Est ce un virus?

Bonjour,
mon souci est que quand j'ouvre une page internet une fenêtre s'ouvre en disant ' tentative de reference à un jeton qui n'existe pas' est ce un virus? ou que doit- je faire?
Configuration: Windows XP
Internet Explorer 7.0

19 réponses

Résumé de la discussion

Problème rencontré lors de l'ouverture de pages web sur Windows XP avec Internet Explorer 7, où une fenêtre affiche une référence à un jeton inexistant, suscitant des soupçons d'infection ou de malware. Plusieurs analyses suggèrent des scans antivirus variés, dont Malwarebytes et Avira; certains rapports indiquent aucun logiciel malveillant, d'autres détectent des éléments suspects ou des fichiers infectés déplacés en quarantine. Des solutions recommandées incluent l'exécution de scans en ligne et l'utilisation d'outils complémentaires comme BitDefender Online Scanner, puis une remise à jour des antivirus et le maintien d'un pare-feu actif. En cas de résultats, le partage des rapports (par exemple Avira ou BitDefender) permet de confirmer l'état et d'orienter vers une mise à jour ou une réinstallation si nécessaire.

Bobot (l’IA à votre service)
  1. Salut fais ceci:

    Télécharge http://www.commentcamarche.net/telecharger/telecharger 159 hijackthis sur ton Bureau.

    Ferme toutes les autres fenêtres, tous les autres programmes. Pas de connexion Internet.

    Double clique dessus pour lancer l installation . Accepte la licence qui va apparaître par " I agree" .

    Puis clique sur "Do a system scan and save a logfile"

    Ferme HijackThis et fais un copier-coller du rapport en entier et poste le ici en réponse.

    Note : le rapport se trouve dans C:\Program Files\Trend Micro\HijackThis

    Tuto : "générer un rapport" http://pageperso.aol.fr/balltrap34/demohijack.htm
    1. Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 10:29:12, on 12/05/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16608)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\WINDOWS\system32\LVCOMSX.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Logitech\Video\LogiTray.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Logitech\Video\FxSvr2.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\System32\alg.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Windows Live\Messenger\usnsvc.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
      O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
      O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
      O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe"
      O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
      O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
      O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
      O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll/206 (file missing)
      O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
      O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
      O16 - DPF: {104B0A37-AB99-4F06-8032-8BBDC3B77DDB} (Telechargement Control) - http://www.photoweb.fr/moncompte/Account/LogOn?ReturnUrl=%2ftransfert
      O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www3.snapfish.fr/SnapfishActivia.cab
      O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
      O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://bmm.imgag.com/imgag/cp/install/crusher-fr.cab
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
      O17 - HKLM\System\CCS\Services\Tcpip\..\{22EBA1D8-CC0A-4554-B559-E1C3F41A8640}: NameServer = 85.255.115.117,85.255.112.204
      O17 - HKLM\System\CCS\Services\Tcpip\..\{3581CBEF-B8E5-42CF-BC45-AE48341EFDBE}: NameServer = 85.255.115.117,85.255.112.204
      O17 - HKLM\System\CCS\Services\Tcpip\..\{73EC3708-6402-4B73-BCAB-1EFABB87F054}: NameServer = 85.255.115.117,85.255.112.204
      O17 - HKLM\System\CCS\Services\Tcpip\..\{BD1AA1EB-9C08-44BE-968A-074F62FEBB83}: NameServer = 85.255.115.117,85.255.112.204
      O17 - HKLM\System\CCS\Services\Tcpip\..\{DE246E2C-8697-44FE-A5BB-FA04D12D4DEC}: NameServer = 85.255.115.117,85.255.112.204
      O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.117 85.255.112.204
      O17 - HKLM\System\CS1\Services\Tcpip\..\{22EBA1D8-CC0A-4554-B559-E1C3F41A8640}: NameServer = 85.255.115.117,85.255.112.204
      O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.117 85.255.112.204
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      1. Ok dans Hijackthis coches ces lignes puis cliques sur fix cheded:

        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
        O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll/206 (file missing)
        O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
        O16 - DPF: {104B0A37-AB99-4F06-8032-8BBDC3B77DDB} (Telechargement Control) - http://www.photoweb.fr/moncompte/Account/LogOn?ReturnUrl=%2ftransfert
        O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://bmm.imgag.com/imgag/cp/install/crusher-fr.cab

        + Tu supprime toute la lgne 17 et tu active le pare-feu et tu me reposte un nouveau rapport
        1. ogfile of Trend Micro HijackThis v2.0.2
          Scan saved at 10:44:33, on 12/05/2008
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16608)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\csrss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\WINDOWS\system32\LVCOMSX.EXE
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Logitech\Video\LogiTray.exe
          C:\Program Files\QuickTime\qttask.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\WINDOWS\system32\nvsvc32.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Logitech\Video\FxSvr2.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\WINDOWS\System32\alg.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\Windows Live\Messenger\usnsvc.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
          C:\Program Files\Internet Explorer\IEXPLORE.EXE
          C:\WINDOWS\ie7\iexplore.exe
          C:\WINDOWS\ie7\iexplore.exe
          C:\WINDOWS\system32\wbem\wmiprvse.exe
          C:\WINDOWS\system32\wscntfy.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
          O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
          O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
          O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
          O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe"
          O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
          O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
          O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
          O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
          O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: {104B0A37-AB99-4F06-8032-8BBDC3B77DDB} (Telechargement Control) - http://www.photoweb.fr/moncompte/Account/LogOn?ReturnUrl=%2ftransfert
          O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www3.snapfish.fr/SnapfishActivia.cab
          O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
          O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
          O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
          1. Ok merci tu es infecter. Quels sont tous tes logiciel de sécurité ?
        2. logiciel de sécurité j'ai avast puis pare feu de windows
          1. Re alors désinstalle tous tes logiciel de sécurité. Et installe AntiVir,Malwarebytes Anti-Malware,Ccleaner et active le pare-feu XP.

            AntiVir: https://www.01net.com/outils/telecharger/windows/Securite/antivirus-antitrojan/fiches/tele13198.html
            Tutoriel AntiVir: https://www.malekal.com/avira-free-security-antivirus-gratuit/

            Malwarebytes Anti-Malware: http://www.malwarebytes.org/mbam/program/mbam-setup.exe
            Tutoriel Malwarebytes Anti-Malware: https://forum.pcastuces.com/malwarebytes_antimalwares___tutoriel-f31s3.htm

            Ccleaner: https://www.01net.com/outils/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/tele32599.html
            Tutoriel Ccleaner: https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php (Tu l'installe sans la bare d'outil Yahoo)

            PS: TU LES INSTALLES SEULEMENT ET TU NE FAIS PAS D'ANALYSE. TU FAIS UNE MISE A JOUR A ANTIVIR ET MALWAREBYTES ANTI-MALWARE.
        3. ça y est j'ai fait ce que tu m'a dit merci beaucoup pour ton aide, puis si un jour j'ai un souci j'espère te retouver car tu explique trés bien...
          1. Tu fais un scan en mode sans échec avec AntiVir. Tu lances le scan et si il détecte un virus (normalement oui) tu cliques sur "delete" et "apply sélection to all following détections. (pour qu'il le supprimes automatiquement). A la fin du scan tu cliques sur "report" tu redémarre en mode normal puis tu me postes le rapport.

            Mode sans Echec:

            Au redémarrage de l'ordinateur, une fois le chargement du BIOS terminé, il y a un écran noir qui apparaît rapidement, appuie sur la touche [F8] (ou [F5] sur certains pc) jusqu'à l'affichage du menu des options avancées de Windows.
            Sélectionner "Mode sans échec" et appuie sur [Entrée]
            Il faudra choisir ta session habituelle, pas le compte "Administrateur" ou une autre.
            Regarde ici si besoin : http://pageperso.aol.fr/loraline60/mode_sans_echec.htm

            Ouvre le fichier texte sauvegardé sur le Bureau afin de suivre les instructions comme il faut.

            PS: JE TE CONSEILLE D'ENREGISTRER CE MESSAGE DANS TON BUREAU OU CAS OU.
        4. c'est toujours entrain de 'sacan' mais je comprend pas si je t'envoi le rapport aprés le mode sans echec ou avant? puis le mode sans echec consiste a quoi? merci
          1. Tu fais le scan en mode sans echec tu l'enregistre puis tu redemarre en mode normal. Pourquoi en mode sans echec car ils trouvent plus de fichiers et pour pas que le virus soit actif.
        5. voici le rapport...

          Avira AntiVir Personal
          Report file date: lundi 12 mai 2008 11:17

          Scanning for 1260844 virus strains and unwanted programs.

          Licensed to: Avira AntiVir PersonalEdition Classic
          Serial number: 0000149996-ADJIE-0001
          Platform: Windows XP
          Windows version: (Service Pack 2) [5.1.2600]
          Boot mode: Normally booted
          Username: SYSTEM
          Computer name: NOM-EB85C523610

          Version information:
          BUILD.DAT : 8.1.00.295 16479 Bytes 09/04/2008 16:24:00
          AVSCAN.EXE : 8.1.2.12 311553 Bytes 18/03/2008 09:02:56
          AVSCAN.DLL : 8.1.1.0 53505 Bytes 07/02/2008 08:43:37
          LUKE.DLL : 8.1.2.9 151809 Bytes 28/02/2008 08:41:23
          LUKERES.DLL : 8.1.2.1 12033 Bytes 21/02/2008 08:28:40
          ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 10:33:34
          ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 13:08:58
          ANTIVIR2.VDF : 7.0.4.0 1554432 Bytes 05/05/2008 08:59:32
          ANTIVIR3.VDF : 7.0.4.25 125952 Bytes 11/05/2008 08:59:33
          Engineversion : 8.1.0.42
          AEVDF.DLL : 8.1.0.5 102772 Bytes 25/02/2008 09:58:21
          AESCRIPT.DLL : 8.1.0.31 262522 Bytes 12/05/2008 08:59:43
          AESCN.DLL : 8.1.0.16 119156 Bytes 12/05/2008 08:59:42
          AERDL.DLL : 8.1.0.20 418165 Bytes 12/05/2008 08:59:42
          AEPACK.DLL : 8.1.1.4 364918 Bytes 12/05/2008 08:59:40
          AEOFFICE.DLL : 8.1.0.18 192890 Bytes 12/05/2008 08:59:39
          AEHEUR.DLL : 8.1.0.26 1237366 Bytes 12/05/2008 08:59:39
          AEHELP.DLL : 8.1.0.14 115063 Bytes 12/05/2008 08:59:37
          AEGEN.DLL : 8.1.0.20 299380 Bytes 12/05/2008 08:59:37
          AEEMU.DLL : 8.1.0.6 430451 Bytes 12/05/2008 08:59:35
          AECORE.DLL : 8.1.0.28 168310 Bytes 12/05/2008 08:59:34
          AVWINLL.DLL : 1.0.0.7 14593 Bytes 23/01/2008 17:07:53
          AVPREF.DLL : 8.0.0.1 25857 Bytes 18/02/2008 10:37:50
          AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:26:47
          AVREG.DLL : 8.0.0.0 30977 Bytes 23/01/2008 17:07:49
          AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
          AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 28/02/2008 08:31:31
          SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
          SMTPLIB.DLL : 1.2.0.19 28929 Bytes 23/01/2008 17:08:39
          NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
          RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 10/03/2008 14:37:25
          RCTEXT.DLL : 8.0.32.0 86273 Bytes 06/03/2008 12:02:11

          Configuration settings for the scan:
          Jobname..........................: Complete system scan
          Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
          Logging..........................: low
          Primary action...................: interactive
          Secondary action.................: ignore
          Scan master boot sector..........: on
          Scan boot sector.................: on
          Boot sectors.....................: C:, D:,
          Scan memory......................: on
          Process scan.....................: on
          Scan registry....................: on
          Search for rootkits..............: off
          Scan all files...................: Intelligent file selection
          Scan archives....................: on
          Recursion depth..................: 20
          Smart extensions.................: on
          Macro heuristic..................: on
          File heuristic...................: medium

          Start of the scan: lundi 12 mai 2008 11:17

          The scan of running processes will be started
          Scan process 'avscan.exe' - '1' Module(s) have been scanned
          Scan process 'avcenter.exe' - '1' Module(s) have been scanned
          Scan process 'WLLoginProxy.exe' - '1' Module(s) have been scanned
          Scan process 'iexplore.exe' - '1' Module(s) have been scanned
          Scan process 'usnsvc.exe' - '1' Module(s) have been scanned
          Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
          Scan process 'alg.exe' - '1' Module(s) have been scanned
          Scan process 'FxSvr2.exe' - '1' Module(s) have been scanned
          Scan process 'svchost.exe' - '1' Module(s) have been scanned
          Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
          Scan process 'avguard.exe' - '1' Module(s) have been scanned
          Scan process 'emule.exe' - '1' Module(s) have been scanned
          Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
          Scan process 'avgnt.exe' - '1' Module(s) have been scanned
          Scan process 'qttask.exe' - '1' Module(s) have been scanned
          Scan process 'LogiTray.exe' - '1' Module(s) have been scanned
          Scan process 'LVCOMSX.EXE' - '1' Module(s) have been scanned
          Scan process 'sched.exe' - '1' Module(s) have been scanned
          Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
          Scan process 'explorer.exe' - '1' Module(s) have been scanned
          Scan process 'svchost.exe' - '1' Module(s) have been scanned
          Scan process 'svchost.exe' - '1' Module(s) have been scanned
          Scan process 'svchost.exe' - '1' Module(s) have been scanned
          Scan process 'svchost.exe' - '1' Module(s) have been scanned
          Scan process 'svchost.exe' - '1' Module(s) have been scanned
          Scan process 'svchost.exe' - '1' Module(s) have been scanned
          Scan process 'lsass.exe' - '1' Module(s) have been scanned
          Scan process 'services.exe' - '1' Module(s) have been scanned
          Scan process 'winlogon.exe' - '1' Module(s) have been scanned
          Scan process 'csrss.exe' - '1' Module(s) have been scanned
          Scan process 'smss.exe' - '1' Module(s) have been scanned
          31 processes with 31 modules were scanned

          Starting master boot sector scan:
          Master boot sector HD0
          [INFO] No virus was found!
          Master boot sector HD1
          [INFO] No virus was found!
          [WARNING] Le périphérique n'est pas prêt.
          Master boot sector HD2
          [INFO] No virus was found!
          [WARNING] Le périphérique n'est pas prêt.
          Master boot sector HD3
          [INFO] No virus was found!
          [WARNING] Le périphérique n'est pas prêt.
          Master boot sector HD4
          [INFO] No virus was found!
          [WARNING] Le périphérique n'est pas prêt.

          Start scanning boot sectors:
          Boot sector 'C:\'
          [INFO] No virus was found!
          Boot sector 'D:\'
          [INFO] No virus was found!

          Starting to scan the registry.
          The registry was scanned ( '23' files ).

          Starting the file scan:

          Begin scan in 'C:\' <HP_PAVILION>
          C:\hiberfil.sys
          [WARNING] The file could not be opened!
          C:\pagefile.sys
          [WARNING] The file could not be opened!
          C:\Documents and Settings\HP_Propriétaire.NOM-EB85C523610\Local Settings\Temporary Internet Files\Content.IE5\11DMHHE4\2b323f1f[1].htm
          [DETECTION] Contains suspicious code HEUR/HTML.Malware
          [NOTE] The fund was classified as suspicious.
          [NOTE] The file was moved to '485b0ec9.qua'!
          C:\Documents and Settings\HP_Propriétaire.NOM-EB85C523610\Mes documents\lakhdar.djezzar\jetcodec4472.exe
          [DETECTION] Contains detection pattern of the dropper DR/Dldr.DNSChanger.Gen
          [NOTE] The file was moved to '489c10dc.qua'!
          C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP135\A0028635.exe
          [DETECTION] Is the Trojan horse TR/PSW.Sinow.333424
          [NOTE] The file was moved to '485818b9.qua'!
          C:\WINDOWS\system32\kdzvv.exe
          [WARNING] The file could not be opened!
          Begin scan in 'D:\' <HP_RECOVERY>

          End of the scan: lundi 12 mai 2008 12:37
          Used time: 1:19:48 min

          The scan has been done completely.

          10813 Scanning directories
          452438 Files were scanned
          2 viruses and/or unwanted programs were found
          1 Files were classified as suspicious:
          0 files were deleted
          0 files were repaired
          3 files were moved to quarantine
          0 files were renamed
          3 Files cannot be scanned
          452436 Files not concerned
          15153 Archives were scanned
          7 Warnings
          3 Notes
          1. POURQUOI LES AS TU MIS EN QUARANTAINE JE T'AI DEMANDE DE LES SUPPRIMER. VAS DANS LA QUARANTAINE ET SUPPRIME LES.
        6. pour le premier je pouvait que choisir mise ne quarantaine ou bien ignoré c'est pour ça mais la je vient de les supprimer...
          1. 1) Redémarre en "Mode sans échec"

            Au redémarrage de l'ordinateur, une fois le chargement du BIOS terminé, il y a un écran noir qui apparaît rapidement, appuie sur la touche [F8] (ou [F5] sur certains pc) jusqu'à l'affichage du menu des options avancées de Windows.
            Sélectionner "Mode sans échec" et appuie sur [Entrée]
            Il faudra choisir ta session habituelle, pas le compte "Administrateur" ou une autre.
            Regarde ici si besoin : http://pageperso.aol.fr/loraline60/mode_sans_echec.htm

            Ouvre le fichier texte sauvegardé sur le Bureau afin de suivre les instructions comme il faut.

            2) Scan avec Malwarebyte's Anti-Malware

            Lance Malwarebyte's Anti-Malware
            Onglet "Recherche" >>> coche Executer un exame complet >>> Rechercher sélectionne tes disques durs puis clique sur Lancer l’examen
            A la fin du scan >>> clique sur Afficher les résultats puis sur Enregistrer le rapport
            Suppression des éléments détectés >>>> clique sur Supprimer la sélection
            S'il t'es demandé de redémarrer >>> clique sur "Yes"

            --> Un rapport de scan s'ouvre, enregistre sur ton Bureau et poste ce rapport en réponse.
            1. voila mon scan...

              Malwarebytes' Anti-Malware 1.12
              Version de la base de données: 742

              Type de recherche: Examen complet (C:\|D:\|E:\|F:\|G:\|H:\|I:\|)
              Eléments examinés: 203329
              Temps écoulé: 4 hour(s), 38 minute(s), 4 second(s)

              Processus mémoire infecté(s): 0
              Module(s) mémoire infecté(s): 0
              Clé(s) du Registre infectée(s): 0
              Valeur(s) du Registre infectée(s): 0
              Elément(s) de données du Registre infecté(s): 0
              Dossier(s) infecté(s): 0
              Fichier(s) infecté(s): 0

              Processus mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Module(s) mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Clé(s) du Registre infectée(s):
              (Aucun élément nuisible détecté)

              Valeur(s) du Registre infectée(s):
              (Aucun élément nuisible détecté)

              Elément(s) de données du Registre infecté(s):
              (Aucun élément nuisible détecté)

              Dossier(s) infecté(s):
              (Aucun élément nuisible détecté)

              Fichier(s) infecté(s):
              (Aucun élément nuisible détecté)
              1. ensuite g nettoyer avec ccleaner... je pense que je né plus rien a faire? en tout cas encore merci!!!
                1. Salut ce n'est pas fini. maintenant fais un scan en ligne avec Internet Explorer stp:

                  BitDefender en ligne: http://www.bitdefender.fr/scan_fr/scan8/ie.html
                  Tutoriel BitDefender en ligne: http://cybersecurite.xooit.com/t201-Scan-en-ligne-BitDefender.htm

                  Ps: N'oublies pas de me poster le rapport. Si tu as besoin d'aide aide toi tu tutoriel.
              2. bonjour, voici le scan en ligne avec internet.

                <HTML>
                <HEAD>
                <TITLE>BitDefender Online Scanner - Rapport virus en temps réel</TITLE>
                <META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
                </HEAD>
                <BODY BGCOLOR=#FFFFFF leftmargin="20" marginwidth="0" topmargin="20" marginheight="0" >

                <table align="center" border="0" cellpadding="0" cellspacing="0" width="90%">
                <tr>
                <td>
                <p><font face="Courier New"><span style="font-size:11pt;"><b>BitDefender Online Scanner - Rapport virus en temps réel</b></span></font></p>
                </td>
                <td width="10%">
                <p> </p>
                </td>
                <td width="10%">
                <p> </p>
                </td>
                </tr>
                <tr>
                <td colspan="3">
                <p><font face="Courier New"><span style="font-size:11pt;">Généré à: Mon, May 19, 2008 - 18:43:44</span></font></p>
                </td>
                </tr>
                <tr>
                <td>
                <hr size="1" width="100%" align="left" noshade color="black">
                <p> </p>
                </td>
                <td width="10%">
                <p> </p>
                </td>
                <td width="10%">
                <p> </p>
                </td>
                </tr>
                <tr>
                <td>
                <p><font face="Courier New"><span style="font-size:11pt;"><b>Info d'analyse</b></span></font></p>
                </td>
                <td width="10%">
                <p> </p>
                </td>
                <td width="10%">
                <p> </p>
                </td>
                </tr>
                <tr>
                <td>
                <table border="0" cellpadding="0" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
                <tr>
                <td width="75%">
                <p><font face="Courier New"><span style="font-size:11pt;">Fichiers scannés</span></font></p>
                </td>
                <td width="25%">
                <p><font face="Courier New"><span style="font-size:11pt;">150829</span></font></p>
                </td>
                </tr>
                <tr>
                <td width="75%">
                <p><font face="Courier New"><span style="font-size:11pt;">Infectés Fichiers</span></font></p>
                </td>
                <td width="25%">
                <p><font face="Courier New"><span style="font-size:11pt;">0</span></font></p>
                </td>
                </tr>
                </table>
                </td>
                <td width="10%">
                <p> </p>
                </td>
                <td width="10%">
                <p> </p>
                </td>
                </tr>
                <tr>
                <td>
                <p><font face="Courier New"><span style="font-size:11pt;"><b> </b></span></font></p>
                </td>
                <td width="10%">
                <p> </p>
                </td>
                <td width="10%">
                <p> </p>
                </td>
                </tr>
                <tr>
                <td>
                <p><font face="Courier New"><span style="font-size:11pt;"><b>Virus Détectés</b></span></font></p>
                </td>
                <td width="10%">
                <p> </p>
                </td>
                <td width="10%">
                <p> </p>
                </td>
                </tr>
                <tr>
                <td>
                <table border="0" cellpadding="0" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
                <tr>
                <td width="75%">
                <p><font face="Courier New"><span style="font-size:11pt;">Aucun virus trouvé.</span></font></p>
                </td>
                <td width="25%">
                <p><font face="Courier New"><span style="font-size:11pt;"></span></font></p>
                </td>
                </tr>
                </table>
                </td>
                <td width="10%">
                <p> </p>
                </td>
                <td width="10%">
                <p> </p>
                </td>
                </tr>
                <tr>
                <td>
                <p> </p>
                </td>
                <td width="10%">
                <p> </p>
                </td>
                <td width="10%">
                <p> </p>
                </td>
                </tr>
                <tr>
                <td>
                <p> </p>
                <hr size="1" width="100%" align="left" noshade color="black">
                </td>
                <td width="10%">
                <p> </p>
                </td>
                <td width="10%">
                <p> </p>
                </td>
                </tr>
                <tr>
                <td>
                <p><font face="Courier New"><span style="font-size:8pt;">Ce sommaire du processus d'analyse sera utilisé par les laboratoires Antivirus BitDefender pour créer des statistiques agréguées sur l'activité des virus dans le monde. </span></font></p>
                </td>
                <td width="10%">
                <p> </p>
                </td>
                <td width="10%">
                <p> </p>
                </td>
                </tr>
                </table>
                <p> </p>

                </body>
                </html>
                1. rien n'a changer appart qu'il vas plu vite... mais ça me fait maintenant ' window ne trouve pas '(null)'.vérifiez que vous avez entré le nom correctement et essayer à nouveau.Pour rechercher un fichier, cliquez sur le menu demarrer puis rechercher' ça me fait ça sur tous les sites...