Ouverture intempestives sur firefox

Résolu
Bonjour,
J'ai un souci depuis quelques temps.
J'utilise mozzilla firefox comme navigateur et j'ai constemment des fenetres de pub qui s'ouvre de maniere intempestives. j'ai fais pas mal de nettoyage mais rien n'y fait. mon ordi est un pentium 4 2.8Mghz avec 512 de ram. je fonctionne sous windows xp.je vous joint un hicjackthis en esperant que quelqu'un pourra m'aider a resoudre ce probleme...
Merci d'avance
Krazy1

Logfile of HijackThis v1.99.1
Scan saved at 20:43:04, on 19/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\atwtusb.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\yz dock 0.8.3 French English Japan German Spanish + 37 Docklets\YzDock.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\WINDOWS\system32\TBLMOUSE.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Windows\System32\wsaupdater.exe,
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMax] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [atwtusb] atwtusb.exe beta
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Raccourci vers YzDock.lnk = C:\Program Files\yz dock 0.8.3 French English Japan German Spanish + 37 Docklets\YzDock.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {317153FE-B7FB-419B-AC87-0B2EC97D7A04} (VB2S ActiveX Control) - http://www.subdo.com/activex/vb2s.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - https://driveragent.com/files/driveragent.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: CleanService - Unknown owner - C:\Program Files\StompSoft\Digital File Shredder Pro\CleanService.exe (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\Win32\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\RpcSandraSrv.exe
O23 - Service: Steganos Live Encryption Engine 8.1 [Service] (SLEE_81_SERVICE) - Unknown owner - C:\WINDOWS\system32\SLEE81.exe (file missing)
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
Configuration: Windows XP
Firefox 2.0.0.9

15 réponses

  1. Contributeur sécurité
    Relance HijackThis, choisis "do a scan only" coche la case devant les lignes ci-dessous et clic en bas sur "fix checked".

    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Windows\System32\wsaupdater.exe,

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)

    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"

    O4 - HKLM\..\Run: [atwtusb] atwtusb.exe beta

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

    O16 - DPF: {317153FE-B7FB-419B-AC87-0B2EC97D7A04} (VB2S ActiveX Control) - http://www.subdo.com/activex/vb2s.cab

    O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - https://driveragent.com/files/driveragent.cab

    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    ________________________

    Fais un clic droit sur ce lien : (IL-MAFIOSO)
    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
    Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
    Ensuite double clique sur navilog1.exe pour lancer l'installation.
    Une fois l'installation terminée, le fix s'exécutera automatiquement.
    (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

    Laisse-toi guider. Au menu principal, choisis 1 et valides.
    (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

    Patiente jusqu'au message :
    *** Analyse Termine le ..... ***
    Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
    Copie-colle l'intégralité dans une réponse. Referme le blocnote.
    Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)
    0
    1. Bonjour jlpjlp,
      j'ai suivi tes instructions.
      voici le resultat:
      Search Navipromo version 3.3.8 commencé le 20/12/2007 à 6:22:10,25

      !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
      !!! Postez ce rapport sur le forum pour le faire analyser !!!
      !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

      Outil exécuté depuis C:\Program Files\navilog1
      Mise à jour le 11.12.2007 à 18h00 par IL-MAFIOSO

      Microsoft Windows XP [version 5.1.2600]
      Internet Explorer : 7.0.5730.11
      Système de fichiers : NTFS

      Executé en mode normal

      *** Recherche Programmes installés ***

      WebMediaPlayer

      *** Recherche dossiers dans C:\WINDOWS ***

      *** Recherche dossiers dans C:\Program Files ***

      C:\Program Files\WebMediaPlayer trouvé !

      *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\APPLIC~1 ***

      *** Recherche dossiers dans "C:\Documents and Settings\krazy\application data" ***

      *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

      ...\WebMediaPlayer trouvé !

      *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
      pour + d'infos : http://www.gmer.net

      Fichier(s) caché(s) :

      C:\Documents and Settings\krazy\Local Settings\Application Data\zgcotxdimr.dat
      C:\Documents and Settings\krazy\Local Settings\Application Data\zgcotxdimr.exe
      C:\Documents and Settings\krazy\Local Settings\Application Data\zgcotxdimr_nav.dat
      C:\Documents and Settings\krazy\Local Settings\Application Data\zgcotxdimr_navps.dat

      *** Recherche avec GenericNaviSearch ***
      !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
      !!! A vérifier impérativement avant toute suppression manuelle !!!

      * Recherche dans C:\WINDOWS\system32 *

      * Recherche dans "C:\Documents and Settings\krazy\local settings\application data" *

      Fichiers trouvés :

      zgcotxdimr.exe trouvé !

      *** Recherche fichiers ***

      C:\DOCUME~1\ALLUSE~1\Bureau\WebMediaPlayer.lnk trouvé !
      C:\WINDOWS\tmlpcert2007 trouvé !
      C:\WINDOWS\system32\nvs2.inf trouvé !

      *** Recherche clés spécifiques dans le Registre ***

      HKEY_CURRENT_USER\Software\Lanconfig trouvé !

      *** Module de Recherche complémentaire ***
      (Recherche fichiers spécifiques)

      1)Recherche nouveaux fichiers Instant Access :

      2)Recherche Heuristique :

      * Dans C:\WINDOWS\system32 :

      * Dans "C:\Documents and Settings\krazy\local settings\application data" :

      zgcotxdimr.dat trouvé !

      3)Recherche Certificats :

      Certificat Egroup trouvé !

      4)Recherche fichiers connus :

      *** Analyse terminée le 20/12/2007 à 6:29:42,53 ***
      Je vais m'absenter quelques jours donc je risque de ne pas repondre rapidement mais en tout cas merci pour la rapidite de ta reponse et pour ton aide...ce forum est super
      0
      1. Contributeur sécurité
        = Lance navilog1
        = Cette fois-ci choisi l'option 2
        = Navilog va faire le nettoyage.. patient jusqu'à ce qui soit marqué *** Nettoyage Termine le ..... ***
        = Un rapport va être génrer sur ton C:\ qui sera en option 2
        Note: le bureau disparaît

        = colle le contenu du rapport de navilog (qui est en option2)

        PS:Si ton bureau ne réapparait pas, fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.
        Puis rends-toi à l'onglet "processus". Clique en haut à gauche sur fichiers et choisis "exécuter"
        Tape explorer et valide. Celà te fera apparaitre ton bureau.

        ______________________

        colle le rapport d'un scan en ligne
        avec un des suivants:

        bitdefender en ligne :
        http://www.bitdefender.fr/scan_fr/scan8/ie.html

        Panda en ligne :
        http://pandasoftware.fr

        secuser en ligne :
        http://www.secuser.com/outils/antivirus.htm

        scan en ligne firefox

        https://www.trendmicro.com/fr_fr/business.html

        ______________________

        puis recolle un rapport hiajckhtis et dis tes problemes actuels
        0
        1. Bonjour,
          Desole pour le retard...je n'etais pas chez moi...!
          voici le resultat de l'analyse navilog:
          Clean Navipromo version 3.3.8 commencé le 24/12/2007 à 19:45:37,57

          Outil exécuté depuis C:\Program Files\navilog1
          Mise à jour le 11.12.2007 à 18h00 par IL-MAFIOSO

          Microsoft Windows XP [version 5.1.2600]
          Internet Explorer : 7.0.5730.11
          Système de fichiers : NTFS

          Mode suppression automatique

          *** Creation backups fichiers trouvés par Catchme ***

          Copie vers "C:\Program Files\navilog1\Backupnavi"

          Copie C:\Documents and Settings\krazy\Local Settings\Application Data\zgcotxdimr.dat réalisée avec succès !
          Copie C:\Documents and Settings\krazy\Local Settings\Application Data\zgcotxdimr.exe réalisée avec succès !
          Copie C:\Documents and Settings\krazy\Local Settings\Application Data\zgcotxdimr_nav.dat réalisée avec succès !
          Copie C:\Documents and Settings\krazy\Local Settings\Application Data\zgcotxdimr_navps.dat réalisée avec succès !

          *** Suppression des fichiers trouvés avec Catchme ***

          C:\Documents and Settings\krazy\Local Settings\Application Data\zgcotxdimr.dat supprimé !
          C:\Documents and Settings\krazy\Local Settings\Application Data\zgcotxdimr.exe supprimé !
          C:\Documents and Settings\krazy\Local Settings\Application Data\zgcotxdimr_nav.dat supprimé !
          C:\Documents and Settings\krazy\Local Settings\Application Data\zgcotxdimr_navps.dat supprimé !

          ** 2ème passage avec résultats Catchme **

          * Dans C:\WINDOWS\system32 *

          C:\WINDOWS\prefetch\zgcotxdimr*.pf trouvé !
          Copie C:\WINDOWS\prefetch\zgcotxdimr*.pf réalisée avec succès !
          C:\WINDOWS\prefetch\zgcotxdimr*.pf supprimé !

          * Dans "C:\Documents and Settings\krazy\local settings\application data" *

          *** Suppression avec sauvegardes résultats GenericNaviSearch ***

          * Suppression dans C:\WINDOWS\System32 *

          * Suppression dans "C:\Documents and Settings\krazy\local settings\application data" *

          *** Suppression dossiers dans C:\WINDOWS ***

          *** Suppression dossiers dans C:\Program Files ***

          *** Suppression dossiers dans C:\DOCUME~1\ALLUSE~1\APPLIC~1 ***

          *** Suppression dossiers dans "C:\Documents and Settings\krazy\application data" ***

          *** Suppression dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

          *** Suppression fichiers ***

          C:\WINDOWS\system32\nvs2.inf supprimé !

          *** Suppression fichiers temporaires ***

          Nettoyage contenu C:\WINDOWS\Temp effectué !
          Nettoyage contenu C:\Documents and Settings\krazy\local settings\Temp effectué !

          *** Traitement Recherche complémentaire ***
          (Recherche fichiers spécifiques)

          1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

          2)Recherche, création sauvegardes et suppression Heuristique :

          * Dans C:\WINDOWS\system32 *

          * Dans "C:\Documents and Settings\krazy\local settings\application data" *

          phlmkf.dat trouvé !
          Copie phlmkf.dat réalisée avec succès !
          phlmkf.dat supprimé !

          phlmkf_nav.dat trouvé !
          Copie phlmkf_nav.dat réalisée avec succès !
          phlmkf_nav.dat supprimé !

          phlmkf.exe trouvé !
          Copie phlmkf.exe réalisée avec succès !
          phlmkf.exe supprimé !

          phlmkf_navps.dat trouvé !
          Copie phlmkf_navps.dat réalisée avec succès !
          phlmkf_navps.dat supprimé !

          C:\WINDOWS\prefetch\phlmkf*.pf trouvé !
          Copie C:\WINDOWS\prefetch\phlmkf*.pf réalisée avec succès !
          C:\WINDOWS\prefetch\phlmkf*.pf supprimé !

          *** Sauvegarde du Registre vers dossier Backupnavi ***

          sauvegarde du Registre réalisée avec succès !

          *** Nettoyage Registre ***

          Nettoyage Registre Ok

          *** Certificats ***

          Certificat Egroup supprimé !

          *** Nettoyage terminé le 24/12/2007 à 19:53:48,01 ***

          et le log hijackthis:
          Logfile of HijackThis v1.99.1
          Scan saved at 19:58:11, on 24/12/2007
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16574)

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\a-squared Free\a2service.exe
          C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
          C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
          C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          C:\PROGRA~1\MICROS~3\rapimgr.exe
          C:\Program Files\yz dock 0.8.3 French English Japan German Spanish + 37 Docklets\YzDock.exe
          C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
          C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
          C:\Program Files\HijackThis\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Windows\System32\wsaupdater.exe,
          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
          O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
          O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
          O4 - HKLM\..\Run: [SoundMax] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
          O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          O4 - Startup: Raccourci vers YzDock.lnk = C:\Program Files\yz dock 0.8.3 French English Japan German Spanish + 37 Docklets\YzDock.exe
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
          O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
          O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
          O11 - Options group: [INTERNATIONAL] International*
          O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
          O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
          O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
          O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
          O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
          O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
          O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab
          O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
          O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
          O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
          O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
          O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
          O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
          O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
          O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
          O23 - Service: CleanService - Unknown owner - C:\Program Files\StompSoft\Digital File Shredder Pro\CleanService.exe (file missing)
          O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
          O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\Win32\RpcDataSrv.exe
          O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\RpcSandraSrv.exe
          O23 - Service: Steganos Live Encryption Engine 8.1 [Service] (SLEE_81_SERVICE) - Unknown owner - C:\WINDOWS\system32\SLEE81.exe (file missing)
          O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

          pour le moment les fenetres ne s'ouvrent plus.
          J'ai aussi fait un scan en ligne et des infrctions ont ete trouvé;mais j'ai oublie de garder le rapport...!
          en tout cas pour le moment ca a l'air de fonctionner...
          merci pour tout...et bonnes fetes de fin d'annee
          krazy
          0
          1. Contributeur sécurité
            analyse ces deux fichiers sur virus total et colleemoi les rapports: https://www.virustotal.com/gui/

            C:\WINDOWS\system32\userinit.exe

            C:\Windows\System32\wsaupdater.exe
            0
            1. Bonjour,
              Voici le rapport dd fichier C:\WINDOWS\system32\userinit.exe :

              File userinit.exe received on 07.11.2006 07:25:02 (CET)
              Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
              Result: 1/28 (3.58%)
              Loading server information...
              Your file is queued in position: ___.
              Estimated start time is between ___ and ___ .
              Do not close the window until scan is complete.
              The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
              If you are waiting for more than five minutes you have to resend your file.
              Your file is being scanned by VirusTotal in this moment,
              results will be shown as they're generated.
              Compact Compact
              Print results Print results
              Your file has expired or does not exists.
              Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.

              You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
              Email:

              Antivirus Version Last Update Result
              AVG - - -
              AntiVir - - -
              Antivir7 - - -
              Authentium - - -
              Avast - - -
              BitDefender - - -
              CAT-QuickHeal - - -
              ClamAV - - -
              DrWeb - - -
              Ewido - - suspicious
              F-Prot - - -
              F-Prot4 - - -
              Fortinet - - -
              Ikarus - - -
              Kaspersky - - -
              McAfee - - -
              Microsoft - - -
              NOD32v2 - - -
              Norman - - -
              Panda - - -
              Sophos - - -
              Symantec - - -
              TheHacker - - -
              UNA - - -
              VBA32 - - -
              VirusBuster - - -
              eTrust-InoculateIT - - -
              eTrust-Vet - - -
              Additional information
              MD5: 84717891f0734c611721f56c60b5fbc3

              je n'ai pas trouvé le second...C:\Windows\System32\wsaupdater.exe...!!!?!

              l
              0
              1. voici le rapport de sacn avec antivir :

                AntiVir PersonalEdition Classic
                Report file date: mercredi 26 décembre 2007 17:30

                Scanning for 992538 virus strains and unwanted programs.

                Licensed to: Avira AntiVir PersonalEdition Classic
                Serial number: 0000149996-ADJIE-0001
                Platform: Windows XP
                Windows version: (Service Pack 2) [5.1.2600]
                Username: krazy
                Computer name: KRAZY-PCSSD3UIO

                Version information:
                BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
                AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
                AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
                LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
                LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
                ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
                ANTIVIR1.VDF : 7.0.1.95 3367424 Bytes 14/12/2007 16:28:12
                ANTIVIR2.VDF : 7.0.1.96 2048 Bytes 14/12/2007 16:28:12
                ANTIVIR3.VDF : 7.0.1.156 284672 Bytes 26/12/2007 16:28:12
                AVEWIN32.DLL : 7.6.0.46 3084800 Bytes 26/12/2007 16:28:13
                AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
                AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
                AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
                AVPACK32.DLL : 7.6.0.2 360488 Bytes 26/12/2007 16:28:13
                AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
                AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
                AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
                NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
                RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
                RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
                SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21

                Configuration settings for the scan:
                Jobname..........................: Local Drives
                Configuration file...............: c:\program files\avira\antivir personaledition classic\alldrives.avp
                Logging..........................: low
                Primary action...................: interactive
                Secondary action.................: ignore
                Scan master boot sector..........: off
                Scan boot sector.................: on
                Boot sectors.....................: H:,
                Scan memory......................: on
                Process scan.....................: on
                Scan registry....................: on
                Search for rootkits..............: off
                Scan all files...................: Intelligent file selection
                Scan archives....................: on
                Recursion depth..................: 20
                Smart extensions.................: on
                Macro heuristic..................: on
                File heuristic...................: medium

                Start of the scan: mercredi 26 décembre 2007 17:30

                The scan of running processes will be started
                Scan process 'avscan.exe' - '1' Module(s) have been scanned
                Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                Scan process 'sched.exe' - '1' Module(s) have been scanned
                Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                Scan process 'avguard.exe' - '1' Module(s) have been scanned
                Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
                Scan process 'CLI.exe' - '1' Module(s) have been scanned
                Scan process 'CLI.exe' - '1' Module(s) have been scanned
                Scan process 'alg.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'rapimgr.exe' - '1' Module(s) have been scanned
                Scan process 'SMAgent.exe' - '1' Module(s) have been scanned
                Scan process 'YzDock.exe' - '1' Module(s) have been scanned
                Scan process 'wcescomm.exe' - '1' Module(s) have been scanned
                Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
                Scan process 'jusched.exe' - '1' Module(s) have been scanned
                Scan process 'CLI.exe' - '1' Module(s) have been scanned
                Scan process 'SMax4.exe' - '1' Module(s) have been scanned
                Scan process 'SMax4PNP.exe' - '1' Module(s) have been scanned
                Scan process 'a2service.exe' - '1' Module(s) have been scanned
                Scan process 'explorer.exe' - '1' Module(s) have been scanned
                Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
                Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
                Scan process 'lsass.exe' - '1' Module(s) have been scanned
                Scan process 'services.exe' - '1' Module(s) have been scanned
                Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                Scan process 'csrss.exe' - '1' Module(s) have been scanned
                Scan process 'smss.exe' - '1' Module(s) have been scanned
                34 processes with 34 modules were scanned

                Start scanning boot sectors:
                Boot sector 'C:\'
                [NOTE] No virus was found!
                Boot sector 'D:\'
                [NOTE] No virus was found!
                Boot sector 'I:\'
                [NOTE] No virus was found!
                Boot sector 'A:\'
                [NOTE] In the drive 'A:\' no data medium is inserted!

                Starting to scan the registry.
                The registry was scanned ( '35' files ).

                Starting the file scan:

                Begin scan in 'C:\'
                C:\pagefile.sys
                [WARNING] The file could not be opened!
                C:\Program Files\Panda Security\NanoScan\Engine\psnflg.dll
                [DETECTION] Is the Trojan horse TR/Agent.bux.1
                [INFO] The file was moved to '47e08874.qua'!
                C:\Program Files\WinISO\WinISO.exe
                [DETECTION] Is the Trojan horse TR/Crypt.U.Gen
                [INFO] The file was moved to '47e088fc.qua'!
                C:\System Volume Information\_restore{FDDE16BD-C162-4CC9-AE82-290E08D1A9D0}\RP2\A0001350.dll
                [DETECTION] Is the Trojan horse TR/Agent.bux.1
                [INFO] The file was moved to '47a28965.qua'!
                C:\System Volume Information\_restore{FDDE16BD-C162-4CC9-AE82-290E08D1A9D0}\RP2\A0001351.exe
                [DETECTION] Is the Trojan horse TR/Crypt.U.Gen
                [INFO] The file was moved to '47a2896c.qua'!
                Begin scan in 'D:\' <D>
                Begin scan in 'I:\' <I>
                Begin scan in 'A:\'
                Search path A:\ could not be opened!
                Le volume ne contient pas de système de fichiers connu. Vérifiez si tous les pilotes de système
                de fichiers nécessaires sont chargés et si le volume n'est pas endommagé.

                Begin scan in 'E:\'
                Search path E:\ could not be opened!
                Le périphérique n'est pas prêt.

                Begin scan in 'F:\'
                Search path F:\ could not be opened!
                Le périphérique n'est pas prêt.

                Begin scan in 'H:\'
                Search path H:\ could not be opened!
                Le périphérique n'est pas prêt.

                End of the scan: mercredi 26 décembre 2007 18:29
                Used time: 59:16 min

                The scan has been done completely.

                7953 Scanning directories
                343038 Files were scanned
                4 viruses and/or unwanted programs were found
                0 Files were classified as suspicious:
                0 files were deleted
                0 files were repaired
                4 files were moved to quarantine
                0 files were renamed
                1 Files cannot be scanned
                343034 Files not concerned
                2221 Archives were scanned
                1 Warnings
                0 Notes
                0
                1. Contributeur sécurité
                  ok

                  vide ce qui est en quarantaine dans antivir,

                  _______________

                  désactive la restauration système pour purger les virus qui seraient dedans
                  puis redemarre
                  puis réactive là (dans DEMARRER puis TOUS LES PROGRAMMES puis ACCESSOIRE puis OUTILS SYSTEME puis RESTAURATION SYSTEME puis paramètre)

                  ______________

                  recolle un scan antivir et hijackthis et dis tes soucis actuels

                  a plus
                  0
                  1. voici les rapports :

                    AntiVir PersonalEdition Classic
                    Report file date: mercredi 26 décembre 2007 19:09

                    Scanning for 992538 virus strains and unwanted programs.

                    Licensed to: Avira AntiVir PersonalEdition Classic
                    Serial number: 0000149996-ADJIE-0001
                    Platform: Windows XP
                    Windows version: (Service Pack 2) [5.1.2600]
                    Username: SYSTEM
                    Computer name: KRAZY-PCSSD3UIO

                    Version information:
                    BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
                    AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
                    AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
                    LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
                    LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
                    ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
                    ANTIVIR1.VDF : 7.0.1.95 3367424 Bytes 14/12/2007 16:28:12
                    ANTIVIR2.VDF : 7.0.1.96 2048 Bytes 14/12/2007 16:28:12
                    ANTIVIR3.VDF : 7.0.1.156 284672 Bytes 26/12/2007 16:28:12
                    AVEWIN32.DLL : 7.6.0.46 3084800 Bytes 26/12/2007 16:28:13
                    AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
                    AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
                    AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
                    AVPACK32.DLL : 7.6.0.2 360488 Bytes 26/12/2007 16:28:13
                    AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
                    AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
                    AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
                    NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
                    RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
                    RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
                    SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21

                    Configuration settings for the scan:
                    Jobname..........................: Complete system scan
                    Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
                    Logging..........................: low
                    Primary action...................: interactive
                    Secondary action.................: ignore
                    Scan master boot sector..........: off
                    Scan boot sector.................: on
                    Boot sectors.....................: I:,
                    Scan memory......................: on
                    Process scan.....................: on
                    Scan registry....................: on
                    Search for rootkits..............: off
                    Scan all files...................: Intelligent file selection
                    Scan archives....................: on
                    Recursion depth..................: 20
                    Smart extensions.................: on
                    Macro heuristic..................: on
                    File heuristic...................: medium

                    Start of the scan: mercredi 26 décembre 2007 19:09

                    The scan of running processes will be started
                    Scan process 'avscan.exe' - '1' Module(s) have been scanned
                    Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                    Scan process 'msimn.exe' - '1' Module(s) have been scanned
                    Scan process 'CLI.exe' - '1' Module(s) have been scanned
                    Scan process 'CLI.exe' - '1' Module(s) have been scanned
                    Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
                    Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
                    Scan process 'alg.exe' - '1' Module(s) have been scanned
                    Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
                    Scan process 'YzDock.exe' - '1' Module(s) have been scanned
                    Scan process 'rapimgr.exe' - '1' Module(s) have been scanned
                    Scan process 'wcescomm.exe' - '1' Module(s) have been scanned
                    Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
                    Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                    Scan process 'jusched.exe' - '1' Module(s) have been scanned
                    Scan process 'CLI.exe' - '1' Module(s) have been scanned
                    Scan process 'SMax4.exe' - '1' Module(s) have been scanned
                    Scan process 'SMax4PNP.exe' - '1' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'SMAgent.exe' - '1' Module(s) have been scanned
                    Scan process 'sched.exe' - '1' Module(s) have been scanned
                    Scan process 'a2service.exe' - '1' Module(s) have been scanned
                    Scan process 'explorer.exe' - '1' Module(s) have been scanned
                    Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
                    Scan process 'avguard.exe' - '1' Module(s) have been scanned
                    Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
                    Scan process 'lsass.exe' - '1' Module(s) have been scanned
                    Scan process 'services.exe' - '1' Module(s) have been scanned
                    Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                    Scan process 'csrss.exe' - '1' Module(s) have been scanned
                    Scan process 'smss.exe' - '1' Module(s) have been scanned
                    37 processes with 37 modules were scanned

                    Start scanning boot sectors:
                    Boot sector 'C:\'
                    [NOTE] No virus was found!
                    Boot sector 'D:\'
                    [NOTE] No virus was found!
                    Boot sector 'I:\'
                    [NOTE] No virus was found!

                    Starting to scan the registry.
                    The registry was scanned ( '34' files ).

                    Starting the file scan:

                    Begin scan in 'C:\'
                    C:\pagefile.sys
                    [WARNING] The file could not be opened!
                    Begin scan in 'D:\' <D>
                    Begin scan in 'I:\' <I>

                    End of the scan: mercredi 26 décembre 2007 20:08
                    Used time: 59:47 min

                    The scan has been done completely.

                    7940 Scanning directories
                    342571 Files were scanned
                    0 viruses and/or unwanted programs were found
                    0 Files were classified as suspicious:
                    0 files were deleted
                    0 files were repaired
                    0 files were moved to quarantine
                    0 files were renamed
                    1 Files cannot be scanned
                    342571 Files not concerned
                    2223 Archives were scanned
                    1 Warnings
                    0 Notes

                    hijackthis :

                    Logfile of HijackThis v1.99.1
                    Scan saved at 20:19:18, on 26/12/2007
                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v7.00 (7.00.6000.16574)

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\Ati2evxx.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                    C:\WINDOWS\system32\Ati2evxx.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\Program Files\a-squared Free\a2service.exe
                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
                    C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
                    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
                    C:\PROGRA~1\MICROS~3\rapimgr.exe
                    C:\Program Files\yz dock 0.8.3 French English Japan German Spanish + 37 Docklets\YzDock.exe
                    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avscan.exe
                    C:\Program Files\Mozilla Firefox\firefox.exe
                    C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
                    C:\Program Files\HijackThis\HijackThis.exe

                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Windows\System32\wsaupdater.exe,
                    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
                    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
                    O4 - HKLM\..\Run: [SoundMax] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
                    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
                    O4 - Startup: Raccourci vers YzDock.lnk = C:\Program Files\yz dock 0.8.3 French English Japan German Spanish + 37 Docklets\YzDock.exe
                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
                    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
                    O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
                    O11 - Options group: [INTERNATIONAL] International*
                    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
                    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
                    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
                    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                    O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab
                    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
                    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
                    O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
                    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                    0
                    1. Contributeur sécurité
                      fix cette ligne

                      O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)

                      _____________

                      desisntalle navilog

                      si pas de problemes c'est bon

                      pour protéger gratos ton ordi

                      http://www.commentcamarche.net/telecharger/logiciel 4 securite

                      mettre un antivirus

                      AVAST en français ou ANTIVIR (en anglais mais très efficace)
                      https://www.malekal.com/avira-free-security-antivirus-gratuit/ (merci Malekal)
                      -------------
                      des anti-espions :
                      AD AWARE + SPYBOT + si tea timer non active de spybot: WINDOWS DEFENDER ou SPYWARE TERMINATOR

                      +/-
                      SPYWAREBLASTER pour immuniser le système contre vundo notamment mais en anglais (mais facile d'utilisation : il suffit de faire "update" pour mettre à jour tous les mois et ensuite" enable all protection" pour immuniser)...

                      Rq : spybot et ad-aware on sorti de nouvelles versions cette année vérifiez que vous avez la dernière version
                      --------
                      un pare feu :
                      celui de Windows ou mieux KERIO ou JETICO ou ZONE ALARM (mettre que le parefeu gratuit)

                      https://www.clubic.com/telecharger-fiche11071-sunbelt-personal-firewall-ex-kerio.html
                      https://manuelsdaide.com/contact/
                      http://www.open-files.com/forum/index.php?showtopic=29277
                      http://www.commentcamarche.net/telecharger/telecharger 157 zonealarm

                      -----------

                      CCLEANER pour effacer les traces de surf
                      0
                      1. ok c'est fait...ca a l'air d'aller...
                        Merci pour l'aide !
                        visiblement antivir a l'air plus performant qu'avast...?!?
                        0
                        1. Contributeur sécurité
                          oui antivir est mieux actuellement
                          0
                          1. Merci pour le temps que tu m'a consacré...
                            Bye
                            krazy
                            0
                            1. Contributeur sécurité
                              bonne continuation!
                              0