Fenetre Firefox qui s'ouvre toute seul.

Résolu
Bonjour,
J'ai des fenetres firefox qui s'ouvrent toutes seules, j'ai regardé les post et j'ai vu qu'il fallait faire un rapport avec navilog1. Je l'ai fais, je vous l'envoie:

Search Navipromo version 3.5.1 commencé le 24/03/2008 à 13:47:52,84

!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

Outil exécuté depuis C:\Program Files\navilog1
Session actuelle : "IcEagLe"

Mise à jour le 23.03.2008 à 22h00 par IL-MAFIOSO

Microsoft Windows XP [version 5.1.2600]
Internet Explorer : 7.0.5730.11
Système de fichiers : NTFS

Executé en mode normal

*** Recherche Programmes installés ***

WebMediaPlayer

*** Recherche dossiers dans C:\WINDOWS ***

*** Recherche dossiers dans C:\Program Files ***

C:\Program Files\WebMediaPlayer trouvé !

*** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\APPLIC~1 ***

*** Recherche dossiers dans "C:\Documents and Settings\IcEagLe\applic~1" ***

*** Recherche dossiers dans "C:\Documents and Settings\IcEagLe\locals~1\applic~1" ***

*** Recherche dossiers dans "C:\Documents and Settings\IcEagLe\menudm~1\progra~1" ***

*** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

...\WebMediaPlayer trouvé !

*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net

Fichier(s) caché(s) :

C:\Documents and Settings\IcEagLe\Local Settings\Application Data\qmwsca.dat
C:\Documents and Settings\IcEagLe\Local Settings\Application Data\qmwsca.exe
C:\Documents and Settings\IcEagLe\Local Settings\Application Data\qmwsca_nav.dat
C:\Documents and Settings\IcEagLe\Local Settings\Application Data\qmwsca_navps.dat

*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!

* Recherche dans C:\WINDOWS\system32 *

* Recherche dans "C:\Documents and Settings\IcEagLe\locals~1\applic~1" *

Fichiers suspects :

qmwsca.exe trouvé !

* Recherche dans "C:\docume~1\Aemelle\locals~1\applic~1" *

*** Recherche fichiers ***

C:\WINDOWS\system32\nvs2.inf trouvé !

*** Recherche clés spécifiques dans le Registre ***

HKEY_CURRENT_USER\Software\Lanconfig trouvé !

*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)

1)Recherche nouveaux fichiers Instant Access :

2)Recherche Heuristique :

* Dans C:\WINDOWS\system32 :

* Dans "C:\Documents and Settings\IcEagLe\locals~1\applic~1" :

qmwsca.dat trouvé !

* Dans "C:\docume~1\Aemelle\locals~1\applic~1" :

3)Recherche Certificats :

Certificat Egroup trouvé !
Certificat Electronic-Group trouvé !
Certificat OOO-Favorit trouvé !
Certificat Sunny-Day-Design-Ltd absent !

4)Recherche fichiers connus :

C:\WINDOWS\system32\dccdd.ini2 trouvé ! infection Vundo possible non traitée par cet outil !
C:\WINDOWS\system32\ddeeg.ini2 trouvé ! infection Vundo possible non traitée par cet outil !
C:\WINDOWS\system32\hjjlm.ini2 trouvé ! infection Vundo possible non traitée par cet outil !
C:\WINDOWS\system32\qrqss.ini2 trouvé ! infection Vundo possible non traitée par cet outil !
C:\WINDOWS\system32\rstwa.ini2 trouvé ! infection Vundo possible non traitée par cet outil !
C:\WINDOWS\system32\utstv.ini2 trouvé ! infection Vundo possible non traitée par cet outil !
C:\WINDOWS\system32\uttss.ini2 trouvé ! infection Vundo possible non traitée par cet outil !
C:\WINDOWS\system32\ututv.ini2 trouvé ! infection Vundo possible non traitée par cet outil !

*** Analyse terminée le 24/03/2008 à 13:58:15,60 ***

En attende de ce qu'il faut faire...
Configuration: Windows XP
Firefox 2.0.0.12

14 réponses

  1. Contributeur sécurité
    slt,

    il y a du boulot!!!!

    ________________

    colle un rapport hijackthis

    http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download

    manuel :

    https://leblogdeclaude.blogspot.com/2006/10/informatique-section-hijackthis.html

    Je conseille de renomer Hijackthis, pour contrer une éventuelle infection de Vundo.

    ex:Renomme le fichier HijackThis.exe en eden.exe pour cela, fais un clic droit sur le fichier HijackThis.exe et choisis renommer dans la liste

    Ensuite avec Explorer créer un dossier c:\hijackthis
    Décompresser Hijackthis dans ce dossier.
    C'est important pour les sauvegardes."
    __________________

    scan avec vundofix (colle le rapport)

    Téléchargez VundoFix -> http://www.atribune.org/ccount/click.php?id=4

    Double cliquez VundoFix.exe pour l'exécuter.
    Quand VundoFix s'ouvre, cliquez sur le bouton Scan for Vundo.
    Une fois le scan fini, cliquez sur le bouton Remove Vundo.
    Vous recevrez un avertissement vous demandant si vous voulez effacer ces
    fichiers répondez en cliquant sur YES
    Une fois que vous avez cliqué yes, votre bureau deviendra vide au moment où il
    enlève Vundo.

    Quand c'est fini, il vous sera demandé de redémarrer votre ordinateur, cliquez
    OK.

    ___________________

    virtumondebegone (colle le rapport)

    http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe
    __________________

    Télécharge Combofix de sUBs : Renomme le avant toute installation, par exemple, nomme le "KillBagle". aide ici : https://forum.pcastuces.com/sujet.asp?f=25&s=37315

    http://download.bleepingcomputer.com/sUBs/ComboFix.exe
    Sauvegarde le sur ton bureau et pas ailleurs !

    Aide à l’utilisation de combofix ici: https://bibou0007.forumpro.fr/login?redirect=%2Ft121-topic

    Double-clic sur combofix, Il va te poser une question, réponds par la touche 1 et entrée pour valider, laisse toi guider.
    Attends que combofix ait terminé, un rapport sera créé. Poste le rapport.

    ___________________

    télécharge OTMoveIt
    http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe (de Old_Timer) sur ton Bureau. Ou sur https://www.luanagames.com/index.fr.html
    double-clique sur OTMoveIt.exe pour le lancer.
    copie la liste qui se trouve en citation ci-dessous,
    et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

    Citation :

    C:\WINDOWS\system32\dccdd.ini2
    C:\WINDOWS\system32\ddeeg.ini2
    C:\WINDOWS\system32\hjjlm.ini2
    C:\WINDOWS\system32\qrqss.ini2
    C:\WINDOWS\system32\rstwa.ini2
    C:\WINDOWS\system32\utstv.ini2
    C:\WINDOWS\system32\uttss.ini2
    C:\WINDOWS\system32\ututv.ini2

    clique sur MoveIt! pour lancer la suppression.
    le résultat apparaitra dans le cadre "Results".
    clique sur Exit pour fermer.
    poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

    il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

    _____________________

    = Lance navilog1
    = Cette fois-ci choisi l'option 2
    = Navilog va faire le nettoyage.. patient jusqu'à ce qui soit marqué *** Nettoyage Termine le ..... ***
    = Un rapport va être génrer sur ton C:\ qui sera en option 2
    Note: le bureau disparaît

    = colle le contenu du rapport de navilog (qui est en option2)

    PS:Si ton bureau ne réapparait pas, fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.
    Puis rends-toi à l'onglet "processus". Clique en haut à gauche sur fichiers et choisis "exécuter"
    Tape explorer et valide. Celà te fera apparaitre ton bureau.
    _______________________
    recolle un nouveau hijakchits
    0
    1. J'ai tout fais, voila le premier rapport de hijackthis:

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 14:17:07, on 24/03/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16608)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
      C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
      C:\Program Files\Razer\Copperhead\razerhid.exe
      C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
      C:\WINDOWS\system32\RUNDLL32.EXE
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Norton Save and Restore\Agent\VProTray.exe
      C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBZE.EXE
      C:\WINDOWS\System32\FTRTSVC.exe
      C:\Program Files\Norton Save and Restore\Agent\VProSvc.exe
      C:\Program Files\Razer\Copperhead\razertra.exe
      C:\Program Files\Razer\Copperhead\razerofa.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\PROGRA~1\FICHIE~1\SYMANT~1\CCPD-LC\symlcsvc.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Windows Live\Messenger\usnsvc.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.instafinder.com/addsearch.asp?err=ADD&url=
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
      O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll (file missing)
      O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
      O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
      O3 - Toolbar: Afficher Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
      O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
      O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
      O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
      O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
      O4 - HKLM\..\Run: [razer] C:\Program Files\Razer\Copperhead\razerhid.exe
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
      O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
      O4 - HKLM\..\Run: [Norton Save and Restore 2.0] "C:\Program Files\Norton Save and Restore\Agent\VProTray.exe"
      O4 - HKLM\..\RunOnce: [SymLnch] "C:\Documents and Settings\IcEagLe\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SymLnch\SymLnch.exe" "C:\Documents and Settings\IcEagLe\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup.exe" "/SCANUPREBOOT /temp /patched"
      O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [EPSON Stylus D92 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBZE.EXE /FU "C:\WINDOWS\TEMP\E_S85.tmp" /EF "HKCU"
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
      O4 - S-1-5-18 Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'SYSTEM')
      O4 - .DEFAULT Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'Default user')
      O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
      O8 - Extra context menu item: &Search - http://ko.bar.need2find.com/KO/menusearch.html?p=KO
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
      O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll
      O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
      O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
      O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
      O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by112fd.bay112.hotmail.msn.com/resources/MsnPUpld.cab
      O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
      O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin11USA.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
      O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
      O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Planificateur LiveUpdate automatique (Automatic LiveUpdate Scheduler) - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
      O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
      O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\VAScanner\comHost.exe
      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
      O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
      O23 - Service: Norton Save and Restore - Symantec Corporation - C:\Program Files\Norton Save and Restore\Agent\VProSvc.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\FICHIE~1\SYMANT~1\CCPD-LC\symlcsvc.exe
      0
  2. Contributeur sécurité
    Relance HijackThis, choisis "do a scan only" coche la case devant les lignes ci-dessous et clic en bas sur "fix checked".

    O2 - BHO: (no name) - {41DA9DAC-BEE7-4D47-AED8-AB26730E715D} - C:\WINDOWS\system32\vtstu.dll (file missing)
    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll (file missing)
    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll (file missing)
    O2 - BHO: (no name) - {EBF3B787-DBF6-4403-8981-4022B6E39654} - C:\WINDOWS\system32\ssqrq.dll (file missing)
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll (file missing)
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [razer] C:\Program Files\Razer\Copperhead\razerhid.exe
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - (file missing) (HKCU)
    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) -
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) -
    O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) -
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) -
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) -
    ____________________

    analyse ce fichier sur virus total et dis moi si infécté:
    https://www.virustotal.com/gui/

    C:\Program Files\Razer\Copperhead\razerhid.exe
    ____________________
    recolle un rapport hiajkchtis en le renommant cette fois
    0
    1. Virustotal me dit que razerhid.exe n'est pas infecté.

      Voila le rapport de hijackthis, j'ai renommé le fichier .exe:

      Logfile of HijackThis v1.99.1
      Scan saved at 19:19, on 2008-03-24
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16608)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
      C:\WINDOWS\System32\FTRTSVC.exe
      C:\Program Files\Norton Save and Restore\Agent\VProSvc.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
      C:\WINDOWS\system32\RUNDLL32.EXE
      C:\Program Files\Norton Save and Restore\Agent\VProTray.exe
      C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Hijackthis\eden.EXE

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
      O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\FICHIE~1\SYMANT~1\IDS\IPSBHO.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
      O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
      O3 - Toolbar: Afficher Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
      O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
      O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
      O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
      O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
      O4 - HKLM\..\Run: [Norton Save and Restore 2.0] "C:\Program Files\Norton Save and Restore\Agent\VProTray.exe"
      O4 - HKLM\..\RunOnce: [SymLnch] "C:\Documents and Settings\IcEagLe\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SymLnch\SymLnch.exe" "C:\Documents and Settings\IcEagLe\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup.exe" "/SCANUPREBOOT /temp /patched"
      O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [EPSON Stylus D92 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBZE.EXE /FU "C:\WINDOWS\TEMP\E_S85.tmp" /EF "HKCU"
      O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
      O8 - Extra context menu item: &Search - http://ko.bar.need2find.com/KO/menusearch.html?p=KO
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
      O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
      O11 - Options group: [INTERNATIONAL] International*
      O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
      O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
      O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\FICHIE~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
      O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
      O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Planificateur LiveUpdate automatique (Automatic LiveUpdate Scheduler) - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
      O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
      O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
      O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
      O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\VAScanner\comHost.exe
      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
      O23 - Service: LiveUpdate Notice - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
      O23 - Service: Norton Save and Restore - Symantec Corporation - C:\Program Files\Norton Save and Restore\Agent\VProSvc.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\FICHIE~1\SYMANT~1\CCPD-LC\symlcsvc.exe
      0
      1. Il y a plus de soucis mais total scan a trouvé pas mal de choses:

        ;***********************************************************************************************************************************************************************************
        ANALYSIS: 2008-03-24 19:46:44
        PROTECTIONS: 1
        MALWARE: 42
        SUSPECTS: 0
        ;***********************************************************************************************************************************************************************************
        PROTECTIONS
        Description Version Active Updated
        ;===================================================================================================================================================================================
        Norton Internet Security 15.0.0.60 Yes Yes
        ;===================================================================================================================================================================================
        MALWARE
        Id Description Type Active Severity Disinfectable Disinfected Location
        ;===================================================================================================================================================================================
        00029258 application/altnet HackTools No 0 Yes No hkey_classes_root\topsearch.tslink
        00029258 application/altnet HackTools No 0 Yes No hkey_classes_root\topsearch.tslink.1
        00029258 application/altnet HackTools No 0 Yes No HKEY_CLASSES_ROOT\Interface\{582AB125-1403-42FB-9EFB-198690BA1496}
        00029258 application/altnet HackTools No 0 Yes No HKEY_LOCAL_MACHINE\software\classes\CLSID\{B7156514-A76C-4545-9D5B-A4E1D02C7AEC}
        00029258 application/altnet HackTools No 0 Yes No hkey_classes_root\clsid\{b7156514-a76c-4545-9d5b-a4e1d02c7aec}
        00029258 application/altnet HackTools No 0 Yes No hkey_local_machine\software\classes\topsearch.tslink
        00029258 application/altnet HackTools No 0 Yes No hkey_local_machine\software\classes\topsearch.tslink.1
        00064489 adware/rxtoolbar Adware No 1 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25D8BACF-3DE2-4B48-AE22-D659B8D835B0}
        00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@doubleclick[1].txt
        00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.doubleclick.net/]
        00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@atdmt[2].txt
        00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.atdmt.com/]
        00145393 Cookie/Tradedoubler TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.tradedoubler.com/]
        00145393 Cookie/Tradedoubler TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.tradedoubler.com/]
        00145393 Cookie/Tradedoubler TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@tradedoubler[1].txt
        00145393 Cookie/Tradedoubler TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.tradedoubler.com/]
        00145393 Cookie/Tradedoubler TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.tradedoubler.com/]
        00145427 Cookie/Kazaa Networks TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@desktop.kazaa[2].txt
        00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.fastclick.net/]
        00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@fastclick[2].txt
        00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.fastclick.net/]
        00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.fastclick.net/]
        00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@tribalfusion[2].txt
        00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.mediaplex.com/]
        00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@mediaplex[2].txt
        00147814 Cookie/AspinallsOnlineCasino TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@pacificpoker[1].txt
        00147824 Cookie/Clickbank TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@clickbank[2].txt
        00167642 Cookie/Com.com TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@com[1].txt
        00167704 Cookie/Xiti TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@xiti[2].txt
        00167704 Cookie/Xiti TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.xiti.com/]
        00167709 Cookie/fe.lea.lycos TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@fe.lea.lycos[1].txt
        00167749 Cookie/Toplist TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@toplist[1].txt
        00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@statcounter[2].txt
        00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[ad.yieldmanager.com/]
        00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[ad.yieldmanager.com/]
        00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[ad.yieldmanager.com/]
        00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[ad.yieldmanager.com/]
        00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[ad.yieldmanager.com/]
        00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@ad.yieldmanager[1].txt
        00168061 Cookie/Apmebf TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.apmebf.com/]
        00168061 Cookie/Apmebf TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.apmebf.com/]
        00168061 Cookie/Apmebf TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@apmebf[1].txt
        00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.serving-sys.com/]
        00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@serving-sys[1].txt
        00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.serving-sys.com/]
        00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.serving-sys.com/]
        00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.serving-sys.com/]
        00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.serving-sys.com/]
        00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.serving-sys.com/]
        00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@bs.serving-sys[2].txt
        00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.bs.serving-sys.com/]
        00168095 Cookie/888 TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@888[1].txt
        00168102 Cookie/Falkag TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@as1.falkag[1].txt
        00168106 Cookie/Weborama TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.weborama.fr/]
        00168106 Cookie/Weborama TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.weborama.fr/]
        00168106 Cookie/Weborama TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@weborama[2].txt
        00168106 Cookie/Weborama TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.weborama.fr/]
        00168106 Cookie/Weborama TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.weborama.fr/]
        00168109 Cookie/Adtech TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.adtech.de/]
        00168109 Cookie/Adtech TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@adtech[2].txt
        00168116 Cookie/Comclick TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[fl01.ct2.comclick.com/]
        00168116 Cookie/Comclick TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[fl01.ct2.comclick.com/]
        00168116 Cookie/Comclick TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[fl01.ct2.comclick.com/]
        00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@advertising[2].txt
        00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.advertising.com/]
        00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.advertising.com/]
        00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.advertising.com/]
        00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.advertising.com/]
        00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@sextracker[1].txt
        00169752 application/need2find HackTools No 0 Yes No hkey_classes_root\need2findbar.toolbarplugin.1
        00169752 application/need2find HackTools No 0 Yes No HKEY_CLASSES_ROOT\Interface\{4D1C4E8A-A32A-416B-BCDB-33B3EF3617D3}
        00169752 application/need2find HackTools No 0 Yes No hkey_local_machine\software\need2find
        00169752 application/need2find HackTools No 0 Yes No hkey_classes_root\clsid\{630d6140-04c5-4db0-b27a-020d766ff09b}
        00169752 application/need2find HackTools No 0 Yes No hkey_classes_root\need2findbar.settingsplugin
        00169752 application/need2find HackTools No 0 Yes No hkey_current_user\software\need2find
        00169752 application/need2find HackTools No 0 Yes No hkey_classes_root\need2findbar.toolbarplugin
        00169752 application/need2find HackTools No 0 Yes No c:\program files\need2find
        00169752 application/need2find HackTools No 0 Yes No hkey_classes_root\need2findbar.settingsplugin.1
        00169752 application/need2find HackTools No 0 Yes No HKEY_LOCAL_MACHINE\software\classes\CLSID\{630D6140-04C5-4db0-B27A-020D766FF09B}
        00170304 Cookie/WebtrendsLive TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[statse.webtrendslive.com/]
        00170304 Cookie/WebtrendsLive TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@statse.webtrendslive[1].txt
        00170554 Cookie/Overture TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@overture[1].txt
        00170554 Cookie/Overture TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.overture.com/]
        00170556 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@realmedia[2].txt
        00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@questionmarket[2].txt
        00172221 Cookie/Zedo TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.zedo.com/]
        00172221 Cookie/Zedo TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.zedo.com/]
        00172221 Cookie/Zedo TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@zedo[1].txt
        00172483 Cookie/888 TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@int.sitestat[2].txt
        00172484 Cookie/Cassava TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@int.sitestat[3].txt
        00173520 Cookie/Bluestreak TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.bluestreak.com/]
        00173520 Cookie/Bluestreak TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@bluestreak[1].txt
        00180153 Cookie/Sextracker TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@counter2.sextracker[1].txt
        00184846 Cookie/Adrevolver TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@adrevolver[1].txt
        00191644 Cookie/adultfriendfinder TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.adultfriendfinder.com/]
        00191644 Cookie/adultfriendfinder TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.adultfriendfinder.com/]
        00207936 Cookie/Adviva TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@adviva[2].txt
        00273339 Cookie/Smartadserver TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.smartadserver.com/]
        00273339 Cookie/Smartadserver TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@smartadserver[2].txt
        00273339 Cookie/Smartadserver TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.smartadserver.com/]
        00273339 Cookie/Smartadserver TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.smartadserver.com/]
        00273339 Cookie/Smartadserver TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.smartadserver.com/]
        00286739 Cookie/Hitbox TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Cookies\iceagle@ehg-dig.hitbox[2].txt
        ;===================================================================================================================================================================================
        SUSPECTS
        Location
        ;===================================================================================================================================================================================
        ;===================================================================================================================================================================================
        0
        1. Contributeur sécurité
          scan avec
          MalwareByte's Anti-Malware et vire ce qui est trouvé

          https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
          _________________

          utilise pour supprimer tes traces

          CCLEANER: (lance un nettoyage et répare 3 fois le registre) sans installer la barre yahoo

          https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html
          -----------------------

          télécharge OTMoveIt
          http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe (de Old_Timer) sur ton Bureau. Ou sur https://www.luanagames.com/index.fr.html
          double-clique sur OTMoveIt.exe pour le lancer.
          copie la liste qui se trouve en citation ci-dessous,
          et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

          Citation :

          hkey_classes_root\topsearch.tslink
          hkey_classes_root\topsearch.tslink.1
          HKEY_CLASSES_ROOT\Interface\{582AB125-1403-42FB-9EFB-198690BA1496}
          HKEY_LOCAL_MACHINE\software\classes\CLSID\{B7156514-A76C-4545-9D5B-A4E1D02C7AEC}
          hkey_classes_root\clsid\{b7156514-a76c-4545-9d5b-a4e1d02c7aec}
          hkey_local_machine\software\classes\topsearch.tslink
          hkey_local_machine\software\classes\topsearch.tslink.1
          No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25D8BACF-3DE2-4B48-­AE22-D659B8D835B0}
          hkey_classes_root\need2findbar.toolbarplugin.1
          HKEY_CLASSES_ROOT\Interface\{4D1C4E8A-A32A-416B-BCDB-33B3EF3617D3}
          hkey_local_machine\software\need2find
          hkey_classes_root\clsid\{630d6140-04c5-4db0-b27a-020d766ff09b}
          hkey_classes_root\need2findbar.settingsplugin
          hkey_current_user\software\need2find
          hkey_classes_root\need2findbar.toolbarplugin
          c:\program files\need2find
          hkey_classes_root\need2findbar.settingsplugin.1
          HKEY_LOCAL_MACHINE\software\classes\CLSID\{630D6140-04C5-4db0-B27A-020D766FF09B}

          clique sur MoveIt! pour lancer la suppression.
          le résultat apparaitra dans le cadre "Results".
          clique sur Exit pour fermer.
          poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

          il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.
          ________________
          0
          1. Voila le rapport de OTMoveit:

            File/Folder hkey_classes_root\topsearch.tslink not found.
            File/Folder hkey_classes_root\topsearch.tslink.1 not found.
            File/Folder HKEY_CLASSES_ROOT\Interface\{582AB125-1403-42FB-9EFB-198690BA1496} not found.
            File/Folder HKEY_LOCAL_MACHINE\software\classes\CLSID\{B7156514-A76C-4545-9D5B-A4E1D02C7AEC} not found.
            File/Folder hkey_classes_root\clsid\{b7156514-a76c-4545-9d5b-a4e1d02c7aec} not found.
            File/Folder hkey_local_machine\software\classes\topsearch.tslink not found.
            File/Folder hkey_local_machine\software\classes\topsearch.tslink.1 not found.
            File/Folder No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25D8BACF-3DE2-4B48-­­AE22-D659B8D835B0} not found.
            File/Folder hkey_classes_root\need2findbar.toolbarplugin.1 not found.
            File/Folder HKEY_CLASSES_ROOT\Interface\{4D1C4E8A-A32A-416B-BCDB-33B3EF3617D3} not found.
            File/Folder hkey_local_machine\software\need2find not found.
            File/Folder hkey_classes_root\clsid\{630d6140-04c5-4db0-b27a-020d766ff09b} not found.
            File/Folder hkey_classes_root\need2findbar.settingsplugin not found.
            File/Folder hkey_current_user\software\need2find not found.
            File/Folder hkey_classes_root\need2findbar.toolbarplugin not found.
            c:\program files\need2find\bar\Settings moved successfully.
            c:\program files\need2find\bar\History moved successfully.
            c:\program files\need2find\bar\Cache moved successfully.
            c:\program files\need2find\bar\1.bin moved successfully.
            c:\program files\need2find\bar moved successfully.
            c:\program files\need2find moved successfully.
            File/Folder hkey_classes_root\need2findbar.settingsplugin.1 not found.
            File/Folder HKEY_LOCAL_MACHINE\software\classes\CLSID\{630D6140-04C5-4db0-B27A-020D766FF09B} not found.

            OTMoveIt2 by OldTimer - Version 1.0.21 log created on 03242008_203307
            0
            1. Contributeur sécurité
              ok vire ce qui est dans moved fiels en allant dans poste de travail puis C puis otmovit

              ______
              recolle un rapport panda pour voir
              0
              1. J'ai refais, il reste ca:

                ;***********************************************************************************************************************************************************************************
                ANALYSIS: 2008-03-24 20:48:48
                PROTECTIONS: 1
                MALWARE: 4
                SUSPECTS: 0
                ;***********************************************************************************************************************************************************************************
                PROTECTIONS
                Description Version Active Updated
                ;===================================================================================================================================================================================
                Norton Internet Security 15.0.0.60 Yes Yes
                ;===================================================================================================================================================================================
                MALWARE
                Id Description Type Active Severity Disinfectable Disinfected Location
                ;===================================================================================================================================================================================
                00029258 application/altnet HackTools No 0 Yes No HKEY_CLASSES_ROOT\Interface\{582AB125-1403-42FB-9EFB-198690BA1496}
                00064489 adware/rxtoolbar Adware No 1 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25D8BACF-3DE2-4B48-AE22-D659B8D835B0}
                00167704 Cookie/Xiti TrackingCookie No 0 Yes No C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.xiti.com/]
                00169752 application/need2find HackTools No 0 Yes No HKEY_CLASSES_ROOT\Interface\{4D1C4E8A-A32A-416B-BCDB-33B3EF3617D3}
                00169752 application/need2find HackTools No 0 Yes No hkey_local_machine\software\need2find
                00169752 application/need2find HackTools No 0 Yes No hkey_current_user\software\need2find
                ;===================================================================================================================================================================================
                SUSPECTS
                Location
                ;===================================================================================================================================================================================
                ;===================================================================================================================================================================================
                0
                1. Contributeur sécurité
                  Télécharge BTFix de Bibi26
                  http://cluster1.easy-hebergement.net/
                  Dézippe l'archive sur ton Bureau.
                  Ouvre le dossier BTFix.
                  Double clique sur BTFix.exe.
                  Clique sur Rechercher.
                  Un rapport va apparaître, copie/colle-le dans ta prochaine réponse.

                  ________________

                  télécharge OTMoveIt
                  http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe (de Old_Timer) sur ton Bureau. Ou sur https://www.luanagames.com/index.fr.html
                  double-clique sur OTMoveIt.exe pour le lancer.
                  copie la liste qui se trouve en citation ci-dessous,
                  et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

                  Citation :

                  HKEY_CLASSES_ROOT\Interface\{582AB125-1403-42FB-9EFB-198690BA1496}
                  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25D8BACF-3DE2-4B48-­AE22-D659B8D835B0}
                  C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.xiti.com/]
                  HKEY_CLASSES_ROOT\Interface\{4D1C4E8A-A32A-416B-BCDB-33B3EF3617D3}
                  hkey_local_machine\software\need2find
                  hkey_current_user\software\need2find

                  clique sur MoveIt! pour lancer la suppression.
                  le résultat apparaitra dans le cadre "Results".
                  clique sur Exit pour fermer.
                  poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

                  il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

                  ________________

                  vire ce qui est dans movedfiles en allant dans poste de travail puis c puis otmovit
                  0
                  1. BTFix:

                    BTFix 1.090 (par bibi26) - 24/03/2008 21:02:39 - Analyse
                    Lancé depuis C:\Documents and Settings\IcEagLe\Bureau\BTFix\BTFix.exe

                    ---> Fichiers/Dossiers trouvés

                    - C:\Program Files\Instafinder\
                    - C:\Documents and Settings\IcEagLe\Menu Démarrer\Programmes\InstaFinder\

                    ---> Analyse terminée

                    OTMoveIt:

                    File/Folder HKEY_CLASSES_ROOT\Interface\{582AB125-1403-42FB-9EFB-198690BA1496} not found.
                    File/Folder HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25D8BACF-3DE2-4B48-­­AE22-D659B8D835B0} not found.
                    File/Folder C:\Documents and Settings\IcEagLe\Application Data\Mozilla\Firefox\Profiles\ooy5jwld.default\cookies.txt[.xiti.com/] not found.
                    File/Folder HKEY_CLASSES_ROOT\Interface\{4D1C4E8A-A32A-416B-BCDB-33B3EF3617D3} not found.
                    File/Folder hkey_local_machine\software\need2find not found.
                    File/Folder hkey_current_user\software\need2find not found.

                    OTMoveIt2 by OldTimer - Version 1.0.21 log created on 03242008_210514
                    0
                    1. Contributeur sécurité
                      ok c'est bon

                      encore des soucis???
                      0
                      1. No No c'est bon, merci beraucoup pour tout le temps a m'expliquer.

                        Vous avez été très rapide et efficace, merci encore.
                        0
                        1. Bonjour j'ai le meme souci pouvez vous m'aider svp.
                          0