Antivirus a la con

Résolu
Bonjour,
alors voila j'ai 2 antivirus et 2 firewall ( je sais faut pas mais jai reussi a les configurer et il tourne sans se gener)
mais 1 trojan est passer et je me suis fait hacker , quelqu'un connait il un programme capable de retrouver des traces de ce trojan sur mon ordi sachan que jai reinstaller windows ?
Configuration: Windows Vista
Internet Explorer 7.0

15 réponses

  1. Salut ,
    j'ai 2 antivirus et 2 firewall 


    Hum ...

    mais jai reussi a les configurer et il tourne sans se gener) 


    Re-Hum !
    mais 1 trojan est passer et je me suis fait hacker 


    Comme quoi toute tes protections n'ont servies à rien ...

    bon on va voir ce qui traine dans ton pc ,

    → Télécharge TrendMicro™ HijackThis™

    '
    Place le dans ' C:\programmes\ ' Une fois cela fait , merci de renommer l'icône ( clique droit > renommer )' Hijackthis.exe 'situé dans le dossier dans C:\ , en 'HJT.exe' <<<<<<<<< Important !!! <<<<<<<

    Le chemin d'accés du programme doit être ressemblant à celui-ci : C:\Programme\Trend Micro\Hijackthis\HJT.exe

    Ne pas renommer l'icône du raccourci sur le bureau bien entendu ...

    /!\ Ferme toute les fenêtres encore ouvertes , et déconnecte toi du web /!\

    Clique droit sur l'icône -> '' Executer en tant qu'administrateur '' , et choisi l'option '' do a system scan and save a logfile '' et poste moi le rapport ( qui apparait sur le bloc-note )

    (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

    Tuto si tu n'y arrive pas : http://pageperso.aol.fr/balltrap34/demohijack.htm

    A+
    0
    1. oui je peux t'aider ! "norton security scan" serai une aide pour toi ( ici http://pack.google.com/intl/fr/pack_installer.html?hl=fr&gl=fr ) apres avoir etait sur ce lien tu desactive tout les autre programme que tu peux installer et tu ne garde que norton security scan tu fais telecharger google pack apres accepter et telecharger et voila !! puis des que c fini ben ouvre norton security scan fait un scan complet !! et puis il va te mettre tout les virus quil a trouver puis tu pourra les reparer !
      0
      1. LOL =P

        Norton xD

        La bonne blague ;)
        0
      2. @Utilisateur anonymenon mais ne t'inquiete pas moi aussi je c que norton c :S mais la tinquiete c une version apart et tu peu la desinstaller normalment et tout senleve
        0
      3. @the_jbOuais mais quitte à le prendre juste pour faire un scan , autant en faire un en ligne avec Bitdefender ;)

        0
      4. @the_jbPerso je l'ai fait avec norton security scan et il ma trouver des trojan et a pu me les virer sans soucis et il ne fait ke des scan donc ! et tu c t 2 antivirus sont en conflit donc peut etre kil ont laisser pas mal de chose ....
        0
      5. @the_jblol bon a lui de voir ^^ moi je l'ai est enlever comme ça bonne chance a vous
        0
    2. st hellmad
      bon apparament tu n'a pas compris que si un trojan passe c'est que tu est trop securiser et cela ne sert a rien!!!!
      enleve un de tes deux antivirus et idem pour les par feu car il vaut mieux un par feu qui tourne super bien que deux qui tourne qu'a moitier voir meme moins
      une fois que tu aura finis sa tu va telecharger hijackthis et faire un scan et coller le rapport ici
      apres si tu ne l'a pas deja tu va telecharger antivir ici:http://www.avira-antivir.info/fr/
      pour une bonne configue ici: http://speedweb1.free.fr/frames2.php?page=tuto5
      avec le par feu windows cela serra emplement suffisant.
      voila pour commencer
      attend que l'on te regarde le rapport hijackthis
      mais en attendent installe antivir fait la configue et les mise a jour une fois fait lance le scan 2a3heure environ mais fait en 1 hijckthis.
      bon courage
      0
      1. Salut ,

        Avant de lui dire de télécharger quoique se soit , ou de virer quoi que se soit , attend de voir son rapport HJT.

        Que d'ailleurs je lui est conseillé de faire , donc pas la peine d'en rajouter une couche ;)
        avec le par feu windows cela serra emplement suffisant. 


        Non. Bien que le pare-feu Vista contrôle les connexions entrantes et sortantes , ça n'empêche pas que ce n'est pas suffisant.

        Amicalement ... ;)
        0
      2. @Utilisateur anonymest cyrildu17
        ne te fache pas on va dans le meme sens
        apres je n'avais pas lue toute les reponces deja faite desoler il est entre bonne main donc je te le laisse .bonne soiree
        0
      3. @Utilisateur anonymesalut,
        alors voila mon hijacksthis si tu peutt m'aider merci d'avance. le truc c que je veut savoir s'il rest 1 trace d'un trojan !

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 11:42:03, on 25/04/2008
        Platform: Windows Vista SP1 (WinNT 6.00.1905)
        MSIE: Internet Explorer v7.00 (7.00.6001.18000)
        Boot mode: Normal

        Running processes:
        C:\Windows\system32\taskeng.exe
        C:\Windows\system32\Dwm.exe
        C:\Windows\Explorer.EXE
        C:\Program Files\Windows Defender\MSASCui.exe
        C:\Program Files\OrangeHSS\Systray\SystrayApp.exe
        C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
        C:\Windows\System32\rundll32.exe
        C:\Program Files\Orange\AntivirusFirewall\Common\FSM32.EXE
        C:\Windows\System32\rundll32.exe
        C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
        C:\Users\DENIS MATHIEU\AppData\Local\ojbewl.exe
        C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
        C:\Program Files\Orange\AntivirusFirewall\FSGUI\fsguidll.exe
        C:\Windows\ehome\ehtray.exe
        C:\Program Files\Windows Media Player\wmpnscfg.exe
        C:\Windows\ehome\ehmsas.exe
        C:\Windows\system32\wbem\unsecapp.exe
        C:\Program Files\Trend Micro\HJT\HijackThis.exe
        C:\Windows\system32\DllHost.exe
        C:\Windows\system32\SearchFilterHost.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
        R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
        O1 - Hosts: ::1 localhost
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
        O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\OrangeHSS\Systray\SystrayApp.exe"
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
        O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Orange\AntivirusFirewall\Common\FSM32.EXE" /splash
        O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Orange\AntivirusFirewall\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
        O4 - HKCU\..\Run: [ojbewl] c:\users\denis mathieu\appdata\local\ojbewl.exe ojbewl
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
        O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-19\..\Run: [OrangePlayer] C:\madgames\pp\Player Orange\Orange Player.exe /systray (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [OrangePlayer] C:\madgames\pp\Player Orange\Orange Player.exe /systray (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [OrangePlayer] C:\madgames\pp\Player Orange\Orange Player.exe /systray (User 'Default user')
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O13 - Gopher Prefix:
        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
        O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\Orange\AntivirusFirewall\Anti-Virus\fsgk32st.exe
        O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\Orange\AntivirusFirewall\FSAUA\program\fsaua.exe
        O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Orange\AntivirusFirewall\FWES\Program\fsdfwd.exe
        O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\Orange\AntivirusFirewall\Common\FSMA32.EXE
        O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        0
    3. jessaierai sa d demain !
      jai l antivirus firewall pc de orange(1bonne galere a config)en principale et le windows en arriere sa marchait jusqu'a ce qu'un soit disant antivirus en ligne arrive la mais bon le mal est fait il s'est fait mon compte bancaire en saisi frappe ce #@& !
      je metrai mon rapport demain mais merci a vous!
      0
      1. Re ,
        ne te fache pas on va dans le meme sens 


        Je me fache pas ;)

        **********

        /!\ Manip crée spécialement pour cet utilisateur , ne pas reproduire chez soi ... /!\

        1)Télécharge OTMoveIt2 ( de Old Timer )

        2)Une fois téléchargé double-clique sur OTMoveIt2.exe pour le lancer.

        Assure toi que la case Unregister Dll's and Ocx's soit bien cochée

        3)puis copie les lignes en gras qui se trouvent en dessous :


        c:\users\denis mathieu\appdata\local\ojbewl.exe


        et colle-les dans le cadre de gauche de OTMoveIt : "Paste List Of Files/Folders to Move."
        clique sur MoveIt! pour lancer la suppression.
        le résultat apparaitra dans le cadre Results.
        clique sur Exit pour fermer.
        4) Poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

        (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

        5) Il te sera peut-être demander de redémarrer le pc pour achever la suppression -> Accepte ( si il ne fait pas automatiquement , fait-le toi même )

        /!\ Note : Au démarrage ton bureau RISQUE de ne plus apparaître , dans ce cas fait --> CTRL+ALT+SUPP pour ouvrir le Gestionnaire des tâches.
        Puis rends toi à l'onglet "Processus". Clique en haut à gauche sur Fichiers et choisis "Exécuter"

        Tape explorer.exe et valide. Cela fera re-apparaître le Bureau.

        ********

        Va sur ce site , /!\ Internet Explorer obligatoire /!\ , Clique sur ' J'accepte ' , Installe les ActiveX si necessaire ,et vérifie si ils sont bien configurés Clique sur ' installer ' puis ' click here to scan '( ou : cliquez ici pour scanner ).
        Et poste moi le rapport.

        (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

        a+
        0
        1. re
          jai fait ske tu mas dit avek OTM et là magie... 2fois moins de memoire vive boufer sur le net !
          pas de prob de bureau MERCI MERCI MERCI
          je pense ke la c bon.
          te faut-il 1 autre rapport hijack pour verifier ou pas???
          0
          1. Re ,

            Lit tout ce que j'ai marqué stp ;)

            Je veux le rapport OtmoveIT + un rapport du scan en ligne Bitdefender , après si c'est ok , je te laisse partir =)

            Mais pour l'instant je ne suis pas sur a 100% si tu es désinfecté totalement.

            +++
            0
            1. Analyse des chemins :Chemin0000: C:\Windows
              Chemin0001: C:\Program Files

              Options d’analyse :Analyse contre les virus : Oui
              Détecter les adwares : Oui
              Analyse contre les spywares : Oui
              Analyse des applications : Oui
              Détecter les numéroteurs : Oui
              Analyse contre les Rootkits : Non

              Options de sélection de cible :Analyse les clés du registre : Non
              Analyse des cookies : Non
              Analyser le secteur de boot : Non
              Analyse des processus mémoire : Non
              Analyser les archives : Non
              Analyser les fichiers enpaquetés : Oui
              Analyser les emails : Oui
              Analyser tous les fichiers : Oui
              Analyse heuristique : Oui
              Extensions analysées :
              Extensions exclues :

              Traitement cibleAction par défaut pour les objets infectés : Désinfecter
              Action par défaut pour les objets suspects : Aucun
              Action par défaut pour les objets camouflés : Aucun

              Résumé de l'analyseNombre de signatures de virus : 986652
              Plugins archives : 41
              Plug-ins messagerie : 6
              Plugins d'analyse : 12
              Plugins archives : 41
              Plug-ins système : 4
              Plug-ins décompression : 7

              Résumé de l'analyse généraleEléments analysés : 71374
              Eléments infectés : 0
              Eléments suspects : 0
              Eléments résolus : 0
              Virus individuels trouvés : 0
              Répertoires analysés : 11518
              Secteur de boot analysés : 0
              Archives analysés : 5
              Erreurs I/O : 42
              Temps d'analyse : 00:00:11:35
              Fichiers par seconde : 102

              Résumé des processus analysésAnalysé(s) : 0
              Infecté(s) : 0

              Résumé des clés de registre analyséesAnalysé(s) : 0
              Infecté(s) : 0

              Résumé des cookies analysésAnalysé(s) : 0
              Infecté(s) : 0

              Problèmes non résolus :Nom de l'objet Nom de la menace Etat final

              Problèmes résolusNom de l'objet Nom de la menace Etat final

              Objets non scannés :Nom de l'objet Raison Etat final

              tin jai ete obliger de remetre ma connection mais c bon alors ken pense tu
              0
              1. Re !

                C'est parfait .

                Vire OtmoveIT .

                Et reposte un dernier rapport Hijackthis stp . ( après tu pourras le supprimer )

                a++
                0
                1. Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 11:42:03, on 25/04/2008
                  Platform: Windows Vista SP1 (WinNT 6.00.1905)
                  MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                  Boot mode: Normal

                  Running processes:
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\Explorer.EXE
                  C:\Program Files\Windows Defender\MSASCui.exe
                  C:\Program Files\OrangeHSS\Systray\SystrayApp.exe
                  C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                  C:\Windows\System32\rundll32.exe
                  C:\Program Files\Orange\AntivirusFirewall\Common\FSM32.EXE
                  C:\Windows\System32\rundll32.exe
                  C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
                  C:\Users\DENIS MATHIEU\AppData\Local\ojbewl.exe
                  C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                  C:\Program Files\Orange\AntivirusFirewall\FSGUI\fsguidll.exe
                  C:\Windows\ehome\ehtray.exe
                  C:\Program Files\Windows Media Player\wmpnscfg.exe
                  C:\Windows\ehome\ehmsas.exe
                  C:\Windows\system32\wbem\unsecapp.exe
                  C:\Program Files\Trend Micro\HJT\HijackThis.exe
                  C:\Windows\system32\DllHost.exe
                  C:\Windows\system32\SearchFilterHost.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                  R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
                  O1 - Hosts: ::1 localhost
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                  O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                  O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\OrangeHSS\Systray\SystrayApp.exe"
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                  O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                  O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                  O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Orange\AntivirusFirewall\Common\FSM32.EXE" /splash
                  O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Orange\AntivirusFirewall\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
                  O4 - HKCU\..\Run: [ojbewl] c:\users\denis mathieu\appdata\local\ojbewl.exe ojbewl
                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                  O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                  O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-19\..\Run: [OrangePlayer] C:\madgames\pp\Player Orange\Orange Player.exe /systray (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                  O4 - HKUS\S-1-5-18\..\Run: [OrangePlayer] C:\madgames\pp\Player Orange\Orange Player.exe /systray (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [OrangePlayer] C:\madgames\pp\Player Orange\Orange Player.exe /systray (User 'Default user')
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O13 - Gopher Prefix:
                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
                  O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\Orange\AntivirusFirewall\Anti-Virus\fsgk32st.exe
                  O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\Orange\AntivirusFirewall\FSAUA\program\fsaua.exe
                  O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Orange\AntivirusFirewall\FWES\Program\fsdfwd.exe
                  O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\Orange\AntivirusFirewall\Common\FSMA32.EXE
                  O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  0
                  1. Re ,

                    Il me faudrait un nouveau rapport Hijackthis. Tout neuf.

                    Lance Hijackthis , ' do a system scan a save a logfile '

                    A+
                    0
                    1. Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 16:45:09, on 25/04/2008
                      Platform: Windows Vista SP1 (WinNT 6.00.1905)
                      MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                      Boot mode: Normal

                      Running processes:
                      C:\Windows\system32\taskeng.exe
                      C:\Windows\system32\Dwm.exe
                      C:\Windows\Explorer.EXE
                      C:\Program Files\OrangeHSS\Systray\SystrayApp.exe
                      C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                      C:\Windows\System32\rundll32.exe
                      C:\Windows\System32\rundll32.exe
                      C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
                      C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                      C:\Windows\ehome\ehtray.exe
                      C:\Program Files\Windows Media Player\wmpnscfg.exe
                      C:\Windows\ehome\ehmsas.exe
                      C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
                      C:\Windows\system32\wbem\unsecapp.exe
                      C:\Windows\system32\conime.exe
                      C:\Windows\system32\taskeng.exe
                      C:\Program Files\OrangeHSS\Launcher\Launcher.exe
                      C:\Program Files\OrangeHSS\Deskboard\deskboard.exe
                      C:\Program Files\OrangeHSS\connectivity\connectivitymanager.exe
                      C:\Program Files\OrangeHSS\connectivity\CoreCom\CoreCom.exe
                      C:\Program Files\OrangeHSS\connectivity\CoreCom\OraConfigRecover.exe
                      C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
                      C:\Program Files\OrangeHSS\browser\browser.exe
                      C:\PROGRA~1\WI1F86~1\MESSEN~1\msnmsgr.exe
                      C:\Windows\system32\SearchFilterHost.exe
                      C:\Program Files\Trend Micro\HJT\HijackThis.exe

                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
                      O1 - Hosts: ::1 localhost
                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                      O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
                      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                      O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\OrangeHSS\Systray\SystrayApp.exe"
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                      O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                      O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
                      O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
                      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                      O4 - HKCU\..\Run: [MsnMsgr] "C:\PROGRA~1\WI1F86~1\MESSEN~1\msnmsgr.exe" /background
                      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-19\..\Run: [OrangePlayer] C:\madgames\pp\Player Orange\Orange Player.exe /systray (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                      O4 - HKUS\S-1-5-18\..\Run: [OrangePlayer] C:\madgames\pp\Player Orange\Orange Player.exe /systray (User 'SYSTEM')
                      O4 - HKUS\.DEFAULT\..\Run: [OrangePlayer] C:\madgames\pp\Player Orange\Orange Player.exe /systray (User 'Default user')
                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                      O13 - Gopher Prefix:
                      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
                      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
                      O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
                      O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
                      0
                      1. MERCI bien !! si t'as du temps vas voir widemess ... ya 8 raport hjt et il trime avec ieplorer et la il se sen delaisser!
                        jai plus ka me fournir 1 version complete de bitdef mais
                        je me courbe avec respet devant le savoir faire ke tu ma prodiguer : )
                        mille merci et bonne cotinuation
                        MAD bourin acermenter ki galere en info dpuis 2ans
                        bon jarete mais delire encore merci
                        ciao
                        0
                        1. =)

                          ^^
                          Bonne continuation & bon surf'

                          +++
                          0