Pub intenpestive

Résolu
Bonjour a tous
Voila mon problème : depuis quelque mois j'ai certaines pubs (genre des pub de casino) qui n'arrete pas de s'afficher ainsi que les fenetres qui me font des analyses pour les spywares alors que j'ai rien demander et je n'arrive pas a men débarrasser , Merci a ceux qui pourront m'aider !!
Configuration: Windows XP
Firefox 2.0.0.8

62 réponses

Résumé de la discussion

Des publicités intempestives, notamment des publicités de casino, et des fenêtres d’analyse de spyware apparaissent sur Windows XP avec Firefox, malgré l’absence d’action de l’utilisateur. Des solutions préconisées incluent la mise à jour du navigateur et la désactivation de conflits entre antivirus, l’utilisation d’outils comme AVG Anti-Spyware et CCleaner, ainsi que l’analyse via HijackThis et Navilog1. Plusieurs conseils recommandent d’éviter les logiciels prétendument anti‑spyware et de privilégier des méthodes vérifiables, tout en gérant les programmes au démarrage et les extensions potentielles. En cas d’attaque persistante, certains auteurs suggèrent des scans hors ligne ou des nettoyages répétés après redémarrage en mode sans échec, afin d’éviter la réinjection.

Bobot (l’IA à votre service)
  1. tu cherche sur le net tu tape telecharger un anti pub et apres ca devrai aller si ca persiste regle bien ta barre de bloguage internet si tu ve plus d'info vien sur msn steve_27@hotmail.fr
    0
    1. Bonsoir ;)

      Ne télécharge surtout pas ces ' prétendu anti-spywares ' ignore-les.

      -----------------------------------------------------------------------------------------------

      Télécharge HJT

      Place le dans ' C:\programmes\ ' Une fois cela fait , merci de renommer le fichier ' Hijackthis.exe '(situé dans le dossier dans C:\ ) en HJT.exe

      Le chemin d'accés du programme doit être ressemblant à celui-ci : C:\Programme\Hijackthis\HJT.exe

      Puis lance-le et choisi l'option '' do a system scan and save a logfile '' et poste moi le rapport ( qui apparait sur le bloc-note )

      Tuto si tu n'y arrive pas : http://pageperso.aol.fr/balltrap34/demohijack.htm

      a+
      0
      1. Merci pour votre aide , voila mon rapport:

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 20:16:29, on 11/02/2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
        C:\Program Files\AVG Anti-Spyware 7.5\avgas.exe
        C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
        C:\Program Files\QuickTime\QTTask.exe
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
        C:\WINDOWS\system32\WTMKM.exe
        C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
        C:\Program Files\Softwin\BitDefender10\bdmcon.exe
        C:\Program Files\Softwin\BitDefender10\bdagent.exe
        C:\windows\system32\rlvknlg.exe
        C:\Program Files\Odebit Multimédia\V3\Odebit.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\Program Files\Save\Save.exe
        C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
        C:\Program Files\Xfire\xfire.exe
        C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
        C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
        C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\AVG Anti-Spyware 7.5\guard.exe
        C:\WINDOWS\eHome\ehRecvr.exe
        C:\WINDOWS\eHome\ehSched.exe
        C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        C:\Program Files\MSN Messenger\msnmsgr.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\PROGRA~1\Mozilla Firefox\firefox.exe
        C:\Program Files\SystemGuards.com\SystemGuards\sgScheduleService.exe
        C:\WINDOWS\system32\atwtusb.exe
        C:\WINDOWS\explorer.exe
        C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
        C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe
        C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
        C:\Program Files\Softwin\BitDefender10\vsserv.exe
        C:\Program Files\iPod\bin\iPodService.exe
        C:\WINDOWS\system32\dllhost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\MSN Messenger\usnsvc.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: Burn4Free Toolbar Helper - {60BF5EE3-0105-4858-AD98-17C19F86B042} - C:\Program Files\Burn4Free Toolbar\v3.3.0.0\Burn4Free_Toolbar.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
        O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
        O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
        O3 - Toolbar: Burn4Free Toolbar - {55FAF0F2-44D4-425F-B5F5-6B275B621EAB} - C:\Program Files\Burn4Free Toolbar\v3.3.0.0\Burn4Free_Toolbar.dll
        O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
        O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\AVG Anti-Spyware 7.5\avgas.exe" /minimized
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
        O4 - HKLM\..\Run: [MacrokeyManager] WTMKM.exe
        O4 - HKLM\..\Run: [System Guards] C:\Program Files\SystemGuards.com\SystemGuards\SysGuards.exe
        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
        O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg
        O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
        O4 - HKLM\..\Run: [RelevantKnowledge] C:\windows\system32\rlvknlg.exe -boot
        O4 - HKCU\..\Run: [Spyware Begone] C:\Documents and Settings\François\Mes documents\freescan.exe -FastScan
        O4 - HKCU\..\Run: [Odebit Multimedia V3 - Services] C:\Program Files\Odebit Multimédia\V3\Odebit.exe /info
        O4 - HKCU\..\Run: [WINSOS VERIFY] "C:\Program Files\WINSOS\WINSOS.EXE" MINI
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"
        O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
        O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe
        O4 - Global Startup: AOL 9.0 Icône AOL.lnk = C:\Program Files\AOL 9.0\aoltray.exe
        O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
        O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?7f2c1675c3464b3683293678f6b64b40
        O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?7f2c1675c3464b3683293678f6b64b40
        O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
        O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://www.cyber-infos.net/files/OnlineScan.cab
        O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
        O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
        O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
        O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
        O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\AVG Anti-Spyware 7.5\guard.exe
        O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
        O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
        O23 - Service: sgSchedulerService - Unknown owner - C:\Program Files\SystemGuards.com\SystemGuards\sgScheduleService.exe
        O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
        O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe
        O23 - Service: WTService - Unknown owner - C:\WINDOWS\system32\atwtusb.exe
        O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
        0
        1. Re,

          Met à jour IE -> https://support.microsoft.com/fr-fr/allproducts
          En effet les version 6 et antérieures , sont bourrées de failles de sécurité , le version 7 les corrigent en partie.

          Met à jour firefox ...

          Lance Firefox > ? > rechercher des mises à jour ( pour infos on est à la 2.0.0.12 )

          **********************************
          renomme Hijackthis STP

          **************

          Télécharge Navilog1

          et enregistre-le sur ton bureau.

          Ensuite double clique sur navilog1.exe pour lancer l'installation.
          Une fois l'installation terminée, le fix s'exécutera automatiquement.
          (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

          Laisse-toi guider. Au menu principal, choisis l'option 1

          -> Pendant le scan ton anti-virus risque de geuler , ne t'inquiete pas c'est normal ;)

          Patiente jusqu'au message :
          *** Analyse Termine le ..... ***

          Puis poste moi le rapport.

          ( rapport situé a la racine du disque -> C:\Fixnavi.txt )

          A+

          0
          1. Re , escuse moi pour le retard, tiens c'est le rapport :

            Search Navipromo version 3.4.4 commencé le 11/02/2008 à 20:49:45,51

            !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
            !!! Postez ce rapport sur le forum pour le faire analyser !!!
            !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

            Outil exécuté depuis C:\Program Files\navilog1
            Mise à jour le 10.02.2008 à 12h00 par IL-MAFIOSO

            Microsoft Windows XP [version 5.1.2600]
            Internet Explorer : 6.0.2900.2180
            Système de fichiers : NTFS

            Executé en mode normal

            *** Recherche Programmes installés ***

            WebMediaPlayer

            *** Recherche dossiers dans C:\WINDOWS ***

            *** Recherche dossiers dans C:\Program Files ***

            C:\Program Files\WebMediaPlayer trouvé !

            *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\APPLIC~1 ***

            *** Recherche dossiers dans "C:\Documents and Settings\François\applic~1" ***

            *** Recherche dossiers dans "C:\Documents and Settings\François\locals~1\applic~1" ***

            *** Recherche dossiers dans "C:\Documents and Settings\François\MENUDM~1\PROGRA~1" ***

            ...\WebMediaPlayer trouvé !

            *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

            ...\WebMediaPlayer trouvé !

            *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
            pour + d'infos : http://www.gmer.net

            Fichier(s) caché(s) :

            C:\Documents and Settings\François\Local Settings\Application Data\xrbijnmie.dat
            C:\Documents and Settings\François\Local Settings\Application Data\xrbijnmie.exe
            C:\Documents and Settings\François\Local Settings\Application Data\xrbijnmie_nav.dat
            C:\Documents and Settings\François\Local Settings\Application Data\xrbijnmie_navps.dat

            *** Recherche avec GenericNaviSearch ***
            !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
            !!! A vérifier impérativement avant toute suppression manuelle !!!

            * Recherche dans C:\WINDOWS\system32 *

            * Recherche dans "C:\Documents and Settings\François\locals~1\applic~1" *

            Fichiers trouvés :

            xrbijnmie.exe trouvé !

            *** Recherche fichiers ***

            C:\DOCUME~1\ALLUSE~1\Bureau\WebMediaPlayer.lnk trouvé !
            C:\WINDOWS\system32\nvs2.inf trouvé !

            *** Recherche clés spécifiques dans le Registre ***

            HKEY_CURRENT_USER\Software\Lanconfig trouvé !

            *** Module de Recherche complémentaire ***
            (Recherche fichiers spécifiques)

            1)Recherche nouveaux fichiers Instant Access :

            2)Recherche Heuristique :

            * Dans C:\WINDOWS\system32 :

            agtdeqtf.dat trouvé !
            agtdeqtf_nav.dat trouvé !
            agtdeqtf_navps.dat trouvé !

            * Dans "C:\Documents and Settings\François\locals~1\applic~1" :

            xrbijnmie.dat trouvé !

            3)Recherche Certificats :

            Certificat Egroup trouvé !

            4)Recherche fichiers connus :

            *** Analyse terminée le 11/02/2008 à 21:00:51,20 ***
            0
            1. Re ,

              Relance Navilog > option2 > poste moi le rapport + Un autre rapport Hijackthis ;)

              a+
              0
              1. c'est normale si je fait l'option2 la fenetre de Navilog n'apparait plus dans la barre des taches ?
                0
                1. ? du moment qu'il y a le rapport à la fin , on s'en fout ;)

                  a+
                  0
                  1. Tien ca c'est le rapport de Navilog1 :

                    Clean Navipromo version 3.4.4 commencé le 11/02/2008 à 22:23:52,89

                    Outil exécuté depuis C:\Program Files\navilog1
                    Mise à jour le 10.02.2008 à 12h00 par IL-MAFIOSO

                    Microsoft Windows XP [version 5.1.2600]
                    Internet Explorer : 6.0.2900.2180
                    Système de fichiers : NTFS

                    Mode suppression automatique
                    avec prise en charge résultats Catchme et GNS

                    *** Creation backups fichiers trouvés par Catchme ***

                    Copie vers "C:\Program Files\navilog1\Backupnavi"

                    Copie C:\Documents and Settings\François\Local Settings\Application Data\xrbijnmie.dat réalisée avec succès !
                    Copie C:\Documents and Settings\François\Local Settings\Application Data\xrbijnmie.exe réalisée avec succès !
                    Copie C:\Documents and Settings\François\Local Settings\Application Data\xrbijnmie_nav.dat réalisée avec succès !
                    Copie C:\Documents and Settings\François\Local Settings\Application Data\xrbijnmie_navps.dat réalisée avec succès !

                    *** Suppression des fichiers trouvés avec Catchme ***

                    ** 2ème passage avec résultats Catchme **

                    * Dans C:\WINDOWS\system32 *

                    C:\WINDOWS\prefetch\xrbijnmie*.pf trouvé !
                    Copie C:\WINDOWS\prefetch\xrbijnmie*.pf réalisée avec succès !
                    C:\WINDOWS\prefetch\xrbijnmie*.pf supprimé !

                    * Dans "C:\Documents and Settings\François\locals~1\applic~1" *

                    xrbijnmie.exe trouvé !
                    Copie xrbijnmie.exe réalisée avec succès !
                    xrbijnmie.exe supprimé !

                    xrbijnmie.dat trouvé !
                    Copie xrbijnmie.dat réalisée avec succès !
                    xrbijnmie.dat supprimé !

                    xrbijnmie_nav.dat trouvé !
                    Copie xrbijnmie_nav.dat réalisée avec succès !
                    xrbijnmie_nav.dat supprimé !

                    xrbijnmie_navps.dat trouvé !
                    Copie xrbijnmie_navps.dat réalisée avec succès !
                    xrbijnmie_navps.dat supprimé !

                    *** Suppression avec sauvegardes résultats GenericNaviSearch ***

                    * Suppression dans C:\WINDOWS\System32 *

                    * Suppression dans "C:\Documents and Settings\François\locals~1\applic~1" *

                    *** Suppression dossiers dans C:\WINDOWS ***

                    *** Suppression dossiers dans C:\Program Files ***

                    *** Suppression dossiers dans C:\DOCUME~1\ALLUSE~1\APPLIC~1 ***

                    *** Suppression dossiers dans "C:\Documents and Settings\François\applic~1" ***

                    *** Suppression dossiers dans "C:\Documents and Settings\François\locals~1\applic~1" ***

                    *** Suppression dossiers dans "C:\Documents and Settings\François\MENUDM~1\PROGRA~1" ***

                    ...\WebMediaPlayer ...suppression...
                    ...\WebMediaPlayer supprimé !

                    *** Suppression dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

                    ...\WebMediaPlayer ...suppression...
                    ...\WebMediaPlayer supprimé !

                    *** Suppression fichiers ***

                    C:\DOCUME~1\ALLUSE~1\Bureau\WebMediaPlayer.lnk supprimé !
                    C:\WINDOWS\system32\nvs2.inf supprimé !

                    *** Suppression fichiers temporaires ***

                    Nettoyage contenu C:\WINDOWS\Temp effectué !
                    Nettoyage contenu C:\Documents and Settings\Fran‡ois\locals~1\Temp effectué !

                    *** Traitement Recherche complémentaire ***
                    (Recherche fichiers spécifiques)

                    1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

                    2)Recherche, création sauvegardes et suppression Heuristique :

                    * Dans C:\WINDOWS\system32 *

                    agtdeqtf.dat trouvé !
                    Copie agtdeqtf.dat réalisée avec succès !
                    agtdeqtf.dat supprimé !

                    agtdeqtf_nav.dat trouvé !
                    Copie agtdeqtf_nav.dat réalisée avec succès !
                    agtdeqtf_nav.dat supprimé !

                    agtdeqtf_navps.dat trouvé !
                    Copie agtdeqtf_navps.dat réalisée avec succès !
                    agtdeqtf_navps.dat supprimé !

                    * Dans "C:\Documents and Settings\François\locals~1\applic~1" *

                    *** Sauvegarde du Registre vers dossier Backupnavi ***

                    sauvegarde du Registre réalisée avec succès !

                    *** Nettoyage Registre ***

                    Nettoyage Registre Ok

                    *** Certificats ***

                    Certificat Egroup supprimé !

                    *** Nettoyage terminé le 11/02/2008 à 22:32:03,96 ***

                    ------------------------------------------

                    Et ca c'est le rapport de HJT :

                    Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 22:39:02, on 11/02/2008
                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                    Boot mode: Normal

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
                    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                    C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
                    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                    C:\Program Files\AVG Anti-Spyware 7.5\guard.exe
                    C:\WINDOWS\eHome\ehRecvr.exe
                    C:\WINDOWS\eHome\ehSched.exe
                    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                    C:\WINDOWS\system32\nvsvc32.exe
                    C:\Program Files\SystemGuards.com\SystemGuards\sgScheduleService.exe
                    C:\WINDOWS\system32\atwtusb.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
                    C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe
                    C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
                    C:\Program Files\Softwin\BitDefender10\vsserv.exe
                    C:\WINDOWS\system32\dllhost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\wuauclt.exe
                    C:\WINDOWS\NOTEPAD.EXE
                    C:\Program Files\AVG Anti-Spyware 7.5\avgas.exe
                    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                    C:\Program Files\QuickTime\QTTask.exe
                    C:\Program Files\iTunes\iTunesHelper.exe
                    C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
                    C:\WINDOWS\system32\WTMKM.exe
                    C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
                    C:\Program Files\Softwin\BitDefender10\bdmcon.exe
                    C:\Program Files\Softwin\BitDefender10\bdagent.exe
                    C:\windows\system32\rlvknlg.exe
                    C:\Program Files\Odebit Multimédia\V3\Odebit.exe
                    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                    C:\Program Files\Save\Save.exe
                    C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
                    C:\Program Files\Xfire\xfire.exe
                    C:\Program Files\iPod\bin\iPodService.exe
                    C:\PROGRA~1\Mozilla Firefox\firefox.exe
                    C:\Program Files\Trend Micro\HijackThis\HJT.exe.exe

                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                    O2 - BHO: Burn4Free Toolbar Helper - {60BF5EE3-0105-4858-AD98-17C19F86B042} - C:\Program Files\Burn4Free Toolbar\v3.3.0.0\Burn4Free_Toolbar.dll
                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
                    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                    O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
                    O3 - Toolbar: Burn4Free Toolbar - {55FAF0F2-44D4-425F-B5F5-6B275B621EAB} - C:\Program Files\Burn4Free Toolbar\v3.3.0.0\Burn4Free_Toolbar.dll
                    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                    O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
                    O4 - HKLM\..\Run: [MacrokeyManager] WTMKM.exe
                    O4 - HKLM\..\Run: [System Guards] C:\Program Files\SystemGuards.com\SystemGuards\SysGuards.exe
                    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
                    O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg
                    O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
                    O4 - HKLM\..\Run: [RelevantKnowledge] C:\windows\system32\rlvknlg.exe -boot
                    O4 - HKCU\..\Run: [Spyware Begone] C:\Documents and Settings\François\Mes documents\freescan.exe -FastScan
                    O4 - HKCU\..\Run: [Odebit Multimedia V3 - Services] C:\Program Files\Odebit Multimédia\V3\Odebit.exe /info
                    O4 - HKCU\..\Run: [WINSOS VERIFY] "C:\Program Files\WINSOS\WINSOS.EXE" MINI
                    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                    O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"
                    O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
                    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                    O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                    O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe
                    O4 - Global Startup: AOL 9.0 Icône AOL.lnk = C:\Program Files\AOL 9.0\aoltray.exe
                    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                    O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?7f2c1675c3464b3683293678f6b64b40
                    O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?7f2c1675c3464b3683293678f6b64b40
                    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
                    O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://www.cyber-infos.net/files/OnlineScan.cab
                    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
                    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
                    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\AVG Anti-Spyware 7.5\guard.exe
                    O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe
                    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
                    O23 - Service: sgSchedulerService - Unknown owner - C:\Program Files\SystemGuards.com\SystemGuards\sgScheduleService.exe
                    O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
                    O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe
                    O23 - Service: WTService - Unknown owner - C:\WINDOWS\system32\atwtusb.exe
                    O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
                    0
                    1. Re ,

                      Met à jour IE stp


                      Tu as 2 anti-virus ( Bitdefender et Antivir) --> conflits , vire Antivir stp

                      *************************

                      Lance AVG Anti-Spyware

                      Clique sur le bouton Analyse (de la barre d'outils)

                      fais dans l'ordre stp. Tu sauvegardes le rapport APRES avoir mis les actions.

                      Puis sur l'onglet Paramètres
                      sous "Comment réagir", clique sur Actions recommandées. Sélectionne Quarantaine.

                      Reviens à l'onglet Analyse. Clique sur Analyse complète du système.

                      A la fin du scan, choisis l'option 3

                      "Appliquer toutes les actions " en bas.

                      Clique sur "Enregistrer le rapport".

                      Ceci génère un rapport en fichier texte qui se trouve dans le dossier Reports du dossier d'AVG Anti-Spyware.

                      Poste le moi.

                      a+
                      0
                      1. Salut , J'ai supprimer comme anti virus Bitdefender (c'etait la version gratuite ) , ça c'est mon rapport d'analyse d'AVG :

                        ---------------------------------------------------------
                        AVG Anti-Spyware - Rapport d'analyse
                        ---------------------------------------------------------

                        + Créé à: 13:37:05 12/02/2008

                        + Résultat de l'analyse:

                        C:\System Volume Information\_restore{D67C0D9D-739F-422A-8391-46B547D4C856}\RP216\A0086520.exe -> Adware.Relevant : Nettoyé.
                        C:\System Volume Information\_restore{D67C0D9D-739F-422A-8391-46B547D4C856}\RP216\A0086514.exe -> Not-A-Virus.Adware.RK : Nettoyé.
                        C:\System Volume Information\_restore{D67C0D9D-739F-422A-8391-46B547D4C856}\RP216\snapshot\MFEX-3.DAT -> Not-A-Virus.Adware.RK : Nettoyé.
                        :mozilla.145:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
                        :mozilla.146:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
                        :mozilla.147:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
                        :mozilla.149:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
                        :mozilla.137:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
                        :mozilla.138:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
                        :mozilla.139:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
                        :mozilla.140:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
                        :mozilla.141:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
                        :mozilla.142:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
                        :mozilla.72:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
                        :mozilla.76:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
                        :mozilla.77:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
                        :mozilla.78:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
                        :mozilla.148:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Adviva : Nettoyé.
                        :mozilla.221:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Atdmt : Nettoyé.
                        :mozilla.73:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Bluestreak : Nettoyé.
                        :mozilla.230:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Casinotropez : Nettoyé.
                        :mozilla.110:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
                        :mozilla.113:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
                        :mozilla.114:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
                        :mozilla.85:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Doubleclick : Nettoyé.
                        C:\Documents and Settings\François\Cookies\françois@doubleclick[2].txt -> TrackingCookie.Doubleclick : Nettoyé.
                        :mozilla.28:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Estat : Nettoyé.
                        :mozilla.100:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Information : Nettoyé.
                        :mozilla.101:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Information : Nettoyé.
                        :mozilla.106:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Information : Nettoyé.
                        :mozilla.107:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Information : Nettoyé.
                        :mozilla.224:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
                        :mozilla.23:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Overture : Nettoyé.
                        :mozilla.109:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Revenue : Nettoyé.
                        :mozilla.117:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
                        :mozilla.118:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
                        :mozilla.119:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
                        :mozilla.120:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
                        :mozilla.63:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
                        :mozilla.64:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
                        :mozilla.79:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
                        :mozilla.80:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
                        :mozilla.81:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
                        :mozilla.82:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
                        :mozilla.83:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
                        :mozilla.171:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Valuead : Nettoyé.
                        :mozilla.172:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Valuead : Nettoyé.
                        :mozilla.173:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Valuead : Nettoyé.
                        :mozilla.174:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Valuead : Nettoyé.
                        :mozilla.60:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
                        :mozilla.61:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
                        :mozilla.62:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
                        :mozilla.30:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Webtrends : Nettoyé.
                        C:\Documents and Settings\François\Cookies\françois@m.webtrends[2].txt -> TrackingCookie.Webtrends : Nettoyé.
                        :mozilla.102:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
                        :mozilla.103:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
                        :mozilla.104:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
                        :mozilla.105:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
                        :mozilla.215:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Zedo : Nettoyé.
                        :mozilla.216:C:\Documents and Settings\François\Application Data\Mozilla\Firefox\Profiles\67ufc9ke.default\cookies.txt -> TrackingCookie.Zedo : Nettoyé.

                        Fin du rapport
                        0
                        1. Re ,

                          Re-poste moi un rapport Hijackthis stp ;)

                          a+
                          0
                          1. Re, le rapport de HJT :

                            Logfile of Trend Micro HijackThis v2.0.2
                            Scan saved at 16:02:00, on 12/02/2008
                            Platform: Windows XP SP2 (WinNT 5.01.2600)
                            MSIE: Internet Explorer v7.00 (7.00.6000.16574)
                            Boot mode: Normal

                            Running processes:
                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
                            C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                            C:\Program Files\QuickTime\QTTask.exe
                            C:\Program Files\iTunes\iTunesHelper.exe
                            C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
                            C:\WINDOWS\system32\WTMKM.exe
                            C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
                            C:\Program Files\Odebit Multimédia\V3\Odebit.exe
                            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                            C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
                            C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                            C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
                            C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                            C:\Program Files\AVG Anti-Spyware 7.5\guard.exe
                            C:\WINDOWS\eHome\ehRecvr.exe
                            C:\WINDOWS\eHome\ehSched.exe
                            C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                            C:\WINDOWS\system32\nvsvc32.exe
                            C:\Program Files\SystemGuards.com\SystemGuards\sgScheduleService.exe
                            C:\WINDOWS\explorer.exe
                            C:\Program Files\iPod\bin\iPodService.exe
                            C:\WINDOWS\system32\dllhost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\system32\ctfmon.exe
                            C:\Program Files\Steam\Steam.exe
                            C:\WINDOWS\system32\wuauclt.exe
                            C:\WINDOWS\system32\atwtusb.exe
                            C:\PROGRA~1\Mozilla Firefox\firefox.exe
                            C:\Program Files\Trend Micro\HijackThis\HJT.exe.exe

                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                            O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                            O2 - BHO: Burn4Free Toolbar Helper - {60BF5EE3-0105-4858-AD98-17C19F86B042} - C:\Program Files\Burn4Free Toolbar\v3.3.0.0\Burn4Free_Toolbar.dll
                            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
                            O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                            O3 - Toolbar: Burn4Free Toolbar - {55FAF0F2-44D4-425F-B5F5-6B275B621EAB} - C:\Program Files\Burn4Free Toolbar\v3.3.0.0\Burn4Free_Toolbar.dll
                            O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                            O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                            O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
                            O4 - HKLM\..\Run: [MacrokeyManager] WTMKM.exe
                            O4 - HKLM\..\Run: [System Guards] C:\Program Files\SystemGuards.com\SystemGuards\SysGuards.exe
                            O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
                            O4 - HKCU\..\Run: [Spyware Begone] C:\Documents and Settings\François\Mes documents\freescan.exe -FastScan
                            O4 - HKCU\..\Run: [Odebit Multimedia V3 - Services] C:\Program Files\Odebit Multimédia\V3\Odebit.exe /info
                            O4 - HKCU\..\Run: [WINSOS VERIFY] "C:\Program Files\WINSOS\WINSOS.EXE" MINI
                            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                            O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
                            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                            O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                            O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe
                            O4 - Global Startup: AOL 9.0 Icône AOL.lnk = C:\Program Files\AOL 9.0\aoltray.exe
                            O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                            O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?7f2c1675c3464b3683293678f6b64b40
                            O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?7f2c1675c3464b3683293678f6b64b40
                            O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                            O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
                            O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://www.cyber-infos.net/files/OnlineScan.cab
                            O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                            O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                            O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
                            O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
                            O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                            O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\AVG Anti-Spyware 7.5\guard.exe
                            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                            O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                            O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                            O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
                            O23 - Service: sgSchedulerService - Unknown owner - C:\Program Files\SystemGuards.com\SystemGuards\sgScheduleService.exe
                            O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
                            O23 - Service: WTService - Unknown owner - C:\WINDOWS\system32\atwtusb.exe
                            0
                            1. Re ,


                              Désinstalle Spyware begone


                              **************************************************

                              Télécharge OTMoveIt2 ( de Old Timer )

                              Une fois téléchargé double-clique sur OTMoveIt2.exe pour le lancer.

                              Assure toi que la case Unregister Dll's and Ocx's soit bien cochée

                              puis copie les lignes en gras qui se trouvent en dessous :

                              C:\WINDOWS\system32\WTMKM.exe


                              et colle-les dans le cadre de gauche de OTMoveIt : "Paste Standard List Of Files/Folders to Move."
                              clique sur MoveIt! pour lancer la suppression.
                              le résultat apparaitra dans le cadre Results.
                              clique sur Exit pour fermer.
                              2) Poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

                              3) Il te sera peut-être demander de redémarrer le pc pour achever la suppression -> Accepte ( si il ne fait pas automatiquement , fait-le toi même )

                              /!\ Note : Au démarrage ton bureau RISQUE de ne plus apparaître , dans ce cas fait --> CTRL+ALT+SUPP pour ouvrir le Gestionnaire des tâches.
                              Puis rends toi à l'onglet "Processus". Clique en haut à gauche sur Fichiers et choisis "Exécuter"

                              Tape explorer.exe et valide. Cela fera re-apparaître le Bureau.

                              ********************

                              a+
                              0
                              1. Re , tiens c'est le rapport de OTMoveIt2 :

                                [Custom Input]
                                < C:\WINDOWS\system32\WTMKM.exe >
                                C:\WINDOWS\system32\WTMKM.exe moved successfully.

                                OTMoveIt2 v1.0.19 log created on 02122008_165516
                                0
                                1. Re ,

                                  Télécharge Cleanup
                                  Lance-le et choisi l'option ' cleanup! '

                                  Tuto: http://pageperso.aol.fr/balltrap34/democleanup.htm ( merci à balltrap34 )

                                  ******************

                                  Télécharge clean : http://www.malekal.com/download/clean.zip

                                  Une fois téléchargé et dézippé ( clique droit , extraire tout) , lance clean.cmd ( ou clean ), Choisi l'option 1 et poste moi le rapport.(- Où est le rapport clean ? : « Poste de travail » / double clic sur disque « C / » double-clic sur « rapport_clean.txt » et « copier/coller le contenu » sur le forum. )

                                  Je re dans 1h30
                                  A+
                                  0
                                  1. Re , le rapport de Clean :

                                    12/02/2008 a 18:14:56,39

                                    *** Recherche des fichiers dans C:

                                    *** Recherche des fichiers dans C:\WINDOWS\

                                    *** Recherche des fichiers dans C:\WINDOWS\system32
                                    C:\WINDOWS\system32\bdod.bin FOUND
                                    C:\WINDOWS\system32\rlls.dll FOUND

                                    a toute
                                    0
                                    1. Re

                                      Redémarre en MSE

                                      Re-lance clean -> Choisis l'option 2

                                      Clean va travailler.

                                      Un rapport Va etre généré , poste le moi ;)

                                      A+
                                      0
                                      1. Re , tiens le rapport :

                                        Script execute en mode sans echec
                                        Rapport clean par Malekal_morte - http://www.malekal.com
                                        Script execute en mode sans echec 12/02/2008 a 19:52:59,04

                                        Microsoft Windows XP [version 5.1.2600]

                                        *** Suppression des fichiers dans C:

                                        *** Suppression des fichiers dans C:\WINDOWS\

                                        *** Suppression des fichiers dans C:\WINDOWS\system32
                                        tentative de suppression de C:\WINDOWS\system32\bdod.bin
                                        tentative de suppression de C:\WINDOWS\system32\rlls.dll
                                        0
                                        1. Re ,

                                          Il résiste ,

                                          Dans OtmoveIt copie/colle ces lignes ( en gras )

                                          C:\WINDOWS\system32\bdod.bin
                                          C:\WINDOWS\system32\rlls.dll


                                          --> ' MoveIt '

                                          Poste le rapport.

                                          a+
                                          0
                                          • 1
                                          • 2
                                          • 3
                                          • 4