Fp pc on internet.com - Page 3

Résolu
  1. il ya beaucoup de fichier et je vois pas le fichier de l'installation d'antivir!!!!
    0
    1. oui j'ai commencé le scan du systeme il a trouvé une infection je l'ai mise en quarantaine
      et pour java il me dis qu'il ne peut pas se connecter au serveur????
      en plus la barre de progression dite copie des nouveaux fichiers est bloquée
      et j'ai déja désinstallé l'ancienne version donc autrement dit je suis sans java maintenant!!!!
      0
      1. pour java telcharge la version HORS LIGNE et instal la
        0
        1. je crois que c'est le rapport d'antivir:

          Avira AntiVir Personal
          Report file date: mardi 27 mai 2008 17:17

          Scanning for 1294131 virus strains and unwanted programs.

          Licensed to: Avira AntiVir PersonalEdition Classic
          Serial number: 0000149996-ADJIE-0001
          Platform: Windows XP
          Windows version: (Service Pack 2) [5.1.2600]
          Boot mode: Normally booted
          Username: SYSTEM
          Computer name: PC-44D7EE417780

          Version information:
          BUILD.DAT : 8.1.00.295 16479 Bytes 09/04/2008 16:24:00
          AVSCAN.EXE : 8.1.2.12 311553 Bytes 18/03/2008 10:02:58
          AVSCAN.DLL : 8.1.1.0 53505 Bytes 07/02/2008 09:43:38
          LUKE.DLL : 8.1.2.9 151809 Bytes 28/02/2008 09:41:24
          LUKERES.DLL : 8.1.2.1 12033 Bytes 21/02/2008 09:28:42
          ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 11:33:34
          ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 14:08:58
          ANTIVIR2.VDF : 7.0.4.53 1848832 Bytes 17/05/2008 15:55:35
          ANTIVIR3.VDF : 7.0.4.101 262144 Bytes 27/05/2008 15:55:55
          Engineversion : 8.1.0.46
          AEVDF.DLL : 8.1.0.5 102772 Bytes 25/02/2008 10:58:22
          AESCRIPT.DLL : 8.1.0.33 266618 Bytes 27/05/2008 15:57:59
          AESCN.DLL : 8.1.0.18 119156 Bytes 27/05/2008 15:57:51
          AERDL.DLL : 8.1.0.20 418165 Bytes 27/05/2008 15:57:47
          AEPACK.DLL : 8.1.1.5 364918 Bytes 27/05/2008 15:57:32
          AEOFFICE.DLL : 8.1.0.18 192890 Bytes 27/05/2008 15:57:17
          AEHEUR.DLL : 8.1.0.29 1253750 Bytes 27/05/2008 15:57:09
          AEHELP.DLL : 8.1.0.14 115063 Bytes 27/05/2008 15:56:29
          AEGEN.DLL : 8.1.0.21 303477 Bytes 27/05/2008 15:56:24
          AEEMU.DLL : 8.1.0.6 430451 Bytes 27/05/2008 15:56:13
          AECORE.DLL : 8.1.0.29 168311 Bytes 27/05/2008 15:56:03
          AVWINLL.DLL : 1.0.0.7 14593 Bytes 23/01/2008 18:07:54
          AVPREF.DLL : 8.0.0.1 25857 Bytes 18/02/2008 11:37:52
          AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 14:26:48
          AVREG.DLL : 8.0.0.0 30977 Bytes 23/01/2008 18:07:50
          AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 09:29:24
          AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 28/02/2008 09:31:32
          SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 18:28:04
          SMTPLIB.DLL : 1.2.0.19 28929 Bytes 23/01/2008 18:08:40
          NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 13:05:12
          RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 10/03/2008 15:37:26
          RCTEXT.DLL : 8.0.32.0 86273 Bytes 06/03/2008 13:02:12

          Configuration settings for the scan:
          Jobname..........................: Complete system scan
          Configuration file...............: C:\Program Files\Avira\AntiVir PersonalEdition Classic\sysscan.avp
          Logging..........................: low
          Primary action...................: interactive
          Secondary action.................: ignore
          Scan master boot sector..........: on
          Scan boot sector.................: on
          Boot sectors.....................: C:, D:, E:,
          Scan memory......................: on
          Process scan.....................: on
          Scan registry....................: on
          Search for rootkits..............: off
          Scan all files...................: All files
          Scan archives....................: on
          Recursion depth..................: 20
          Smart extensions.................: on
          Macro heuristic..................: on
          File heuristic...................: medium

          Start of the scan: mardi 27 mai 2008 17:17

          The scan of running processes will be started
          Scan process 'avscan.exe' - '1' Module(s) have been scanned
          Scan process 'avcenter.exe' - '1' Module(s) have been scanned
          Scan process 'msiexec.exe' - '1' Module(s) have been scanned
          Scan process 'msiexec.exe' - '1' Module(s) have been scanned
          Scan process 'msiexec.exe' - '1' Module(s) have been scanned
          Scan process 'avgnt.exe' - '1' Module(s) have been scanned
          Scan process 'msiexec.exe' - '1' Module(s) have been scanned
          Scan process 'jre-6u6-windows-i586-p-iftw.exe' - '1' Module(s) have been scanned
          Scan process 'avguard.exe' - '1' Module(s) have been scanned
          Scan process 'sched.exe' - '1' Module(s) have been scanned
          Scan process 'WLLoginProxy.exe' - '1' Module(s) have been scanned
          Scan process 'IEXPLORE.EXE' - '1' Module(s) have been scanned
          Scan process 'explorer.exe' - '1' Module(s) have been scanned
          Scan process 'GoogleDesktopCrawl.exe' - '1' Module(s) have been scanned
          Scan process 'GoogleDesktopIndex.exe' - '1' Module(s) have been scanned
          Scan process 'NMIndexingService.exe' - '1' Module(s) have been scanned
          Scan process 'Ymsgr_tray.exe' - '1' Module(s) have been scanned
          Scan process 'WinCinemaMgr.exe' - '1' Module(s) have been scanned
          Scan process 'NMIndexStoreSvr.exe' - '1' Module(s) have been scanned
          Scan process 'NMBgMonitor.exe' - '1' Module(s) have been scanned
          Scan process 'GoogleDesktop.exe' - '1' Module(s) have been scanned
          Scan process 'LightScribeControlPanel.exe' - '1' Module(s) have been scanned
          Scan process 'vsnp2std.exe' - '1' Module(s) have been scanned
          Scan process 'DAP.exe' - '1' Module(s) have been scanned
          Scan process 'tsnp2std.exe' - '1' Module(s) have been scanned
          Scan process 'FixCamera.exe' - '1' Module(s) have been scanned
          Scan process 'qttask.exe' - '1' Module(s) have been scanned
          Scan process 'realsched.exe' - '1' Module(s) have been scanned
          Scan process 'RTHDCPL.exe' - '1' Module(s) have been scanned
          Scan process 'igfxpers.exe' - '1' Module(s) have been scanned
          Scan process 'hkcmd.exe' - '1' Module(s) have been scanned
          Scan process 'WgaTray.exe' - '1' Module(s) have been scanned
          Scan process 'alg.exe' - '1' Module(s) have been scanned
          Scan process 'wdfmgr.exe' - '1' Module(s) have been scanned
          Scan process 'svchost.exe' - '1' Module(s) have been scanned
          Scan process 'MDM.EXE' - '1' Module(s) have been scanned
          Scan process 'LSSrvc.exe' - '1' Module(s) have been scanned
          Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
          Scan process 'ashServ.exe' - '1' Module(s) have been scanned
          Scan process 'aawservice.exe' - '1' Module(s) have been scanned
          Scan process 'svchost.exe' - '1' Module(s) have been scanned
          Scan process 'svchost.exe' - '1' Module(s) have been scanned
          Scan process 'svchost.exe' - '1' Module(s) have been scanned
          Scan process 'svchost.exe' - '1' Module(s) have been scanned
          Scan process 'svchost.exe' - '1' Module(s) have been scanned
          Scan process 'lsass.exe' - '1' Module(s) have been scanned
          Scan process 'services.exe' - '1' Module(s) have been scanned
          Scan process 'winlogon.exe' - '1' Module(s) have been scanned
          Scan process 'csrss.exe' - '1' Module(s) have been scanned
          Scan process 'smss.exe' - '1' Module(s) have been scanned
          50 processes with 50 modules were scanned

          Starting master boot sector scan:
          Master boot sector HD0
          [INFO] No virus was found!

          Start scanning boot sectors:
          Boot sector 'C:\'
          [INFO] No virus was found!
          Boot sector 'D:\'
          [INFO] No virus was found!
          Boot sector 'E:\'
          [INFO] No virus was found!

          Starting to scan the registry.
          The registry was scanned ( '31' files ).

          Starting the file scan:

          Begin scan in 'C:\'
          C:\pagefile.sys
          [WARNING] The file could not be opened!
          C:\Documents and Settings\pc\Mes documents\My Completed Downloads\Navilog1.exe
          [DETECTION] Contains detection pattern of the dropper DR/Tool.Reboot.F.94
          [NOTE] The file was moved to '48b234b1.qua'!
          C:\System Volume Information\_restore{F9CEEB5C-4CED-44BD-97F2-D7CDE83CE033}\RP102\A0029053.DLL
          [DETECTION] Contains detection pattern of a probably damaged sample CC/Agent.CS
          [NOTE] The file was moved to '486c36be.qua'!
          C:\System Volume Information\_restore{F9CEEB5C-4CED-44BD-97F2-D7CDE83CE033}\RP102\A0029066.exe
          [DETECTION] Is the Trojan horse TR/Trash.Gen
          [NOTE] The file was moved to '486c3741.qua'!
          C:\System Volume Information\_restore{F9CEEB5C-4CED-44BD-97F2-D7CDE83CE033}\RP102\A0029067.exe
          [DETECTION] Is the Trojan horse TR/Trash.Gen
          [NOTE] The file was moved to '486c3743.qua'!
          C:\System Volume Information\_restore{F9CEEB5C-4CED-44BD-97F2-D7CDE83CE033}\RP102\A0029068.dll
          [DETECTION] Is the Trojan horse TR/Trash.Gen
          [NOTE] The file was moved to '486c3747.qua'!
          C:\System Volume Information\_restore{F9CEEB5C-4CED-44BD-97F2-D7CDE83CE033}\RP80\A0020282.exe
          [DETECTION] Is the Trojan horse TR/Crypt.CFI.Gen
          [NOTE] The file was moved to '486c37ef.qua'!
          C:\System Volume Information\_restore{F9CEEB5C-4CED-44BD-97F2-D7CDE83CE033}\RP81\A0021357.exe
          [DETECTION] Is the Trojan horse TR/Crypt.CFI.Gen
          [NOTE] The file was moved to '486c37f2.qua'!
          Begin scan in 'D:\'
          D:\LOGICIELS\utilitaires\SmitfraudFix\SmitfraudFix.exe
          [DETECTION] Contains detection pattern of the dropper DR/Tool.Reboot.F.87
          [NOTE] The file was moved to '48a5399d.qua'!
          D:\System Volume Information\_restore{F9CEEB5C-4CED-44BD-97F2-D7CDE83CE033}\RP109\A0029508.exe
          [DETECTION] Contains detection pattern of the dropper DR/Tool.Reboot.F.87
          [NOTE] The file was moved to '486c39ca.qua'!
          D:\System Volume Information\_restore{F9CEEB5C-4CED-44BD-97F2-D7CDE83CE033}\RP86\A0025311.exe
          [DETECTION] Contains detection pattern of the dropper DR/Tool.Reboot.F.94
          [NOTE] The file was moved to '486c39d1.qua'!
          Begin scan in 'E:\' <bibliotheque>

          End of the scan: mardi 27 mai 2008 17:44
          Used time: 27:13 min

          The scan has been done completely.

          5420 Scanning directories
          170841 Files were scanned
          10 viruses and/or unwanted programs were found
          0 Files were classified as suspicious:
          0 files were deleted
          0 files were repaired
          10 files were moved to quarantine
          0 files were renamed
          1 Files cannot be scanned
          170831 Files not concerned
          4247 Archives were scanned
          1 Warnings
          10 Notes
          0
          1. ok ras

            envoi un rapport hijackthis stp
            0
            1. le rapport de hijackthis:

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 17:53:35, on 27/05/2008
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
              C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\WgaTray.exe
              C:\WINDOWS\system32\hkcmd.exe
              C:\WINDOWS\system32\igfxpers.exe
              C:\WINDOWS\RTHDCPL.EXE
              C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
              C:\Program Files\QuickTime\qttask.exe
              C:\WINDOWS\FixCamera.exe
              C:\WINDOWS\tsnp2std.exe
              C:\Program Files\DAP\DAP.EXE
              C:\WINDOWS\vsnp2std.exe
              C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe
              C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
              C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
              C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
              C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
              C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
              C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
              C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
              C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
              C:\WINDOWS\explorer.exe
              C:\Program Files\Internet Explorer\IEXPLORE.EXE
              C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
              C:\WINDOWS\system32\msiexec.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avcenter.exe
              C:\Documents and Settings\pc\Mes documents\My Completed Downloads\HiJackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              R3 - URLSearchHook: speed-bit Toolbar - {2ba521ac-b9b9-4433-ba45-dba2f02cba5a} - C:\Program Files\speed-bit\tbspee.dll
              R3 - URLSearchHook: SrchHook Class - {F4F10C1D-87C7-404A-B4B3-000000000000} - C:\PROGRA~1\DAP\SBSearch.dll
              R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
              O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
              O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
              O2 - BHO: speed-bit Toolbar - {2ba521ac-b9b9-4433-ba45-dba2f02cba5a} - C:\Program Files\speed-bit\tbspee.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Catcher Class - {ADECBED6-0366-4377-A739-E69DFBA04663} - C:\Program Files\Moyea\FLV Downloader\MoyeaCth.dll
              O3 - Toolbar: speed-bit Toolbar - {2ba521ac-b9b9-4433-ba45-dba2f02cba5a} - C:\Program Files\speed-bit\tbspee.dll
              O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
              O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
              O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
              O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
              O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
              O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
              O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
              O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
              O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
              O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
              O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
              O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe
              O4 - HKLM\..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe
              O4 - HKLM\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP
              O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe
              O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe -hidden
              O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
              O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
              O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
              O4 - HKCU\..\Run: [X'nBeep] C:\Program Files\X'nBeep 1.1\XnBeep.exe
              O4 - HKCU\..\Run: [Lyad] C:\Program Files\Lyad Messenger\lyad_messenger.exe autostart
              O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
              O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
              O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
              O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
              O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
              O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
              O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
              O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
              O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
              O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
              O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
              0
              1. tu connais ces programmes :

                C:\Program Files\X'nBeep 1.1\XnBeep.exe
                C:\Program Files\Lyad Messenger\lyad_messenger.exe autostart

                si oui désinstal les

                désinstal aussi avast :

                Pour désinstaller Avast telecharge cet outil

                https://www.avast.com/fr-fr/uninstall-utility

                dis moi ce que ça donne
                0
                1. pour lyad il ne figure pas sur la liste pour pouvoir le désinstaller
                  et pour X'nBeep 1.1 il me dis qu'une erreur c'est produite alors qaund je vais >démarrer>tout les programmes >X'nBee>qaund je cilc il me demmande de choisir un programme dans le web ou dans la liste car il peut pas le lire.et il ne figure plus dans la liste de supprimer/installer.
                  pour avast je l'ai désinstallé mais pas avec le module que tu m'a donné car si je l'execute il affiche ce message d'alerte: the avast self protection module is enable.for this raison the opperation cannot be completed.
                  0
                  1. ok

                    1) vire avast

                    2) vas dans poste de travail

                    disque c

                    entre dans programmes

                    supprimes les dossiers :

                    XnBeep et Lyad Messenger

                    ensuite refais un scan hijackthis et psote le rapport stp
                    0
                    1. lyad messenger je l'ai suprimmé hier comme tu m'a dis de le faire mainrenant alors je le trouve pas et XnBeep je l'ai suprimmer a partir de poste de travail>C:\Documents and Settings\All Users\Menu Démarrer\Programmes.
                      pour avast il me dit que le disque est plein ou protégé par une ecriture alors impossible de le suprimmer a partir de programme files
                      voici le rapport:

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 18:20:54, on 27/05/2008
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                      C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\WgaTray.exe
                      C:\WINDOWS\system32\hkcmd.exe
                      C:\WINDOWS\system32\igfxpers.exe
                      C:\WINDOWS\RTHDCPL.EXE
                      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                      C:\Program Files\QuickTime\qttask.exe
                      C:\WINDOWS\FixCamera.exe
                      C:\WINDOWS\tsnp2std.exe
                      C:\Program Files\DAP\DAP.EXE
                      C:\WINDOWS\vsnp2std.exe
                      C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe
                      C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                      C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
                      C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
                      C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
                      C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
                      C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
                      C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
                      C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
                      C:\WINDOWS\explorer.exe
                      C:\Program Files\Internet Explorer\IEXPLORE.EXE
                      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                      C:\Documents and Settings\pc\Mes documents\My Completed Downloads\HiJackThis.exe

                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      R3 - URLSearchHook: speed-bit Toolbar - {2ba521ac-b9b9-4433-ba45-dba2f02cba5a} - C:\Program Files\speed-bit\tbspee.dll
                      R3 - URLSearchHook: SrchHook Class - {F4F10C1D-87C7-404A-B4B3-000000000000} - C:\PROGRA~1\DAP\SBSearch.dll
                      R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
                      O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
                      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                      O2 - BHO: speed-bit Toolbar - {2ba521ac-b9b9-4433-ba45-dba2f02cba5a} - C:\Program Files\speed-bit\tbspee.dll
                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: Catcher Class - {ADECBED6-0366-4377-A739-E69DFBA04663} - C:\Program Files\Moyea\FLV Downloader\MoyeaCth.dll
                      O3 - Toolbar: speed-bit Toolbar - {2ba521ac-b9b9-4433-ba45-dba2f02cba5a} - C:\Program Files\speed-bit\tbspee.dll
                      O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
                      O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                      O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
                      O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                      O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                      O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
                      O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
                      O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
                      O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
                      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                      O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
                      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                      O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe
                      O4 - HKLM\..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe
                      O4 - HKLM\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP
                      O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe
                      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
                      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe -hidden
                      O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                      O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
                      O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
                      O4 - HKCU\..\Run: [X'nBeep] C:\Program Files\X'nBeep 1.1\XnBeep.exe
                      O4 - HKCU\..\Run: [Lyad] C:\Program Files\Lyad Messenger\lyad_messenger.exe autostart
                      O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
                      O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
                      O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
                      O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                      O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
                      O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
                      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                      O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                      O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                      O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                      O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
                      0
                      1. réouvre hijackthis

                        fais scan only

                        coche ces lignes :

                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                        R3 - URLSearchHook: speed-bit Toolbar - {2ba521ac-b9b9-4433-ba45-dba2f02cba5a} - C:\Program Files\speed-bit\tbspee.dll

                        O4 - HKCU\..\Run: [X'nBeep] C:\Program Files\X'nBeep 1.1\XnBeep.exe
                        O4 - HKCU\..\Run: [Lyad] C:\Program Files\Lyad Messenger\lyad_messenger.exe autostart

                        coche les et clci sur fix checked

                        Pour désinstaller Avast telecharge cet outil

                        https://www.avast.com/fr-fr/uninstall-utility

                        fais le en mode sans echec

                        ensuite suis cette procédure

                        Maintenant , nous allons supprimer les logiciels de désinfection que je t'ai fait téléchargé.
                        En effet , s'en servir est dangereux pour le pc si l'on ne s'y connais pas.
                        De plus ils sont mis régulièrement à jours.

                        ? Ferme toutes les applications en cours, puis télécharge ToolsCleaner2 sur ton Bureau.

                        http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner

                        ? Double clique sur ToolsCleaner2.exe >
                        ? Clique sur .Recherche
                        ? puis sur Suppression quand la liste est trouvée.
                        ? Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

                        (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                        Note : ton bureau RISQUE de disparaître, c'est normal. S'il n'apparaît pas à la fin du scan, fais la manip suivante :

                        CTRL+ALT+SUPP pour ouvrir le Gestionnaire des tâches.
                        Puis rends toi à l'onglet "Processus". Clique en haut à gauche sur Fichiers et choisis "Exécuter"

                        Tape explorer.exe et valide. Cela fera re-apparaître le Bureau

                        Tuto : https://www.commentcamarche.net/list 8341 toolscleaner suppression des fix de force brute ( merci espion3004 )
                        0
                        1. voici le rapport:

                          -->- Recherche:

                          C:\Combofix: trouvé !
                          C:\Qoobox: trouvé !
                          C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1: trouvé !
                          C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1\Navilog1.lnk: trouvé !
                          C:\Documents and Settings\pc\Bureau\Les racourcis\Navilog1.lnk: trouvé !
                          C:\Documents and Settings\pc\Mes documents\My Completed Downloads\HijackThis.exe: trouvé !
                          C:\Documents and Settings\pc\Mes documents\My Completed Downloads\Btfix: trouvé !
                          C:\Documents and Settings\pc\Mes documents\My Completed Downloads\BTFix\Btfix: trouvé !
                          C:\Documents and Settings\pc\Mes documents\My Completed Downloads\clean\Clean.zip: trouvé !
                          C:\Documents and Settings\pc\Mes documents\My Completed Downloads\ComboFix1\BtFix.zip: trouvé !
                          C:\Documents and Settings\pc\Mes documents\My Completed Downloads\ComboFix1\ComboFix.exe: trouvé !
                          C:\Documents and Settings\pc\Recent\HijackThis.lnk: trouvé !
                          C:\Program Files\Navilog1: trouvé !
                          C:\Program Files\Navilog1\Navilog1.bat: trouvé !

                          ---------------------------------
                          -->- Suppression:

                          C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1\Navilog1.lnk: supprimé !
                          C:\Documents and Settings\pc\Bureau\Les racourcis\Navilog1.lnk: supprimé !
                          C:\Documents and Settings\pc\Mes documents\My Completed Downloads\HijackThis.exe: supprimé !
                          C:\Documents and Settings\pc\Mes documents\My Completed Downloads\clean\Clean.zip: supprimé !
                          C:\Documents and Settings\pc\Mes documents\My Completed Downloads\ComboFix1\BtFix.zip: supprimé !
                          C:\Documents and Settings\pc\Mes documents\My Completed Downloads\ComboFix1\ComboFix.exe: supprimé !
                          C:\Documents and Settings\pc\Recent\HijackThis.lnk: supprimé !
                          C:\Program Files\Navilog1\Navilog1.bat: supprimé !
                          C:\Combofix: supprimé !
                          C:\Qoobox: supprimé !
                          C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1: supprimé !
                          C:\Documents and Settings\pc\Mes documents\My Completed Downloads\Btfix: supprimé !
                          C:\Program Files\Navilog1: supprimé !

                          Corbeille vidée!
                          0
                          1. ok c est propre

                            Si tu es satisfait de mon intervention

                            et que tu n as plus de probleme

                            change le statut du sujet en résolu stp

                            pour cela va en haut sur ta premiere question et la tu as le choix
                            0
                            1. oui je pense que tout est reglé
                              et franchement je n'arrive pas a le croire
                              merci beaucoup pour votre aide merci.
                              0
                              1. derniere question comment je pourrai savoir que je suis infecté? dans le futur???
                                si vous etes là bien sur!!
                                0
                                Précédent
                                • 1
                                • 2
                                • 3