Dysfonctionnement

Fermé
dw 37 - 22 mars 2008 à 19:03
 ssmo - 23 avril 2008 à 09:33
Bonjour,
Depuis quelques jour j'ai le fameux ecran bleu , j'ai fait plusieurs sacn avec antivirus, antispyware , j'ai tout nettoyé mais ca change rien :

ogfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:53:58, on 22/03/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
C:\Program Files\DAP\DAP.exe
C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Windows\System32\rundll32.exe
C:\Windows\SOUNDMAN.EXE
C:\Program Files\Common Files\logishrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Nosibay\Mon Widget RMC\Launcher.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Nosibay\Mon Widget RMC\Mon Widget RMC.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9e.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = file://C:\PROGRA~1\SPEEDB~1\proxy.pac
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [amd_dc_opt] "C:\Program Files\AMD\amd_dc_opt\amd_dc_opt.exe"
O4 - HKLM\..\Run: [RivaTunerStartupDaemon] "C:\Program Files\RivaTuner v2.06\RivaTuner.exe" /S
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [00PCTFW] "C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s
O4 - HKLM\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP
O4 - HKLM\..\Run: [SpeedBitVideoAccelerator] "C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe"
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Mon Widget RMC] "C:\Program Files\Nosibay\Mon Widget RMC\launcher.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {12345678-1234-1234-1234-1234567890AB} - (no file)
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Betway Casino - {3063c161-2f7e-4225-ba73-08bc8f64c67e} - C:\Betway\Casino\casinogame.exe
O9 - Extra button: Betway.com Poker - {4CBB5C71-1BA0-49ca-93CD-159AF8AA0CC9} - C:\Betway\Poker\MPPoker.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Unibet Poker - {C53BFCFC-7A54-4627-AEBA-2CD4871FCA97} - C:\Microgaming\Poker\UnibetpokerMPP\MPPoker.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O15 - Trusted Zone: http://asia.msi.com.tw
O15 - Trusted Zone: http://global.msi.com.tw
O15 - Trusted Zone: http://www.msi.com.tw
O15 - Trusted Zone: https://www.nvidia.com/fr-fr/
O15 - Trusted Zone: http://housecall65.trendmicro.com
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onecare.live.com/resource/download/scanner/fr-fr/wlscctrl2.cab
O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase370.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/LOnline/install.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://betway.microgaming.com/betway/FlashAX.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - https://driveragent.com/files/driveragent.cab
O16 - DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} (Flash Casino Helper Object) - https://betway.microgaming.com/betway/FlashAX2.cab
O18 - Protocol: bw+0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw+0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw-0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw-0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw00 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw00s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw10 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw10s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw20 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw20s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw30 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw30s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw40 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw40s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw50 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw50s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw60 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw60s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw70 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw70s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw80 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw80s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw90 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw90s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwa0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwa0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwb0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwb0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwc0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwc0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwd0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwd0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwe0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwe0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwf0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwf0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - (no file)
O18 - Protocol: bwg0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwg0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwh0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwh0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwi0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwi0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwj0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwj0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwk0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwk0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwl0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwl0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwm0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwm0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwn0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwn0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwo0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwo0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwp0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwp0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwq0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwq0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwr0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwr0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bws0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bws0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwt0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwt0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwu0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwu0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwv0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwv0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bww0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bww0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwx0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwx0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwy0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwy0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwz0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwz0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: offline-8876480 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\logishrd\Bluetooth\LBTServ.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - PC Tools - C:\Program Files\PC Tools Firewall Plus\FWService.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe

3 réponses

^^Marie^^ Messages postés 113901 Date d'inscription mardi 6 septembre 2005 Statut Membre Dernière intervention 28 août 2020 3 275
24 mars 2008 à 11:28
Salut

Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

- Va dans démarrer puis panneau de configuration
- Double Clique sur l'icône "Comptes d'utilisateurs"
- Clique ensuite sur désactiver et valide.


1/ Télécharge et installe CCleaner
(attention à l'installation penser à DECOCHER l'installation de Yahoo toolbar discrètement proposé en plus de CCleaner).

http://www.clubic.com/lancer-le-telechargement-20932-0-ccleaner-crap-cleaner-.html

2/ 2/ Télécharge AVG
https://www.avg.com/en-ww/free-antivirus-download
Lance AVG Anti-Spyware et clique sur le bouton Mise à jour.
Tu fermes



3/ Redémarre en mode sans échec

(Pour cela : démarrer le PC en tapotant sur la touche F8 du clavier jusqu'à ce que le menu des options avancées de Windows apparaisse puis avec les touches fléchées du clavier, sélectionner Mode sans échec puis appuyer sur la touche Entrée...)
Attention tu n'as pas accès à Internet dans ce mode donc note ou imprime les consignes qui suivent.
http://www.coupdepoucepc.com/modules/news/article.php?storyid=253
https://www.micro-astuce.com/depannage/demarrer-mode-sans-echec.php




4/ Lance HijackThis
puis --> Do a system scan only
coche les lignes indiquées ci-dessous
puis --> Fix checked
puis oui à la question de confirmation

O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onecare.live.com/resource/download/scanner/fr-fr/wlscctrl2.cab
O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase370.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/default.aspx
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/
O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/LOnline/install.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://betway.microgaming.com/betway/FlashAX.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - https://driveragent.com/files/driveragent.cab
O16 - DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} (Flash Casino Helper Object) - https://betway.microgaming.com/betway/FlashAX2.cab
O18 - Protocol: bw+0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw+0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw-0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw-0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw00 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw00s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw10 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw10s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw20 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw20s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw30 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw30s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw40 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw40s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw50 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw50s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw60 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw60s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw70 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw70s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw80 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw80s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw90 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bw90s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwa0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwa0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwb0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwb0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwc0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwc0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwd0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwd0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwe0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwe0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwf0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwf0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - (no file)
O18 - Protocol: bwg0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwg0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwh0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwh0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwi0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwi0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwj0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwj0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwk0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwk0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwl0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwl0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwm0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwm0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwn0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwn0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwo0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwo0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwp0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwp0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwq0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwq0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwr0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwr0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bws0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bws0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwt0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwt0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwu0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwu0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwv0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwv0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bww0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bww0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwx0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwx0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwy0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwy0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwz0 - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)
O18 - Protocol: bwz0s - {F37E6D14-5686-4507-9743-CE96AE2D625D} - (no file)



7/ Lance CCleaner puis bouton Analyse ensuite Bouton Lancer le Nettoyage

8/ Lance AVG
Lance AVG Anti-Spyware
Clique sur le bouton Analyse (de la barre d'outils)
Puis sur l'onglets Comment réagir, clique sur Actions recommandées.
Reviens à l'onglet Analyse. Clique sur Analyse complète du système.
/!\ Si un fichier est infecté en fin d'analyse /!\
choisis l'option " Appliquer toutes les actions " en bas.
Clique sur "Enregistrer le rapport" puis sur "Enregistrer le rapport sous"
Enregistre ce fichier texte sur ton bureau.
Copie/colle le rapport




Télécharge maintenant Navilog1 depuis-ce lien :

http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
Ensuite double clique sur navilog1.exe pour lancer l'installation.
Une fois l'installation terminée, Fais un Clic-droit sur le raccourci Navilog1 présent sur ton bureau et choisis
"Exécuter en tant qu'administrateur".

Au menu principal, Fais le choix 1
Laisse toi guider et patiente.
Patiente jusqu'au message :
*** Analyse Termine le ..... ***
Appuie sur une touche le blocnote va s'ouvrir.
Copie-colle l'intégralité du rapport dans une réponse.
Referme le blocnote
Le rapport fixnavi.txt est en outre sauvegardé dans %systemdrive%.

Bon courage
A++
1
martine03 Messages postés 2129 Date d'inscription jeudi 28 septembre 2006 Statut Membre Dernière intervention 24 février 2021 17
22 mars 2008 à 19:07
bonjour je ny connais pas bien pour lire un log mais là je vois qu il y a un souci car la ligne 18 est tres bizard
0
Bonjour, mon Yahoo Messenger disparait tout seul. comment le rétablir. svp Merci!
0