éliminer navipromo!

Bonjour,

je suis envahi par navipromo!!!
je posséde bitdefender 08

je ne suis trés expérimenté en informatique donc s'il vous plaît donné moi des conseils simple!

voici le rapport de bitdefender

Fichier journal de BitDefender
Produit : BitDefender Antivirus 2008
Version : BitDefender UIScanner V.11
Date du journal : 15:40:36 14/03/2008
Chemin du journal : C:\ProgramData\Bitdefender\Desktop\Profiles\Logs\deep_scan\1205505636_1_02.xml
Analyse des chemins :
Chemin0000: C:\
Chemin0001: D:\

Options d’analyse :
Analyse contre les virus : Oui
Détecter les adwares : Oui
Analyse contre les spywares : Oui
Analyse des applications : Oui
Détecter les numéroteurs : Oui
Analyse contre les Rootkits : Oui

Options de sélection de cible :
Analyse les clés du registre : Oui
Analyse des cookies : Oui
Analyser le secteur de boot : Oui
Analyse des processus mémoire : Oui
Analyser les archives : Oui
Analyser les fichiers enpaquetés : Oui
Analyser les emails : Oui
Analyser tous les fichiers : Oui
Analyse heuristique : Oui
Extensions analysées :
Extensions exclues :

Traitement cible
Action par défaut pour les objets infectés : Désinfecter
Action par défaut pour les objets suspects : Aucun
Action par défaut pour les objets camouflés : Aucun

Résumé de l'analyse
Nombre de signatures de virus : 995195
Plugins archives : 41
Plug-ins messagerie : 6
Plugins d'analyse : 12
Plugins archives : 41
Plug-ins système : 4
Plug-ins décompression : 7

Résumé de l'analyse générale
Eléments analysés : 237445
Eléments infectés : 8
Eléments suspects : 0
Eléments résolus : 0
Virus individuels trouvés : 2
Répertoires analysés : 15332
Secteur de boot analysés : 5
Archives analysés : 5349
Erreurs I/O : 96
Temps d'analyse : 00:01:23:21
Fichiers par seconde : 47

Résumé des processus analysés
Analysé(s) : 78
Infecté(s) : 0

Résumé des clés de registre analysées
Analysé(s) : 427
Infecté(s) : 0

Résumé des cookies analysés
Analysé(s) : 1
Infecté(s) : 0

Problèmes non résolus :
Nom de l'objet Nom de la menace Etat final
C:\Users\cécile\AppData\Local\Temp\pack.epk=](NSIS 2g)=]lzma_solid_nsis0008 Adware.MSNSkinner.A Echec de la suppression (fichier dans une archive)
C:\Users\cécile\AppData\Local\Temp\pack.epk=](NSIS 2g)=]lzma_solid_nsis0009 Adware.MSNSkinner.A Echec de la suppression (fichier dans une archive)
C:\Windows\Temp\NSIS_install_msgskinner.exe=](NSIS o)=]lzma_solid_nsis0008 Adware.MSNSkinner.A Echec de la suppression (fichier dans une archive)
C:\Windows\Temp\NSIS_install_msgskinner.exe=](NSIS o)=]lzma_solid_nsis0009 Adware.MSNSkinner.A Echec de la suppression (fichier dans une archive)
C:\Users\cécile\AppData\Local\Temp\pack.epk=](NSIS 2g)=]lzma_solid_nsis0006 Adware.Navipromo.BZN Echec de la suppression (fichier dans une archive)
C:\Users\cécile\AppData\Local\Temp\pack.epk=](NSIS 2g)=]lzma_solid_nsis0028=](NSIS g)=]lzma_solid_nsis0005 Adware.Navipromo.BZN Echec de la suppression (fichier dans une archive)
C:\Windows\Temp\NSIS_install_msgskinner.exe=](NSIS o)=]lzma_solid_nsis0006 Adware.Navipromo.BZN Echec de la suppression (fichier dans une archive)
C:\Windows\Temp\NSIS_install_msgskinner.exe=](NSIS o)=]lzma_solid_nsis0028=](NSIS g)=]lzma_solid_nsis0005 Adware.Navipromo.BZN Echec de la suppression (fichier dans une archive)

Problèmes résolus
Nom de l'objet Nom de la menace Etat final

Objets non scannés :
Nom de l'objet Raison Etat final

et ensuite la recherche de navilog1

Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

Outil exécuté depuis C:\Program Files\navilog1
Mise à jour le 04.03.2008 à 17h00 par IL-MAFIOSO

Microsoft Windows Vista 6.0.6000
Internet Explorer : 7.0.6000.16609
Système de fichiers : NTFS

Executé en mode normal

*** Recherche Programmes installés ***

*** Recherche dossiers dans C:\Windows ***

*** Recherche dossiers dans C:\Program Files ***

*** Recherche dossiers dans C:\ProgramData ***

*** Recherche dossiers dans C:\ProgramData\Microsoft\Windows\Start Menu\Programs ***

...\MessengerSkinner trouvé !

*** Recherche dossiers dans C:\Users\c‚cile\AppData\Local\virtualstore\Program Files ***

*** Recherche dossiers dans C:\Users\c‚cile\AppData\Roaming ***

...\MessengerSkinner trouvé !

*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net

Fichier(s) caché(s) :

C:\Users\cécile\AppData\Local\mkuexzkvm.dat
C:\Users\cécile\AppData\Local\mkuexzkvm.exe
C:\Users\cécile\AppData\Local\mkuexzkvm_nav.dat
C:\Users\cécile\AppData\Local\mkuexzkvm_navps.dat

*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!

* Recherche dans C:\Windows\system32 *

* Recherche dans C:\Users\c‚cile\AppData\Local\Microsoft *

* Recherche dans C:\Users\c‚cile\AppData\Local *

Fichiers suspects :

mkuexzkvm.exe trouvé !
mkuexzkvm.dat trouvé !
mkuexzkvm_nav.dat trouvé !
mkuexzkvm_navps.dat trouvé !

*** Recherche fichiers ***

C:\Windows\system32\nvs2.inf trouvé !

*** Recherche clés spécifiques dans le Registre ***

*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)

1)Recherche nouveaux fichiers Instant Access :

2)Recherche Heuristique :

* Dans C:\Windows\system32 :

* Dans C:\Users\c‚cile\AppData\Local\Microsoft :

* Dans C:\Users\c‚cile\AppData\Local :

mkuexzkvm.dat trouvé !
mkuexzkvm_nav.dat trouvé !
mkuexzkvm_navps.dat trouvé !

3)Recherche Certificats :

Certificat Egroup trouvé !
Certificat Electronic-Group trouvé !
Certificat OOO-Favorit trouvé !

4)Recherche fichiers connus :

*** Analyse terminée le 15/03/2008 à 16:31:45,16 ***

merci d'avance pour vos réponse!

et j'ai déjà vidé ma poubelle!
Configuration: Windows Vista
Internet Explorer 7.0

39 réponses

Résumé de la discussion

Infection Navipromo signalée sur Windows Vista, détectée par BitDefender 2008 avec 8 éléments infectés et des fichiers cachés dans AppData Local et dans les dossiers Temp. Plusieurs éléments de réponse préconisent l'exécution en mode administrateur de Navilog1 pour une désinfection automatique et l'utilisation d'outils comme HijackThis pour générer des rapports et orienter l'analyse. D'autres conseils mentions le nettoyage automatique via Navilog1, la vérification des résultats avant toute suppression manuelle et l'éventuelle remaniement du nom d'exécutable pour HijackThis afin d'éviter le contournement des détections. Des zones repérées, comme des fichiers dans AppData Local et dans C:\Windows\Temp, nécessitent une vérification approfondie car certains éléments peuvent être légitimes et la suppression indépendante peut endommager le système.

Bobot (l’IA à votre service)
  1. Désinfection automatique
    • Sous Windows Vista : Faire un clic droit sur l’icône Navilog1 qui se trouve sur le bureau, et
    Choisir « exécuter en tant qu’administrateur » Sous XP passer cette phase

    • Double-click sur le raccourci navilog1 du bureau et refaire les mêmes opérations que
    dans la section Recherche de fichiers infectieux de cet article jusqu'à arriver au menu de Navilog1

    • Pour lancer le nettoyage automatique, taper 2
    • Appuyer sur la touche Entrée.

    Laisser Navilog1 travailler et être patient !
    Il demandera d'enregistrer les documents en cours d'utilisation, car il aura besoin de redémarrer le PC.


    • Quand le PC sera prêt à redémarrer, appuyer sur une touche du clavier et laisser Navilog1 opérer.
    • Une fois le PC redémarré, Navilog1 terminera la désinfection et il fournira un rapport de désinfection.
    • L'enregistrer si besoin, par exemple si on demande de le poster sur un forum (menu Edition / Enregistrer sous).
    Sans quoi le rapport sera quand même sauvegardé dans le fichier suivant : "cleannavi.txt"
    à la racine du disque dur (ex : C:\cleannavi.txt).

    ==================== HIJACKTHIS ======================

    HijackThis

    • Télécharger HijackThis
    • Installer HijackThis en se laissant guider
    • Renommer HijackThis.exe en Monjack.exe
    • Fermer toutes les applications
    • Lancer hitjackthis
    • Click sur Do a system scan and save a logfile
    • Copier/Coller le rapport dans le prochain message

    _
    1
    1. tu as essyer avec ccleanear?
      0
      1. non c'est quoi???

        faut un truc pas trop compliqué pour une puvre blonde comme moi!?

        dis moi si c'est simple je fais !!!
        0
        1. Si tu ne fais pas tu resteras infectée
          0
      2. j'ai fait le choix 2 mais il me demande de faire d'abord une recherche je suposse que c'est parce que la recherche que j'avais fait date de hier du coup je relançé la recherche!

        merci à vous 2 vous etes trop génial!!

        je vous tiens au courant!
        0
        1. Clean Navipromo version 3.5.0 commencé le 17/03/2008 à 16:39:35,76

          Outil exécuté depuis C:\Program Files\navilog1
          Mise à jour le 04.03.2008 à 17h00 par IL-MAFIOSO

          Microsoft Windows Vista 6.0.6000
          Internet Explorer : 7.0.6000.16609
          Système de fichiers : NTFS

          Mode suppression automatique
          avec prise en charge résultats Catchme et GNS

          *** Creation backups fichiers trouvés par Catchme ***

          Copie vers "C:\Program Files\navilog1\Backupnavi"

          Copie C:\Users\cécile\AppData\Local\mkuexzkvm.dat réalisée avec succès !
          Copie C:\Users\cécile\AppData\Local\mkuexzkvm.exe réalisée avec succès !
          Copie C:\Users\cécile\AppData\Local\mkuexzkvm_nav.dat réalisée avec succès !
          Copie C:\Users\cécile\AppData\Local\mkuexzkvm_navps.dat réalisée avec succès !

          *** Suppression des fichiers trouvés avec Catchme ***

          ** 2ème passage avec résultats Catchme **

          * Dans C:\Windows\system32 *

          * Dans C:\Users\c‚cile\AppData\Local\Microsoft *

          * Dans C:\Users\c‚cile\AppData\Local *

          mkuexzkvm.exe trouvé !
          Copie mkuexzkvm.exe réalisée avec succès !
          mkuexzkvm.exe supprimé !

          mkuexzkvm.dat trouvé !
          Copie mkuexzkvm.dat réalisée avec succès !
          mkuexzkvm.dat supprimé !

          mkuexzkvm_nav.dat trouvé !
          Copie mkuexzkvm_nav.dat réalisée avec succès !
          mkuexzkvm_nav.dat supprimé !

          mkuexzkvm_navps.dat trouvé !
          Copie mkuexzkvm_navps.dat réalisée avec succès !
          mkuexzkvm_navps.dat supprimé !

          *** Suppression avec sauvegardes résultats GenericNaviSearch ***

          * Suppression dans C:\Windows\System32 *

          * Suppression dans C:\Users\c‚cile\AppData\Local\Microsoft *

          * Suppression dans C:\Users\c‚cile\AppData\Local *

          *** Suppression dossiers dans C:\Windows ***

          *** Suppression dossiers dans C:\Program Files ***

          *** Suppression dossiers dans C:\ProgramData ***

          *** Suppression dossiers dans C:\ProgramData\Microsoft\Windows\Start Menu\Programs ***

          *** Suppression dossiers dans C:\Users\c‚cile\AppData\Local\virtualstore\Program Files ***

          *** Suppression dossiers dans C:\Users\c‚cile\AppData\Roaming ***

          *** Suppression fichiers ***

          *** Suppression fichiers temporaires ***

          Nettoyage contenu C:\Windows\Temp effectué !
          Nettoyage contenu C:\Users\CCILE~1\AppData\Local\Temp effectué !

          *** Traitement Recherche complémentaire ***
          (Recherche fichiers spécifiques)

          1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

          2)Recherche, création sauvegardes et suppression Heuristique :

          * Dans C:\Windows\system32 *

          * Dans C:\Users\c‚cile\AppData\Local\Microsoft *

          * Dans C:\Users\c‚cile\AppData\Local *

          *** Sauvegarde du Registre vers dossier Backupnavi ***

          sauvegarde du Registre réalisée avec succès !

          *** Nettoyage Registre ***

          Nettoyage Registre Ok

          *** Certificats ***

          Certificat Egroup supprimé !
          Certificat Electronic-Group supprimé !
          Certificat OOO-Favorit supprimé !

          *** Nettoyage terminé le 17/03/2008 à 16:47:52,90 ***

          voici le rapport de navilog choix 2

          donc si j'ai bien compris je fais la seconde étape je télécharge HIJACKTHIS et je suis les instuction!

          je vous tiens au courant!
          0
          1. punaise falait préciser que c'était écrit en anglais!!!

            bon j'éspére avoir fait ce qu'il falait!

            j'ai pas changer le nom c'est grave!????

            voilà le rapport!

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 16:55:43, on 17/03/2008
            Platform: Windows Vista (WinNT 6.00.1904)
            MSIE: Internet Explorer v7.00 (7.00.6000.16609)
            Boot mode: Normal

            Running processes:
            C:\Windows\system32\Dwm.exe
            C:\Windows\Explorer.EXE
            C:\Windows\system32\taskeng.exe
            C:\Windows\system32\conime.exe
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            C:\Windows\OEM02Mon.exe
            C:\Windows\System32\rundll32.exe
            C:\Windows\System32\rundll32.exe
            C:\Program Files\Java\jre1.6.0\bin\jusched.exe
            C:\Windows\System32\rundll32.exe
            C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
            C:\Program Files\Dell\MediaDirect\PCMService.exe
            C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
            C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
            C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
            C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
            C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
            C:\Windows\ehome\ehtray.exe
            C:\Program Files\Windows Live\Messenger\msnmsgr.exe
            C:\Program Files\Dell Support Center\bin\sprtcmd.exe
            C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
            C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
            C:\Program Files\Dell\DELL Webcam Manager\DellWMgr.exe
            C:\Program Files\Windows Media Player\wmpnscfg.exe
            C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
            C:\Program Files\Digital Line Detect\DLG.exe
            C:\Program Files\Dell\QuickSet\quickset.exe
            C:\Windows\ehome\ehmsas.exe
            C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
            C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
            C:\PROGRA~1\INCRED~1\bin\ImApp.exe
            c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
            C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
            C:\Program Files\Internet Explorer\ieuser.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
            C:\Windows\system32\Macromed\Flash\FlashUtil9e.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
            C:\Windows\system32\SearchFilterHost.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer fourni par Dell
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
            O1 - Hosts: ::1 localhost
            O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
            O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
            O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
            O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
            O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
            O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
            O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "c:\Program Files\Java\jre1.6.0\bin\jusched.exe"
            O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
            O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
            O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
            O4 - HKLM\..\Run: [dscactivate] c:\dell\dsca.exe 3
            O4 - HKLM\..\Run: [ECenter] c:\dell\E-Center\EULALauncher.exe
            O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
            O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
            O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe"
            O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe"
            O4 - HKLM\..\Run: [PPort11reminder] "C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini
            O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
            O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
            O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
            O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
            O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
            O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
            O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
            O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8
            O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
            O4 - HKCU\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\DELL Webcam Manager\DellWMgr.exe" /s
            O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
            O4 - HKCU\..\Run: [mkuexzkvm] c:\users\cécile\appdata\local\mkuexzkvm.exe mkuexzkvm
            O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
            O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
            O4 - Global Startup: BTTray.lnk = ?
            O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
            O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
            O4 - Global Startup: QuickSet.lnk = ?
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
            O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
            O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
            O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
            O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
            O13 - Gopher Prefix:
            O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/VistaMSNPUpldfr-fr.cab
            O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
            O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
            O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\Windows\System32\LEXBCES.EXE
            O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
            O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
            O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
            O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
            O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\STacSV.exe
            O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
            O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
            O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
            O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
            0
            1. Bon, y a eu du ménage de fait, mais il en reste, je te prépare la suite.

              Oui, change le nom de

              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

              en

              C:\Program Files\Trend Micro\HijackThis\MonJack.exe

              Certaines infection se cache d'HJ si on ne change pas son nom.
              0
              1. c'est bon j'ai fait un clic droit sur l'icone du bureau et mis le nouveau nom!!

                donc je pense que c'est bon!?

                je fais quoi maintenant!
                0
                1. ----------------------- Fixer des lignes HitjackThis -------------------

                  Relancer Hitjackthis

                  • Fixer cette/ces lignes


                  O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
                  O4 - HKCU\..\Run: [mkuexzkvm] c:\users\cécile\appdata\local\mkuexzkvm.exe mkuexzkvm


                  • Pour fixer cette/ces lignes.
                  • Cliquer sur la petite case à gauche de chaque ligne à fixer.

                  • Une fois cette/ces lignes cochées, cliquer sur le bouton en bas FIX CHECKED
                  • Fermer et relancer HitJackThis
                  • Copier/Coller le nouveau rapport sur le forum.
                  </gras>

                  • Pour fixer cette/ces lignes.
                  • Cliquer sur la petite case à gauche de chaque ligne à fixer.

                  • Une fois cette/ces lignes cochées, cliquer sur le bouton en bas FIX CHECKED

                  ========================= OTMOVE IT ===========================

                  OteMoveIt

                  • Télécharger : OteMoveIt
                  • L'installer sur le bureau
                  • Le lancer.
                  • S'Assurer que la case Unregister Dll's and Ocx's soit bien cochée.
                  • Copier/Coller les lignes ci-dessous en gras de OTMoveIt nommé
                  Paste Standard List of Files/Folders to move.


                  c:\users\cécile\appdata\local\mkuexzkvm.exe
                  C:\Windows\OEM02Mon.exe
                  C:\Users\cécile\AppData\Local\Temp\pack.epk
                  C:\Windows\Temp\NSIS_install_msgskinner.exe
                  c:\windows\oem02mon.exe
                  c:\users\cécile\appdata\local\mkuexzkvm.exe


                  • Click sur MoveIt! pour lancer la suppression.
                  • Si OTMoveIt propose de redémarrer le PC, accepter !
                  • Lorsque un résultat apparaît dans le cadre Results, click sur Exit.
                  • Copier/Coller sur le forum le rapport de OTMoveIt situé sur C:\_OTMoveIt\MovedFiles.

                  ===================== COMBOFIX ========================

                  Combofix

                  Installer ComboFix sur le bureau
                  Note :
                  Le serveur de téléchargement peut être en surcharge et renvoyer une page d'erreur. Il faut insister.


                  • Se déconnecter d'internet
                  • Désactiver seulement pendant l'utilisation de ComboFix, la protection de l'antivirus et de l'antispyware ceux-ci pouvant entraver le bon fonctionnement de combofix
                  • Fermer toutes les applications en cours
                  • Double-click sur l'icône qui s'est installé sur le bureau
                  • Appuyer sur la touche 1 puis sur entrée:
                  • Laisser Combofix travailler sans se servir de la machine.
                  • Si ComboFix a besoin de redémarrer la machine, laisser faire.
                  • Réactiver la protection de l'antivirus et de l'antispyware

                  • Copier/Coller le rapport généré dans le bloc-note dans le prochain message
                  (Ce fichier est automatiquement généré et enregistré sous C:\Combofix.txt)

                  Si la machine a redémarrer,
                  • Copier/Coller un nouveau rapport sur le forum sinon le faire après avoir redémarrer la machine
                  0
                  1. c'est bon j'ai fait un clic droit sur l'icone du bureau et mis le nouveau nom!!

                    donc je pense que c'est bon!?

                    Non, c'es pas bon, il faut le renommer là ou il est Cad C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                    0
                    1. Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 16:55:43, on 17/03/2008
                      Platform: Windows Vista (WinNT 6.00.1904)
                      MSIE: Internet Explorer v7.00 (7.00.6000.16609)
                      Boot mode: Normal

                      Running processes:
                      C:\Windows\system32\Dwm.exe
                      C:\Windows\Explorer.EXE
                      C:\Windows\system32\taskeng.exe
                      C:\Windows\system32\conime.exe
                      C:\Program Files\Windows Defender\MSASCui.exe
                      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                      C:\Windows\OEM02Mon.exe
                      C:\Windows\System32\rundll32.exe
                      C:\Windows\System32\rundll32.exe
                      C:\Program Files\Java\jre1.6.0\bin\jusched.exe
                      C:\Windows\System32\rundll32.exe
                      C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
                      C:\Program Files\Dell\MediaDirect\PCMService.exe
                      C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                      C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
                      C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
                      C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                      C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
                      C:\Windows\ehome\ehtray.exe
                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                      C:\Program Files\Dell Support Center\bin\sprtcmd.exe
                      C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                      C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
                      C:\Program Files\Dell\DELL Webcam Manager\DellWMgr.exe
                      C:\Program Files\Windows Media Player\wmpnscfg.exe
                      C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
                      C:\Program Files\Digital Line Detect\DLG.exe
                      C:\Program Files\Dell\QuickSet\quickset.exe
                      C:\Windows\ehome\ehmsas.exe
                      C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                      C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
                      C:\PROGRA~1\INCRED~1\bin\ImApp.exe
                      c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
                      C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
                      C:\Program Files\Internet Explorer\ieuser.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                      C:\Windows\system32\Macromed\Flash\FlashUtil9e.exe
                      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                      C:\Windows\system32\SearchFilterHost.exe

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer fourni par Dell
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                      O1 - Hosts: ::1 localhost
                      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
                      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                      O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                      O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
                      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                      O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
                      O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                      O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "c:\Program Files\Java\jre1.6.0\bin\jusched.exe"
                      O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
                      O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
                      O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
                      O4 - HKLM\..\Run: [dscactivate] c:\dell\dsca.exe 3
                      O4 - HKLM\..\Run: [ECenter] c:\dell\E-Center\EULALauncher.exe
                      O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                      O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
                      O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe"
                      O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe"
                      O4 - HKLM\..\Run: [PPort11reminder] "C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini
                      O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
                      O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
                      O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                      O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
                      O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
                      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                      O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
                      O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8
                      O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
                      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                      O4 - HKCU\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\DELL Webcam Manager\DellWMgr.exe" /s
                      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                      O4 - HKCU\..\Run: [mkuexzkvm] c:\users\cécile\appdata\local\mkuexzkvm.exe mkuexzkvm
                      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                      O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
                      O4 - Global Startup: BTTray.lnk = ?
                      O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
                      O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                      O4 - Global Startup: QuickSet.lnk = ?
                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
                      O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                      O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
                      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
                      O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                      O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                      O13 - Gopher Prefix:
                      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/VistaMSNPUpldfr-fr.cab
                      O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
                      O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                      O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\Windows\System32\LEXBCES.EXE
                      O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
                      O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                      O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                      O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
                      O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\STacSV.exe
                      O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                      O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
                      O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                      O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
                      0
                      1. Non, il y a des choses à faire avant

                        je te remet la procédure, il faut la faire dans l'ordre

                        ----------------------- Fixer des lignes HitjackThis -------------------

                        Relancer Hitjackthis

                        • Fixer cette/ces lignes


                        O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
                        O4 - HKCU\..\Run: [mkuexzkvm] c:\users\cécile\appdata\local\mkuexzkvm.exe mkuexzkvm


                        • Pour fixer cette/ces lignes.
                        • Cliquer sur la petite case à gauche de chaque ligne à fixer.

                        • Une fois cette/ces lignes cochées, cliquer sur le bouton en bas FIX CHECKED
                        • Fermer et relancer HitJackThis
                        • Copier/Coller le nouveau rapport sur le forum.
                        </gras>

                        • Pour fixer cette/ces lignes.
                        • Cliquer sur la petite case à gauche de chaque ligne à fixer.

                        • Une fois cette/ces lignes cochées, cliquer sur le bouton en bas FIX CHECKED

                        ========================= OTMOVE IT ===========================

                        OteMoveIt

                        • Télécharger : OteMoveIt
                        • L'installer sur le bureau
                        • Le lancer.
                        • S'Assurer que la case Unregister Dll's and Ocx's soit bien cochée.
                        • Copier/Coller les lignes ci-dessous en gras de OTMoveIt nommé
                        Paste Standard List of Files/Folders to move.


                        c:\users\cécile\appdata\local\mkuexzkvm.exe
                        C:\Windows\OEM02Mon.exe
                        C:\Users\cécile\AppData\Local\Temp\pack.epk
                        C:\Windows\Temp\NSIS_install_msgskinner.exe
                        c:\windows\oem02mon.exe
                        c:\users\cécile\appdata\local\mkuexzkvm.exe


                        • Click sur MoveIt! pour lancer la suppression.
                        • Si OTMoveIt propose de redémarrer le PC, accepter !
                        • Lorsque un résultat apparaît dans le cadre Results, click sur Exit.
                        • Copier/Coller sur le forum le rapport de OTMoveIt situé sur C:\_OTMoveIt\MovedFiles.

                        ===================== COMBOFIX ========================

                        Combofix

                        Installer ComboFix sur le bureau
                        Note :
                        Le serveur de téléchargement peut être en surcharge et renvoyer une page d'erreur. Il faut insister.


                        • Se déconnecter d'internet
                        • Désactiver seulement pendant l'utilisation de ComboFix, la protection de l'antivirus et de l'antispyware ceux-ci pouvant entraver le bon fonctionnement de combofix
                        • Fermer toutes les applications en cours
                        • Double-click sur l'icône qui s'est installé sur le bureau
                        • Appuyer sur la touche 1 puis sur entrée:
                        • Laisser Combofix travailler sans se servir de la machine.
                        • Si ComboFix a besoin de redémarrer la machine, laisser faire.
                        • Réactiver la protection de l'antivirus et de l'antispyware

                        • Copier/Coller le rapport généré dans le bloc-note dans le prochain message
                        (Ce fichier est automatiquement généré et enregistré sous C:\Combofix.txt)

                        Si la machine a redémarrer,
                        • Copier/Coller un nouveau rapport sur le forum sinon le faire après avoir redémarrer la machine
                        0
                        1. booddha m'oublie pas s'il te plait!!!
                          0
                      2. je comprends pas j'ai coché les deux lignes j'ai cliqué sur fix cheked

                        ça m'as affiché un truc en anglais

                        et j'ai fais ok!

                        j'ai posté le rapport donc je vois pas ce qu'il y as à faire d'autre avant otmove it!

                        jy dsl mais je comprends pas grand chose à tout ça et je voudrais pas faire une bourde...

                        je te remets le rapport de monjack

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 16:55:43, on 17/03/2008
                        Platform: Windows Vista (WinNT 6.00.1904)
                        MSIE: Internet Explorer v7.00 (7.00.6000.16609)
                        Boot mode: Normal

                        Running processes:
                        C:\Windows\system32\Dwm.exe
                        C:\Windows\Explorer.EXE
                        C:\Windows\system32\taskeng.exe
                        C:\Windows\system32\conime.exe
                        C:\Program Files\Windows Defender\MSASCui.exe
                        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                        C:\Windows\OEM02Mon.exe
                        C:\Windows\System32\rundll32.exe
                        C:\Windows\System32\rundll32.exe
                        C:\Program Files\Java\jre1.6.0\bin\jusched.exe
                        C:\Windows\System32\rundll32.exe
                        C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
                        C:\Program Files\Dell\MediaDirect\PCMService.exe
                        C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                        C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
                        C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
                        C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                        C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
                        C:\Windows\ehome\ehtray.exe
                        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                        C:\Program Files\Dell Support Center\bin\sprtcmd.exe
                        C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                        C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
                        C:\Program Files\Dell\DELL Webcam Manager\DellWMgr.exe
                        C:\Program Files\Windows Media Player\wmpnscfg.exe
                        C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
                        C:\Program Files\Digital Line Detect\DLG.exe
                        C:\Program Files\Dell\QuickSet\quickset.exe
                        C:\Windows\ehome\ehmsas.exe
                        C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                        C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
                        C:\PROGRA~1\INCRED~1\bin\ImApp.exe
                        c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
                        C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
                        C:\Program Files\Internet Explorer\ieuser.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                        C:\Windows\system32\Macromed\Flash\FlashUtil9e.exe
                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                        C:\Windows\system32\SearchFilterHost.exe

                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer fourni par Dell
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                        O1 - Hosts: ::1 localhost
                        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
                        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                        O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
                        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                        O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
                        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                        O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
                        O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                        O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "c:\Program Files\Java\jre1.6.0\bin\jusched.exe"
                        O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
                        O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
                        O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
                        O4 - HKLM\..\Run: [dscactivate] c:\dell\dsca.exe 3
                        O4 - HKLM\..\Run: [ECenter] c:\dell\E-Center\EULALauncher.exe
                        O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                        O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
                        O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe"
                        O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe"
                        O4 - HKLM\..\Run: [PPort11reminder] "C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini
                        O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
                        O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
                        O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                        O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
                        O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
                        O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                        O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
                        O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8
                        O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
                        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                        O4 - HKCU\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\DELL Webcam Manager\DellWMgr.exe" /s
                        O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                        O4 - HKCU\..\Run: [mkuexzkvm] c:\users\cécile\appdata\local\mkuexzkvm.exe mkuexzkvm
                        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                        O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
                        O4 - Global Startup: BTTray.lnk = ?
                        O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
                        O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                        O4 - Global Startup: QuickSet.lnk = ?
                        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
                        O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                        O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
                        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
                        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
                        O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                        O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                        O13 - Gopher Prefix:
                        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/VistaMSNPUpldfr-fr.cab
                        O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
                        O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                        O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\Windows\System32\LEXBCES.EXE
                        O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
                        O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                        O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                        O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
                        O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\STacSV.exe
                        O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                        O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
                        O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                        O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
                        0
                        1. de toute façon j'avais déjà lançé OTMOVE IT

                          donc je te mets quand même le rapport
                          File/Folder c:\users\cécile\appdata\local\mkuexzkvm.exe not found.
                          File move failed. C:\Windows\OEM02Mon.exe scheduled to be moved on reboot.
                          File/Folder C:\Users\cécile\AppData\Local\Temp\pack.epk not found.
                          File/Folder C:\Windows\Temp\NSIS_install_msgskinner.exe not found.
                          File move failed. c:\windows\oem02mon.exe scheduled to be moved on reboot.
                          File/Folder c:\users\cécile\appdata\local\mkuexzkvm.exe not found.

                          OTMoveIt2 by OldTimer - Version 1.0.21 log created on 03172008_172941


                          dis moi si c'est pas bon!!!

                          et si il faut recommencer!!

                          jy dsl jy pas doué!
                          0
                          1. bon je suposse que t'es plus là on finiras demain!!!

                            je veut vraiment me débarrassé de ce truc!
                            0
                            1. Si, si je suis là.

                              Relance ta machine et nouveau rapport hitjackthis

                              -
                              0
                              1. donc j'ai redémarrer

                                et voici le nouveau rapport

                                Logfile of Trend Micro HijackThis v2.0.2
                                Scan saved at 19:17:46, on 17/03/2008
                                Platform: Windows Vista (WinNT 6.00.1904)
                                MSIE: Internet Explorer v7.00 (7.00.6000.16609)
                                Boot mode: Normal

                                Running processes:
                                C:\Windows\system32\Dwm.exe
                                C:\Windows\system32\taskeng.exe
                                C:\Windows\Explorer.EXE
                                C:\Program Files\Windows Defender\MSASCui.exe
                                C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                C:\Windows\OEM02Mon.exe
                                C:\Windows\System32\rundll32.exe
                                C:\Windows\System32\rundll32.exe
                                C:\Program Files\Java\jre1.6.0\bin\jusched.exe
                                C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
                                C:\Program Files\Dell\MediaDirect\PCMService.exe
                                C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
                                C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
                                C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                                C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
                                C:\Windows\ehome\ehtray.exe
                                C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                C:\Windows\System32\rundll32.exe
                                C:\Program Files\Dell Support Center\bin\sprtcmd.exe
                                C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                                C:\Program Files\Dell\DELL Webcam Manager\DellWMgr.exe
                                C:\Program Files\Windows Media Player\wmpnscfg.exe
                                C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
                                C:\Program Files\Digital Line Detect\DLG.exe
                                C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                                C:\Program Files\Dell\QuickSet\quickset.exe
                                C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
                                C:\Windows\ehome\ehmsas.exe
                                C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
                                c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
                                C:\PROGRA~1\INCRED~1\bin\ImApp.exe
                                C:\Windows\system32\SearchFilterHost.exe
                                C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
                                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer fourni par Dell
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                O1 - Hosts: ::1 localhost
                                O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
                                O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                                O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
                                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                                O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
                                O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
                                O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                                O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                                O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
                                O4 - HKLM\..\Run: [SunJavaUpdateSched] "c:\Program Files\Java\jre1.6.0\bin\jusched.exe"
                                O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
                                O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
                                O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
                                O4 - HKLM\..\Run: [dscactivate] c:\dell\dsca.exe 3
                                O4 - HKLM\..\Run: [ECenter] c:\dell\E-Center\EULALauncher.exe
                                O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                                O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
                                O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe"
                                O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe"
                                O4 - HKLM\..\Run: [PPort11reminder] "C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini
                                O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
                                O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
                                O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                                O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
                                O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
                                O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                                O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
                                O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8
                                O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
                                O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                                O4 - HKCU\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\DELL Webcam Manager\DellWMgr.exe" /s
                                O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
                                O4 - Global Startup: BTTray.lnk = ?
                                O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
                                O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                                O4 - Global Startup: QuickSet.lnk = ?
                                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
                                O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                                O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
                                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
                                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
                                O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
                                O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                                O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                                O13 - Gopher Prefix:
                                O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/VistaMSNPUpldfr-fr.cab
                                O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
                                O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\Windows\System32\LEXBCES.EXE
                                O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
                                O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                                O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                                O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
                                O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\STacSV.exe
                                O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                                O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
                                O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                                O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
                                0
                            2. Tu as fait

                              ===================== COMBOFIX ========================

                              Combofix

                              Installer ComboFix sur le bureau
                              Note :
                              Le serveur de téléchargement peut être en surcharge et renvoyer une page d'erreur. Il faut insister.

                              • Se déconnecter d'internet
                              • Désactiver seulement pendant l'utilisation de ComboFix, la protection de l'antivirus et de l'antispyware ceux-ci pouvant entraver le bon fonctionnement de combofix
                              • Fermer toutes les applications en cours
                              • Double-click sur l'icône qui s'est installé sur le bureau
                              • Appuyer sur la touche 1 puis sur entrée:
                              • Laisser Combofix travailler sans se servir de la machine.
                              • Si ComboFix a besoin de redémarrer la machine, laisser faire.
                              • Réactiver la protection de l'antivirus et de l'antispyware

                              • Copier/Coller le rapport généré dans le bloc-note dans le prochain message
                              (Ce fichier est automatiquement généré et enregistré sous C:\Combofix.txt)

                              Si la machine a redémarrer,
                              • Copier/Coller un nouveau rapport sur le forum sinon le faire après avoir redémarrer la machine
                              0
                              • 1
                              • 2