Nombreux processus au démarrage

Résolu
Bonjour,
mon pc est lent : j'ai constaté que de nombreux processus sont en cours au démarrage, mais je ne m'y connais pas assez pour savoir lesquels désactiver. comment faire ?

je ne sais même pas comment faire pour fournir ici une liste de ces processus, merci de m'aider.
Configuration: Windows XP
Firefox 2.0.0.12

21 réponses

  1. Contributeur
    Salut,

    Télécharge HijackThis ici :

    -> http://www.commentcamarche.net/telecharger/telecharger 159 hijackthis

    Tutoriel d´instalation : (Merci a Balltrap34 pour cette réalisation)

    -> http://pageperso.aol.fr/balltrap34/Hijenr.gif

    Tutoriel d´utilisation (video) : (Merci a Balltrap34 pour cette réalisation)

    -> http://pageperso.aol.fr/balltrap34/demohijack.htm

    Post le rapport généré ici stp...

    @+
    0
    1. Bonjour,

      ci-dessous rapport hijackthis
      merci de ta réponse

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 10:25:02, on 11/03/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16608)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\RTHDCPL.EXE
      C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
      C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
      C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      C:\Program Files\Spyware Doctor\pctsTray.exe
      C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Windows Media Player\WMPNSCFG.exe
      C:\Program Files\MSN Messenger\msnmsgr.exe
      C:\Program Files\Intel\IntelDH\CCU\CCU_Engine.exe
      C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
      C:\PROGRA~1\Wanadoo\ComComp.exe
      C:\PROGRA~1\Wanadoo\Toaster.exe
      C:\PROGRA~1\Wanadoo\Inactivity.exe
      C:\PROGRA~1\Wanadoo\PollingModule.exe
      C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
      C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\WINDOWS\eHome\ehRecvr.exe
      C:\WINDOWS\eHome\ehSched.exe
      C:\WINDOWS\System32\FTRTSVC.exe
      C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
      C:\WINDOWS\system32\inetsrv\inetinfo.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\Program Files\Spyware Doctor\pctsAuxs.exe
      C:\Program Files\Spyware Doctor\pctsSvc.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
      C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
      C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
      C:\WINDOWS\ehome\mcrdsvc.exe
      C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\Elservice.exe
      C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
      C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Windows Media Player\wmpnetwk.exe
      C:\WINDOWS\system32\dllhost.exe
      C:\WINDOWS\system32\rsvp.exe
      C:\WINDOWS\System32\alg.exe
      C:\PROGRA~1\Wanadoo\Watch.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: Control Popups in Internet Explorer - {41353F8B-78CE-48A5-BE44-153ED293D192} - C:\PROGRA~1\POPUPP~1\PopLib.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: PopupZeroIEDLL.CPopupZeroIEDLL - {A94EDD52-85B3-472F-8BC0-D651D760FBF8} - C:\Program Files\PopupZero\PopupZeroIEDLL.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
      O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
      O4 - HKLM\..\Run: [CCUTRAYICON] C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe
      O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
      O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
      O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
      O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
      O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
      O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-21-1723211696-292700969-4135070537-1004\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'IUSR_NMPR')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\S-1-5-18\..\RunOnce: [^SetupICWDesktop] (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] (User 'Default user')
      O9 - Extra button: PopupPopper Control Panel - {3E94F358-9537-4BBA-8D12-D7F8A0136973} - C:\Program Files\PopupPopper\SiteList.exe
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
      O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
      O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
      O14 - IERESET.INF: START_PAGE_URL=http://www.carrefour-multimedia.fr/
      O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
      O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
      O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab55762.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL
      O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
      O23 - Service: Intel(R) Alert Service (AlertService) - Intel Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: Intel(R) Quick Resume technology (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\Elservice.exe
      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
      O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
      O23 - Service: Serveur Média Intel(R) Viiv(TM) (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
      O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
      O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
      O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
      O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
      0
      1. Contributeur
        salut trouspette,

        a l´aide de hijack this coche et fix les lignes ci dessous

        O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
        O4 - HKUS\S-1-5-18\..\RunOnce: [^SetupICWDesktop] (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] (User 'Default user')

        comment fixer :

        Tutoriel d´utilisation (video) : (Merci a Balltrap34 pour cette réalisation)

        -> http://pageperso.aol.fr/balltrap34/demohijack.htm

        Ccleaner:

        -> Télécharge Ccleaner (n'installe pas la barre d'outil Yahoo):

        http://www.commentcamarche.net/telecharger/telechargement 168 ccleaner

        -> L´installer.

        -> Une fois installé et lancé :

        Dans la colonne de gauche, click sur :

        ->"erreurs" :

        Coches toutes les cases sous"l´integrité du registre", puis click en bas sur "chercher des erreurs" une fois terminé, clic sur "reparer les erreurs", tu auras un message pour sauvegarder ta base de registre, tu click "oui" puis tu recommence jusqu'à ce qu'il ne trouve plus rien.

        ps : les sauvegardes que tu auras faites, pourront etre supprimées ulterieurement si tout va bien.

        ->"nettoyeur"

        quitte ton navigateur avant de le lancer, dans les propriétés du nettoyeur de l´onglet "windows" et "applications"décoche la derniere case (Avancé si elle est cochée) puis click sur "lancer le nettoyage" qunand il aura terminé le scan click en bas a droite sur "lancer le nettoyage" et accepte par oui.

        -> Tutoriel en image :

        https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php

        -> Pour ceux qui voudraient aller plus loin en compagnie de jesses (fonctions avancés) :

        http://perso.orange.fr/jesses/Docs/Logiciels/CCleaner.htm

        puis :

        telecharge malwarebytes

        -> http://forum.telecharger.01net.com/forum/high-tech/PRODUITS/Questions-techniques/anti-malware-sujet_197382_1.htm

        tu l´instales, le programme va se mettre a jour automatiquement.

        une fois a jour le programme va se lancer, clcik sur l´onglet parametre, tu coche la case : Arreter internet explorer pendant la suppression.

        click sur l´onglet recherche maintenant et coche la case : executer un examun complet.

        puis click sur rechercher.

        laisses le scanner le pc, a la fin un rapport va s´ouvrir copie et colle le ici stp

        @+
        0
        1. rebonjour,

          désolée pour le décallage temporel ; j'ai fait ce que tu as dit et voici le rapport de malwarebytes : apparemment aucun fichier infecté.

          Malwarebytes' Anti-Malware 1.08
          Version de la base de données: 477

          Type de recherche: Examen complet (C:\|D:\|E:\|G:\|H:\|I:\|)
          Eléments examinés: 89443
          Temps écoulé: 14 minute(s), 51 second(s)

          Processus mémoire infecté(s): 0
          Module(s) mémoire infecté(s): 0
          Clé(s) du Registre infectée(s): 0
          Valeur(s) du Registre infectée(s): 0
          Elément(s) de données du Registre infecté(s): 0
          Dossier(s) infecté(s): 0
          Fichier(s) infecté(s): 0

          Processus mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Module(s) mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Clé(s) du Registre infectée(s):
          (Aucun élément nuisible détecté)

          Valeur(s) du Registre infectée(s):
          (Aucun élément nuisible détecté)

          Elément(s) de données du Registre infecté(s):
          (Aucun élément nuisible détecté)

          Dossier(s) infecté(s):
          (Aucun élément nuisible détecté)

          Fichier(s) infecté(s):
          (Aucun élément nuisible détecté)

          merci de ton aide
          0
          1. Contributeur
            bonsoir trouspette,

            oui moi aussi j´suis un peu decallée, alors pas de souci,

            malwarebytes ne detecte rien, c´est une bonne chose ;-)

            repost un nouveau hijack this voir stp

            @+
            0
            1. bonjour g!rly,

              ci-dessous rapport hijackthis.

              si tout est normal, peux-tu avant de cesser cette discussion me conseiller pour les anti-virus, firewal et anti spyware, parce qu'actuellement j'en ai pas mal et je ne sais pas trop que garder / virer /remplacer. voici la liste :

              avast
              spybot
              spyware doctor
              ccleaner
              navilog
              smitfraudfix
              ad aware
              avg anti spyware
              malwarebytes

              je préfère bien sûr les logiciels gratuits, mais est-ce bien raisonnable ? ne vaut-il pas mieux payer pour quelque chose de plus sûr ? Merci de ton aide en tous cas.

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 10:24:55, on 12/03/2008
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16608)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\csrss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\RTHDCPL.EXE
              C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
              C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
              C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
              C:\Program Files\Spyware Doctor\pctsTray.exe
              C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
              C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
              C:\Program Files\Intel\IntelDH\CCU\CCU_Engine.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Windows Media Player\WMPNSCFG.exe
              C:\Program Files\MSN Messenger\msnmsgr.exe
              C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
              C:\PROGRA~1\Wanadoo\ComComp.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\PROGRA~1\Wanadoo\Toaster.exe
              C:\PROGRA~1\Wanadoo\Inactivity.exe
              C:\PROGRA~1\Wanadoo\PollingModule.exe
              C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
              C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
              C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
              C:\WINDOWS\eHome\ehRecvr.exe
              C:\WINDOWS\eHome\ehSched.exe
              C:\WINDOWS\System32\FTRTSVC.exe
              C:\WINDOWS\eHome\ehRec.exe
              C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
              C:\WINDOWS\system32\inetsrv\inetinfo.exe
              C:\WINDOWS\system32\nvsvc32.exe
              C:\Program Files\Spyware Doctor\pctsAuxs.exe
              C:\Program Files\Spyware Doctor\pctsSvc.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
              C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\Elservice.exe
              C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
              C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
              C:\WINDOWS\ehome\mcrdsvc.exe
              C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
              C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
              C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Windows Media Player\wmpnetwk.exe
              C:\WINDOWS\system32\dllhost.exe
              C:\WINDOWS\system32\rsvp.exe
              C:\WINDOWS\System32\alg.exe
              C:\PROGRA~1\Wanadoo\Watch.exe
              C:\WINDOWS\system32\wbem\wmiprvse.exe
              C:\Program Files\Mozilla Firefox\firefox.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
              C:\WINDOWS\system32\wbem\wmiprvse.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
              O2 - BHO: Control Popups in Internet Explorer - {41353F8B-78CE-48A5-BE44-153ED293D192} - C:\PROGRA~1\POPUPP~1\PopLib.dll
              O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: PopupZeroIEDLL.CPopupZeroIEDLL - {A94EDD52-85B3-472F-8BC0-D651D760FBF8} - C:\Program Files\PopupZero\PopupZeroIEDLL.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
              O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
              O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
              O4 - HKLM\..\Run: [CCUTRAYICON] C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe
              O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
              O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
              O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
              O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
              O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
              O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
              O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
              O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
              O4 - HKUS\S-1-5-21-1723211696-292700969-4135070537-1004\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'IUSR_NMPR')
              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
              O9 - Extra button: PopupPopper Control Panel - {3E94F358-9537-4BBA-8D12-D7F8A0136973} - C:\Program Files\PopupPopper\SiteList.exe
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
              O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
              O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
              O14 - IERESET.INF: START_PAGE_URL=http://www.carrefour-multimedia.fr/
              O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
              O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
              O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
              O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
              O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab55762.cab
              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
              O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL
              O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
              O23 - Service: Intel(R) Alert Service (AlertService) - Intel Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
              O23 - Service: Intel(R) Quick Resume technology (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\Elservice.exe
              O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
              O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
              O23 - Service: Serveur Média Intel(R) Viiv(TM) (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
              O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
              O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
              O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
              O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
              O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
              O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
              0
              1. Contributeur
                salut trouspette,

                ca m´a l´air ok

                a part que tu n´as pas de par feu a part celui de windows :

                telecharges en un ci dessous :

                par feu : kerio

                telechargement : http://sd-1.archive-host.com/membres/up/1366464061/kerio-kpf-422-911-win.rar

                tuto :

                http://www.malekal.com/kerio_firewall.php#mozTocId721480

                https://www.vulgarisation-informatique.com/kerio.php

                https://kerio.probb.fr/f2-sunbelt-kerio-personal-firewall

                Comodo 3 pro :

                http://www.commentcamarche.net/telecharger/telecharger 34055041 comodo firewall pro

                Online armor :

                http://www.commentcamarche.net/telecharger/telecharger 34055356 online armor personal firewall

                tuto : https://forum.pcastuces.com/sujet.asp?f=25&s=35606

                ou zone alarm plus facil a configurer mais moins performant

                https://www.malekal.com/tutoriel-zonealarm-firewall/

                puis un petit bonus qui n´utilise pas de ressource mais qui est un must :

                spywareblaster :

                http://www.brightfort.com/spywareblaster.html

                c´est un resident, il suffit de le mettre a jour de temps en temps car la version gratuite ne le fait pas toute seul , une fois installé et mis a jour tu mets toutes les protections sur "enable"

                tuto : http://forum.telecharger.01net.com/forum/high-tech/PRODUITS/Questions-techniques/question-spywareblaser-sujet_174747_1.htm

                spybot > garde
                spyware doctor Tu peux le desinstaller si tu veux
                ccleaner > garde > a utiiser regulierement
                navilog > desinstale
                smitfraudfix > desinstale
                ad aware > garde
                avg anti spyware > desinstale le > malwarebytes est plus performant !
                malwarebytes > garde
                avast > desinstale le et remplace le par antivir :

                regarde ceci concernant avast :

                antivir vs avast :

                -> http://forum.malekal.com/ftopic3528.php

                alors je te conseille de le desinstaller et d´installer antivir a la place

                Telecharge et instales l'antivirus Antivir Personal Edition Classic :

                ->https://www.malekal.com/avira-free-security-antivirus-gratuit/

                https://www.avira.com/en/prime

                http://mickael.barroux.free.fr/securite/antivir.php
                http://speedweb1.free.fr/frames2.php?page=tuto5
                <- tutoriel configuration du scanner...

                une fois antivir ouvert click surconfiguration et coche la case "expert mode" puis sur l´onglet scanner dans la fenetre du dessous tu va voir : rootkit search click sur le petit + pour deployer et coche la case a coté de ton disk dur
                puis click sur configuration en haut a droite; dans la nouvelle fenetre a gauche >scanner > coche "scan all files" et en dessous >scanner priority = High
                coche : allow stopping the scanner, comme cela tu peux faire une pause pendant le scan si tu le desir.
                puis sur la droite coche les case suivantes :
                scan boot sectors of selected drives
                scan master boot sectors
                scan memory
                search foe rootkit before scan
                decoche :
                ignore off line files
                toujours a gauche > scan > deploie > heuristique > macrovirus heuristic = coché et en dessous > win32 heuristic la case coché et high detection level

                Je te dis tous ca car j´aimerais que tu performes un scan entier de ta machine a l´aide d´antivir avec les reglages stipulés ci dessus et que tu post le rapport généré ici stp

                donc post le rapport de scan d´antivir stp

                @+
                0
                1. bonjour g!rly,

                  j'ai fait tout ce que tu as dit.

                  ci-dessous le rapport d'antivir qui en effet a détecté 19 infections !!!!
                  au lieu de mettre en quarantaine, j'ai fait delete à chaque fois, je ne sais pas si j'ai bien fait.

                  tout a été trouvé dans C/System Volume Information ; il s'agissait de :
                  -TR/Dropper.Gen (trouvé 2 fois)
                  -DR/Fraudtool.spywaresecure.A ; trouvé plein de fois, alors que je croyais l'avoir éliminé (choppé suite à téléchérgement de web média player ...)
                  -DR/Tod.Reboot.F.50 (trouvé 1 fois)

                  ce qui m'inquiète dans le rapport c'est que 2 files n'ont pu être ouvertes.

                  Mais bon, tu verras tout ça dans le rapport ci-dessous. encore merci pour ton aide précieuse.

                  AntiVir PersonalEdition Classic
                  Report file date: jeudi 13 mars 2008 10:16

                  Scanning for 1145851 virus strains and unwanted programs.

                  Licensed to: Avira AntiVir PersonalEdition Classic
                  Serial number: 0000149996-ADJIE-0001
                  Platform: Windows XP
                  Windows version: (Service Pack 2) [5.1.2600]
                  Username: SYSTEM
                  Computer name: NOM-3189168

                  Version information:
                  BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
                  AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
                  AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
                  LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
                  LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
                  ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
                  ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 09:10:11
                  ANTIVIR2.VDF : 7.0.3.3 2048 Bytes 07/03/2008 09:10:11
                  ANTIVIR3.VDF : 7.0.3.23 132096 Bytes 13/03/2008 09:10:11
                  AVEWIN32.DLL : 7.6.0.73 3334656 Bytes 13/03/2008 09:10:11
                  AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
                  AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
                  AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
                  AVPACK32.DLL : 7.6.0.3 360488 Bytes 13/03/2008 09:10:11
                  AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
                  AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
                  AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
                  NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
                  RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
                  RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
                  SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21

                  Configuration settings for the scan:
                  Jobname..........................: Complete system scan
                  Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
                  Logging..........................: low
                  Primary action...................: interactive
                  Secondary action.................: ignore
                  Scan master boot sector..........: off
                  Scan boot sector.................: on
                  Boot sectors.....................: E:,
                  Scan memory......................: on
                  Process scan.....................: on
                  Scan registry....................: on
                  Search for rootkits..............: off
                  Scan all files...................: Intelligent file selection
                  Scan archives....................: on
                  Recursion depth..................: 20
                  Smart extensions.................: on
                  Macro heuristic..................: on
                  File heuristic...................: medium

                  Start of the scan: jeudi 13 mars 2008 10:16

                  The scan of running processes will be started
                  Scan process 'avscan.exe' - '1' Module(s) have been scanned
                  Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                  Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
                  Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
                  Scan process 'Watch.exe' - '1' Module(s) have been scanned
                  Scan process 'GoogleDesktop.exe' - '1' Module(s) have been scanned
                  Scan process 'kpf4gui.exe' - '1' Module(s) have been scanned
                  Scan process 'alg.exe' - '1' Module(s) have been scanned
                  Scan process 'rsvp.exe' - '1' Module(s) have been scanned
                  Scan process 'dllhost.exe' - '1' Module(s) have been scanned
                  Scan process 'wmpnetwk.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'Remote UI Service.exe' - '1' Module(s) have been scanned
                  Scan process 'mediaserver.exe' - '1' Module(s) have been scanned
                  Scan process 'kpf4gui.exe' - '1' Module(s) have been scanned
                  Scan process 'MCLServiceATL.exe' - '1' Module(s) have been scanned
                  Scan process 'ISSM.exe' - '1' Module(s) have been scanned
                  Scan process 'ELService.exe' - '1' Module(s) have been scanned
                  Scan process 'mcrdsvc.exe' - '1' Module(s) have been scanned
                  Scan process 'X10nets.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'kpf4ss.exe' - '1' Module(s) have been scanned
                  Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
                  Scan process 'inetinfo.exe' - '1' Module(s) have been scanned
                  Scan process 'IAANTmon.exe' - '1' Module(s) have been scanned
                  Scan process 'GoogleUpdaterService.exe' - '1' Module(s) have been scanned
                  Scan process 'FTRTSVC.exe' - '1' Module(s) have been scanned
                  Scan process 'ehSched.exe' - '1' Module(s) have been scanned
                  Scan process 'ehrecvr.exe' - '1' Module(s) have been scanned
                  Scan process 'sched.exe' - '1' Module(s) have been scanned
                  Scan process 'AlertService.exe' - '1' Module(s) have been scanned
                  Scan process 'ALERTM~1.EXE' - '1' Module(s) have been scanned
                  Scan process 'PollingModule.exe' - '1' Module(s) have been scanned
                  Scan process 'Inactivity.exe' - '1' Module(s) have been scanned
                  Scan process 'Toaster.exe' - '1' Module(s) have been scanned
                  Scan process 'ComComp.exe' - '1' Module(s) have been scanned
                  Scan process 'CCU_Engine.exe' - '1' Module(s) have been scanned
                  Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
                  Scan process 'GestionnaireInternet.exe' - '1' Module(s) have been scanned
                  Scan process 'TaskBarIcon.exe' - '1' Module(s) have been scanned
                  Scan process 'wmpnscfg.exe' - '1' Module(s) have been scanned
                  Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
                  Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                  Scan process 'GoogleDesktop.exe' - '1' Module(s) have been scanned
                  Scan process 'hpcmpmgr.exe' - '1' Module(s) have been scanned
                  Scan process 'hpztsb10.exe' - '1' Module(s) have been scanned
                  Scan process 'IAAnotif.exe' - '1' Module(s) have been scanned
                  Scan process 'CCU_TrayIcon.exe' - '1' Module(s) have been scanned
                  Scan process 'RTHDCPL.exe' - '1' Module(s) have been scanned
                  Scan process 'avguard.exe' - '1' Module(s) have been scanned
                  Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                  Scan process 'explorer.exe' - '1' Module(s) have been scanned
                  Scan process 'aawservice.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'lsass.exe' - '1' Module(s) have been scanned
                  Scan process 'services.exe' - '1' Module(s) have been scanned
                  Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                  Scan process 'csrss.exe' - '1' Module(s) have been scanned
                  Scan process 'smss.exe' - '1' Module(s) have been scanned
                  64 processes with 64 modules were scanned

                  Start scanning boot sectors:
                  Boot sector 'C:\'
                  [NOTE] No virus was found!
                  Boot sector 'D:\'
                  [NOTE] No virus was found!
                  Boot sector 'E:\'
                  [NOTE] No virus was found!

                  Starting to scan the registry.
                  The registry was scanned ( '24' files ).

                  Starting the file scan:

                  Begin scan in 'C:\' <BOOT>
                  C:\hiberfil.sys
                  [WARNING] The file could not be opened!
                  C:\pagefile.sys
                  [WARNING] The file could not be opened!
                  C:\System Volume Information\_restore{4FB01477-A450-4158-BD4C-9558288D7632}\RP278\A0147039.exe
                  [DETECTION] Is the Trojan horse TR/Dropper.Gen
                  [INFO] The file was deleted!
                  C:\System Volume Information\_restore{4FB01477-A450-4158-BD4C-9558288D7632}\RP283\A0147430.exe
                  [DETECTION] Contains detection pattern of the dropper DR/FraudTool.SpywareSecure.A
                  [INFO] The file was deleted!
                  C:\System Volume Information\_restore{4FB01477-A450-4158-BD4C-9558288D7632}\RP283\A0147436.exe
                  [DETECTION] Contains detection pattern of the dropper DR/FraudTool.SpywareSecure.A
                  [INFO] The file was deleted!
                  C:\System Volume Information\_restore{4FB01477-A450-4158-BD4C-9558288D7632}\RP291\A0148098.exe
                  [DETECTION] Contains detection pattern of the dropper DR/FraudTool.SpywareSecure.A
                  [INFO] The file was deleted!
                  C:\System Volume Information\_restore{4FB01477-A450-4158-BD4C-9558288D7632}\RP291\A0148101.exe
                  [DETECTION] Contains detection pattern of the dropper DR/FraudTool.SpywareSecure.A
                  [INFO] The file was deleted!
                  C:\System Volume Information\_restore{4FB01477-A450-4158-BD4C-9558288D7632}\RP291\A0148505.exe
                  [DETECTION] Is the Trojan horse TR/Dropper.Gen
                  [INFO] The file was deleted!
                  C:\System Volume Information\_restore{4FB01477-A450-4158-BD4C-9558288D7632}\RP293\A0149053.exe
                  [DETECTION] Contains detection pattern of the dropper DR/FraudTool.SpywareSecure.A
                  [INFO] The file was deleted!
                  C:\System Volume Information\_restore{4FB01477-A450-4158-BD4C-9558288D7632}\RP293\A0149054.exe
                  [DETECTION] Contains detection pattern of the dropper DR/FraudTool.SpywareSecure.A
                  [INFO] The file was deleted!
                  C:\System Volume Information\_restore{4FB01477-A450-4158-BD4C-9558288D7632}\RP293\A0149183.exe
                  [DETECTION] Contains detection pattern of the dropper DR/FraudTool.SpywareSecure.A
                  [INFO] The file was deleted!
                  C:\System Volume Information\_restore{4FB01477-A450-4158-BD4C-9558288D7632}\RP293\A0149184.exe
                  [DETECTION] Contains detection pattern of the dropper DR/FraudTool.SpywareSecure.A
                  [INFO] The file was deleted!
                  C:\System Volume Information\_restore{4FB01477-A450-4158-BD4C-9558288D7632}\RP294\A0150014.exe
                  [DETECTION] Contains detection pattern of the dropper DR/FraudTool.SpywareSecure.A
                  [INFO] The file was deleted!
                  C:\System Volume Information\_restore{4FB01477-A450-4158-BD4C-9558288D7632}\RP294\A0150015.exe
                  [DETECTION] Contains detection pattern of the dropper DR/FraudTool.SpywareSecure.A
                  [INFO] The file was deleted!
                  C:\System Volume Information\_restore{4FB01477-A450-4158-BD4C-9558288D7632}\RP294\A0150144.exe
                  [DETECTION] Contains detection pattern of the dropper DR/FraudTool.SpywareSecure.A
                  [INFO] The file was deleted!
                  C:\System Volume Information\_restore{4FB01477-A450-4158-BD4C-9558288D7632}\RP294\A0150145.exe
                  [DETECTION] Contains detection pattern of the dropper DR/FraudTool.SpywareSecure.A
                  [INFO] The file was deleted!
                  C:\System Volume Information\_restore{4FB01477-A450-4158-BD4C-9558288D7632}\RP295\A0150976.exe
                  [DETECTION] Contains detection pattern of the dropper DR/FraudTool.SpywareSecure.A
                  [INFO] The file was deleted!
                  C:\System Volume Information\_restore{4FB01477-A450-4158-BD4C-9558288D7632}\RP295\A0150977.exe
                  [DETECTION] Contains detection pattern of the dropper DR/FraudTool.SpywareSecure.A
                  [INFO] The file was deleted!
                  C:\System Volume Information\_restore{4FB01477-A450-4158-BD4C-9558288D7632}\RP295\A0151106.exe
                  [DETECTION] Contains detection pattern of the dropper DR/FraudTool.SpywareSecure.A
                  [INFO] The file was deleted!
                  C:\System Volume Information\_restore{4FB01477-A450-4158-BD4C-9558288D7632}\RP295\A0151107.exe
                  [DETECTION] Contains detection pattern of the dropper DR/FraudTool.SpywareSecure.A
                  [INFO] The file was deleted!
                  C:\System Volume Information\_restore{4FB01477-A450-4158-BD4C-9558288D7632}\RP312\A0155379.exe
                  [DETECTION] Contains detection pattern of the dropper DR/Tool.Reboot.F.50
                  [INFO] The file was deleted!
                  Begin scan in 'D:\' <BACKUP>
                  Begin scan in 'E:\' <RECOVER>

                  End of the scan: jeudi 13 mars 2008 10:42
                  Used time: 26:04 min

                  The scan has been done completely.

                  6298 Scanning directories
                  239396 Files were scanned
                  19 viruses and/or unwanted programs were found
                  0 Files were classified as suspicious:
                  19 files were deleted
                  0 files were repaired
                  0 files were moved to quarantine
                  0 files were renamed
                  2 Files cannot be scanned
                  239377 Files not concerned
                  8433 Archives were scanned
                  2 Warnings
                  0 Notes
                  0
                  1. re-bonjour g!rly,

                    en fait j'avais zappé que tu me demandais une config spéciale pour antivir ; j'ai donc fait la config que tu demandais et un nouveau scan dont voici le rapport ci-dessous :

                    AntiVir PersonalEdition Classic
                    Report file date: jeudi 13 mars 2008 10:59

                    Scanning for 1145851 virus strains and unwanted programs.

                    Licensed to: Avira AntiVir PersonalEdition Classic
                    Serial number: 0000149996-ADJIE-0001
                    Platform: Windows XP
                    Windows version: (Service Pack 2) [5.1.2600]
                    Username: SYSTEM
                    Computer name: NOM-3189168

                    Version information:
                    BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
                    AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
                    AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
                    LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
                    LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
                    ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
                    ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 09:10:11
                    ANTIVIR2.VDF : 7.0.3.3 2048 Bytes 07/03/2008 09:10:11
                    ANTIVIR3.VDF : 7.0.3.23 132096 Bytes 13/03/2008 09:10:11
                    AVEWIN32.DLL : 7.6.0.73 3334656 Bytes 13/03/2008 09:10:11
                    AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
                    AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
                    AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
                    AVPACK32.DLL : 7.6.0.3 360488 Bytes 13/03/2008 09:10:11
                    AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
                    AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
                    AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
                    NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
                    RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
                    RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
                    SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21

                    Configuration settings for the scan:
                    Jobname..........................: Complete system scan
                    Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
                    Logging..........................: low
                    Primary action...................: interactive
                    Secondary action.................: ignore
                    Scan master boot sector..........: on
                    Scan boot sector.................: on
                    Boot sectors.....................: E:,
                    Scan memory......................: on
                    Process scan.....................: on
                    Scan registry....................: on
                    Search for rootkits..............: on
                    Scan all files...................: All files
                    Scan archives....................: on
                    Recursion depth..................: 20
                    Smart extensions.................: on
                    Macro heuristic..................: on
                    File heuristic...................: high

                    Start of the scan: jeudi 13 mars 2008 10:59

                    Starting search for hidden objects.
                    '48727' objects were checked, '0' hidden objects were found.

                    The scan of running processes will be started
                    Scan process 'avscan.exe' - '1' Module(s) have been scanned
                    Scan process 'firefox.exe' - '1' Module(s) have been scanned
                    Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                    Scan process 'Watch.exe' - '1' Module(s) have been scanned
                    Scan process 'GoogleDesktop.exe' - '1' Module(s) have been scanned
                    Scan process 'kpf4gui.exe' - '1' Module(s) have been scanned
                    Scan process 'alg.exe' - '1' Module(s) have been scanned
                    Scan process 'rsvp.exe' - '1' Module(s) have been scanned
                    Scan process 'dllhost.exe' - '1' Module(s) have been scanned
                    Scan process 'wmpnetwk.exe' - '1' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'Remote UI Service.exe' - '1' Module(s) have been scanned
                    Scan process 'mediaserver.exe' - '1' Module(s) have been scanned
                    Scan process 'kpf4gui.exe' - '1' Module(s) have been scanned
                    Scan process 'MCLServiceATL.exe' - '1' Module(s) have been scanned
                    Scan process 'ISSM.exe' - '1' Module(s) have been scanned
                    Scan process 'ELService.exe' - '1' Module(s) have been scanned
                    Scan process 'mcrdsvc.exe' - '1' Module(s) have been scanned
                    Scan process 'X10nets.exe' - '1' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'kpf4ss.exe' - '1' Module(s) have been scanned
                    Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
                    Scan process 'inetinfo.exe' - '1' Module(s) have been scanned
                    Scan process 'IAANTmon.exe' - '1' Module(s) have been scanned
                    Scan process 'GoogleUpdaterService.exe' - '1' Module(s) have been scanned
                    Scan process 'FTRTSVC.exe' - '1' Module(s) have been scanned
                    Scan process 'ehSched.exe' - '1' Module(s) have been scanned
                    Scan process 'ehrecvr.exe' - '1' Module(s) have been scanned
                    Scan process 'sched.exe' - '1' Module(s) have been scanned
                    Scan process 'AlertService.exe' - '1' Module(s) have been scanned
                    Scan process 'ALERTM~1.EXE' - '1' Module(s) have been scanned
                    Scan process 'PollingModule.exe' - '1' Module(s) have been scanned
                    Scan process 'Inactivity.exe' - '1' Module(s) have been scanned
                    Scan process 'Toaster.exe' - '1' Module(s) have been scanned
                    Scan process 'ComComp.exe' - '1' Module(s) have been scanned
                    Scan process 'CCU_Engine.exe' - '1' Module(s) have been scanned
                    Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
                    Scan process 'GestionnaireInternet.exe' - '1' Module(s) have been scanned
                    Scan process 'TaskBarIcon.exe' - '1' Module(s) have been scanned
                    Scan process 'wmpnscfg.exe' - '1' Module(s) have been scanned
                    Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
                    Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                    Scan process 'GoogleDesktop.exe' - '1' Module(s) have been scanned
                    Scan process 'hpcmpmgr.exe' - '1' Module(s) have been scanned
                    Scan process 'hpztsb10.exe' - '1' Module(s) have been scanned
                    Scan process 'IAAnotif.exe' - '1' Module(s) have been scanned
                    Scan process 'CCU_TrayIcon.exe' - '1' Module(s) have been scanned
                    Scan process 'RTHDCPL.exe' - '1' Module(s) have been scanned
                    Scan process 'avguard.exe' - '1' Module(s) have been scanned
                    Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                    Scan process 'explorer.exe' - '1' Module(s) have been scanned
                    Scan process 'aawservice.exe' - '1' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                    Scan process 'lsass.exe' - '1' Module(s) have been scanned
                    Scan process 'services.exe' - '1' Module(s) have been scanned
                    Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                    Scan process 'csrss.exe' - '1' Module(s) have been scanned
                    Scan process 'smss.exe' - '1' Module(s) have been scanned
                    63 processes with 63 modules were scanned

                    Starting master boot sector scan:
                    Master boot sector HD0
                    [NOTE] No virus was found!
                    Master boot sector HD1
                    [NOTE] No virus was found!
                    [WARNING] The boot sector file could not be read!
                    [WARNING] Error code: 0x0015
                    Master boot sector HD2
                    [NOTE] No virus was found!
                    [WARNING] The boot sector file could not be read!
                    [WARNING] Error code: 0x0015
                    Master boot sector HD3
                    [NOTE] No virus was found!
                    [WARNING] The boot sector file could not be read!
                    [WARNING] Error code: 0x0015

                    Start scanning boot sectors:
                    Boot sector 'C:\'
                    [NOTE] No virus was found!
                    Boot sector 'D:\'
                    [NOTE] No virus was found!
                    Boot sector 'E:\'
                    [NOTE] No virus was found!

                    Starting to scan the registry.
                    The registry was scanned ( '24' files ).

                    Starting the file scan:

                    Begin scan in 'C:\' <BOOT>
                    C:\hiberfil.sys
                    [WARNING] The file could not be opened!
                    C:\pagefile.sys
                    [WARNING] The file could not be opened!
                    Begin scan in 'D:\' <BACKUP>
                    Begin scan in 'E:\' <RECOVER>

                    End of the scan: jeudi 13 mars 2008 11:24
                    Used time: 24:16 min

                    The scan has been done completely.

                    6298 Scanning directories
                    239386 Files were scanned
                    0 viruses and/or unwanted programs were found
                    0 Files were classified as suspicious:
                    0 files were deleted
                    0 files were repaired
                    0 files were moved to quarantine
                    0 files were renamed
                    2 Files cannot be scanned
                    239386 Files not concerned
                    8433 Archives were scanned
                    2 Warnings
                    0 Notes
                    48727 Objects were scanned with rootkit scan
                    0 Hidden objects were found

                    -------------------------
                    à+
                    0
                    1. Contributeur
                      trouspette,

                      tu as ete infecté par spyware secure ressament ?

                      @+
                      0
                      1. désolée de ce retard de réponse : oui, j'ai été infectée par spyware secure en téléchargeant web média player ; depuis, il me semblait m'en être débérassée;

                        antivir semble avoir effacé les dernières traces non ?

                        dits moi ce que je dois faire si tu souhaites faire de nouvelles vérifs ?

                        à+
                        0
                    2. Contributeur
                      salut trouspette,

                      peux tu paser ceci juste pour voir :

                      Fais un clic droit sur ce lien :
                      http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
                      Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
                      Ensuite double clique sur navilog1.exe pour lancer l'installation.
                      Une fois l'installation terminée, le fix s'exécutera automatiquement.
                      (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

                      Laisse-toi guider. Au menu principal, choisis 1 et valides.
                      (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

                      Patiente jusqu'au message :
                      *** Analyse Termine le ..... ***
                      Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
                      Copie-colle l'intégralité dans une réponse. Referme le blocnote.
                      Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)

                      @+
                      0
                      1. salut g!rly,

                        j'ai rencontré des problèmes pour télécharger navilog1 (antivir bloquait)
                        je suis passée outre et pendant l'ananlyse de navilog, le firewal sunbelt que tu m'as conseillé m'a signallé une tentative d'intrusion bloquée, dont rapport ci-dessous:

                        Détails techniques sur l'intrusion :

                        Application injectrice : <inconnu>(new line)
                        Description : <inconnu>(new line)
                        Version du fichier : (new line)
                        Produit : (new line)
                        Version du produit : (new line)
                        Créé le : N/A(new line)
                        Modifié le : N/A(new line)
                        Dernier accès le : N/A

                        Application cible : C:\Program Files\Navilog1\catchme.exe(new line)
                        Description : catchme(new line)
                        Version du fichier : (new line)
                        Produit : (new line)
                        Version du produit : (new line)
                        Créé le : 2008/3/20, 18:19:28(new line)
                        Modifié le : 2008/2/11, 19:01:02(new line)
                        Dernier accès le : 2008/3/20, 18:21:50

                        Adresse de l'injection : 0x7C801D77

                        voici maintenant le rapport de navilog ; sur la recherche de certificats, je sais que favorit est le nom de la boîte russe qui fourgue le spyware secure :

                        Search Navipromo version 3.5.0 commencé le 20/03/2008 à 19:21:43,67

                        !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                        !!! Postez ce rapport sur le forum pour le faire analyser !!!
                        !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

                        Outil exécuté depuis C:\Program Files\navilog1
                        Mise à jour le 04.03.2008 à 17h00 par IL-MAFIOSO

                        Microsoft Windows XP [version 5.1.2600]
                        Internet Explorer : 7.0.5730.11
                        Système de fichiers : NTFS

                        Executé en mode normal

                        *** Recherche Programmes installés ***

                        *** Recherche dossiers dans C:\WINDOWS ***

                        *** Recherche dossiers dans C:\Program Files ***

                        *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\APPLIC~1 ***

                        *** Recherche dossiers dans "C:\Documents and Settings\sarah\applic~1" ***

                        *** Recherche dossiers dans "C:\Documents and Settings\sarah\locals~1\applic~1" ***

                        *** Recherche dossiers dans "C:\Documents and Settings\sarah\menudm~1\progra~1" ***

                        *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

                        *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
                        pour + d'infos : http://www.gmer.net

                        Aucun Fichier trouvé

                        *** Recherche avec GenericNaviSearch ***
                        !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
                        !!! A vérifier impérativement avant toute suppression manuelle !!!

                        * Recherche dans C:\WINDOWS\system32 *

                        * Recherche dans "C:\Documents and Settings\sarah\locals~1\applic~1" *

                        *** Recherche fichiers ***

                        *** Recherche clés spécifiques dans le Registre ***

                        *** Module de Recherche complémentaire ***
                        (Recherche fichiers spécifiques)

                        1)Recherche nouveaux fichiers Instant Access :

                        2)Recherche Heuristique :

                        * Dans C:\WINDOWS\system32 :

                        * Dans "C:\Documents and Settings\sarah\locals~1\applic~1" :

                        3)Recherche Certificats :

                        Certificat Egroup absent !
                        Certificat Electronic-Group trouvé !
                        Certificat OOO-Favorit trouvé !

                        4)Recherche fichiers connus :

                        *** Analyse terminée le 20/03/2008 à 19:24:02,71 ***

                        merci encore de ton aide

                        à +
                        0
                    3. re g!rly,

                      j'ai fait un scan antivir et il a trouvé quelque chose qui ne me semble pas sans lien avec navilog, mais je suis pas sûre : DR/tool.Reboot.F.59

                      ci-dessous le rapport d'antivir :

                      AntiVir PersonalEdition Classic
                      Report file date: jeudi 20 mars 2008 19:40

                      Scanning for 1160082 virus strains and unwanted programs.

                      Licensed to: Avira AntiVir PersonalEdition Classic
                      Serial number: 0000149996-ADJIE-0001
                      Platform: Windows XP
                      Windows version: (Service Pack 2) [5.1.2600]
                      Username: SYSTEM
                      Computer name: NOM-3189168

                      Version information:
                      BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
                      AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
                      AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
                      LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
                      LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
                      ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
                      ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 09:10:11
                      ANTIVIR2.VDF : 7.0.3.3 2048 Bytes 07/03/2008 09:10:11
                      ANTIVIR3.VDF : 7.0.3.61 328192 Bytes 20/03/2008 18:39:28
                      AVEWIN32.DLL : 7.6.0.75 3334656 Bytes 18/03/2008 18:10:23
                      AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
                      AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
                      AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
                      AVPACK32.DLL : 7.6.0.3 360488 Bytes 13/03/2008 09:10:11
                      AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
                      AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
                      AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
                      NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
                      RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
                      RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
                      SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21

                      Configuration settings for the scan:
                      Jobname..........................: Complete system scan
                      Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
                      Logging..........................: low
                      Primary action...................: interactive
                      Secondary action.................: ignore
                      Scan master boot sector..........: on
                      Scan boot sector.................: on
                      Boot sectors.....................: E:,
                      Scan memory......................: on
                      Process scan.....................: on
                      Scan registry....................: on
                      Search for rootkits..............: on
                      Scan all files...................: All files
                      Scan archives....................: on
                      Recursion depth..................: 20
                      Smart extensions.................: on
                      Macro heuristic..................: on
                      File heuristic...................: high

                      Start of the scan: jeudi 20 mars 2008 19:40

                      Starting search for hidden objects.
                      '49018' objects were checked, '0' hidden objects were found.

                      The scan of running processes will be started
                      Scan process 'avscan.exe' - '1' Module(s) have been scanned
                      Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                      Scan process 'kpf4gui.exe' - '1' Module(s) have been scanned
                      Scan process 'Watch.exe' - '1' Module(s) have been scanned
                      Scan process 'alg.exe' - '1' Module(s) have been scanned
                      Scan process 'rsvp.exe' - '1' Module(s) have been scanned
                      Scan process 'dllhost.exe' - '1' Module(s) have been scanned
                      Scan process 'wmpnetwk.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'Remote UI Service.exe' - '1' Module(s) have been scanned
                      Scan process 'mediaserver.exe' - '1' Module(s) have been scanned
                      Scan process 'mcrdsvc.exe' - '1' Module(s) have been scanned
                      Scan process 'kpf4gui.exe' - '1' Module(s) have been scanned
                      Scan process 'MCLServiceATL.exe' - '1' Module(s) have been scanned
                      Scan process 'ISSM.exe' - '1' Module(s) have been scanned
                      Scan process 'ELService.exe' - '1' Module(s) have been scanned
                      Scan process 'X10nets.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'kpf4ss.exe' - '1' Module(s) have been scanned
                      Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
                      Scan process 'inetinfo.exe' - '1' Module(s) have been scanned
                      Scan process 'IAANTmon.exe' - '1' Module(s) have been scanned
                      Scan process 'GoogleUpdaterService.exe' - '1' Module(s) have been scanned
                      Scan process 'FTRTSVC.exe' - '1' Module(s) have been scanned
                      Scan process 'ehSched.exe' - '1' Module(s) have been scanned
                      Scan process 'ehrecvr.exe' - '1' Module(s) have been scanned
                      Scan process 'sched.exe' - '1' Module(s) have been scanned
                      Scan process 'AlertService.exe' - '1' Module(s) have been scanned
                      Scan process 'AlertModule.exe' - '1' Module(s) have been scanned
                      Scan process 'PollingModule.exe' - '1' Module(s) have been scanned
                      Scan process 'Inactivity.exe' - '1' Module(s) have been scanned
                      Scan process 'Toaster.exe' - '1' Module(s) have been scanned
                      Scan process 'GoogleDesktop.exe' - '1' Module(s) have been scanned
                      Scan process 'ComComp.exe' - '1' Module(s) have been scanned
                      Scan process 'avguard.exe' - '1' Module(s) have been scanned
                      Scan process 'GestionnaireInternet.exe' - '1' Module(s) have been scanned
                      Scan process 'CCU_Engine.exe' - '1' Module(s) have been scanned
                      Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
                      Scan process 'wmpnscfg.exe' - '1' Module(s) have been scanned
                      Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
                      Scan process 'TaskBarIcon.exe' - '1' Module(s) have been scanned
                      Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                      Scan process 'GoogleDesktop.exe' - '1' Module(s) have been scanned
                      Scan process 'hpcmpmgr.exe' - '1' Module(s) have been scanned
                      Scan process 'hpztsb10.exe' - '1' Module(s) have been scanned
                      Scan process 'IAAnotif.exe' - '1' Module(s) have been scanned
                      Scan process 'CCU_TrayIcon.exe' - '1' Module(s) have been scanned
                      Scan process 'RTHDCPL.exe' - '1' Module(s) have been scanned
                      Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                      Scan process 'explorer.exe' - '1' Module(s) have been scanned
                      Scan process 'aawservice.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'lsass.exe' - '1' Module(s) have been scanned
                      Scan process 'services.exe' - '1' Module(s) have been scanned
                      Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                      Scan process 'csrss.exe' - '1' Module(s) have been scanned
                      Scan process 'smss.exe' - '1' Module(s) have been scanned
                      62 processes with 62 modules were scanned

                      Starting master boot sector scan:
                      Master boot sector HD0
                      [NOTE] No virus was found!
                      Master boot sector HD1
                      [NOTE] No virus was found!
                      [WARNING] The boot sector file could not be read!
                      [WARNING] Error code: 0x0015
                      Master boot sector HD2
                      [NOTE] No virus was found!
                      [WARNING] The boot sector file could not be read!
                      [WARNING] Error code: 0x0015
                      Master boot sector HD3
                      [NOTE] No virus was found!
                      [WARNING] The boot sector file could not be read!
                      [WARNING] Error code: 0x0015

                      Start scanning boot sectors:
                      Boot sector 'C:\'
                      [NOTE] No virus was found!
                      Boot sector 'D:\'
                      [NOTE] No virus was found!
                      Boot sector 'E:\'
                      [NOTE] No virus was found!

                      Starting to scan the registry.
                      The registry was scanned ( '24' files ).

                      Starting the file scan:

                      Begin scan in 'C:\' <BOOT>
                      C:\hiberfil.sys
                      [WARNING] The file could not be opened!
                      C:\pagefile.sys
                      [WARNING] The file could not be opened!
                      C:\Documents and Settings\sarah\Mes documents\Nouveau dossier\Navilog1.exe
                      [DETECTION] Contains detection pattern of the dropper DR/Tool.Reboot.F.59
                      [INFO] The file was deleted!
                      Begin scan in 'D:\' <BACKUP>
                      Begin scan in 'E:\' <RECOVER>

                      End of the scan: jeudi 20 mars 2008 20:24
                      Used time: 44:42 min

                      The scan has been done completely.

                      6327 Scanning directories
                      239216 Files were scanned
                      1 viruses and/or unwanted programs were found
                      0 Files were classified as suspicious:
                      1 files were deleted
                      0 files were repaired
                      0 files were moved to quarantine
                      0 files were renamed
                      2 Files cannot be scanned
                      239215 Files not concerned
                      8424 Archives were scanned
                      2 Warnings
                      0 Notes
                      49018 Objects were scanned with rootkit scan
                      0 Hidden objects were found
                      0
                      1. Contributeur sécurité
                        slt
                        g!rly etant non dispo actuellement je poursuis un peu si tu veux bien

                        _______________

                        antivir à en effet considéré que navilog est un intrus mais pas d'inquiétude ce n'est pas le cas!

                        _______________

                        désactive antivir le temps de faire navilog avec l'option 2

                        = Lance navilog1
                        = Cette fois-ci choisi l'option 2
                        = Navilog va faire le nettoyage.. patient jusqu'à ce qui soit marqué *** Nettoyage Termine le ..... ***
                        = Un rapport va être génrer sur ton C:\ qui sera en option 2
                        Note: le bureau disparaît

                        = colle le contenu du rapport de navilog (qui est en option2)

                        PS:Si ton bureau ne réapparait pas, fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.
                        Puis rends-toi à l'onglet "processus". Clique en haut à gauche sur fichiers et choisis "exécuter"
                        Tape explorer et valide. Celà te fera apparaitre ton bureau.
                        0
                        1. Contributeur
                          Merci encore jpljpl ;-)

                          Ca y est tu m´as rendu l´appareil ;-)

                          @ bientot

                          g!rly`
                          0
                          1. Contributeur sécurité
                            de rien c'est normal je te laisse reprendre la main

                            @ bientôt
                            0
                        2. Contributeur
                          ok ;-)
                          Bonne soirée ;-)
                          @´+
                          0
                          1. bonjour jlpjlp et g!rly,

                            pardon pour absence prolongée (monde à la maison pendant 5 jours)
                            retour au calme, ai fait ce qui était préscrit, et voici le résultat navilog option 2 :

                            Clean Navipromo version 3.5.0 commencé le 28/03/2008 à 11:19:12,85

                            Outil exécuté depuis C:\Program Files\navilog1
                            Mise à jour le 04.03.2008 à 17h00 par IL-MAFIOSO

                            Microsoft Windows XP [version 5.1.2600]
                            Internet Explorer : 7.0.5730.11
                            Système de fichiers : NTFS

                            Mode suppression automatique
                            avec prise en charge résultats Catchme et GNS

                            *** fsbl1.txt non trouvé ***
                            (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)

                            *** Suppression avec sauvegardes résultats GenericNaviSearch ***

                            * Suppression dans C:\WINDOWS\System32 *

                            * Suppression dans "C:\Documents and Settings\sarah\locals~1\applic~1" *

                            *** Suppression dossiers dans C:\WINDOWS ***

                            *** Suppression dossiers dans C:\Program Files ***

                            *** Suppression dossiers dans C:\DOCUME~1\ALLUSE~1\APPLIC~1 ***

                            *** Suppression dossiers dans "C:\Documents and Settings\sarah\applic~1" ***

                            *** Suppression dossiers dans "C:\Documents and Settings\sarah\locals~1\applic~1" ***

                            *** Suppression dossiers dans "C:\Documents and Settings\sarah\menudm~1\progra~1" ***

                            *** Suppression dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

                            *** Suppression fichiers ***

                            *** Suppression fichiers temporaires ***

                            Nettoyage contenu C:\WINDOWS\Temp effectué !
                            Nettoyage contenu C:\Documents and Settings\sarah\locals~1\Temp effectué !

                            *** Traitement Recherche complémentaire ***
                            (Recherche fichiers spécifiques)

                            1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

                            2)Recherche, création sauvegardes et suppression Heuristique :

                            * Dans C:\WINDOWS\system32 *

                            * Dans "C:\Documents and Settings\sarah\locals~1\applic~1" *

                            *** Sauvegarde du Registre vers dossier Backupnavi ***

                            sauvegarde du Registre réalisée avec succès !

                            *** Nettoyage Registre ***

                            Nettoyage Registre Ok

                            *** Certificats ***

                            Certificat Egroup absent !
                            Certificat Electronic-Group supprimé !
                            Certificat OOO-Favorit supprimé !

                            *** Nettoyage terminé le 28/03/2008 à 11:22:54,98 ***

                            merci pour votre aide à tous les 2 ; j'ai l'impression que mon pc est moins lent ; que dois-je faire pour m'assurer que tout est clean maintenant (et le restera) ?
                            0
                            1. Contributeur
                              salut trouspette,

                              Fais un scan avec cet antispyware :

                              Telecharge malwarebytes

                              -> http://forum.telecharger.01net.com/forum/high-tech/PRODUITS/Questions-techniques/anti-malware-sujet_197382_1.htm

                              Tu l´instale; le programme va se mettre automatiquement a jour.

                              Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

                              Click maintenant sur l´onglet recherche et coche la case : "executer un examun complet".

                              Puis click sur "rechercher".

                              Laisse le scanner le pc...

                              Si des elements on ete trouvés > click sur supprimer la selection.

                              si il t´es demandé de redemarrer > click sur "yes".

                              A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.

                              Copie et colle le rapport stp.

                              post un nouveau rapport hijack this egalement

                              @+
                              0
                              1. Bonjour G!rly,

                                ci-dessous les deux rapports demandés ;
                                actuellement et suite à tes conseils, j'utilise comme protection : antivir, malewarebytes, spybot search and destroy, spywareblaster, ccleaner et sunbelt personnal firewall : cela te semble-t-il suffisant ? est-il suffisant de faire un balayage malewarebytes, spybot, ccleaner et antivir avec updates 1 fois par semaine ?

                                bonne journée et bon we à toi

                                RAPPORT MALWAREBYTES

                                Malwarebytes' Anti-Malware 1.08
                                Version de la base de données: 477

                                Type de recherche: Examen complet (C:\|D:\|E:\|G:\|H:\|I:\|)
                                Eléments examinés: 88759
                                Temps écoulé: 16 minute(s), 36 second(s)

                                Processus mémoire infecté(s): 0
                                Module(s) mémoire infecté(s): 0
                                Clé(s) du Registre infectée(s): 0
                                Valeur(s) du Registre infectée(s): 0
                                Elément(s) de données du Registre infecté(s): 0
                                Dossier(s) infecté(s): 0
                                Fichier(s) infecté(s): 0

                                Processus mémoire infecté(s):
                                (Aucun élément nuisible détecté)

                                Module(s) mémoire infecté(s):
                                (Aucun élément nuisible détecté)

                                Clé(s) du Registre infectée(s):
                                (Aucun élément nuisible détecté)

                                Valeur(s) du Registre infectée(s):
                                (Aucun élément nuisible détecté)

                                Elément(s) de données du Registre infecté(s):
                                (Aucun élément nuisible détecté)

                                Dossier(s) infecté(s):
                                (Aucun élément nuisible détecté)

                                Fichier(s) infecté(s):
                                (Aucun élément nuisible détecté)

                                RAPPORT HIJACKTHIS

                                Logfile of Trend Micro HijackThis v2.0.2
                                Scan saved at 16:32:50, on 29/03/2008
                                Platform: Windows XP SP2 (WinNT 5.01.2600)
                                MSIE: Internet Explorer v7.00 (7.00.6000.16608)
                                Boot mode: Normal

                                Running processes:
                                C:\WINDOWS\System32\smss.exe
                                C:\WINDOWS\system32\winlogon.exe
                                C:\WINDOWS\system32\services.exe
                                C:\WINDOWS\system32\lsass.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                C:\WINDOWS\Explorer.EXE
                                C:\WINDOWS\system32\spoolsv.exe
                                C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                C:\WINDOWS\RTHDCPL.EXE
                                C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe
                                C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
                                C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
                                C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
                                C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                                C:\WINDOWS\system32\ctfmon.exe
                                C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
                                C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                C:\Program Files\MSN Messenger\msnmsgr.exe
                                C:\Program Files\Intel\IntelDH\CCU\CCU_Engine.exe
                                C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
                                C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                C:\PROGRA~1\Wanadoo\ComComp.exe
                                C:\PROGRA~1\Wanadoo\Toaster.exe
                                C:\PROGRA~1\Wanadoo\Inactivity.exe
                                C:\PROGRA~1\Wanadoo\PollingModule.exe
                                C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                                C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
                                C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                C:\WINDOWS\eHome\ehRecvr.exe
                                C:\WINDOWS\eHome\ehSched.exe
                                C:\WINDOWS\System32\FTRTSVC.exe
                                C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                                C:\WINDOWS\system32\inetsrv\inetinfo.exe
                                C:\WINDOWS\system32\nvsvc32.exe
                                C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
                                C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\Elservice.exe
                                C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
                                C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
                                C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\WINDOWS\system32\dllhost.exe
                                C:\WINDOWS\system32\rsvp.exe
                                C:\PROGRA~1\Wanadoo\Watch.exe
                                C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
                                C:\Program Files\Mozilla Firefox\firefox.exe
                                C:\Program Files\Outlook Express\msimn.exe
                                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                                O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                                O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
                                O4 - HKLM\..\Run: [CCUTRAYICON] C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe
                                O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
                                O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
                                O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
                                O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
                                O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                                O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
                                O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                                O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                O4 - HKUS\S-1-5-21-1723211696-292700969-4135070537-1004\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'IUSR_NMPR')
                                O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
                                O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
                                O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                                O14 - IERESET.INF: START_PAGE_URL=http://www.carrefour-multimedia.fr/
                                O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
                                O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
                                O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
                                O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
                                O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab55762.cab
                                O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                                O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL
                                O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                O23 - Service: Intel(R) Alert Service (AlertService) - Intel Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
                                O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                O23 - Service: Intel(R) Quick Resume technology (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\Elservice.exe
                                O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                                O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                                O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
                                O23 - Service: Serveur Média Intel(R) Viiv(TM) (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
                                O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
                                O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
                                O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
                                O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
                                0
                                1. Contributeur
                                  salut trouspette,

                                  oui niveau protection c´est ok.

                                  tu peux passer malwarebytes ainsi que spybot une fois toutes les deux semaines voir trois.

                                  et faire un scan avec antivir une fois tout les mois et demi ou deux; mais tout depend de ce que tu fais sur le net...

                                  pour ccleaner passe le regulierement apres avoir surfer en fin de journée par exemple, et nettoie le registre surtout apres desinstallation d´un programme.

                                  tu as encore des soucis ?

                                  bonne soirée ;-)

                                  @+
                                  0
                                  1. salut g!rly,

                                    plus de soucis pour le moment, grâce à toi . merci beaucoup pour ton aide et ta patience .
                                    0
                                    • 1
                                    • 2