guard.exe
          O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
          O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
          O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
          O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
          O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XIIc\Win32\RpcDataSrv.exe
          O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XIIc\RpcSandraSrv.exe
          O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
          O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
          O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
          O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
          0
      3. RE,

        je regarde ton log...

        tu n'as que le parefeu windows ?
        > Télécharge Zone Alarme, en cas de problème
        > Télécharge Ccleaner, si besoin est tu trouveras des Tutoriaux ici,
        ici et là
        0
        1. je t'envoie le rapport d'avg
          ---------------------------------------------------------
          AVG Anti-Spyware - Rapport d'analyse
          ---------------------------------------------------------

          + Créé à: 07:57:54 08/12/2007

          + Résultat de l'analyse:

          C:\Documents and Settings\laurence\Cookies\laurence@2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@himedia.112.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@adtech[2].txt -> TrackingCookie.Adtech : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CA2D7LG3.txt -> TrackingCookie.Advertising : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAA3FYF6.txt -> TrackingCookie.Advertising : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAHZMUQB.txt -> TrackingCookie.Advertising : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAN8RMPK.txt -> TrackingCookie.Advertising : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAOJNJ72.txt -> TrackingCookie.Advertising : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAOL4B1L.txt -> TrackingCookie.Advertising : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAPQ2DBR.txt -> TrackingCookie.Advertising : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAV4APPV.txt -> TrackingCookie.Advertising : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAYC1TZF.txt -> TrackingCookie.Advertising : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@advertising[1].txt -> TrackingCookie.Advertising : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@advertising[2].txt -> TrackingCookie.Advertising : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@advertising[4].txt -> TrackingCookie.Advertising : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@atdmt[2].txt -> TrackingCookie.Atdmt : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CA2KWOO5.txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CA6OOOH9.txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CA74GM9D.txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CA7BW6D7.txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAF21FKW.txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAGA203L.txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAHSAA7E.txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAL3M81Y.txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAPIF7KC.txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@bluestreak[1].txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@bluestreak[2].txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@bluestreak[4].txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@doubleclick[1].txt -> TrackingCookie.Doubleclick : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CA4AYJD9.txt -> TrackingCookie.Euroclick : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CA6OHIHG.txt -> TrackingCookie.Euroclick : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAF85G77.txt -> TrackingCookie.Euroclick : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAG5V26T.txt -> TrackingCookie.Euroclick : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@mediaplex[1].txt -> TrackingCookie.Mediaplex : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CA0GZSPA.txt -> TrackingCookie.Netflame : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CA0K7HQ9.txt -> TrackingCookie.Netflame : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAL2YQNW.txt -> TrackingCookie.Netflame : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAPZPJF5.txt -> TrackingCookie.Netflame : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAVWIBH0.txt -> TrackingCookie.Netflame : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@ssl-hints.netflame[1].txt -> TrackingCookie.Netflame : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@ssl-hints.netflame[2].txt -> TrackingCookie.Netflame : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CA0WGGAM.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CA0Z1KYA.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CA160JO8.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CA1SR5N6.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CA2VXVZZ.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CA3WFA8J.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CA40S1ZS.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CA5WLKPY.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CA67KK1W.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CA6RWGFK.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CA8INRJU.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAAQL2DG.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAARPDDB.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CADKC311.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAHP9JIZ.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAJ3XEOV.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAJSHTNR.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAKK0HTD.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAMXW12N.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CANHEETE.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAO54X85.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CARFWZ7S.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CARM3JBY.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CASPII2I.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAW6PMT9.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAXY9E7C.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@bs.serving-sys[2].txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@serving-sys[1].txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@serving-sys[2].txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@serving-sys[4].txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CA0UG0N9.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CA2RZT55.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CA3GY77B.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CA4W0RE7.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CA7J3HGT.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CA7S3LJD.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CA8EES37.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CA8US135.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAEPUD9T.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAF4ZKSB.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAK84NXE.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAO4EH3V.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAOWBMJS.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAQQ7DXZ.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAR1VYDF.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAS352YN.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAVJRPOF.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAWTBO5S.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAYV3QLH.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAZPGFPE.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@smartadserver[1].txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@smartadserver[2].txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@smartadserver[4].txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@tradedoubler[3].txt -> TrackingCookie.Tradedoubler : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CA2VXAOC.txt -> TrackingCookie.Weborama : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CA3KI9MJ.txt -> TrackingCookie.Weborama : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@CAYR5OHB.txt -> TrackingCookie.Weborama : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@weborama[1].txt -> TrackingCookie.Weborama : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@weborama[2].txt -> TrackingCookie.Weborama : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@weborama[3].txt -> TrackingCookie.Weborama : Aucune action entreprise.
          C:\Documents and Settings\laurence\Cookies\laurence@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Aucune action entreprise.

          Fin du rapport

          et merci de ton aide
          0
        2. je n'ai pas trouver l'onglet erreur dans ccleaner mais bon pour le reste j'ai bien tout suivie tes instruction et je t'envoie mon rapport hijackthis après redemarrage de mon pc.
          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 08:39:14, on 08/12/2007
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16544)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\csrss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Windows Defender\MsMpEng.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\ZoneLabs\vsmon.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\guard.exe
          C:\WINDOWS\System32\FTRTSVC.exe
          C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          C:\Program Files\Spyware Doctor\svcntaux.exe
          C:\Program Files\Spyware Doctor\swdsvc.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Spyware Doctor\SDTrayApp.exe
          C:\WINDOWS\system32\wdfmgr.exe
          C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
          C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
          C:\WINDOWS\system32\RunDll32.exe
          C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
          C:\Program Files\Windows Defender\MSASCui.exe
          C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\avgas.exe
          C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
          C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
          C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
          C:\Program Files\Messenger\msmsgs.exe
          C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
          C:\Program Files\Google\Google Updater\GoogleUpdater.exe
          C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
          C:\PROGRA~1\Wanadoo\ComComp.exe
          C:\PROGRA~1\Wanadoo\Toaster.exe
          C:\PROGRA~1\Wanadoo\Inactivity.exe
          C:\PROGRA~1\Wanadoo\PollingModule.exe
          C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
          C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
          C:\WINDOWS\System32\alg.exe
          C:\PROGRA~1\Wanadoo\Watch.exe
          C:\Program Files\Internet Explorer\IEXPLORE.EXE
          C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
          C:\WINDOWS\system32\wbem\wmiprvse.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
          R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - (no file)
          R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
          O2 - BHO: (no name) - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - (no file)
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
          O3 - Toolbar: (no name) - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - (no file)
          O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
          O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
          O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
          O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
          O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
          O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
          O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
          O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\avgas.exe" /minimized
          O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
          O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
          O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
          O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Global Startup: AVG Anti-Spyware 7.5
          O4 - Global Startup: BTTray.lnk = ?
          O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
          O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
          O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
          O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
          O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
          O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\guard.exe
          O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
          O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
          O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
          O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
          O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XIIc\Win32\RpcDataSrv.exe
          O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XIIc\RpcSandraSrv.exe
          O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
          O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
          O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
          O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
          O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
          0
      4. Salut,

        Oui MessengerSkinner a encore frappé....avec ses fichiers .dat

        0
        1. j'ai fait ce que jfk avait noté pour navilog option 2 mais après scan avec bit defender navipro etait toujours là oh rage et desespoir
          pour ton message dlld je n'ai pas les programmes que tu m'indiques dans ajout/suppression de programme. J'ai juste window live installer et window live messenger.
          Je suis un peu desesperer et compte sur vous pour votre aide. Merci de rester dans la chasse comme tu dis.
          0
      5. virgoginie,

        Peux-tu te rendre sur ce site virustotal ou virusscan.jotti et faire analyser les fichiers suivants (s'ils existent encore) :
        0
        1. J'ai un peu du mal avec ces programmes et je n'arrive pas a vous envoyer le rapport mais quand je scan msn messenger il apparait que fileAdvisor Low threat detected
          0
        2. @virgoginieOk pour les fichiers où il met 'no found' ou rien, n'envoie pas de rapport.

          Pour les autres (attends bien qu'il est terminé l'analyse) :
          puis :
          0
      6. Contributeur sécurité
        virustotal tres bien pour analyser des fichiers précis
        0
        1. jfkpresident,

          je trouve le deuxième rappot navilog pas très bavard...
          On pourrait recommancer l'étape de détection (1), qu'en penses-tu ?
          0
        2. @Utilisateur anonymedesolé, obligé de reprendre mes occupation de maman, je reviens lundi soir pour voir si vous voulez bien encore m'aider. Merci pour votre patience et gentillesse a lundi si vous le voulez bien donc
          0
        3. Contributeur sécurité
          @Utilisateur anonymece serait préférable effectivement
          0
      7. Bonsoir, bonsoir.....

        peux-tu refaire le poste 2 stp.

        télécharge navilog:http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
        fais l'option 1 puis copie/colle ton rapport ici
        ne fais pas l'option 2 sans avis!
        0
        1. Search Navipromo version 3.3.6 commencé le 10/12/2007 à 22:13:24,59

          !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
          !!! Postez ce rapport sur le forum pour le faire analyser !!!
          !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

          Outil exécuté depuis C:\Program Files\navilog1
          Mise à jour le 14.11.2007 à 18h00 par IL-MAFIOSO

          Microsoft Windows XP [version 5.1.2600]
          Internet Explorer : 7.0.5730.13

          *** Recherche Programmes installés ***

          *** Recherche dossiers dans C:\WINDOWS ***

          *** Recherche dossiers dans C:\Program Files ***

          *** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***

          *** Recherche dossiers dans C:\Documents and Settings\laurence\Application Data ***

          *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

          *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
          pour + d'infos : http://www.gmer.net

          Aucun fichier trouvé dans :

          - C:\WINDOWS\system32
          - C:\DOCUME~1\LAURENCE\LOCALS~1\APPLIC~1

          *** Recherche avec GenericNaviSearch ***
          !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
          !!! A vérifier impérativement avant toute suppression manuelle !!!

          * Recherche dans C:\WINDOWS\system32 *

          Fichiers suspects :

          * Recherche dans C:\DOCUME~1\LAURENCE\LOCALS~1\APPLIC~1 *

          *** Recherche fichiers ***

          *** Recherche clés spécifiques dans le Registre ***

          *** Module de Recherche complémentaire ***
          (Recherche fichiers spécifiques)

          1)Recherche fichiers connus:

          2)Recherche Heuristique :

          3)Recherche Certificats :

          Certificat Egroup absent !

          *** Analyse terminée le 10/12/2007 à 22:14:44,14 ***
          0
      8. Contributeur sécurité
        une fois de plus pas tres bavard ce rapport
        0
        1. En effet mais l'ordi semble sain,
          0
          1. oui, toujours - analyser avec bitdefender
            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 22:53:29, on 10/12/2007
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16544)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\csrss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Windows Defender\MsMpEng.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\ZoneLabs\vsmon.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\guard.exe
            C:\WINDOWS\System32\FTRTSVC.exe
            C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            C:\Program Files\Spyware Doctor\svcntaux.exe
            C:\Program Files\Spyware Doctor\swdsvc.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\wdfmgr.exe
            C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
            C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
            C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\System32\alg.exe
            C:\Program Files\Spyware Doctor\SDTrayApp.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            C:\WINDOWS\system32\RunDll32.exe
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\avgas.exe
            C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
            C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
            C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
            C:\Program Files\Messenger\msmsgs.exe
            C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
            C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
            C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
            C:\Program Files\Google\Google Updater\GoogleUpdater.exe
            C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
            C:\PROGRA~1\Wanadoo\ComComp.exe
            C:\PROGRA~1\Wanadoo\Toaster.exe
            C:\PROGRA~1\Wanadoo\Inactivity.exe
            C:\PROGRA~1\Wanadoo\PollingModule.exe
            C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
            C:\PROGRA~1\Wanadoo\Watch.exe
            C:\Program Files\Internet Explorer\IEXPLORE.EXE
            C:\WINDOWS\system32\msiexec.exe
            C:\Program Files\Windows Live\installer\WLSetupSvc.exe
            C:\Program Files\Windows Live\Messenger\usnsvc.exe
            C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
            C:\WINDOWS\system32\wbem\wmiprvse.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
            R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - (no file)
            R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
            O2 - BHO: (no name) - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - (no file)
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
            O3 - Toolbar: (no name) - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - (no file)
            O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
            O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
            O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
            O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
            O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
            O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
            O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\avgas.exe" /minimized
            O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
            O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
            O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
            O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
            O4 - Global Startup: AVG Anti-Spyware 7.5
            O4 - Global Startup: BTTray.lnk = ?
            O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
            O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
            O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
            O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
            O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
            O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
            O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
            O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
            O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\guard.exe
            O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
            O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
            O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
            O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
            O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
            O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XIIc\Win32\RpcDataSrv.exe
            O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XIIc\RpcSandraSrv.exe
            O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
            O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
            O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
            O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
            O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
            0
        2. Re,

          pour info
          0
          1. bonjour et encore merci pour ton aide je ne faire que ceci, mais bon voici mon rapport hijackthis après avoir suivie toutes tes consignes
            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 10:51:39, on 11/12/2007
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16544)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\csrss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Windows Defender\MsMpEng.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\ZoneLabs\vsmon.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\guard.exe
            C:\WINDOWS\System32\FTRTSVC.exe
            C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            C:\Program Files\Spyware Doctor\svcntaux.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Spyware Doctor\swdsvc.exe
            C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            C:\WINDOWS\system32\RunDll32.exe
            C:\Program Files\Spyware Doctor\SDTrayApp.exe
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\avgas.exe
            C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
            C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
            C:\WINDOWS\system32\svchost.exe
            C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
            C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
            C:\Program Files\Messenger\msmsgs.exe
            C:\WINDOWS\system32\wdfmgr.exe
            C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
            C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
            C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
            C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
            C:\Program Files\Google\Google Updater\GoogleUpdater.exe
            C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
            C:\PROGRA~1\Wanadoo\ComComp.exe
            C:\PROGRA~1\Wanadoo\Toaster.exe
            C:\PROGRA~1\Wanadoo\Inactivity.exe
            C:\PROGRA~1\Wanadoo\PollingModule.exe
            C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
            C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
            C:\WINDOWS\System32\alg.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\PROGRA~1\Wanadoo\Watch.exe
            C:\Program Files\Internet Explorer\IEXPLORE.EXE
            C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
            C:\WINDOWS\system32\wbem\wmiprvse.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
            O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
            O2 - BHO: (no name) - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - (no file)
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
            O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
            O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
            O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
            O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
            O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
            O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
            O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\avgas.exe" /minimized
            O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
            O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
            O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
            O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
            O4 - Global Startup: AVG Anti-Spyware 7.5
            O4 - Global Startup: BTTray.lnk = ?
            O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
            O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
            O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
            O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
            O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
            O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
            O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
            O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
            O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\guard.exe
            O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
            O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
            O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
            O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
            O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
            O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XIIc\Win32\RpcDataSrv.exe
            O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XIIc\RpcSandraSrv.exe
            O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
            O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
            O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
            O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
            O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
            0
        3. Bonsoir,
          comment se comporte le PC?
          A+
          --
          0
          1. bonjour,
            il y a un leger mieux mais bitdefender me dit que maintenant il y 5 fichiers infestés par navipromo.
            0
        4. Re,
          JFK, si t'es encore là....

          > Essaye d'installer Antivir : ouvre ce lien, lis le tuto, télécharge Antivir.
          Tu peux aussi télecharger Antivir ICI.

          > télécharge GenProc http://www.alt-shift-return.org/Info/Fichiers/GenProc.zip sur ton bureau
          0
          1. Contributeur sécurité
            je suis encore la .
            fais ce que te dit dlld post 45 et je jetterai un coup d'oeil sur les rapports;
            0
          2. re, je n'ai plus accés à ma messagerie mais je vous envoie le rapport antivir

            AntiVir PersonalEdition Classic
            Report file date: mercredi 12 décembre 2007 17:02

            Scanning for 971385 virus strains and unwanted programs.

            Licensed to: Avira AntiVir PersonalEdition Classic
            Serial number: 0000149996-ADJIE-0001
            Platform: Windows XP
            Windows version: (Service Pack 2) [5.1.2600]
            Username: SYSTEM
            Computer name: PCBUREAU

            Version information:
            BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
            AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
            AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
            LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
            LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
            ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
            ANTIVIR1.VDF : 7.0.0.0 1640448 Bytes 13/09/2007 14:26:55
            ANTIVIR2.VDF : 7.0.1.30 1575424 Bytes 30/11/2007 16:00:48
            ANTIVIR3.VDF : 7.0.1.80 214528 Bytes 12/12/2007 16:00:48
            AVEWIN32.DLL : 7.6.0.40 3064320 Bytes 12/12/2007 16:00:49
            AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
            AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
            AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
            AVPACK32.DLL : 7.3.0.15 360488 Bytes 03/08/2007 08:46:00
            AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
            AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
            AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
            NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
            RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
            RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
            SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21

            Configuration settings for the scan:
            Jobname..........................: Complete system scan
            Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
            Logging..........................: low
            Primary action...................: interactive
            Secondary action.................: ignore
            Scan master boot sector..........: off
            Scan boot sector.................: on
            Boot sectors.....................: C:,
            Scan memory......................: on
            Process scan.....................: on
            Scan registry....................: on
            Search for rootkits..............: off
            Scan all files...................: Intelligent file selection
            Scan archives....................: on
            Recursion depth..................: 20
            Smart extensions.................: on
            Macro heuristic..................: on
            File heuristic...................: medium

            Start of the scan: mercredi 12 décembre 2007 17:02

            The scan of running processes will be started
            Scan process 'avscan.exe' - '1' Module(s) have been scanned
            Scan process 'avcenter.exe' - '1' Module(s) have been scanned
            Scan process 'sched.exe' - '1' Module(s) have been scanned
            Scan process 'avgnt.exe' - '1' Module(s) have been scanned
            Scan process 'avguard.exe' - '1' Module(s) have been scanned
            Scan process 'iexplore.exe' - '1' Module(s) have been scanned
            Scan process 'WLLoginProxy.exe' - '1' Module(s) have been scanned
            Scan process 'emule.exe' - '1' Module(s) have been scanned
            Scan process 'Watch.exe' - '1' Module(s) have been scanned
            Scan process 'ALERTM~1.EXE' - '1' Module(s) have been scanned
            Scan process 'PollingModule.exe' - '1' Module(s) have been scanned
            Scan process 'Inactivity.exe' - '1' Module(s) have been scanned
            Scan process 'Toaster.exe' - '1' Module(s) have been scanned
            Scan process 'ComComp.exe' - '1' Module(s) have been scanned
            Scan process 'GestionnaireInternet.exe' - '1' Module(s) have been scanned
            Scan process 'NMIndexStoreSvr.exe' - '1' Module(s) have been scanned
            Scan process 'alg.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '0' Module(s) have been scanned
            Scan process 'NMIndexingService.exe' - '1' Module(s) have been scanned
            Scan process 'GoogleUpdater.exe' - '1' Module(s) have been scanned
            Scan process 'BTTray.exe' - '1' Module(s) have been scanned
            Scan process 'TeaTimer.exe' - '1' Module(s) have been scanned
            Scan process 'msmsgs.exe' - '1' Module(s) have been scanned
            Scan process 'TaskBarIcon.exe' - '1' Module(s) have been scanned
            Scan process 'NMBgMonitor.exe' - '1' Module(s) have been scanned
            Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
            Scan process 'zlclient.exe' - '0' Module(s) have been scanned
            Scan process 'bdagent.exe' - '1' Module(s) have been scanned
            Scan process 'avgas.exe' - '1' Module(s) have been scanned
            Scan process 'MSASCui.exe' - '1' Module(s) have been scanned
            Scan process 'rundll32.exe' - '1' Module(s) have been scanned
            Scan process 'atiptaxx.exe' - '1' Module(s) have been scanned
            Scan process 'livesrv.exe' - '0' Module(s) have been scanned
            Scan process 'vsserv.exe' - '0' Module(s) have been scanned
            Scan process 'xcommsvr.exe' - '0' Module(s) have been scanned
            Scan process 'wdfmgr.exe' - '1' Module(s) have been scanned
            Scan process 'SDTrayApp.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'explorer.exe' - '1' Module(s) have been scanned
            Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
            Scan process 'swdsvc.exe' - '1' Module(s) have been scanned
            Scan process 'svcntaux.exe' - '1' Module(s) have been scanned
            Scan process 'GoogleUpdaterService.exe' - '1' Module(s) have been scanned
            Scan process 'FTRTSVC.exe' - '1' Module(s) have been scanned
            Scan process 'guard.exe' - '0' Module(s) have been scanned
            Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
            Scan process 'vsmon.exe' - '0' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'btwdins.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'MsMpEng.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
            Scan process 'lsass.exe' - '1' Module(s) have been scanned
            Scan process 'services.exe' - '1' Module(s) have been scanned
            Scan process 'winlogon.exe' - '1' Module(s) have been scanned
            Scan process 'csrss.exe' - '1' Module(s) have been scanned
            Scan process 'smss.exe' - '1' Module(s) have been scanned
            53 processes with 53 modules were scanned

            Start scanning boot sectors:
            Boot sector 'C:\'
            [NOTE] No virus was found!

            Starting to scan the registry.
            The registry was scanned ( '29' files ).

            Starting the file scan:

            Begin scan in 'C:\'
            C:\pagefile.sys
            [WARNING] The file could not be opened!
            C:\Program Files\Navilog1\Backupnavi\ognvfnfmue.exe
            [DETECTION] Is the Trojan horse TR/Dropper.Gen
            [INFO] The file was deleted!
            C:\System Volume Information\_restore{09B1298D-ED77-4BB7-A8E9-8BCE24EA457C}\RP39\A0006949.exe
            [DETECTION] Is the Trojan horse TR/Dropper.Gen
            [INFO] The file was moved to '47900c87.qua'!
            C:\System Volume Information\_restore{09B1298D-ED77-4BB7-A8E9-8BCE24EA457C}\RP55\A0010866.exe
            [DETECTION] Is the Trojan horse TR/Dropper.Gen
            [INFO] The file was moved to '47900d1f.qua'!

            End of the scan: mercredi 12 décembre 2007 18:03
            Used time: 1:00:44 min

            The scan has been done completely.

            2703 Scanning directories
            60445 Files were scanned
            3 viruses and/or unwanted programs were found
            0 Files were classified as suspicious:
            1 files were deleted
            0 files were repaired
            2 files were moved to quarantine
            0 files were renamed
            1 Files cannot be scanned
            60442 Files not concerned
            852 Archives were scanned
            1 Warnings
            1 Notes
            0
          3. et voici lRapport GenProc 0.72 [1] effectué le 12/12/2007 à 18:11:18,31 - SystemRoot = C:\WINDOWS

            Dans CCleaner, clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures". Par la suite, laisse-le avec ses réglages par défaut. C'est tout.

            # Etape 1/ Télécharge :

            - Brute Force Uninstaller http://www.merijn.org/files/bfu.zip et décompresse-le dans un dossier propre à lui (C:\BFU)
            * Fais un clic droit de souris sur ce lien : http://perso.orange.fr/Chercheur-perso/scripts/toolbar.bfu
            et choisis "Enregistrer sous" (dans IE c'est "Enregistrer le lien sous..")
            afin de télécharger toolbar.bfu (de Chercheur), Type "Tous les fichiers". Sauvegarde dans le dossier créé (C:\BFU)

            ***** Copie ce qui suit dans un fichier texte et redémarre en mode sans échec comme indiqué ici https://docs.microsoft.com/en-us/?mfr=true (choisis ta session courante "laurence") *****

            # Etape 2/

            * Démarre le "Brute Force Uninstaller" en double-cliquant sur BFU.exe.
            Clique sur le petit dossier jaune, à la droite de la boîte "Scriptline to execute", et double-clique sur : Toolbar.bfu
            - Dans la boîte "Scriptline to execute", tu devrais maintenant voir ceci : C:\BFU\Toolbar.bfu
            Clique sur "Execute" et laisse-le faire son travail.
            Attendre que "Complete script execution" apparaîsse et clique sur OK. Clique exit pour fermer le programme BFU.
            Recommence encore une fois.

            # Etape 3/

            Lance CCleaner : "Nettoyeur"/"lancer le nettoyage" et c'est tout.

            # Etape 4/

            Redémarre normalement et poste :
            - Un nouveau rapport HijackThis, toutes fenêtres et applications fermées http://www.trendsecure.com/portal/en-US/threat_analytics/HiJackThis.exe ;

            Précise les difficultés que tu as eu (ce que tu n'as pas pu faire...) ainsi que l'évolution de la situation.
            e rapport genproc
            0
          4. @virgoginieje n'ai rien compris à ce dernier message. N'empêche que je n'ai plus accés à ma messagerie. Je suis en panique,
            0
        5. Bon bah voilà....
          0
          1. Contributeur sécurité
            coucou MP
            0
          2. oui, plus de mail, je suis obligés de passer par ootlook express sinon je ne vois pas ce que vous me répondez
            0
          3. @virgoginieRe,
            tu passais par quoi avant pour les mails ? (web, msn ?)
            --
            0
          4. @Utilisateur anonymej'ai résolue mon problème de messagerie mais pas celui de 'navipromo'
            0
          5. @virgoginieOK, je vais t'envoyer une recette pour forcer la désinstallation de la crasse cet PM
            0
        6. Re,

          > Télécharge sur ton bureau : Brute Force Uninstaller (= le programme) et le script bfu suivant : http://perso.orange.fr/Chercheur-perso/scripts/toolbar.bfu.
          NB : pour télécharger le script toolbar.bfu (de Chercheur), clique droit sur le lien ci-dessus et choisis < Entregistrer la cible sous > ou quelque chose comme ça (Enregistrer la cible du lien sous, enregistrer sous...), puis enregistre le script sur le bureau.
          0
          1. je n'arrive pas à télécharger le script. orange me dit que l'adresse est fausse ce qui fait que quand je télécharge bfu je n'ai pas la toolbar.bfu donc ne peut pas faire le programme en mode sans echec. Maintenant 6 files contaminé. Jusqu'au ca va aller ?
            0
        • 1
        • 2